Signature algorithm updating method and device, storage medium and electronic equipment
By deploying smart contracts in the blockchain system, dynamic update and management of signature algorithms are solved, the problem of downtime maintenance in the upgrade of signature algorithms in the existing technology is solved, system stability and transaction efficiency are improved, and cross-chain interaction compatibility and efficiency are supported.
Patent Information
- Application Number
- CN202510262152.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-06-03
AI Technical Summary
The existing blockchain system needs to perform hard fork or shutdown maintenance when upgrading or switching signature algorithms, which affects system stability and efficiency. The incompatibility of signature algorithms between different blockchains leads to low cross-chain interaction efficiency.
By deploying smart contracts in the blockchain system, dynamic updates and management of signature algorithms are realized, allowing updates to signature algorithms at runtime, supporting hot-swap and dynamic updates, and avoiding system-level downtime maintenance.
It realizes flexible update and management of signature algorithms, improves the stability and transaction efficiency of blockchain systems, and supports the compatibility and efficiency of cross-chain interactions.
Smart Images

Figure CN120090799A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and in particular to a signature algorithm updating method, device, storage medium and electronic device. Background Art
[0002] Blockchain is a decentralized distributed ledger technology that uses cryptography to achieve functions such as information addressing, verification, storage and transaction through a peer-to-peer blockchain network. With its decentralization, transparency, traceability and tamper-proof characteristics, it is widely used in smart contract transactions including encrypted asset transactions.
[0003] In the current blockchain ecosystem, different public chains, public chains and consortium chains, and different consortium chains use different signature algorithms and key management mechanisms. Some use the Elliptic Curve Digital Signature Algorithm (ECDSA). Hyperledger Fabric supports the high-speed and high-security signature algorithm (Ed25519) and ECDSA. Some blockchains widely use the Elliptic Curve Public Key Cryptography Algorithm (SM2). Since the signature algorithm is statically deployed, the transaction verification relies on the fixed algorithm agreed upon by negotiation, which cannot be updated during the operation of the blockchain. When upgrading or switching the signature algorithm, hard forks or downtime maintenance are required, which affects the stability and efficiency of the blockchain system. Furthermore, since different blockchains use different signature algorithms, and the current blockchain architecture only supports one or more fixed signature algorithms, when cross-chain interaction is performed, when the signature algorithms supported by the source blockchain and the target blockchain of the cross-chain interaction do not have a common signature algorithm, cross-chain interaction cannot be performed, thereby affecting the efficiency of cross-chain interaction. Summary of the invention
[0004] In view of this, the present invention provides a signature algorithm updating method, device, storage medium and electronic device.
[0005] Specifically, the present invention is achieved through the following technical solutions:
[0006] According to a first aspect of the present invention, a signature algorithm updating method is provided, the signature algorithm updating method comprising:
[0007] The target blockchain node initiates a signature algorithm update request in the blockchain system to which it belongs. The signature algorithm update request carries the algorithm configuration of the new signature algorithm, the latest signature algorithm library hash value, and the target blockchain node information;
[0008] Receive an update response from other blockchain nodes in the blockchain system for the signature algorithm update request. The update response is obtained by other blockchain nodes through verifying the target blockchain based on the target blockchain node information, matching the hash value of the signature algorithm library in its own smart contract with the latest hash value of the signature algorithm library, and determining whether the algorithm configuration of the new signature algorithm is satisfied;
[0009] After determining to agree to the update based on the received update response, publish the signature agreeing to the update and the algorithm configuration of the new signature algorithm to the smart contract of the blockchain system;
[0010] The blockchain system triggers an update configuration event according to the preset settings, so that each blockchain node in the blockchain system updates the local signature algorithm library based on the update configuration event;
[0011] Each blockchain node obtains the time of the new signature algorithm in the locally activated and updated signature algorithm library according to the smart contract of the blockchain system.
[0012] Optionally, the method further includes:
[0013] When a cross-chain transaction is required, generate a user key pair for the user based on the currently effective signature algorithm, register the public key hash in the user key pair and the identifier of the currently effective signature algorithm to the decentralized identity contract of the blockchain system, and obtain a decentralized identity first identifier;
[0014] Initiate a cross-chain transaction request to the target chain, and carry the decentralized identity first identifier in the cross-chain transaction request, so that the target chain can parse the cross-chain transaction request and obtain a decentralized identity second identifier;
[0015] Load the signature algorithm corresponding to the signature algorithm identifier carried in the decentralized identity second identifier, and use the public key corresponding to the public key hash carried in the decentralized identity second identifier to verify the signature of the cross-chain transaction request.
[0016] Optionally, the step of initiating a cross-chain transaction request to the target chain and carrying the decentralized identity first identifier in the cross-chain transaction request includes:
[0017] After the cross-chain gateway on the source chain monitors a cross-chain transaction event, verify the cross-chain transaction request;
[0018] After passing the verification, lock the assets in the source chain, and generate a cross-chain transaction proof based on the locked assets;
[0019] Encapsulate the cross-chain transaction proof in a standardized cross-chain message, carry the standardized cross-chain message in the cross-chain transaction request carrying the decentralized identity first identifier, and broadcast it to the cross-chain gateway of the target chain.
[0020] Optionally, before loading the signature algorithm corresponding to the signature algorithm identifier carried in the second decentralized identity identifier, the method further includes:
[0021] The cross-chain gateway of the target chain listens for cross-chain transaction events, parses cross-chain transaction requests, obtains standardized cross-chain messages, and after verifying the standardized cross-chain messages, distributes the cross-chain transaction requests to the target chain.
[0022] Optionally, publishing the algorithm configuration of the new signature algorithm to the blockchain system includes:
[0023] Invoking the signature algorithm update interface to update the algorithm configuration of the new signature algorithm and the hash value of the latest signature algorithm library into the smart contract of the blockchain system.
[0024] Optionally, the method further includes:
[0025] If any blockchain node in the blockchain system encounters an exception during the process of conducting blockchain transactions using the new signature algorithm, a rollback proposal is initiated.
[0026] Optionally, before initiating the signature algorithm update request, the method further includes:
[0027] According to a preset time period, the target blockchain node obtains the hash value of the first signature algorithm library in its own smart contract and the hash value of the second signature algorithm library in the smart contract of the signature algorithm dynamic link library within the blockchain system to which it belongs;
[0028] Determine that the hash value of the first signature algorithm library is inconsistent with the hash value of the second signature algorithm library, and execute the step of initiating the signature algorithm update request.
[0029] In the signature algorithm update method of this technical solution, a target blockchain node initiates a signature algorithm update request within the blockchain system to which it belongs. In the signature algorithm update request, the algorithm configuration of the new signature algorithm, the hash value of the latest signature algorithm library, and the target blockchain node information are carried; receive the update responses of other blockchain nodes in the blockchain system to the signature algorithm update request. The update responses are obtained by other blockchain nodes verifying the target blockchain based on the target blockchain node information, matching the hash value of the signature algorithm library in their own smart contracts queried with the hash value of the latest signature algorithm library, and whether the algorithm configuration of the new signature algorithm is satisfied; after determining to agree to the update based on the received update responses, publish the signature agreeing to the update and the algorithm configuration of the new signature algorithm to the smart contract of the blockchain system; the blockchain system triggers an update configuration event according to the preset settings, so that each blockchain node in the blockchain system updates the local signature algorithm library according to the update configuration event; each blockchain node obtains the time to activate the new signature algorithm in the updated local signature algorithm library according to the smart contract of the blockchain system. In this way, by deploying smart contracts on each blockchain node to update, query, and manage the configuration information of the signature algorithms supported by the blockchain system in real time, the update during the operation of the signature algorithm can be realized, thereby realizing the hot plug and dynamic update of the signature algorithm, enabling the blockchain system to more flexibly adapt to new signature algorithms without system-level downtime maintenance, and improving the stability and transaction efficiency of the blockchain system.
[0030] According to the second aspect of the present invention, a signature algorithm update device is provided. The signature algorithm update device includes:
[0031] An update request module, configured to initiate a signature algorithm update request by a target blockchain node within the blockchain system to which it belongs. In the signature algorithm update request, the algorithm configuration of the new signature algorithm, the hash value of the latest signature algorithm library, and the target blockchain node information are carried;
[0032] A request response module, configured to receive the update responses of other blockchain nodes in the blockchain system to the signature algorithm update request. The update responses are obtained by other blockchain nodes verifying the target blockchain based on the target blockchain node information, matching the hash value of the signature algorithm library in their own smart contracts queried with the hash value of the latest signature algorithm library, and whether the algorithm configuration of the new signature algorithm is satisfied;
[0033] A publishing module, configured to publish the signature agreeing to the update and the algorithm configuration of the new signature algorithm to the smart contract of the blockchain system after determining to agree to the update based on the received update responses;
[0034] An algorithm update module, configured to trigger an update configuration event according to preset settings in the blockchain system, so that each blockchain node in the blockchain system updates its local signature algorithm library according to the update configuration event;
[0035] An algorithm activation module, configured to obtain the time for activating a new signature algorithm in the updated local signature algorithm library by each blockchain node according to the smart contract of the blockchain system.
[0036] According to a third aspect of the present invention, there is provided a storage medium, on which a computer program is stored, and when the program is executed by a processor, the steps of the signature algorithm update method in any possible implementation manner of the first aspect are implemented.
[0037] According to a fourth aspect of the present invention, there is provided an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, the steps of the signature algorithm update method in any possible implementation manner of the first aspect are implemented. Description of the Drawings
[0038] The drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present invention, and are used together with the specification to explain the principles of the present invention.
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0040] Figure 1 It is a schematic flowchart of a signature algorithm update method provided by an embodiment of the present invention;
[0041] Figure 2 It is a schematic diagram of a signature algorithm update device provided by an embodiment of the present invention;
[0042] Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed Embodiments
[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0044] In the related art, since different public chains and consortium chains use different signature algorithms and key management mechanisms, the key management mechanism only supports one or more fixed signature algorithms, and there is a lack of unified signature algorithm management between different blockchains, which may cause cross-chain transactions to fail due to incompatibility of signature algorithms during cross-chain interaction, or require complex protocol conversion to verify different signature algorithms, affecting the efficiency of cross-chain interaction, and the efficiency of cross-chain transactions is low. Furthermore, the signature algorithm of the current blockchain adopts a static deployment method, for example, by setting up a relay chain and a cross-chain communication protocol to achieve interoperability between different blockchains, wherein the relay chain is used to verify and forward cross-chain transactions, and each independent blockchain communicates with the relay chain through a cross-chain communication protocol. All participating chains in blockchain transactions use the same signature algorithm (such as Ed25519 or ECDSA) through pre-negotiation. The transaction verification relies on the fixed algorithm agreed upon by negotiation, which cannot be updated when the blockchain is running. When upgrading or switching the signature algorithm, a hard fork or shutdown maintenance is required, which affects the stability of the blockchain. Moreover, the private key and public key systems of different blockchains are incompatible with each other. Users need to generate different key pairs for different blockchains, that is, users need to generate key pairs for each blockchain separately in advance. When conducting cross-chain transactions, signature conversion is performed through the verification node of the relay chain, which makes the integration of key management more decentralized and the management cost higher. It has the following defects:
[0045] ① Each blockchain uses a fixed signature algorithm and cannot upgrade the signature algorithm during operation. If you want to upgrade or make it compatible with different types of signature algorithms, you need to make complex changes to the blockchain's computing logic, which requires downtime for maintenance. This cannot meet the demand for real-time updates of the signature algorithm during the operation of the blockchain node.
[0046] ② The key systems are incompatible with each other, cross-chain operations require repeated key generation, and the inconsistent signature verification protocols lead to interoperability barriers.
[0047] In this embodiment, a dynamic signature management method is provided for the blockchain, which can support the dynamic loading and upgrading of different signature algorithms when the blockchain is running, realize the unified management of cross-chain accounts and signature interoperability, so as to improve the security, compatibility and efficiency of cross-chain transactions.
[0048] See also Figure 1 The embodiment of the present invention provides a signature algorithm update method, which may include the following steps:
[0049] S101. The target blockchain node initiates a signature algorithm update request in the blockchain system to which it belongs. The signature algorithm update request carries the algorithm configuration of the new signature algorithm, the latest signature algorithm library hash value, and the target blockchain node information;
[0050] In this embodiment, as an alternative embodiment, the target blockchain node may be a client, which is provided with a visual front-end interface, and the user initiates a signature algorithm update request through the visual front-end interface.
[0051] In this embodiment, as an alternative embodiment, the signature algorithm update request may also be to delete an existing signature algorithm or change the configuration information of an existing signature algorithm.
[0052] In this embodiment, as an alternative embodiment, before initiating the signature algorithm update request, the method further includes:
[0053] According to a preset time period, the target blockchain node obtains the hash value of the first signature algorithm library in its own smart contract, and the hash value of the second signature algorithm library in the smart contract in the signature algorithm dynamic link library within the blockchain system to which it belongs;
[0054] Determine that the hash value of the first signature algorithm library is inconsistent with the hash value of the second signature algorithm library, and execute the step of initiating the signature algorithm update request.
[0055] In this embodiment, the blockchain system includes each blockchain node and a signature algorithm dynamic link library. Among them, each blockchain node, the signature algorithm dynamic link library, and the blockchain system are all configured with corresponding smart contracts. The signature algorithm dynamic link library is used to store various signature algorithms supported by the blockchain system, and can be dynamically updated by the administrator. After each update of the signature algorithm, a corresponding signature algorithm library hash value is generated, and the signature algorithm library hash value stored in the smart contract in the signature algorithm dynamic link library is updated.
[0056] In this embodiment, as an alternative embodiment, a dynamic signature algorithm management module is used to manage the signature algorithm dynamic link library. The signature algorithm dynamic link library is used to store different signature algorithms. The dynamic signature algorithm management module adopts a plug-in architecture and supports hot plugging to facilitate the dynamic loading and unloading of signature algorithms. As an alternative embodiment, the signature algorithms include, but are not limited to, multiple signature algorithms such as SM2, Ed25519, and ECDSA, so as to meet the cross-chain transaction requirements between different blockchain systems.
[0057] In this embodiment, as an alternative embodiment, the signature algorithm includes the following elements:
[0058] ① Algorithm identifier: The unique identifier of the signature algorithm.
[0059] ② Version number: Used to track the signature algorithm version to ensure the compatibility and security of the signature algorithm.
[0060] ③Verify the Application Program Interface (API): It is a verification function pointing to the signature algorithm and is used to verify the effectiveness of the signature algorithm.
[0061] ④Key generation API: It is used to generate a key pair for signature.
[0062] In this embodiment, through the dynamic link library (DLL, Dynamic Link Library) hot loading technology, the runtime loading of the signature algorithm can be realized.
[0063] In this embodiment, as another optional embodiment, before initiating a signature algorithm update request, the method further includes:
[0064] Receiving a new signature algorithm and executing the step of initiating the signature algorithm update request.
[0065] In this embodiment, when any blockchain node in the blockchain system needs to update the signature algorithm, a signature algorithm update request is initiated. As an optional embodiment, the signature algorithm update request carries the algorithm configuration of the new signature algorithm, the latest signature algorithm library hash value, and the target blockchain node information.
[0066] In this embodiment, as an optional embodiment, the target blockchain node can also, based on the deployed smart contract, verify the legality of the signature algorithm update request. After the verification passes, a signature algorithm update request for initiating a signature algorithm update vote is sent to other blockchain nodes in the blockchain system.
[0067] S102. Receive the update response of other blockchain nodes in the blockchain system to the signature algorithm update request. The update response is obtained by other blockchain nodes verifying the target blockchain based on the target blockchain node information, matching the signature algorithm library hash value in their own smart contract with the latest signature algorithm library hash value, and whether it meets the algorithm configuration of the new signature algorithm.
[0068] In this embodiment, after the target blockchain node initiates a signature algorithm update request, other blockchain nodes in the blockchain system will evaluate the signature algorithm update request. For example, other blockchain nodes use the current signature algorithm to sign and verify the signature algorithm update request (verify the target blockchain based on the target blockchain node information), whether the signature algorithm library hash value in the smart contract matches the latest signature algorithm library hash value, whether the resources meet the algorithm configuration of the new signature algorithm, etc., and send the signatures agreeing to the update back to the target blockchain node. The target blockchain node collects the signature confirmations to determine whether it passes.
[0069] S103. After determining to agree to the update based on the received update response, publish the signature agreeing to the update and the algorithm configuration of the new signature algorithm to the smart contract of the blockchain system;
[0070] In this embodiment, among the received update responses, if more than the preset node threshold of blockchain nodes (e.g., 51%) agree to the update, it indicates that the blockchain system agrees to the update. In the case where the approval of the update passes, the smart contract of the target blockchain node updates the configuration according to the algorithm configuration of the new signature algorithm based on the signature algorithm dynamic link library, obtains the dynamically updated signature algorithm information, and synchronizes the updated signature algorithm information to the smart contract of the blockchain system and other blockchain nodes of the blockchain system, and writes the transaction record into the blockchain ledger.
[0071] In this embodiment, after determining to agree to the update, submit the multi-signature agreeing to the update to the smart contract, that is, after collecting a sufficient number of signatures agreeing to the update, the target blockchain node publishes all the signatures agreeing to the update and the algorithm configuration of the new signature algorithm (new signature algorithm configuration) to the blockchain system.
[0072] In this embodiment, as an optional embodiment, publishing the algorithm configuration of the new signature algorithm to the blockchain system includes:
[0073] Call the signature algorithm update interface to update the algorithm configuration of the new signature algorithm and the latest signature algorithm library hash value into the smart contract of the blockchain system.
[0074] In this embodiment, by calling the signature algorithm update (updateAlgorithm) interface, the new signature algorithm configuration and the latest signature algorithm library hash value are updated into the smart contract of the blockchain system to ensure the transparency and immutability of the signature algorithm update.
[0075] In this embodiment, as an optional embodiment, use the dynamic configuration contract unit in the dynamic signature algorithm management module to configure the smart contract, including the smart contracts deployed on each blockchain node and the smart contract on the blockchain system, to update, query, and manage the configuration information of the signature algorithms supported by the signature algorithm dynamic link library of the blockchain system in real time, and ensure cross-chain transaction operations between each blockchain node and the cross-chain blockchain system.
[0076] In this embodiment, as an optional embodiment, the data structure (AlgorithmConfig) of the configuration information in the smart contract is used to define the parameters of the signature algorithm configuration, and the corresponding code segment is as follows:
[0077]
[0078]
[0079] Among them, algorithmID represents the algorithm identifier of the signature algorithm; version represents the effective version of the signature algorithm to determine whether the version of the signature algorithm used is the latest or the specified version; maintainer represents the address of the maintainer, which is used to track the maintainer of the signature algorithm; activationBlock identifies the activation block height of the signature algorithm, which is used to specify when the signature algorithm starts to take effect; isActive identifies whether the signature algorithm is in an active state.
[0080] The code segments corresponding to the on-chain interfaces provided by the smart contract are as follows:
[0081] updateAlgorithm(uint8 id,string memory libHash,AlgorithmConfig config,Signature sign[])
[0082] getActiveAlgorithms()returns(AlgorithmConfig config)
[0083] Among them, updateAlgorithm is used to allow the update of the signature algorithm configuration, and libHash is the hash value of the signature algorithm library, which is used to verify the integrity of the signature algorithm library.
[0084] getActiveAlgorithms is used to query the currently active signature algorithm configuration and returns the configuration parameters of all active signature algorithms.
[0085] S104. The blockchain system triggers a configuration update event according to the preset, so that each blockchain node in the blockchain system updates the local signature algorithm library according to the configuration update event;
[0086] In this embodiment, after the blockchain system receives the signature agreeing to the update, it triggers a configuration update (ConfigUpdate) event to drive each blockchain node in the blockchain system to update the signature algorithm. As an alternative embodiment, the blockchain system uses the blockchain event subscription mode to drive each blockchain node to update the signature algorithm, that is, each blockchain node listens for the ConfigUpdate event, and after listening for the ConfigUpdate event, it triggers the local signature algorithm library to update the signature algorithm from the signature algorithm dynamic link library of the blockchain system.
[0087] In this embodiment, the target blockchain node publishes the new signature algorithm configuration to the blockchain system, and after the update takes effect, it triggers the ConfigUpdate event of the blockchain system. After each blockchain node monitors the ConfigUpdate event, it automatically synchronizes the new signature algorithm to the local signature algorithm library.
[0088] In this embodiment, each blockchain node verifies the hash value of the new signature algorithm library to ensure the integrity and correctness of the new signature algorithm library, and updates the local signature algorithm library based on the new signature algorithm library.
[0089] S105. Each blockchain node obtains the time to activate the new signature algorithm in the updated local signature algorithm library according to the smart contract of the blockchain system.
[0090] In this embodiment, after the local signature algorithm library is updated, the blockchain node will obtain the time to start activating the new signature algorithm according to the activationBlock parameter in the smart contract of the blockchain system, that is, according to the activationBlock parameter, modify the value of isActive in the smart contract configuration corresponding to the local signature algorithm library, so that after the configured value of isActive takes effect, the new signature algorithm is enabled.
[0091] In this embodiment, if the activationBlock parameter is set to the current block or an earlier block, the blockchain node will immediately start using the new signature algorithm for signature and verification operations.
[0092] In this embodiment, the local signature algorithm library stores various types of signature algorithms compatible with the blockchain system, and dynamically updates the signature algorithm through the smart contract deployed on the blockchain node, so that after there is a new signature algorithm in the dynamic link library of the signature algorithm of the blockchain system, it can obtain the latest signature algorithm based on the smart contract, thereby realizing the dynamic update of the signature algorithm; at the same time, because the local signature algorithm library stores multiple signature algorithms compatible with the blockchain system, it can support dynamic loading, unloading, version update, etc. of multiple types of signature algorithms, enabling the blockchain node to replace or upgrade the signature algorithm without downtime during operation, effectively improving the transaction efficiency of the blockchain node.
[0093] In this embodiment, as an alternative embodiment, the method further includes:
[0094] If any blockchain node in the blockchain system encounters an exception during the process of using the new signature algorithm for blockchain transactions, a rollback proposal is initiated.
[0095] In this embodiment, if an exception occurs during a blockchain transaction when a blockchain node uses a new signature algorithm for the blockchain transaction, the blockchain node can initiate a rollback proposal to return to the previous version of the signature algorithm to ensure the stability, security, and availability of the signature algorithm.
[0096] In this embodiment, as an alternative embodiment, the method further includes:
[0097] B11. When a cross-chain transaction is required, generate a user key pair for the user based on the currently effective signature algorithm, register the public key hash in the user key pair and the identifier of the currently effective signature algorithm in the decentralized identity contract of the blockchain system, and obtain a decentralized identity first identifier.
[0098] In this embodiment, the dynamic configuration contract (smart contract) deployed by the blockchain node is configured with the configuration information of the signature algorithms supported by the blockchain network. The dynamic configuration contract is used to obtain the configuration information of the signature algorithms compatible with the blockchain system and update it dynamically, and record and manage the configuration parameter information of the signature algorithms of the blockchain system. As an alternative embodiment, the blockchain node calls the createKeyPair interface to call the signature algorithm from the local signature algorithm library to generate a user key pair.
[0099] In this embodiment, to implement a cross-chain transaction, after the blockchain node generates a user key pair based on the currently effective signature algorithm, it registers the public key hash and the algorithm identifier of the signature algorithm, that is, the signature algorithm identifier (algorithmID), in the decentralized identity (DID) contract to generate a unique DID identifier for cross-chain transactions. For example, the generated DID identifier is: did:crosschain:keccak256(publicKey). Here, the blockchain system is the source chain.
[0100] In this embodiment, a cross-chain identity identification protocol is set in the DID contract to establish a decentralized identity identification to achieve a global mapping of the public key independent of the chain. As an alternative embodiment, the data structure in the DID contract is as follows:
[0101]
[0102] mapping(bytes32 => DIDDocument) public didRegistry;
[0103] Among them, algorithmID is the signature algorithm identifier, publicKeyHash is the public key hash, updateBlock represents the last updated block, and controller represents the control account address, which can be replaced.
[0104] In this embodiment, each DID identifier corresponds to an object of a DIDDocument, and the decentralized identity first identifier is the registered account used for cross-chain transactions with the target chain.
[0105] B12. Initiate a cross-chain transaction request to the target chain, and carry the decentralized identity first identifier in the cross-chain transaction request, so that the target chain can parse the cross-chain transaction request to obtain the decentralized identity second identifier.
[0106] In this embodiment, the source chain initiates a cross-chain transaction, creates a cross-chain transaction request for transferring assets to the target chain on the source chain. In the cross-chain transaction request, carry the DID identifier instead of the original public key, and the target chain parses the cross-chain transaction request to obtain the carried DID identifier.
[0107] In this embodiment, after generating the cross-chain transaction request, sign the cross-chain transaction request and broadcast the signed cross-chain transaction request to the target chain. As an optional embodiment, the transaction initiator creates a cross-chain transaction on the source chain, requests to transfer assets to the target chain. When signing the cross-chain transaction, select the currently active signature algorithm according to AlgorithmConfig, broadcast the cross-chain transaction request to the cross-chain gateway on the source chain, and the cross-chain gateway on the source chain will confirm it.
[0108] In this embodiment, as an optional embodiment, initiating a cross-chain transaction request to the target chain and carrying the decentralized identity first identifier in the cross-chain transaction request includes:
[0109] C11. After the cross-chain gateway on the source chain detects a cross-chain transaction event, verify the cross-chain transaction request.
[0110] In this embodiment, after the source chain initiates a cross-chain transaction request, it triggers a cross-chain transaction event. The cross-chain gateway on the source chain monitors the cross-chain transaction event and verifies the cross-chain transaction request, that is, verifies the transaction signature and content in the cross-chain transaction request. As an optional embodiment, by calling the getActiveAlgorithms() function, ensure that the signature algorithm used for cross-chain transactions is acceptable to the current chain (source chain); verify whether the signature conforms to the signature algorithm specified by algorithmID, check the timestamp to prevent replay attacks, and ensure that the balance of the source chain account (sourceAccount) is sufficient.
[0111] C12. After passing the verification, lock the assets in the source chain, and generate a cross-chain transaction proof based on the locked assets.
[0112] In this embodiment, the assets are locked in the source chain, so that the assets are frozen in the smart contract of the source chain, and a cross-chain transaction proof is generated. As an alternative embodiment, the cross-chain transaction proof includes: txID, transaction details, and current chain signature information.
[0113] C13. Encapsulate the cross-chain transaction proof in a standardized cross-chain message, carry the standardized cross-chain message in a cross-chain transaction request carrying the first identifier of the decentralized identity, and broadcast it to the cross-chain gateway of the target chain.
[0114] In this embodiment, the cross-chain gateway of the target chain verifies the received cross-chain transaction request.
[0115] B13. Load the signature algorithm corresponding to the signature algorithm identifier carried in the second identifier of the decentralized identity, and use the public key corresponding to the public key hash carried in the second identifier of the decentralized identity to verify the signature of the cross-chain transaction request.
[0116] In this embodiment, as an alternative embodiment, before loading the signature algorithm corresponding to the signature algorithm identifier carried in the second identifier of the decentralized identity, the method further includes:
[0117] The cross-chain gateway of the target chain listens for cross-chain transaction events, parses the cross-chain transaction request, obtains the standardized cross-chain message, verifies the standardized cross-chain message, and then distributes the cross-chain transaction request to the target chain.
[0118] In this embodiment, the cross-chain gateway listens for cross-chain transaction events, obtains the cross-chain transaction proof in the cross-chain transaction request, and parses to obtain information such as txID, signature, and algorithmID. The parsed information is preliminarily verified to ensure the integrity of the cross-chain transaction. After the preliminary verification passes, the cross-chain transaction request carrying the standardized cross-chain message and the second identifier of the decentralized identity is transmitted to the target chain.
[0119] In this embodiment, after receiving the standardized cross-chain message, the cross-chain gateway on the target chain verifies it, checks the validity of the DID, parses the DID to obtain the second identifier of the decentralized identity, and loads the corresponding signature algorithm to verify the signature. After the signature verification passes, the asset mapping and transfer are executed.
[0120] In this embodiment, since cross-chain transactions involve multiple blockchain systems, different blockchain systems use different signature algorithms and key management methods. To achieve efficient cross-chain transactions, this embodiment sets up a standardized cross-chain protocol for transmitting cross-chain transaction requests. Among them, the transmission of cross-chain transaction requests adopts a standardized cross-chain transaction message format. As an alternative embodiment, the cross-chain transaction message format is as follows:
[0121]
[0122]
[0123] In this embodiment, the cross-chain transaction message includes four main fields, where:
[0124] The header field, which contains blockchain system information. Among them, txID represents the unique identifier of the cross-chain transaction, configVersion represents the configuration version of the source chain signature algorithm for compatibility verification, and nonce represents the anti-replay sequence number;
[0125] The identity field, which contains identity information. Among them, sourceDID / targetDID represents the global identity identifiers of the source chain / target chain, that is, decentralized identity identifiers, and sourceChain / destChain represents the source chain and target chain corresponding to the cross-chain transaction request;
[0126] The payload field, which contains cross-chain transferred asset information. Among them, assetType represents the asset type of the cross-chain transaction, and amount represents the quantity of the cross-chain transaction assets;
[0127] The signature field, which contains the cross-chain transaction signature.
[0128] In this embodiment, for signature verification, please refer to relevant technical literature for details, which are omitted here.
[0129] In this embodiment, by constructing a unified dynamic signature algorithm management module, the hot plugging and dynamic update of the signature algorithm are realized, enabling the blockchain system to more flexibly adapt to new signature algorithm standards or security requirements without system-level downtime maintenance. At the same time, by introducing a cross-chain identity identification system (DID), a decentralized identity identification is established, realizing a global mapping of public keys independent of the chain, simplifying the identity authentication process in cross-chain transactions, improving the efficiency and security of cross-chain transactions, and realizing unified management of cross-chain accounts. Further, by designing a cross-chain protocol and cross-chain transaction message format, a standardized solution is provided for the interoperability between different blockchain systems, enabling transactions between different blockchains to be carried out more efficiently and securely, reducing complex protocol conversions in cross-chain transactions, improving the efficiency of cross-chain transactions, and realizing signature interoperability. Moreover, the smart contracts deployed on each blockchain node can update, query, and manage the configuration information of the signature algorithms supported by each system in real time, enabling the update of the signature algorithm during runtime, ensuring the transparency and immutability of the signature algorithm update, realizing signature algorithm version synchronization through the blockchain event subscription mode, and improving the stability and security of the blockchain system. In addition, the update process includes an exception handling mechanism that can quickly roll back to the previous algorithm version when problems are found, ensuring the stability and security of the blockchain system.
[0130] Based on the same inventive concept, as Figure 2 shown, an embodiment of the present invention further provides a signature algorithm update device, which includes:
[0131] An update request module 201, configured to initiate a signature algorithm update request within the blockchain system to which the target blockchain node belongs. In the signature algorithm update request, the algorithm configuration of the new signature algorithm, the hash value of the latest signature algorithm library, and the target blockchain node information are carried;
[0132] In this embodiment, the blockchain system includes each blockchain node and a signature algorithm dynamic link library. Among them, each blockchain node, the signature algorithm dynamic link library, and the blockchain system are all configured with corresponding smart contracts. The signature algorithm dynamic link library is used to store each signature algorithm supported by the blockchain system, which can be dynamically updated by the administrator. After each update of the signature algorithm, a corresponding signature algorithm library hash value is generated, and the signature algorithm library hash value stored in the smart contract in the signature algorithm dynamic link library is updated.
[0133] A request response module 202, configured to receive an update response from other blockchain nodes in the blockchain system for a signature algorithm update request, where the update response is obtained by other blockchain nodes verifying the target blockchain based on target blockchain node information, matching the hash value of the signature algorithm library in its own smart contract queried with the latest hash value of the signature algorithm library, and determining whether the algorithm configuration of the new signature algorithm is satisfied;
[0134] In this embodiment, after the target blockchain node initiates a signature algorithm update request, other blockchain nodes in the blockchain system will evaluate the signature algorithm update request.
[0135] A publishing module 203, configured to, after determining to agree to the update according to the received update response, publish the signature agreeing to the update and the algorithm configuration of the new signature algorithm to the smart contract of the blockchain system;
[0136] In this embodiment, as an optional embodiment, the publishing module 203 is specifically configured to:
[0137] Call a signature algorithm update interface to update the algorithm configuration of the new signature algorithm and the latest hash value of the signature algorithm library to the smart contract of the blockchain system.
[0138] An algorithm update module 204, configured to trigger an update configuration event according to a preset setting by the blockchain system, so that each blockchain node in the blockchain system updates its local signature algorithm library according to the update configuration event;
[0139] In this embodiment, each blockchain node verifies the hash value of the new signature algorithm library to ensure the integrity and correctness of the new signature algorithm library, and updates its local signature algorithm library based on the new signature algorithm library.
[0140] An algorithm activation module 205, configured to obtain the time for activating the new signature algorithm in the locally updated signature algorithm library by each blockchain node according to the smart contract of the blockchain system.
[0141] In this embodiment, after the local signature algorithm library of the blockchain node is updated, the time for starting to activate the new signature algorithm will be obtained according to the activation block parameter in the smart contract of the blockchain system.
[0142] In this embodiment, as an optional embodiment, the device further includes:
[0143] A rollback module (not shown in the figure), configured to initiate a rollback proposal if any blockchain node in the blockchain system encounters an exception during the process of conducting blockchain transactions using the new signature algorithm.
[0144] In this embodiment, as another optional embodiment, the device further includes:
[0145] A cross-chain transaction module (not shown in the figure) is used to generate a user key pair for the user based on the currently effective signature algorithm when a cross-chain transaction is required, register the public key hash in the user key pair and the identifier of the currently effective signature algorithm in the decentralized identity contract of the blockchain system, and obtain the first decentralized identity identifier;
[0146] Initiate a cross-chain transaction request to the target chain, and carry the first decentralized identity identifier in the cross-chain transaction request, so that the target chain can parse the cross-chain transaction request and obtain the second decentralized identity identifier;
[0147] Load the signature algorithm corresponding to the signature algorithm identifier carried in the second decentralized identity identifier, and use the public key corresponding to the public key hash carried in the second decentralized identity identifier to verify the cross-chain transaction request.
[0148] In this embodiment, as an optional embodiment, initiating a cross-chain transaction request to the target chain and carrying the first decentralized identity identifier in the cross-chain transaction request includes:
[0149] After the cross-chain gateway on the source chain monitors a cross-chain transaction event, it verifies the cross-chain transaction request;
[0150] After passing the verification, lock the assets in the source chain, and generate a cross-chain transaction proof based on the locked assets;
[0151] Encapsulate the cross-chain transaction proof in a standardized cross-chain message, carry the standardized cross-chain message in the cross-chain transaction request carrying the first decentralized identity identifier, and broadcast it to the cross-chain gateway of the target chain.
[0152] In this embodiment, as an optional embodiment, before loading the signature algorithm corresponding to the signature algorithm identifier carried in the second decentralized identity identifier, it further includes:
[0153] The cross-chain gateway of the target chain monitors the cross-chain transaction event, parses the cross-chain transaction request, obtains the standardized cross-chain message, and after verifying the standardized cross-chain message, distributes the cross-chain transaction request to the target chain.
[0154] In this embodiment, as another optional embodiment, the device further includes:
[0155] An update detection module is used to, according to a preset time period, the target blockchain node obtains the hash value of the first signature algorithm library in its own smart contract, and the hash value of the second signature algorithm library in the smart contract in the signature algorithm dynamic link library within the blockchain system to which it belongs;
[0156] It is determined that the hash value of the first signature algorithm library is inconsistent with the hash value of the second signature algorithm library, and the step of initiating a signature algorithm update request is executed.
[0157] Based on the same inventive concept, an embodiment of the present invention further provides a storage medium, on which a computer program is stored. When the program is executed by a processor, the steps of the signature algorithm update method in any possible implementation manner described above are implemented.
[0158] Optionally, the storage medium may be a non-transitory computer-readable storage medium. For example, the non-transitory computer-readable storage medium may be ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.
[0159] Based on the same inventive concept, see Figure 3 , an embodiment of the present invention further provides an electronic device, including a memory 101 (such as a non-volatile memory), a processor 102, and a computer program stored on the memory 101 and executable on the processor 102. When the processor 102 executes the program, the steps of the signature algorithm update method in any possible implementation manner described above are implemented, which is equivalent to the signature algorithm update device as described above. Of course, the processor can also be used to process other data or perform operations. The electronic device may be a device such as a PC, a server, or a terminal.
[0160] As Figure 3 shown, the electronic device generally may further include: a memory 103, a network interface 104, and an internal bus 105. In addition to these components, other hardware may also be included, which will not be elaborated here.
[0161] It should be noted that the above signature algorithm update device may be implemented by software. As a logically meaningful device, it is formed by the processor 102 of the electronic device where it is located reading the computer program instructions stored in the non-volatile memory into the memory 103 and running.
[0162] The embodiments of the subject matter and the functional operations described in this specification can be implemented in the following: digital electronic circuits, tangible computer software or firmware, computer hardware including the structures disclosed in this specification and their structural equivalents, or a combination of one or more of them. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules in computer program instructions encoded on a tangible non-transitory program carrier to be executed by a data processing apparatus or to control the operation of a data processing apparatus. Alternatively or additionally, the program instructions can be encoded on an artificially generated propagated signal, such as a machine-generated electrical, optical, or electromagnetic signal, which is generated to encode information and transmit it to a suitable receiving device for execution by a data processing apparatus. A computer storage medium can be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or a combination of one or more of them.
[0163] The processes and logical flows described in this specification can be performed by one or more programmable computers executing one or more computer programs to perform the corresponding functions by operating on input data and generating output. The processes and logical flows can also be performed by special purpose logic circuitry, such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit), and the apparatus can also be implemented as special purpose logic circuitry.
[0164] Computers suitable for executing computer programs include, for example, general and / or special purpose microprocessors, or any other type of central processing unit. Generally, the central processing unit will receive instructions and data from a read-only memory and / or a random access memory. The basic components of a computer include a central processing unit for implementing or executing instructions and one or more memory devices for storing instructions and data. Generally, a computer will also include one or more mass storage devices for storing data, such as magnetic disks, magneto-optical disks, or optical disks, etc., or the computer will be operatively coupled to such mass storage devices to receive data from them or to transmit data to them, or both. However, a computer is not necessarily required to have such devices. In addition, a computer can be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device such as a universal serial bus (USB) flash drive, to name just a few.
[0165] Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, including, for example, semiconductor memory devices (such as EPROM, EEPROM, and flash memory devices), magnetic disks (such as internal hard disks or removable disks), magneto-optical disks, and CD-ROM and DVD-ROM disks. The processor and the memory may be supplemented by, or incorporated in, special purpose logic circuitry.
[0166] Although this specification contains many specific implementation details, these should not be construed as limiting the scope of any invention or the scope of what is claimed, but rather as mainly being used to describe the features of specific embodiments of a particular invention. Certain features that are described in multiple embodiments in this specification may also be implemented in combination in a single embodiment. On the other hand, the various features described in a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination. Additionally, although features may operate in certain combinations and even be claimed as such initially, one or more features from a claimed combination may in some cases be removed from that combination, and the claimed combination may be directed to a sub-combination or a variation of a sub-combination.
[0167] Similarly, although operations are depicted in the drawings in a particular order, this should not be understood as requiring that the operations be performed in the particular order shown or sequentially, or that all illustrated operations be performed, to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Additionally, the separation of the various system modules and components in the above embodiments should not be understood as being required in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.
[0168] Thus, specific embodiments of the subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the acts recited in the claims may be performed in a different order and still achieve the desired result. Additionally, the processes depicted in the drawings are not necessarily in the particular order or sequential order shown to achieve the desired result. In some implementations, multitasking and parallel processing may be advantageous.
[0169] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0170] The above are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features claimed herein.
Claims
1. A signature algorithm updating method, characterized in that: include: The target blockchain node initiates a signature algorithm update request in the blockchain system to which it belongs. The signature algorithm update request carries the algorithm configuration of the new signature algorithm, the latest signature algorithm library hash value, and the target blockchain node information; Receive update responses to signature algorithm update requests from other blockchain nodes in the blockchain system, where the update responses are obtained by other blockchain nodes verifying the target blockchain based on the target blockchain node information, matching the signature algorithm library hash value in the queried smart contract with the latest signature algorithm library hash value, and whether the algorithm configuration of the new signature algorithm is satisfied; After determining that the update is approved according to the received update response, the signature of the update approval and the algorithm configuration of the new signature algorithm are published to the smart contract of the blockchain system; The blockchain system triggers an update configuration event according to the pre-settings, so that each blockchain node in the blockchain system updates the local signature algorithm library according to the update configuration event; Each blockchain node obtains the time to activate the new signature algorithm in the updated local signature algorithm library based on the smart contract of the blockchain system.
2. The signature algorithm updating method according to claim 1, characterized in that: The method further comprises: When a cross-chain transaction is required, a user key pair of the user is generated based on the currently effective signature algorithm, and the public key hash in the user key pair and the currently effective signature algorithm identifier are registered to the decentralized identity contract of the blockchain system to obtain the decentralized identity first identifier; Initiate a cross-chain transaction request to the target chain, and carry the first decentralized identity identifier in the cross-chain transaction request, so that the target chain parses the cross-chain transaction request and obtains the second decentralized identity identifier; The signature algorithm corresponding to the signature algorithm identifier carried in the second identifier of the decentralized identity is loaded, and the signature verification of the cross-chain transaction request is performed using the public key corresponding to the public key hash carried in the second identifier of the decentralized identity.
3. The signature algorithm updating method according to claim 2, characterized in that: The initiating a cross-chain transaction request to the target chain, carrying the decentralized identity first identifier in the cross-chain transaction request, includes: After monitoring the cross-chain transaction event, the cross-chain gateway on the source chain verifies the cross-chain transaction request; After passing the verification, the assets in the source chain are locked, and a cross-chain transaction certificate is generated based on the locked assets; The cross-chain transaction proof is encapsulated in a standardized cross-chain message, the standardized cross-chain message is carried in a cross-chain transaction request carrying the first identifier of the decentralized identity, and is broadcast to the cross-chain gateway of the target chain.
4. The signature algorithm updating method according to claim 2, characterized in that: Before loading the signature algorithm corresponding to the signature algorithm identifier carried in the second identifier based on the decentralized identity, the method further includes: The cross-chain gateway of the target chain listens to cross-chain transaction events, parses cross-chain transaction requests, obtains standardized cross-chain messages, verifies the standardized cross-chain messages, and then distributes the cross-chain transaction requests to the target chain.
5. The signature algorithm updating method according to any one of claims 1 to 4, characterized in that: Publishing the algorithm configuration of the new signature algorithm to the blockchain system includes: Call the signature algorithm update interface to update the algorithm configuration of the new signature algorithm and the latest signature algorithm library hash value to the smart contract of the blockchain system.
6. The signature algorithm updating method according to any one of claims 1 to 4, characterized in that: The method further comprises: If any blockchain node in the blockchain system encounters an exception during a blockchain transaction using the new signature algorithm, a rollback proposal will be initiated.
7. The signature algorithm updating method according to any one of claims 1 to 4, characterized in that: Before initiating the signature algorithm update request, the method further includes: According to the preset time period, the target blockchain node obtains the hash value of the first signature algorithm library in its own smart contract and the hash value of the second signature algorithm library in the smart contract in the signature algorithm dynamic link library in the blockchain system to which it belongs; Determine that the first signature algorithm library hash value is inconsistent with the second signature algorithm library hash value, and execute the step of initiating the signature algorithm update request.
8. A signature algorithm updating device, characterized in that: The signature algorithm updating device comprises: An update request module is used for the target blockchain node to initiate a signature algorithm update request in the blockchain system to which it belongs. The signature algorithm update request carries the algorithm configuration of the new signature algorithm, the latest signature algorithm library hash value, and the target blockchain node information; A request response module is used to receive update responses from other blockchain nodes in the blockchain system to signature algorithm update requests. The update response is obtained by other blockchain nodes verifying the target blockchain based on the target blockchain node information, matching the signature algorithm library hash value in the queried smart contract with the latest signature algorithm library hash value, and whether the algorithm configuration of the new signature algorithm is satisfied; A publishing module, configured to publish the signature of the update approval and the algorithm configuration of the new signature algorithm to the smart contract of the blockchain system after determining that the update is approved according to the received update response; The algorithm update module is used for the blockchain system to trigger an update configuration event according to the pre-settings, so that each blockchain node in the blockchain system updates the local signature algorithm library according to the update configuration event; The algorithm activation module is used by each blockchain node to obtain the time to activate the new signature algorithm in the updated local signature algorithm library based on the smart contract of the blockchain system.
9. A storage medium, characterized in that: The storage medium stores a program or instruction, and when the program or instruction is executed by the processor, the steps of the signature algorithm updating method as described in any one of claims 1 to 7 are implemented.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the signature algorithm updating method described in any one of claims 1 to 7 are implemented.