Raft consensus algorithm anti-forgery attack improvement method based on reputation model

By introducing a reputation model, quantifying and evaluating node behavior and dynamically monitoring term numbers and log index values, the problem of Raft consensus algorithm being vulnerable to forgery attacks is solved, and the security enhancement and data protection of Raft consensus algorithm are achieved.

CN120358056APending Publication Date: 2025-07-22TIANJIN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510490803.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The Raft consensus algorithm is susceptible to forgery attacks. Malicious nodes seize leadership by forging term numbers and log index values, resulting in a threat to blockchain data security.

Method used

Introduce a reputation model, by quantifying the evaluation of node behavior, periodically broadcasting and verification messages, dynamically monitor term numbers and log index values, reduce the reputation value of abnormal nodes, force back the status and freeze the election rights, and permanently remove malicious nodes.

Benefits of technology

Enhanced the security of Raft consensus algorithm, effectively defend against forgery attacks, and ensure the consistency of node status and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358056A_ABST
    Figure CN120358056A_ABST
Patent Text Reader

Abstract

The invention discloses a reputation model-based Raft consensus algorithm anti-forgery attack improvement method, and relates to the technical field of block chain consensus algorithms. The method comprises the following steps: S1, creating Raft nodes, adding the Raft nodes into a constructed Raft cluster, and initializing information such as a reputation value of the Raft nodes; s2, reputation model design suitable for a data sharing scene; s3, periodically broadcasting an MsgTermSync message by the node, including a current tentative number and a log index value, and updating a state table after receiving node verification; s4, based on the dynamic threshold value, judging whether the duration number or the log index value of the candidate person node is abnormally increased or not, and if yes, triggering an MsgTermVerify verification process and reducing the reputation value of the MsgTermVerify verification process; and S5, forcibly fallback the malicious low-reputation-value node and freezing the election right, and accumulating three times of violators to permanently move out of the cluster. In the Raft consensus process, the low-reputation-value nodes are limited in an all-around mode, and safety enhancement of the Raft consensus algorithm is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain consensus algorithms, and in particular to an improved method for resisting counterfeit attacks of a Raft consensus algorithm based on a reputation model. Background Art

[0002] As a core component of a distributed system, the core function of the consensus algorithm is to ensure the consistency of the states among multiple nodes. In the Raft consensus algorithm, each node is in one of the following three states: leader, candidate, or follower. As the core coordinator, the leader node is responsible for encapsulating client requests as log entries and broadcasting them to the remaining follower nodes. At the same time, the node ensures that the log entries are correctly copied and submitted. The leader node periodically sends heartbeat information to all follower nodes to confirm their online status. If a follower node does not receive a heartbeat signal within the preset timeout window, a state transition is triggered, and the node will be transformed into a candidate state and initiate an election request. When a candidate receives more than half of the votes from the nodes, it is elected as the new leader node.

[0003] To ensure that the leader node always has the latest log information, Raft's "security guarantee" stipulates that follower nodes can only vote for candidate nodes that meet the following conditions: the candidate node's log index value (Log Index) and term number (Term) are not less than its own log index value and term number. However, Raft does not limit the growth of term numbers and log index values, which allows malicious nodes to take advantage of this. After losing the leader node's heartbeat information, the malicious node can launch a forgery attack, forge a higher term number or log index value and initiate an election. Even if there are normal nodes that initiate an election at the same time as the malicious node, their term numbers and log index values cannot exceed the values forged by the malicious node, thereby making the malicious node the leader node, resulting in a threat to the security of blockchain data.

[0004] In order to defend against malicious attacks, many studies have introduced reputation models based on data sharing scenarios, and established dynamic defense mechanisms to combat malicious behavior by continuously evaluating user behavior and quantifying entity credibility. The reputation model can accurately quantify user behavior tendencies and credibility. Based on the user reputation value evaluated by the reputation model, the Raft consensus algorithm can be improved to enable it to resist forgery attacks. In view of this, the present invention proposes an improved method for the Raft consensus algorithm to resist forgery attacks based on a reputation model. Summary of the invention

[0005] The purpose of the present invention is to propose an improved method for resisting forgery attacks of the Raft consensus algorithm based on a reputation model to solve the problems raised in the above background technology and to enhance the security of the Raft consensus algorithm.

[0006] To achieve the above object, the present invention adopts the following technical solutions:

[0007] An improved method for anti-forgery attack of Raft consensus algorithm based on reputation model, comprising the following steps:

[0008] S1. Create multiple Raft nodes in the application environment of the Raft consensus algorithm, add them to the pre-constructed Raft cluster, and initialize the Raft node information;

[0009] S2. In view of the security threats faced by the Raft cluster in the data sharing scenario, design a reputation model suitable for the data sharing scenario, quantitatively evaluate the reputation of Raft nodes, and provide a basis for subsequent forgery attack detection and node management;

[0010] S3. During the normal operation of the Raft cluster, each Raft node periodically broadcasts a MsgTermSync message, and the receiving node verifies the received MsgTermSync message, and updates the status table after passing the verification; wherein, the MsgTermSync message includes the term number of the current node and the log index value information;

[0011] S4. Monitor the term number or log index value of candidate nodes in the Raft cluster based on the dynamic threshold mechanism. If an abnormal growth occurs, trigger the MsgTermVerify verification process and reduce its reputation value;

[0012] S5. Dynamically manage the nodes in the Raft cluster according to the reputation values of the nodes, force the nodes with reputation values lower than the preset threshold to roll back their states, freeze their election rights, and permanently remove the nodes that have accumulated three violation behaviors from the Raft cluster.

[0013] Preferably, the S1 specifically includes the following content:

[0014] S1.1. Create Raft nodes and add them to the pre-constructed Raft cluster:

[0015] Create a single Raft node using the NewRaft interface provided by the Raft consensus algorithm; when there is no Raft node, call NewRaft to construct a Raft cluster and add a Raft node to the cluster; when there are Raft nodes in the existing Raft cluster, call NewRaft to add a new Raft node to the cluster;

[0016] S1.2. Initialize the Raft node information

[0017] The Raft node information is represented based on five dimensions, including:

[0018] ① Node ID: id; ② Node reputation value: Rep; ③ Node current state: state; ④ The latest term number stored by the node: curTerm; ⑤ The latest log index value stored by the node: curIndex;

[0019] When calling the NewRaft method to add a new Raft node, the node ID is automatically generated by the system; the state state is set to Follower, that is, the follower state; the latest term number curTerm and the latest log index value curIndex stored by the node are both set to 0; the node reputation value Rep is initialized to 0.5.

[0020] Preferably, the S2 specifically includes the following content:

[0021] S2.1. Manage node behavior:

[0022] In the data sharing scenario, continuously monitor the data upload behavior and data update behavior of the nodes, and calculate the metrics of the nodes in the data upload behavior and data update behavior to accurately capture the behaviors carried out between the nodes and highlight the subtle differences caused by different behaviors in the reputation value. The specific content is as follows:.

[0023] Manage data upload behavior:

[0024] Assume that node j represents the data uploader and node i represents the data user; let N Good represent the number of high-quality data uploaded by node j as considered by node i, and N Bad represent the number of low-quality or non-compliant data uploaded by node j as considered by node i; the metric φ Upload of the node in terms of data upload behavior is calculated as follows:

[0025]

[0026] where θ represents the penalty factor;

[0027] Manage data update behavior:

[0028] Assume that node i represents the data uploader and node j represents the data user. Let N Good ′ represent the number of normal modification operations on its data by node j as considered by node i, and N Bad ′ represent the number of malicious modification operations on its data by node j as considered by node i; the metric φ Modify of the node in terms of data update behavior is calculated as follows:

[0029]

[0030] S2.2, Reputation Value Update:

[0031] Each node updates its reputation value at a preset time interval, and the update method is as follows:

[0032]

[0033] Among them, represents the reputation value of the node after update; represents the reputation value of the node before update; w U , w M are the weights of φ Upload and φ Modify respectively; the value range of the reputation value Rep is 0 < Rep < 1.

[0034] Preferably, the above-mentioned S3 specifically includes the following content:

[0035] S3.1. Obtain the term number and log index value information of the node to detect forged attack behaviors, and add a new message type MsgTermSync. The format of the MsgTermSync message is expressed as:

[0036] <NodeID, curTerm, curIndex, CheckSum>

[0037] Among them, NodeID is the node ID that sends the MsgTermSync message; curTerm and curIndex are the latest term number and log index value of this node; CheckSum is the data verification hash value of this MsgTermSync message;

[0038] Each node broadcasts a MsgTermSync message to the remaining nodes in the Raft cluster once every preset period T sync including its own latest curTerm and curIndex, so that the remaining nodes can perform subsequent verification;

[0039] S3.2. Update the status table after the receiving node verifies

[0040] After the receiving node receives the MsgTermSync message sent by the remaining nodes, it verifies the message; after successful verification, it updates the node status table stored locally and stores the information of the remaining nodes. The storage format is expressed as:

[0041] <ts, NodeID, Term, Index>

[0042] Among them, ts is the sending time of the MsgTermSync message; NodeID is the node ID that sends the MsgTermSync message; Term and Index are respectively the latest term number and log index value of this node contained in the MsgTermSync message at ts.

[0043] Preferably, the S4 specifically includes the following content:

[0044] S4.1. Judge the term number and log index value of the candidate node based on the dynamic threshold

[0045] Suppose the ID of a certain candidate node is i. If a certain follower node finds that the increment of the term number or log index value of this candidate node exceeds m times the cluster mean, that is:

[0046] Condition 1:

[0047] Or

[0048]

[0049] Among them, respectively represent the term numbers of this candidate node at the current moment and the previous moment; respectively represent the log index values of this candidate node at the current moment and the previous moment; n represents the total number of Raft nodes in the cluster; And are both obtained by the follower node querying the local node status table stored;

[0050] If one or more of the above two conditions are satisfied, it is determined that the term number or log index value of this candidate node has an abnormal increase, and enter S4.2; if no condition is satisfied, do not enter;

[0051] S4.2. Trigger the MsgTermVerify verification process and reduce its credibility value

[0052] When a certain follower node finds that the term number or log index value of a certain candidate node has an abnormal increase, this follower node reminds the other nodes and requests the other nodes to check this suspected malicious candidate node; for this reason, a new MsgTermVerify message type is added, and its message format is expressed as:

[0053] <NodeID,TermDelta,IndexDelta>

[0054] Among them, NodeID is the ID of the candidate node to be verified; TermDelta and IndexDelta are the term number and log index value increments of this candidate node, and their calculation methods are respectively:

[0055]

[0056] The follower node broadcasts the above MsgTermVerify message to the remaining nodes. After receiving the MsgTermVerify message, other nodes verify whether there is an abnormality in the increment of its term number and log index value based on the historical data of this candidate node stored locally, and return the verification result;

[0057] If more than half of the nodes consider the increment of this candidate node to be abnormal, the reputation value of this candidate node is halved and enter the next step; otherwise, the reputation value of this candidate node remains unchanged and does not enter the next step.

[0058] Preferably, the S5 specifically includes the following content:

[0059] S5.1. Force the malicious nodes with low reputation values to roll back their states and freeze their election rights:

[0060] Force to roll back the state:

[0061] If the reputation value Rep of the candidate node is lower than the preset minimum threshold, the state state of this candidate node will be forced to roll back to Follower, that is, the follower state, and it cannot be voted for and elected as the leader node;

[0062] Force to roll back the term number and log index value:

[0063] After rolling back the state state of the malicious candidate node to Follower, roll back its forged latest term number and log index value to the values before forgery, that is

[0064] Freeze the election right:

[0065] Even if the state state of this candidate node is forced to roll back to Follower, the number of times mTimes it is verified as malicious will not change; it is further stipulated that all follower nodes with the number of times mTimes verified as malicious being positive can neither vote for other nodes nor be voted for by other nodes, so as to prevent this malicious node from interfering with the election process of the Raft consensus;

[0066] S5.2. Permanently remove violators who have violated the rules three times from the cluster:

[0067] When the number of violations of a node is less than 3 times, that is, the number of times the reputation value is lower than the preset minimum threshold is less than 3 times, only the election right of this node is frozen; for a node with three cumulative violations, that is, a node whose number of times the reputation value is lower than the preset minimum threshold is equal to 3 times, it will be permanently removed from the cluster and is not allowed to join the cluster again.

[0068] Compared with the prior art, the present invention provides an improved method for anti-forgery attack of the Raft consensus algorithm based on a reputation model, and has the following beneficial effects:

[0069] Aiming at the problem that the Raft consensus algorithm is vulnerable to forgery attacks, the present invention introduces an improved method for anti-forgery attack based on a reputation model to realize the security optimization of the Raft consensus algorithm, and comprehensively restricts nodes with low reputation values during the Raft consensus process to enhance the security of the Raft consensus algorithm. BRIEF DESCRIPTION OF THE DRAWINGS

[0070] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings involved in the embodiments are briefly introduced below. Obviously, the accompanying drawings in the following description are only schematic illustrations of some embodiments of the present invention, and those skilled in the art can also construct other forms of drawings based on these drawings without creative work.

[0071] Figure 1 It is a schematic diagram of the forgery attack faced by the Raft consensus algorithm proposed in the embodiment of the present invention;

[0072] Figure 2 It is the overall flowchart of the improved method for anti-forgery attack of the Raft consensus algorithm based on a dynamic threshold proposed in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0073] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments.

[0074] The following will explain an improved method for anti-forgery attack of the Raft consensus algorithm based on a reputation model proposed by the present invention with reference to relevant accompanying drawings and specific examples. The specific content is as follows.

[0075] Embodiment 1:

[0076] Please refer to Figure 1-2 , the present invention proposes an improved method for anti-forgery attack of the Raft consensus algorithm based on a reputation model, including the following content:

[0077] S1. In the application environment of the Raft consensus algorithm, create multiple Raft nodes, add them to a pre-constructed Raft cluster, and initialize the Raft node information. Specifically, it includes the following content:

[0078] S1.1. Create a Raft node and add it to the constructed Raft cluster

[0079] The NewRaft interface provided by the Raft consensus algorithm can create a single Raft node. When there is no Raft node, calling NewRaft is equivalent to constructing a Raft cluster and adding a Raft node to the cluster. When there are Raft nodes in an existing Raft cluster, calling NewRaft will add a new Raft node to the cluster.

[0080] S1.2. Initialize information such as the reputation value of the Raft node

[0081] The Raft node information is characterized by five dimensions: node ID: id; node reputation value Rep; node current state: state; the latest term number stored by the node: curTerm; the latest log index value stored by the node: curIndex.

[0082] When calling the NewRaft method to add a new Raft node, the node ID is automatically generated by the system; the state state is set to Follower, that is, the follower state; the latest term number curTerm and the latest log index value curIndex stored by the node are both set to 0; the node reputation value is initialized to 0.5.

[0083] S2. For the security threats faced by the Raft cluster in the data sharing scenario, design a reputation model suitable for the data sharing scenario, quantitatively evaluate the reputation of Raft nodes, and provide a basis for subsequent forgery attack detection and node management. Specifically, it includes the following content:

[0084] S2.1. Manage node behaviors

[0085] In order to accurately capture the behaviors carried out between nodes and highlight the subtle differences caused by different behaviors in the reputation value, in the data sharing scenario, it is necessary to continuously monitor the data upload behavior and data update behavior of nodes and calculate the indicators of nodes in these two aspects of behavior.

[0086] Manage data upload behavior

[0087] In the data sharing scenario, malicious nodes may deliberately upload low-quality data. Assume that node j is the uploader of the data, and node i represents the user of the data. Let N Good represent the number of high-quality data uploaded by node j as considered by node i, NBad Indicates the number of low-quality or non-compliant data uploaded by node j as considered by node i. The metric φ of the node in terms of data upload behavior Upload is calculated as follows:

[0088]

[0089] where θ acts as a penalty factor, which amplifies the impact of negative evaluations on the direct reputation value of the node. In practical applications, the value of is usually set to 3. If more stringent monitoring of node behavior is desired, can be adjusted to a higher value.

[0090] Managing data update behavior

[0091] Malicious nodes can modify the uploaded data. In this context, assume that node i represents the data uploader and node j is the data user, where N Good ′ represents the number of normal modification operations on its data by node j as considered by node i, and N Bad ′ represents the number of malicious modification operations on its data by node j as considered by node i. The metric φ of the node in terms of data update behavior Modify is calculated as follows:

[0092]

[0093] S2.2. Reputation value update

[0094] Each node updates its reputation value every 5 minutes, and the update method is as follows:

[0095]

[0096] where are the reputation values of the node after and before the update respectively, and w U , w M are the weights of φ Upload and φ Modify respectively. Given the importance of data upload behavior compared to other types of behavior, set w U = 0.7, w M = 0.3. Nodes with a preference for behavior will obtain a higher reputation value Rep, and vice versa. Due to the calculation methods of φ Upload and φ Modify , the range of the reputation value is 0 < Rep < 1.

[0097] S3. During the normal operation of the Raft cluster, each Raft node periodically broadcasts a MsgTermSync message, and the receiving node verifies the received MsgTermSync message and updates the status table after successful verification. Among them, the MsgTermSync message contains the term number of the current node and the log index value information. Specifically, it includes the following content:

[0098] S3.1. The node periodically broadcasts a MsgTermSync message, which contains the current term number and the log index value. To detect forged attack behaviors, information such as the term number and the log index value of the node needs to be obtained. For this purpose, a new MsgTermSync message type needs to be added, and its message format can be expressed as:

[0099] <NodeID,curTerm,curIndex,CheckSum>

[0100] Among them, NodeID is the node ID that sends the MsgTermSync message; curTerm and curIndex are the latest term number and log index value of this node; CheckSum is the data verification hash value of this MsgTermSync message.

[0101] Each node broadcasts a MsgTermSync message to the remaining nodes in the cluster every (such as 200ms), which contains its own latest curTerm and curIndex, so that the remaining nodes can perform subsequent verification.

[0102] S3.2. The receiving node updates the status table after verification

[0103] After the receiving node receives the MsgTermSync message sent by the remaining nodes, it verifies the message. After successful verification, it updates the node status table stored locally, stores the information of the remaining nodes, and the storage format can be expressed as:

[0104] <ts,NodeID,Term,Index>

[0105] Among them, ts is the sending time of the MsgTermSync message; NodeID is the node ID that sends the MsgTermSync message; Term and Index are respectively the latest term number and log index value of this node contained in the MsgTermSync message.

[0106] S4. Monitor the term number or log index value of candidate nodes in the Raft cluster based on the dynamic threshold mechanism. If there is an abnormal growth situation, trigger the MsgTermVerify verification process and reduce its reputation value. Specifically, it includes the following content:

[0107] S4.1. Determine the term number and log index value of candidate nodes based on dynamic thresholds

[0108] If a follower node finds that the increment of the term number or log index value of a candidate node (assuming the ID of the candidate node is i) exceeds m times the cluster mean, i.e.:

[0109] Condition 1:

[0110] or

[0111] Condition 2:

[0112] where represent the term numbers of the candidate node at the current moment and the previous moment respectively, represent the log index values of the candidate node at the current moment and the previous moment respectively, and n represents the total number of Raft nodes in the cluster. and are both obtained by the follower node querying the node status table stored locally.

[0113] If one or more of the above two conditions are met, it is determined that the term number or log index value of the candidate node has abnormal growth, and proceed to the next step; if no condition is met, do not proceed to the next step.

[0114] S4.2. Trigger the MsgTermVerify verification process and reduce its reputation value

[0115] When a follower node finds that the term number or log index value of a candidate node (assuming the ID of the candidate node is i) has abnormal growth, the node needs to alert the other nodes and request the other nodes to check the suspected malicious candidate node. For this purpose, a new MsgTermVerify message type needs to be added, and its message format can be expressed as:

[0116] <NodeID,TermDelta,IndexDelta>

[0117] where NodeID is the ID of the candidate node to be verified, and TermDelta and IndexDelta are the term number and log index value increment of the candidate node, and their calculation methods are respectively:

[0118]

[0119] The calculation methods of TermDelta and IndexDelta are the same as those in the previous step, so they will not be elaborated here.

[0120] When a follower node discovers that the term number or log index value of a candidate node has an abnormal increase, the follower node broadcasts the above MsgTermVerify message to the other nodes. After receiving the MsgTermVerify message, the other nodes verify whether the increment of the term number and log index value of the candidate node is really abnormal based on the historical data of the candidate node stored locally and return the verification result. The verification method is the same as the judgment method in the previous step, so it will not be elaborated here.

[0121] If more than half of the nodes believe that the increment of the candidate node is abnormal, the reputation value of the candidate node is halved and enter the next step; otherwise, the reputation value of the candidate node remains unchanged and does not enter the next step

[0122] S5. Dynamically manage the nodes in the Raft cluster according to the reputation values of the nodes. Force the nodes with reputation values lower than the preset threshold to roll back their states and freeze their election rights. Permanently remove the nodes that have accumulated three violations from the Raft cluster; the specific content is as follows:

[0123] S5.1. Force malicious nodes with low reputation values to roll back their states and freeze their election rights

[0124] Force to roll back the state

[0125] If the reputation value Rep of the candidate node is less than 0.4, the state state of the candidate node will be forced to roll back to Follower, that is, the follower state, and it cannot be voted for and elected as the leader node.

[0126] Force to roll back the term number and log index value

[0127] After rolling back the state state of the malicious candidate node to Follower, it is also necessary to roll back its forged latest term number and log index value to the value before forgery, that is

[0128] Freeze the election right

[0129] In addition, even if the state state of the candidate node is forced to roll back to Follower, the number of times mTimes it is verified as malicious will not change. To prevent this malicious node from interfering with the election process of the Raft consensus, it is further stipulated that all follower nodes with a positive number of times mTimes verified as malicious can neither vote for other nodes nor be voted for by other nodes.

[0130] Step5.2. Permanently remove those who have accumulated three violations from the cluster

[0131] When the number of violations of a node is less than 3 times, that is, the number of times the reputation value Rep < 0.4 is less than 3 times, although the node's election right is frozen, it can still perform other normal behaviors in the cluster, which reflects the tolerance for all nodes. A node with three cumulative violations, that is, a node with the number of times the reputation value Rep < 0.4 equal to 3 times, will be permanently removed from the cluster and is not allowed to rejoin the cluster.

[0132] Embodiment 2:

[0133] Based on Embodiment 1 but different in that, please refer to Figure 1 , which shows a schematic diagram of the forgery attack faced by the Raft consensus algorithm in this embodiment. When a follower node does not detect a heartbeat from the leader node within its election timeout period, it will change its own state to a candidate, increment its own term number by 1, and broadcast a candidacy message RequestVote RPC to other nodes to initiate an election. When a candidate node receives more than half of the votes in the cluster, it will become the new leader node. However, Raft does not limit the growth of the term number and log index value, which allows malicious nodes to take advantage of this to forge a higher term number or log index value and initiate an election. Even if there are normal nodes initiating an election simultaneously with this malicious node, their term numbers and log index values cannot exceed the values forged by the malicious node, thus enabling the malicious node to become the leader node and threatening the security of blockchain data.

[0134] The following is based on Figure 2 Describe the system process of the method for the Raft consensus algorithm based on dynamic threshold to resist forgery attacks. First, use the NewRaft method provided by the Raft consensus algorithm to create Raft nodes and join them into the constructed Raft cluster, and initialize information such as the reputation value; then, each node performs data upload or data update behaviors and updates its reputation value; and, each node periodically broadcasts a MsgTermSync message, which contains the current latest term number and log index value of each node itself. After each node receives the MsgTermSync message, it updates the node status table stored locally and stores the information of the other nodes; when a follower node finds that the increment of the term number or log index value of a candidate node exceeds m times the cluster mean, it broadcasts a MsgTermVerify message. After other nodes receive this message, they verify whether the increment anomaly is true based on the historical data of this candidate node stored locally; if more than half of the nodes believe that the increment of this candidate node is abnormal, the reputation value of this candidate node is halved If this results in the reputation value Rep of the candidate node being less than 0.4, the forged term number and other information will be rolled back, and the state will also be forced to roll back to Follower. Nodes with the reputation value Rep less than 0.4 for 3 times will be permanently removed from the cluster. After testing, m = 2 can effectively defend against forgery attacks while avoiding normal nodes being misidentified as malicious nodes. The specific value of m can be adjusted according to the actual deployment environment.

[0135] The above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, making equivalent substitutions or changes, should be covered within the protection scope of the present invention.

Claims

1. An improved method for the Raft consensus algorithm against forgery attacks based on a reputation model, characterized in that It includes the following steps: S1. In the application environment of the Raft consensus algorithm, create multiple Raft nodes, add them to a pre-constructed Raft cluster, and initialize the Raft node information; S2. For the security threats faced by the Raft cluster in the data sharing scenario, design a reputation model suitable for the data sharing scenario, quantitatively evaluate the reputation of Raft nodes, and provide a basis for subsequent forgery attack detection and node management; S3. During the normal operation of the Raft cluster, each Raft node periodically broadcasts a MsgTermSync message, and the receiving node verifies the received MsgTermSync message and updates the status table after passing the verification; among them, the MsgTermSync message contains the term number of the current node and the log index value information; S4. Monitor the term number or log index value of candidate nodes in the Raft cluster based on a dynamic threshold mechanism. If an abnormal growth occurs, trigger the MsgTermVerify verification process and reduce its reputation value; S5. Dynamically manage the nodes in the Raft cluster according to the reputation value of the nodes, force the nodes with a reputation value lower than the preset threshold to roll back their status and freeze their election rights, and permanently remove the nodes that have committed three violations from the Raft cluster.

2. An improved method for anti-forgery attack of Raft consensus algorithm based on reputation model according to claim 1, characterized in that The specific content of S1 is as follows: S1.

1. Create a Raft node and add it to a pre-constructed Raft cluster: Use the NewRaft interface provided by the Raft consensus algorithm to create a single Raft node; when there is no Raft node, call NewRaft to construct a Raft cluster and add a Raft node to the cluster; when there are Raft nodes in the existing Raft cluster, call NewRaft to add a new Raft node to the cluster; S1.

2. Initialize the Raft node information The Raft node information is characterized by five dimensions, including: ① Node ID: id; ② Node reputation value: Rep; ③ Node current state: state; ④ The latest term number stored by the node: curTerm; ⑤ The latest log index value stored by the node: curIndex; When calling the NewRaft method to add a new Raft node, the node ID is automatically generated by the system; the state state is set to Follower, that is, the follower state; the latest term number curTerm and the latest log index value curIndex stored by the node are both set to 0; the node reputation value Rep is initialized to 0.

5.

3. An improved method for anti-forgery attack of the Raft consensus algorithm based on a reputation model according to claim 2, characterized in that, The specific content of S2 is as follows: S2.

1. Manage node behavior: In the data sharing scenario, continuously monitor the data upload behavior and data update behavior of nodes, and calculate the metrics of the data upload behavior and data update behavior of nodes to accurately capture the behaviors between nodes and highlight the subtle differences caused by different behaviors in the reputation value. The specific content is as follows:. Manage data upload behavior: Suppose node j represents the data uploader and node i represents the data user; let N Good denote the number of high-quality data uploaded by node j as considered by node i, and N Bad denote the number of low-quality or non-compliant data uploaded by node j as considered by node i; the metric φ Upload of the node in terms of data upload behavior is calculated as follows: Among them, θ represents the penalty factor; Manage data update behavior: Suppose node i represents the data uploader and node j represents the data user. Let N Good ′ denote the number of normal modification operations that node i believes node j has performed on its data, and N Bad ′ denote the number of malicious modification operations that node i believes node j has performed on its data; the metric φ Modify of the node in terms of data update behavior is calculated as follows: S2.

2. Reputation value update: Each node updates its reputation value once at a preset time interval, and the update method is as follows: Among them, represents the reputation value of the node after update; represents the reputation value of the node before update; w U , w M are the weights of φ Upload and φ Modify respectively; the value range of the reputation value Rep is 0 < Rep < 1.

4. An improved method for anti-forgery attack of Raft consensus algorithm based on reputation model according to claim 3, characterized in that, The specific content of S3 is as follows: S3.

1. Obtain the term number and log index value information of the node to detect forged attack behaviors, and add a new MsgTermSync message type. The MsgTermSync message format is expressed as: <NodeID,curTerm,curIndex,CheckSum> Among them, NodeID is the node ID that sends the MsgTermSync message; curTerm and curIndex are the latest term number and log index value of this node; CheckSum is the data verification hash value of this MsgTermSync message; Each node broadcasts a MsgTermSync message to the remaining nodes in the Raft cluster once every preset period T sync containing its latest curTerm and curIndex for the remaining nodes to perform subsequent verification; S3.

2. The receiving node updates the status table after verification After the receiving node receives the MsgTermSync message sent by the other nodes, it verifies the message; after successful verification, it updates the node status table stored locally, stores the information of the other nodes, and the storage format is expressed as: <ts,NodeID,Term,Index> Among them, ts is the sending time of the MsgTermSync message; NodeID is the node ID that sends the MsgTermSync message; Term and Index are respectively the latest term number and log index value of this node included in the MsgTermSync message at ts.

5. An improved method for the Raft consensus algorithm to resist forgery attacks based on a reputation model according to claim 4, characterized in that, The specific content of S4 is as follows: S4.

1. Judge the term number and log index value of the candidate node based on the dynamic threshold Assume that the ID of a certain candidate node is i. If a follower node finds that the increment of the term number or log index value of this candidate node exceeds m times the cluster mean, that is: Condition 1: or Condition 2: Among them, respectively represent the term numbers of the candidate node at the current moment and the previous moment; respectively represent the log index values of the candidate node at the current moment and the previous moment; n represents the total number of Raft nodes in the cluster; and are both obtained by the follower node querying the node status table stored locally; If one or more of the above two conditions are met, it is determined that the term number or log index value of this candidate node has an abnormal increase, and enter S4.2; if no condition is met, do not enter; S4.

2. Trigger the MsgTermVerify verification process and reduce its reputation value When a follower node finds that the term number or log index value of a candidate node has an abnormal increase, this follower node reminds the other nodes and requests the other nodes to check this suspected malicious candidate node; for this reason, a new MsgTermVerify message type is added, and its message format is expressed as: <NodeID,TermDelta,IndexDelta> Among them, NodeID is the ID of the candidate node to be verified; TermDelta and IndexDelta are the increments of the term number and log index value of this candidate node, and their calculation methods are respectively: The follower node broadcasts the above MsgTermVerify message to the other nodes. After receiving the MsgTermVerify message, other nodes verify whether the increment of the term number and log index value of this candidate node is abnormal based on the historical data of this candidate node stored locally, and return the verification result; If more than half of the nodes consider the increment of the candidate node to be abnormal, the credit value of the candidate node is halved and proceed to the next step; otherwise, the credit value of the candidate node remains unchanged and does not proceed to the next step.

6. An improved method for anti-forgery attack of Raft consensus algorithm based on reputation model according to claim 5, characterized in that, The specific content of S5 is as follows: S5.

1. Force malicious nodes with low reputation values to roll back their status and freeze their election rights: Force rollback of status: If the reputation value Rep of a candidate node is lower than the preset minimum threshold, the status state of the candidate node will be forced to roll back to Follower, that is, the follower state, and it cannot be voted for and elected as the leader node; Force rollback of term number and log index value: After reverting the state of the malicious candidate node to Follower, revert its forged latest term number and log index value to the values before forgery, that is Freeze election rights: Even if the status state of the candidate node is forced to roll back to Follower, the number of times mTimes it is verified as malicious will not change; it is further stipulated that all follower nodes with a positive number of times mTimes verified as malicious can neither vote for other nodes nor be voted for by other nodes, to prevent the malicious node from interfering with the election process of Raft consensus; S5.

2. Permanently remove nodes that violate the rules three times: When the number of times a node violates the rules is less than 3, that is, the number of times its reputation value is lower than the preset minimum threshold is less than 3, only freeze the election rights of the node; nodes that violate the rules three times, that is, nodes whose number of times the reputation value is lower than the preset minimum threshold is equal to 3, will be permanently removed from the cluster and are not allowed to rejoin the cluster.