Method, system, medium and equipment for realizing random beacon
Through the management of blockchain node packets and quantum random number generation, the problems of node overload and low pseudo-random number security in the existing random beacon system are solved, efficient, stable and secure random number generation is achieved, and the fault tolerance and credibility of the system are enhanced.
Patent Information
- Application Number
- CN202311869534.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-01
AI Technical Summary
In existing random beacon systems, node overload, low pseudo-random number security, slow nodes and malicious nodes affect system stability and reliability, resulting in inefficiency and insufficient security.
The nodes in the blockchain are grouped, distributed key generation algorithms and quantum random number generation, and signature verification within the group and supervision of abnormal nodes, ensuring that each group of nodes independently generates and takes turns to output random numbers. Quantum random numbers are used as the entropy source to improve the stability and security of the system.
It improves the efficiency and stability of the system, ensures the authenticity and security of random numbers, enhances the fault tolerance and credibility of the system, and prevents malicious nodes from being affected.
Smart Images

Figure CN120238330A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication security technologies, and in particular, to a method, system, medium, and device for implementing a random beacon. Background Art
[0002] In different scenarios, the requirements for random numbers will vary. Random numbers are widely used in fields such as cryptography, gaming, auctions, and lotteries. Generally speaking, private random numbers and public random numbers are two different types of random numbers. Private random numbers are usually used in scenarios related to personal privacy and security, such as password generation, encryption and decryption, etc. In this case, it is necessary to ensure the randomness and unpredictability of the random numbers to avoid being guessed or cracked by attackers. Public random numbers are usually used in scenarios shared by multiple people, such as lottery draws, gaming random events, etc. In this case, it is necessary to ensure the fairness and randomness of the random numbers to avoid cheating or forgery. Random numbers can be used in many scenarios, such as random selection, lottery draws, and auctions.
[0003] A random beacon is a provably fair random number generation and publishing mechanism based on blockchain technology. It utilizes the decentralization and immutability of the blockchain to ensure the unpredictability and fairness of random numbers. The generation process of the random beacon requires the participation of multiple nodes to ensure the true randomness of the random numbers. At the same time, the result of the random beacon can also be publicly verified to ensure the randomness and credibility of the random numbers. Most current random beacon implementation solutions have the following defects:
[0004] (1) Regarding multiple nodes as a whole, when a certain node experiences overload or downtime, random numbers cannot be generated normally, affecting normal operation, resulting in instability and low efficiency;
[0005] (2) The random numbers generated based on algorithms are pseudo-random numbers. Since pseudo-random numbers can be predicted, absolute security cannot be guaranteed, resulting in low security;
[0006] (3) There may be problems with slow nodes or malicious nodes in the blockchain underlying layer. Slow nodes will affect the efficiency of the random beacon system, and malicious nodes may deceive the system to obtain improper benefits, affecting the reliability of the random beacon system. Summary of the Invention
[0007] To at least partially address the above defects, embodiments of the present invention provide a method, system, medium, and device for implementing a random beacon.
[0008] In a first aspect, the method for implementing a random beacon provided by embodiments of the present invention includes the following steps:
[0009] Step S1: Group M nodes in the same blockchain to obtain N groups. Each node in the N groups respectively and in real time obtains the behaviors of the remaining nodes in its own group and, based on the behaviors, determines whether there are abnormal nodes, and removes the abnormal nodes, where both M and N are natural numbers.
[0010] Step S2: Based on the distributed key generation algorithm, calculate the group public keys of the N groups respectively. Each node in the N groups respectively generates its own signature private key and verification public key.
[0011] Step S3: Based on the signature private key, each of the nodes signs the same message to be signed to obtain its own signed message.
[0012] Step S4: Based on the verification public key, each of the nodes respectively verifies its own signed message and outputs the verified signed message, generating N sets of group signature messages.
[0013] Step S5: Based on the group public key, verify the N sets of group signature messages respectively.
[0014] Step S6: Based on the verified set of group signature messages, control each corresponding group to output a common random number in a set order.
[0015] In some examples, determining whether there are abnormal nodes based on the behaviors includes:
[0016] For a node that has one or more of the three behaviors of sending an error message, providing an incorrect signature result, and refusing to participate in the random beacon, determine that the node is an abnormal node and mark the node as a malicious node.
[0017] In some examples, determining whether there are abnormal nodes based on the behaviors includes:
[0018] For a node that has one or both of the behaviors of being unable to send information in a timely manner and having a response duration greater than a set threshold, determine that the node is an abnormal node and mark the node as a slow node.
[0019] In some examples, Step S6 includes:
[0020] Perform a hash calculation on the verified group signature messages, use the obtained calculation result as the common random number, and control each corresponding group to output the calculation result in turn in a set order.
[0021] In some examples, before Step S2, the method further includes:
[0022] S21: Each node respectively obtains a first quantum random number from a quantum random number generator;
[0023] S22. Based on the first quantum random number, each node respectively generates its own initial quantum key;
[0024] S23. Each node respectively divides the initial quantum key into n portions of quantum keys;
[0025] S24. Each node respectively obtains one portion of the quantum key belonging to itself from the n portions of the quantum keys, and sequentially sends the remaining n - 1 portions of the quantum keys to the remaining n - 1 nodes respectively;
[0026] S25. Each node respectively verifies the received n - 1 portions of the quantum keys. If all the n - 1 portions of the quantum keys are successfully verified, then execute step S2.
[0027] In some examples, before step S2, the method further includes:
[0028] Each of the nodes respectively obtains t second quantum random numbers from the quantum random number generator, and generates its own quantum random number sequence, where n / 2 ≤ t < n, and n is the total number of nodes in each group;
[0029] Each of the nodes respectively generates a proof of knowledge and a common commitment for the first quantum random number in the quantum random number sequence, and broadcasts the proof of knowledge and the common commitment as proof information to the remaining n - 1 nodes;
[0030] Each of the nodes respectively verifies the received proof of knowledge and common commitment. If both the proof of knowledge and the common commitment pass the verification, then execute steps S21 - S25 and delete the proof of knowledge and the common commitment.
[0031] In some examples, step S2 includes:
[0032] Based on the formula Each node respectively calculates its own signature private key, where a ij is the j - th quantum random number among the t second quantum random numbers obtained by the (i + 1) - th node, 0 ≤ i ≤ n - 1, 0 ≤ l ≤ n - 1, l ≠ i.
[0033] In some examples, step S2 further includes:
[0034] Based on the formula Each of the nodes respectively calculates its own verification public key Y i ;
[0035] Based on the formula Respectively calculate the group public key V of each group; where g is the generator of the cyclic group G of order q, s iis the signature private key of the i+1th node,
[0036] In some examples, after step S2, the method further includes:
[0037] Based on the formula Each of the nodes calculates and obtains any node P in the group l The verification public key is q, where q is the order of the cyclic group G, which is randomly selected uniformly. 1≤l≤n, l≠i, n / 2≤t <n。
[0038] In a second aspect, a system for implementing a random beacon provided by an embodiment of the present invention includes:
[0039] The grouping module is configured to group M nodes in the same blockchain into N groups, wherein each node in the N groups respectively obtains the behavior of the remaining nodes in the group in real time and determines whether there are abnormal nodes based on the behavior, and removes the abnormal nodes, wherein M and N are both natural numbers;
[0040] A generation module is configured to calculate the group public keys of the N groups respectively based on a distributed key generation algorithm, and each of the nodes generates its own signature private key and verification public key respectively;
[0041] The signing module is configured to sign the same message to be signed by each node based on the signature private key to obtain its own signed message;
[0042] A verification module is configured to verify each of the nodes on its own signature message based on the verification public key and output a verified signature message to generate N signature message sets;
[0043] The verification module is further configured to verify the N group signature messages respectively based on the group public key;
[0044] The control module is configured to control the corresponding groups to output the public random numbers in a set order based on the verified group signature message.
[0045] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium storing a computer program, wherein, when the computer program is executed by a processor, the method for implementing a random beacon as disclosed in the first aspect is implemented.
[0046] In a fourth aspect, an electronic device provided by an embodiment of the present invention includes:
[0047] processor;
[0048] A memory stores a computer program which, when executed by the processor, implements the method for implementing a random beacon as disclosed in the first aspect.
[0049] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0050] (1) Each node is grouped and managed, and random beacons are independently performed within each group. The tasks are assigned to different groups, and the tasks can be processed in parallel, improving the efficiency.
[0051] (2) By having each group perform random beacons in turn according to a preset order, it is possible to avoid the situation of a certain node being overloaded or having unbalanced load, improving the stability. At the same time, the sequential output can also improve the fault tolerance of the system. Even if a certain group fails, other groups can still perform random beacons normally.
[0052] (3) Using quantum random numbers as the entropy source of the random beacon, since quantum random numbers are true random numbers and are not easily cracked, the security is improved.
[0053] (4) By mutual supervision among nodes, abnormal nodes are determined and reported to the system for processing, improving the credibility and security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Through the following description in conjunction with the drawings, the above objects and features of the present invention will become clearer.
[0055] Figure 1 FIG. shows a schematic flowchart of a method for implementing a random beacon according to an exemplary embodiment of the present invention.
[0056] Figure 2 FIG. shows a schematic module structure diagram of a system for implementing a random beacon according to an exemplary embodiment of the present invention.
[0057] Figure 3 FIG. shows a schematic flowchart of sharing quantum keys among nodes in a single group in the method for implementing a random beacon according to an exemplary embodiment of the present invention.
[0058] Figure 4 FIG. shows a schematic flowchart of a single group implementing a random beacon in the method for implementing a random beacon according to an exemplary embodiment of the present invention.
[0059] Figure 5 FIG. shows a schematic diagram of a single group implementing a signature verification process in the method for implementing a random beacon according to an exemplary embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0060] Next, embodiments of the present invention will be described in detail with reference to the accompanying drawings.
[0061] Referring to Figure 1 , the method for implementing a random beacon according to an exemplary embodiment of the present invention includes the following steps:
[0062] Step S1, group M nodes in the same blockchain to obtain N groups. Each node in the N groups respectively and in real time obtains the behaviors of the remaining nodes in its own group and, based on this behavior, determines whether there are abnormal nodes, and removes the abnormal nodes, where both M and N are natural numbers.
[0063] In some examples, determining whether there are abnormal nodes based on this behavior includes:
[0064] For a node that exhibits one or more of the three behaviors of sending an error message, providing an incorrect signature result, and refusing to participate in the random beacon, it is determined that the node is an abnormal node and the node is marked as a malicious node.
[0065] In some examples, determining whether there are abnormal nodes based on the said behavior includes:
[0066] For a node that exhibits one or both of the behaviors of being unable to send information in a timely manner and having a response duration greater than a set threshold, it is determined that the node is an abnormal node and the node is marked as a slow node.
[0067] Since malicious nodes and slow nodes may have a negative impact on the security and performance of the system, corresponding measures need to be taken to mitigate these risks. A corresponding complaint mechanism and exit mechanism are constructed according to the type of abnormal node for handling abnormal nodes. Once an abnormal node is discovered, other nodes can report the abnormal node to the system through the complaint mechanism. By mutually supervising the behaviors among nodes, abnormal nodes are determined and reported to the system for processing, improving the credibility and security of the system.
[0068] Among them, the complaint mechanism allows other nodes to report the existence of abnormal nodes to the system and provide relevant evidence. When an abnormal node is discovered, other nodes can submit a complaint to the system administrator and provide the necessary evidence and information. When a node submits a complaint, the system has a corresponding processing flow to review the complaint, including verifying the validity of the complaint and taking appropriate measures according to the situation to solve the problem, such as warning the node operator, temporarily disabling the node, removing the node, etc. At the same time, the complained node also has the right to appeal.
[0069] Specifically, when a certain node is determined to be an abnormal node, other nodes can initiate a complaint request to the system by calling the node management smart contract. The complaint request is divided into malicious node complaints and slow node complaints, and relevant evidence and information are provided. After receiving the complaint request, the system broadcasts it to the entire network. All nodes review and process the complaint request and vote on the complaint according to the results. If it is unified through the consensus of the entire network, the complaint is confirmed to be valid, and an effective complaint is recorded for the abnormal node. Each time an abnormal node is successfully complained about, an effective complaint record is accumulated. Among them, the effective complaints of malicious nodes and slow nodes are processed and recorded separately. The effective complaint of abnormal behavior is judged based on the evidence provided by the complaining node. If different nodes initiate complaints based on the same evidence, only one broadcast is made, and an effective complaint is recorded for the abnormal node after passing the consensus of the entire network.
[0070] Furthermore, in order to better manage nodes, maintain the stability of the system, and avoid abnormal behaviors of nodes caused by occasional problems. Different thresholds are set for the number of complaints received by malicious nodes and slow nodes. Threshold a is set for malicious nodes, and two thresholds b and c (b < c) are set for slow nodes respectively. Among them, thresholds b and c correspond to two different management methods for slow nodes.
[0071] While recording the number of effective complaints of abnormal nodes, the node management smart contract compares the cumulative number of effective complaints of the node with the corresponding threshold and implements corresponding handling measures for the node according to the comparison results.
[0072] Specifically, when the cumulative number of effective complaints received by a malicious node exceeds threshold a, it is marked as an abnormal node and classified as a malicious node. The node is prohibited from continuing to participate in the random beacon and is removed from the system according to the exit mechanism.
[0073] When the cumulative number of effective complaints received by a slow node exceeds threshold b or c, the handling measures for the node will be triggered. Specifically, when the cumulative number of effective complaints received by a slow node exceeds threshold b, the system will issue a warning to the node, requiring the node to be temporarily disabled, optimized, and then enabled again. When the cumulative number of effective complaints received by a slow node exceeds threshold c, the system will mark the node as an abnormal node, classify it as a slow node, and remove it from the system according to the exit mechanism.
[0074] For the situation where nodes are confirmed to be abnormal nodes, an exit mechanism is needed to remove these nodes from the system. For abnormal nodes, the embodiment of the present invention constructs a corresponding exit mechanism. The exit mechanism is executed for the nodes confirmed to be abnormal nodes.
[0075] The exit mechanism allows abnormal nodes to be removed from the system. In an embodiment of the present invention, one feasible solution is to use two schemes to execute different exit mechanisms according to the different numbers of abnormal nodes, namely dynamic exit and static exit.
[0076] First, sum the numbers of malicious nodes and slow nodes to calculate the total number f of abnormal nodes in the system. Among them, if a node is both a malicious node and a slow node, only count this node once. When the number f of abnormal nodes is less than n - p, execute the dynamic exit mechanism; otherwise, execute the static exit mechanism. (n is the total number of nodes participating in the distributed key generation in a certain group of the system in the most recent time, and p is a threshold related to n set according to the system rules)
[0077] Dynamic exit: When the number f of abnormal nodes is less than n - p, the number of normal nodes in the system meets the minimum number of nodes required to implement the random beacon, and can complete message signature and random beacon calculation. Therefore, after determining the list of abnormal nodes, remove the abnormal nodes from the system. During the removal process, the system still performs normal random beacon calculation internally, outputs a common random number, and provides a random beacon.
[0078] At the same time, the system recalculates the threshold p according to the latest number n - f of normal nodes, and the normal nodes perform distributed key generation to generate a new distributed key pair.
[0079] After the malicious nodes and slow nodes are successfully removed, the normal nodes in the system use the newly generated key to perform random beacon calculation and verification, output a common random number, and provide a random beacon.
[0080] Static exit: When the number f of abnormal nodes is greater than or equal to n - p, the remaining normal nodes in the system do not meet the minimum number of nodes required for random beacon generation, and the system does not meet the conditions for completing message signature and random beacon calculation.
[0081] After determining the list of abnormal nodes, the system suspends service and removes them from the system. After the abnormal nodes are completely removed, the system recalculates the threshold p according to the number of normal nodes, performs distributed key generation. After completing the distributed key generation, the system restarts and continues to perform random beacon based on the new distributed key pair, outputs a common random number, and realizes the random beacon.
[0082] Specifically, the M nodes can be grouped based on quantum random numbers, which improves the randomness of grouping.
[0083] Specifically, divide the M nodes into N groups, where the number of nodes in each group is equal or close, and the number of nodes in each group is not less than a set first threshold and not greater than a set second threshold. The first threshold is the lower limit of the number of nodes that can be used to implement the random beacon, and the second threshold is the upper limit of the number of nodes that can be used to implement the random beacon. Group and manage the nodes of the same blockchain, and generate random beacons separately within each group of nodes. Each group takes turns to generate random beacons to improve efficiency.
[0084] Among them, based on the decentralization and immutability of the blockchain, no third-party intervention is required, which increases the reliability and fairness of the random beacon.
[0085] Step S2: Based on the distributed key generation algorithm, calculate the group public keys of the N groups respectively, and each node in the N groups generates its own signature private key and verification public key.
[0086] Specifically, one node is configured with one quantum random number generator, or multiple nodes can be configured with one quantum random number generator, or one node can be configured with multiple quantum random number generators, aiming to facilitate each node to obtain quantum random numbers normally and ensure sufficient entropy sources.
[0087] In some examples, before step S2, the method specifically includes:
[0088] Based on the obtained first quantum random number, each node generates its own initial quantum key respectively;
[0089] Each node divides the initial quantum key into n parts of quantum keys respectively;
[0090] Each node obtains one part of the quantum key belonging to itself from the n parts of the quantum keys, and sends the remaining n - 1 parts of the quantum keys to the remaining n - 1 nodes in sequence;
[0091] Each node verifies the received n - 1 parts of the quantum keys respectively. If all the n - 1 parts of the quantum keys are verified successfully, then execute the above step S3.
[0092] Specifically, the specific process of each node verifying the received n - 1 parts of the quantum keys respectively is:
[0093] For any node P i , by comparing with to obtain the verification result. When , the verification fails, and the quantum key generation process is aborted. When , the verification is successful, and then the node P is calculated through the formula i Signature private key S i , the signature private key s i is securely stored, and the initial key share f sent from other nodes P l is deleted l (i), where 1 ≤ l ≤ n, l ≠ i, n is the total number of nodes in the blockchain, and n / 2 ≤ t < n.
[0094] As Figure 3 shown, when the number of nodes in a certain group is 4, the specific process of sharing quantum keys among each node is as follows:
[0095] Node P0 divides its own initial quantum key into 4 quantum keys: f0(0), f0(1), f0(2), f0(3), where f0(0) is reserved by node 0 itself, f0(1) is sent to node P1, f0(2) is sent to node P2, and f0(3) is sent to node P3.
[0096] Node P1 divides its own initial quantum key into 4 quantum keys: f1(0), f1(1), f1(2), f1(3), where f1(1) is reserved by node P1 itself, f1(0) is sent to node P0, f1(2) is sent to node P2, and f1(3) is sent to node P3.
[0097] Node P2 divides its own initial quantum key into 4 quantum keys: f2(0), f2(1), f2(2), f2(3), where f2(2) is reserved by node P2 itself, f2(0) is sent to node P0, f2(1) is sent to node P1, and f2(3) is sent to node P3.
[0098] Node P3 divides its own initial quantum key into 4 quantum keys: f3(0), f3(1), f3(2), f3(3), where f3(3) is reserved by node P3 itself, f3(0) is sent to node P0, f3(1) is sent to node P1, and f3(3) is sent to node P3.
[0099] In some examples, before step S2, the method further specifically includes:
[0100] Each node respectively obtains t second quantum random numbers from the quantum random number generator to generate its own quantum random number sequence, where t is the minimum number of signature private keys required to aggregate the group private key and n / 2 ≤ t < n, and n is the total number of nodes in each group;
[0101] Each node separately generates a proof of knowledge and a common commitment for the first quantum random number in the quantum random number sequence, and broadcasts the proof of knowledge and the common commitment as proof information to the remaining n - 1 nodes.
[0102] Specifically, when the total number of nodes n on the blockchain is 4, and the 4 nodes are node 0, node 1, node 2, and node 3 respectively, the value of the threshold t is set to 3. Taking node 0 as an example for illustration, other nodes perform the same operations. The quantum random number generator provides a quantum random number to node 0. Node 0 samples the quantum random number provided by the quantum random number generator t = 3 times to obtain 3 quantum random numbers, forming a quantum random number sequence (a 00 , a 01 , a 02 ), where (a 00 , a 01 , a 02 ) are the coefficients of the polynomial coefficients .
[0103] Specifically, through the formula σ i = (R i , μ i ), each node calculates the proof of knowledge σ i of the corresponding quantum random number, where R is randomly and uniformly selected i = g k , where g is the generator of the cyclic group G of order q, and μ i = k + a i0 ·c i , where Φ is the context string for preventing replay attacks. At the same time, each node generates a common commitment , where each node broadcasts the common commitment and the proof of knowledge σ i as proof information to the remaining all n - 1 nodes respectively, and a i0 is the first quantum random number among the t second quantum random numbers obtained by the (i + 1)-th node.
[0104] Each node verifies the received proof of knowledge and common commitment respectively. If the received proof of knowledge and common commitment both pass the verification, then the proof of knowledge and the common commitment are deleted.
[0105] Specifically, each node confirms the verification result by calculating whether R l is equal to . If , the verification is successful, and then σ lDelete and continue to generate the quantum key; conversely, if the verification fails, the quantum key generation process is aborted, where 0 ≤ l ≤ n - 1 and l ≠ i.
[0106] In some examples, step S2 specifically includes:
[0107] Based on the formula Each node calculates its own signature private key respectively, where a ij is the j-th quantum random number among the t second quantum random numbers obtained by the (i + 1)-th node, 0 ≤ i ≤ n - 1, 0 ≤ l ≤ n - 1, l ≠ i.
[0108] In some examples, step S2 specifically further includes:
[0109] Based on the formula Each of the nodes calculates its own verification public key Y i ;
[0110] Based on the formula Calculate the group public key V of the group where it is located respectively; where g is the generator of the cyclic group G of order q, and s i is the signature private key of the (i + 1)-th node,
[0111] Among them, the signature private key, verification public key, and group public key calculated based on the quantum random numbers are all true random numbers, ensuring the security of the signature private key, verification public key, and group public key.
[0112] In some examples, after step S2, the method further includes:
[0113] Based on the formula Each node calculates the verification public key of any node P l respectively, where q is the order of the cyclic group G, and randomly and uniformly select 1 ≤ l ≤ n, l ≠ i, n is the total number of nodes in each group of groups, and n / 2 ≤ t < n.
[0114] Step S3, based on the signature private key, each node signs the same message to be signed to obtain its own signed message.
[0115] Specifically, each node uses the threshold signature algorithm to sign the message to be signed. Among them, the threshold signature algorithm starts from the single-signature algorithm and splits the private key among each participant. In the signature phase, each participant can run the signature algorithm to obtain the signature, and any party can use the algorithm for verifying the signature of a single signer to verify the signature. That is to say, the signatures generated by the threshold signature algorithm and the single-signature algorithm are interchangeable. The threshold signature algorithm is a method based on the signer generating a single digital signature. The signature generated by this method looks the same as the signature generated without using the threshold signature algorithm, but the signature generated by the threshold signature algorithm is created by sharing multiple private keys, so that no single participant can fully control the private key.
[0116] Step S4, based on the verification public key, each node verifies its own signed message and outputs the verified signed messages, generating N sets of signed messages.
[0117] Step S5, based on the group public key, verify the N group-signed messages respectively.
[0118] Step S6, based on the set of verified group-signed messages, control each corresponding group to output the common random number in the set order.
[0119] In some examples, step S6 specifically includes:
[0120] Perform a hash calculation on the verified group-signed messages, use the obtained calculation result as the common random number, and control each corresponding group to take turns outputting the corresponding calculation result in the set order.
[0121] Specifically, for the set of verified group-signed messages, perform a hash calculation on each set of signed messages respectively. Each set of group-signed messages after the hash calculation is the common random number, realizing the random beacon.
[0122] Specifically, according to the preset rounds, each group outputs the common random number generated by itself in turn, which can avoid the situation of overload or unbalanced load inside a certain group of nodes, ensuring balance and stability. At the same time, taking turns to output can also improve the fault tolerance of the system. Even if a failure occurs inside a certain group, other groups can still continue to output random numbers for realizing the random beacon, improving continuity and reliability.
[0123] So far, each node in each group has generated its own signature private key S i and verification public key Y i as well as the group public key V on the blockchain. When it is necessary to perform global verification on the set of verified group-signed messages using the private key, this group public key can be used for verification.
[0124] Furthermore, a key update smart contract can also be deployed on the blockchain. The key update smart contract mainly provides two functional interfaces: one is a timed automatic update functional interface, and the other is an active application update functional interface. For the automatic update function, the key update smart contract will record the time point of each quantum key generation on the chain. According to the time of the most recent quantum key generation, a certain period is set. After each period ends, the quantum random number is called again to generate a quantum key once to address the possible leakage of the signature private key on the blockchain. When there is an increase or decrease in nodes on the blockchain, or when a node on the chain discovers that there is a leakage or theft of the signature private key, the active update function of the key update smart contract can be actively called to regenerate the quantum key to ensure security.
[0125] Figure 2 The system shown for implementing the random beacon includes:
[0126] A grouping module, configured to group M nodes in the same blockchain to obtain N groups. Each node in the N groups respectively and real-time obtains the behaviors of the remaining nodes in its own group and determines whether there are abnormal nodes according to the behaviors, and removes the abnormal nodes, where both M and N are natural numbers;
[0127] A generation module, configured to respectively calculate the group public keys of the N groups based on the distributed key generation algorithm. Each node in the N groups respectively generates its own signature private key, verification public key, and group public key;
[0128] A signature module, configured to, based on the signature private key, each node signs the same message to be signed to obtain its own signed message;
[0129] A verification module, configured to, based on the verification public key, each of the nodes respectively verifies its own signed message and outputs the verified signed message, generating N sets of signed messages;
[0130] The verification module is further configured to, based on the group public key, respectively verify the N group signed messages;
[0131] A control module, configured to, based on the verified group signed messages, control the corresponding groups to output the common random number in a set order.
[0132] Specifically, in order to ensure the publicly verifiable nature of the system for implementing the random beacon provided by the embodiments of the present invention, the system provides a verification interface to external users. This verification interface can be used to verify whether the services provided by the system are trustworthy and provide necessary evidence and information.
[0133] Specifically, the verification interface has functions such as querying beacons, verifying beacons, and querying algorithms. Among them:
[0134] The beacon query function includes: Users can input the round ID information of the random beacon through the query function provided by the verification interface, and the system will return the beacon value matching the round ID and the generation time of the random beacon.
[0135] The beacon verification function includes: The system provides a function to verify beacons. When users input the round ID of the beacon, the system will verify the validity of the beacon and return the verification result. At the same time, the system will also provide the message to be signed in this round, the node information participating in the random beacon in this round, the node signature message, the group signature message of the beacon in this round, and the group public key. Users can use the above parameters to verify the correctness of the random beacon provided in this round by themselves.
[0136] The algorithm query function includes: Users can query the generation steps of the random beacon currently provided by the system, the group public key, and the threshold signature algorithm used through the algorithm query function.
[0137] All users can verify the random beacon by calling the verification interface and the returned results of the interface to confirm whether the provided random beacon is trustworthy.
[0138] Figure 4 Shows a schematic flowchart of a method for a certain group of groups to implement random beacons. The entire process for implementing random beacons is divided into two stages: the distributed quantum key generation stage and the signature verification stage.
[0139] In the blockchain, the total number of nodes in each group of groups is M, and these nodes are divided into N groups. Each node in each group of groups is represented as P i , i = 1,..., n. A threshold t is set for the number of blockchain nodes. The threshold t is the number of signature private keys required to construct the group public key, and n is the number of nodes in each group of groups.
[0140] In the distributed quantum key generation stage, each node in each group randomly samples t random numbers (a 00 , a 01 ,..., a 0(t-1) ) as the coefficients of the t - 1 step polynomial , calculates and broadcasts the proof of knowledge of the zero - order coefficient of the polynomial to all other nodes, that is, the proof of knowledge σ i0 of the first random number a i , and a common commitment C i . Each other node receives σ i and C iWhen it is verified, if the verification passes, the next step is carried out; if the verification fails, the quantum key is regenerated.
[0141] Each node in each group obtains the initial quantum key from the quantum random number generator, divides the initial quantum key into n parts of quantum keys, where one part of the quantum key is reserved by the node itself, and the remaining n - 1 parts are separately sent to the remaining n - 1 nodes. When a node receives the initial key share sent separately by other nodes, it separately verifies the initial key share. If any initial key share verification fails, the process is aborted and the quantum key generation is restarted. After all the received initial key shares are successfully verified, the node generates its own signature private key s according to the initial key share. i Other nodes perform the same operation to generate their own signature private keys respectively.
[0142] Each node P i calculates its own verification public key Y i and the group public key V. Among them, any node can obtain the verification public key of any other node by calculating Y i . After the above steps are completed, the distributed quantum key generation stage in the process of the random beacon generating random numbers is completed. All nodes broadcast the calculated group public key. After passing the on-chain consensus, it is stored on the blockchain. When verifying the signature message set, this group public key can be used for verification.
[0143] In the signature verification stage, the random beacon generates random numbers according to rounds, and each generated random number is one round. A message m to be signed is preset. The message to be signed is generated according to certain rules. In each round of the random beacon (i.e., one random number generation), the message m to be signed is different. Let r represent the round of the random beacon, then the message to be signed in each round is represented by m r ; in each round of random beacon generation, all nodes use their own signature private keys to sign the message m to be signed r and after the signature is completed, the signed message is sent to the deployed smart contract.
[0144] In the signature verification phase, a random number is calculated for each round through a threshold signature algorithm. The threshold signature algorithm is implemented by deploying a smart contract on the blockchain. The smart contract acts as a node signer, collecting and verifying the signature messages sent by the nodes. When the correct signature messages of t nodes in each group are collected, the t correct signature messages are aggregated to obtain the group signature result for the message of the current round, and the number of correct signature messages is greater than or equal to t. The group public key generated in the distributed quantum key generation phase is used to verify the group signature result. After successful verification, the group signature result is hashed, and the hashed group signature result is the random number output for the current round.
[0145] As Figure 5 shown, taking the generation of a random number by a random beacon with 4 participants as an example, a node is assigned to each participant to participate in the random beacon. The 4 nodes on the blockchain are numbered P0, P1, P2, and P3 respectively, and the threshold t is set to 3.
[0146] The four nodes start to calculate the random number. In the distributed quantum key generation phase, node P0 calculates and obtains its own signature private key S0 and verification public key Y0 through the quantum key generation method. Similarly, nodes P1, P2, and P3 respectively obtain their own signature private keys S1, S2, S3, and verification public keys Y1, Y2, Y3, and all nodes obtain a copy of the group public key V through calculation and on-chain broadcast.
[0147] In the signature verification phase, each successful signature verification realizes a random beacon and outputs a public random number.
[0148] As Figure 5 shown, node P0 uses its signature private key S0 to sign the message m r to generate the signature message Sig0(m r ), and sends the signature message Sig0(m r ) to the smart contract. Similarly, nodes P1, P2, and P3 also perform the same operation, using their own signature private keys S1, S2, S3 to sign the message m r to generate the signature messages Sig1(m r ), Sig2(m r ), Sig3(m r ), and send the signature messages to the smart contract.
[0149] After receiving the signed messages sent by the nodes, the smart contract verifies them using the verification public keys Y0, Y1, Y2, and Y3 of the nodes themselves, records the signed messages that pass the verification as correctly signed messages, and after collecting the correctly signed messages sent by any 3 of the four nodes, performs signature processing on them and outputs the message m r for the group signature result Sig(m r ).
[0150] Verify the group signature result Sig(m r ) using the group public key V. After passing the verification, perform a hash calculation on the group signature result, and the group signature result output after the hash calculation is the common random number for this round.
[0151] The randomness beacon can be used to provide on-chain randomness and is a key factor for fair, secure, and transparent on-chain applications. The technical solution of the present invention implements a random beacon based on a blockchain, encrypts and verifies through the quantum key of the blockchain, and then generates a decentralized random number for implementing the random beacon to provide a secure and reliable random number to the outside world. All participants on the blockchain need to agree on the output (randomness), and malicious participants in the protocol should not be able to bias or predict the output.
[0152] In addition, according to an exemplary embodiment of the present invention, a computer-readable storage medium storing a computer program may also be provided. The computer-readable storage medium stores a computer program that, when executed by a processor, causes the processor to execute the method for implementing a distributed random beacon based on a blockchain according to an exemplary embodiment of the present invention. The computer-readable recording medium is any data storage device capable of storing data readable by a computer system. Examples of computer-readable recording media include: read-only memory, random access memory, read-only optical discs, magnetic tapes, floppy disks, optical data storage devices, and carrier waves (such as data transmission via the Internet through a wired or wireless transmission path).
[0153] In addition, according to an exemplary embodiment of the present invention, a computing device may also be provided. The computing device includes a processor and a memory. The memory is used to store a computer program. The computer program is executed by the processor to cause the processor to execute the computer program of the method for implementing a distributed random beacon based on a blockchain according to an exemplary embodiment of the present invention.
[0154] It should be noted that the first, second, third, fourth, etc. in the above description are used to distinguish features with the same name in the same or different embodiments, and are not limitations in terms of quantity. Moreover, the present invention is not limited to the specific configurations and processes described above or shown in the figures. The above description is only the specific implementation manner of the present invention. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the described systems, devices, modules or units can refer to their own processes in the method embodiments and will not be elaborated here. It should be understood that the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present invention.
Claims
1. A method for implementing a random beacon, characterized in that, It includes the following steps: Step S1: Group M nodes in the same blockchain to obtain N groups. Each node in the N groups respectively and real-time obtains the behaviors of the remaining nodes in its own group, and based on the behaviors, determines whether there are abnormal nodes, and removes the abnormal nodes, where both M and N are natural numbers; Step S2: Based on the distributed key generation algorithm, calculate the group public keys of the N groups respectively. Each node in the N groups respectively generates its own signature private key, verification public key, and group public key; Step S3: Based on the signature private key, each of the nodes signs the same message to be signed to obtain its own signed message; Step S4: Based on the verification public key, each of the nodes respectively verifies its own signed message and outputs the verified signed messages, generating N sets of group signature messages; Step S5: Based on the group public key, verify the N sets of group signature messages respectively; Step S6: Based on the set of verified group signature messages, control each corresponding group to output a common random number in a set order.
2. The method for implementing a random beacon according to claim 1, wherein Judging whether there are abnormal nodes according to the behaviors includes: For a node that has one or more of the behaviors of sending an error message, providing an incorrect signature result, and refusing to participate in the random beacon, it is determined that the node is an abnormal node and the node is marked as a malicious node.
3. The method for implementing a random beacon according to claim 1, characterized in that, Judging whether there are abnormal nodes according to the behaviors includes: For a node that has one or both of the behaviors of being unable to send information in time and having a response duration greater than a set threshold, it is determined that the node is an abnormal node and the node is marked as a slow node.
4. The method for implementing a random beacon according to claim 1, characterized in that, Step S6 includes: Performing a hash calculation on the verified group signature messages, using the obtained calculation result as the common random number, and controlling each corresponding group to output the calculation result in a set order in turn.
5. The method for implementing a random beacon according to claim 1, characterized in that, Before step S2, the method further includes: S21: Each node respectively obtains a first quantum random number from a quantum random number generator; S22: Based on the first quantum random number, each node respectively generates its own initial quantum key; S23: Each node respectively divides the initial quantum key into n parts of quantum keys; S24: Each node respectively obtains one part of the quantum key belonging to itself from the n parts of the quantum keys, and sequentially sends the remaining n - 1 parts of the quantum keys to the remaining n - 1 nodes; S25: Each node respectively verifies the received n - 1 parts of the quantum keys. If all the n - 1 parts of the quantum keys are verified successfully, then execute step S2.
6. The method for implementing a random beacon according to claim 5, wherein, Before step S2, the method further includes: Each of the nodes respectively obtains t second quantum random numbers from the quantum random number generator and generates its own quantum random number sequence, where n / 2 ≤ t < n, and n is the total number of nodes in each group; Each of the nodes respectively generates a proof of knowledge and a common commitment of the first quantum random number in the quantum random number sequence, and broadcasts the proof of knowledge and the common commitment as proof information to the remaining n - 1 nodes; Each of the nodes verifies the received knowledge proof and the common commitment respectively. If both the knowledge proof and the common commitment pass the verification, steps S21 - S25 are executed and the knowledge proof and the common commitment are deleted.
7. The method for implementing a random beacon according to claim 6, wherein Step S2 includes: Based on the formula Each node calculates its own signature private key respectively, where a ij is the j-th quantum random number among the t second quantum random numbers obtained by the (i + 1)-th node, 0 ≤ i ≤ n - 1, 0 ≤ l ≤ n - 1, l ≠ i.
8. The method for implementing a random beacon according to claim 7, wherein Step S2 further includes: Based on the formula Each of the nodes calculates its own verification public key Y i ; Based on the formula calculate the group public key V of each group respectively; where g is the generator of the cyclic group G of order q, and s i is the signature private key of the (i + 1)-th node, 9. The method for implementing a random beacon according to claim 8, characterized in that, After step S2, the method further includes: Based on the formula Each of the nodes calculates the verification public key of any node P within the group, where q is the order of the cyclic group G, and 1 ≤ l ≤ n, l ≠ i, n / 2 ≤ t < n are randomly and uniformly selected l where q is the order of the cyclic group G, and 1 ≤ l ≤ n, l ≠ i, n / 2 ≤ t < n are randomly and uniformly selected 1 ≤ l ≤ n, l ≠ i, n / 2 ≤ t < n 10. A system for implementing a random beacon, characterized in that, Includes: A grouping module, configured to group M nodes in the same blockchain to obtain N groups. Each node in the N groups respectively and real - time obtains the behaviors of the remaining nodes in its own group and determines whether there are abnormal nodes according to the behaviors, and removes the abnormal nodes, where both M and N are natural numbers; A generation module, configured to calculate the group public keys of the N groups respectively based on the distributed key generation algorithm. Each node in the N groups respectively generates its own signature private key and verification public key; A signature module, configured to sign the same message to be signed by each of the nodes based on the signature private key to obtain its own signed message; A verification module, configured to verify its own signed message by each of the nodes based on the verification public key and output the verified signed messages, generating N sets of signed messages; The verification module is further configured to verify the N group - signed messages based on the group public keys; A control module, configured to control the corresponding groups to output common random numbers in a set order based on the verified group - signed messages.
11. A computer-readable storage medium storing a computer program, wherein, When the computer program is executed by a processor, it implements the method for implementing a random beacon as described in any one of claims 1 to 9.
12. An electronic device, comprising: A processor; A memory storing a computer program, which when executed by the processor, implements the method for implementing a random beacon as described in any one of claims 1 to 9.