DPOS consensus method based on improved SM9 algorithm

By improving the SM9 algorithm to construct VRF and introducing the binomial distribution DPOS consensus method, combined with a deposit and reward/penalty mechanism, the problems of node non-participation in voting and monopoly of accounting rights are solved, thereby improving the security and efficiency of the DPOS consensus mechanism.

CN120956402APending Publication Date: 2025-11-14ZHENGZHOU UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511213311.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

Traditional DPOS consensus mechanisms suffer from problems such as nodes not actively voting, monopolizing the right to record transactions, and malicious behavior by block-producing nodes. Existing solutions have failed to effectively address these issues or have shortcomings.

Method used

An improved SM9 algorithm is used to construct a verifiable random function (VRF), which is combined with a binomial distribution to select block-producing nodes through local lottery. A deposit and reward/penalty mechanism are also introduced to ensure that nodes honestly fulfill their responsibilities.

Benefits of technology

It enables fair competition among nodes for block production rights, reduces passive voting and monopolistic accounting rights, improves the security and efficiency of the consensus mechanism, and prevents malicious behavior by nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956402A_ABST
    Figure CN120956402A_ABST
Patent Text Reader

Abstract

The invention provides a DPOS consensus method based on an improved SM9 algorithm, and provides a VRF construction method based on the improved SM9 algorithm in order to solve the problems of inactive node voting, billing right monopoly and chunk node disability existing in a traditional DPOS consensus mechanism. Due to the fact that the improved SM9 algorithm is an uncertain algorithm, in order to meet the requirement for constructing the VRF, a random function is not used for generating the pseudo-random number any more, the RFC algorithm is used for generating the pseudo-random number, and the improved SM9 algorithm is a deterministic algorithm. In order to select a fixed number of representative nodes through drawing to introduce binomial distribution, and meanwhile, in order to avoid an accounting right monopoly phenomenon caused by factors such as node weights and reputation values, the selection probability of each node is regulated to be equal and is irrelevant to the weights and reputation values of the nodes. Meanwhile, a reward and punishment scheme is designed for reward and punishment conditions of the nodes to encourage honest nodes to restrain dishonest nodes, so that the safety of the system is maintained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of blockchain technology, and in particular relates to a DPOS consensus method based on an improved SM9 algorithm. Background Technology

[0002] With the rapid development of blockchain technology, the mainstream consensus mechanisms for public blockchains currently include Proof-of-Work (PoW), Proof-of-Stake (PoS), and Delegated Proof-of-Stake (DPoS). Bitcoin is a typical example of PoW, Ethereum a typical example of PoS, and Ethereum (EOS), based on SDH, a typical example of DPoS. The PoW consensus mechanism is based on the competition for the right to record transactions using computing power. Its disadvantages include high energy consumption, slow transaction confirmation speed, and the gradual concentration of computing power in a few large mining pools, leading to a degree of centralization. To address the shortcomings of the PoW consensus mechanism in terms of resource waste, low transaction efficiency, and security, a consensus mechanism based on the amount of staked tokens—PoS—was proposed. In the PoS mechanism, nodes holding a certain number of tokens have the opportunity to be selected as validator nodes to participate in the consensus process. However, its disadvantages include lower security against attacks, vulnerability to double-spending attacks, 51% attacks, and stakeless attacks. Furthermore, the number of elected nodes is relatively large, and their quality varies, resulting in lower decentralization compared to PoW. To address the problems of Proof-of-Stake (PoS), a consensus mechanism called Delegated Proof-of-Stake (DPoS) is proposed, where token holders compete for the right to record transactions based on the number of votes they receive. In DPOS, the representative nodes with the most votes participate in the consensus process. Compared to Proof-of-Work (PoW) and PoS, this mechanism significantly reduces the number of nodes involved in verification and recording, enabling rapid consensus verification (reaching second-level processing speeds). Furthermore, the system's election process allows everyone to become a delegator. This mechanism demonstrates robustness in various scenarios (minor forks, network fragmentation, offline minority multi-production, majority producer fraud, etc.). However, it also has drawbacks: low voting enthusiasm among token holders, inability to promptly handle malicious nodes, collusion among representative nodes, and low decentralization. A comparison of PoW, PoS, and DPOS is shown in the table below.

[0003] consensus mechanism POW POS DPOS Typical Representative Bitcoin Ethereum 2.0 EOS Implementation mechanism The competition for the right to record transactions is based on computing power. The right to record transactions is determined by the amount of collateralized tokens. The right to record transactions is determined by the number of votes received by each token holder. Transaction speed It's relatively slow; Bitcoin produces a block approximately every 10 minutes. Fast, thousands of transactions per second Fast, thousands of transactions per second Resource consumption High, requiring a large amount of computing resources and electricity. Low cost, relies on token holdings, requires minimal computation Low resource consumption, requiring only a small number of representative nodes to operate. Security High, possessing strong resistance to 51% attacks. It is relatively vulnerable to long-range attacks, 51% attacks, and stakeless attacks. The electoral mechanism is relatively high, but it may lead to the concentration of power, posing a risk of manipulation and malicious actions by representative nodes. Decentralization High, low barrier to entry for node participation High participation rate among token holders Lower, transactions are verified by a small number of representatives.

[0004] Currently, improvements to the DPOS consensus mechanism can be broadly categorized into three aspects: 1) increasing the speed of transaction recording on the blockchain; 2) accelerating the elimination of malicious nodes; and 3) refining the revenue distribution and incentive mechanisms for different nodes. A common solution to ensure that voting nodes, representative nodes, and other ordinary nodes honestly fulfill their responsibilities is to use economic means to incentivize nodes to maintain system security and constrain malicious behavior.

[0005] In response to the problems of lack of incentives for voting nodes leading to inactive voting and the inability to quickly remove representative nodes with malicious behavior, [Miao Guitian. Research on DPoS Consensus Mechanism Based on Incentive Mechanism and Implementation of Prototype System [D]. Beijing University of Posts and Telecommunications, 2023.] proposed the following methods: 1) Add voting rewards for voting nodes. To prevent nodes from voting maliciously, a deposit system is established, and reputation value rewards and punishments are set to increase the cost of malicious voting by nodes. 2) For representative nodes, while giving block rewards (including fixed rewards and floating rewards), a deposit system also needs to be increased to raise the cost of doing evil, and a reputation value rewards and punishment system is established to quickly screen and remove malicious nodes. However, she only simply gave the overall issuance level of tokens and did not give the expenditure method of transactions. There may be an inflation phenomenon in the system. Moreover, for the floating reward f, in order to control the upper limit of f, only f = g×k, (0 < k < 1) is used for simplified processing (where g is the fixed reward), and the value of f cannot be dynamically set according to the actual situation.

[0006] In response to the phenomenon of monopoly of accounting rights, [Zhao Yiwen. Research on Blockchain Consensus Algorithm [D]. Nankai University, 2022.] used the VRF verifiable random function to replace the node voting process and randomly selected each role in the consensus, enabling each node to fairly compete for the accounting right and achieving the decentralized requirement of the blockchain. He used the national cryptography SM2 algorithm to construct the VRF and used the SM3 algorithm as the hash function. The designed lottery algorithm allocates weights according to the tokens held by each user, and the probability of each user being selected is proportional to its weight. In order to select a fixed number of representative nodes through lottery, the binomial distribution is introduced. However, this article did not use the SM2 algorithm for encryption or signature processes. It only used the system parameters of the SM2 algorithm and combined with the VRF construction process based on ECC. Moreover, the probability of a node being selected is proportional to its weight and is also related to the reputation value of the node. Since the node weight is measured based on the amount of tokens held by the node, over time, nodes with more tokens in the system will have a higher probability of being selected, and thus the phenomenon of monopoly of accounting rights will occur again.

[0007] [Li Yilin, Huang Hui, Lan Yu. Multi-Master Node Consensus Algorithm of Verifiable Random Function [J]. Journal of Minnan Normal University (Natural Science Edition), 2024, 37(02): 74-86.] proposed the VRF cryptographic lottery method, which calculates the k value when e falls within the interval I based on the normal distribution and selects representative nodes according to the size of the k value. The probability of a node being selected by this method is also related to the weight and reputation value of the node.

[0008] [Li Yifan. Research on Hierarchical Byzantine Fault-Tolerant Consensus Algorithm Based on Verifiable Random Function [D]. Beijing Jiaotong University, 2023.] The proposed lottery method first numbers the nodes in the system from 0 to n, then obtains a random value based on the VRF and takes the modulo of n, i.e., let vote = nonce % n, then the node with the sequence number vote gets a vote, and finally the representative node is selected according to the number of votes. However, this method generally works well when the value of n is relatively large, and the result after taking the modulo of n is... Vote j They will be randomly distributed in the range [0, n-1]. The probability of different nonces having the same result when modulo n is very low. p j =1 / n ×1 / n =1 / n 2 Therefore, most nodes will receive 1 vote, making it impossible to select a block-producing node based on the number of votes. Summary of the Invention

[0009] This invention addresses the problems of non-active node voting, monopoly of accounting rights, and malicious behavior of block-producing nodes in traditional DPOS consensus mechanisms. To overcome the shortcomings of the above-mentioned schemes, it proposes a DPOS consensus method based on an improved SM9 algorithm.

[0010] In a first aspect, the present invention provides a DPOS consensus method based on an improved SM9 algorithm, comprising the following steps: Each node in the network executes the VRF generation algorithm locally to generate a random number R and a proof P; then, based on the generated random number R, it calculates e = R / N, where e ∈ [0, 1) is the cumulative probability value, and N is the order of the subgroup, which is a prime number; Each node calculates and obtains its own inequality. The value of j; where j is an integer used to mark the endpoints of the cumulative probability interval, and is used as a numerical value to select the block-producing node; the election probability p = m / n, where n is the total number of nodes in the network, and m is the number of block-producing nodes to be generated; Broadcast the value of j, the random number R, and the proof P to other nodes; Each node executes the VRF verification algorithm to verify the random number R and proof P received from other nodes; Determine whether all nodes have reached a 2 / 3 consensus on the verification of the received random number R and the proof P. If a 2 / 3 consensus is not reached, i.e. the verification fails, then it is determined that a minority of nodes have engaged in misconduct, and the nodes with misconduct are marked once. If a 2 / 3 consensus is reached, each node that has reached a consensus sorts all the obtained j values ​​from largest to smallest. When the j values ​​are the same, they are sorted according to the size of the corresponding e values. Finally, the first m nodes are selected as the nodes to be produced, and the results of the nodes to be produced are broadcast. Determine whether the results of the pending block-producing nodes have reached a 2 / 3 consensus. If not, determine that a minority of nodes have engaged in misconduct. If a 2 / 3 consensus is reached, the local node determines whether it is among the top m nodes. If it is not among the first m nodes, then convert the local node to a normal node; If it is within the first m nodes, then the local node is the block-producing node and a block is produced. When a block-producing node produces a block, it first collects and verifies the transactions, packages them into a block, and then broadcasts the generated block. When a block-producing node produces a valid block, it performs the on-chain operation and enters the next round of election; Nodes exhibiting misconduct are marked once, and it is determined whether the number of times a marked node has been marked is greater than or equal to 3. If it is greater than or equal to 3, the corresponding node is removed from the network. If the number of violations is less than 3, the corresponding node will be disqualified from this election and will be converted into a regular node. Each ordinary node generates a new transaction and broadcasts it, then verifies and synchronizes the block. Once all ordinary nodes have reached a consensus, they enter the next round of elections.

[0011] Based on the above, the methods for generating random numbers R and proving P using the VRF algorithm are as follows: (1) System parameter generation; The Key Generation Center (KGC) generates a random number S. S ∈[1,N-1], serving as the master private key; The Key Generation Center (KGC) selects and publishes a private key generation function identifier (hid) represented by a single byte. Assume user A's identity is identified by ID. A The key generation center KGC first in the finite field F N The above calculation t1=H1(ID) A ||hid,N)+S S ; If t1=0, then regenerate the master private key and simultaneously calculate element P in group G1. S =S S • P1 is used as the system's master public key and made public, thus obtaining the master key pair (S S ,P S Based on the regenerated master private key, the user private key S is recalculated.A ; If t1≠0, then calculate t2=S S ∙t1 -1 Then calculate the user's private key S A =t2∙P2, and the user's public key Q A =H1(ID A ||hid,N)∙P1+P S ; Where t1 and t2 are intermediate data; H1 and H2 are cryptographic functions; P1 and P2 are the generators of groups G1 and G2, respectively, where groups G1 and G2 are the elliptic curve groups E(F) and G2, respectively. q ) and E(F q 2 G1 is a subgroup of two additive cyclic groups on G2, and there exists a homomorphism f from group G2 to group G1 such that f(P2) = P1. Calculate the multiplicative cyclic group G T The element g=e(P) S ,P2);G T It is composed of the finite field F q¹² The subgroup of the multiplicative cyclic group consisting of all non-zero elements in the set G1, G2, and G2 is a prime number N, where e is a bilinear pair satisfying G1×G2→G2. T Mapping; Let message M be the header information of the last block in the current blockchain, including version number, parent block hash value, Merkle root, timestamp, user ID, random number R, proof P, round, j value and position; t is the round in which the current block was generated; (2) A VRF generation algorithm for generating random numbers R and proving P; The local node executes the VRF algorithm, inputting S. A After message M, output a pseudo-random number r∈[1,N-1]; Calculate the multiplicative cyclic group G T The element w=g r And convert the data type of w to a bit string; Calculate the integer h = H2(M||W,N); Calculate the integer L = (rh) mod N, and determine whether L is 0. If L = 0, then the node cannot generate a random number R and prove P. Calculate the multiplicative cyclic group G T The element S = [L]·S A And convert the data types of h and S into bit strings; Calculate the integer R = H2(h||S,N) and use it as the random number R; The calculation yields the proof that P=(h,S).

[0012] Based on the above, the verification process of the VRF verification algorithm is as follows: Convert the data type of h' to an integer and verify whether h'∈[1,N-1] is true. If it is not true, the verification fails. Convert the data type of S' to a point on the elliptic curve, and check whether S'∈G2 is true. If not, the verification fails. Calculate the multiplicative cyclic group G T The element g=e(P) S ,P2); Calculate the multiplicative cyclic group G T elements in ; Calculate the multiplicative cyclic group G T The element u=e(Q) A ,S'); Calculate the multiplicative cyclic group G T The element w' = u∙t is set in the array, and the data type of w' is converted to a bit string; Calculate the integer h2=H2(M'||w',N), and check whether h2=h' is true. If it is true, then P is valid and the verification is successful; otherwise, the verification fails. Calculate the random number R'=H2(h'||S',N), and determine whether R=R' is true. If it is true, the random number R has not been tampered with during transmission, and the verification is successful; otherwise, the verification fails.

[0013] Based on the above, a reward and punishment mechanism should be set up to prevent block-producing nodes from acting maliciously: When more than 2 / 3 of the pending block-producing nodes reach a consensus, the pending block-producing nodes pay a deposit, and the pending block-producing nodes that have paid the deposit become block-producing nodes and produce blocks. Determine whether the node to be produced a block has produced a block within the specified time period; If a block is generated within a specified time period, the transactions are first collected and verified, then packaged into a block and broadcast, and then it is determined whether the block generated by the block-producing node is a valid block. If it is a valid block, then add it to the blockchain; If it is not a valid block, then count it as an invalid block; If a block is not produced within the specified time period, check whether all nodes waiting to produce blocks have completed producing blocks. If they have not completed producing blocks, wait for a block to be produced and verify the blocks produced by other producing nodes. If block production has been completed, determine whether the consensus period has ended; If it has not ended, then wait for a block to be produced and verify the blocks produced by other block-producing nodes; If the process has ended, check if the number of invalid blocks produced by each block-producing node is greater than 3. If the value is greater than or equal to 3, the corresponding block-producing node's reward will be cancelled, its deposit will be confiscated, and it will be either registered or removed from the network. If the value is less than 3, a fixed reward and a floating reward are issued to the corresponding block-producing node. After receiving the fixed reward and the floating reward, the block-producing node returns to participate in the next round of election.

[0014] Based on the above, let the fixed reward be C. g =S×1 token, where S is the total number of valid blocks generated in one consensus cycle; 1 token is one token unit; Let the floating reward be C. f =C g ×α, where α is the floating factor, α=(S-f)÷B×k; where f is the total number of invalid blocks generated in a consensus cycle; B is the total number of blocks produced in a consensus cycle as defined by the system; k is a constant, which is determined according to the actual situation; The fixed reward C received by block-producing node i is then... gi =(S i -f i )×1 token; The floating reward C received by block-producing node i fi =C f ×α i ; The deposit D that block-producing node i needs to pay i =C g / 2; Among them, S i f is the number of valid blocks packaged by node i within a consensus period. i α is the number of invalid blocks packaged by node i within a consensus period. i =(S i -f i )÷B×k is the floating factor of node i.

[0015] Secondly, the present invention provides a DPOS consensus system based on an improved SM9 algorithm, comprising: Nodes are located within the network; The lottery election module is set up locally on each node to execute the VRF generation algorithm, generate random numbers R and proofs P; then calculate e=R / N based on the generated random numbers R, where e∈[0,1) is the cumulative probability value and N is the order of the subgroup being a prime number; It is also used to calculate and obtain the satisfying inequalities for each node. The value of j is an integer used to mark the endpoints of the cumulative probability interval, which serves as a numerical value to select the block-producing node; the election probability p = m / n, where n is the total number of nodes in the network and m is the number of block-producing nodes to be generated; And used to broadcast the j value, the random number R, and the proof P to other nodes; The first judgment and processing module is set up locally on each node to execute the VRF verification algorithm to verify the random number R and proof P received from other nodes. The second judgment and processing module is used to determine whether all nodes have reached a 2 / 3 consensus on the verification of the received random number R and proof P, and when it is determined that a 2 / 3 consensus has not been reached, it outputs the result that a minority of nodes have engaged in misconduct. And when it is determined that a 2 / 3 consensus has been reached, each node that has reached the consensus sorts all the j values ​​obtained from largest to smallest. When the j values ​​are the same, they are sorted according to the size of the corresponding e values. Finally, the first m nodes are selected as the nodes to be produced by blocks, and the results of the nodes to be produced by blocks are broadcast. The third judgment and processing module is used to determine whether the results of the pending block-producing nodes have reached a 2 / 3 consensus, and when it is determined that a 2 / 3 consensus has not been reached, it outputs the result that a minority of nodes have engaged in misconduct. The fourth judgment and processing module is set up locally on each node. When the third judgment and processing module determines that a 2 / 3 consensus has been reached, it determines whether the local node itself is among the top m nodes. If it is not among the top m nodes, the local node becomes a normal node; otherwise, the local node becomes a block-producing node. The block production module is set up locally on each node. When a node is about to produce a block, it first collects and verifies the transactions, packages them into a block, and then broadcasts the generated block. The fifth judgment and processing module is used to determine whether the block produced by the block producing node is a valid block, and when the block produced by the block producing node is determined to be a valid block, it notifies the block producing node to perform the on-chain operation and enter the next round of election. The sixth judgment and processing module is used to mark a node with misconduct once, and at the same time determine whether the number of times the marked node has been marked is greater than or equal to 3. If it is greater than or equal to 3 times, the corresponding node is removed from the network; and if it is less than 3 times, the corresponding node is disqualified from this election and the corresponding node is converted into an ordinary node. The regular block production module is set up locally on each node. It is used to generate new transactions and broadcast the generated new transactions after the corresponding node is converted into a regular node, as well as to verify blocks and synchronize blocks. The seventh judgment and processing module is used to notify all ordinary nodes to enter the next round of election after determining that all ordinary nodes have completed consensus.

[0016] Thirdly, the present invention provides a computer device, comprising: One or more processors; Memory, used to store one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors perform the steps of the DPOS consensus method based on the improved SM9 algorithm as described above.

[0017] Fourthly, the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the DPOS consensus method based on the improved SM9 algorithm as described above.

[0018] Fifthly, the present invention provides a computer program product, including a computer program / instruction that, when executed by a processor, implements the steps of the DPOS consensus method based on the improved SM9 algorithm as described above.

[0019] Compared with the prior art, the present invention has the following significant advantages: 1. This invention uses an improved SM9 algorithm combined with the RFC algorithm, which transforms the improved SM9 algorithm from an uncertain algorithm to a deterministic algorithm. That is, once the input data content is determined, the output content is determined and unique, avoiding the node from trying different inputs to generate an output that is advantageous to itself.

[0020] 2. This invention designs a lottery algorithm based on the Verifiable Random Function (VRF) of the improved SM9 algorithm and introduces a binomial distribution. Through this algorithm, nodes can use local lottery instead of the traditional voting method, thus effectively solving the problem of unenthusiastic node voting.

[0021] 3. When introducing binary distributed systems, this invention stipulates that the probability p of a node being selected is equal, and no longer depends on external evaluation factors such as the node's reputation value or the amount of tokens it possesses. This solves the problem of monopoly on the right to record transactions.

[0022] 4. This invention designs a reward and punishment mechanism. Its core idea is to use economic means to incentivize honest nodes and constrain malicious nodes, thereby enabling each node to consciously maintain system security and achieve fair participation in consensus. This solves the problem of malicious nodes and improves the security of the DPOS consensus mechanism. Attached Figure Description

[0023] Figure 1 A schematic diagram for generating proof P and random number R using a verifiable random function (VRF) based on the improved SM9 algorithm.

[0024] Figure 2 This diagram illustrates the verification of random number R using a verifiable random function (VRF) based on the improved SM9 algorithm.

[0025] Figure 3 This is a schematic diagram of the block structure of the present invention.

[0026] Figure 4 This is a schematic diagram illustrating the specific process of the DPOS consensus mechanism of the present invention. Detailed Implementation

[0027] The present invention will be further illustrated below with reference to specific embodiments. It should be understood that these embodiments are for illustrative purposes only and are not intended to limit the scope of the invention. After reading the present invention, any modifications of the present invention in various equivalent forms by those skilled in the art will fall within the scope defined by the appended claims.

[0028] Key Generation Center (KGC): Its primary responsibility is to generate, store, and manage keys to ensure information security and data privacy. In KGC, session keys are identity-based keys, which are temporary keys used in one-time sessions.

[0029] Blockchain Structure In a narrow sense, blockchain is an immutable, chain-like distributed database; in a broad sense, blockchain is a decentralized system that integrates technologies such as cryptography, P2P networks, consensus algorithms, and smart contracts.

[0030] The chain-like structure of a blockchain consists of multiple blocks connected together. A schematic diagram of the block structure of this invention is shown below. Figure 3 As shown, a complete block consists of a block header and a block body. The block header records information such as the version number, parent block hash, and Merkle root, while the block body records the transaction request and specific operations. Blocks are linked together to form a complete chain through the parent block hash.

[0031] VRF: Verifiable Random Functions (VRFs) possess characteristics such as verifiability, randomness, and uniqueness. Each node has a unique public-private key pair (public key pk). i With private key sk i ), when the same sk is input i In the case of a seed, the VRF computation function VRF_Evaluate will produce the same vrf_hash and vrf_proof. Where: vrf_hash is a hash generated by sk... i The seed is used as a parameter factor to generate a fixed-length pseudo-random string; vrf_proof is a document that proves that vrf_hash was generated by sk. i Evidence generated by the seed. The VRF verification function VRF_Verify can verify the evidence without considering the seed. i When it is made public, use the corresponding PK. iPerform verification. The output of VRF_Verify is a boolean value; it outputs true if the verification passes, and false otherwise.

[0032] RFC (Request for Comments) algorithm: RFC is an algorithm used to calculate hash values. Its design goal is to quickly calculate hash values ​​while maintaining a low collision rate. The RFC algorithm is based on bitwise operations and circular shift operations. It uses an iterative approach, performing a series of bitwise operations on each byte of the input data to calculate the hash value. Specifically, the RFC algorithm processes the input data byte by byte, then uses bitwise operations and circular shift operations to process each byte, ultimately obtaining a 32-bit hash value.

[0033] Improved SM9 algorithm: See Chinese invention patent application No. CN118694524A, published on September 24, 2024, entitled "A Blockchain Address Generation Method Based on an Improved SM9 Algorithm".

[0034] Example 1 This embodiment provides a DPOS consensus method based on an improved SM9 algorithm.

[0035] VRF construction based on the improved SM9 algorithm: (1) System parameter generation; The Key Generation Center (KGC) generates a random number S. S ∈[1,N-1], serving as the master private key; The Key Generation Center (KGC) selects and publishes a private key generation function identifier (hid) represented by a single byte. Assume user A's identity is identified by ID. A The key generation center KGC first in the finite field F N The above calculation t1=H1(ID) A ||hid,N)+S S ; If t1=0, then regenerate the master private key and simultaneously calculate element P in G1. S =S S • P1 is used as the system's master public key and made public, thus obtaining the master key pair (S S ,P S Update the existing user's private key S A ; If t1≠0, then calculate t2=S S ∙t1 -1 Then calculate the user's private key S A =t2∙P2, and the user's public key QA =H1(ID A ||hid,N)∙P1+P S ; Where t1 and t2 are intermediate data; H1 and H2 are cryptographic functions; P1 and P2 are the generators of groups G1 and G2, respectively, where groups G1 and G2 are the elliptic curve groups E(F) and G2, respectively. q ) and E(F q 2 G1 is a subgroup of two additive cyclic groups on G2, and there exists a homomorphism f from group G2 to group G1 such that f(P2) = P1. Calculate the multiplicative cyclic group G T The element g=e(P) S ,P2);G T It is composed of the finite field F q¹² The subgroup of the multiplicative cyclic group consisting of all non-zero elements in the set G1, G2, and G2 is a prime number N, where e is a bilinear pair satisfying G1×G2→G2. T Mapping; Let message M be the header information of the last block in the current blockchain, including version number, parent block hash value, Merkle root, timestamp, user ID, random number R, proof P, round, j value and position; t is the round in which the current block was generated.

[0036] (2) VRF generation algorithm (generating random number R and proving P); like Figure 1 As shown, the local node executes the VRF algorithm, with input S. A After message M, output a pseudo-random number r∈[1,N-1]; Calculate the multiplicative cyclic group G T The element w=g r And convert the data type of w to a bit string; Calculate the integer h = H2(M||W,N); Calculate the integer L = (rh) mod N, and check if L is 0. If L = 0, then select a random number again. Calculate the multiplicative cyclic group G T The element S = [L]·S A And convert the data types of h and S into bit strings; Calculate the integer R = H2(h||S,N) and use it as the random number R; The calculation yields the proof that P=(h,S).

[0037] (3) The verification process of the VRF verification algorithm is as follows: like Figure 2 As shown, the integrity of the random number R is determined using a hash function, and the user's public key Q is used as the reference. ATo prove that the random number R is indeed generated by the message M, the specific process is as follows: Convert the data type of h' to an integer and verify whether h'∈[1,N-1] is true. If it is not true, the verification fails. Convert the data type of S' to a point on the elliptic curve, and check whether S'∈G2 is true. If not, the verification fails. Calculate the multiplicative cyclic group G T The element g=e(P) S ,P2); Calculate the multiplicative cyclic group G T elements in ; Calculate the multiplicative cyclic group G T The element u=e(Q) A ,S'); Calculate the multiplicative cyclic group G T The element w' = u∙t is set in the array, and the data type of w' is converted to a bit string; Calculate the integer h2=H2(M'||w',N), and check whether h2=h' is true. If it is true, then P is valid and the verification is successful; otherwise, the verification fails. Calculate the random number R'=H2(h'||S',N), and determine whether R=R' is true. If it is true, the random number R has not been tampered with during transmission, and the verification is successful; otherwise, the verification fails.

[0038] To prove h2=h', it suffices to prove w=w' on the premise that M≠M'. If M≠M', even if w=w', then h2≠h'. This indicates that the node is not using the publicly specified M, and that the node is engaging in misconduct by repeatedly attempting to obtain random numbers that are advantageous to itself by inputting different values ​​of M.

[0039]

[0040] The VRF constructed in this invention based on the improved SM9 algorithm satisfies three properties of the VRF: (1) Uniqueness: Since the VRF algorithm involves the RFC6979 algorithm, the generated pseudo-random number r is determined, so the generated proof P and random number R are unique.

[0041] (2) Pseudo-randomness: The generated random number R uses a hash function, so that R is different for different inputs M (determined by the collision resistance of the hash function), and is randomly distributed in [0, N-1].

[0042] (3) Verifiability: The verifier uses the other party's public key Q. AAnd prove the correctness of the random number R verified by P (R is indeed generated by M and has not been tampered with during transmission), which is guaranteed by the mathematical proof of the SM9 signature verification algorithm.

[0043] Lottery algorithm: Assuming there are n nodes in the network, and m block-producing nodes are needed, the DPOS consensus mechanism is used to produce blocks in turn.

[0044] Each node can conduct a local "lottery" to elect a block-producing node with equal probability p=m / n. Here, p no longer depends on the node's token weight, margin ratio, or other reputation score. This is done to prevent monopolies, where nodes with more tokens and higher reputation scores are more likely to be elected as block-producing nodes, thus avoiding a large "wealth gap." By having each node conduct its own local lottery to elect block-producing nodes, instead of acting as a voting node, unfair practices such as passive voting and vote-buying are avoided.

[0045] (1) Lottery algorithm Each node in the network executes the VRF generation algorithm locally to generate a random number R and a proof P. Then, it calculates e = R / N based on the generated random number R, where e ∈ [0, 1) is the cumulative probability value and N is the order of the subgroup, which is a prime number. Each node calculates and finds those that satisfy the inequality. The value of j; where j is an integer used to mark the endpoints of the cumulative probability interval, and is used as a numerical value to select the block-producing node; the election probability p = m / n, where n is the total number of nodes in the network, and m is the number of block-producing nodes to be generated; Then the value of j, the random number R, and the proof P are broadcast to other nodes; Each node executes the VRF verification algorithm to verify the random number R and proof P received from other nodes; it then determines whether all nodes have reached a 2 / 3 consensus on the verification of the received random number R and proof P. If a two-thirds consensus is not reached, i.e. verification fails, then it is determined that a minority of nodes have engaged in misconduct, and the nodes with misconduct are marked once. If a 2 / 3 consensus is reached, each node obtains the j values ​​corresponding to all nodes, sorts the j values ​​from largest to smallest, and sorts them according to the corresponding e values ​​when the j values ​​are the same. Finally, the first m nodes are selected as block-producing nodes, and the results of the pending block-producing nodes are broadcast.

[0046] (2) Feasibility analysis of the plan Since n is relatively large in practice, satisfying np=n×m / n=m≥5 and n(1-p)=n-m≥5, the binomial probability curve can be approximately fitted by a normal distribution. According to the characteristics of the normal distribution, most nodes will find the corresponding j, so they can be sorted from large to small according to the j value.

[0047] Reward and punishment scheme: When m block-producing nodes are generated, in order to prevent block-producing nodes from acting maliciously, they need to pay a certain amount of security deposit to the system. Once misconduct is discovered (such as passively packaging blocks, invalid blocks reaching a set threshold, etc.), the security deposit will be confiscated, and the security deposit is greater than the node's revenue.

[0048] (1) Fixed reward C g C g =S×1 token Where S is the total number of valid blocks generated within a consensus cycle; 1 token is a token unit.

[0049] The fixed reward received by block-producing node i: C gi =(S i -f i )×1 token; Among them, S i f is the number of valid blocks packaged by node i within a consensus period. i This represents the number of invalid blocks packaged by node i within a consensus cycle.

[0050] (2) Floating reward C f C f =C g ×α Where α is the floating factor, α = (S - f) ÷ B × k; where f is the total number of invalid blocks generated within a consensus cycle; B is the total number of blocks produced within a consensus cycle as defined by the system; and k is a constant, determined according to the actual situation, tentatively set at 20%, meaning that α is a constant multiplied by a variable to adjust C. f size; The floating reward C received by block-producing node i fi =C f ×α i ; Where, α i =(S i -f i )÷B×k is the floating factor for node i; Block-producing node i receives an additional reward C fi Condition: f i<3 (tentative setting), which means that nodes are allowed to have individual invalid blocks, but once the threshold is exceeded, no additional rewards will be given, the deposit will be confiscated, and the node will be either named or removed from the network; The deposit D that block-producing node i needs to pay i =C gi / 2.

[0051] DPOS consensus based on the improved SM9 algorithm: Assuming there are n nodes in the network and m block-producing nodes are needed, the DPOS consensus mechanism is used to produce blocks in turn. The specific DPOS consensus method based on the improved SM9 algorithm is as follows: Step 1: Node i executes the VRF generation algorithm locally to generate a random number R and a proof P; then calculates e based on the generated random number R and the lottery algorithm to obtain its own j value; and broadcasts the j value, random number R, and proof P to other nodes. Step 2: Node i receives the value of j, the random number R, and the proof P broadcast by other nodes, and executes the VRF verification algorithm to verify the random number R and the proof P; Determine whether all nodes have reached a 2 / 3 consensus on the verification of the received random number R and the proof P. If not, proceed to step 3; if so, proceed to step 4.

[0052] Step 3: Determine if a few nodes have engaged in misconduct. Record the nodes with misconduct once. At the same time, determine if the number of times the recorded nodes have been recorded is greater than or equal to 3. If it is greater than or equal to 3, proceed to step 31; otherwise, proceed to step 32. Step 31: Remove the corresponding node from the network; Step 32: Cancel the corresponding node's eligibility for this election and convert it to a regular node; proceed to step 321. Step 321: Each ordinary node generates a new transaction and broadcasts it. Step 322, verify the block; Step 323, synchronize blocks; Step 324: Determine if the consensus period has ended. If yes, ordinary nodes return to step 1 to proceed to the next election; otherwise, return to step 321.

[0053] Step 4: Each node that has reached a consensus sorts all the obtained j values ​​from largest to smallest. When the j values ​​are the same, they are sorted according to the size of the corresponding e values. Finally, the first m nodes are selected as the nodes to be produced by blocks, and the results of the nodes to be produced by blocks are broadcast.

[0054] Step 5: Determine whether the results of the pending block-producing nodes have reached a 2 / 3 consensus. If not, proceed to step 32. If a 2 / 3 consensus has been reached, the local node determines whether it is among the top m nodes. If not, proceed to step 32. If it is among the top m nodes, proceed to step 6.

[0055] Step 6: The node waiting to produce a block pays the deposit.

[0056] Step 7: The nodes that have paid the deposit become block-producing nodes and produce blocks.

[0057] Step 8: Determine whether the node to be produced a block has produced a block within the specified time period. If it has, proceed to Step 9; otherwise, proceed to Step 10.

[0058] Step 9: First, collect and verify the transactions, then package them into blocks and broadcast them. Then, determine whether the block produced by the block-producing node is a valid block. If it is a valid block, it will be added to the chain; otherwise, invalid blocks will be counted.

[0059] Step 10: Determine whether the node to be produced has completed producing a block. If it has not completed producing a block, wait for the block to be produced and verify the block (each producing node has a producing window. When it is not in the specified time period, verify the blocks produced by other producing nodes); if the block has been produced, proceed to step 101. Step 101: Determine if the consensus period has ended. If not, wait for a block to be produced and verify the block (each block-producing node has a block production window; when it is not in the specified time period, verify the blocks produced by other block-producing nodes); if yes, proceed to step 101. Step 101: Determine whether the number of invalid blocks produced by each block-producing node is greater than 3. If so, cancel the reward of the corresponding block-producing node, confiscate its deposit and record or remove it from the network. If not, issue a fixed reward and a floating reward to the corresponding block-producing node. Step 11: After receiving the fixed reward and the floating reward, the block-producing node returns to Step 1 to participate in the next round of elections.

[0060] Example 2 Based on the same inventive concept, this application also provides a DPOS consensus system based on the improved SM9 algorithm. The solution provided by this DPOS consensus system based on the improved SM9 algorithm is similar to the solution described in the method of Embodiment 1. Therefore, the specific limitations of one or more embodiments of the DPOS consensus system based on the improved SM9 algorithm provided below can be found in the limitations of the method in Embodiment 1, and will not be repeated here.

[0061] In one exemplary embodiment, a DPOS consensus system based on an improved SM9 algorithm is provided, comprising: Nodes are located within the network; The lottery election module is set up locally on each node to execute the VRF generation algorithm, generate random numbers R and proofs P; then calculate e=R / N based on the generated random numbers R, where e∈[0,1) is the cumulative probability value and N is the order of the subgroup being a prime number; It is also used to calculate and obtain the satisfying inequalities for each node. The value of j is an integer used to mark the endpoints of the cumulative probability interval, which serves as a numerical value to select the block-producing node; the election probability p = m / n, where n is the total number of nodes in the network and m is the number of block-producing nodes to be generated; And used to broadcast the j value, the random number R, and the proof P to other nodes; The first judgment and processing module is set up locally on each node to execute the VRF verification algorithm to verify the random number R and proof P received from other nodes. The second judgment and processing module is used to determine whether all nodes have reached a 2 / 3 consensus on the verification of the received random number R and proof P, and when it is determined that a 2 / 3 consensus has not been reached, it outputs the result that a minority of nodes have engaged in misconduct. And when it is determined that a 2 / 3 consensus has been reached, each node that has reached the consensus sorts all the j values ​​obtained from largest to smallest. When the j values ​​are the same, they are sorted according to the size of the corresponding e values. Finally, the first m nodes are selected as the nodes to be produced by blocks, and the results of the nodes to be produced by blocks are broadcast. The third judgment and processing module is used to determine whether the results of the pending block-producing nodes have reached a 2 / 3 consensus, and when it is determined that a 2 / 3 consensus has not been reached, it outputs the result that a minority of nodes have engaged in misconduct. The fourth judgment and processing module is set up locally on each node. When the third judgment and processing module determines that a 2 / 3 consensus has been reached, it determines whether the local node itself is among the top m nodes. If it is not among the top m nodes, the local node becomes a normal node; otherwise, the local node becomes a block-producing node. The block production module is set up locally on each node. When a node is about to produce a block, it first collects and verifies the transactions, packages them into a block, and then broadcasts the generated block. The fifth judgment and processing module is used to determine whether the block produced by the block producing node is a valid block, and when the block produced by the block producing node is determined to be a valid block, it notifies the block producing node to perform the on-chain operation and enter the next round of election. The sixth judgment and processing module is used to mark a node with misconduct once, and at the same time determine whether the number of times the marked node has been marked is greater than or equal to 3. If it is greater than or equal to 3 times, the corresponding node is removed from the network; and if it is less than 3 times, the corresponding node is disqualified from this election and the corresponding node is converted into an ordinary node. The regular block production module is set up locally on each node. It is used to generate new transactions and broadcast the generated new transactions after the corresponding node is converted into a regular node, as well as to verify blocks and synchronize blocks. The seventh judgment and processing module is used to notify all ordinary nodes to enter the next round of election after determining that all ordinary nodes have completed consensus.

[0062] Example 3 Each module in the above system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or they can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0063] In an exemplary embodiment, a computer device is provided, which may be a terminal. The computer device further includes a processor, memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are connected to the system bus via the input / output interface. The processor of the computer device provides computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The input / output interface of the computer device is used for exchanging information between the processor and external devices. The communication interface of the computer device is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements the steps of a DPOS consensus method based on an improved SM9 algorithm. The display unit of the computer device is used to form a visually visible image and may be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0064] Those skilled in the art will understand that the structure of the computer device described above is only a partial structure related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. A specific computer device may include more or fewer components, or combine certain components, or have different component arrangements.

[0065] In one exemplary embodiment, a computer-readable storage medium is also provided, on which a computer program is stored, which, when executed by a processor, implements the steps of a DPOS consensus method based on an improved SM9 algorithm.

[0066] In one exemplary embodiment, a computer program product is also provided, including a computer program / instructions, characterized in that, when executed by a processor, the computer program / instructions implement the steps of a DPOS consensus method based on an improved SM9 algorithm.

[0067] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0068] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0069] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A DPOS consensus method based on an improved SM9 algorithm, characterized in that, Includes the following steps: Each node in the network executes the VRF generation algorithm locally to generate a random number R and a proof P; then, based on the generated random number R, it calculates e = R / N, where e ∈ [0, 1) is the cumulative probability value, and N is the order of the subgroup, which is a prime number; Each node calculates and obtains its own inequality. The value of j; where j is an integer used to mark the endpoints of the cumulative probability interval, and is used as a numerical value to select the block-producing node; the election probability p = m / n, where n is the total number of nodes in the network, and m is the number of block-producing nodes to be generated; Broadcast the value of j, the random number R, and the proof P to other nodes; Each node executes the VRF verification algorithm to verify the random number R and proof P received from other nodes; Determine whether all nodes have reached a 2 / 3 consensus on the verification of the received random number R and the proof P. If a 2 / 3 consensus is not reached, i.e. the verification fails, then it is determined that a minority of nodes have engaged in misconduct, and the nodes with misconduct are marked once. If a 2 / 3 consensus is reached, each node that has reached a consensus sorts all the obtained j values ​​from largest to smallest. When the j values ​​are the same, they are sorted according to the size of the corresponding e values. Finally, the first m nodes are selected as the nodes to be produced, and the results of the nodes to be produced are broadcast. Determine whether the results of the pending block-producing nodes have reached a 2 / 3 consensus. If not, determine that a minority of nodes have engaged in misconduct. If a 2 / 3 consensus is reached, the local node determines whether it is among the top m nodes. If it is not among the first m nodes, then convert the local node to a normal node; If it is within the first m nodes, then the local node is the block-producing node and a block is produced. When a block-producing node produces a block, it first collects and verifies the transactions, packages them into a block, and then broadcasts the generated block. When a block-producing node produces a valid block, it performs the on-chain operation and enters the next round of election; Nodes exhibiting misconduct are marked once, and it is determined whether the number of times a marked node has been marked is greater than or equal to 3. If it is greater than or equal to 3, the corresponding node is removed from the network. If the number of violations is less than 3, the corresponding node will be disqualified from this election and will be converted into a regular node. Each ordinary node generates a new transaction and broadcasts it, then verifies and synchronizes the block. Once all ordinary nodes have reached a consensus, they enter the next round of elections.

2. The DPOS consensus method based on the improved SM9 algorithm according to claim 1, characterized in that, The VRF algorithm generates random numbers R and proves P as follows: (1) System parameter generation; The Key Generation Center (KGC) generates a random number S. S ∈[1,N-1], serving as the master private key; The Key Generation Center (KGC) selects and publishes a private key generation function identifier (hid) represented by a single byte. Assume user A's identity is identified by ID. A The key generation center KGC first in the finite field F N The above calculation t1=H1(ID) A ||hid,N)+S S ; If t1=0, then regenerate the master private key and simultaneously calculate element P in group G1. S =S S • P1 is used as the system's master public key and made public, thus obtaining the master key pair (S S ,P S Based on the regenerated master private key, the user private key S is recalculated. A ; If t1≠0, then calculate t2=S S ∙t1 -1 Then calculate the user's private key S A =t2∙P2, and the user's public key Q A =H1(ID A ||hid,N)∙P1+P S ; Where t1 and t2 are intermediate data; H1 and H2 are cryptographic functions; P1 and P2 are the generators of groups G1 and G2, respectively, where groups G1 and G2 are the elliptic curve groups E(F) and G2, respectively. q ) and E(F q 2 G1 is a subgroup of two additive cyclic groups on G2, and there exists a homomorphism f from group G2 to group G1 such that f(P2) = P1. Calculate the multiplicative cyclic group G T The element g=e(P) S ,P2);G T It is composed of the finite field F q¹² The subgroup of the multiplicative cyclic group consisting of all non-zero elements in the set G1, G2, and G2 is a prime number N, where e is a bilinear pair satisfying G1×G2→G2. T Mapping; Let message M be the header information of the last block in the current blockchain, including version number, parent block hash value, Merkle root, timestamp, user ID, random number R, proof P, round, j value and position; t is the round in which the current block was generated; (2) A VRF generation algorithm for generating random numbers R and proving P; The local node executes the VRF algorithm, inputting S. A After message M, output a pseudo-random number r∈[1,N-1]; Calculate the multiplicative cyclic group G T The element w=g r And convert the data type of w to a bit string; Calculate the integer h = H2(M||W,N); Calculate the integer L = (rh) mod N, and determine whether L is 0. If L = 0, then the node cannot generate a random number R and prove P. Calculate the multiplicative cyclic group G T The element S = [L]·S A And convert the data types of h and S into bit strings; Calculate the integer R = H2(h||S,N) and use it as the random number R; The calculation yields the proof that P=(h,S).

3. The DPOS consensus method based on the improved SM9 algorithm according to claim 2, characterized in that, The verification process of the VRF verification algorithm is as follows: Convert the data type of h' to an integer and verify whether h'∈[1,N-1] is true. If it is not true, the verification fails. Convert the data type of S' to a point on the elliptic curve, and check whether S'∈G2 is true. If not, the verification fails. Calculate the multiplicative cyclic group G T The element g=e(P) S ,P2); Calculate the multiplicative cyclic group G T elements in ; Calculate the multiplicative cyclic group G T The element u=e(Q) A ,S'); Calculate the multiplicative cyclic group G T The element w' = u∙t is set in the array, and the data type of w' is converted to a bit string; Calculate the integer h2=H2(M'||w',N), and check whether h2=h' is true. If it is true, then P is valid and the verification is successful; otherwise, the verification fails. Calculate the random number R'=H2(h'||S',N), and determine whether R=R' is true. If it is true, the random number R has not been tampered with during transmission, and the verification is successful; otherwise, the verification fails.

4. The DPOS consensus method based on the improved SM9 algorithm according to any one of claims 1-3, characterized in that, Set up a reward and punishment mechanism to prevent block-producing nodes from acting maliciously: When more than 2 / 3 of the pending block-producing nodes reach a consensus, the pending block-producing nodes pay a deposit, and the pending block-producing nodes that have paid the deposit become block-producing nodes and produce blocks. Determine whether the node to be produced a block has produced a block within the specified time period; If a block is generated within a specified time period, the transactions are first collected and verified, then packaged into a block and broadcast, and then it is determined whether the block generated by the block-producing node is a valid block. If it is a valid block, then add it to the blockchain; If it is not a valid block, then count it as an invalid block; If a block is not produced within the specified time period, check whether all nodes waiting to produce blocks have completed producing blocks. If they have not completed producing blocks, wait for a block to be produced and verify the blocks produced by other producing nodes. If block production has been completed, determine whether the consensus period has ended; If it has not ended, then wait for a block to be produced and verify the blocks produced by other block-producing nodes; If the process has ended, check if the number of invalid blocks produced by each block-producing node is greater than 3. If the value is greater than or equal to 3, the corresponding block-producing node's reward will be cancelled, its deposit will be confiscated, and it will be either registered or removed from the network. If the value is less than 3, a fixed reward and a floating reward are issued to the corresponding block-producing node. After receiving the fixed reward and the floating reward, the block-producing node returns to participate in the next round of election.

5. The DPOS consensus method based on the improved SM9 algorithm according to claim 4, characterized in that: Let the fixed reward be C. g =S×1 token, where S is the total number of valid blocks generated in one consensus cycle; 1 token is one token unit; Let the floating reward be C. f =C g ×α, where α is the floating factor, α=(S-f)÷B×k; where f is the total number of invalid blocks generated in a consensus cycle; B is the total number of blocks produced in a consensus cycle as defined by the system; k is a constant, which is determined according to the actual situation; The fixed reward C received by block-producing node i is then... gi =(S i -f i )×1 token; The floating reward C received by block-producing node i fi =C f ×α i ; The deposit D that block-producing node i needs to pay i =C g / 2; Among them, S i f is the number of valid blocks packaged by node i within a consensus period. i α is the number of invalid blocks packaged by node i within a consensus period. i =(S i -f i )÷B×k is the floating factor of node i.

6. A DPOS consensus system based on an improved SM9 algorithm, characterized in that, include: Nodes are located within the network; The lottery election module, set up locally on each node, is used to execute the VRF generation algorithm to generate random numbers R and proofs P; Then, calculate e = R / N based on the generated random number R, where e ∈ [0, 1) is the cumulative probability value, and N is the order of the subgroup being a prime number; It is also used to calculate and obtain the satisfying inequalities for each node. The value of j is an integer used to mark the endpoints of the cumulative probability interval, which serves as a numerical value to select the block-producing node; the election probability p = m / n, where n is the total number of nodes in the network and m is the number of block-producing nodes to be generated; And used to broadcast the j value, the random number R, and the proof P to other nodes; The first judgment and processing module is set up locally on each node to execute the VRF verification algorithm to verify the random number R and proof P received from other nodes. The second judgment and processing module is used to determine whether all nodes have reached a 2 / 3 consensus on the verification of the received random number R and proof P, and when it is determined that a 2 / 3 consensus has not been reached, it outputs the result that a minority of nodes have engaged in misconduct. And when it is determined that a 2 / 3 consensus has been reached, each node that has reached the consensus sorts all the j values ​​obtained from largest to smallest. When the j values ​​are the same, they are sorted according to the size of the corresponding e values. Finally, the first m nodes are selected as the nodes to be produced by blocks, and the results of the nodes to be produced by blocks are broadcast. The third judgment and processing module is used to determine whether the results of the pending block-producing nodes have reached a 2 / 3 consensus, and when it is determined that a 2 / 3 consensus has not been reached, it outputs the result that a minority of nodes have engaged in misconduct. The fourth judgment and processing module is set up locally on each node. When the third judgment and processing module determines that a 2 / 3 consensus has been reached, it determines whether the local node itself is among the top m nodes. If it is not among the top m nodes, the local node becomes a normal node; otherwise, the local node becomes a block-producing node. The block production module is set up locally on each node. When a node is about to produce a block, it first collects and verifies the transactions, packages them into a block, and then broadcasts the generated block. The fifth judgment and processing module is used to determine whether the block produced by the block producing node is a valid block, and when the block produced by the block producing node is determined to be a valid block, it notifies the block producing node to perform the on-chain operation and enter the next round of election. The sixth judgment and processing module is used to mark a node with misconduct once, and at the same time determine whether the number of times the marked node has been marked is greater than or equal to 3. If it is greater than or equal to 3 times, the corresponding node is removed from the network; and if it is less than 3 times, the corresponding node is disqualified from this election and the corresponding node is converted into an ordinary node. The regular block production module is set up locally on each node. It is used to generate new transactions and broadcast the generated new transactions after the corresponding node is converted into a regular node, as well as to verify blocks and synchronize blocks. The seventh judgment and processing module is used to notify all ordinary nodes to enter the next round of election after determining that all ordinary nodes have completed consensus.

7. A computer device, characterized in that, include: One or more processors; Memory, used to store one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors perform the steps of the DPOS consensus method based on the improved SM9 algorithm as described in any one of claims 1-5.

8. A computer-readable storage medium storing a computer program, characterized in that, When executed by the processor, the program implements the steps of the DPOS consensus method based on the improved SM9 algorithm as described in any one of claims 1-5.

9. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the steps of the DPOS consensus method based on the improved SM9 algorithm as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Block chain address generation method based on improved SM9 algorithm

    CN118694524A