Method for generating block chain intelligent contract semantic graph
Through the smart contract semantic graph generation method based on semantic rules, the limitations of existing data flow analysis technology in smart contract analysis are solved. The generated semantic graph can more comprehensively analyze the execution process of smart contracts, discover potential vulnerabilities, and improve the security and reliability of smart contracts.
Patent Information
- Application Number
- CN202510065052.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-15
AI Technical Summary
The existing data flow analysis technology is limited by the control flow and data flow information in the analysis of smart contracts, making it difficult to fully understand the execution process and potential vulnerabilities of the smart contract, and errors in the compilation process may lead to incorrect analysis results.
A smart contract semantic graph generation method based on semantic rules is adopted. By defining the syntax and semantics of the smart contract, a semantic interpreter and semantic validator are generated. Combining user-defined security attributes and function call sequences, a semantic graph of the smart contract is generated, including contract semantics, semantic control flow, semantic data flow and verification constraint information.
The generated semantic graph can more comprehensively characterize the execution details and program characteristics of smart contracts. Through analysis of symbol execution and vulnerability detection, it discovers problems that are ignored in traditional software testing, improving the security and reliability of smart contracts.
Smart Images

Figure CN119990293A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and in particular to a method for generating a blockchain smart contract semantic graph. Background Art
[0002] Blockchain is a distributed database technology that stores data in the form of blocks and uses cryptographic methods to ensure the security and integrity of data. Smart contracts are automatically executed and tamper-proof programs on the blockchain. They rely on the distributed ledger of blockchain technology to ensure the transparency of contract terms. However, once a smart contract has a loophole, the execution process may cause significant economic losses and be difficult to repair. There are now many ways to verify smart contracts, such as formal verification, static analysis technology, dynamic analysis technology, data flow analysis technology, etc.
[0003] Data flow analysis technology is a commonly used technical means in compilation optimization and vulnerability detection. It is used to obtain information during program execution and analyze it. In data flow analysis, the following graphs can be analyzed: Control flow graph is an abstract representation of the program execution process, which can show all the paths that a program will traverse during execution. Control flow graph can be generated based on the information in the compilation process and used for compiler optimization and analysis. Data flow graph represents the change process of data from the perspective of data transmission and processing. Function call graph is a graphical representation of the relationship between different function calls in a program, showing how functions in the program interact with each other. It is usually divided into static call graph and dynamic call graph. Static call graph is based on the source code of the program to build the calling relationship of functions in the program, without considering the actual execution of the program. Dynamic call graph is a control flow representation of function calls when the program is executed, which can show the function call relationship during the execution of the program. Program dependency graph is a directed graph that represents the control and data dependency relationship between program statements. Nodes represent program statements, and edges represent the dependencies between program statements, including control dependencies (such as conditional statements) and data dependencies (such as variable assignments). However, these graphs are generated by different analysis, execution, and compilation methods, and the information is scattered, making it difficult to cross-validate. The semantic graph is generated based on the execution of semantic rules. The semantic rules are defined in a fine-grained manner, and can scalably display the information generated and required in program execution, compilation, and analysis from a semantic level. Combined with symbolic execution technology, the state parameters that need to be tracked in the function call sequence are symbolized, and all possible paths of program semantic execution are explored, which can discover problems that are ignored in traditional software testing.
[0004] Formal semantics can be divided into operational semantics (based on the implementation of the programming language), axiomatic semantics (based on logic and proof) and denotational semantics (based on mathematical objects and functions), etc. It is the basis of formal verification and program development, which helps developers understand the programming of the program, and verifiers abstract the program and establish a formal model. In operational semantics, the program is usually described as a state transition system, and the program is executed through a series of operational definitions. The present invention defines the formal semantics of the smart contract language based on operational semantics, so that the smart contract written in the language can be automatically executed through the rewrite rules defined by operational semantics, and the semantic graph generation method of the present invention is used to generate the semantic graph of the smart contract.
[0005] The analysis results of existing data flow analysis technology are limited to the information in the control flow and data flow. The program is compiled and executed in a specified compiler and execution environment to obtain this information. This process requires additional data extraction and analysis methods. If there are errors in the compilation process itself, the results are usually incorrect. In addition, the amount of data in the compilation process is limited, and there is insufficient information that can be analyzed.
[0006] The present invention designs a method for generating a semantic graph of a smart contract based on semantic rules. First, the syntax BNF (Backus-Naur Form) and semantic rules of the smart contract are defined, so that the smart contract can be executed under the rules of the semantic system. Then, a semantic interpreter and a semantic verifier generated by the semantic rules are used to generate a semantic graph. From the data flow and control flow information of the semantic graph, fine-grained function calls, program dependencies, and state transition relationships are analyzed. This semantic rule-driven semantic graph can depict more program features and execution details, and can further enrich the information of the semantic graph by combining user-defined security attributes and function call sequences. Summary of the invention
[0007] A method for generating a blockchain smart contract semantic graph, comprising:
[0008] Define syntax and semantics according to the smart contract specification, where syntax is defined in Backus-Naur Form (BNF) and semantics is defined in the form of rules that conform to the rewriting logic;
[0009] Compile the written smart contract semantic set to generate a semantic interpreter and a semantic verifier;
[0010] Receive user input for the smart contract program, which includes user-defined security attributes and function call sequences;
[0011] Input the smart contract program into the generated semantic interpreter, generate a program execution state sequence, extract the i-th step and the j-th step in the execution state sequence as the state change in the attribute specification according to the verification attribute, input the symbolic constraint conditions to form the attribute specification, and input the attribute specification into the semantic verifier;
[0012] The semantic verifier performs path exploration according to the rewriting rules and simplification rules to generate a smart contract semantic graph, which contains contract semantics, semantic control flow, semantic data flow, and verification constraint information;
[0013] Performing semantic graph analysis according to the semantic graph, wherein the semantic graph analysis includes any one of symbolic execution and vulnerability detection;
[0014] Based on the results, the smart contract is iteratively optimized until the generated semantic graph meets the verification constraint requirements.
[0015] Preferably, the step of inputting the smart contract program into a generated semantic interpreter to generate a program execution state sequence includes:
[0016] The user enters the smart contract information. If the initialization information is related to the verification attributes, the user needs to customize the initialization information at the same time. If it is not related, the default initialization information is used, including blockchain information and customized security attributes;
[0017] Create a new contract instance, use the contract instance to call the function in the smart contract, determine the calling relationship of the contract function, obtain the function calling sequence, parse the initialization information, and establish the contract storage stack, which is divided into the user account and contract information storage area;
[0018] According to the pre-defined semantic rules, the smart contract is executed according to the rewritten logic to obtain the constraints, execution state sequence and storage slot dynamic information of the smart contract, and the dynamic information updates the data of the storage stack.
[0019] Preferably, the semantic verifier performs path exploration according to the rewriting rules and the simplification rules to generate a smart contract semantic graph, including:
[0020] Convert the smart contract code according to BNF syntax, input the contract, function call sequence, initial account information, constraint information, etc., and convert and reason according to the call rules and state transition rules defined based on the rewriting logic;
[0021] The entire reasoning process is numbered through the reasoning depth array, and each step generates a collection in the form of a Cell, which contains the smart contract information, function information, storage slot information, and execution engine;
[0022] Based on the inference depth array, a series of state sets are obtained, and the initial state that needs to be explored is extracted through branch nodes or suspected problematic states. i and final state j , and then according to the templates and rules in the reachability assertion generator, the Statei and State j Perform item-by-item state alignment and generate reachability assertions based on rewriting logic;
[0023] In the reachability proof system, different state information corresponding to the reachability assertion is extracted, the final state is used as the leaf node of the path exploration, the initial state is used as the root node, the tree-like execution path is explored, and a semantic graph is generated through the semantic verifier.
[0024] Preferably, the extraction of the initial state State to be explored i and final state j , including: If the total number of states is small, directly use State0 and State n As the start and end state.
[0025] Preferably, after generating the semantic graph, the method further includes:
[0026] Based on the results, symbolic execution is performed to symbolize part of the call information to iteratively generate more execution paths and capture potential vulnerability information.
[0027] Preferably, the creation of a new contract instance, using the contract instance to call the function in the smart contract, determining the calling relationship of the contract function, obtaining the function calling sequence, parsing the initialization information, establishing the contract storage stack, and dividing it into user account and contract information storage areas specifically include:
[0028] Create a new contract instance, use the contract instance to call the function in the smart contract, determine the calling relationship of the contract function, obtain the function calling sequence, establish and initialize the contract storage stack, which is divided into user account and contract information storage areas, each area contains multiple storage slots;
[0029] User accounts are external accounts, applied for on the blockchain in the form of the user's public key;
[0030] The contract information storage area is used to store contract account information, variable status information, and caller information;
[0031] The caller can be a user account or a smart contract account. The contract account can be represented as:
[0032] contract(index:Int,CN:ContractName)
[0033] When a contract call occurs, an account switch will be performed:
[0034]
[0035] User accounts are of the form:
[0036] <msgsender>contractInstance∷=[addr1,addr2,…]
[0037] After the contract is called by an external account, the external account is stored in the caller's storage slot:
[0038]
[0039] Preferably, the constraint conditions may be user-defined, or general security attribute rules may be defined in advance as a constraint condition library and automatically called;
[0040] The execution state sequence represents the calling logic, calling order and relationship of the function;
[0041] The storage slot is used to store variables, functions, and contract data in the execution of smart contracts. This information changes dynamically during the execution process.
[0042] Preferably, the execution engine includes a call stack, an external account, callTrack, and callState, wherein the call stack includes caller information and a storage slot used during the call, the external account is user account information inserted in advance, callTrack indicates the order in which function calls are executed, and callState indicates information about the called function.
[0043] Preferably, the reachability assertion generator includes templates and generation rules required for assertion generation, i and State j Perform item-by-item state alignment and generate a reachability assertion form based on the rewriting logic:
[0044] <cellname>VariableState m ∈State i =>VariableState n ∈State j < / cellname> .
[0045] The semantic graph is a tree structure consisting of nodes and directed edges:
[0046] SemanticGraph=<Node,Edge>
[0047] The node set includes each state on the execution path, which is related to the defined rules, and each state transition corresponds to a rule:
[0048] Node i = <FromEdgeIndex i ,State i ,Rule i ,ToEdgeIndex i >
[0049] The node corresponds to the starting state of the branch, pointing to the set of multiple outgoing edges, which is:
[0050] BranchNode i = <FromEdgeIndex i ,State i ,rule i ,ToEdgeSet i >. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Hereinafter, some specific embodiments of the present invention will be described in detail in an exemplary and non-limiting manner with reference to the accompanying drawings. The same reference numerals in the accompanying drawings indicate the same or similar components or parts. It should be understood by those skilled in the art that these drawings are not necessarily drawn to scale. The objects and features of the present invention will become more apparent in view of the following description in conjunction with the accompanying drawings, in which:
[0052] Figure 1 This is an architectural diagram of the method for generating the semantic graph of blockchain smart contracts.
[0053] Figure 2 Generate and store the execution state sequence of smart contracts.
[0054] Figure 3 Generate process flow chart for semantic graph. DETAILED DESCRIPTION
[0055] The purpose of the present invention is to provide a method for generating a semantic graph of a blockchain smart contract, construct a smart contract semantic set, including syntax and semantics defined for the smart contract specification, wherein the syntax is defined in Backus-Naur Form (BNF), and the semantics is defined in the form of rules that conform to the rewriting logic. A semantic interpreter and a semantic verifier are generated through the above-mentioned syntax and semantics, and the semantic interpreter can automatically obtain the state sequence of the smart contract execution process, and the semantic verifier can generate a smart contract semantic graph through a path exploration method.
[0056] The specific implementation of the present invention is further described in detail below in conjunction with the accompanying drawings and examples. The following examples are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0057] See also Figure 1 On the one hand, the present invention provides a method for generating a blockchain smart contract semantic graph, and the overall architecture is as follows:
[0058] Define syntax and semantics according to the smart contract specification, where syntax is defined in Backus-Naur Form (BNF) and semantics is defined in the form of rules that conform to the rewriting logic;
[0059] Compile the written smart contract semantic set to generate a semantic interpreter and a semantic verifier;
[0060] The user inputs the smart contract program, which includes user-defined security properties and function call sequences;
[0061] Input the smart contract program into the generated semantic interpreter to generate the program execution state sequence. The user extracts the i-th and j-th steps in the execution state sequence as the state changes in the attribute specification based on the verification attribute, and then inputs the symbolic constraint conditions to form the attribute specification, which is input into the semantic verifier.
[0062] The semantic validator performs path exploration based on rewriting rules and simplification rules to obtain a smart contract semantic graph, which contains contract semantics, semantic control flow, semantic data flow, verification constraint information, etc.
[0063] Based on the generated semantic graph, symbolic execution, vulnerability detection and other semantic graph analysis can be performed;
[0064] Based on the results, the smart contract is iteratively optimized until the generated semantic graph meets the verification constraint requirements.
[0065] See also Figure 2 , which is a smart contract execution state sequence generation process and storage mechanism, which is specifically described as follows: the user needs to input the smart contract information (as shown in ① in the figure). If the initialization information is related to the verification attribute, the user also needs to customize the initialization information. If it is not related, the default initialization information can be used, including blockchain information and customized security attributes; create a new contract instance, use the contract instance to call the function in the smart contract, determine the calling relationship of the contract function, obtain the function call sequence, and parse the initialization information at the same time, establish the contract storage stack, which is divided into user account and contract information storage area (as shown in ② in the figure); according to the pre-defined semantic rules, execute the smart contract according to the rewrite logic (as shown in ③ in the figure), obtain the constraints of the smart contract, the execution state sequence and the dynamic information of the storage slot, and update the data of the storage stack according to this information.
[0066] See also Figure 3 , the generation process of the semantic graph of the smart contract code is described as follows: First, the smart contract code is converted according to the BNF syntax to ensure that it complies with the syntax specification. At the same time, the contract, function call sequence, initial account information, constraint information, etc. are input, and the conversion and reasoning are performed according to the call rules and state transition rules defined based on the rewriting logic; then, the entire reasoning process is numbered through the Depth array, and each step generates a collection in the form of Cell, which contains the smart contract information, function information, storage slot information (including variables and storage information), execution engine and other information.
[0067] Get a series of State sets based on the Depth array, and then extract the initial state that needs to be explored through branch nodes or suspected problematic states i and final state j If the total number of states is small, you can also directly use State0 and State n As the start and end state. Then according to the template and rules in the reachability assertion generator, the State i and State j Perform item-by-item state alignment and generate reachability assertions based on rewrite logic.
[0068] Finally, in the reachability proof system, different state information corresponding to the reachability assertion is extracted, the final state is used as the leaf node of the path exploration, the initial state is used as the root node, the tree-like execution path is explored, and a semantic graph is generated through the semantic verifier.
[0069] Based on the results, symbolic execution can be performed to symbolize part of the call information to iteratively generate more execution paths to capture potential vulnerability information.
[0070] in:
[0071] (1) The specific method for generating the smart contract execution state sequence is as follows:
[0072] Using Storage Slots <cell>The form defines the information involved in smart contract execution and function calls. This form can be nested to form a collection of Cells, for example:
[0073] <cell1>
[0074] <cell2>
[0075] < / cell2>
[0076] < / cell1>
[0077] Smart contract execution state sequence generation and storage mechanism Figure 2 As shown:
[0078] In the first step, the user needs to enter at least the smart contract, and other information can be entered optionally, such as blockchain information and custom security attributes;
[0079] Allow users to define the calling sequence of contracts or functions, and traverse all public functions for calling by default;
[0080] The second step is to create a new contract instance, use the contract instance to call the function in the smart contract, determine the calling relationship of the contract function, obtain the function calling sequence, establish and initialize the contract storage stack, which is divided into user account and contract information storage areas, each area contains multiple storage slots;
[0081] User accounts are external accounts, applied for on the blockchain in the form of the user's public key;
[0082] The contract information storage area is used to store contract account information (the smart contract account is stored in this area), variable status information, and caller information;
[0083] The caller can be a user account or a smart contract account. Using different calling methods, the caller sometimes differs according to the code specifications of the smart contract. This is the key information that needs to be paid attention to when developing smart contracts. The contract account can be expressed as:
[0084] contract(index:Int,CN:ContractName)
[0085] When a contract call occurs, an account switch will be performed:
[0086]
[0087] User accounts are of the form:
[0088] <msgsender> contractInstance ∷=[addr1,addr2,…]
[0089] After the contract is called by an external account, the external account will be stored in the caller's storage slot:
[0090]
[0091] The third step is to execute the smart contract according to the rewritten logic according to the pre-defined semantic rules in the subsequent execution process to obtain the constraints, execution state sequence and storage slot dynamic information of the smart contract. Constraints, execution state sequence and storage slot dynamic information may dynamically affect the value of the storage stack;
[0092] The constraints can be user-defined, or general security attribute rules can be defined in advance in the form of a constraint library and automatically called;
[0093] The execution state sequence represents the calling logic, calling order and relationship of the function;
[0094] Storage slots are used to store variables, functions, and contract data in smart contract execution. This information changes dynamically during the execution process.
[0095] (2) The specific method for generating the smart contract semantic graph is as follows:
[0096] The smart contract is converted according to the syntax defined by BNF, and the contract, function calling sequence, initial account information, and constraint information are input at the same time. The conversion and reasoning are based on the calling rules and state transition rules defined by the rewriting logic. The entire reasoning process is numbered through the Depth array, and each step generates a set of Cell-form collections, such as smart contract information, function information, storage slot information (including variables and storage information), and execution engine.
[0097] The execution engine includes call stack, external account, callTrack, and callState. The call stack includes caller information and storage slots required for calling. External account is user account information placed in advance. callTrack indicates the order of function call execution. callState indicates the information of the called function, such as variable value, storage location, storage type, call order Depth, call type, and error information. The execution engine can fully reflect the semantic details of the contract call process and can supplement the definition of the data that needs to be recorded. All data recording processes meet the call rules and state transition rules, so as to meet the discovery and verification of scalable new vulnerabilities.
[0098] Get a series of State sets based on the execution order array Depth, and extract the initial state that needs to be explored through the branch nodes or suspected problematic states i and final state j If the total number of states is small, you can also directly use 0 and n as the start and end states. This selection method is related to the time required for subsequent verification execution.
[0099] The reachability assertion generator includes the templates and generation rules required for assertion generation. i and State j Perform item-by-item state alignment and generate a reachability assertion form based on the rewriting logic:
[0100] <cellname>VariableState m ∈State i =>VariableState n ∈State j < / cellname>
[0101] In the reachability proof system, different state information corresponding to the reachability assertion is extracted, the final state information is used as the leaf node of the path exploration, and the initial state is used as the root node to explore the tree-like execution path. Semantics The validator generates a semantic graph, which is usually a tree structure consisting of nodes and directed edges:
[0102] SemanticGraph=<Node,Edge>
[0103] The node set includes each state on the execution path, which is related to the defined rules, and each state transition corresponds to a rule:
[0104] Node i = <FromEdgeIndex i ,State i ,Rule i ,ToEdgeIndex i >
[0105] Some nodes correspond to the starting state of the branch, pointing to the set of multiple outgoing edges, then:
[0106] BranchNode i = <FromEdgeIndex i ,State i ,rule i ,ToEdgeSet i >
[0107] From the semantic tree, you can see the execution semantic rules, variable status, contract status, called functions, executed smart contract code, rules to be executed, execution steps, function call times, storage stack information corresponding to each node state, and support tracking based on semantic graph variables set for vulnerabilities, which has strong scalability. Based on the results, symbolic execution can be performed to symbolize part of the call information, thereby iterating the generation process of the semantic graph, obtaining more execution paths, and capturing possible vulnerability information.
[0108] Beneficial effects of the present invention:
[0109] (1) A smart contract semantic graph is proposed. This graph can show function call relationships, data dependencies, simulate user call sequences, and distinguish caller information. It has the characteristics of symbolic execution and semantic execution, reflecting the execution process of the formal semantics of the program under given rules, as well as the constraint properties described by symbols. It can affect the information and generation process of the graph through semantic definition, thereby achieving the goal of fine-grained and scalable display of smart contract execution characteristics and information. The semantic graph integrates the information of the control flow graph, data flow graph, function call graph, and program dependency graph, and comprehensively reflects the program execution process.
[0110] (2) A semantic graph generation process is proposed, including the semantic rule-driven Cell set generation, reachability assertion generation, reachability assertion proof, and semantic graph generation. This method establishes a formal semantic execution and verification system for smart contracts through semantic rules based on rewriting logic, which allows smart contracts to break away from the traditional compilation and execution environment and reflect the original execution process from a semantic perspective. However, data analysis rules are added. This process can accelerate the semantic graph generation process by selecting different start and end states and optimizing path exploration methods. Different syntax parsing rules can realize semantic graphs of different languages. It is scalable and suitable for semantic graph generation of multi-language interactions and calls.
[0111] In the above embodiments, all or part of the functions can be implemented by software, hardware, or a combination of software and hardware. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or a data center that includes one or more available media integrations. The available medium can be a magnetic medium, (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state disk (SSD)), etc.
[0112] The above is only a specific implementation of the embodiment of the present application, but the protection scope of the embodiment of the present application is not limited thereto, and any changes or replacements within the technical scope disclosed in the embodiment of the present application should be included in the protection scope of the embodiment of the present application. Therefore, the protection scope of the embodiment of the present application should be based on the protection scope of the claims.< / msgsender> < / cell> < / msgsender>
Claims
1. A method for generating a semantic graph of a blockchain smart contract, characterized in that: include: Define syntax and semantics according to the smart contract specification, where syntax is defined in Backus-Naur Form (BNF) and semantics is defined in the form of rules that conform to the rewriting logic; Compile the written smart contract semantic set to generate a semantic interpreter and a semantic verifier; Receive user input for the smart contract program, which includes user-defined security attributes and function call sequences; Input the smart contract program into the generated semantic interpreter, generate a program execution state sequence, extract the i-th step and the j-th step in the execution state sequence as the state change in the attribute specification according to the verification attribute, input the symbolic constraint conditions to form the attribute specification, and input the attribute specification into the semantic verifier; The semantic verifier performs path exploration according to the rewriting rules and simplification rules to generate a smart contract semantic graph, which contains contract semantics, semantic control flow, semantic data flow, and verification constraint information; Performing semantic graph analysis according to the semantic graph, wherein the semantic graph analysis includes any one of symbolic execution and vulnerability detection; Based on the results, the smart contract is iteratively optimized until the generated semantic graph meets the verification constraint requirements.
2. The method according to claim 1, characterized in that: The step of inputting the smart contract program into the generated semantic interpreter to generate a program execution state sequence includes: The user enters the smart contract information. If the initialization information is related to the verification attributes, the user needs to customize the initialization information at the same time. If it is not related, the default initialization information is used, including blockchain information and customized security attributes; Create a new contract instance, use the contract instance to call the function in the smart contract, determine the calling relationship of the contract function, obtain the function calling sequence, parse the initialization information, and establish the contract storage stack, which is divided into the user account and contract information storage area; According to the pre-defined semantic rules, the smart contract is executed according to the rewritten logic to obtain the constraints, execution state sequence and storage slot dynamic information of the smart contract, and the dynamic information updates the data of the storage stack.
3. The method according to claim 1, characterized in that: The semantic validator performs path exploration according to the rewriting rules and simplification rules to generate a smart contract semantic graph, including: Convert the smart contract code according to BNF syntax, input the contract, function call sequence, initial account information, constraint information, etc., and convert and reason according to the call rules and state transition rules defined based on the rewriting logic; The entire reasoning process is numbered through the reasoning depth array, and each step generates a collection in the form of a Cell, which contains the smart contract information, function information, storage slot information, and execution engine; Get a series of State sets based on the Depth array, and extract the initial state that needs to be explored through branch nodes or suspected problematic states i and final state j , and then according to the templates and rules in the reachability assertion generator, the State i and State j Perform item-by-item state alignment and generate reachability assertions based on rewriting logic; In the reachability proof system, different state information corresponding to the reachability assertion is extracted, the final state is used as the leaf node of the path exploration, the initial state is used as the root node, the tree-like execution path is explored, and a semantic graph is generated through the semantic verifier.
4. The method according to claim 3, characterized in that: The extraction needs to explore the initial state State i and final state j , including: If the total number of states is small, directly use State0 and State n As the start and end state.
5. The method according to claim 3, characterized in that: After generating the semantic graph, it also includes: Based on the results, symbolic execution is performed to symbolize part of the call information to iteratively generate more execution paths and capture potential vulnerability information.
6. The method according to claim 2, characterized in that: The new contract instance is created, the contract instance is used to call the function in the smart contract, the calling relationship of the contract function is determined, the function calling sequence is obtained, and the initialization information is parsed to establish the storage stack of the contract, which is divided into the user account and the contract information storage area, specifically including: Create a new contract instance, use the contract instance to call the function in the smart contract, determine the calling relationship of the contract function, obtain the function calling sequence, establish and initialize the contract storage stack, which is divided into user account and contract information storage areas, each area contains multiple storage slots; User accounts are external accounts, applied for on the blockchain in the form of the user's public key; The contract information storage area is used to store contract account information, variable status information, and caller information; The caller can be a user account or a smart contract account. The contract account can be represented as: contract(index:Int,CN:ContractName) When a contract call occurs, an account switch will be performed: User accounts are of the form: <msgsender> contractInstance∷=[addr1,addr2,…]< / msgsender> After the contract is called by an external account, the external account is stored in the caller's storage slot:
7. The method according to claim 2, characterized in that: The constraints can be user-defined, or general security attribute rules can be defined in advance in the form of a constraint library and automatically called; The execution state sequence represents the calling logic, calling order and relationship of the function; The storage slot is used to store variables, functions, and contract data in the execution of smart contracts. This information changes dynamically during the execution process.
8. The method according to claim 3, characterized in that: The execution engine includes a call stack, an external account, callTrack, and callState, wherein the call stack includes caller information and a storage slot used during the call, the external account is user account information inserted in advance, callTrack indicates the order in which function calls are executed, and callState indicates information about the called function.
9. The method according to claim 3, characterized in that: The reachability assertion generator includes the templates and generation rules required for assertion generation. i and State j Perform item-by-item state alignment and generate a reachability assertion form based on the rewriting logic: <cellname>VariableState m ∈State i =>VariableState n ∈State j < / cellname> The semantic graph is a tree structure consisting of nodes and directed edges. composition: SemanticGraph=<Node,Edge> The node set includes each state on the execution path, which is related to the defined rules, and each state transition corresponds to a rule: Node i =<FromEdgeIndex i ,State i ,Rule i ,ToEdgeIndex i > The node corresponds to the starting state of the branch, pointing to the set of multiple outgoing edges, which is: BranchNode i =<FromEdgeIndex i ,State i ,rule i ,ToEdgeSet i >。
Citation Information
Patent Citations
Method and system for automatically verifying business attributes of smart contract in formalized manner
CN116432245A
Intelligent contract vulnerability detection method based on contract semantic graph and deep feature fusion
CN116561771A