Decentralized trust root generation method suitable for block chain oracle machine
By introducing physically unclonable functions and trusted platform modules into the blockchain oracle system, generating a unique root key and performing decentralized authentication, the security and decentralization issues of existing oracle systems are solved, achieving efficient and reliable trust management and incentive mechanisms, and improving the system's security and stability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- XIDIAN UNIV
- Filing Date
- 2025-12-22
- Publication Date
- 2026-04-24
AI Technical Summary
Existing blockchain oracle systems suffer from insufficient security, inadequate decentralization, and weak node trust mechanisms, particularly in terms of root key management, trust sustainability, communication efficiency, IRoT node selection, and incentive mechanisms.
A unique root key is generated using a physically unclonable function. The root key is then used in conjunction with a trusted platform module to generate and verify authentication reports. The root key is stored on the blockchain network via smart contracts to establish a decentralized root of trust. A periodic authentication and trust scoring mechanism is employed to select a trusted oracle committee and allocate incentives based on the trust scores.
It improves the security, scalability, and stability of the blockchain oracle system, ensures the immutability and verifiability of node identities, enables continuous monitoring and fair selection of node states, enhances the system's adaptive security and anti-attack capabilities, and promotes the long-term healthy development of the system.
Smart Images

Figure CN121923786A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of blockchain technology, and in particular to a decentralized trust root generation method suitable for blockchain oracles. Background Technology
[0002] Blockchain oracles are crucial components connecting blockchain smart contracts with the external world. Because the blockchain itself is a deterministic system, it cannot directly access off-chain data. Blockchain oracles play a vital role in enabling smart contracts to interact with off-chain data, bridging the gap between on-chain smart contracts and external data. Ideally, oracles should provide a secure mechanism to acquire, verify, and transmit real-world data, such as stock prices, weather information, and market conditions, to trigger the execution of smart contracts. Therefore, the security and trustworthiness of oracles are paramount, directly impacting the correct execution of smart contracts, preventing malicious tampering or forgery of data, and thus ensuring the security of the entire blockchain system.
[0003] Existing blockchain oracles can be divided into two categories: reputation-based oracles and Trusted Execution Environment (TEE)-based oracles. Reputation-based oracles establish trust by evaluating the reputation of oracle nodes, with trust assessment relying on collective feedback and historical performance. Specifically, reputation oracles aggregate node scores or ratings to assess the consistency, accuracy, and reliability of their historical performance, thereby selecting trustworthy data providers. Reputation-based oracles are distributed, with trust assessments conducted collaboratively by multiple nodes in the blockchain network, reducing reliance on a single authority and thus exhibiting good scalability. However, despite these advantages, reputation-based oracles remain vulnerable to security threats such as Sybil attacks and collusion attacks. These attacks can compromise the security of reputation oracles, especially when malicious actors manipulate reputation scores, potentially undermining the credibility of the entire oracle system.
[0004] To address these issues, blockchain oracles based on Trusted Execution Environments (TEEs) have emerged. TEEs ensure data integrity and authenticity by utilizing secure hardware. Compared to reputation-based oracles, TEE oracles offer stronger security, effectively preventing external interference and ensuring data reliability. However, while TEE oracles effectively protect against threats such as reputation manipulation, Sybil attacks, and collusion attacks, they still rely on a single node's Root of Trust (RoT), introducing certain security risks. The RoT, as the foundation of TEE's secure operation, is responsible for initializing secure zones, protecting cryptographic key generation and storage, and generating trusted proofs. As a hardware-based trust anchor, the RoT ensures the integrity and authenticity of data within the TEE. However, the reliance on a centralized RoT introduces a single point of failure; if the RoT is compromised, the security of the entire oracle is compromised. Furthermore, centralized RoTs face scalability challenges in large-scale applications because the trust model relies on a single entity, limiting its adaptability in large-scale systems.
[0005] With the continuous development of blockchain technology, decentralized root trust (DRoT) schemes have gradually attracted widespread attention. However, current research on DRoT remains relatively limited, especially regarding DRoT schemes supporting blockchain oracles, where systematic research is still lacking. Existing decentralized remote authentication (DRA) schemes primarily rely on cryptographic proofs, using multiple independent verification nodes to collaboratively verify the integrity of system software and hardware configurations, thereby reducing the trust risks associated with a single centralized authenticator. However, existing DRA schemes still have significant shortcomings in several key aspects, including root key management, trust sustainability, communication efficiency, IRoT node selection, and incentive mechanisms.
[0006] Security risks of pre-configured root keys: Existing DRA schemes generally rely on root keys pre-configured by device manufacturers. However, these keys may be at risk of leakage during device manufacturing or distribution, and their static nature makes them vulnerable to key extraction or attacks. Once the key is compromised, the security of the entire authentication system will be threatened. Therefore, ensuring the security of the root key and avoiding the security risks caused by key pre-configuration is one of the key issues that this invention aims to address.
[0007] The unsustainability of authentication trust: Existing DRA schemes generally employ an interactive challenge-response authentication model, which establishes trust only after authentication is completed, leaving a "trust vacuum" between the two authentications. Attackers can exploit this vulnerability to launch dynamic attacks after a device passes authentication and restore the device state before the next authentication, thus evading detection. This model is particularly vulnerable to mobile attacks, allowing malicious nodes to tamper with data or perform illegal operations undetected. Therefore, this invention addresses the issue of the sustainability of authentication trust to prevent attackers from exploiting the trust vacuum for security breaches.
[0008] Excessive communication overhead: Existing DRA schemes typically require multiple rounds of interactive communication during the authentication process, resulting in high communication overhead. This interactive authentication mechanism not only increases authentication latency but also affects system scalability, especially in large-scale blockchain oracle networks, where frequent data transmissions reduce overall system efficiency. Therefore, this invention aims to optimize the authentication mechanism and reduce unnecessary communication overhead to improve system performance and scalability.
[0009] Fairness and Security of IRoT Node Selection: While some DRA (Decentralized Arbitration) schemes primarily select IRoT nodes through reputation systems or token mechanisms, these methods are vulnerable to collusion attacks and Sybil attacks. For example, attackers can manipulate multiple fake nodes or influence the node selection process through collusion, thereby undermining the fairness of the system and even controlling the authenticity of oracle data. This security vulnerability could lead to the continuous selection of malicious nodes, affecting the overall credibility of the system. Therefore, this invention aims to establish a fairer and more secure IRoT node selection mechanism to ensure the impartiality and attack resistance of the decentralized authentication process.
[0010] Lack of Participation Incentive Mechanism: The multi-DRA scheme lacks an effective incentive mechanism, resulting in IRoT nodes having little motivation to actively participate in the authentication process. Since the stable operation of a blockchain oracle relies on trusted nodes continuously providing services, the absence of a reasonable economic incentive mechanism may lead to trusted nodes reducing participation due to cost or resource consumption issues, thereby affecting the overall availability and security of the system. Therefore, this invention requires designing a reasonable participation incentive mechanism to encourage more IRoT nodes to actively join the oracle network, improving the stability and security of the system. Summary of the Invention
[0011] This invention provides a decentralized trust root generation method suitable for blockchain oracles, which solves the problems of insufficient security, decentralization and weak node trust mechanism in traditional blockchain oracle systems in the prior art, and realizes the security, scalability and stability of blockchain oracle systems.
[0012] This invention provides a decentralized root of trust generation method suitable for blockchain oracles, comprising: During the IRoT node root key generation phase, each IRoT node generates a corresponding root key using a physically unclonable function, and then generates an AIK credential based on the authentication identity key pair derived from the root key. During the IRoT node registration phase, the trusted platform module is used to generate a first authentication report based on the authentication identity key pair, and the first authentication report is submitted to the blockchain network for verification and registration, so as to store the identity information of the IRoT node on the blockchain network. During the IRoT node authentication phase, each IRoT node generates a second authentication report based on a preset period or event-driven approach using the trusted platform module, and submits the second authentication report to the blockchain network to continuously verify and quantify the runtime trusted status of registered IRoT nodes, thereby obtaining a pool of authenticated nodes. During the IRoT node selection phase, in response to data requests to access the blockchain, a group of IRoT nodes are selected from the certified node pool to form a trusted oracle committee, a trusted task allocation record is generated, and one of the IRoT nodes is designated as the leader node. During the oracle service execution phase, the trusted oracle committee processes off-chain data requests, and each node generates a signed response, which is then aggregated by the leader node and submitted to the consumer blockchain. During the incentive mechanism execution phase, oracle service fees are weighted and allocated based on the trust scores of each IRoT node.
[0013] In one possible implementation, each IRoT node generates its own root key using a physically unclonable function, including: After the IRoT node is powered on, it inputs a predefined challenge value into the PUF circuit; Each node generates a PUF response based on the predefined challenge value and derives an endorsement private key through a hash function. ; Each node uses elliptic curve cryptography, based on the endorsed private key. Calculate the endorsement public key and the endorsement public key Each node is bound to its own identity to obtain a cryptographic identity identifier; The endorsement private key and the endorsement public key As the complete root key.
[0014] In one possible implementation, submitting the first authentication report to the blockchain network for verification and registration includes: The first authentication report is signed using the private key in the authentication identity key pair to obtain a first signed authentication report; The IRoT node submits a registration request to the DRoT client; wherein the registration request includes: a first signature authentication report and the IRoT node's configuration information. ; The DRoT client receives the registration request, invokes the oracle registration contract pre-deployed on the blockchain network to verify the registration request, and calculates the unique identifier of the IRoT node. ; The DRoT client will use the unique identifier of the IRoT node. Store it.
[0015] In one possible implementation, each IRoT node generates a second authentication report using a trusted platform module based on a preset period or event-driven mechanism, and submits the second authentication report to the blockchain network to continuously verify and quantify the runtime trusted state of the registered IRoT nodes, thereby obtaining a pool of authenticated nodes, including: IRoT nodes obtain current runtime measurements. And use verifiable functions to generate unpredictable random values for this authentication. and proof ; The IRoT node utilizes the trusted platform module to determine the random value based on the private key in the authentication identity key pair. and the proof Calculations are performed to obtain the second certification report; The blockchain network verifies the authenticity of the digital signature in the second authentication report and uses the proof. Verify the random value The correctness of the measurement is verified to obtain the result; if the verification result is passed, the measurement value in the second certification report is used. and benchmark reference measurement value A comparison is performed to obtain the comparison result; if the comparison result is equal, the time decay function is called to calculate the trust score corresponding to the IRoT node. If the trust score Higher than the set threshold If so, the IRoT node will be added to the pool of certified nodes.
[0016] In one possible implementation, the reference measurement value The methods of obtaining it include: During the IRoT node registration phase, initial runtime measurements are extracted from the verified first authentication report and used as the baseline reference measurements. Stored in the blockchain network.
[0017] In one possible implementation, the step of selecting a group of IRoT nodes from the certified node pool to form a trusted oracle committee includes: Receive a data request, the data request including: the number of IRoT nodes to be selected. ; Using smart contracts deployed on the blockchain network, all available IRoT nodes and their corresponding trust scores are obtained from the certified node pool. And use verifiable random functions to generate random numbers. ; The smart contract is based on the trust score. With the random number Calculate the priority weight of each IRoT node and the total priority value. ; Through random index Select nodes cyclically from the pool of certified nodes. IRoT nodes, and repeat this selection process until all nodes are selected to obtain a task node group, and designate the group of nodes as the Trusted Oracle Committee; The oracle selection contract stores the list of node identifiers of the trusted oracle committee on the blockchain as the trusted task allocation record.
[0018] In one possible implementation, the oracle service phase includes: Each IRoT node in the Trusted Oracle Committee uses its authentication key to sign off-chain data responses; The leader node collects all signature responses and generates an aggregate signature using the aggregate signature algorithm. ; The aggregate signature The data response is submitted to the consumer's blockchain for verification.
[0019] In one possible implementation, the incentive mechanism execution phase includes: Total cost of oracle services Rewards are divided into leadership node rewards according to a preset ratio. And participation node rewards ; Based on the trust scores of each participating node By weight Distribute the rewards to the participating nodes, and record and execute the reward distribution results on the blockchain.
[0020] In one possible implementation, the physically unclonable function is an endogenous key generation module based on hardware characteristics, and the trusted platform module is a security coprocessor that performs encryption operations and generates authentication reports.
[0021] In one possible implementation, the blockchain network is deployed with smart contracts for node registration, authentication report verification, and node selection to execute decentralized logic at each stage.
[0022] One or more technical solutions provided in this invention have at least the following technical effects or advantages: This invention, during the IRoT node root key generation phase, involves each IRoT node generating a corresponding root key using a physically unclonable function. Based on this root key, an authentication key pair is derived, and then an AIK credential is generated. This step, leveraging the hardware-level security features of the physically unclonable function, ensures the uniqueness and tamper-proof nature of each node's root key, enhancing the reliability and attack resistance of the root of trust from the source, thus laying a solid identity foundation for the decentralized system. During the IRoT node registration phase, a trusted platform module generates a first authentication report based on the authentication key pair and submits it to the blockchain network for verification and registration, thus storing the IRoT node's identity information on the blockchain network. This step combines the hardware security protection of the trusted platform module with the immutability of the blockchain, achieving verifiable and transparent registration of node identities, effectively preventing identity forgery or impersonation, and enhancing the initial trust level of the entire system. During the IRoT node authentication phase, each IRoT node generates a second authentication report based on a preset period or event-driven mechanism using the trusted platform module. This report is then submitted to the blockchain network to continuously verify and quantify the runtime trusted state of registered IRoT nodes, resulting in a pool of authenticated nodes. This step, through a periodic or event-driven dynamic authentication mechanism, enables real-time monitoring and quantitative evaluation of the node's runtime state, ensuring continuous verification of the node's trusted state and improving the system's adaptive security and resistance to dynamic attacks. In the IRoT node selection phase, in response to data requests to access the blockchain, a group of IRoT nodes is selected from the authenticated node pool to form a trusted oracle committee. A trusted task allocation record is generated, and one IRoT node is designated as the leader node. This step selects nodes from the authenticated node pool based on trusted scores, reducing the risk of malicious node involvement. Simultaneously, the leader node mechanism optimizes task coordination efficiency, ensuring the reliability of the oracle committee and the fairness of task allocation. During the oracle service execution phase, the Trusted Oracle Committee processes off-chain data requests. Each node generates a signed response, which is then aggregated by the leader node and submitted to the consumer blockchain. This step, through multi-node collaborative processing and signature aggregation technology, ensures the integrity, consistency, and resistance to single points of failure in the data response, improving the efficiency, accuracy, and tamper resistance of the oracle service. In the incentive mechanism execution phase, oracle service fees are weighted and allocated based on the trust scores of each IRoT node. This step directly links trust scores to economic incentives, encouraging nodes to proactively maintain a high level of trust and penalizing untrustworthy behavior, thereby promoting the long-term health, stability, and sustainable development of the decentralized trust ecosystem. Attached Figure Description
[0023] Figure 1 A flowchart illustrating the steps of a decentralized trust root generation method for blockchain oracles provided in this embodiment of the invention; Figure 2 A flowchart of the DRoT construction process provided in this embodiment of the invention; Figure 3 A construction flowchart provided for embodiments of the present invention; Figure 4 The DRoT-driven oracle workflow provided in this embodiment of the invention. Detailed Implementation
[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0025] This invention, EnduraTrust, combines two interconnected networks: an off-chain oracle network and the EnduraTrust blockchain. It provides consumer blockchains (CBs) with an oracle service based on Decentralized Root Trust (DRoT), enabling them to reliably access off-chain data. EnduraTrust primarily involves three core entities: Oracle nodes are nodes with an Individual Root of Trust (IRoT). Each node consists of a Physically Unclonable Function (PUF) and a Trusted Platform Module (TPM). In this invention, oracle nodes are also referred to as IRoT nodes.
[0026] PUF is responsible for generating a unique, non-cloneable root key for each device, which fundamentally improves key security and avoids the security risks associated with traditional pre-configured keys.
[0027] TPM is responsible for performing encryption operations and remote authentication to ensure the trusted status of nodes.
[0028] Through remote authentication, IRoT nodes can generate Attestation Reports (ARs), providing cryptographic evidence to prove their trustworthy status, and the decentralized authentication is completed by the EnduraTrust blockchain.
[0029] All oracle nodes form a decentralized peer-to-peer (P2P) network, also known as the oracle network, which connects consumer blockchains (CBs) with off-chain data sources to provide data interaction services.
[0030] DRoT Clients run on the EnduraTrust blockchain and are responsible for handling oracle-related operation requests, including Oracle Registration, Oracle Attestation, and Oracle Selection.
[0031] Validator (Miner) nodes are responsible for maintaining the EnduraTrust blockchain and mainly perform the following tasks: verifying transactions on the blockchain, generating new blocks, executing smart contracts, and updating the blockchain state.
[0032] In the EnduraTrust architecture, the Decentralized Root Trust (DRoT) consists of IRoT modules and their host devices that have been decentralized certified by the EnduraTrust blockchain. Overall, it possesses a verifiable level of trust, thus forming a secure and reliable oracle network. Furthermore, consumer blockchains (CBs), which can be either permissioned or permissionless, rely on EnduraTrust to obtain off-chain data. CB clients act as a bridge throughout the interaction process, retrieving data from off-chain data sources through EnduraTrust and transmitting the data to the consumer blockchain to support smart contract execution and various blockchain applications. Throughout this process, EnduraTrust ensures the integrity and trustworthiness of the data.
[0033] To manage interactions between different entities and execute system policies, EnduraTrust has deployed the following three key types of smart contracts on the blockchain: Oracle Registration Contract: This contract is responsible for managing the registration of oracles and securely recording the configuration information of each node on the blockchain to ensure that all nodes joining the network meet the security requirements.
[0034] Oracle Attestation Contract: This contract is used to verify the Attestation Reports (ARs) submitted by oracles, calculate their Trust Score, and maintain a pool of certified oracle nodes to ensure that only trusted nodes can provide oracle services.
[0035] Oracle Selection Contract: This contract selects suitable oracle nodes from the pool of certified nodes based on the trust score of the oracles to perform off-chain data acquisition tasks, ensuring that the selected nodes are highly trustworthy and fair.
[0036] Table 2: Explanation of Relevant Parameters
[0037] The present invention, EnduraTrust, constructs a decentralized root trust (DRoT) through a series of strictly defined steps, ensuring the security, scalability, and decentralization of the system. Figure 2 The DRoT construction process is demonstrated, which mainly includes the following four stages: root key generation, IRoT node registration, IRoT node authentication, and IRoT node selection.
[0038] This invention provides a decentralized root of trust generation method suitable for blockchain oracles, see [link to relevant documentation]. Figure 1 The process includes the following steps S101 to S106.
[0039] S101, In the IRoT node root key generation stage, each IRoT node generates the corresponding root key using the physical non-cloning function, and generates the AIK credential based on the authentication identity key pair AIK derived from the root key. Here, the physically unclonable function is an endogenous key generation module based on hardware characteristics, and the trusted platform module is a security coprocessor that performs encryption operations and generates authentication reports.
[0040] Specifically, in step S101, each IRoT node generates its own root key using a physically unclonable function, including the following steps S1011 to S1014.
[0041] S1011, after the IRoT node is powered on, a predefined challenge value is input to the PUF circuit; In S1012, each node generates a PUF response based on a predefined challenge value and derives the endorsement private key through a hash function. ; S1013, each node uses elliptic curve cryptography, based on the endorsed private key. Calculate the endorsement public key and endorse the public key Each node is bound to its own identity to obtain a cryptographic identity identifier; S1014, endorse the private key and endorsement public key As the complete root key.
[0042] For example, during the root key generation phase, each IRoT node independently generates its own root key using a Physically Unclonable Function (PUF). This method ensures that each IRoT node can generate a unique and unclonable intrinsic cryptographic key, providing a solid foundation of trust for subsequent security operations. Compared to traditional methods that rely on pre-configured keys from device manufacturers, this method effectively avoids security risks such as key leakage, forgery, and key reuse.
[0043] In this embodiment, each IRoT node generates a device-unique endorsement key EK using the Physically Unclonable Function (PUF), and further derives an authentication identity key AIK. This process includes the following key steps: PUF Response Generation EK: IRoT nodes generate a PUF response based on a predefined challenge value and derive the endorsement private key using a hash function. .
[0044] Elliptic Curve Cryptography (ECC) for Generating Public Keys: IRoT Nodes Use ECC Algorithms to Calculate Endorsing Public Keys It is bound to its own identity to achieve a unique encrypted identifier for the device.
[0045] AIK generation based on EK: IRoT nodes use EK to generate AIK and apply for AIK certification from the Trusted Platform Module (TPM) to ensure the authenticity and integrity of AIK.
[0046] PUF Dynamic Key Recovery: The private EK is recalculated via PUF only when needed, eliminating the need for long-term storage and thus reducing the risk of key leakage.
[0047] This embodiment ensures that the device identity of IRoT nodes is unique, secure, and tamper-proof, avoiding the security risks of traditional device key pre-configuration.
[0048] This step significantly reduces the security risks of traditional static key systems by utilizing Physically Unclonable Functions (PUFs) to generate secure and intrinsic root keys for each IRoT node. PUFs leverage the physical characteristics of hardware components to generate unique and unclonable keys, avoiding the risk of key leakage or cracking, and ensuring system security and reliability at the hardware level.
[0049] S102, During the IRoT node registration phase, the trusted platform module is used to generate the first authentication report based on the authentication identity key pair, and the first authentication report is submitted to the blockchain network for verification and registration, so as to store the identity information of the IRoT node on the blockchain network. Here, the blockchain network is equipped with smart contracts for node registration, authentication report verification, and node selection to execute decentralized logic at each stage.
[0050] Specifically, in step S102, the first authentication report is submitted to the blockchain network for verification and registration, including the following steps S1021 to S1024.
[0051] S1021, Sign the first authentication report according to the private key in the authentication identity key pair to obtain the first signed authentication report; S1022, the IRoT node submits a registration request to the DRoT client; the registration request includes: a first signature authentication report and the IRoT node's configuration information. ; S1023, the DRoT client receives the registration request, calls the oracle registration contract pre-deployed on the blockchain network to verify the registration request, and calculates the unique identifier of the IRoT node. ; S1024, The DRoT client will use the unique identifier of the IRoT node. Store it.
[0052] For example, after generating the root key, the IRoT node needs to register on the blockchain to establish its trusted identity within the system. The registration process is as follows: The IRoT node submits a registration request to the DRoT client. This request includes an Authentication Report (AR) generated by its Trusted Platform Module (TPM), providing cryptographic evidence to prove that the IRoT node is in a trusted state. The Oracle Registration Contract verifies the authenticity of this AR and securely records the IRoT node's configuration information on the blockchain. This process ensures the tamper-proof and verifiable identity of IRoT nodes and establishes an initial foundation of trust in the underlying blockchain network.
[0053] Specifically, this embodiment describes the registration process of IRoT nodes on the blockchain to ensure the verifiability and tamper resistance of their identities: IRoT node generates Authentication Report (AR): The node uses TPM to generate an AR containing its own trusted state and signs it using AIK.
[0054] Submitting a registration request: The IRoT node submits a registration request to the DRoT client. This request contains the AR and the node's configuration information. .
[0055] Oracle registration contract verification of AR: The smart contract verifies the authenticity of AR on-chain and calculates the unique identifier of the IRoT node. .
[0056] Blockchain-based notarization: After successful verification, the Oracle Registration Contract stores the identity information of the IRoT node on the blockchain, forming a tamper-proof and trustworthy registration record.
[0057] This embodiment ensures the security, verifiability, and decentralized management of IRoT node identity registration.
[0058] S103, During the IRoT node authentication phase, each IRoT node generates a second authentication report based on a preset period or event-driven approach using the trusted platform module, and submits the second authentication report to the blockchain network to continuously verify and quantify the runtime trusted state of the registered IRoT nodes, thereby obtaining a pool of authenticated nodes. Specifically, in step S103, each IRoT node generates a second authentication report based on a preset period or event-driven method using the trusted platform module, and submits the second authentication report to the blockchain network to continuously verify and quantify the runtime trusted status of the registered IRoT nodes, thereby obtaining a pool of authenticated nodes, including the following steps S1031 to S1033.
[0059] S1031, IRoT node obtains current runtime measurement values. And use verifiable functions to generate unpredictable random values for this authentication. and proof ; S1032, the IRoT node utilizes the trusted platform module to generate a random value based on the private key pair in the authentication identity key pair. and proof Calculations are performed to obtain the second certification report; S1033, the blockchain network verifies the authenticity of the digital signature in the second authentication report and uses the proof Validate random values The correctness of the measurements is verified to obtain the results; if the verification result is passed, the measured values in the second certification report will be used. and benchmark reference measurement value The comparison is performed to obtain the comparison result; if the comparison result is equal, the time decay function is called to calculate the trust score corresponding to the IRoT node. If trust score Higher than the set threshold If so, the IRoT node will be added to the pool of certified nodes.
[0060] Here, the reference measurement value The acquisition methods include: during the IRoT node registration phase, extracting initial runtime measurement values from the verified first certification report, and using the initial runtime measurement values as benchmark reference measurement values. Stored on a blockchain network.
[0061] For example, the IRoT node authentication phase aims to continuously maintain and dynamically update the trusted state of IRoT nodes to ensure their long-term availability and security. The authentication process consists of two steps: (1) Off-Chain AR Generation.
[0062] (1.1) After registration, IRoT nodes will periodically use TPM to generate new authentication reports AR and sign them with their own private authentication keys; (1.2) The AR is then submitted to the blockchain as a cryptographic proof of the node’s continued trustworthiness.
[0063] (2) On-Chain AR Verification.
[0064] (2.1) Verify the digital signature to ensure the authenticity of the AR; (2.2) Inspect AR content to prevent forgery or tampering; (2.3) Calculate the trust score The trusted state of IRoT nodes is dynamically adjusted using a predefined time decay function.
[0065] Through this mechanism, the system can continuously assess and maintain the trustworthiness of IRoT nodes and dynamically adjust their trust scores throughout the entire operation, ensuring the long-term security and reliability of the entire system.
[0066] This step combines off-chain AR generation with a decentralized authentication protocol that eliminates on-chain interaction, continuously verifying the integrity of IRoT nodes and ensuring their trust level remains above a predetermined threshold. This protocol reduces communication overhead and latency during the verification process while maintaining system scalability and responsiveness, enabling it to handle dynamic changes in trust relationships within the network.
[0067] S104, In the IRoT node selection phase, in response to the data request to access the blockchain, a group of IRoT nodes are selected from the certified node pool to form a trusted oracle committee, a trusted task allocation record is generated, and one of the IRoT nodes is designated as the leader node. Specifically, in step S104, a group of IRoT nodes are selected from the certified node pool to form a trusted oracle committee, including the following steps S1041 to S1045.
[0068] S1041, Receive data request, the data request includes: the number of IRoT nodes to be selected. ; S1042 utilizes smart contracts deployed on the blockchain network to obtain all available IRoT nodes and their corresponding trust scores from the certified node pool. And use verifiable random functions to generate random numbers. ; S1043, Smart contracts are based on trust scores With random numbers Calculate the priority weight of each IRoT node and the total priority value. ; S1044, via random index Select nodes in a loop from the pool of certified nodes. Select 1 IRoT node and repeat this selection process until all nodes are selected to obtain a task node group. Then, designate the group nodes as the Trusted Oracle Committee. S1045, the oracle selection contract stores the list of node identifiers of the trusted oracle committee as a trusted task allocation record on the blockchain. See here. Figure 3 The process of building a Trusted Oracle Committee.
[0069] For example, in the IRoT node selection phase, the system employs a fair and secure selection algorithm that comprehensively considers randomness and trust scoring to ensure that the finally selected nodes have high credibility, while avoiding centralization and security risks. The specific steps are as follows: (1) The Oracle Selection Contract uses a Verifiable Random Function (VRF) to generate random numbers, which are then compared with the node's trust score. Combined, a priority decision-making mechanism is formed.
[0070] (2) Prioritize IRoT nodes with higher trust scores to ensure that the selected nodes are the most reliable parts of the system.
[0071] This mechanism can effectively resist Sybil attacks and conspiracy attacks, while enhancing the security and decentralization of blockchain oracles.
[0072] In this embodiment, the selection of IRoT nodes is executed by a smart contract, which combines randomness and trust score to ensure the fairness of the selection process: (1) Calculate priority weight: The smart contract uses VRF to generate random numbers and combines them with the trust score of the IRoT nodes. Calculate the weighted priority; (2) Calculate the total weight and randomly select: (2.1) Calculate the total priority value of all IRoT nodes. (2.2) Through random indexing Select a node, where, (2.3) Output selected nodes: Finally, a set of IRoT nodes will be selected to perform oracle tasks and the selection results will be recorded on the blockchain.
[0073] This embodiment employs an innovative algorithm combining a Verifiable Random Function (VRF) and node trust scoring to ensure the fairness and security of the IRoT node selection process. This algorithm uses a weighted priority mechanism to make high-trust nodes more likely to be selected, while maintaining a degree of randomness to prevent predictability and manipulation of the selection process. The use of VRF also provides transparency through public verification, ensuring the openness and impartiality of the node selection process.
[0074] S105, during the oracle service execution phase, the Trusted Oracle Committee processes off-chain data requests and each node generates a signed response, which is then aggregated by the leader node and submitted to the consumer blockchain. Specifically, in step S105, the oracle service phase includes the following steps S1051 to S1053.
[0075] S1051, Each IRoT node in the Trusted Oracle Committee uses its authentication identity key to sign off-chain data responses; S1052, the leader node collects all signed responses and generates an aggregate signature using the aggregate signature algorithm. ; S1053, aggregate signature The data response is submitted to the consumer's blockchain for verification.
[0076] For example, this embodiment demonstrates how to use EnduraTrust to build a decentralized blockchain oracle to achieve trusted off-chain data interaction: (1) See Figure 4 To establish the Trustworthy Oracle Committee (TOC): (1.1) A group of trusted nodes is determined by the IRoT node selection contract to form the Trustworthy Oracle Committee (TOC); (1.2) The first selected node is the leader node.
[0077] (2) Oracle response generation: (2.1) Each IRoT node in the TOC processes off-chain data requests and signs oracle responses using the AIK private key; (2.2) The leader node collects all signed responses and verifies their authenticity.
[0078] (3) Response aggregation and verification: (3.1) The leader node uses the BLS signature aggregation algorithm to merge all signatures into a single aggregated signature. (3.2) The validator node executes the smart contract and uses the public key of the IRoT node to verify the aggregated signature to ensure data integrity.
[0079] (4) Oracle data submission: (4.1) The client submits the final data to the blockchain for use by smart contracts, ensuring the security and immutability of off-chain data.
[0080] This embodiment implements a decentralized, verifiable, and highly secure blockchain oracle to ensure the credibility of off-chain data.
[0081] S106, during the incentive mechanism execution phase, the oracle service fee is weighted and allocated based on the trust score of each IRoT node.
[0082] Specifically, in step S106, the incentive mechanism execution phase includes: S1061, the total cost of oracle services Rewards are divided into leadership node rewards according to a preset ratio. And participation node rewards ; S1062, based on the trust score of each participating node By weight Distribute rewards to participating nodes and record and execute the reward distribution results on the blockchain.
[0083] For example, in this embodiment, in order to incentivize IRoT nodes to continuously provide high-quality oracle services, the system introduces an incentive mechanism based on trust scores: (1) Reward pool allocation: (1.1) Fees paid by oracle service users Classified as a leadership node reward And participation node rewards : , ; in, This indicates the percentage allocated to the leader node, which receives a higher percentage of the reward due to its additional computational and management work.
[0084] (2) Rewards are distributed based on trust scores: (2.1) The rewards for participating nodes are distributed according to their trust scores. Weighting: ; in, For the first Trust score of each participating node. This represents the total number of all participating nodes. Nodes with higher trust scores receive more incentives, promoting healthy competition.
[0085] This embodiment employs an incentive mechanism based on trust scores and node contributions to fairly distribute service fees paid by oracle users, rewarding nodes for their historical performance and reliability. Nodes with high trust levels will receive more rewards, which incentivizes nodes to maintain high service quality and promotes healthy competition among nodes, thereby improving the system's stability, decentralization, and efficiency.
[0086] These key technologies effectively address issues such as security, decentralization, trust mechanisms, and incentive structures in traditional blockchain oracle systems, thereby enhancing the overall security, scalability, and long-term stability of the system.
[0087] This invention significantly enhances the system's key security by introducing a decentralized root trust (DRoT) module and employing physically unclonable functions (PUFs) to generate secure and intrinsic root keys, thus avoiding the leakage risks of traditional static key systems. Combining off-chain AR generation with an on-chain, non-interactive authentication decentralized authentication protocol, the system can continuously and efficiently maintain dynamic trust relationships, reducing communication overhead and improving response speed. Through an innovative node selection algorithm, combining verifiable random functions (VRFs) and node trust scoring, the fairness and security of IRoT node selection are ensured, preventing attacks and manipulation and enhancing decentralized characteristics. Finally, a trust-based incentive mechanism fairly distributes service fees, incentivizing nodes to provide reliable services, thereby ensuring the system's stability and efficiency.
[0088] Overall, this invention effectively solves the problems of security, decentralization, trust mechanism and incentive structure in traditional blockchain oracle systems, and greatly improves the security, scalability and long-term stability of the system.
[0089] The various embodiments described in this specification are presented in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on its differences from other embodiments. All or part of this invention can be used in numerous general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, mobile communication terminals, multiprocessor systems, microprocessor-based systems, programmable electronic devices, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices, etc.
[0090] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the present invention.
Claims
1. A decentralized root of trust generation method suitable for blockchain oracles, characterized in that, include: During the IRoT node root key generation phase, each IRoT node generates a corresponding root key using a physically unclonable function, and then generates an AIK credential based on the authentication identity key pair derived from the root key. During the IRoT node registration phase, the trusted platform module is used to generate a first authentication report based on the authentication identity key pair, and the first authentication report is submitted to the blockchain network for verification and registration, so as to store the identity information of the IRoT node on the blockchain network. During the IRoT node authentication phase, each IRoT node generates a second authentication report based on a preset period or event-driven approach using the trusted platform module, and submits the second authentication report to the blockchain network to continuously verify and quantify the runtime trusted status of the registered IRoT nodes, thereby obtaining a pool of authenticated nodes. During the IRoT node selection phase, in response to data requests to access the blockchain, a group of IRoT nodes are selected from the certified node pool to form a trusted oracle committee, a trusted task allocation record is generated, and one of the IRoT nodes is designated as the leader node. During the oracle service execution phase, the trusted oracle committee processes off-chain data requests, and each node generates a signed response, which is then aggregated by the leader node and submitted to the consumer blockchain. During the incentive mechanism execution phase, oracle service fees are weighted and allocated based on the trust scores of each IRoT node.
2. The decentralized root of trust generation method for blockchain oracles according to claim 1, characterized in that, Each IRoT node generates its own root key using a physically unclonable function, including: After the IRoT node is powered on, it inputs a predefined challenge value into the PUF circuit; Each node generates a PUF response based on the predefined challenge value and derives an endorsement private key through a hash function. ; Each node uses elliptic curve cryptography, based on the endorsed private key. Calculate the endorsement public key and the endorsement public key Each node is bound to its own identity to obtain a cryptographic identity identifier; The endorsement private key and the endorsement public key As the complete root key.
3. The decentralized root of trust generation method for blockchain oracles according to claim 1, characterized in that, Submitting the first authentication report to the blockchain network for verification and registration includes: The first authentication report is signed using the private key in the authentication identity key pair to obtain the first signed authentication report; The IRoT node submits a registration request to the DRoT client; wherein the registration request includes: a first signature authentication report and the IRoT node's configuration information. ; The DRoT client receives the registration request, invokes the oracle registration contract pre-deployed on the blockchain network to verify the registration request, and calculates the unique identifier of the IRoT node. ; The DRoT client will use the unique identifier of the IRoT node. Store it.
4. The decentralized root of trust generation method for blockchain oracles according to claim 1, characterized in that, Each IRoT node generates a second authentication report based on a preset period or event-driven mechanism using the trusted platform module, and submits the second authentication report to the blockchain network. This continuously verifies and quantifies the runtime trusted status of registered IRoT nodes, resulting in a pool of authenticated nodes, including: IRoT nodes obtain current runtime measurements. And it uses a verifiable function to generate unpredictable random values for this authentication. and proof ; The IRoT node utilizes the trusted platform module to determine the random value based on the private key in the authentication identity key pair. and the proof Calculations are performed to obtain the second certification report; The blockchain network verifies the authenticity of the digital signature in the second authentication report and uses the proof. Verify the random value The correctness of the measurement is verified to obtain the result; if the verification result is passed, the measurement value in the second certification report is used. and benchmark reference measurement value A comparison is performed to obtain the comparison result; if the comparison result is equal, the time decay function is called to calculate the trust score corresponding to the IRoT node. If the trust score Higher than the set threshold If so, the IRoT node will be added to the pool of certified nodes.
5. The decentralized root of trust generation method for blockchain oracles according to claim 4, characterized in that, The reference measurement value The methods of obtaining it include: During the IRoT node registration phase, initial runtime measurement values are extracted from the verified first authentication report and used as the baseline reference measurement values. Stored in the blockchain network.
6. The decentralized root of trust generation method for blockchain oracles according to claim 1, characterized in that, The step of selecting a group of IRoT nodes from the certified node pool to form a trusted oracle committee includes: Receive a data request, the data request including: the number of IRoT nodes to be selected. ; Using smart contracts deployed on the blockchain network, all available IRoT nodes and their corresponding trust scores are obtained from the certified node pool. And use verifiable random functions to generate random numbers. ; The smart contract is based on the trust score. With the random number Calculate the priority weight of each IRoT node and the total priority value. ; Through random index Select nodes cyclically from the pool of certified nodes. IRoT nodes, and repeat this selection process until all nodes are selected to obtain a task node group, and designate the group of nodes as the Trusted Oracle Committee; The oracle selection contract stores the list of node identifiers of the trusted oracle committee on the blockchain as the trusted task allocation record.
7. The decentralized root of trust generation method for blockchain oracles according to claim 6, characterized in that, The oracle service phase includes: Each IRoT node in the Trusted Oracle Committee uses its authentication key to sign off-chain data responses; The leader node collects all signature responses and generates an aggregate signature using the aggregate signature algorithm. ; The aggregate signature The data response is submitted to the consumer's blockchain for verification.
8. The decentralized root of trust generation method for blockchain oracles according to claim 1, characterized in that, The implementation phase of the incentive mechanism includes: Total cost of oracle services Rewards are divided into leadership node rewards according to a preset ratio. And participation node rewards ; Based on the trust scores of each participating node By weight Distribute the rewards to the participating nodes, and record and execute the reward distribution results on the blockchain.
9. The decentralized root of trust generation method for blockchain oracles according to any one of claims 1 to 8, characterized in that, The physically unclonable function is an endogenous key generation module based on hardware characteristics, and the trusted platform module is a security coprocessor that performs encryption operations and generates authentication reports.
10. The decentralized root of trust generation method for blockchain oracles according to any one of claims 1 to 8, characterized in that, The blockchain network is deployed with smart contracts for node registration, authentication report verification, and node selection to execute decentralized logic at each stage.