Block chain under-chain channel consensus method and system

By electing high-quality leaders through a node scoring mechanism and a verifiable random algorithm, the problems of poor leader quality and privacy risks in multi-party payment channels are solved, and efficient and secure leader election and information exchange are achieved.

CN120639307APending Publication Date: 2025-09-12INST OF COMPUTING TECH CHINESE ACAD OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510707890.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

The leader election in existing multi-party payment channels is of poor quality, leading to transaction errors and privacy risks. The new leader's identity is exposed and vulnerable to attacks, affecting system efficiency and security.

Method used

A node scoring mechanism is used to calculate importance scores, a verifiable random algorithm is used to elect high-quality leaders, and the current leader is used as a mixer to generate unbiased random numbers to ensure the security and privacy of information exchange.

Benefits of technology

It improves the transaction efficiency and security of multi-party payment channels, reduces on-chain pressure, and ensures the security and privacy protection of information exchange before the identity of the new leader is revealed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639307A_ABST
    Figure CN120639307A_ABST
Patent Text Reader

Abstract

The invention discloses a block chain under-chain channel consensus method. The method comprises the following steps: constructing a scoring system of consensus participation nodes in a block chain channel; calculating importance share values corresponding to the nodes through an election strategy algorithm, and calculating respective candidate hash values and seed values of the nodes; the current leader obtains a total seed value for the seed values sent by all the nodes, generates corresponding hash values and proof values by using a verifiable random algorithm according to the total seed value, generates a first random number according to the hash values, calculates a second random number according to the first random number and the number of the candidate hash values, and sends the second random number to the current leader; and selecting a node corresponding to the second random number from the candidate hash values as a following leader, and completing the election of a new leader. The method provided by the invention ensures that the channel fair elects the high-quality leader, and all nodes can verify the whole election process, thereby playing a role in privacy protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for electing a leader of an off-chain payment channel, and in particular to a consensus method and system within an off-chain channel. Background Art

[0002] Blockchain technology can establish peer-to-peer trust relationships between network nodes, overcoming the trust dependency and monopoly issues inherent in centralized models. However, current blockchain systems suffer from insufficient data processing capabilities. Off-chain scaling does not alter the blockchain's fundamental protocols or the existing on-chain trust assumptions. Instead, it establishes a high-frequency, real-time peer-to-peer operation protocol outside the blockchain, thereby increasing the overall system's throughput and providing a promising future for blockchain's application expansion.

[0003] Payment channels are an off-chain scaling solution. If a node joins a multi-party channel to conduct transactions, n one-way connections are formed, effectively increasing network connectivity by n times compared to a two-party payment channel, which only establishes a single one-way connection. Therefore, in current research, multi-party payment channels are the primary solution for improving blockchain transaction processing performance. However, they also introduce the double-spending problem. To address this, multi-party payment channels typically use a leader as an off-chain hub, using consensus strategies and candidate node oversight to resolve funding issues.

[0004] Multi-party off-chain payment channels can be divided into two types based on whether the central node (leader) is fixed. One type is based on a fixed leader. Throughout the channel establishment, update, and closure process, the leader remains unchanged and is responsible for processing all transactions in the channel. Representative schemes include Nocust, Gnocchi, and Gnocch. In Nocust, the leader periodically submits current transaction credentials to the chain, and global consensus is reached through a consensus mechanism. Reaching global consensus through a consensus mechanism is open and transparent, but requires frequent interaction with the on-chain system, resulting in relatively low consensus efficiency. Gnocchi, on the other hand, does not require frequent interaction with the blockchain. The leader periodically broadcasts verified transactions to all nodes in the channel. This scheme does not achieve true channel consensus and poses the security risk of double spending. In contrast to the fixed-leader schemes mentioned above, another scheme is based on a variable leader, represented by Garou, an improvement on Gnocchi. In each consensus cycle, a leader is randomly selected and initiates a two-phase consensus in the channel. Consensus is considered reached only when every node in the channel receives signatures from all other nodes agreeing on the state update. In general, the Garou solution does not interact frequently with the chain and has relatively low overhead, while strong consensus can better maintain the consistency of the off-chain state and has better security performance.

[0005] However, there are some problems with leader election in current multi-party payment channels:

[0006] Transaction confirmation and consensus in a multi-party payment channel are led by a leader. The quality of the leader directly impacts the efficiency of the channel. When the leader acts maliciously, erroneous transactions occur within the channel. To protect the security of their funds, honest nodes challenge the leader on-chain, prompting the channel to enter a dispute resolution process. During this challenge process, the chain reaches an agreement through consensus and conducts actions such as asset severance against the malicious node. The blockchain acts as an arbitrator, ensuring the security of off-chain funds. However, increasing the number of such challenges places processing pressure on the chain, consuming both time and resources. This contradicts the original purpose of establishing a multi-party payment channel. Rather than increasing throughput, it can actually reduce it. Therefore, it is crucial to ensure the quality of the leader, ensuring that the leader acts as proactively as possible to achieve correct consensus within the channel and reduce pressure on the chain. However, current multi-party payment channel solutions employ fixed or randomly selected leaders without considering node quality.

[0007] The leader election process presents a challenge. Because the new leader's identity is revealed in advance, the information transmission channel between the old and new leaders is vulnerable to attacks by malicious nodes, who could steal information. Currently, multi-party payment channels primarily utilize a pre-backup mechanism, where all nodes back up the channel ledger and then reveal the new leader. After the disclosure, the new leader already has access to the ledger information, eliminating the risk of channel attacks. However, this also presents a significant privacy risk.

[0008] Multi-party payment channels are decentralized, off-chain solutions. The transparency of transaction information can be exploited by malicious nodes to launch spoofing attacks. Therefore, transaction information is typically stored by the leader node. This full-node backup approach poses significant privacy risks to multi-party payment channels.

[0009] Therefore, it is urgent to propose an off-chain leader election scheme with privacy protection as the core, and to propose an off-chain expansion solution - leader election in multi-party payment channel technology. Summary of the Invention

[0010] In order to solve the problem that the existing technology adopts a fixed leader or a randomly selected leader without considering the quality of the nodes and lacks privacy protection, the present invention proposes a blockchain off-chain channel consensus method and system.

[0011] In a first aspect, an embodiment of the present application provides a blockchain off-chain channel consensus method, the method comprising:

[0012] Build a scoring system for consensus-participating nodes in blockchain channels. The scoring system is used to measure the importance of each node.

[0013] Based on the importance score, the importance share value corresponding to the node is calculated through the election strategy algorithm, and each node calculates its own candidate hash value and seed value;

[0014] The current leader obtains the total seed value from the seed values ​​sent to all nodes. The corresponding hash value and proof value are generated based on the total seed value using a verifiable random algorithm. The first random number is generated based on the hash value. The second random number is calculated based on the first random number and the number of candidate hash values. The node corresponding to the second random number is selected from the candidate hash values ​​as the next leader, completing the election of the new leader.

[0015] In an embodiment of the present invention, the above-mentioned blockchain off-chain channel consensus method further includes:

[0016] After a new leader is elected, all nodes in the channel verify the election process.

[0017] In the embodiment of the present invention, the step of constructing a scoring system for consensus participating nodes in a blockchain channel includes:

[0018] The importance score of each node in the channel in the current round is calculated based on the node's balance, number of outgoing transactions, number of incoming transactions, contribution rate, and the influence weight value of each score; and the importance score is normalized.

[0019] In the embodiment of the present invention, the step of calculating the importance share value corresponding to the node using the election strategy algorithm based on the importance score includes:

[0020] Each node calculates its importance share using a verifiable random algorithm based on a random seed value, private key, public key, hyperparameters, importance score, and the sum of importance scores. The higher the value of the hyperparameter, the higher the proportion of nodes elected as candidate leaders.

[0021] For any node i, the value interval [0,1) is divided into ω i +1 subinterval, calculate the probability that a random number in the range [0,1) falls in interval j, that is, the probability that any node i is selected, and the probability that any node i is selected is the importance share j of the node, where ω i is the importance score of any node i, that is, the importance share value of the node, j = 0, 1, ..., ω i .

[0022] In the embodiment of the present invention, the step of each node calculating its own candidate hash value and seed value includes:

[0023] The balance of each node plus the current number of cycles is used as the seed value, and together with the node's private key, the corresponding candidate hash value and proof value are generated;

[0024] Based on a set of candidate hash values ​​and a corresponding set of proof values, the node verifies whether the lengths of the two arrays are equal to the node's importance share j;

[0025] After a new leader is elected, all nodes verify the hash value and proof value announced by the new leader.

[0026] In an embodiment of the present invention, the steps of obtaining a total seed value by using the seed values ​​sent by the current leader to all nodes, generating a corresponding hash value and a proof value based on the total seed value using a verifiable random algorithm, calculating a second random number based on the first random number and the number of candidate hash values, and selecting a node corresponding to the second random number from the candidate hash values ​​as the next leader include:

[0027] Each node in the channel sends the candidate hash value and its own seed value to the current leader. After receiving the seed values ​​of all nodes, the current leader performs an XOR operation to obtain the total seed value;

[0028] Based on the total seed value and the current leader's private key, a verifiable random algorithm is used to calculate the hash value and verification value;

[0029] Calculate a first random number k according to the hash value, wherein the first random number is an unbiased random number in the value range [0, 1);

[0030] The current leader counts the total number of candidate hash values ​​collected as N, and multiplies the first random number k by the total number of hash values ​​N to obtain a second random number in the range [0, N). The second random number corresponds to N candidate hash values.

[0031] Arrange the N candidate hash values ​​in order, select the candidate hash value corresponding to the second random number, and the node corresponding to the candidate hash value will be the next leader.

[0032] In the embodiment of the present invention, after a new leader is elected, the step of verifying the election process by all nodes in the channel includes:

[0033] Based on the leader's public key, all nodes verify the authenticity of the total seed value;

[0034] All nodes verify the correctness of the hash value based on the total seed value, leader public key and verification value;

[0035] All nodes verify the correctness of the first random value and the total number of candidates;

[0036] All nodes verify the correctness of the candidate hash value.

[0037] In a second aspect, an embodiment of the present invention provides a blockchain off-chain channel consensus system, which adopts the above-mentioned blockchain off-chain channel consensus method, and the system includes:

[0038] Scoring system construction module: Build a scoring system for consensus participating nodes in the blockchain channel. The scoring system is used to measure the importance score of each node;

[0039] Importance share calculation module: Based on the importance score, the importance share value corresponding to the node is calculated through the election strategy algorithm, and each node calculates its own candidate hash value and seed value;

[0040] New leader election module: The current leader obtains the total seed value from the seed values ​​sent to all nodes. The corresponding hash value and proof value are generated using a verifiable random algorithm based on the total seed value. The first random number is generated based on the hash value. The second random number is calculated based on the first random number and the number of candidate hash values. The node corresponding to the second random number is selected from the candidate hash values ​​as the next leader to complete the election of the new leader.

[0041] In a third aspect, an embodiment of the present application provides a computer-readable storage medium on which a computer program is stored, which implements the steps of the blockchain off-chain channel consensus method when the program is executed by a processor.

[0042] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the blockchain off-chain channel consensus method as described above are implemented.

[0043] Compared with the related existing technologies, it has the following outstanding beneficial effects:

[0044] (1) This paper proposes a leader election algorithm Eleder based on the Garou scheme of a multi-party payment channel. On the one hand, it can ensure that the channel fairly elects a high-quality leader, while preventing the leader from doing evil, and at the same time, it can stimulate the enthusiasm of the nodes in the channel to compete for the leader and ensure fairness; on the other hand, before the new leader is announced, the old and new leaders can complete the information exchange safely. After the new leader is announced, all nodes can verify the entire election process, which plays a role in privacy protection.

[0045] (2) This invention proposes a node scoring mechanism to elect high-quality leaders. During the election process, it is necessary to maintain the activity of the nodes. A fixed leader will make other nodes feel that they cannot become leaders and lose their enthusiasm for participating in the decentralized system. Therefore, this invention also takes activity into consideration when electing high-quality leaders, thereby fairly selecting high-quality leaders.

[0046] (3) The present invention proposes using the old leader as an obfuscator and using unbiased random numbers to elect a new leader. After the entire election process is revealed, the entire election process can be verified by all nodes. This design ensures that only the old leader knows the identity of the new leader before it is revealed, which can not only complete information exchange but also avoid attacks from other nodes. After the disclosure, other nodes can verify the entire election process, ensuring security and achieving the effect of privacy protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0048] Figure 1 This is a schematic diagram of the blockchain off-chain channel consensus method of the present invention;

[0049] Figure 2 Schematic diagram of the candidate leader election algorithm of the present invention;

[0050] Figure 3 This is a schematic diagram of the candidate leader verification algorithm 2 of the present invention;

[0051] Figure 4 Schematic diagram of the candidate hash value generation method of the present invention;

[0052] Figure 5 This is a schematic diagram of the method for generating unbiased random numbers using VRF, which is currently the leader of the present invention;

[0053] Figure 6 A schematic diagram of the process of generating unbiased random numbers for the verification leader of the present invention to act as an obfuscator;

[0054] Figure 7 This is a schematic diagram of the off-chain channel consensus system of the blockchain of the present invention;

[0055] Figure 8 Schematic diagram of computer hardware of the present invention. DETAILED DESCRIPTION

[0056] In this disclosure, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0057] It should also be understood that the term "and / or" in this document simply describes an association between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " in this document generally indicates an "or" relationship between the related objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0058] It should also be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0059] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of the device or unit, which can be electrical, mechanical or other forms.

[0060] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0061] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0062] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0063] To illustrate the above-mentioned features and effects of the present invention more clearly and easily, the following embodiments are specifically described below with reference to the accompanying drawings. This specification discloses one or more embodiments incorporating the features of the present invention. The disclosed embodiments are for illustrative purposes only. The scope of protection of the present invention is not limited to the disclosed embodiments; the present invention is defined by the appended claims.

[0064] The following is a system embodiment corresponding to the above method embodiment. This embodiment can be implemented in conjunction with the above embodiment. The relevant technical details mentioned in the above embodiment are still valid in this embodiment and will not be repeated here to reduce repetition. Accordingly, the relevant technical details mentioned in this embodiment can also be applied to the above embodiment.

[0065] This invention proposes a node scoring mechanism to select high-quality leaders. During the election process, node activity must be maintained. This avoids a "fixed leader mechanism" that causes other nodes to believe they cannot become leaders, thus losing the opportunity to participate in the decentralized protocol. Therefore, this invention considers the activity of the consensus node set while selecting high-quality leaders, thereby fairly selecting high-quality leaders from the more active consensus nodes.

[0066] This paper analyzes existing leader consensus methods in multi-party channels and finds that existing leader election consensus methods fail to achieve a compromise between activity and high quality, often leading to oligopoly and premature exposure of new leaders, posing security risks. To address this issue, this paper proposes an innovative leader election algorithm. Its design consists of three components. In the first component, the leader calculates the importance score of each node based on a scoring system and performs normalization to ensure that the variance of the importance score is within a predetermined range, ensuring the rationality of the importance score and comprehensively evaluating each node. In the second component, each node, after obtaining its importance score, calculates its corresponding importance share using the Algorand election algorithm. This ensures fair election of high-quality leaders. Nodes with higher importance scores also have higher importance shares, and the relationship between the two is proportional, but not linear. The entire calculation process is also verifiable. After obtaining the importance share, the node uses VRF to generate a corresponding number of candidate hash values ​​and sends them to the leader. Consequently, a higher importance score is associated with a larger importance share, generating more candidate hashes and increasing the probability of election. The third part is that the leader acts as a mixer to elect a new leader. The current leader performs an XOR operation on the seed values ​​sent by all nodes to obtain the total seed value, and uses VRF to generate the corresponding hash value and proof value. Generate an unbiased random number with a total number of candidates N, and then select the k×N candidate hash values ​​from small to large to complete the election of the new leader.

[0067] The following describes the method of the embodiment of the present application in detail with reference to specific embodiments:

[0068] Example 1

[0069] like Figure 1 As shown, the embodiment of the present application proposes a blockchain off-chain channel consensus method, the method comprising:

[0070] Step 101: Construct a scoring system for consensus participating nodes in the blockchain channel. The scoring system is used to measure the importance score of each node.

[0071] Step 102: Based on the importance score, the importance share value corresponding to the node is calculated through the election strategy algorithm, and each node calculates its own candidate hash value and seed value;

[0072] Step 103: The current leader obtains the total seed value from the seed values ​​sent to all nodes, generates the corresponding hash value and proof value based on the total seed value using a verifiable random algorithm, generates a first random number based on the hash value, calculates a second random number based on the first random number and the number of candidate hash values, selects the node corresponding to the second random number from the candidate hash values ​​as the next leader, and completes the election of the new leader.

[0073] In an embodiment of the present invention, the above-mentioned blockchain off-chain channel consensus method further includes:

[0074] Step 104: After the new leader is elected, all nodes in the channel verify the election process.

[0075] In the embodiment of the present invention, the step 101 above constructs a scoring system for consensus participating nodes in the blockchain channel, including:

[0076] The importance score of each node in the channel in the current round is calculated based on the node's balance, number of outgoing transactions, number of incoming transactions, contribution rate, and the influence weight value of each score; and the importance score is normalized.

[0077] Specifically, in a specific embodiment of the present invention, in order to measure the quality of consensus participating nodes in a channel, the present invention proposes a scoring system that comprehensively considers various node indicators. The probability of a node being elected is positively correlated with its score. To comprehensively consider the performance of a node, the present invention considers four indicators: the node's balance, number of outgoing transactions, number of incoming transactions, and contribution rate. The details are as follows:

[0078] Balance ratio: The ratio of the node's locked funds in the channel to the total balance of all accounts;

[0079] Percentage of outgoing transactions: The ratio of the number of transactions in which the node participated as the initiator of the transfer (i.e., outbound transactions) to the total number of outbound transactions in the previous cycles;

[0080] Incoming transactions ratio: The ratio of the number of transactions in which the node participated as the transfer recipient (i.e., incoming transactions) to the total number of incoming transactions in the previous cycles;

[0081] Contribution ratio: The ratio of valid transactions signed by the node to all valid transactions when the node served as a leader.

[0082] According to these four indicators, the importance score of node i in the current round r is It can be obtained from formula 1:

[0083]

[0084] Formula 1 is the calculation formula for the importance score of node i in the channel in the current r-th round of consensus, where α, β, γ, and δ represent the weights of each item on the importance score of this node.

[0085] 1. Balancei represents the balance of node i at the previous consensus point, i.e. the r-1 consensus point, ∑balance i The balance of the entire channel. In this embodiment of the present invention, the node balance is a positive indicator. That is, the more balance a node has in the channel, the lower the likelihood of malicious behavior. This is because once a leader commits malicious behavior, the funds in the channel will be deducted. However, malicious behavior itself is unprofitable in the channel, and the loss is greater than the income, thus restraining malicious behavior.

[0086] 2. outTransactionNum i The denominator ∑outTransactionNum is the number of transactions issued by node i in several consensus cycles before the rth checkpoint. i The sum of the number of outgoing transactions for the entire channel during the corresponding period. Outgoing transactions represent transactions initiated by the node to other nodes, and the number of outgoing transactions represents the number of transactions issued by the node. Each time a node initiates a transaction to another node, the number of outgoing transactions for the node increases by 1. A larger number of outgoing transactions indicates active transaction activity within the channel, indicating high transaction demand. If the node is elected as a leader, it can reduce the processing overhead of some transactions.

[0087] 3. inTransactionNum i The denominator ∑inTransactionNum is the number of transactions entered by node i in several consensus cycles before the rth checkpoint. i The sum of the number of incoming transactions for the entire channel during the corresponding period. Incoming transactions and outgoing transactions are relative. Incoming transactions represent the node's acceptance of transactions from other nodes. The number of incoming transactions represents the node's acceptance of transactions. The number of incoming transactions increases by 1 with each transaction accepted. Similarly, incoming transactions can also represent the node's activity within the channel. The larger the number of incoming transactions, the more active the node's trading behavior within the channel and the higher the transaction demand. If the node is elected as a leader, it can also reduce some transaction processing overhead.

[0088] 4. singedTransactionNum i Indicates the total number of transactions signed and confirmed when node i was elected as a leader. A non-zero value means that the node has made effective contributions to the system's transaction processing. The denominator ∑singedTransactionNum iThe total number of valid transactions during the channel's lifetime. This value represents the node's historical performance within the channel. This is the number of correct transaction signatures the node has provided. A larger number indicates a greater number of valid signatures and a greater contribution, making it a positive indicator. A node's historical contribution reflects its processing power and stability. Multiple elections as a leader and a high total transaction volume indicate overall superiority. These factors, to a certain extent, measure a node's reliability and relative performance.

[0089] The importance score of each node can be calculated using Formula 1. However, after this scoring, the variance of scores between different nodes may be relatively large, which is not conducive to the fairness of the election. A score normalization process will be performed to control the variance of the scores within a certain range, which is beneficial to the election. The specific method is shown in Formula 2:

[0090]

[0091] The variance of importance scores between nodes can be determined by the coefficient k, which is a constant greater than 0. By changing the value of coefficient k, the variance of importance scores for all nodes can be controlled within a certain range. This value can be added to the minimum importance score to make all node scores positive, which facilitates subsequent processing.

[0092] As can be seen, the above normalization process can control the variance of the importance scores between nodes within a certain range, without changing the original score ranking. Nodes with high scores will still have high scores after the adjustment, and nodes with low scores will still have low scores after the adjustment. This normalization keeps the variance of the importance scores of nodes within a certain range, making the scoring system more reasonable and reducing the influence of subjectivity. Through the above process, the importance score of each node can be obtained.

[0093] In the embodiment of the present invention, the above step 102, in which the importance share value corresponding to the node is calculated by the election strategy algorithm based on the importance score, includes:

[0094] Each node calculates its importance share using a verifiable random algorithm based on a random seed value, private key, public key, hyperparameters, importance score, and the sum of importance scores. The higher the value of the hyperparameter, the higher the proportion of nodes elected as candidate leaders.

[0095] For any node i, the value interval [0,1) is divided into ω i +1 subinterval, calculate the probability that a random number in the range [0,1) falls in interval j, that is, the probability that any node i is selected, and the probability that any node i is selected is the importance share j of the node, where ω iis the importance score of any node i, that is, the importance share value of the node, j = 0, 1, ..., ω i .

[0096] Specifically, in a specific embodiment of the present invention, based on the above node scoring mechanism, the present invention proposes a cryptographic random election strategy based on the importance score of the candidate leader. This strategy is based on the Algorand election algorithm. Each node i has a corresponding importance score ω i , the probability of being selected as a candidate leader is Positive correlation, using VRF (Verifiable Random Function: Verifiable Random Function) as a verifiable random function, can make the candidate set obtained in each cycle have unpredictable randomness, and the election results can be independently verified by other nodes. VRF can convert a random seed seed into a hash value hash and a proof value proof. It is generated by the random seed and the current node's private key sk. Using this proof value, the node's seed and public key pk can prove that the hash value is correct. As long as the node's private key sk is unknown, other nodes cannot predict the hash value generated by the node. Algorand's sorted election strategy and its verification mechanism are shown in Algorithm 1 and Algorithm 2:

[0097] like Figure 2 and Figure 3 As shown, the specific candidate leader algorithm is shown in Algorithm 1, and the specific verification algorithm is shown in Algorithm 2. Each node calculates the importance sharing j value and importance score ω based on the public key and private key through the VRF function i , if the output value j is greater than 0, it proves that the candidate leader has been elected. In addition, Used to control the proportion of candidates elected as candidate leaders among all candidates, where W = ∑ω i τ is a hyperparameter. The higher the value of the hyperparameter τ, the higher the proportion of nodes that can be elected as candidate leaders;

[0098] The input of Algorithm 1 is: the node's private key, random seed, and the node's importance score; the output is: the node's election value j.

[0099] Here are the steps:

[0100] First, a random seed value for the VRF is generated. All nodes can calculate this value locally, without being controlled by other nodes. This calculation can be considered completely random. A simple strategy is to XOR all account balances and then hash them. Each participating node then generates a hash value and proof value based on the VRF function.

[0101] The participating node then normalizes the hash value and calculates whether it is elected as the candidate leader according to the binomial distribution probability. If the output value j is greater than 0, it proves that it has been elected as the candidate leader.

[0102] in addition Is a hyperparameter used to control the proportion of elected candidate leaders to all candidates, where W = ∑ω i The higher the value of the hyperparameter τ, the higher the proportion of nodes that can be elected as candidate leaders. Conversely, a lower value will reduce the proportion of nodes that can be elected as candidate leaders.

[0103] The input of Algorithm 2 is: node public key, random seed, hash generated by VR, proof value, and the output is: node election value j.

[0104] The steps are to verify whether the election value is j through the verifyVRF function and the above input. The rest of the process is similar to Algorithm 1.

[0105] Analogous to similar probability problems, it can be explained intuitively: in this algorithm, the probability of a node being elected is positively correlated with its own importance score. The importance score of node i is ω i , which can be understood as node i has ω i coins, all nodes have a total of W = ∑ω i Coins. Let the probability of a single coin being selected be Then it is obvious that node i has ω i The probability of being selected k times in the case of a coin is:

[0106]

[0107] Divide the interval [0,1) into ω i +1 interval, the jth (j=0,1,…,ω i The length of each interval is B(j;ω i ,p), that is, the probability of node i being selected is j times. Then each interval I j It can be expressed as:

[0108]

[0109] Then a random number in the range [0,1) The probability of falling in interval j is equivalent to node i holding ω iThe probability of being selected j times given a given value of 0. The return value j is the number of times a node has been selected. In this algorithm, a node is considered a candidate leader only if j is greater than 0, meaning it has been selected at least once. Theoretically, the proportion of candidate nodes can be reduced by raising the j threshold. However, in practice, all adjustments to j can be made by adjusting p, and adjustments to p are continuous, while adjustments to j are discontinuous. After a node obtains its importance share j, it uses VRF to generate j candidate hash values. These candidate hash values ​​are sent to the current leader to participate in the next round of leader election.

[0110] In the embodiment of the present invention, the step of each node calculating its own candidate hash value and seed value includes:

[0111] The balance of each node plus the current number of cycles is used as the seed value, and together with the node's private key, the corresponding candidate hash value and proof value are generated;

[0112] Based on a set of candidate hash values ​​and a corresponding set of proof values, the node verifies whether the lengths of the two arrays are equal to the node's importance share j;

[0113] After a new leader is elected, all nodes verify the hash value and proof value announced by the new leader.

[0114] Specifically, in the specific embodiment of the present invention, Figure 4 As shown in , after a node obtains its own importance share j, it will use VRF to generate j candidate hash values. These candidate hash values ​​will be sent to the current leader to participate in the next round of leader election. The generation process of candidate hash values ​​is as follows Figure 4 As shown in Algorithm 3.

[0115] Because each node has a different importance share, each node generates its own seed value when generating candidate hash values. This embodiment of the present invention provides a method that uses the node's balance plus the current cycle count as a seed value, along with the node's private key, to generate corresponding candidate hash values ​​and proof values. When a candidate hash participates in an election, the random number is unbiased and the node is unaware of the candidate hash values ​​of other nodes. Therefore, the selection of candidate hashes is unpredictable, eliminating the need for nodes to specifically generate unique candidate hash values. This method, which uses the balance plus the current cycle count, is simple and easy to use. Firstly, it makes it easy for nodes to calculate the seed and for other nodes to verify it. Secondly, each node uses the same rules to generate candidate hash values, ensuring fairness among nodes. After a node generates a candidate hash value, other nodes can verify the process to ensure that the hash value generated by the node is not fraudulent. Verification consists of two parts. The first part involves quantitative measurement. A node is given a set of candidate hash values ​​and a corresponding set of proof values, and it verifies whether the lengths of these two arrays are equal to the node's importance share j. The second part involves the measurement of specific information. When a node uses the VRF algorithm, the seed value is fixed, so the generated hash value and proof value are unique. Of course, this verification process occurs after a new leader is elected, preventing premature disclosure of the leader's information. All nodes in the channel know the selected candidate hash value, but not who it belongs to. After the new and old leaders exchange information, the new leader publishes its own hash value and proof value and, after verification, assumes leadership.

[0116] In the embodiment of the present invention, in step 103, the seed values ​​sent by the current leader to all nodes are used to obtain a total seed value, a corresponding hash value and a proof value are generated based on the total seed value using a verifiable random algorithm, a second random number is calculated based on the first random number and the number of candidate hash values, and a node corresponding to the second random number is selected from the candidate hash values ​​as the next leader, including:

[0117] Each node in the channel sends the candidate hash value and its own seed value to the current leader. After receiving the seed values ​​of all nodes, the current leader performs an XOR operation to obtain the total seed value;

[0118] Based on the total seed value and the current leader's private key, a verifiable random algorithm is used to calculate the hash value and verification value;

[0119] Calculate a first random number k according to the hash value, wherein the first random number is an unbiased random number in the value range [0, 1);

[0120] The current leader counts the total number of candidate hash values ​​collected as N, and multiplies the first random number k by the total number of hash values ​​N to obtain a second random number in the range [0, N). The second random number corresponds to N candidate hash values.

[0121] Arrange the N candidate hash values ​​in order, select the candidate hash value corresponding to the second random number, and the node corresponding to the candidate hash value will be the next leader.

[0122] Specifically, in a specific embodiment of the present invention, after each node calculates its own importance share j through the Algorand algorithm, it will use VRF to generate j verifiable hash values, which are its own candidate hash values. It can be seen that when the importance score is higher, the importance share calculated by the Algorand algorithm is larger, and thus more candidate hash values ​​can be generated, and the possibility of being elected as a leader is greater. Conversely, when the importance score is lower, the importance share calculated by the Algorand algorithm is smaller, and thus fewer candidate hash values ​​can be generated, and the possibility of being elected as a leader is smaller. The current leader will collect within a certain period of time, and the nodes acting in the right direction will send candidate hash values ​​as required. The malicious nodes will also send candidate hash values ​​in order to become the leader. The leader will record the total number of candidate hash values ​​collected, as well as each corresponding node. The current leader then uses VRF to generate unbiased random numbers. The specific process is as follows: Figure 5 shown.

[0123] from Figure 5As can be seen, the VRF algorithm is primarily used here to generate unbiased random numbers. The VRF algorithm is run by the current leader, acting as an obfuscator. The VRF has two inputs: a total seed value. This total seed value is crucial to prevent the current leader from controlling the election. The value of this parameter must be uncontrollable and unknowable by the leader in advance, otherwise the leader could manipulate the election. In this embodiment of the present invention, this total seed value is generated by all participating nodes. Specifically, when a node in a channel sends its candidate hash to the leader, it also sends its own seed value. This seed value is determined by the node itself and cannot be controlled by others. After receiving the seed values ​​from all nodes, the leader performs an XOR operation on them to obtain the total seed value. This ensures that the seed value input to the VRF is not controlled by the leader or individual nodes. It is a random number generated by all nodes, ensuring uncontrolled and secure generation of unbiased random numbers. Another parameter is the leader's private key, which is known only to the leader. It can be verified in the future through the leader's public key, which is known to all nodes. Therefore, when the leader acts as a mixer, all nodes jointly generate the seed value, which can ensure that this part is not controlled by the leader or other nodes, ensuring security. In addition, after using VRF to obtain the hash value and proof verification value, because the hash value is a binary number, it is calculated by The value of can get a random number between [0,1), denoted as k. According to the properties of VRF, it can be proved that this random number is an unbiased random number. The generated value between [0,1) is random and discrete, and each value has the same probability. At the same time, the current leader will put the collected candidate hash values ​​together and count the total number. Assuming that the total number of all candidate hashes is N, an unbiased random number in [0,N) can be obtained through k×N. This random number is of equal probability and equal spacing, which just corresponds to the N candidate hash values. Then the N candidate hash values ​​are arranged from small to large, and the k×N hash value is elected. The corresponding node is the next leader, and the current leader can transfer information with the node. At this time, other nodes do not know what the selected hash value is, because ordinary nodes do not know the candidate hash situation of other nodes. Only the leader knows all the candidate hashes. In this way, the current leader acts as a mixer, so this can ensure the security of information transfer between new and old leaders. After the information transfer is completed, the current leader will announce the VRF parameters and the candidate hash situation. The candidate hash can also be verified. In this way, all information is verifiable and security can be guaranteed.

[0124] In general, the current leader is used as an obfuscator. The current leader knows all the information and is directly responsible for the election. However, all the information is visible and available to the leader and cannot be changed. The leader only plays a role in calculation. The result is controlled by all nodes and cannot be controlled by the leader alone. Therefore, it prevents the leader from falsifying information and avoids the situation where the leader has too much power. As long as the leader acts normally and completes the information transfer with the new leader after the new leader is generated, the purpose of hiding the new leader can be achieved by not exposing the new leader in advance. This solves the problem of privacy leakage and forms privacy protection.

[0125] In the embodiment of the present invention, after a new leader is elected, the step of verifying the election process by all nodes in the channel includes:

[0126] Based on the leader's public key, all nodes verify the authenticity of the total seed value;

[0127] All nodes verify the correctness of the hash value based on the total seed value, leader public key and verification value;

[0128] All nodes verify the correctness of the first random value and the total number of candidates;

[0129] All nodes verify the correctness of the candidate hash value.

[0130] Specifically, in a specific embodiment of the present invention, after a new leader is elected, all nodes in the channel can verify the election process. In the part where the leader acts as a mixer, the verification process is as follows: Figure 6 As shown:

[0131] In the part where the leader acts as a mixer to generate unbiased random numbers to elect a leader, the verification process of nodes in the channel mainly consists of four parts. Only when all four parts are verified can the nodes in the channel recognize the election of the new leader and the new leader can perform their functions. Otherwise, the nodes in the channel cannot reach a consensus and will enter the arbitration stage.

[0132] The first part is to verify the total seed value. The leader's public key is known. The total seed value is generated by all nodes. It is the XOR result of the seed values ​​provided by all nodes. This total seed value directly determines the subsequent results and is very important for the subsequent election results. Therefore, all nodes need to verify the authenticity of the total seed value first. Each node can know the seed value of other nodes. This can be obtained through point-to-point communication or from the leader's information. After the XOR operation, it is compared with the total seed value announced by the leader. If they are the same, the verification is passed. If they are different, the verification fails, and it is considered that there is a problem with the process.

[0133] The second part is to verify the hash value generated by VRF. This is verified based on the total seed value, leader public key, and proof value. When the total seed value is constant and the leader's public and private keys remain unchanged, the hash value and proof value are determined and correspond one-to-one to the total seed value and public and private keys. Therefore, when the hash value and proof value change, the VRF verification will not pass, ensuring the uniqueness of the hash value and proof value and the correctness of the hash value.

[0134] Part III, Verification After verifying that the hash value generated by VRF is correct, it is necessary to verify the correctness of the value generated in the related calculation to ensure that there is no falsification. At the same time, the total number of candidates must also be correct. The candidate values ​​of some nodes cannot be missing, which is unfair and falsified. Therefore, the total number of candidates N also needs to be verified to be correct. In this way, k×N is correct, ensuring the correctness of the unbiased random number.

[0135] The fourth part verifies the correctness of the candidate hash values. The candidate hash values ​​need to be arranged from small to large, and the k×Nth hash value is selected. Therefore, the node needs to know the total number of candidate hash values. This can be announced by the leader. Each candidate hash value is previously generated by the node through VRF and can also be verified for correctness. This ensures that the candidate hash value is not generated out of thin air or fabricated, but needs to have a source. This source requires nodes to communicate with each other point to point. The source of the new leader's candidate hash will be verified throughout the network, thereby confirming the correctness of the candidate hash and the correctness of the order. Through the above verification, the correctness of the election process in which the leader acts as a mixer to generate unbiased random numbers to elect the leader can be guaranteed.

[0136] As described above, the method of the present invention can be better implemented.

[0137] Compared to existing technologies, the first part of this invention involves each node determining its importance share based on its importance score. This process ensures quality and fairness, while a verification algorithm ensures security. The second part uses the node's importance share to generate candidate hash values. This invention provides algorithms for generating candidate hash values ​​and uses a verification algorithm to ensure the security of the process, thereby detecting fraudulent activity.

[0138] Example 2

[0139] like Figure 7 As shown, the embodiment of the present application provides a blockchain off-chain channel consensus system, which adopts the above-mentioned blockchain off-chain channel consensus method, and the system includes:

[0140] Scoring system construction module 201: Constructing a scoring system for consensus participating nodes in the blockchain channel. The scoring system is used to measure the importance score of each node;

[0141] Importance share calculation module 202: Based on the importance score, the importance share value corresponding to the node is calculated through the election strategy algorithm, and each node calculates its own candidate hash value and seed value;

[0142] New leader election module 203: The current leader obtains the total seed value from the seed values ​​sent to all nodes, generates the corresponding hash value and proof value based on the total seed value using a verifiable random algorithm, generates a first random number based on the hash value, calculates a second random number based on the first random number and the number of candidate hash values, selects the node corresponding to the second random number from the candidate hash values ​​as the next leader, and completes the election of the new leader.

[0143] Example 3

[0144] An embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the blockchain off-chain channel consensus method.

[0145] Example 4

[0146] An embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the steps of the blockchain off-chain channel consensus method are implemented.

[0147] In addition, combined Figure 1 The blockchain off-chain channel consensus method described in the embodiment of the present application can be implemented by electronic devices, such as computer devices. Figure 8 Schematic diagram of the hardware structure of a computer device according to an embodiment of the present application.

[0148] In some embodiments, the computer device may further include a communication interface 83 and a bus 80. Figure 8 As shown, the processor 81, the memory 82, and the communication interface 83 are connected via a bus 80 and communicate with each other.

[0149] Specifically, the processor 81 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0150] The memory 82 may be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 81 .

[0151] The processor 81 implements any one of the blockchain off-chain channel consensus methods in the above embodiments by reading and executing computer program instructions stored in the memory 82.

[0152] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0153] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.

Claims

1. A blockchain off-chain channel consensus method, characterized by: The method comprises: Constructing a scoring system for consensus-participating nodes in blockchain channels, which is used to measure the importance score of each node; Based on the importance score, the importance share value corresponding to the node is calculated by an election strategy algorithm, and each node calculates its own candidate hash value and seed value; The current leader obtains a total seed value from the seed values ​​sent to all nodes, generates a corresponding hash value and proof value based on the total seed value using a verifiable random algorithm, generates a first random number based on the hash value, calculates a second random number based on the first random number and the number of candidate hash values, selects the node corresponding to the second random number from the candidate hash values ​​as the next leader, and completes the election of a new leader.

2. The blockchain off-chain channel consensus method according to claim 1, characterized in that: The method further comprises: After a new leader is elected, all nodes in the channel verify the election process.

3. The blockchain off-chain channel consensus method according to claim 1 or 2, characterized in that: The steps of constructing a scoring system for consensus participating nodes in the blockchain channel include: The importance score of each node in the channel of the current round is calculated based on the node's balance, number of outgoing transactions, number of incoming transactions, contribution rate, and the influence weight value of each score; and the importance score is normalized.

4. The blockchain off-chain channel consensus method according to claim 1 or 2, characterized in that: The step of calculating the importance share value corresponding to the node by using an election strategy algorithm based on the importance score includes: Each node calculates an importance share value using a verifiable random algorithm based on a random seed value, a private key, a public key, a hyperparameter, an importance score, and the sum of the importance scores; wherein a higher value of the hyperparameter indicates a higher proportion of nodes elected as candidate leaders; For any node i, the value interval [0,1) is divided into ω i +1 subinterval, calculate the probability that a random number in the range [0,1) falls in the j interval, that is, the probability that any node i is selected, and the probability that any node i is selected is the importance share j of the node, where ω i is the importance score of any node i, that is, the importance share value of the node, j = 0, 1, ..., ω i .

5. The blockchain off-chain channel consensus method according to claim 4 is characterized in that: The step of each of the nodes calculating their respective candidate hash values ​​and seed values ​​includes: Using the balance of each node plus the current number of cycles as a seed value, together with the private key of the node, to generate a corresponding candidate hash value and proof value; The node verifies whether the lengths of the two arrays are equal to the importance share j of the node based on a set of candidate hash values ​​and a corresponding set of proof values; After a new leader is elected, all of the nodes verify the hash and proof values ​​that the new leader will publish.

6. The blockchain off-chain channel consensus method according to claim 1 or 2, characterized in that: The step of obtaining a total seed value from the seed values ​​sent by the current leader to all nodes, generating a corresponding hash value and a proof value based on the total seed value using a verifiable random algorithm, calculating a second random number based on the first random number and the number of the candidate hash values, and selecting the node corresponding to the second random number from the candidate hash values ​​as the next leader includes: Each node in the channel sends a candidate hash value and its own seed value to the current leader. After receiving the seed values ​​of all nodes, the current leader performs an XOR operation to obtain a total seed value. Calculate a hash value and a verification value using a verifiable random algorithm based on the total seed value and the private key of the current leader; Calculate the first random number k according to the hash value, wherein the first random number is an unbiased random number in the value range [0, 1); The current leader counts the total number of candidate hash values ​​collected as N, and obtains the second random number in the interval [0, N) by multiplying the first random number k by the total number of hash values ​​N, where the second random number corresponds to the N candidate hash values; Arrange the N candidate hash values ​​in order, select the candidate hash value corresponding to the second random number, and the node corresponding to the candidate hash value is the next leader.

7. The blockchain off-chain channel consensus method according to claim 2, characterized in that: After the new leader is elected, all nodes in the channel verify the election process, including: Based on the leader's public key, all nodes verify the authenticity of the total seed value; All nodes verify the correctness of the hash value based on the total seed value, leader public key and verification value; All nodes verify the correctness of the first random value and the total number of candidates; All nodes verify the correctness of the candidate hash value.

8. A blockchain off-chain channel consensus system, using the blockchain off-chain channel consensus method according to any one of claims 1 to 7, characterized in that: The system comprises: Scoring system construction module: Build a scoring system for consensus participating nodes in the blockchain channel, which is used to measure the importance score of each node; Importance share calculation module: Based on the importance score, calculate the importance share value corresponding to the node through the election strategy algorithm, and each node calculates its own candidate hash value and seed value; New leader election module: The current leader obtains the total seed value from the seed values ​​sent to all nodes, generates a corresponding hash value and proof value based on the total seed value using a verifiable random algorithm, generates a first random number based on the hash value, calculates a second random number based on the first random number and the number of candidate hash values, selects the node corresponding to the second random number from the candidate hash values ​​as the next leader, and completes the election of the new leader.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the blockchain off-chain channel consensus method described in any one of claims 1 to 7 are implemented.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the blockchain off-chain channel consensus method according to any one of claims 1 to 7 are implemented.