Intelligent contract enhancement method and system based on formal verification

By syntax analysis of smart contract code and automatic generation of formal regulations, combined with model detection and dynamic testing, the problems of low efficiency and insufficient coverage of smart contract security verification are solved, efficient vulnerability positioning and repairing are achieved, and the security and development efficiency of smart contracts are improved.

CN120337228AInactive Publication Date: 2025-07-18李丹
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510400438.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2025-07-18
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The security verification of existing smart contracts relies on manual audits and fuzzy testing, which has low efficiency and insufficient coverage, high complexity and low automation, and has no combination of dynamic testing, feedback delays, and inefficient repair of vulnerabilities.

Method used

By syntax analysis of the smart contract code, formal regulations are automatically generated, logical consistency is verified using model detection tools, boundary condition test cases are dynamically generated, and real-time feedback is provided to the development environment, and the exception path is covered in combination with dynamic testing.

Benefits of technology

It significantly reduces the technical threshold and time cost of formal verification, ensures the rigor of contract logic, covers abnormal execution paths, realizes real-time vulnerability positioning and repair suggestions, and improves security and development efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337228A_ABST
    Figure CN120337228A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent contract enhancement method and system based on formalized verification, and the method comprises the steps: carrying out the grammar analysis of a target intelligent contract code, extracting a contract function logic and a state variable, automatically generating a formalized protocol corresponding to the contract function logic based on a predefined formalized protocol template, and carrying out the verification of the formalized protocol. And verifying the logic consistency of the formal protocol and the target smart contract code through a model detection tool to obtain a verification result, when the verification result indicates that a logic conflict exists, dynamically generating a boundary condition test case according to a conflict type, and feeding back the verification result and the test case to a smart contract development environment in real time. The system comprises a protocol generation module, a verification engine, a dynamic test module and an interactive interface. Therefore, the formal protocol is automatically generated and the verification tool is integrated, the verification complexity and error are reduced, the leakproofness is ensured, dynamic testing and real-time feedback are combined, an abnormal execution path is covered, vulnerabilities are quickly positioned, and the safety and the development efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology, and specifically refers to an intelligent contract enhancement method and system based on formal verification. Background Art

[0002] Smart contracts are widely used in blockchain technology, but their code vulnerabilities may cause serious economic losses. In the prior art, the security verification of smart contracts mainly relies on manual auditing and fuzz testing, which have problems of low efficiency and insufficient coverage.

[0003] Although the formal verification method can ensure the correctness of the contract logic through mathematical proof, the existing solutions have the following defects: First, the verification complexity of smart contracts is high, and formal specifications need to be manually written, which is time-consuming and error-prone. Second, the automation degree is low, lacking integration with the development process, and the verification tools run in isolation. Third, dynamic testing is missing, and formal verification only covers static logic without generating test cases by combining dynamic execution paths. Fourth, the feedback is delayed, and the verification results are not synchronized to the development environment in real time, resulting in low efficiency in fixing vulnerabilities. Summary of the Invention

[0004] The present invention aims to solve at least to some extent the technical problems in the above technologies.

[0005] For this purpose, on the one hand, the present invention discloses an intelligent contract enhancement method based on formal verification, including the following steps:

[0006] S1. Parse the syntax of the target smart contract code, and extract the contract function logic and state variables;

[0007] S2. Automatically generate a formal specification corresponding to the contract function logic based on a predefined formal specification template;

[0008] S3. Verify the logical consistency between the formal specification and the target smart contract code through a model checker to obtain a verification result;

[0009] S4. When the verification result indicates a logical conflict, dynamically generate boundary condition test cases according to the conflict type;

[0010] S5. Real-time feedback the verification result and test cases to the smart contract development environment.

[0011] In addition, the intelligent contract enhancement method based on formal verification disclosed by the present invention may also have the following additional technical features:

[0012] In an embodiment of the present invention, in step S2, the formal specification template includes, but is not limited to:

[0013] The logical expressions of the preconditions and postconditions of the function, as well as the mathematical descriptions of the value range constraints of the state variables.

[0014] In one embodiment of the present invention, in step S3, the model checking tool describes the contract behavior using a temporal logic formula and traverses all possible execution paths through symbolic execution.

[0015] In one embodiment of the present invention, in step S4, the method for generating the boundary condition test cases includes, but is not limited to:

[0016] Extracting the abnormal input parameter combinations in the logical conflict, and injecting the abnormal input parameter combinations into the test framework to trigger the contract execution and record the output.

[0017] In one embodiment of the present invention, in step S5, the real-time feedback includes, but is not limited to:

[0018] Highlighting the location of the vulnerable code in the development environment interface, and providing a logical code snippet for the repair suggestion.

[0019] In one embodiment of the present invention, after step S3, it further includes:

[0020] S31. When the verification result passes, compiling the target smart contract code into bytecode;

[0021] S32. Decompiling the bytecode to verify its logical equivalence with the original code.

[0022] In one embodiment of the present invention, in step S32, the verification of the logical equivalence includes, but is not limited to:

[0023] Performing symbolic execution on the source code and the bytecode respectively to generate corresponding path constraint sets, comparing the path constraint sets of the two, if there are inconsistent constraint conditions, it is determined as logically non-equivalent, and otherwise, performing dynamic testing on the source code and the bytecode within the same input domain to verify the output consistency.

[0024] In one embodiment of the present invention, before step S1, receiving the contract code input by the user and detecting its syntax legality, and when a syntax error is detected, terminating the process and returning an error message.

[0025] In one embodiment of the present invention, in step S4, when the test case execution fails, automatically generating a minimized counterexample and mapping it to the conflict location of the formal specification.

[0026] On the other hand, the present invention discloses an enhanced system for smart contracts based on formal verification, including:

[0027] A specification generation module, configured to parse smart contract code and automatically generate a formal specification;

[0028] A verification engine, connected to the specification generation module, configured to perform model checking and output a verification result;

[0029] A dynamic testing module, connected to the verification engine, configured to generate test cases according to the verification result;

[0030] An interaction interface, connected to the dynamic testing module, configured to synchronize the verification result and test cases to a development environment, where

[0031] the specification generation module, verification engine, dynamic testing module, and interaction interface are connected in series in sequence to form a closed-loop data flow.

[0032] According to the smart contract enhancement method and system based on formal verification disclosed in the present invention, on the one hand, by automatically generating a formal specification and integrating a model checking tool, the technical threshold and time cost of formal verification are significantly reduced, the error-proneness of manually writing specifications is avoided, and the mathematical rigor of contract logic is ensured. On the other hand, by combining dynamic test case generation and a real-time feedback mechanism, not only the abnormal execution paths that are difficult to reach by static formal verification are covered, but also vulnerabilities can be located immediately in the development stage and repair suggestions can be provided, thereby comprehensively improving the security and development efficiency of smart contracts.

[0033] Additional content and advantages of the present invention will be given in the following description, or understood through the practice of the present invention. Description of the Drawings

[0034] The technical solutions and beneficial effects of the present invention will become obvious and easy to understand from the following content in combination with the drawings, where:

[0035] Figure 1 is a working flowchart of the smart contract enhancement method and system based on formal verification of the present invention;

[0036] Figure 2 is another working flowchart of the smart contract enhancement method and system based on formal verification of the present invention;

[0037] Figure 3 is another working flowchart of the smart contract enhancement method and system based on formal verification of the present invention;

[0038] Figure 4 is another working flowchart of the smart contract enhancement method and system based on formal verification of the present invention. Detailed Embodiments

[0039] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.

[0040] Next, a method and system for enhancing smart contracts based on formal verification disclosed in the present invention will be described with reference to the accompanying drawings;

[0041] As Figure 1 、 Figure 2 、 Figure 3 and Figure 4 shown, a method for enhancing smart contracts based on formal verification is characterized by including the following steps:

[0042] A method for enhancing smart contracts based on formal verification includes the following steps:

[0043] S1. Perform syntax parsing on the target smart contract code, and extract contract function logic and state variables;

[0044] Specifically, a professional syntax parser is used. For example, for the commonly used Solidity language for smart contracts, its syntax rules are used to scan and analyze the input contract code line by line;

[0045] During the parsing process, the function definitions in the contract are identified, including information such as the parameter list and return value type of the function, and then the logical implementation part of the function, that is, the code logic in the function body, is extracted;

[0046] At the same time, the state variables defined in the contract are found, and key information such as their data types and initial values is clarified;

[0047] This process provides basic data for subsequent generation of formal specifications, ensuring an accurate understanding and grasp of the contract logic;

[0048] S2. Automatically generate a formal specification corresponding to the contract function logic based on a predefined formal specification template;

[0049] Specifically, when automatically generating a formal specification, for the preconditions of the function, constraints are imposed from aspects such as the types, value ranges, and mutual relationships of the input parameters according to the functional requirements and business logic of the function;

[0050] For example, if the function is used to handle transfer operations, the preconditions will stipulate that the transfer amount must be greater than 0, and the account balance of the transferor must be greater than or equal to the transfer amount, etc.;

[0051] For the postconditions, they are set according to the expected results after the function execution. For example, after a successful transfer, the account balance of the transferor should be reduced by the corresponding amount, and the account balance of the recipient should be increased by the corresponding amount;

[0052] For the constraints on the value range of state variables, they are determined in combination with the business scenario of the contract and the requirements for data integrity;

[0053] For example, in a smart contract that records user points, the value range of the points state variable may be restricted to non - negative integers, which can be mathematically described as "points variable >= 0";

[0054] In this way, using a predefined template, according to the logic of the contract function and the specific situation of the state variable, the corresponding logical expressions and mathematical descriptions are automatically filled to generate an accurate and comprehensive formal specification;

[0055] As a possibility, in step S2, the formal specification template includes, but is not limited to:

[0056] The logical expressions of the function pre - conditions and post - conditions, as well as the mathematical description of the constraints on the value range of state variables;

[0057] Specifically, taking a simple smart contract function "add(uint256 a, uint256 b)" as an example, its function is to add two unsigned integers and return the result;

[0058] The logical expression of the function pre - condition can be defined as "a >= 0 && b >= 0", ensuring that the two input numbers are non - negative integers, which conforms to the basic requirements of mathematical operations and the business logic of the contract;

[0059] The logical expression of the post - condition is "returnValue == a + b", clearly stipulating that the return value after the function execution must be equal to the sum of the two input numbers, which is an accurate constraint on the correct execution result of the function;

[0060] For the state variable, assuming there is a state variable "totalSum" in the contract to record the total sum of multiple additions, the mathematical description of the constraints on its value range can be set as "totalSum >= 0", ensuring that the total sum is always non - negative and maintaining the rationality and consistency of the data;

[0061] S3. Verify the logical consistency between the formal specification and the target smart contract code through a model checking tool to obtain a verification result;

[0062] Specifically, select a suitable model checking tool, such as NuSMV, etc.; when using the tool for verification, first configure the input of the generated formal specification and the target smart contract code in the format required by the tool;

[0063] The tool uses temporal logic formulas to describe the behavior of the contract, regarding the execution process of the contract as a state transition system, and each state change follows certain logical rules;

[0064] Symbolic execution traverses all possible execution paths. During the traversal, the tool records the state changes and execution conditions at each step, and comprehensively checks all possible situations of the contract;

[0065] For example, in a smart contract involving multi-party interactions, symbolic execution will consider the operations of different parties in different orders, as well as various abnormal situations, such as transaction failures and insufficient balances, to ensure that the contract meets the requirements of the formal specification in all situations;

[0066] After the traversal is completed, the tool will output the verification result according to the inspection result, clearly indicating whether there are logical conflicts and the location and reason of the conflicts;

[0067] As a possibility, in step S3, the model checking tool uses temporal logic formulas to describe the contract behavior and traverses all possible execution paths through symbolic execution;

[0068] Specifically, taking a simple lending smart contract as an example, in the model checking tool, temporal logic formulas are used to describe the contract behavior;

[0069] For example, define a temporal logic formula "□(borrower.balance >= 0)", which means that the borrower's balance should always be non-negative. "□" represents the temporal logic operator "always";

[0070] During the symbolic execution process, the tool starts from the initial state of the contract and gradually simulates various operations;

[0071] When the borrowing operation is executed, the tool will check whether the borrowing amount is within the borrower's borrowable limit and update the borrower's balance status at the same time;

[0072] If during the execution process, the situation where the borrower's balance is less than 0 occurs, it means that the pre-set temporal logic formula is violated, that is, there is a logical conflict;

[0073] In this way, the tool can conduct a rigorous logical analysis of the contract behavior, comprehensively cover all possible execution paths, and effectively detect potential logical problems;

[0074] In addition, as another possibility, after step S3, it further includes:

[0075] S31. When the verification result passes, compile the target smart contract code into bytecode;

[0076] Specifically, use the compiler integrated in the smart contract development environment, such as the solc compiler commonly used in Ethereum development;

[0077] After the verification result passes, the target smart contract code is input into the compiler, and the compiler converts the high-level smart contract code into bytecode format according to specific compilation rules;

[0078] During the compilation process, the compiler will perform a series of optimization operations, such as removing redundant code and optimizing the execution efficiency of algorithms, to improve the execution performance of the bytecode on the blockchain;

[0079] At the same time, the compiler will generate relevant metadata to describe information such as the functions and interfaces of the bytecode, facilitating subsequent deployment and invocation in the blockchain network;

[0080] S32. Decompile the bytecode to verify its logical equivalence with the original code;

[0081] Specifically, use a dedicated decompilation tool, such as the decompilation function provided by Etherscan;

[0082] Input the bytecode generated by compilation into the decompilation tool, and the decompilation tool will attempt to restore the bytecode to a form close to the original smart contract code;

[0083] During the decompilation process, the tool will analyze its execution logic and data processing method based on the instruction set and operation code of the bytecode, and reconstruct the code structure;

[0084] After obtaining the decompiled code, compare it in detail with the original smart contract code;

[0085] First, perform symbolic execution on the source code and the bytecode respectively to generate corresponding path constraint sets, compare the path constraint sets of the two, and if there are inconsistent constraint conditions, it is determined that they are not logically equivalent;

[0086] For example, the execution path of a certain function in the original code will return a specific value under specific conditions, but the decompiled code returns a different value or the execution path is different under the same conditions, which indicates that there is a situation of non-logical equivalence;

[0087] If the path constraint sets are consistent, then perform dynamic testing on the source code and the bytecode within the same input domain to verify the output consistency;

[0088] By inputting a series of different test data, observe whether the output results of the original code and the decompiled code are consistent, and further ensure the logical equivalence of the two;

[0089] In addition, as a possibility, in step S32, the logical equivalence verification includes, but is not limited to:

[0090] Symbolically execute the source code and bytecode respectively to generate corresponding path constraint sets. Compare the path constraint sets of the two. If there are inconsistent constraint conditions, it is determined to be logically inequivalent. Otherwise, perform dynamic testing on the source code and bytecode within the same input domain to verify output consistency;

[0091] Specifically, taking a simple smart contract calculation function "calculate(uint256 x)" as an example, its function is to perform some calculations based on the input value x and return the result;

[0092] When symbolically executing the source code, assume that the generated path constraint set contains the condition "when x > 0, execute calculation branch 1; when x <= 0, execute calculation branch 2";

[0093] After decompiling and symbolically executing the bytecode, if the path constraint set obtained contains an inconsistent constraint condition with the source code such as "when x > 1, execute calculation branch 1; when x <= 1, execute calculation branch 2", it can be determined to be logically inequivalent;

[0094] If the path constraint sets are consistent, next, within the same input domain, for example, input different values of x such as 1, -1, 5, etc. to perform dynamic testing on the source code and bytecode;

[0095] Observe the output results of the two. If the outputs are the same for all input values, it can be confirmed that they are logically equivalent;

[0096] If there is an input value that causes different outputs, it means there is a logical difference and further inspection and repair are required;

[0097] S4. When the verification result indicates the existence of a logical conflict, dynamically generate boundary condition test cases according to the conflict type;

[0098] Specifically, when the verification result shows the existence of a logical conflict, first conduct a detailed analysis of the conflict type;

[0099] If the conflict is caused by the value range of the function input parameters, for example, a certain function requires the input integer to be within a specific range, and it is found in actual verification that an out-of-range input causes an error, then extract the abnormal input parameter combinations from the logical conflict;

[0100] For example, if the function requires the input integer range to be 0 to 100, and it is found that there is a conflict when inputting 101 during verification, then

[101] is an abnormal input parameter combination;

[0101] Then, inject these abnormal input parameter combinations into a dedicated test framework, such as the Truffle test framework;

[0102] In the test framework, configure the running environment and related dependencies of the contract, and trigger the contract execution;

[0103] During the execution process, record the output results of the contract, including information such as the return values of functions and changes in state variables;

[0104] Through these detailed output records, developers can gain a deeper understanding of the behavior of the contract under abnormal input conditions, thus providing strong evidence for fixing vulnerabilities;

[0105] As a possibility, in step S4, the method for generating boundary condition test cases includes, but is not limited to:

[0106] Extract the abnormal input parameter combinations in the logical conflict, and inject the abnormal input parameter combinations into the test framework to trigger the contract execution and record the output;

[0107] Specifically, in a smart contract for handling user registration, assume that the function "register(string memory username, uint256 age)" requires that the length of the username does not exceed 20 characters and the age must be between 18 and 60 years old;

[0108] When the model detection tool discovers a logical conflict, for example, there is a problem when the input username length is 25 characters and the age is 15 years old;

[0109] At this time, extract the abnormal input parameter combination as ["abcdefghijklmnopqrstuvwxy", 15]; inject this abnormal input parameter combination into the Truffle test framework, create a test case in the test framework, call the "register" function and pass in this abnormal input parameter combination;

[0110] During the contract execution process, use a logging tool, such as the console.log() function of Ethereum, to record the execution status of each key step inside the contract, including information such as the input parameters of the function, changes in state variables, and the branch code executed;

[0111] After the contract execution ends, collect these log information and the return values of the functions, and organize them into a detailed test report to provide comprehensive data support for subsequent analysis of contract vulnerabilities;

[0112] In addition, as another possibility, in step S4, when the test case execution fails, automatically generate a minimized counterexample and map it to the conflict location of the formal specification;

[0113] Specifically, when the test case execution fails, use an automated tool, such as QuickCheck, to analyze the failed test scenario;

[0114] The QuickCheck tool extracts a minimized counterexample from complex failed test data through a series of algorithms and strategies;

[0115] This minimized counterexample is the most concise combination of input data that can cause an error in the contract;

[0116] For example, in a complex financial smart contract test, the original test case contains a large amount of data such as the balances of multiple accounts and transaction records, resulting in a test failure;

[0117] The QuickCheck tool analyzes this data, removes unnecessary parts, and obtains a minimized counterexample that only contains key information, such as the initial balance of a specific account and a specific transaction operation;

[0118] Then, map this minimized counterexample to the conflict location in the formal specification;

[0119] By searching for the constraint conditions and logical expressions related to the failed test in the formal specification, associate and label the minimized counterexample with the corresponding conflict points, facilitating developers to quickly locate the parts in the formal specification that need to be modified and improved, thereby more efficiently fixing contract vulnerabilities;

[0120] S5. Feed the verification results and test cases back to the smart contract development environment in real time;

[0121] Specifically, through the integration interface with the smart contract development environment (such as Remix, Visual Studio Code plugin, etc.), transmit the verification results and test case information to the development environment in real time;

[0122] In the development environment interface, use the highlighting function of the code editor to prominently display the code locations with vulnerabilities;

[0123] For example, in the Remix development environment, JavaScript scripts can be used in combination with its API to set the background color of the vulnerable code lines pointed out in the verification results to a prominent red, and at the same time add a hint icon next to the code line, and display detailed vulnerability information such as "Logic conflict: The function input parameter exceeds the expected range" when the mouse hovers;

[0124] For the logical code snippets of the repair suggestions, provide targeted modification solutions according to the type and specific situation of the vulnerability;

[0125] For example, if the vulnerability is caused by an incorrect conditional judgment in the function logic, the repair suggestion may be to modify the conditional judgment expression and give an example of the modified code;

[0126] Developers can directly view this feedback information in the development environment, quickly perform code fixes and optimizations, and greatly improve development efficiency;

[0127] As a possibility, in step S5, real-time feedback includes, but is not limited to:

[0128] Highlight the location of the vulnerable code in the development environment interface, and provide a logical code snippet with a repair suggestion;

[0129] Specifically, when using a smart contract development plugin in Visual Studio Code, after receiving the verification result and test case feedback information, the plugin will call the editing interface of Visual Studio Code;

[0130] For the location of the vulnerable code, by parsing the line number information in the verification result, locate the corresponding code snippet, and then use the syntax highlighting function of the editor to set the text color of this code snippet to yellow, and at the same time display a red exclamation mark icon in the sidebar on the right side of the code. Clicking on the icon can expand the detailed vulnerability description, such as "The contract function has an infinite loop when processing specific inputs, which may lead to resource exhaustion";

[0131] For the logical code snippet with a repair suggestion, the plugin will select a suitable code example from the pre-set repair solution library according to the analysis result of the vulnerability, and insert it near the vulnerable code in the form of a comment in the editor;

[0132] For example, for a vulnerability caused by out-of-bounds array access, the repair suggestion code snippet may be " / / Add array boundary check, add the following code before accessing array elements: if(index >= 0 && index < array.length){ / / Original array access code}", which is convenient for developers to directly refer to and modify the code;

[0133] It should be noted that before step S1, receive the contract code input by the user, detect its syntax legality, and when a syntax error is detected, terminate the process and return an error message;

[0134] Specifically, set a code input area on the front-end interface of the smart contract development platform, and the user inputs the contract code in this area;

[0135] When the user clicks the submit button, the platform backend will call a syntax detection tool, such as the solc-compiler syntax check module for the Solidity language;

[0136] This module will perform lexical analysis, syntax analysis, and semantic analysis on the input contract code; in the lexical analysis stage, check whether keywords, identifiers, operators, etc. in the code are spelled correctly;

[0137] In the syntax analysis stage, verify whether the statement structure of the code conforms to the syntax rules of the Solidity language, such as whether the function definition is correct, whether the statement ends with a semicolon, etc.;

[0138] In the semantic analysis stage, check whether the variable declarations and uses are consistent, whether the types match, etc.; If a syntax error is detected at any stage, the system will immediately terminate the subsequent verification process and return a detailed error message, such as "Line 5: Syntax error, missing right parenthesis in function definition", and in the code input area of the front-end interface, the error code line will be marked with a wavy line and an error prompt message will be displayed beside it to facilitate users to promptly discover and correct the syntax error;

[0139] An intelligent contract enhancement system based on formal verification, including:

[0140] A specification generation module, used to parse the intelligent contract code and automatically generate a formal specification;

[0141] A verification engine, connected to the specification generation module, used to perform model checking and output verification results;

[0142] A dynamic testing module, connected to the verification engine, used to generate test cases according to the verification results;

[0143] An interaction interface, connected to the dynamic testing module, used to synchronize the verification results and test cases to the development environment, where

[0144] The specification generation module, verification engine, dynamic testing module, and interaction interface are connected in series in sequence to form a closed-loop data flow;

[0145] Specifically, the specification generation module adopts an efficient code parsing algorithm, which can quickly and accurately identify the function logic and state variables in the intelligent contract code;

[0146] For example, use the ANTLR (ANother Tool for Language Recognition) tool to build a code parser. ANTLR can generate parser code according to the syntax rules of the Solidity language. Through it, information such as function definitions and variable declarations can be accurately extracted, and corresponding formal specifications can be generated according to the predefined formal specification templates;

[0147] After receiving the formal specification generated by the specification generation module and the target intelligent contract code, the verification engine starts the model checking process;

[0148] It will call the internal timing logic analyzer and symbolic execution engine to comprehensively check the contract according to the set verification strategy, ensure that the contract behavior meets the requirements of the formal specification, and output the verification results to the dynamic testing module;

[0149] After receiving the verification results, if there are logical conflicts, the dynamic testing module will call a dedicated test case generation algorithm according to the conflict type, perform a series of operations such as extracting from abnormal input parameter combinations, injecting into the test framework, and outputting records, to generate comprehensive and effective boundary condition test cases;

[0150] The interaction interface is responsible for communicating with the smart contract development environment, transmitting the verification results and test cases to the development environment in a suitable format, and visualizing them in the development environment for developers to view and process;

[0151] Through such a sequentially cascaded module design, an efficient closed-loop data flow is formed, realizing the full-process automation of smart contract from code writing, verification to testing and feedback, effectively improving the development quality and efficiency of smart contracts;

[0152] In summary, according to the smart contract enhancement method and system based on formal verification disclosed in the present invention, on the one hand, it can significantly reduce the technical threshold and time cost of formal verification by automatically generating formal specifications and integrating model checking tools, avoid the error-prone nature of manually writing specifications, and at the same time ensure the mathematical rigor of the contract logic. On the other hand, it can combine dynamic test case generation and real-time feedback mechanisms, not only covering the abnormal execution paths that are difficult to reach by static formal verification, but also instantly locating vulnerabilities and providing repair suggestions during the development stage, thus comprehensively improving the security and development efficiency of smart contracts.

[0153] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.

Claims

1. An intelligent contract enhancement method based on formal verification, characterized in that It includes the following steps: S1. Perform syntax parsing on the target smart contract code, and extract contract function logic and state variables; S2. Automatically generate a formal specification corresponding to the contract function logic based on a predefined formal specification template; S3. Verify the logical consistency between the formal specification and the target smart contract code through a model checking tool to obtain a verification result; S4. When the verification result indicates the existence of a logical conflict, dynamically generate boundary condition test cases according to the conflict type; S5. Real-time feedback the verification result and test cases to the smart contract development environment.

2. The method for enhancing an intelligent contract based on formal verification according to claim 1, wherein In step S2, the formal specification template includes, but is not limited to: Logical expressions for function preconditions and postconditions, and mathematical descriptions of state variable value range constraints.

3. The method for enhancing an intelligent contract based on formal verification according to claim 1, wherein In step S3, the model checking tool uses temporal logic formulas to describe contract behaviors and traverses all possible execution paths through symbolic execution.

4. The formal-verification-based intelligent contract enhancement method according to claim 1, wherein In step S4, the method for generating boundary condition test cases includes, but is not limited to: Extract the abnormal input parameter combinations in the logical conflict, and inject the abnormal input parameter combinations into the test framework to trigger contract execution and record the output.

5. The method for enhancing an intelligent contract based on formal verification according to claim 1, wherein In step S5, the real-time feedback includes, but is not limited to: Highlight the location of the vulnerable code in the development environment interface, and provide logical code snippets for repair suggestions.

6. The formal-verification-based intelligent contract enhancement method according to claim 1, wherein After step S3, it further includes: S31. When the verification result passes, compile the target smart contract code into bytecode; S32. Decompile the bytecode and verify its logical equivalence with the original code.

7. The method for enhancing an intelligent contract based on formal verification according to claim 6, wherein In step S32, the verification of logical equivalence includes, but is not limited to: Perform symbolic execution on the source code and bytecode respectively to generate corresponding path constraint sets, compare the path constraint sets of the two, if there are inconsistent constraint conditions, it is determined as logically non-equivalent, and otherwise perform dynamic testing on the source code and bytecode within the same input domain to verify the output consistency.

8. The method for enhancing an intelligent contract based on formal verification according to claim 1, wherein Before step S1, receive the contract code input by the user, detect its syntax legality, and when a syntax error is detected, terminate the process and return an error message.

9. The method for enhancing an intelligent contract based on formal verification according to claim 1, wherein In step S4, when the test case execution fails, automatically generate a minimized counterexample and map it to the conflict location of the formal specification.

10. An intelligent contract enhancement system based on formal verification, characterized in that, It includes: A specification generation module, which is used to parse the smart contract code and automatically generate a formal specification; A verification engine, connected to the specification generation module, which is used to perform model checking and output a verification result; A dynamic testing module, connected to the verification engine, which is used to generate test cases according to the verification result; An interaction interface, connected to the dynamic testing module, which is used to synchronize the verification result and test cases to the development environment, where The specification generation module, the verification engine, the dynamic testing module and the interaction interface are connected in series in sequence to form a closed-loop data flow.