A blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature

Through the multi-layer retrieval integrity verification method of Shamir threshold signature and Lagrange interpolation recovery, the problems of data unreliability and high overhead in the blockchain oracle system are solved, and efficient and reliable data integrity verification is achieved, which is suitable for fields such as finance, supply chain management, meteorological services and the Internet of Things.

CN120151056BActive Publication Date: 2025-09-12广西壮族自治区气象台(广西壮族自治区海洋气象台) +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510363092.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-09-12
Estimated Expiration
2045-03-26

AI Technical Summary

Technical Problem

In blockchain oracle systems, the unreliability and security issues of external data sources lead to data distortion or delay, affecting the accuracy of smart contract decisions. Existing retrieval integrity verification schemes have high computational and communication overheads, making it difficult to meet the data authenticity and efficiency requirements of blockchain applications.

Method used

A multi-layer retrieval integrity verification method is constructed using Shamir threshold signatures. The key fragments are distributed to primary verification nodes through the key generation center. The primary nodes generate partial signatures, and the advanced nodes recover the secret value through Lagrange interpolation to generate a complete signature. Combined with the Merkle tree and reputation management mechanism, data integrity and authenticity are ensured.

Benefits of technology

It significantly improves the efficiency and reliability of oracle data retrieval integrity verification, reduces computing and storage costs, is suitable for large-scale data application scenarios, and improves the security and applicability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151056B_ABST
    Figure CN120151056B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-layer retrieval integrity verification method for a blockchain oracle based on Shamir threshold signature, comprising: system initialization and configuration of security parameters, user generation of a key pair, encryption of data to generate a data tag and a signature, construction of a root hash value of a Merkle tree, and uploading of the encrypted data to a data source server; a data requester generates a retrieval request according to specific conditions and sends the request to the data source, and the data source returns ciphertext data and a verification certificate that meet the conditions; a key generation center uses the Shamir threshold signature scheme to distribute key fragments to primary verification nodes; the primary verification nodes use the Shamir threshold signature to generate partial signatures, and submit the partial signatures to advanced verification nodes, and the advanced verification nodes recover secret values ​​through Lagrange interpolation; the advanced verification nodes verify data integrity and generate a complete signature, and transmit the verified data back to the data requester.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer science and technology, and in particular relates to a blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature. Background Art

[0002] With the rapid development of blockchain technology, blockchain oracles have become a crucial bridge between on-chain smart contracts and off-chain data sources. Since blockchain networks themselves cannot directly access external data, oracles primarily retrieve information from off-chain sources and transmit it to on-chain smart contracts, enabling more complex application scenarios such as financial payments, supply chain management, meteorological services, and IoT data sharing. However, the security and reliability of external data sources remain a major challenge for oracles. Data sources can be distorted or delayed due to malicious attacks or technical failures, impacting the accuracy of on-chain smart contract decisions and potentially jeopardizing the credibility of the entire system. Therefore, ensuring the integrity and authenticity of data retrieved by oracles from external sources becomes a critical issue.

[0003] Shamir threshold signatures are a distributed cryptographic technique widely used for data verification and fault-tolerance control in distributed systems. The core idea is to split a secret into multiple shares and distribute them to different participants. The secret can only be reconstructed when a preset threshold number of shares is reached. Shamir threshold signatures offer significant advantages in multi-node data verification, allowing multiple nodes to participate in the signature generation process, thereby reducing the risk of single points of failure and improving system security.

[0004] Retrieval integrity verification technology is an important means of ensuring data consistency and integrity during transmission from the source to the user end, and is widely used in database systems and cloud storage. The core concept of this technology is to ensure that data has not been tampered with or lost during transmission through layered verification. Currently, common retrieval integrity verification technologies are mainly based on authenticated data structures such as hash functions, Merkle trees, and signature chains, which can effectively support large-scale data verification needs. In blockchain oracle systems, the introduction of a retrieval integrity verification mechanism can reduce computational and communication overhead during data query and verification. This is particularly applicable to the security requirements of off-chain data and helps improve the data reliability and efficiency of oracle systems.

[0005] Currently, in blockchain oracle systems, the authenticity and integrity of off-chain data are key factors affecting the accuracy of smart contract decisions. However, the data obtained by the oracle from external data sources may be distorted or delayed due to the unreliability or security issues of the data source, causing the smart contract to make incorrect judgments during the decision-making process and even endangering the credibility of the entire system. In addition, existing retrieval integrity verification schemes usually rely on centralized or semi-centralized verification nodes, which have single points of failure and potential trust risks, making it difficult to meet the dual requirements of blockchain applications for data authenticity and efficiency. Therefore, a multi-level retrieval integrity verification method is needed. In particular, in large-scale data verification, the computational and communication overhead of existing schemes is high, further limiting the applicability of oracle systems in complex data scenarios. To this end, the present invention proposes a blockchain oracle multi-level retrieval integrity verification method based on Shamir threshold signatures. Summary of the Invention

[0006] To solve the above technical problems, the present invention proposes a blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature, which effectively ensures the integrity and authenticity of data obtained by the blockchain oracle from external data sources.

[0007] To achieve the above objectives, the present invention provides a blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature, comprising:

[0008] The system initializes and configures security parameters. The user generates a key pair and encrypts the data to generate a data tag and signature. The root hash value of the Merkle tree is constructed and the encrypted data is uploaded to the data source server.

[0009] The data requester generates a retrieval request based on specific conditions and sends it to the data source. The data source returns the ciphertext data that meets the conditions and a verification certificate.

[0010] The key generation center uses the Shamir threshold signature scheme to distribute key fragments to primary verification nodes;

[0011] The primary verification node generates a partial signature using Shamir threshold signature and submits the partial signature to the senior verification node, which recovers the secret value through Lagrange interpolation.

[0012] Based on the recovered secret value, the advanced verification node verifies the data integrity and generates a complete signature, and transmits the verified data back to the data requester.

[0013] Optionally, the system initializes and configures security parameters. User-generated key pairs include:

[0014] The user selects a random number x as the private key sk and calculates the public key pk = (u, v) to generate a key pair, where and The user publishes the public key and shares the private key with the blockchain oracle.

[0015] Optionally, the data requester generates a retrieval request based on specific conditions and sends it to the data source. The data source returns the ciphertext data that meets the conditions and a verification certificate including:

[0016] The data requester sends a retrieval request T = (w, A j ), requesting a specific attribute A j All records that match the value w;

[0017] After receiving the request, the data source traverses the stored data and filters out the set of ciphertext records that meet the conditions And generate the aggregate signature σ and verification proof π and return them to the oracle node.

[0018] Optionally, the key generation center uses the Shamir threshold signature scheme to distribute key fragments to primary verification nodes, including:

[0019] The key generation center generates the secret value x and the threshold value t, and defines a large prime number p and a p-order finite field F p ;

[0020] The key generation center selects the parameter set {a1, a2, ..., a t-1}, construct a t-1 order polynomial:

[0021] f(z)=x+a1z+a2z 2 +…+a t-1 z t-1 ;

[0022] Calculate each verification node P i Secret Shares i =f(ID i ), distributed to n primary verification nodes, forming a key slice set {(ID1, s1), (ID2, s2), ..., (ID n , s n )}.

[0023] Optionally, the primary verification node generates a partial signature using Shamir threshold signatures and submits the partial signature to the senior verification node including:

[0024] Each primary verification node uses a key slice s i Ciphertext records and the Merkle tree root hash H root Conduct verification;

[0025] For each record that meets the criteria The primary verification node generates a partial signature:

[0026]

[0027] After verification is completed, each node will partially sign σ i Submit to the senior validator node.

[0028] Optionally, advanced verification nodes recover secret values ​​through Lagrange interpolation including:

[0029] Suppose the partial signature set is Reconstruct the value of the polynomial f(z) at z=0 using the Lagrange interpolation method and recover the secret value:

[0030]

[0031] Among them, s i is the received partial signature key fragment σ i , is the Lagrange interpolation coefficient.

[0032] Optionally, based on the recovered secret value, the advanced verification node generates a complete signature σ including:

[0033]

[0034] Optionally, the method further includes: the reputation management mechanism dynamically adjusts the reputation score of the data source, and the initial score R of each data source is D (0) Set by the system, the advanced verification node updates the reputation score of the data source based on the verification results:

[0035] R D (t+1)=R D (t)+α·V success (t)-β·V failure (t);

[0036] Where V success and V failure are the number of successful and failed verifications, respectively, and α and β are adjustment coefficients.

[0037] Technical Effects: This invention discloses a multi-layered retrieval integrity verification method for blockchain oracles based on Shamir threshold signatures. Through this multi-layered threshold signature verification mechanism, the efficiency and reliability of oracle data retrieval integrity verification are significantly improved, while simultaneously reducing computational and storage costs. This layered verification structure can flexibly adapt to large-scale data application scenarios while ensuring data integrity, and is widely applicable to fields such as finance, supply chain management, and the Internet of Things. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] The accompanying drawings, which constitute part of this application, are intended to provide a further understanding of this application. The exemplary embodiments and descriptions of this application are intended to explain this application and do not constitute an improper limitation on this application. In the accompanying drawings:

[0039] Figure 1 This is a flow chart of a blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signatures according to an embodiment of the present invention;

[0040] Figure 2 This is a schematic diagram of the system model of an embodiment of the present invention, showing the interaction process between smart contracts, oracle nodes, and data sources. DETAILED DESCRIPTION

[0041] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0042] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0043] like Figure 1 As shown, in this embodiment, a multi-layer retrieval integrity verification method for a blockchain oracle based on Shamir threshold signature is provided, including four parts: data source preparation stage, retrieval stage, hierarchical verification stage and data source reputation management mechanism. The specific process is as follows: First, the system is initialized and security parameters are configured. The user generates a key pair, encrypts the data to generate a data label and signature, and constructs the root hash value of the Merkle tree at the same time, and finally uploads the encrypted data to the data source server. Then, the data requester (such as a smart contract) generates a retrieval request according to specific conditions and sends it to the data source. The data source returns a retrieval result containing a verification certificate. The primary verification node uses the Shamir threshold signature to generate a partial signature and submits it to the advanced verification node. The advanced verification node verifies the data integrity and generates a complete signature, and finally transmits the verified data back to the smart contract. Through the synergistic effect of each stage, the present invention effectively guarantees the integrity and authenticity of the data obtained by the blockchain oracle from the external data source.

[0044] Data source preparation stage:

[0045] The user first initializes the system parameters and generates a private key and a public key pair to ensure the security of the system parameter configuration. The user selects a random number x as the private key sk and calculates the public key pk = (u, v) to generate a key pair, where and Users disclose their public keys and share their private keys with blockchain oracles to ensure the retrieval and verification process of external data.

[0046] Dataset D = {(a i1, a i2 ,...,a in )|i=1,2,...} is encrypted by the user and generates a tag to construct a ciphertext structure. ij Encrypted and label t ij =h1(a ij ), forming a ciphertext record D with a label E ={t ij , c ij The user uses these encrypted data to build a Merkle tree and generate a root hash H root , ensuring data integrity. Finally, the ciphertext data, signature, and root hash are sent to the data source for storage and retrieval.

[0047] Retrieval stage:

[0048] The smart contract sends a retrieval request T = (w, A j ), requesting a specific attribute A j After receiving the request, the data source traverses the stored data and filters out the set of ciphertext records that meet the conditions. And generate the aggregate signature σ and verification proof π and return them to the oracle node for subsequent integrity verification.

[0049] Layered verification phase:

[0050] The core innovation of this invention lies in the multi-layer retrieval integrity verification method constructed by Shamir threshold signature. The specific steps are as follows:

[0051] Threshold signature initialization: The key generation center generates a secret value x and a threshold value t (satisfying t≤n), and defines a large prime number p and a p-order finite field F p The key generation center selects the parameter set {a1, a2, ..., a t-1}, construct a t-1 order polynomial:

[0052] f(z)=x+a1z+a2z 2 +…+a t-1 z t-1 ;

[0053] Calculate each verification node P i Secret Shares i =f(ID i ), distributed to n primary verification nodes, forming a key slice set {(ID1, s1), (ID2, s2), ..., (ID n , s n )}.

[0054] Partial signature generation of primary verification node: Each primary verification node uses its key slice s i Ciphertext records and the Merkle tree root hash H root For each record that meets the conditions The primary verification node generates a partial signature:

[0055]

[0056] After verification is completed, each node will partially sign σ i Submit to the senior validator node.

[0057] Threshold signature recovery of advanced verification nodes: When an advanced verification node receives at least t valid partial signatures, it uses Lagrange interpolation to reconstruct the original secret value x and calculate the complete signature. Let the partial signature set be Reconstruct the value of the polynomial f(z) at z=0 according to the Lagrange interpolation method to recover the secret value:

[0058]

[0059] where s i is the received partial signature key fragment σ i , is the Lagrange interpolation coefficient.

[0060] Using the recovered x, the advanced verification node calculates the complete signature:

[0061]

[0062] The generated full signature σ is submitted to the smart contract to prove data consistency and integrity.

[0063] Data source reputation management mechanism:

[0064] The reputation management mechanism in this invention ensures the overall reliability of the system data source by dynamically adjusting the reputation score of the data source. D (0) Set by the system, the advanced verification node updates the reputation score of the data source based on the verification results:

[0065] R D (t+1)=R D (t)+α·V success (t)-β·V failure (t);

[0066] Where V success and V failure are the number of successful and failed verifications, respectively, and α and β are adjustment coefficients. Data sources with higher credibility will be given priority in future retrieval requests and receive more economic incentives.

[0067] like Figure 2 As shown in FIG, a schematic diagram of an application scenario of the present invention in meteorological data sharing shows the specific process of the system in meteorological data retrieval and verification. The specific steps are as follows:

[0068] (1) In the meteorological data sharing system, the system is initialized, security parameters are generated, and public and private keys are configured. The system performs parameter configuration checks to ensure that all node parameters are correctly set.

[0069] (2) The meteorological data center encrypts the meteorological data such as rainfall, temperature, and humidity at each site or grid point, generates corresponding data tags and Merkle tree root hash values, and distributes key fragments to primary verification nodes. The data source uploads the encrypted meteorological data and verification information to the meteorological data sharing system for storage.

[0070] (3) When a user needs to obtain weather information for a certain region within a certain time period, they submit a search request to the data source. The request format is Request = {RegionID, Timestamp}. If the request format is incorrect or the data does not meet the requirements, the data source returns an error message and terminates the request.

[0071] (4) After receiving the request, the meteorological data center screens the matching data one by one and generates a verification proof Proof = {MerklePath}, and returns the meteorological data and verification proof Response = {RegionData, Proof} to the verification node.

[0072] (5) The primary verification node verifies the received data and verification certificate, generates a partial signature, and submits it to the advanced verification node. The advanced verification node recovers the full signature through Shamir threshold signature and Lagrange interpolation, verifies the data integrity, and transmits the final verification result back to the third-party platform. After verification, the third-party platform can use this data for related meteorological services, environmental modeling, scientific research analysis, and other operations.

[0073] This paper discloses a multi-layered retrieval integrity verification method for blockchain oracles based on Shamir threshold signatures. Through this multi-layered threshold signature verification mechanism, the efficiency and reliability of oracle data retrieval integrity verification are significantly improved, while reducing computational and storage costs. This layered verification structure can flexibly adapt to large-scale data application scenarios while ensuring data integrity, and is widely applicable to fields such as finance, supply chain management, meteorological services, and the Internet of Things.

[0074] The above are merely preferred embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature, characterized in that: include: The system initializes and configures security parameters. The user generates a key pair and encrypts the data to generate a data tag and signature. The root hash value of the Merkle tree is constructed and the encrypted data is uploaded to the data source server. The data requester generates a retrieval request based on specific conditions and sends it to the data source. The data source returns the ciphertext data that meets the conditions and a verification certificate. The key generation center uses the Shamir threshold signature scheme to distribute key fragments to primary verification nodes; The primary verification node generates a partial signature using Shamir threshold signature and submits the partial signature to the senior verification node, which recovers the secret value through Lagrange interpolation. Based on the recovered secret value, the advanced verification node verifies the data integrity and generates a complete signature, and transmits the verified data back to the data requester.

2. The blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature as claimed in claim 1 is characterized in that: The system initializes and configures security parameters. The user generates a key pair including: The user selects a random number x as the private key sk and calculates the public key pk = (u, v) to generate a key pair, where and The user publishes the public key and shares the private key with the blockchain oracle.

3. The blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature as claimed in claim 1 is characterized in that: The data requester generates a retrieval request based on specific conditions and sends it to the data source. The data source returns the ciphertext data that meets the conditions and the verification certificate, including: The data requester sends a retrieval request T = (w, A j ), requesting a specific attribute A j All records that match the value w; After receiving the request, the data source traverses the stored data and filters out the set of ciphertext records that meet the conditions And generate the aggregate signature σ and verification proof π and return them to the oracle node.

4. The blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature as claimed in claim 1 is characterized in that: The key generation center uses the Shamir threshold signature scheme to distribute key fragments to primary verification nodes, including: The key generation center generates the secret value x and the threshold value t, and defines a large prime number p and a p-order finite field F p ; The key generation center selects the parameter set {a1, a2, ..., a t-1 }, construct a t-1 order polynomial: f(z)=x+a1z+a2z 2 +…+a t-1 z t-1 ; Calculate each verification node P i Secret Shares i =f(ID i ), distributed to n primary verification nodes, forming a key slice set {(ID1, s1), (ID2, s2), ..., (ID n , s n )}.

5. The blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature as claimed in claim 1 is characterized in that: The primary verification node generates a partial signature using Shamir threshold signature and submits the partial signature to the advanced verification node including: Each primary verification node uses a key slice s i Ciphertext records and the Merkle tree root hash H root Conduct verification; For each record that meets the criteria The primary verification node generates a partial signature: After verification is completed, each node will partially sign σ i Submit to the senior validator node.

6. The blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature as claimed in claim 1 is characterized in that: Advanced verification nodes recover secret values ​​through Lagrange interpolation including: Suppose the partial signature set is Reconstruct the value of the polynomial f(z) at z=0 using the Lagrange interpolation method and recover the secret value: Among them, s i is the received partial signature key fragment σ i , is the Lagrange interpolation coefficient.

7. The blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature as claimed in claim 1 is characterized in that: Based on the recovered secret value, the advanced verification node generates a complete signature σ including:

8. The blockchain oracle multi-layer retrieval integrity verification method based on Shamir threshold signature as claimed in claim 1 is characterized in that: The method further includes: the reputation management mechanism dynamically adjusts the reputation score of the data source, and the initial score R of each data source is D (0) Set by the system, the advanced verification node updates the reputation score of the data source based on the verification results: R D (t+1)=R D (t)+α·V success (t)-β·V failure (t); Where V success and V failure are the number of successful and failed verifications, respectively, and α and β are adjustment coefficients.

Citation Information

Patent Citations

  • Block chain fragmentation storage method based on threshold secret sharing

    CN110297831A

  • Blockchain key management method, multi-person common signature method and electronic device

    CN111639361A