Distributed oracle authentication system based on reputation score

By introducing a distributed oracle authentication system based on reputation scores into the blockchain oracle system, the problems of data source trustworthiness, transmission efficiency and operation cost are solved, and higher data credibility and system attack resistance are achieved.

CN120128341APending Publication Date: 2025-06-10NANJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510282230.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The current blockchain oracle system faces the problems of data source credibility, data transmission efficiency and high operating costs, which leads to inconsistency between on-chain and off-chain data, affecting the implementation of blockchain technology.

Method used

A distributed oracle authentication system based on reputation score is adopted, and a random function can be verified to elect leadership nodes, a threshold signature and multiple signature mechanism is adopted, a reputation score and dynamic management mechanism is introduced, and incentives are issued and punishments are implemented based on reputation value.

Benefits of technology

It improves the credibility and flexibility of blockchain data links, optimizes data transmission efficiency, reduces operating costs, and enhances the system's attack resistance and fairness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128341A_ABST
    Figure CN120128341A_ABST
Patent Text Reader

Abstract

According to the distributed oracle authentication system based on reputation scoring, selectable threshold signatures, multiple signatures and aggregation signatures are adopted to meet applications under different authentication requirements, automatic management and data verification of nodes are achieved through on-chain and off-chain cooperation, the on-chain part comprises a signature module, a reputation scoring module and an excitation module, and the off-chain part comprises a signature module, a reputation scoring module and a reputation scoring module. And dynamic scoring and automatic updating of the nodes are realized through an intelligent contract. And the under-chain part is responsible for data acquisition and verification and data integrity check of a Merkel tree structure. A scoring mechanism in the system is automatically updated based on the performance of nodes in a data verification task, and a high-reputation node is selected as a leader node, so that the anti-attack capability of the system and the reliability of task execution are improved. And through an automatic reward and punishment mechanism, the nodes are stimulated to maintain good service performance. The whole reputation management and election process is automatically executed through the smart contract, and it is ensured that the distributed Oracle system can operate efficiently and transparently without human intervention.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of blockchain security in information security, and specifically relates to a distributed oracle authentication system based on reputation scoring. Background Art

[0002] With the development of blockchain applications, more and more real-world data needs to be uploaded to the blockchain. The immutable feature of the blockchain ensures the consistency of the data on the chain, while the off-chain data may be damaged during the process of recording, storing, and transmitting, resulting in the problem of inconsistent data on and off the chain, which greatly affects the implementation and development of blockchain technology. Therefore, some mechanisms are needed to ensure the consistency of the data on and off the chain. As a "bridge" connecting the blockchain and the off-chain world, the oracle transmits the data in the off-chain real world to the blockchain on the chain.

[0003] Currently, the problems in the use and design of oracle data are gradually exposed, facing a series of severe challenges, including oracle contract security, credibility of data sources, data transmission efficiency, contract operation costs, etc. Under this problem background, the distributed oracle describes a secure multi-party computing scenario, which needs to ensure the confidentiality, integrity, and availability of data, and the correct data acquisition result cannot be tampered with by a few participating parties. In addition, there is a business coupling between the on-chain and off-chain parts of the blockchain oracle, and the current cost of performing computing and storage operations on public blockchains such as Ethereum is relatively high. Therefore, discussing how to optimize the design and implementation to save the operating cost of the on-chain part is also an issue that needs to be considered, otherwise it will limit the application of the blockchain oracle. Summary of the Invention

[0004] In view of the above problems, the present invention proposes a distributed oracle authentication system based on reputation scoring to improve the credibility and flexibility of blockchain data linkage.

[0005] To achieve the above object, the technical solution adopted by the present invention is:

[0006] A distributed oracle authentication system based on reputation scoring, characterized in that it includes three types of entities: a distributed oracle network, a blockchain, and a data source;

[0007] The distributed oracle network elects a leader node through a verifiable random function and adopts a fair leader node rotation mechanism;

[0008] The distributed oracle network introduces optional threshold signatures and multi-signatures to adapt to application scenarios with different authentication requirements, and introduces a node effective report function to evaluate the reputation value of nodes, and distributes incentives according to the reputation value;

[0009] The distributed oracle network includes a reputation-based dynamic scoring and node management mechanism that scores oracle nodes, determines node joining and exiting based on reputation values, and implements an incentive mechanism of rewards and punishments;

[0010] The blockchain receives data requests sent by users through smart contracts. The contract broadcasts the data requests to the leader nodes in the distributed oracle network, and at the same time allows users to specify the signature type in the contract and clarify the minimum reputation value that the nodes participating in the request processing need to reach;

[0011] After the data source receives the access request from the oracle node, it returns the result to the distributed oracle network;

[0012] The reputation-based distributed oracle authentication system takes into account the historical reputation of the nodes when performing reputation scoring;

[0013] When the reputation-based distributed oracle authentication system uses threshold signatures based on BLS, it distributes private key shards according to the reputation values of the nodes;

[0014] When the reputation-based distributed oracle authentication system uses multi-signatures based on BLS, it determines the weights of nodes participating in aggregation according to the reputation values of the nodes. The on-chain contract can require a minimum threshold for the sum of the weights of the nodes participating in the signature this time;

[0015] The reputation-based distributed oracle authentication system executes corresponding incentive strategies according to the type differences of node signatures. For the dual functions of verification and aggregation of the leader nodes, an additional incentive is issued to them;

[0016] The reputation-based distributed oracle authentication system includes an appeal mechanism for nodes using threshold signatures, enabling child nodes to file appeals in cases where the leader nodes distribute rewards unfairly;

[0017] The distributed oracle network uses a Merkle tree to verify the data source.

[0018] As a further improvement of the present invention, the distributed oracle network elects leader nodes through a verifiable random function and adopts a fair leader node rotation mechanism, which includes the following steps:

[0019] Step 1: System initialization. Set a reputationi with an initial value of 0 for all nodes, and define the election period T and the minimum reputation scoring threshold reputataion min , the maximum reputation scoring threshold reputataion max ;

[0020] Step 2: Trigger the first leader node election. The system generates a random number through a verifiable random function (VRF) to determine the leader node in the first round.

[0021] Step 3: The system maps the generated VRF random number to the node list and selects a node as the first leader node. The specific mapping method can be set according to the number of nodes as: random number % total number of nodes = serial number of the selected node.

[0022] Step 4: Each node uses the VRF result to verify the legality of the election process to ensure that the selected node is truly random and fair. Once selected, the smart contract records this node as the current leader node until the next cycle starts.

[0023] Step 5: The on-chain smart contract sends a request to the leader node, specifies the required signature type, and clearly requires the minimum reputation value that the nodes participating in processing this request need to reach. The leader node then notifies the message to the distributed oracle network.

[0024] Step 6: The distributed oracle network obtains data from the data source. The data source returns the result to the distributed oracle network. The nodes in the distributed oracle network use the signatures required by the contract to calculate and verify the result respectively.

[0025] Step 7: The leader node accepts the signatures related to the reputation value from other nodes, records the submitted node ID and timestamp, aggregates according to the used signatures and judges whether the signatures are valid. Subsequently, the leader node aggregates the result and the signature and returns them to the on-chain contract.

[0026] Step 8: The on-chain contract verifies the legality of the result based on the result of this group of data, the public key set, and the final signature, thereby proving the correctness of the data acquisition result. If the result passes, the report of the leader node leader increases, otherwise it decreases, and adjusts the effective reporting function report of these nodes in this round according to the behavior of the nodes in this time. i ;

[0027] Step 9: After T periods have passed, incentives are first distributed to all nodes, and then a new round of election starts. At this time, the reputation value of the nodes is calculated according to the effective reporting function of the nodes. Subsequently, the child nodes are sorted from high to low according to the reputation value. The node with the highest reputation value among the child nodes uses the verifiable secret sharing Byzantine fault-tolerant Raft consensus algorithm for election. If the election fails, it switches to the next child node.

[0028] Step 10: When the reputation value of a node in the distributed oracle network is lower than the minimum reputation score threshold reputataion min then the exit of the node is executed.

[0029] As a further improvement of the present invention, a node valid report function is introduced, including the valid report function of the leader node, the valid report function of the threshold signature sub-node, and the valid report function of the multi-signature sub-node:

[0030] The valid report function of the leader node is:

[0031]

[0032] Wherein, represents the valid report function of the leader node within the current work cycle T, The initial value of is 0, T represents the cycle of the sub-node work in this round, j represents the jth generation result of the leader node within the cycle T of this round, and t j represents the time spent by the leader node for the jth generation result, and S i represents whether the leader node generates a correct signature and passes the on-chain verification for the jth time. If the signature is successfully generated and passes the on-chain verification, it is 1; otherwise, it is 0 for other cases. α is the increased weight;

[0033] The valid report function of the threshold signature sub-node is:

[0034]

[0035] Wherein, represents the valid report function of sub-node i within the current work cycle T. The initial value of is 0, T represents the cycle of the sub-node work in this round, j represents the jth generation result of the sub-node within the cycle T of this round, and t j represents the time spent by the sub-node for the jth generation result. If ≥t signatures have been collected and verify = 1, it means that the threshold signature has been correctly generated by the system when the jth generation result is obtained, and it will not be included in the scoring. V i represents whether the sub-node correctly generates the result and passes the on-chain verification for the jth time. If the result is successfully generated and passes the on-chain verification, it is 1; otherwise, it is -1 for other cases. α is the increased weight, and β is the deducted weight;

[0036] The valid report function of the multi-signature sub-node is:

[0037]

[0038] Wherein, represents the valid report function of sub-node i within the current work cycle T, The initial value of is 0, T represents the cycle of the sub-node work in this round, the waiting time of the leader node is t, j represents the jth generation result of the sub-node within the cycle T of this round, and t jRepresents the time taken for the j-th generation result of the child node. If t j > t and verify = 1, it means that the node did not submit the public key and signature within the waiting time t of the leader node, so it is not included in the scoring, V i Represents whether the j-th generation result of the child node is correctly generated and passes the on-chain verification. If the result is successfully generated and passes the on-chain verification, it is 1; otherwise, it is -1. α is the increased weight, and β is the deducted weight.

[0039] As a further improvement of the present invention, the reputation scoring formula of the nodes in the distributed oracle network including a reputation-based dynamic scoring and node management mechanism is:

[0040] Reputation incentive formula:

[0041]

[0042] Reputation penalty formula:

[0043]

[0044] Represents the reputation of node i during the n-th round of work. r is the absolute value of the effective reporting function of the node. If this value is greater than 0, it is determined that the node has positive network contribution behavior in the previous evaluation period, and the reputation incentive function is triggered. If this value is less than zero, it is determined that the node has malicious network behavior, and the reputation penalty function is triggered. If it is equal to 0, it is determined that the node is in a low activity state, and the node penalty function is triggered. x and y are the reputation incentive coefficient and reputation penalty coefficient respectively, and the default value is 1. Represents the historical average reputation value of the node, reputation max and reputation min are the maximum reputation value and minimum reputation value of the node respectively. When the reputation of the node approaches reputation max , the reputation value is more difficult to increase and finally converges to reputation max . When the node performs malicious value behavior, for nodes with higher reputation values, the penalty is greater. If it finally drops below reputation min , it will be excluded from the oracle network.

[0045] As a further improvement of the present invention, the determination of the historical reputation of the node includes:

[0046] The initial values of x and y in the reputation scoring formula are 1. Assume that the node has experienced n rounds of work. Let \(R_{i,k}\) denote the reputation value of node \(i\) in the \(k\)-th round, where \(k = 1, 2, 3, \cdots, n\). \(\gamma\) and \(\lambda\) are adjustment coefficients. The greater the historical reputation of a node, the larger \(x\) is when the oracle's effective reporting function increases. When the oracle's effective reporting function decreases, the penalty for high-reputation nodes should be increased, so \(y\) is also larger.

[0047]

[0048] As a further improvement of the present invention, when using threshold signature based on BLS, private key shards are allocated according to the reputation value of nodes. The higher the reputation value of a node, the more private key shards it obtains, including the following steps:

[0049] Step 1: The on-chain contract designates the use of threshold signature, gives the threshold value \(t\), and sends a request to the distributed oracle network;

[0050] Step 2: Generate the public parameters required by the system, \(G\) 1 、\(G\) 2 、\(G\) T are multiplicative cyclic groups of prime order \(p\), and the generators are \(g\) 1 and \(g\) 2 , the bilinear pairing \(e: G\) 1 ×\(G\) 2 →\(G\) T , \(H\) is a hash function mapping to \(G\) 1 , and the public parameter \(\eta=(G\) 1 , \(G\) 2 , \(G\) T , \(p\), \(g\) 1 , \(g\) 2 , \(e\), \(H)\);

[0051] Step 3: Generate the master private key and master public key of the distributed oracle network, calculate the private key and public key of each node respectively. The master private key of the leader node \(MSK = x\), where \(x\) is a random number selected by the system. The master public key of the leader node: Randomly select a polynomial \(P\) of degree \(t - 1\) over \(\mathbb{Z}\) p such that \(P(0)=x\);

[0052] Step 4: Suppose there are \(n\) nodes in the distributed oracle network participating in aggregation, \(i\in\{1, 2, \cdots, n\}\), and calculate the weight of node \(i\) as The higher the reputation value of a node, the higher its weight. In the BLS algorithm, the prime number \(p\) is much larger than the weight \(w\) i , so nodes with different weights will not collide;

[0053] Step 5: The number of private key shards \(k\) i obtained by node \(i\) is \(k\) i \(=w\) i \(\geq1\),

[0054] Step 6: Set a sequence For each node i, allocate k i index points to generate private key shards from the polynomial P(x);

[0055] Step 7: Calculate the X of each node i As the private key of node i, each node obtains private key shards of different sizes according to the reputation value X i , The calculation formula is as follows,[[]] as the public key of node i;

[0056]

[0057] Step 8: Node i uses the private key shards it owns to calculate the signature for the message m one by one: and aggregate them into Subsequently, the node will and ∑ i submit to the leader node;

[0058] Step 9: The leader node first verifies the signatures received from the child nodes and records the passed signatures. After receiving the results submitted by node i, the leader node first verifies the correctness of the signatures:

[0059] e(∑ i , g 2 ) = e(H(m), v i ),

[0060] If the equation holds, the verification passes, and record the signatures collected so far through K = K + k i ;

[0061] Step 10: Verify the threshold signature: When the K signatures collected are greater than or equal to the threshold value t, the leader node aggregates and verifies the complete threshold signature;

[0062] where

[0063] According to the Lagrange interpolation formula, the complete signatures generated by any t or more signatures are the same. Verify the signature: verify(σ, m, v) → (0, 1)

[0064] e(σ, g 2 ) = e(H(m), g 2 x )

[0065] If the equation holds, it is a correct threshold signature; otherwise, the verification fails.

[0066] As a further improvement of the present invention, when performing multiple signatures based on BLS, the weights of nodes participating in aggregation are determined according to the reputation values of the nodes. The on-chain contract can require a minimum threshold for the sum of the weights of the nodes participating in the signature this time, including the following steps:

[0067] Step 1: The on-chain contract designates the use of multiple signatures and gives the minimum sum of reputations R of the nodes participating this time, and sends a request to the distributed oracle network;

[0068] Step 2: Generate the public parameters required by the system. This scheme is based on the bilinear mapping e: G 1 ×G 2 =G t where G 1 , G 2 , G t are all groups of prime order q, g 1 and g 2 are the generators of G 1 and G 2 respectively, and there are hash algorithms H 0 :{0,1} * →G 1 , H 2 :{0,1} * →G 1 such that the calculated hash value is an element in the group G 1 , H 1 :{0,1} * →Z q

[0069] such that the calculated hash value is an element in the group Z q , and set the fixed waiting time t for the leader node;

[0070] Step 3: Key generation: Construct the bilinear pair system parameters par←(q, G 1 , G 2 , G t , e, g 1 , g 2 ), and generate a pair of key pairs for each node i in the distributed oracle, the private key sk i , public key pk i :

[0071]

[0072] Step 4: Suppose there are n nodes in the distributed oracle, i∈{1, 2,..., n}, calculate the weight of node i as The higher the reputation value of a node, the higher its weight. In the BLS algorithm, the prime number p is much larger than the weight w i , so nodes with different weights will not collide. Finally, round it up, and represent the weights of all nodes with a vector .

[0073] Step 5: All nodes in the system send their public keys and signatures to the leader node for aggregation. The leader node accepts the signatures and public keys from the child nodes and records: In the distributed oracle network, the child node sends its signature σ i and public key pk i to the leader node, and counts the nodes participating in the calculation within the waiting time T. There are n nodes in the distributed oracle network, is a vector of length n with an initial value of 0. When node i sends its signature and public key to the leader node within the waiting time T, b i = 1, is the list of public keys of all nodes generated by the leader node's statistics, with an initial value of 1;

[0074]

[0075] a i = H 1 (pk i ,{pk 1 ,…,pk n )

[0076]

[0077] Step 6: The leader node checks whether the reputation values of the participating nodes meet the requirements of the contract for reputation values, is a vector composed of the reputation values of all nodes in the distributed oracle. If indicates that the sum of the reputation values of the nodes participating in the calculation this time meets the requirements of the on-chain contract for reputation values, otherwise reset the waiting time T;

[0078] Step 7: The leader node performs aggregation to generate an aggregated signature σ and an aggregated public key apk;

[0079]

[0080] Step 8: The on-chain smart contract verifies the correctness of the multi-signature. If the equation holds, it is a correct multi-signature, otherwise the verification fails. verify(σ,m,apk)→(0,1)

[0081]

[0082] As a further improvement of the present invention, corresponding incentive policies are implemented for different types of node signatures. For the dual functions of verification and aggregation of the leader node, an additional incentive is provided, including the following steps:

[0083] The leader node receives an additional reward each time it successfully passes the on-chain verification:

[0084]

[0085] Since the leader node needs to perform additional verification, the leader node will receive an additional incentive. After each aggregation of signatures by the leader node and confirmation through the on-chain contract, an additional incentive will be given to the leader node. C represents the consumption cost of on-chain verification, which can be adjusted according to the actual situation. represents the average value of the node's historical reputation. As the node's reputation value continuously increases, gradually increases and finally approaches 1;

[0086] When the reputation value of the node increases after the end of a round of election cycle, the incentive for the execution node is as follows:

[0087]

[0088] Given the current available incentive pool I of the system total , the incentive is distributed after each round of work cycle is completed. represents the incentive received by node j in the Kth round. is the incentive coefficient a. n represents which round of incentive distribution is currently in progress, with an initial value of 1. Considering the node's historical reputation value and the maximum reputation value, when the incentive is distributed to the node for the first time, the past reputation value does not exist, n is 1, and the value of a is 1. As the node participates in multiple rounds of incentive distribution, a gradually becomes greater than 1. The greater the gap between the initial reputation value and the maximum reputation value, the greater a is. As the node's reputation value gradually approaches the maximum reputation value, a gradually returns to 1. represents the ratio of the reputation value of node j at the Kth round to the sum of the reputation values of all nodes. N is the number of all nodes in the current system;

[0089] When the reputation value of the node decreases after the end of a round of election cycle, the node will not receive an incentive in this round;

[0090] The incentive method for the threshold signature node includes the following steps:

[0091] The leader node receives an additional reward each time it successfully passes the on-chain verification:

[0092]

[0093] Since the leader node needs to perform additional verification, the leader node will receive an additional incentive. After each leader node aggregates the signature and is confirmed by the on-chain contract, the leader node will receive additional incentives. C represents the consumption cost of on-chain verification, which can be adjusted according to actual conditions. It represents the average value of the node's historical reputation. As the node's reputation value increases, It gradually increases and eventually approaches 1;

[0094] After a round of election cycle, the system will count the nodes with increased reputation and distribute all the incentives to the leading nodes. After the leading nodes are incentivized, they must first submit 120% of the collateral of the incentives to the smart contract. If the distribution is illegal, the collateral will be confiscated. Then the incentives will be distributed to the child nodes. After the distribution is completed, the collateral will not be unlocked until the appeal period ends.

[0095]

[0096] I send represents the total incentives sent by the system to the leader node, and m represents the number of nodes that should be incentivized.

[0097]

[0098] The currently available incentive pool I for a given leader node send , incentives are issued after each round of work cycle is completed, represents the incentive received by node j in round K, is the incentive coefficient a, n indicates the number of the current round of incentive issuance, the initial value is 1, taking into account the historical reputation value and maximum reputation value of the node, when the node issues incentives in the first round, the past reputation value does not exist, n is 1, and the value of a is 1. As the node participates in multiple rounds of incentive issuance, a gradually increases. The greater the gap between the initial reputation value and the maximum reputation value, the larger a becomes. As the reputation value of the node gradually approaches the maximum reputation value, a gradually returns to 1. It represents the ratio of the reputation value of node j in the Kth round to the sum of the reputation values ​​of all nodes.

[0099] As a further improvement of the present invention, the appeal mechanism of the threshold signature node includes the following steps:

[0100] Step 1: All participating nodes have the right to submit objections to the distribution results of the aggregation node through the appeal channel specified in the smart contract before the task is completed and the rewards are issued;

[0101] Step 2: The complaint submission period is limited to the time window predetermined by the smart contract, and the complainant is required to provide supporting materials including but not limited to contribution data, signature submission records, etc.

[0102] Step 3: Set the appeal ratio threshold. When more than 30% of the participating nodes submit an appeal, the system automatically determines that there is an unfair distribution problem with the aggregation node, triggers an appeal, and audits the distribution behavior of the aggregation node.

[0103] Step 4: Based on the pre-set distribution rules and arbitration results, the smart contract makes a judgment to confirm whether there are any violations by the aggregation node.

[0104] Step 5: According to the ratio of the appealing nodes, deduct the corresponding proportion of the collateral of the leading node as compensation and distribute it to the appealing nodes.

[0105] Step 6: Set the reputation value of the node to reputation min

[0106] As a further improvement of the present invention, the distributed oracle network uses a Merkle tree to verify the data source, including the following steps:

[0107] Step 1: Each oracle node obtains data from an external data source, performs a hash operation on each piece of data or each data block to generate leaf nodes, and the hash values of these leaf nodes will serve as the base layer of the Merkle tree.

[0108] Step 2: Combine the hash values of the leaf nodes in pairs and calculate the hash value again to form new parent nodes. Continuously repeat this process until a unique root hash value (Merkle root) is obtained, representing the unique identifier of the entire data set.

[0109] Step 3: Calculate the Merkle root. The Merkle root generated by each node represents the unique hash value of the complete data set obtained by it from the data source.

[0110] Step 4: All oracle nodes broadcast their Merkle roots to other nodes through the leading node, so that the nodes in the system can mutually verify the correctness of the Merkle root.

[0111] Step 5: All nodes in the system compare their respective Merkle roots with each other to check if they are consistent. If the root hash values are consistent, it means that the data obtained by each node is the same and the data has not been tampered with. Subsequently, the distributed oracle network uploads the finally confirmed consistent Merkle root to the chain through the leading node as a public record of the verification result. Users or other systems can verify the integrity of the data through the root hash stored on the chain. In subsequent data verification, anyone can use the Merkle path to verify whether a specific data block belongs to the confirmed data set, enhancing the transparency and security of the system.

[0112] Step 6: If there is an inconsistency, it indicates that some nodes may have received different data or the data has been tampered with, and it is necessary to further verify the data sources of these nodes.

[0113] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0114] The beneficial effects of the present invention are as follows: First, by adopting two different signature mechanisms, the system can select the most suitable signature strategy according to the different requirements of specific scenarios, thereby optimizing performance, enhancing security, and meeting the specific requirements of different applications. The threshold signature mechanism provides strong security. The system can still operate normally even when some nodes fail or are malicious. And through weight allocation, nodes with higher reputation values have higher priorities in the signature process, further improving the anti-attack ability of the system. Multiple signatures reduce bandwidth and computational overhead through aggregated signatures and improve the credibility of the signature results. The weight mechanism is dynamically allocated based on the reputation values of nodes, motivating high-reputation nodes to provide higher-quality data, while marginalizing malicious or low-reputation nodes, thereby enhancing the fairness and decentralization characteristics of the system. The fault tolerance and robustness of the system are also enhanced because even if nodes fail or refuse to participate, the reliability of the data can still be guaranteed. Through reputation scoring and dynamic management, the system can flexibly adapt to the joining and leaving of nodes, avoiding the single-point control problem. Overall, this design takes into account efficiency, security, and fairness, and adapts to the high-efficiency and decentralized distributed oracle application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0115] Figure 1 It is a schematic structural diagram of a distributed oracle authentication system based on reputation scoring in an embodiment of the present invention;

[0116] Figure 2 It is the election process of the first leader node and subsequent leader nodes in an embodiment of the present invention;

[0117] Figure 3 It is the relationship between the effective report values, reputation values, incentive values, and historical reputation values of the leader node and sub-nodes in an embodiment of the present invention;

[0118] Figure 4 It is the process of selecting a signature and updating the reputation value after going through an election cycle in an embodiment of the present invention;

[0119] Figure 5 It is the process of verifying the consistency of data sources using a Merkle tree in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0120] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. The following embodiments are used to illustrate the present invention but are not used to limit the scope of the present invention.

[0121] The present invention provides a distributed oracle authentication system based on reputation scoring, such as Figure 1 As shown, it includes three entities: distributed oracle network, blockchain and data source, and specifically includes the following steps:

[0122] In a distributed oracle network, the oracle node listens to the requests of the user contract in the blockchain, and calls the oracle contract through the user contract, so that the oracle node is activated. When the oracle node is called, it starts to access the data source and send a request message to it to obtain the data from the data source. Subsequently, the oracle node uploads the data obtained from the data source to the specified user contract on the private chain of the blockchain.

[0123] The user initiates a request for data from the data source by calling the contract to send the data request. After the data is returned from the data source to the blockchain network through the oracle node, the user contract will parse the data and display it to the data user through the system's user interface.

[0124] In this embodiment, the user can access the blockchain network through JavaScript scripts or blockchain clients, and call the user contract to initiate a data request by entering a specified user contract address in the script, or selecting a specific user contract through the user front-end graphical interface. Data users can also call smart contracts through specific interfaces and use function libraries (such as web3.js, web3.py or truffle framework) to complete the data request function.

[0125] Furthermore, the data provider uses Python scripts to pre-process the collected IoT data before uploading it to the blockchain, including size comparison, data screening, homomorphic encryption, etc. The processed data is then uploaded to the cloud server built by the data provider.

[0126] The cloud server built by the data source will provide an open API network address to receive data requests from the oracle node and send response messages to the oracle node.

[0127] In order to monitor the data acquisition requests of user contracts in the blockchain network, a polling method is used to process the requests.

[0128] Initialization of the distributed oracle network. The system ensures the fairness of the network through a fair leader node rotation mechanism. Inside the distributed oracle network, a verifiable random function (VRF) is used to elect leader nodes, and a dynamic scoring mechanism is combined to manage the reputation of each node. Initially, the reputation values of all nodes are set to 0.

[0129] Reputation scoring and dynamic node management. The system performs dynamic reputation scoring on oracle nodes based on their historical behaviors. The reputation scoring is based on the following factors: the number of valid reports completed by the node within a specified period, participation in data verification and signature generation, historical performance, etc. The reputation score determines whether a node can continue to participate in network activities and affects the node's reward and punishment mechanisms. Only nodes with reputation values reaching the minimum requirement can participate in the processing of the current data request. If a node's reputation value is below the threshold, it will be removed temporarily or permanently.

[0130] Users on the blockchain send data requests to the distributed oracle network by calling smart contracts. The smart contract broadcasts the data request to the leader nodes in the network and allows users to specify the required signature type (such as threshold signature, multi-signature, or aggregated signature) in the contract, as well as the minimum reputation value that the nodes participating in processing this request must reach. The contract can also specify the time limit requirement for data acquisition.

[0131] Once receiving the request from the smart contract, the leader node sends the request to other oracle nodes via broadcast and determines which nodes participate in the data acquisition process. All participating nodes obtain the requested data from the data source. After receiving the access request, the data source returns the result to the oracle network. To ensure the authenticity and integrity of the data, the system uses a Merkle tree to verify the data source and ensure that the returned data has not been tampered with.

[0132] Multiple oracle nodes in the network process the acquired data and generate corresponding signatures based on their respective weight values. Each signature will be linked to the node's reputation value. The higher the node's reputation value, the greater the weight of the signature it generates. After multiple nodes generate signatures, they are packaged together with the data and sent to the leader node.

[0133] After receiving the data and signatures from each oracle node, the leader node first checks the integrity of the data and the legality of the signatures. For signatures that meet the requirements, the leader node performs aggregation (which may be threshold signature, multi-signature according to the pre-set signature type). Subsequently, the leader node returns the aggregated result and the corresponding public key set to the smart contract on the chain. The contract performs data verification based on the data, signatures, and public key set provided by the leader node to confirm the legality and validity of the result.

[0134] After the smart contract on the chain receives the data, signature, and public key set returned by the leader node, the contract verifies the legality of the data. If the verification passes, the contract will prove the correctness of the data acquisition and store the verification result on the blockchain to ensure the traceability and immutability of the data source.

[0135] According to the performance of each node in this data verification process, the system will adjust the reputation of the node accordingly. Nodes that successfully generate valid signatures will have their reputation values increased accordingly and have the opportunity to receive blockchain rewards; conversely, the node's reputation will decline and it may face the penalty of being removed from the oracle network. Based on the reputation values of the nodes, the system will also execute reward and punishment mechanisms to encourage nodes to participate in high-quality data processing tasks and ensure the stable operation of the network.

[0136] Among them, the oracle is a distributed oracle. This application realizes the authentication of blockchain network data by using a distributed oracle, which can resist various malicious attacks and prevent single-point failure problems during the data link process. Further, based on the equal-probability random selection algorithm of reputation values, after a certain period of time, the nodes will re-elect the leader node, improving fairness. Further, the reputation value of a node not only affects its participation degree in the signature process but also determines its weight distribution in threshold signatures and multi-signatures. In threshold signatures, nodes with higher reputation values can obtain more private key fragments and thus have greater influence when generating the final signature; in multi-signatures, the reputation value of a node directly affects its signature weight. The higher the reputation, the greater the signature weight, and the final signature result will be more affected by high-reputation nodes. Such a design effectively guides the behavior of nodes, prompting nodes to remain honest and efficient throughout the network, thereby enhancing the security and reliability of the entire system.

[0137] Further, after the authentication system receives the contract request for the first time, it performs system initialization, as Figure 2 shown:

[0138] During system initialization, an initial reputation value reputation is assigned to all participating oracle nodes i , and the initial value is set to 0. The system also needs to set the election period T, that is, the rotation period of the leader node; at the same time, the minimum reputation score threshold reputation min and the maximum reputation score threshold reputation max are defined. These two thresholds are used to determine whether a node can participate in the next round of authentication process and whether it is eligible to become the leader node. The reputation score of a node will be dynamically adjusted according to its behavior during the operation of the system.

[0139] The system generates a random number through VRF (Verifiable Random Function) to determine the leader node in the first round. VRF can generate a verifiable and fair random number, ensuring that the leader node election process is random and fair. This random number will play a key role in the subsequent node mapping process. According to the generated VRF random number, the system maps it to the node list. The mapping rule is: random number % total number of nodes = serial number of the selected node. In this way, the system can fairly select a node from all nodes as the first leader node.

[0140] All nodes use the VRF result to verify the legality of the leader node election process, ensuring that the elected leader node is random and fair. Nodes verify to ensure that no node maliciously manipulates the election result. Once the election result is confirmed, the smart contract will record the current leader node and mark it as the leader node for this cycle until the next election cycle begins.

[0141] On the blockchain, users initiate data requests to the distributed oracle network through smart contracts. The contract will specify the required signature type and clearly require the minimum reputation value that the nodes participating in processing this request must reach. After receiving the contract request, the leader node will notify the entire distributed oracle network and require the nodes to respond according to the requirements in the contract.

[0142] Nodes in the distributed oracle network will obtain the required data from the data source according to the requirements of the smart contract. After receiving the request, the data source returns the result to the oracle network. All oracle nodes calculate and verify the result according to the signature type required by the contract. Each node will process the data according to its own judgment and generate relevant signatures to ensure the correctness of the data source and content. After receiving the signature information from other nodes, the leader node aggregates according to these signatures to judge whether the signatures are valid. The verified signatures will be aggregated with the data to form the final data verification result. The aggregated data and signatures will be returned to the smart contract on the chain for verification.

[0143] After receiving the aggregated data, public key set and final signature, the smart contract on the chain conducts a legality verification of the result. The contract confirms its legality by comparing the signature, public key set and the returned data. If the verification passes, it proves that the data acquisition result is correct. At this time, the valid report value report of the leader node leader will increase, and the valid report value report of the nodes participating in the calculation i will also increase. If the result fails the verification, the report of the node participating in the calculation i will decrease.

[0144] After the cycle T ends, the system adjusts the effective reporting function report of each node according to the behavior of the node in this round i , so as to calculate the reputation value reputation of the node i . Then, corresponding incentives are distributed according to the performance of each node in this cycle. The relationships among the effective reporting value, reputation value, incentive value, and historical reputation value are as Figure 3 shown

[0145] Furthermore, in the method of the distributed oracle authentication system based on reputation scoring, users can select different signatures according to their needs and combine the reputation mechanism to determine the degree of each node's participation in the signature. As Figure 4 shown

[0146] The contract specifies the signature type (threshold signature or multi-signature) by sending a request. The contract can dynamically select the signature method to ensure that the system is adjusted according to the requirements. After the system receives the request from the contract, the distributed oracle network will start to execute the corresponding signature process according to this request

[0147] The reputation value of a node directly affects its degree of participation in the signature process. The higher the reputation value of a node, the more private key fragments or higher weights it can obtain. When the leader node receives the signatures submitted by each node, it first verifies and aggregates them, and then verifies the correctness of the final signature according to the signature type. According to the performance of the node in the signature process, the on-chain contract will update its effective reporting function, thereby adjusting the reputation value of the node. The effective reporting function of a node reflects its performance in the current cycle T, and after the election cycle ends, the final reputation value of the node will be calculated and updated based on this performance. The reputation value of a node is a comprehensive reflection of its performance in all historical cycles

[0148] Furthermore, in the method of the distributed oracle authentication system based on reputation scoring, the effective reporting function of the leader node is

[0149]

[0150] where represents the effective reporting function of the leader node in the current working cycle T of this round The initial value of is 0, T represents the cycle of the sub-node work in this round, j represents the jth time the leader node generates a result in the cycle T of this round, and t j represents the time spent by the leader node to generate the jth result. S i represents whether the leader node generates a correct signature and passes the on-chain verification for the jth time. If the signature is successfully generated and passes the on-chain verification, it is 1, otherwise it is 0 for other cases. α is the increased weight

[0151] Further, for the method of the distributed oracle authentication system based on reputation scoring, the effective reporting function of the threshold signature sub-node is:

[0152]

[0153] where represents the effective reporting function of sub-node i within the current working cycle T. The initial value of is 0, T represents the cycle of the sub-node's work in this round, j represents the jth time the sub-node generates a result within the cycle T of this round, and t j represents the time taken for the sub-node to generate the jth result. If ≥ t signatures have been collected and verify = 1, it means that the threshold signature has been correctly generated by the system when the jth result is generated, and the score is not counted. V i represents whether the sub-node correctly generates the result and passes the on-chain verification at the jth time. If the result is successfully generated and passes the on-chain verification, it is 1; otherwise, it is -1 in other cases. α is the increased weight, and β is the deducted weight.

[0154] Further, for the method of the distributed oracle authentication system based on reputation scoring, the effective reporting function of the multi-signature sub-node is:

[0155]

[0156] where represents the effective reporting function of sub-node i within the current working cycle T. The initial value of is 0, T represents the cycle of the sub-node's work in this round, the waiting time of the leader node is t, j represents the jth time the sub-node generates a result within the cycle T of this round, and t j represents the time taken for the sub-node to generate the jth result. If t j > t and verify = 1, it means that the node does not submit the public key and signature within the waiting time t of the leader node, and the score is not counted. V i represents whether the sub-node correctly generates the result and passes the on-chain verification at the jth time. If the result is successfully generated and passes the on-chain verification, it is 1; otherwise, it is -1 in other cases. α is the increased weight, and β is the deducted weight.

[0157] Further, for the method of the distributed oracle authentication system based on reputation scoring, the reputation scoring formula of the node:

[0158] Reputation incentive formula:

[0159]

[0160] Reputation penalty formula:

[0161]

[0162] It represents the reputation of node i during the nth round of operation. r is the absolute value of the effective reporting function of the node. If this value is greater than 0, it is determined that the node has positive network contribution behavior in the previous evaluation period, and the reputation incentive function is triggered. If this value is less than zero, it is determined that the node has malicious network behavior, and the reputation penalty function is triggered. If it is equal to 0, it is determined that the node is in a low activity state, and the node penalty function is triggered. x and y are the reputation incentive coefficient and the reputation penalty coefficient respectively, and the default value is 1. It represents the historical average reputation value of the node, reputation max and reputation min are the maximum reputation value and the minimum reputation value of the node respectively. When the reputation of the node approaches reputation max , it is more difficult for the reputation value to increase, and finally converges to reputation max . When the node performs malicious value behavior, for nodes with higher reputation values, the penalty is greater. If it finally drops below reputation min , it will be removed from the oracle network.

[0163] Furthermore, in the method of the distributed oracle authentication system based on reputation scoring, x and y in the reputation scoring formula are determined by the historical reputation of the node. The method includes:

[0164] The initial values of x and y in the reputation scoring formula are 1. Suppose the node has experienced n rounds of operation. It represents the reputation value of node i in the kth round, where k = 1, 2, 3,..., n. γ and λ are adjustment coefficients respectively. The greater the historical reputation of the node, the greater x is when the effective reporting function of the oracle increases. And when the effective reporting function of the oracle decreases, the penalty for high-reputation nodes should be increased, so y is also greater.

[0165]

[0166] It should be noted that the node effective reporting function is to evaluate the number of valid votes cast by the node within a period T. It is updated in real time according to the performance of the node during the period T. When a period ends, the reputation value is calculated based on the node's effective reporting function, and then incentives are distributed according to the reputation value. Finally, the effective reporting functions of all nodes are reset to 0, and the next round of period election begins.

[0167] Further, for the method of the distributed oracle authentication system based on reputation scoring, when using threshold signature based on BLS, private key shards are allocated according to the reputation values of nodes. The higher the reputation value of a node, the more private key shards it obtains, including the following steps:

[0168] Step 1: The on-chain contract designates the use of threshold signature, gives the threshold value t, and sends a request to the distributed oracle network.

[0169] Step 2: Generate the public parameters G 1 、G 2 、G T which are multiplicative cyclic groups of prime order p, with generators g 1 and g 2 respectively, and a bilinear pairing e: G 1 ×G 2 →G T , H is a hash function mapping to G 1 , and the public parameters η = (G 1 , G 2 , G T , p, g 1 , g 2 , e, H).

[0170] Step 3: Generate the master private key and master public key of the distributed oracle network, and calculate the private key and public key of each node respectively. The master private key of the leader node MSK = x, where x is a random number selected by the system, and the master public key of the leader node: Randomly select a polynomial P of degree t - 1 over Z p such that P(0) = x.

[0171] Step 4: Suppose there are n nodes in the distributed oracle participating in aggregation, i ∈ {1, 2,..., n}, and calculate the weight of node i as The higher the reputation value of a node, the higher its weight. In the BLS algorithm, the prime number p is much larger than the weight w i , so nodes with different weights will not collide.

[0172] Step 5: The number of private key shards k i allocated to node i i = w i ≥ 1,

[0173] Step 6: Suppose the sequence For each node i, allocate k i index points for generating private key shards from the polynomial P(x).

[0174] Step 7: Calculate X for each node iAs the private key of node i, each node obtains a private key shard X of different sizes according to the reputation value i , The calculation formula is as follows As the public key of node i

[0175]

[0176] Step 8: Node i uses the private key shards it owns to calculate the signature of message m one by one And aggregate them into Subsequently, the node will And ∑ i Submit to the leader node

[0177] Step 9: The leader node first verifies and records the passed signatures after receiving the signatures from the child nodes. After receiving the results submitted by node i, the leader node first verifies the correctness of the signature

[0178] e(∑ i , g 2 ) = e(H(m), v i ),

[0179] If the equation holds, the verification passes. Record the signatures collected so far through K = K + k i

[0180] Step 10: Verify the threshold signature: When the K signatures collected are greater than or equal to the threshold value t, the leader node aggregates and verifies the complete threshold signature

[0181] Among them

[0182] It can be seen from the Lagrange interpolation formula that the complete signatures generated by any t or more signatures are the same. Verify the signature: verify(σ, m, v) → (0, 1)

[0183] e(σ, g 2 ) = e(H(m), g 2 x )

[0184] If the equation holds, it is a correct threshold signature; otherwise, the verification fails

[0185] ​Further, for the method of the distributed oracle authentication system based on reputation scoring, when using BLS-based multi-signature, the weight of each node participating in aggregation is determined according to its reputation value. The higher the reputation value of a node, the higher its weight in aggregation. The smart contract on the chain can require a minimum threshold for the sum of the weights of the nodes participating in the signature this time, and the method includes the following steps:

[0186] Step 1: The smart contract on the chain designates the use of multi-signature, and gives the minimum reputation sum R of the nodes participating this time, and sends a request to the distributed oracle network.

[0187] Step 2: Generate the public parameters required by the system. This scheme is based on the bilinear mapping e: G 1 ×G 2 =G t where G 1 , G 2 , G t are all groups of prime order q, g 1 and g 2 are the generators of G 1 and G 2 respectively, and there are hash algorithms J 0 :{0,1} * →G 1 , H 2 :{0,1} * →G 1 such that the calculated hash value is an element in the group G 1 , H 1 :{0,1} * →Z q

[0188] such that the calculated hash value is an element in the group Z q , and set the fixed waiting time t of the leader node.

[0189] Step 3: Key generation: Construct the bilinear pairing system parameters par←(q, G 1 , G 2 , G t , e, g 1 , g 2 ), and generate a pair of key pairs for each node i in the distributed oracle, the private key sk i and the public key pk i :

[0190]

[0191] Step 4: Suppose there are n nodes in the distributed oracle, i ∈ {1, 2,..., n}, calculate the weight of node i as The higher the reputation value of a node, the higher its weight. In the BLS algorithm, the prime number p is much larger than the weight w i , so nodes with different weights will not collide. Finally, round it up, and represent the weights of all nodes with a vector .

[0192] Step 5: All nodes in the system send their public keys and signatures to the leader node for aggregation. The leader node accepts the signatures and public keys from the child nodes and records: In the distributed oracle network, the child node sends its signature σ i and public key pk i to the leader node, and counts the nodes participating in the calculation within the waiting time T. There are n nodes in the distributed oracle network, is a vector of length n with an initial value of 0. When node i sends its signature and public key to the leader node within the waiting time T, b i = 1. is the list of public keys of all nodes statistically generated by the leader node, with an initial value of 1.

[0193]

[0194] a i = H 1 (pk i ,{pk 1 ,…,pk n )

[0195]

[0196] Step 6: The leader node checks whether the reputation values of the participating nodes meet the requirements of the contract for reputation values. is a vector composed of the reputation values of all nodes in the distributed oracle. If indicates that the sum of the reputation values of the nodes participating in the calculation this time meets the requirements of the on-chain contract for reputation values, otherwise reset the waiting time T.

[0197] Step 7: The leader node performs aggregation to generate an aggregated signature σ and an aggregated public key apk.

[0198]

[0199] Step 8: The on-chain smart contract verifies the correctness of the multi-signature. If the equation holds, it is a correct multi-signature, otherwise the verification fails. verify(σ, m, apk) → (0, 1)

[0200]

[0201] Furthermore, the incentive method for the nodes of the method includes the following steps:

[0202] For the incentive method of multi-signature nodes, the leading node obtains an additional reward every time it successfully passes the on-chain verification:

[0203]

[0204] Since the leading node has to perform additional verification, the leading node will receive an additional incentive. After each aggregation signature of the leading node is confirmed and passed by the on-chain contract, an additional incentive will be given to the leading node. C represents the consumption cost of on-chain verification, which can be adjusted according to the actual situation. represents the average value of the node's historical reputation. As the reputation value of the node continues to increase, gradually increases and finally approaches 1.

[0205] When the reputation value of the node increases after the end of a round of election cycle, execute the incentive for the execution node:

[0206]

[0207] Given the current available incentive pool I of the system total , the incentive is distributed after each round of work cycle is completed. represents the incentive received by node j in the Kth round. is the incentive coefficient a, n represents which round of incentive distribution is currently in progress, with an initial value of 1. Considering the historical reputation value and the maximum reputation value of the node, when the incentive is distributed to the node in the first round, the past reputation value does not exist at this time, n is 1, and the value of a is 1. As the node participates in multiple rounds of incentive distribution, a gradually becomes greater than 1. The greater the gap between the initial reputation value and the maximum reputation value, the greater a is. As the reputation value of this node gradually approaches the maximum reputation value, a gradually returns to 1. represents the ratio of the reputation value of node j in the Kth round to the sum of the reputation values of all nodes. N is the number of all nodes in the current system.

[0208] When the reputation value of the node decreases after the end of a round of election cycle, this round will not receive an incentive.

[0209] For the incentive method of threshold-signature nodes, the leading node obtains an additional reward every time it successfully passes the on-chain verification:

[0210]

[0211] Since the leader node needs to perform additional verification, the leader node will receive an additional incentive. After each leader node aggregates the signature and is confirmed by the on-chain contract, the leader node will receive additional incentives. C represents the consumption cost of on-chain verification, which can be adjusted according to actual conditions. It represents the average value of the node's historical reputation. As the node's reputation value increases, It gradually increases and eventually approaches 1.

[0212] After a round of election cycle, the system will count the nodes with increased reputation values ​​and distribute all the incentives to the leading nodes. After the leading nodes are incentivized, they must first submit a 120% collateral deposit of the incentives to the smart contract. If the distribution is illegal, the collateral will be confiscated. The incentives will then be distributed to the child nodes. After the distribution is completed, the collateral will not be unlocked until the appeal period ends.

[0213]

[0214] I send represents the total incentives sent by the system to the leader node, and m represents the number of nodes that should be incentivized.

[0215]

[0216] The currently available incentive pool I for a given leader node send , incentives are issued after each round of work cycle is completed, represents the incentive received by node j in round K, is the incentive coefficient a, n indicates the number of the current round of incentive issuance, the initial value is 1, taking into account the historical reputation value and maximum reputation value of the node, when the node issues incentives in the first round, the past reputation value does not exist, n is 1, and the value of a is 1. As the node participates in multiple rounds of incentive issuance, a gradually increases. The greater the gap between the initial reputation value and the maximum reputation value, the larger a becomes. As the reputation value of the node gradually approaches the maximum reputation value, a gradually returns to 1. It represents the ratio of the reputation value of node j in the Kth round to the sum of the reputation values ​​of all nodes.

[0217] Furthermore, the appeal mechanism of the threshold signature node includes the following steps:

[0218] Step 1: After the leader node is incentivized, it must first submit 120% of the mortgage to the smart contract for locking. The mortgage cannot be refunded during the appeal period and will be released after the appeal period ends.

[0219] Step 2: All participating nodes have the right to submit objections to the distribution results of the aggregation node through the appeal channel specified in the smart contract before the task is completed and the rewards are issued.

[0220] Step 3: The appeal submission period is limited within the time window predetermined by the smart contract, and the appellant is required to provide supporting materials including but not limited to contribution data, signature submission records, etc.

[0221] Step 4: A 30% appeal ratio threshold is preset in the smart contract. When the ratio of the number of submitted appeals to the total number of all participating nodes exceeds this threshold, the system automatically determines that there is an unfair distribution problem with the aggregation node and triggers an audit procedure for the distribution behavior of the aggregation node.

[0222] Step 5: The system randomly selects nodes with the same number as the appellant nodes from the nodes that have not participated in the distribution according to the preset rules to form a jury. The jury uses the Byzantine Fault Tolerance (BFT) consensus mechanism for voting and adjudication. If more than 2 / 3 of the members in the jury approve the appellant's opinion, the smart contract determines that the aggregation node has violated the regulations.

[0223] Step 6: According to the ratio of the appellant nodes, the system automatically deducts the corresponding proportion of the amount from the deposit of the aggregation node as a penalty. For example, when the ratio of the appellant nodes is x, the system deducts an amount equivalent to x proportion from the deposit of the aggregation node; the deducted part is redistributed to all appellant nodes according to the preset distribution rules as compensation for them.

[0224] Step 7: After the arbitration procedure determines that the aggregation node has violated the regulations, the system directly sets the reputation value of the aggregation node to the preset minimum reputation value reputation min as a punishment for its violation.

[0225] Furthermore, for the method of the distributed oracle authentication system based on reputation scoring, the distributed oracle can verify the data source, such as Figure 5 , including the following steps:

[0226] Step 1: Each oracle node obtains data from an external data source, performs a hash operation on each piece of data or each data block to generate leaf nodes (hash values), and the hash values of these leaf nodes will serve as the basic layer of the Merkle tree.

[0227] Step 2: Combine the hash values of the leaf nodes in pairs, and calculate the hash value again to form new parent nodes. Continuously repeat this process until a unique root hash value (Merkle root) is obtained, representing the unique identifier of the entire data set.

[0228] Step 3: Calculate the Merkle root. The Merkle Root generated by each node represents the unique hash value of the complete data set obtained by it from the data source.

[0229] Step 4: All oracle nodes broadcast their Merkle roots to other nodes through the leader node, enabling the nodes in the system to mutually verify the correctness of the Merkle roots.

[0230] Step 5: All nodes in the system compare their respective Merkle roots with each other to check for consistency. If the root hash values are consistent, it indicates that the data obtained by each node is the same and the data has not been tampered with. Subsequently, the distributed oracle network uploads the finally confirmed consistent Merkle root to the chain through the leader node as a public record of the verification result. Users or other systems can verify the integrity of the data through the root hash stored on the chain. In subsequent data verification, anyone can use the Merkle path to verify whether a specific data block belongs to the confirmed dataset, enhancing the transparency and security of the system.

[0231] Step 6: If there is an inconsistency, it indicates that some nodes may have received different data or the data has been tampered with, and it is necessary to further verify the data sources of these nodes.

[0232] The above is only a preferred embodiment of the present invention, and it is not intended to limit the present invention in any other form. Any modification or equivalent change made according to the technical essence of the present invention still falls within the scope of the present invention claimed.

Claims

1. A distributed oracle authentication system based on reputation scoring, characterized by: It includes three entities: distributed oracle network, blockchain, and data source; The distributed oracle network elects the leader node through a verifiable random function and adopts a fair leader node rotation mechanism; The distributed oracle network introduces optional threshold signatures and multi-signatures to adapt to application scenarios with different authentication requirements, introduces a node effective reporting function to evaluate the reputation value of the node, and issues incentives based on the reputation value; The distributed oracle network includes a dynamic scoring and node management mechanism based on reputation, which scores oracle nodes, determines the joining and exit of nodes according to the reputation value, and implements an incentive mechanism of rewards and penalties; The blockchain receives data requests sent by users through smart contracts, and the contracts broadcast the data requests to the leading nodes in the distributed oracle network, while allowing users to specify the signature type in the contract and specify the minimum reputation value that the nodes participating in the request processing must reach; After receiving the access request from the oracle node, the data source returns the result to the distributed oracle network; The distributed oracle authentication system based on reputation scoring takes into account the historical reputation of the node when performing reputation scoring; When the distributed oracle authentication system based on reputation score adopts threshold signature based on BLS, private key shards are allocated according to the reputation value of the node; When the distributed oracle authentication system based on reputation score adopts multi-signature based on BLS, the weight of the node participating in the aggregation is determined according to the reputation value of the node, and the on-chain contract can require the minimum threshold of the sum of the weights of the nodes participating in the signature this time; The distributed oracle authentication system based on reputation score implements corresponding incentive strategies according to the type difference of node signatures, and issues an additional incentive to the leader node for its dual functions of verification and aggregation; The distributed oracle authentication system based on reputation scoring includes a node appeal mechanism using threshold signatures, so that child nodes can file an appeal if the leader node distributes rewards unfairly; The distributed oracle network uses a Merkle tree to verify the data source.

2. The distributed oracle authentication system based on reputation scoring according to claim 1, characterized in that: The distributed oracle network elects a leader node through a verifiable random function and adopts a fair leader node rotation mechanism including the following steps: Step 1: Initialize the system, set an initial value of reputationi to 0 for all nodes, and define the election cycle T and the minimum reputation score threshold reputation min , the maximum reputation score threshold reputataion max ; Step 2: Trigger the first leader node election. The system generates a random number through the VRF verifiable random function to determine the leader node of the first round. Step 3: The system maps the generated VRF random number to the node list and selects a node as the first leader node. The specific mapping method can be set according to the number of nodes: random number % total number of nodes = serial number of the selected node; Step 4: Each node uses the VRF result to verify the legitimacy of the election process to ensure that the selected node is indeed random and fair. Once selected, the smart contract will record the node as the current leader node until the next cycle begins; Step 5: The on-chain smart contract sends a request to the leader node, specifies the required signature type, and explicitly requires the minimum reputation value that the nodes participating in processing this request need to reach. The leader node notifies the distributed oracle network of the message. Step 6: The distributed oracle network obtains data from the data source, and the data source returns the result to the distributed oracle network. The nodes in the distributed oracle network use the signatures required by the contract to calculate and verify the results respectively; Step 7: The leader node accepts signatures related to reputation values ​​from other nodes, records the submitted node ID and timestamp, aggregates based on the signature used and determines whether the signature is valid, and then aggregates the result and signature and returns it to the on-chain contract; Step 8: The on-chain contract verifies the legitimacy of the result based on the result of the group of data, the public key set and the final signature, thereby proving the correctness of the data acquisition result. If the result passes, the report of the leader node leader Increase, otherwise decrease, and adjust the effective report function report of these nodes in this round according to the behavior of the nodes in this round i ; Step 9: After the period T, all nodes are first given incentives, and then a new round of elections begins. At this time, the node's reputation is calculated based on the node's effective reporting function, and then the child nodes are sorted from high to low according to the reputation value. The node with the highest reputation among the child nodes uses the verifiable secret sharing Byzantine fault-tolerant Raft consensus algorithm to elect. If the election fails, it switches to the next child node; Step 10: When the reputation value of a node in the distributed oracle network is lower than the minimum reputation score threshold min , the node exit is executed.

3. The distributed oracle authentication system based on reputation scoring according to claim 1, characterized in that: The node valid reporting function is introduced, including the valid reporting function of the leader node, the valid reporting function of the threshold signature subnode, and the valid reporting function of the multi-signature subnode: Valid reporting functions for leader nodes are: in, Represents the effective reporting function of the leader node in this round of work cycle T, The initial value of is 0, T represents the working period of the wheel node, j represents the jth generation result of the leader node in the round period T, t j represents the time taken by the leader node to generate the result for the jth time, S i Indicates whether the leader node generates the correct signature for the jth time and passes the on-chain verification. If the signature is successfully generated and passed the on-chain verification, it is 1, otherwise it is 0. α is the added weight; The effective reporting function of the threshold signature child node is: in, Represents the effective reporting function of child node i in this round of working cycle T. The initial value of is 0, T represents the working period of the wheel node, j represents the result generated by the child node for the jth time in the round period T, and t j Indicates the time it takes for the child node to generate the result for the jth time. If ≥t signatures have been collected and verify=1, it means that the system has correctly generated the threshold signature when the result is generated for the jth time, and it is not included in the score. V i Indicates whether the child node has correctly generated the result for the jth time and passed the on-chain verification. If the result is successfully generated and passed the on-chain verification, it is 1, otherwise it is -1. α is the added weight, and β is the deducted weight; The multi-signature sub-node effective reporting function is: in, represents the effective reporting function of child node i in this round of working cycle T, The initial value of is 0, T represents the working cycle of the wheel node, the waiting time of the leader node is t, j represents the result generated by the child node for the jth time in the round cycle T, t j Indicates the time it takes for the child node to generate the result for the jth time. If t j >t and verify=1, indicating that the node did not submit the public key and signature within the leader node waiting time t, and will not be counted in the score, V i Indicates whether the child node has correctly generated the result for the jth time and passed the on-chain verification. If the result is successfully generated and passed the on-chain verification, it is 1, otherwise it is -1. α is the added weight, and β is the deducted weight.

4. The distributed oracle authentication system based on reputation scoring according to claim 1, characterized in that: The distributed oracle network includes a reputation scoring formula for nodes based on a dynamic rating and node management mechanism based on reputation: Reputation incentive formula: Credit penalty formula: It represents the reputation of node i in the nth round of work, r is the absolute value of the node's effective report function, if the value is greater than 0, it is judged that the node has positive network contribution behavior in the previous evaluation cycle, and the reputation incentive function is triggered, if the value is less than zero, it is judged that the node has malicious network behavior, and the reputation penalty function is triggered, if it is equal to 0, it is judged that the node is in a low activity state, and the node penalty function is triggered, x and y are the reputation incentive coefficient and the reputation penalty coefficient respectively, the default value is 1, Represents the historical average reputation value of the node, reputation max and reputation min are the maximum and minimum reputation values ​​of the node, respectively. When the reputation of the node approaches reputation max When the reputation value increases, it becomes more difficult to grow, and finally converges to reputation max When a node performs malicious behavior, the higher the reputation value of the node, the greater the penalty. min , will be removed from the oracle network.

5. The distributed oracle authentication system based on reputation scoring according to claim 1, characterized in that: The historical reputation of the node is determined, including: The initial value of x and y in the reputation scoring formula is 1. Assume that the node has gone through n rounds of work. Indicates the reputation value of node i in the kth round, k = 1, 2, 3, ..., n. γ and λ are adjustment coefficients. The greater the historical reputation of the node, the greater the x will be when the oracle effective reporting function increases. When the oracle effective reporting function decreases, the penalty for high-reputation nodes should be increased, so y will also be greater.

6. The distributed oracle authentication system based on reputation scoring according to claim 1, characterized in that: When using threshold signatures based on BLS, private key shards are allocated based on the reputation of the node. Nodes with higher reputations receive more private key shards. The following steps are included: Step 1: The on-chain contract specifies the use of threshold signatures, gives the threshold value t, and sends a request to the distributed oracle network; Step 2: Generate the public parameters required by the system, G1, G2, G T is a multiplicative cyclic group of prime order p, with generators g1 and g2, and a bilinear pairing e: G1×G2→G T , H is the hash function mapped to G1, and the public parameter η=(G1,G2,G T , p, g1, g2, e, H); Step 3: Generate the master private key and master public key of the distributed oracle network, calculate the private key and public key of the node respectively, the leader node master private key MSK = x, x is the random number selected by the system, the leader node master public key: Randomly select a Z p The t-1 order polynomial P on the matrix satisfies P(0)=x; Step 4: Assume that there are n nodes participating in the aggregation in the distributed oracle, i∈{1, 2, …, n}, and calculate the weight of node i as The higher the reputation of a node, the higher its weight. In the BLS algorithm, the prime number p is much larger than the weight w. i , so nodes with different weights will not collide; Step 5: The number of private key fragments k allocated to node i i =w i , k i ≥1, Step 6: Set the sequence For each node i, assign k i Index Points Used to generate private key shards from the polynomial P(x); Step 7: Calculate X for each node i As the private key of node i, each node gets a private key of different size according to its reputation The calculation formula is as follows, As the public key of node i; Step 8: Node i uses its private key shards to calculate the signature of message m one by one: And aggregated into The node will then i and Σ i Submit to the leader node; Step 9: The leader node receives the signature of the child node and verifies it first and records the passed signature. After receiving the result submitted by node i, the leader node first verifies the correctness of the signature: e(Σ i ,g2)=e(H(m),v i ), If the equation holds, the verification is successful, and K=K+k i To record the signatures collected so far; Step 10: Verify the threshold signature: When the collected K signatures are greater than or equal to the threshold value t, the leader node aggregates and verifies the complete threshold signature; in From the Lagrange interpolation formula, we know that the complete signatures generated by any t or more signatures are the same, and the signatures are verified: verify(σ,m,v)→(0,1) e(σ,g2(=e(H(m),g2 x ) If the equation holds true, it is a correct threshold signature, otherwise the verification fails.

7. The distributed oracle authentication system based on reputation scoring according to claim 1, characterized in that: When multi-signature based on BLS is used, the weight of the node participating in the aggregation is determined according to the reputation value of the node. The on-chain contract can require a minimum threshold for the sum of the weights of the nodes participating in the signature, which includes the following steps: Step 1: The on-chain contract specifies the use of multi-signatures and gives the minimum sum of the reputations of the participating nodes, R, to send a request to the distributed oracle network; Step 2: Generate the public parameters required by the system. The scheme is based on the bilinear mapping e: G1×G2=G t On, G1, G2, G t They are all groups of prime order q, g1 and g2 are generators of G1 and G2 respectively, and there is a hash algorithm H0:{0,1} * →G1,H2:{0,1} * →G1, so that the calculated hash value is an element in group G1, H1:{0,1} * →Z q The calculated hash value is group Z q The elements in and set the leader node fixed waiting time t; Step 3: Key generation: Construct bilinear pairing system parameters par←(q,G1,G2,G t ,e,g1,g2), a key pair is generated for each node i in the distributed oracle, the private key sk i 、Public key pk i : Step 4: Assume that there are n nodes in the distributed oracle, i∈{1, 2, …, n}, and calculate the weight of node i as The higher the reputation of a node, the higher its weight. In the BLS algorithm, the prime number p is much larger than the weight w. i , so nodes with different weights will not collide, and finally round it up and use the vector express, Step 5: All nodes in the system send their public keys and signatures to the leader node for aggregation. The leader node accepts the signatures and public keys from the child nodes and records: The child nodes in the distributed oracle network send their signatures σ i and public key pk i Send it to the leader node and count the nodes participating in the calculation within the waiting time T. There are n nodes in the distributed oracle network. is a vector of length n, with an initial value of 0. When node i sends the signature and public key to the leader node within a waiting time of less than T, b i =1, It is a list of public keys of all nodes generated by the leader node, with an initial value of 1; a i =H1(pk i ,{pk1,…,pk n }) Step 6: The leader node checks whether the reputation of the participating nodes meets the reputation requirements of the contract. is a vector composed of the reputation values ​​of all nodes in the distributed oracle. If Indicates that the sum of the reputation values ​​of the nodes participating in the calculation this time meets the requirements of the on-chain contract for the reputation value, otherwise the waiting time T is reset; Step 7: The leader node aggregates and generates the aggregate signature σ and aggregate public key apk; Step 8: The on-chain smart contract verifies the correctness of the multi-signature. If the equation holds, it is a correct multi-signature. Otherwise, the verification fails. verify(σ,m,apk)→(0,1) 8. The distributed oracle authentication system based on reputation scoring according to claim 1, characterized in that: The corresponding incentive strategy is implemented according to the type difference of node signature. For the dual functions of verification and aggregation of the leader node, an additional incentive is issued to it, including the following steps: The leader node receives additional rewards for each successful on-chain verification: Since the leader node needs to perform additional verification, the leader node will receive an additional incentive. After each leader node aggregates the signature and is confirmed by the on-chain contract, the leader node will receive additional incentives. C represents the consumption cost of on-chain verification, which can be adjusted according to actual conditions. It represents the average value of the node's historical reputation. As the node's reputation value increases, It gradually increases and eventually approaches 1; When the reputation of a node increases after a round of election cycle, the incentives for executing the node are: The currently available incentive pool I for a given system total , incentives are issued after each round of work cycle is completed, represents the incentive received by node j in round K, is the incentive coefficient a, n indicates the number of the current round of incentive issuance, the initial value is 1, taking into account the historical reputation value and maximum reputation value of the node, when the node issues incentives in the first round, the past reputation value does not exist, n is 1, and the value of a is 1. As the node participates in multiple rounds of incentive issuance, a gradually increases. The greater the gap between the initial reputation value and the maximum reputation value, the larger a becomes. As the reputation value of the node gradually approaches the maximum reputation value, a gradually returns to 1. It represents the ratio of the reputation value of node j in the Kth round to the sum of the reputation values ​​of all nodes, and N is the number of all nodes in the current system; When the reputation of a node decreases after an election cycle, it will not receive incentives in this round; The incentive method for threshold signature nodes includes the following steps: The leader node receives additional rewards for each successful on-chain verification: Since the leader node needs to perform additional verification, the leader node will receive an additional incentive. After each leader node aggregates the signature and is confirmed by the on-chain contract, the leader node will receive additional incentives. C represents the consumption cost of on-chain verification, which can be adjusted according to actual conditions. It represents the average value of the node's historical reputation. As the node's reputation value increases, It gradually increases and eventually approaches 1; After a round of election cycle, the system will count the nodes with increased reputation and distribute all the incentives to the leading nodes. After the leading nodes are incentivized, they must first submit 120% of the collateral of the incentives to the smart contract. If the distribution is illegal, the collateral will be confiscated. Then the incentives will be distributed to the child nodes. After the distribution is completed, the collateral will not be unlocked until the appeal period ends. I send represents the total incentives sent by the system to the leader node, and m represents the number of nodes that should be incentivized. The currently available incentive pool I for a given leader node send , incentives are issued after each round of work cycle is completed, represents the incentive received by node j in round K, is the incentive coefficient a, n indicates the number of the current round of incentive issuance, the initial value is 1, taking into account the historical reputation value and maximum reputation value of the node, when the node issues incentives in the first round, the past reputation value does not exist, n is 1, and the value of a is 1. As the node participates in multiple rounds of incentive issuance, a gradually increases. The greater the gap between the initial reputation value and the maximum reputation value, the larger a becomes. As the reputation value of the node gradually approaches the maximum reputation value, a gradually returns to 1. It represents the ratio of the reputation value of node j in the Kth round to the sum of the reputation values ​​of all nodes.

9. The distributed oracle authentication system based on reputation scoring according to claim 1, characterized in that: The appeal mechanism for threshold signature nodes includes the following steps: Step 1: All participating nodes have the right to submit objections to the distribution results of the aggregation node through the appeal channel specified in the smart contract before the task is completed and the rewards are issued; Step 2: The complaint submission period is limited to the time window predetermined by the smart contract, and the complainant is required to provide supporting materials including but not limited to contribution data, signature submission records, etc. Step 3: Set the appeal ratio threshold. When more than 30% of participating nodes submit an appeal, the system automatically determines that there is an unfair distribution problem in the aggregation node, triggers the appeal, and reviews the distribution behavior of the aggregation node; Step 4: Based on the pre-set distribution rules and arbitration results, the smart contract makes a judgment to confirm whether the aggregation node has violated the rules. Step 5: Based on the proportion of appealing nodes, deduct the corresponding proportion of the leader node’s collateral as compensation and distribute it to the appealing nodes. Step 6: Set the node's reputation value to reputation min 10. The distributed oracle authentication system based on reputation scoring according to claim 1, characterized in that: The distributed oracle network uses the Merkle tree to verify the data source, including the following steps: Step 1: Each oracle node obtains data from an external data source, performs hash operations on each piece of data or each data block, and generates leaf nodes. The hash values ​​of these leaf nodes will serve as the base layer of the Merkle tree. Step 2: Combine the hash values ​​of the leaf nodes in pairs and calculate the hash value again to form a new parent node. Repeat this process until a unique root hash value (Merkle root) is obtained, which represents the unique identifier of the entire data set. Step 3: Calculate the Merkle root. The Merkle root generated by each node represents the unique hash value of the complete data set obtained from the data source. Step 4: All oracle nodes broadcast their Merkle roots to other nodes through the leader node, so that the nodes in the system can verify the correctness of the Merkle roots with each other. Step 5: All nodes in the system compare their Merkle roots to check whether they are consistent. If the root hash values ​​are consistent, it means that the data obtained by each node is the same and the data has not been tampered with. Subsequently, the distributed oracle network uploads the final confirmed consistency Merkle root to the chain through the leader node as a public record of the verification results. Users or other systems can verify the integrity of the data through the root hash stored on the chain. In subsequent data verification, anyone can use the Merkle path to verify whether a specific data block belongs to a confirmed data set, enhancing the transparency and security of the system. Step 6: If inconsistencies occur, it means that some nodes may have received different data or the data has been tampered with, and the data sources of these nodes need to be further verified.

Citation Information

Cited By

  • Self-adaptive weight task scheduling method and system based on time sequence differential learning

    CN120973493A

  • Smart contract enhanced data aggregation method based on large language model and block chain collaboration

    CN121350091A