Block chain network equipment information verification method, verification node and terminal equipment
By using differentiated PUF models and unique first vectors in the verification nodes of the blockchain network, the single point leakage problem is solved, and the reliability of device information verification and the security of the blockchain network are improved.
Patent Information
- Application Number
- CN202510006141.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-02
- Publication Date
- 2025-05-09
AI Technical Summary
There is a single point of leakage problem in the blockchain network. Attackers can use the leaked verification information to make false devices pass the verification of all verification nodes, reducing the reliability of device information verification and the security of the blockchain network.
By using differentiated PUF models in the verification nodes of the blockchain network, each verification node generates a unique verification response value based on its corresponding first vector. Even if a single verification node is leaked, the attacker cannot make the fake device pass the verification of all verification nodes.
Improve the reliability of device information verification and the overall security of blockchain network to prevent security threats caused by single-point leakage.
Smart Images

Figure CN119966600A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of blockchain technology, and in particular, relates to a device information verification method, verification node and terminal device of a blockchain network. Background Art
[0002] Blockchain refers to a decentralized distributed data structure. The emergence of blockchain technology has brought a solution to the security verification of device information. For example, the Physical Unclonable Function (PUF) can be applied to the blockchain network to realize the registration and verification of the device. However, this method requires the PUF to be registered to each verification node of the blockchain network first, and then the PUF registered to the verification node is used to verify the device. All verification nodes share the verification information containing the PUF at the same time and it is not public.
[0003] However, this method has a single point leakage problem. If a verification node in the blockchain network leaks verification information, the attacker can use the verification information to make a fake device pass the verification of all verification nodes, thereby reducing the reliability of device information verification and the overall security of the blockchain network. Summary of the invention
[0004] The embodiments of the present application provide a device information verification method, verification node and terminal device of a blockchain network. Each verification node in the blockchain network can generate a different verification response value based on its corresponding first vector. Even if a single verification node is leaked, an attacker cannot make a false device pass the verification of all verification nodes based on the leaked information, thereby improving the reliability of device information verification and the overall security of the blockchain network.
[0005] In the first aspect, an embodiment of the present application provides a device information verification method for a blockchain network, comprising: performing the following processing through a verification node of the blockchain network: receiving a differentiated PUF model sent by a first blockchain node; in response to a transaction request sent by a second blockchain node, sending a challenge value to the second blockchain node, wherein the transaction request includes target device information; in response to a target response value sent by the second blockchain node, inputting the challenge value and a first vector built into the differentiated PUF model into the differentiated PUF model to obtain a verification response value output by the differentiated PUF model; wherein each of the first vectors corresponds to one verification node; and when the similarity between the target response value and the verification response value is greater than a preset threshold, determining that the target device information has passed the verification.
[0006] In some embodiments, the differentiated PUF model includes an XOR module and a PUF module; inputting the challenge value and the first vector built into the differentiated PUF model into the differentiated PUF model, and obtaining the verification response value output by the differentiated PUF model includes: inputting the challenge value and the first vector into the XOR module to obtain the XOR result output by the XOR module; inputting the XOR result into the PUF module to obtain the verification response value output by the PUF module.
[0007] In some embodiments, before receiving the differentiated PUF model sent by the first blockchain node, the method also includes: performing the following processing through the first blockchain node: sending a registration request to all verification nodes of the blockchain network, wherein the registration request includes device information, manufacturer information and a second vector corresponding to each of the verification nodes; in response to the verification pass information sent by the verification node, hashing the second vector corresponding to the verification node with a preset security seed to obtain the first vector; and generating the differentiated PUF model based on the first vector, the XOR module and the PUF module; wherein the verification pass information is the information sent to the first blockchain node after the verification node authenticates the first blockchain node based on the device information and the manufacturer information, and determines that the first blockchain node passes the identity authentication; and sending the differentiated PUF model corresponding to the verification node to the verification node.
[0008] In some embodiments, before sending a registration request to all verification nodes of the blockchain network, the method also includes: performing the following processing through the first blockchain node: generating a device PUF model for all devices that need to be registered to the blockchain network; wherein the device PUF model includes a hash module, the XOR module and the PUF module; the hash module is used to perform a hash operation on the input second vector and the security seed to generate the first vector; the XOR module is used to perform an XOR operation on the input challenge value and the first vector to generate an XOR result; the PUF module is used to generate a response value based on the input XOR result.
[0009] In some embodiments, after sending the challenge value to the second blockchain node in response to the transaction request sent by the second blockchain node, the method also includes: performing the following processing through the second blockchain node: obtaining the second vector corresponding to the verification node; inputting the second vector and the challenge value into the target device PUF model corresponding to the target device information to obtain the target response value output by the target device PUF model; and sending the challenge value and the target response value as a challenge-response pair to the verification node.
[0010] In some embodiments, when the similarity between the target response value and the verification response value is greater than a preset threshold, after determining that the target device information has passed the verification, the method further includes: uploading and broadcasting the target device information and the verification result corresponding to the target device information to the blockchain network, and sending the verification result to the second blockchain node.
[0011] In some embodiments, when the similarity between the target response value and the verification response value is greater than a preset threshold, determining that the target device information has passed the verification includes: comparing the target response value with the verification response value bit by bit; and when the number of identical bits between the target response value and the verification response value is greater than the preset threshold, determining that the target device information has passed the verification.
[0012] In the second aspect, an embodiment of the present application provides a verification node, including: a receiving module, used to receive a differentiated PUF model sent by a first blockchain node; a sending module, used to send a challenge value to the second blockchain node in response to a transaction request sent by the second blockchain node, wherein the transaction request includes target device information; a calculation module, used to respond to the target response value sent by the second blockchain node, input the challenge value and the first vector built into the differentiated PUF model into the differentiated PUF model, and obtain a verification response value output by the differentiated PUF model; wherein each first vector corresponds to one verification node; a verification module, used to determine that the target device information has passed the verification when the similarity between the target response value and the verification response value is greater than a preset threshold.
[0013] In a third aspect, an embodiment of the present application provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the device information verification method of the blockchain network according to any one of the first aspects described above is implemented.
[0014] In a fourth aspect, an embodiment of the present application provides a computer program product, including a computer program. When the computer program is run, the device information verification method of the blockchain network described in any one of the first aspects above is executed.
[0015] Compared with the related art, the device information verification method, verification node and terminal device of the blockchain network provided by the embodiment of the present application, the verification node can receive the differentiated PUF model sent by the first blockchain node, input the challenge value and the first vector corresponding to the verification node itself into the differentiated PUF model, obtain the verification response value, and verify the target device information sent by the second blockchain node based on the target response value and the verification response value sent by the second blockchain node. Since each first vector corresponds to a verification node, the verification response values generated by different verification nodes for the target device information are also different. In this way, each verification node in the blockchain network can generate different verification response values based on their respective corresponding first vectors. Even if a single verification node is leaked, the attacker cannot make the false device pass the verification of all verification nodes based on the leaked information, thereby improving the reliability of device information verification and the overall security of the blockchain network.
[0016] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 This is a schematic diagram of the application architecture of a blockchain network according to an embodiment of the present application;
[0019] Figure 2 is a schematic diagram of the structure of a device PUF model according to an embodiment of the present application;
[0020] Figure 3 This is a flow chart of a device information verification method for a blockchain network according to an embodiment of the present application;
[0021] Figure 4 is a flow chart of a device information verification method of a blockchain network according to another embodiment of the present application;
[0022] Figure 5 is a schematic diagram of the structure of a verification node according to an embodiment of the present application;
[0023] Figure 6 It is a structural diagram of a terminal device according to an embodiment of the present application. DETAILED DESCRIPTION
[0024] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0025] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0026] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0027] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.
[0028] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0029] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0030] Blockchain refers to a decentralized distributed data structure. The emergence of blockchain technology has brought a solution to the security verification of device information. For example, PUF can be applied to the blockchain network to realize the registration and verification of devices. However, this method requires the PUF to be registered to each verification node of the blockchain network first, and then the PUF registered to the verification node is used to verify the device. All verification nodes share the verification information containing PUF at the same time and it is not public.
[0031] However, this method has a single point leakage problem. If a verification node in the blockchain network leaks verification information, the attacker can use the verification information to make a fake device pass the verification of all verification nodes, which will pose a threat to the user's privacy and security, and reduce the reliability of device information verification and the overall security of the blockchain network.
[0032] In view of this, the embodiments of the present application provide a device information verification method, verification node, terminal device and computer program product of a blockchain network, wherein the verification node can receive a differentiated PUF model sent by a first blockchain node, input a challenge value and a first vector corresponding to the verification node itself into the differentiated PUF model, obtain a verification response value, and verify the target device information sent by the second blockchain node based on the target response value and the verification response value sent by the second blockchain node. Since each first vector corresponds to a verification node, the verification response values generated by different verification nodes for the target device information are also different. In this way, each verification node in the blockchain network can generate a different verification response value based on the first vector corresponding to each of them. Even if a single verification node is leaked, the attacker cannot make the false device pass the verification of all verification nodes based on the leaked information, thereby improving the reliability of device information verification and the overall security of the blockchain network.
[0033] Before further describing the embodiments of the present application in detail, the nouns and terms involved in the embodiments of the present application are described. The nouns and terms involved in the embodiments of the present application are subject to the following interpretations.
[0034] 1) Physical Unclonable Function (PUF) is a unique hardware security mechanism that uses microscopic physical properties inherent in semiconductor devices or circuits and generated by random variations in the production process. The design of PUF is based on the fact that even in the precisely controlled semiconductor manufacturing process, tiny process deviations are inevitable, resulting in each chip having unique physical properties. When a specific challenge signal (Challenge) is applied to the PUF, it produces a unique response (Response), which reflects the differences in the physical structure inside the chip. Since these differences cannot be reproduced by copying the manufacturing process, the key or signature generated by the PUF is difficult to copy or clone, providing an effective means for device authentication, key generation and anti-counterfeiting.
[0035] 2) Blockchain, a decentralized, tamper-proof distributed database technology. It stores transaction data in the form of a hash chain, with each block recording the hash value of the previous block, and ensures the final consistency of each blockchain copy through encryption and consensus algorithms, thereby eliminating dependence on the center. Smart contract technology is a computer program stored on the blockchain that can automatically execute contract terms when specific conditions are met, ensuring that it is executed according to the rules defined in its code. Once a smart contract is created, it cannot be changed.
[0036] The following describes an exemplary application architecture of the blockchain network provided by the embodiment of the present application, see Figure 1 , Figure 1 The present invention is a schematic diagram of an application architecture of a blockchain network according to an embodiment of the present application, including multiple verification nodes, a first blockchain node, and a second blockchain node. Each verification node can establish a connection with the first blockchain node through a wired network or a wireless network, and each verification node can establish a connection with the second blockchain node through a wired network or a wireless network.
[0037] The types of blockchain networks are flexible and diverse, such as public chains, private chains, or consortium chains. Taking the public chain as an example, any client running in the terminal or server of any business entity can access the blockchain network without authorization and become a special type of node, becoming the first blockchain node or the second blockchain node.
[0038] The verification node can be a certified entity (e.g., an enterprise, government agency, or industry organization). Each verification node must be equipped with server-level computing processing power, sufficient storage resources, and high-speed network communication capabilities.
[0039] The first blockchain node can be a node used by the device manufacturer. The device manufacturer is responsible for producing the device, generating and distributing the differentiated PUF model (also called the H-MPUF model), and the device flows into the market from the device manufacturer. The first blockchain node can also assume the function of a verification node and have the same computing resources as the verification node.
[0040] The second blockchain node can be a node used by users. Untrusted users need to prove the authenticity of the device to the verification node. Users who own the device are sellers and may sell fake devices, so they are untrusted users; users who are buyers will pay a price to become device owners and be responsible for the device, so they are trusted users, but buyers will also become untrusted parties after the transaction. The computing resources and bandwidth of the second blockchain node are limited.
[0041] The PUF module embedded in the device provides sufficient cryptographic security and cannot be effectively copied or cloned.
[0042] The verification node is used to receive the differentiated PUF model sent by the first blockchain node; in response to the transaction request sent by the second blockchain node, the challenge value is sent to the second blockchain node; the verification node is also used to respond to the target response value sent by the second blockchain node, input the challenge value and the first vector built into the differentiated PUF model into the differentiated PUF model, and obtain the verification response value output by the differentiated PUF model; the verification node is also used to determine that the target device information has passed the verification when the similarity between the target response value and the verification response value is greater than a preset threshold.
[0043] The operation of the first blockchain node on the blockchain network mainly includes sending a registration request to all verification nodes of the blockchain network, wherein the registration request includes device information, manufacturer information, and a second vector corresponding to each verification node.
[0044] The verification node can authenticate the first blockchain node based on the device information and the manufacturer information, and send verification pass information to the first blockchain node after determining that the first blockchain node identity authentication is passed.
[0045] In response to the verification pass information sent by the verification node, the first blockchain node performs a hash operation on the second vector corresponding to the verification node and the preset security seed to obtain the first vector; the first blockchain node is also used to generate a differentiated PUF model based on the first vector, the XOR module and the PUF module; the first blockchain node is also used to send the differentiated PUF model corresponding to the verification node to the verification node.
[0046] In addition, the first blockchain node is also used to generate a device PUF model for all devices that need to be registered to the blockchain network.
[0047] Will combine Figure 2 The exemplary structure of the device PUF model provided in the embodiments of the present application is described. Figure 2 is a schematic diagram of the structure of a device PUF model according to an embodiment of the present application, such as Figure 2 As shown, in one embodiment, the device PUF model includes a hash module, an XOR module and a PUF module; the hash module is used to input a second vector vector k Perform hash operation with the security seed seed to generate the first vector H k ; XOR module is used to input the challenge value C and the first vector H k Perform XOR operation to generate XOR result S k PUF module is used to XOR the result S based on the input k , generating the response value r k .
[0048] It should be noted that the differentiated PUF model generated by the first blockchain node only includes the XOR module and the PUF module, but it is different from the verification node peer. k The first vector H is built into the corresponding differentiated PUF model. k . Among them, the first vector H k It is based on the verification node peer k The corresponding second vector vector k and the security seed seed by hashing. Since each second vector vector k The corresponding verification node peer k is unique, therefore, each first vector H k The corresponding verification node peer k It is also unique. In turn, the first blockchain node sends a verification node peer k The differentiated PUF model sent is also the same as the verification node peer k Unique correspondence. This ensures that the verification response values generated by each verification node are different. Even if a single verification node is leaked, attackers cannot use the leaked information to make a fake device pass the verification of all verification nodes, thereby improving the reliability of device information verification and the overall security of the blockchain network.
[0049] In this embodiment, the first blockchain node can be each verification node peer k Distribute the only corresponding second vector vector k (For example, vector 1 The only corresponding peer 1 ), and can publish all second vectors vector to the blockchain network kAt the same time, in order to differentiate the security of the PUF model, the second vector vector k After hashing with the security seed (confidential to the outside world), the first vector H is obtained. k By introducing a secure seed, malicious nodes can be prevented from using the leaked differentiated PUF model to reverse the original PUF model (for example, reverse the PUF module). k The challenge value C can be combined with the first vector H k The XOR result S k As the input of the differentiated PUF model, the verification response value R output by the differentiated PUF model is obtained k .
[0050] Based on the above description, the operation of the second blockchain node on the blockchain network can be discussed in two cases. In the first case, the target device that the second blockchain node needs to trade is a device that has been registered to the blockchain network by the first blockchain node. In this case, the target device PUF model corresponding to the target device is the device PUF model generated by the first blockchain node configuration, which is Figure 2 The composition results are the same as shown. Therefore, when the second blockchain node conducts a device transaction, it can send a verification node peer k Send a transaction request, first obtain the verification node peer k The corresponding second vector vector k , and the verification node peer k The challenge value C sent; secondly, the second vector vector k The first vector H generated by the hash module is obtained by inputting the security seed seed into the hash module. k ; Again, the first vector H k And the challenge value C is input into the XOR module to obtain the XOR result S generated by the XOR module k ; Finally, XOR the result S k Input the PUF module and get the target response value r output by the PUF module k In this case, the target response value r k With the verification node peer k The verification response value R obtained k should be roughly the same. Therefore, for each verification node peer k , the target device information can be verified.
[0051] In the second case, the target device that the second blockchain node needs to trade with is not the device that the first blockchain node has registered with the blockchain network, that is, the target device may be a fake device. The second blockchain node may use the differential PUF model leaked by the verification node to try to pass the verification of all verification nodes in the blockchain network. In this case, since the target device PUF model used by the second blockchain node is the differential PUF model leaked by the verification node, it is difficult to obtain the same PUF model as the verification node peer. k The corresponding second vector vector k , and the verification node peer k After sending the challenge value C, only the target response value that can be verified by the verification node corresponding to the differentiated model can be obtained.
[0052] As an example, suppose the validator peer 1 The differential PUF model is leaked, and the second blockchain node will verify the node peer 1 The corresponding differentiated PUF model is used as the target device PUF model. The second blockchain node can obtain the challenge value C and input the challenge value C into the target device PUF model. However, since the target device PUF model is essentially a verification node peer 1 The corresponding differentiated PUF model has built-in verification node peer 1 The corresponding first vector H 1 Therefore, the target response value R1 generated by the target device PUF model 1 Only through the verification node peer 1 Verification by peers is not possible in the blockchain network except for verification nodes. 1 Verification nodes other than peer 2 、peer 3 、……、peer n ) detection. In this way, even if a single verification node is leaked, the attacker cannot use the leaked information to make a fake device pass the verification of other verification nodes in the blockchain network except the leaked verification node, which can improve the reliability of device information verification in the blockchain network and the overall security of the blockchain network.
[0053] In the specific implementation, the verification node, the first blockchain node and the second blockchain node can all use Figure 6 The composition results shown or include Figure 6 Parts shown. Figure 6It is a structural diagram of a terminal device according to an embodiment of the present application. When the terminal device 6 has the function of the verification node described in the embodiment of the present application, the terminal device 6 can be a verification node or a chip or system on chip in the verification node; when the terminal device 6 has the function of the first blockchain node described in the embodiment of the present application, the terminal device 6 can be the first blockchain node or a chip or system on chip in the first blockchain node; when the terminal device 6 has the function of the second blockchain node described in the embodiment of the present application, the terminal device 6 can be the second blockchain node or a chip or system on chip in the second blockchain node.
[0054] In some embodiments, the verification node provided in the embodiments of the present application can be implemented in a software manner. For example, it can be installed on Figure 6 In the memory 61 of the terminal device 6 shown, the verification node can be software in the form of a program or plug-in, including: a receiving module 50, a sending module 51 and a verification module 52. These modules are logical, and thus can be arbitrarily combined or further split according to the functions implemented.
[0055] The functions of each module will be described below.
[0056] The device information verification method of the blockchain network provided in the embodiment of the present application will be explained in combination with the exemplary application architecture of the blockchain network provided in the embodiment of the present application.
[0057] The following will be combined Figure 3 For an explanation of the device information verification method of the blockchain network provided by an embodiment of the present application, please refer to Figure 3 , Figure 3 is a flowchart of a device information verification method for a blockchain network according to an embodiment of the present application, such as Figure 3 As shown, the method performs the following processing through the verification node of the blockchain network:
[0058] Step S301, receiving a differentiated PUF model sent by a first blockchain node.
[0059] In this embodiment, the first blockchain node may be a node used by the device manufacturer. The differentiated PUF model includes an XOR module and a PUF module. The XOR module is used to compare the input challenge value C and the first vector H. k Perform XOR operation to generate XOR result S k PUF module is used to XOR the result S based on the input k , generating the response value R k .
[0060] The PUF module can be constructed based on an arbiter PUF (APUF). APUF is a typical time-delay PUF circuit that uses timing differences in electronic circuits to generate a unique, non-replicable response.
[0061] In one embodiment, before step S301, the method further includes: performing the following steps by the first blockchain node:
[0062] Step 1: Send a registration request to all verification nodes of the blockchain network, wherein the registration request includes device information, manufacturer information, and a second vector corresponding to each verification node.
[0063] Step 2, in response to the verification pass information sent by the verification node, the second vector corresponding to the verification node is hashed with the preset security seed to obtain the first vector; and based on the first vector, the XOR module and the PUF module, a differentiated PUF model is generated; wherein, the verification pass information is the information sent to the first blockchain node after the verification node authenticates the first blockchain node based on the device information and the manufacturer information, and determines that the first blockchain node has passed the identity authentication.
[0064] Step 3: Send the differentiated PUF model corresponding to the verification node to the verification node.
[0065] In this embodiment, the first blockchain node needs to send the differentiated PUF model to each verification node in the blockchain network to complete the registration of the device, after which the device can flow from the device manufacturer corresponding to the first blockchain node to the market for trading.
[0066] First, the first blockchain node can submit a registration request to all verification nodes in the blockchain network. The registration request includes device information, manufacturer information, and peer information with each verification node. k The corresponding second vector vector k And other information.
[0067] Secondly, in response to the registration request submitted by the first blockchain node, the verification node can call the smart contract in the blockchain network to authenticate the device manufacturer corresponding to the first blockchain node based on the device information and manufacturer information to prevent malicious users from registering fake devices to the blockchain network. If the identity authentication of the first blockchain node is successful, the verification pass information is sent to the first blockchain node.
[0068] Again, the first blockchain node responds to the verification node peer k The verification information sent will verify the peer k The corresponding second vector vector kPerform hash operation with the preset security seed seed to obtain the first vector H k ; By putting the first vector H k A PUF model including an XOR module and a PUF module is built into the system to generate a differentiated PUF model.
[0069] Finally, the first blockchain node can send the generated differentiated PUF model to all verification nodes in the blockchain network. The first vector H built into each differentiated PUF model k Corresponding to the verification node peer that receives the differentiated PUF model k For example, the first blockchain node can store the first built-in vector H 1 The differentiated PUF model is sent to the verification node peer 1 .
[0070] Since the first blockchain node sends the verification node peer k The differentiated PUF model sent is also the same as the verification node peer k Unique correspondence. This ensures that the verification response values generated by each verification node are different. Even if a single verification node is leaked, attackers cannot use the leaked information to make a fake device pass the verification of all verification nodes, thereby improving the reliability of device information verification and the overall security of the blockchain network.
[0071] In one embodiment, the PUF module in the differentiated PUF model can be expressed as:
[0072] R=Θ(△)=Θ(ω0ψ0+...+ω n ψ n ) = Θ(〈ω, ψ〉);
[0073] Wherein, if Δ≥1, R=0, otherwise R=1. ω is a weight vector (depending on the process variation of a specific manufactured APUF); ψ is a parity vector, and the challenge value C includes a large set of values C0, C1, ..., C n .
[0074] Where ψn=1,
[0075] For verification node peer k , we can assume that τ k =(τ0 k , τ1 k , ..., τ n k ) is the XOR result S k =(S0 k , S1 k , ..., S nk ) derived from the parity vector, we can calculate τ i k (0≤i≤n-1) is as follows:
[0076]
[0077] Among them, τ n k =1, the first vector H k =(H0 k , H1 k , ..., H n k ). Then, the first blockchain node finally sends it to the verification node peer k The differentiated PUF model can be expressed as:
[0078]
[0079] in, Represents the weight vector of the differentiated PUF model.
[0080] Through the above H-MPUF model, the first blockchain node can send k Distribute differentiated PUF models PUF k Even if there is a certain verification node information leakage, due to the irreversibility of the calculation results, the attacker cannot use the differential PUF model PUF k , reverse the original PUF model (for example, reverse the PUF module) and the security seed seed. Therefore, the differentiated PUF model PUF belonging to other verification nodes k It cannot be cracked, thus overcoming the hidden danger of single-point leakage. At the same time, the conversion of the challenge value C will not spread the bit errors caused by the instability of PUF.
[0081] In one embodiment, before sending a registration request to all verification nodes of the blockchain network, the first blockchain node may also perform the following processing: generating a device PUF model for all devices that need to be registered to the blockchain network; wherein the device PUF model includes a hash module, an XOR module, and a PUF module; the hash module is used to perform a second vector vector k Perform hash operation with the security seed seed to generate the first vector H k ; XOR module is used to input the challenge value C and the first vector H k Perform XOR operation to generate XOR result S k PUF module is used to XOR the result S based on the input k , generating the response value r k .
[0082] Step S302: In response to a transaction request sent by the second blockchain node, a challenge value is sent to the second blockchain node, wherein the transaction request includes target device information.
[0083] In this embodiment, after step S302, the method further includes: performing the following steps by the second blockchain node:
[0084] Step 1: Obtain a second vector corresponding to the verification node.
[0085] Step 2: Input the second vector and the challenge value into the target device PUF model corresponding to the target device information to obtain a target response value output by the target device PUF model.
[0086] Step 3: Send the challenge value and target response value as a challenge response pair to the verification node.
[0087] In this embodiment, the operation of the second blockchain node on the blockchain network can be discussed in two cases. In the first case, the target device that the second blockchain node needs to trade is a device that has been registered to the blockchain network by the first blockchain node. In this case, the target device PUF model corresponding to the target device is the device PUF model generated by the first blockchain node configuration, which is Figure 2 The composition results are the same as shown. Therefore, when the second blockchain node conducts a device transaction, it can send a verification node peer k Send a transaction request, first obtain the verification node peer k The corresponding second vector vector k , and the verification node peer k The challenge value C sent; secondly, the second vector vector k The first vector H generated by the hash module is obtained by inputting the security seed seed into the hash module. k ; Again, the first vector H k And the challenge value C is input into the XOR module to obtain the XOR result S generated by the XOR module k ; Finally, XOR the result S k Input the PUF module and get the target response value r output by the PUF module k In this case, the target response value r k With the verification node peer k The verification response value R obtained k should be roughly the same. Therefore, for each verification node peer k , the target device information can be verified.
[0088] In the second case, the target device that the second blockchain node needs to trade with is not the device that the first blockchain node has registered with the blockchain network, that is, the target device may be a fake device. The second blockchain node may use the differential PUF model leaked by the verification node to try to pass the verification of all verification nodes in the blockchain network. In this case, since the target device PUF model used by the second blockchain node is the differential PUF model leaked by the verification node, it is difficult to obtain the same PUF model as the verification node peer. k The corresponding second vector vector k , and the verification node peer k After sending the challenge value C, only the target response value that can be verified by the verification node corresponding to the differentiated model can be obtained.
[0089] As an example, suppose the validator peer 1 The differential PUF model is leaked, and the second blockchain node will verify the node peer 1 The corresponding differentiated PUF model is used as the target device PUF model. The second blockchain node can obtain the challenge value C and input the challenge value C into the target device PUF model. However, since the target device PUF model is essentially a verification node peer 1 The corresponding differentiated PUF model has built-in verification node peer 1 The corresponding first vector H 1 Therefore, the target response value R1 generated by the target device PUF model 1 Only through the verification node peer 1 Verification by peers is not possible in the blockchain network except for verification nodes. 1 Verification nodes other than peer 2 、peer 3 、……、peer n ) detection. In this way, even if a single verification node is leaked, the attacker cannot use the leaked information to make a fake device pass the verification of other verification nodes in the blockchain network except the leaked verification node, which can improve the reliability of device information verification in the blockchain network and the overall security of the blockchain network.
[0090] Step S303, in response to the target response value sent by the second blockchain node, the challenge value and the first vector built into the differentiated PUF model are input into the differentiated PUF model to obtain a verification response value output by the differentiated PUF model; wherein each first vector corresponds to a verification node.
[0091] In this embodiment, the challenge value C and the first vector H built into the differentiated PUF model are kInput the differentiated PUF model and obtain the verification response value R output by the differentiated PUF model k The steps include:
[0092] Step 1: Combine the challenge value C and the first vector H k Input the XOR module and get the XOR result S output by the XOR module k .
[0093] Step 2: XOR the result S k Input the PUF module and get the verification response value R output by the PUF module k .
[0094] In this embodiment, the differentiated PUF model generated by the first blockchain node only includes the XOR module and the PUF module, but k The first vector H is built into the corresponding differentiated PUF model. k . Among them, the first vector H k It is based on the verification node peer k The corresponding second vector vector k and the security seed seed by hashing. Since each second vector vector k The corresponding verification node peer k is unique, therefore, each first vector H k The corresponding verification node peer k It is also unique. In turn, the first blockchain node sends a verification node peer k The differentiated PUF model sent is also the same as the verification node peer k Unique correspondence. This ensures that the verification response values generated by each verification node are different. Even if a single verification node is leaked, attackers cannot use the leaked information to make a fake device pass the verification of all verification nodes, thereby improving the reliability of device information verification and the overall security of the blockchain network.
[0095] In this embodiment, the first blockchain node can be each verification node peer k Distribute the only corresponding second vector vector k (For example, vector 1 The only corresponding peer 1 ), and can publish all second vectors vector to the blockchain network k At the same time, in order to differentiate the security of the PUF model, the second vector vector k After hashing with the security seed (confidential to the outside world), the first vector H is obtained. kBy introducing a secure seed, malicious nodes can be prevented from using the leaked differentiated PUF model to reverse the original PUF model (for example, reverse the PUF module). k The challenge value C can be combined with the first vector H k The XOR result S k As the input of the differentiated PUF model, the verification response value R output by the differentiated PUF model is obtained k .
[0096] Step S304: when the similarity between the target response value and the verification response value is greater than a preset threshold, it is determined that the target device information has passed the verification.
[0097] In this embodiment, step S304 may include the following steps:
[0098] Step 1: compare the target response value with the verification response value bit by bit.
[0099] Step 2: When the number of identical bits between the target response value and the verification response value is greater than a preset threshold, it is determined that the target device information passes the verification.
[0100] For example, the preset threshold may be 90% of the total number of target response values or verification response values.
[0101] In this embodiment, after step S304, the method further includes: uploading and broadcasting the target device information and the verification result corresponding to the target device information to the blockchain network, and sending the verification result to the second blockchain node.
[0102] The blockchain network can collect the verification results of all verification nodes on the target device information, and determine whether the target device information is credible based on the ratio of passed and failed verification in the verification results.
[0103] The following will be combined Figure 4 For an explanation of the information interaction between the verification node and the first blockchain node and the second blockchain node provided in the embodiment of the present application, see Figure 4 , Figure 4 is a flow chart of a transaction processing method of a blockchain network according to another embodiment of the present application, such as Figure 4 As shown: The method includes:
[0104] S401, the first blockchain node sends a verification node peer k Send a registration request.
[0105] The registration request may include device information, manufacturer information, and verification node peer information. k The corresponding second vector vector k .
[0106] S402, verify the peer k A first smart contract in the blockchain network is called to authenticate the first blockchain node based on the device information and the manufacturer information.
[0107] In this embodiment, the first smart contract can be a smart contract for identity authentication. By authenticating the device manufacturer corresponding to the first blockchain node, malicious users can be prevented from registering false devices to the blockchain network. If the identity authentication of the first blockchain node is passed, the verification node peer k Verification pass information can be sent to the first blockchain node.
[0108] S403, verify the peer k Send verification pass information to the first blockchain node.
[0109] S404, the first blockchain node is based on the second vector vector k , generate and verify peer nodes k Corresponding differentiated PUF model PUF k .
[0110] S405, the first blockchain node sends a verification node peer k Send differentiated PUF model PUF k .
[0111] In this embodiment, after receiving the verification pass information, the first blockchain node can send a message to the verification node peer through a secure channel in a P2P manner. k Send the corresponding differentiated PUF model PUF k .
[0112] The above steps S401 to S405 introduce the process of the first blockchain node registering the device to the blockchain network. The transaction process of the device will be described below.
[0113] S406, the second blockchain node sends a request to the verification node peer k Send a transaction request.
[0114] The transaction request includes target device information.
[0115] In this embodiment, during the transaction phase, the verification node peer k The differentiated PUF model obtained during the enrollment phase can be used k , to verify the authenticity of the seller’s (i.e., the second blockchain node) device (corresponding to the target device information).
[0116] The second blockchain node, as the device seller, needs to verify the peer node before conducting a transaction. k Send a transaction request containing the target device information for device verification; the transaction request will be sent to all verification nodes in the blockchain network.
[0117] S407, verify the peer k Call the second smart contract in the blockchain network to generate a challenge value C.
[0118] In this embodiment, the second smart contract can be a smart contract for device verification. The contract data domain of the smart contract can include: the address of the current device owner, device information, product manufacturer, and historical owner; and also needs to include a function Get_Challenge() for generating a challenge value, a function Get_Response() for generating a verification response value, and a verification function Verify().
[0119] Among them, the verification node peer k The challenge value generation function Get_Challenge() in the second smart contract can be called to generate the challenge value C.
[0120] S408, verify the peer k Send the challenge value C to the second blockchain node.
[0121] S409, the second blockchain node obtains and verifies the peer node k The corresponding second vector vector k , the second vector vector k The target device PUF model corresponding to the target device information is input with the challenge value C to obtain the target response value r k .
[0122] S410, the challenge value C and the target response value r k As a challenge response pair (C, r k ) is sent to the verification node peer k .
[0123] S411, verification node peer k Call the second smart contract in the blockchain network, using the differentiated PUF model PUF k Generate verification response value R k .
[0124] In this embodiment, the verification node peer k You can call the Get_Response() function in the second smart contract to generate the verification response value, using the differentiated PUF model PUF k Generate verification response value Rk .
[0125] S412, verification node peer k Call the second smart contract in the blockchain network and compare and verify the response value R k and the target response value r k The similarity.
[0126] In this embodiment, the verification node peer k You can call the verification function Verify() in the second smart contract to compare the verification response value R k and the target response value r k For example, the verification function Verify() can compare the target response value with the verification response value bit by bit; if the number of identical bits between the target response value and the verification response value is greater than a preset threshold, it is determined that the target device information has passed the verification. The preset threshold may be 90% of the total number of bits of the target response value or the verification response value.
[0127] S413, verification node peer k Send the verification result to the second blockchain node.
[0128] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0129] Corresponding to the device information verification method of the blockchain network described in the above embodiment, Figure 5 A schematic diagram of the structure of a verification node according to an embodiment of the present application is shown. For ease of explanation, only the parts related to the embodiment of the present application are shown.
[0130] See also Figure 5 The verification node 5 includes: a receiving module 50, which is used to receive the differentiated PUF model sent by the first blockchain node; a sending module 51, which is used to send the challenge value to the second blockchain node in response to the transaction request sent by the second blockchain node, wherein the transaction request includes the target device information; a calculation module 52, which is used to respond to the target response value sent by the second blockchain node, input the challenge value and the first vector built into the differentiated PUF model into the differentiated PUF model, and obtain the verification response value output by the differentiated PUF model; wherein each first vector corresponds to a verification node; a verification module 53, which is used to determine that the target device information has passed the verification when the similarity between the target response value and the verification response value is greater than a preset threshold.
[0131] In one embodiment, the differentiated PUF model includes an XOR module and a PUF module;
[0132] In one embodiment, the calculation module 52 is further used to input the challenge value and the first vector into the XOR module to obtain the XOR result output by the XOR module; input the XOR result into the PUF module to obtain the verification response value output by the PUF module.
[0133] In one embodiment, a first blockchain node in a blockchain network is used to perform the following processing: sending a registration request to all verification nodes of the blockchain network, wherein the registration request includes device information, manufacturer information, and a second vector corresponding to each verification node; in response to verification pass information sent by the verification node, performing a hash operation on the second vector corresponding to the verification node and a preset security seed to obtain a first vector; and generating a differentiated PUF model based on the first vector, an XOR module, and a PUF module; wherein the verification pass information is information sent to the first blockchain node after the verification node authenticates the identity of the first blockchain node based on the device information and the manufacturer information, and determines that the first blockchain node passes the identity authentication; and sending the differentiated PUF model corresponding to the verification node to the verification node.
[0134] In one embodiment, the first blockchain node in the blockchain network is further used to perform the following processing: generating a device PUF model for all devices that need to be registered to the blockchain network; wherein the device PUF model includes a hash module, an XOR module and a PUF module; the hash module is used to perform a hash operation on the input second vector and the security seed to generate a first vector; the XOR module is used to perform an XOR operation on the input challenge value and the first vector to generate an XOR result; the PUF module is used to generate a response value based on the input XOR result.
[0135] In one embodiment, the second blockchain node in the blockchain network is also used to perform the following processing: obtain a second vector corresponding to the verification node; input the second vector and the challenge value into the target device PUF model corresponding to the target device information to obtain the target response value output by the target device PUF model; send the challenge value and the target response value as a challenge-response pair to the verification node.
[0136] In one embodiment, the verification node 5 also includes a broadcast module for uploading and broadcasting the target device information and the verification result corresponding to the target device information to the blockchain network, and sending the verification result to the second blockchain node.
[0137] In one embodiment, the verification module 53 is further used to compare the target response value with the verification response value bit by bit; when the number of identical bits between the target response value and the verification response value is greater than a preset threshold, it is determined that the target device information has passed the verification.
[0138] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0139] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0140] Figure 6 is a schematic diagram of the structure of a terminal device according to an embodiment of the present application. Figure 6 As shown, the terminal device 6 includes: at least one processor 60 ( Figure 6 (Only one is shown in the figure) a processor, a memory 61, and a computer program 62 stored in the memory 61 and executable on at least one processor 60. When the processor 60 executes the computer program 62, the steps in the device information verification method embodiment of any of the above-mentioned blockchain networks are implemented.
[0141] The terminal device 6 may be a computing device such as a desktop computer, a notebook, a PDA, or a cloud server. The terminal device 6 may include but is not limited to a processor 60 and a memory 61. It is understood by those skilled in the art that Figure 6 It is only an example of the terminal device 6 and does not constitute a limitation on the terminal device 6. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, it may also include input and output devices, network access devices, etc.
[0142] The processor 60 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0143] In some embodiments, the memory 61 may be an internal storage unit of the terminal device 6, such as a hard disk or memory of the terminal device 6. In other embodiments, the memory 61 may also be an external storage device of the terminal device 6, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the terminal device 6. In other embodiments, the memory 61 may also include both an internal storage unit and an external storage device of the terminal device 6. The memory 61 is used to store an operating system, an application program, a boot loader (BootLoader), data, and other programs, such as program codes of a computer program 62. The memory 61 may also be used to temporarily store data that has been output or is to be output.
[0144] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it can implement the steps in the device information verification method embodiments of the above-mentioned various blockchain networks.
[0145] An embodiment of the present application provides a computer program product. When the computer program product is run on a mobile terminal, the mobile terminal implements the steps in the device information verification method embodiments of the above-mentioned various blockchain networks when executing the computer program product.
[0146] The present application implements all or part of the processes in the above-mentioned embodiment method, and can instruct the relevant hardware to complete through a computer program, and the computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device capable of carrying the computer program code to the terminal device, a recording medium, a computer memory, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), an electric carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disk.
[0147] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0148] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0149] In the embodiments provided in the present application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are only schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0150] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0151] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A device information verification method for a blockchain network, characterized in that: include: The following processing is performed by the verification nodes of the blockchain network: Receiving a differentiated PUF model sent by the first blockchain node; In response to a transaction request sent by a second blockchain node, sending a challenge value to the second blockchain node, wherein the transaction request includes target device information; In response to the target response value sent by the second blockchain node, the challenge value and the first vector built into the differentiated PUF model are input into the differentiated PUF model to obtain a verification response value output by the differentiated PUF model; wherein each of the first vectors corresponds to one of the verification nodes; When the similarity between the target response value and the verification response value is greater than a preset threshold, it is determined that the target device information passes the verification.
2. The method according to claim 1, characterized in that The differentiated PUF model includes an XOR module and a PUF module; the challenge value and the first vector built into the differentiated PUF model are input into the differentiated PUF model, and the verification response value output by the differentiated PUF model is obtained, including: Inputting the challenge value and the first vector into the XOR module to obtain an XOR result output by the XOR module; The XOR result is input into the PUF module to obtain the verification response value output by the PUF module.
3. The method according to claim 2, characterized in that Before receiving the differentiated PUF model sent by the first blockchain node, the method further includes: The following processing is performed by the first blockchain node: Sending a registration request to all verification nodes of the blockchain network, wherein the registration request includes device information, manufacturer information, and a second vector corresponding to each verification node; In response to the verification pass information sent by the verification node, the second vector corresponding to the verification node is hashed with a preset security seed to obtain the first vector; and based on the first vector, the XOR module and the PUF module, the differentiated PUF model is generated; wherein the verification pass information is information sent to the first blockchain node after the verification node authenticates the first blockchain node based on the device information and the manufacturer information and determines that the first blockchain node has passed the identity authentication; The differentiated PUF model corresponding to the verification node is sent to the verification node.
4. The method according to any one of claims 3, characterized in that Before sending the registration request to all verification nodes of the blockchain network, the method further includes: The following processing is performed by the first blockchain node: Generate a device PUF model for all devices that need to be registered to the blockchain network; wherein the device PUF model includes a hash module, the XOR module and the PUF module; the hash module is used to perform a hash operation on the input second vector and the security seed to generate the first vector; the XOR module is used to perform an XOR operation on the input challenge value and the first vector to generate an XOR result; the PUF module is used to generate a response value based on the input XOR result.
5. The method according to claim 4, characterized in that After sending the challenge value to the second blockchain node in response to the transaction request sent by the second blockchain node, the method further includes: The following processing is performed by the second blockchain node: Obtaining the second vector corresponding to the verification node; Inputting the second vector and the challenge value into a target device PUF model corresponding to the target device information to obtain the target response value output by the target device PUF model; The challenge value and the target response value are sent to the verification node as a challenge response pair.
6. The method according to any one of claims 1 to 5, characterized in that When the similarity between the target response value and the verification response value is greater than a preset threshold, after determining that the target device information passes the verification, the method further includes: The target device information and the verification result corresponding to the target device information are uploaded and broadcasted to the blockchain network, and the verification result is sent to the second blockchain node.
7. The method according to any one of claims 1 to 5, characterized in that When the similarity between the target response value and the verification response value is greater than a preset threshold, determining that the target device information passes the verification includes: Comparing the target response value with the verification response value bit by bit; When the number of identical bits between the target response value and the verification response value is greater than the preset threshold, it is determined that the target device information passes the verification.
8. A verification node, characterized in that: include: A receiving module, used to receive a differentiated PUF model sent by the first blockchain node; A sending module, configured to send a challenge value to the second blockchain node in response to a transaction request sent by the second blockchain node, wherein the transaction request includes target device information; A calculation module, configured to input the challenge value and the first vector built into the differentiated PUF model into the differentiated PUF model in response to the target response value sent by the second blockchain node, to obtain a verification response value output by the differentiated PUF model; wherein each of the first vectors corresponds to one of the verification nodes; The verification module is used to determine that the target device information has passed the verification when the similarity between the target response value and the verification response value is greater than a preset threshold.
9. A terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the device information verification method of the blockchain network as described in any one of claims 1 to 7 is implemented.
10. A computer program product, characterized in that It includes a computer program, which, when executed, enables the device information verification method of the blockchain network as described in any one of claims 1 to 7 to be executed.