On-chain and off-chain collaborative transaction method and computer readable storage medium
By employing on-chain and off-chain collaborative transaction methods and trusted hardware technology, the bottlenecks in throughput and high costs in intelligent connected vehicle data transactions have been resolved, enabling secure, efficient, and fair data exchange, which is suitable for intelligent connected vehicle data transactions.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- XIAMEN YAXON ZHILLAN TECHNOLOGY CO LTD
- Filing Date
- 2024-12-04
- Publication Date
- 2026-06-05
AI Technical Summary
Existing technologies in intelligent connected vehicle data transactions suffer from throughput bottlenecks, high transaction costs, inability to guarantee transaction atomicity and reliability, and reliance on third-party storage nodes, which poses a single point of failure risk.
It adopts an on-chain and off-chain collaborative transaction method, which performs on-chain processing at the start and settlement of transactions, while data exchange is carried out off-chain in intermediate transactions. It uses multi-signature addresses and smart contracts to lock digital currencies, and uses trusted hardware and adapter signature algorithms to verify and encrypt data, thereby realizing peer-to-peer transactions.
It increases transaction throughput, reduces transaction costs, ensures transaction security and fairness, is suitable for large-scale data exchange scenarios, has good compatibility, does not rely on third parties, and improves credibility.
Smart Images

Figure CN122155716A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of blockchain technology, and in particular to an on-chain and off-chain collaborative transaction method and a computer-readable storage medium. Background Technology
[0002] Secure exchange in the data trading mechanism and trust establishment of intelligent connected vehicles is a core function to be achieved in the data circulation process of intelligent connected vehicles. Participants in the exchange need to exchange intelligent connected vehicle data products online on an equal footing with digital currency (referring to digital forms of legal tender, such as digital RMB) to achieve the effective supply and use of intelligent connected vehicle data products. Secure exchange generally requires the exchange process to meet the following security properties:
[0003] 1. Predictability: The exchange results meet the requirements of the pre-agreed consensus among the participants (such as the requirement of equivalence between the exchanged content and the digital currency);
[0004] 2. Fairness: Participants in the exchange cannot gain an unfair advantage by adjusting the order of the exchange operations or by terminating their participation in the exchange;
[0005] 3. Privacy: Protect the privacy information of the participants in the exchange and prevent unrelated third parties from knowing about it.
[0006] However, in the data security exchange process of intelligent connected vehicles, existing solutions based on trusted third parties, blockchain, zero-knowledge proofs, or their improved versions all have the problem of difficulty in ensuring the fairness and security of intelligent connected vehicle data transactions.
[0007] Chinese patent document CN116245646A discloses an electronic resource trading method, apparatus, electronic device, and readable storage medium. The method includes: applying to a resource sender; generating a binary relation pair, the binary relation pair including a first element and a second element; encrypting a pre-generated symmetric key using the first element to obtain key ciphertext; uploading the key ciphertext to a third-party storage node, and uploading the resource sender information, the storage address of the resource ciphertext and the key ciphertext, and the resource ciphertext information to a publicly available blockchain; receiving a smart contract deployment address sent by a resource receiver; sending the first element to the resource receiver; receiving a pre-signature sent by the resource receiver; verifying the pre-signature based on the first element, the transaction information of the publicly available resource ciphertext on the blockchain, and the blockchain public key of the resource receiver; if the verification is successful, converting the pre-signature into a signature using the second element and an adapter signature algorithm; sending the signature to the smart contract; and receiving digital assets transferred by the smart contract.
[0008] However, this plan has the following drawbacks:
[0009] 1. In this scheme, all transactions are online. With the continuous and dynamic flow of data in the vehicle-to-everything (V2X) network, the blockchain's throughput becomes a bottleneck. If all transactions are conducted on-chain, the existing blockchain's throughput cannot meet the demands of large-scale data exchange in the V2X scenario. Improving throughput requires a more efficient consensus algorithm, which would involve updating all nodes in the system. Even with an updated consensus algorithm, the throughput wouldn't be significantly increased. Furthermore, recording transactions on the blockchain incurs fees; recording every transaction would result in substantial transaction costs.
[0010] 2. This solution requires uploading information to a third-party storage node, which raises issues such as single point of failure and whether the third party is truly trustworthy and will not tamper with the data.
[0011] 3. This scheme cannot guarantee the atomicity of transactions; it only considers the case where the transaction is successful.
[0012] 4. This scheme does not consider the reliability of transaction data. Summary of the Invention
[0013] The technical problem to be solved by this invention is to provide an on-chain and off-chain collaborative transaction method and a computer-readable storage medium that can realize secure, efficient and fair transactions.
[0014] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is: an on-chain and off-chain collaborative transaction method, comprising:
[0015] The first and second transaction terminals agree on the transaction objects and transaction amounts, and verify the transaction objects. The first transaction terminal is the equipment terminal of the demand side of the transaction objects, and the second transaction terminal is the equipment terminal of the supply side of the transaction objects.
[0016] If the verification is successful, the first transaction terminal will submit the digital currency corresponding to the transaction amount to the blockchain for locking;
[0017] The second transaction terminal encrypts and transmits the transaction object to the first transaction terminal, and collaborates with the first transaction terminal to generate a commitment transaction. The commitment transaction is then submitted to the blockchain to update the allocation of digital currency in the blockchain.
[0018] The present invention also proposes a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method described above.
[0019] The beneficial effects of this invention are as follows: only the start and settlement of transactions require on-chain processing and confirmation, while intermediate transactions are conducted off-chain for data exchange. Therefore, it can improve transaction throughput, making it suitable for large-scale data exchange scenarios in the Internet of Vehicles, and can reduce transaction costs. It is also applicable to all blockchains and has good compatibility. Furthermore, the two parties to the transaction can conduct direct peer-to-peer transactions without relying on a third party, resulting in high credibility. Attached Figure Description
[0020] Figure 1 A flowchart of an on-chain and off-chain collaborative transaction method according to the present invention;
[0021] Figure 2 This is a schematic diagram of the transaction process according to an embodiment of the present invention.
[0022] Figure 3 This is a schematic diagram illustrating the design of a payment repayment mechanism using smart contracts according to an embodiment of the present invention;
[0023] Figure 4 This is a schematic diagram of the commitment transaction generation process according to an embodiment of the present invention. Detailed Implementation
[0024] To explain in detail the technical content, objectives, and effects of the present invention, the following description is provided in conjunction with the embodiments and accompanying drawings.
[0025] Please refer to Figure 1 A method for on-chain and off-chain collaborative transactions, comprising:
[0026] The first and second transaction terminals agree on the transaction objects and transaction amounts, and verify the transaction objects. The first transaction terminal is the equipment terminal of the demand side of the transaction objects, and the second transaction terminal is the equipment terminal of the supply side of the transaction objects.
[0027] If the verification is successful, the first transaction terminal will submit the digital currency corresponding to the transaction amount to the blockchain for locking;
[0028] The second transaction terminal encrypts and transmits the transaction object to the first transaction terminal, and collaborates with the first transaction terminal to generate a commitment transaction. The commitment transaction is then submitted to the blockchain to update the allocation of digital currency in the blockchain.
[0029] As can be seen from the above description, the beneficial effects of the present invention are: it can increase transaction throughput and has high reliability.
[0030] Furthermore, before the first and second transaction terminals agree on the transaction partners and transaction amount, and before verifying the transaction partners, the process also includes:
[0031] The first transaction terminal verifies the second transaction terminal. If the verification is successful, the first and second transaction terminals agree on the transaction object and transaction amount, and the transaction object is verified.
[0032] Furthermore, the first transaction terminal verifies the second transaction terminal, including:
[0033] The first transaction terminal uses the blockchain to query whether the second transaction terminal has any security violations or data loss records;
[0034] If there are no security violations or data loss records on the device, the verification is considered successful.
[0035] As described above, verifying the second transaction terminal ensures the credibility of the transaction terminal and improves the security of the transaction.
[0036] Furthermore, the transaction object includes target product data; the verification of the transaction object includes:
[0037] The first transaction terminal queries the target product data through the blockchain and submits the hash value of the target product data to the secure area of the second transaction terminal.
[0038] The second transaction terminal's secure zone retrieves the target product data from the ordinary zone and determines whether the hash value of the retrieved target product data matches the hash value submitted by the first transaction terminal.
[0039] If a match is found, the verification is considered successful.
[0040] As described above, verifying the trading partner ensures its credibility and improves transaction security.
[0041] Furthermore, the first transaction terminal submits the digital currency corresponding to the transaction amount to the blockchain for locking, including:
[0042] Generate multi-signature addresses corresponding to the first and second transaction terminals;
[0043] The first transaction terminal generates a locked transaction, which is a transaction that transfers the digital currency corresponding to the transaction amount into the multi-signature address.
[0044] The second transaction terminal generates a cancellation transaction and submits it to the blockchain. The cancellation transaction is accompanied by a lock-up period, which is a preset duration.
[0045] The first transaction client submits the locked transaction to the blockchain.
[0046] As described above, by using multi-signature addresses and smart contracts to lock up digital currency with a time limit, if the digital currency in the multi-signature address has not been used after the lock-up period expires, the first transaction party can directly retrieve the funds in that address, thereby ensuring the fairness of the transaction.
[0047] Furthermore, the transaction object includes target product data;
[0048] After the first and second transaction terminals agree on the transaction partners and transaction amount, and verify the transaction partners, the process further includes:
[0049] If the verification is successful, the second transaction terminal will segment the target product data to obtain a preset number of data blocks.
[0050] Furthermore, the second transaction terminal encrypts and transmits the transaction object to the first transaction terminal, and collaborates with the first transaction terminal to generate a commitment transaction, submitting the commitment transaction to the blockchain, including:
[0051] The second transaction terminal iterates through each data block of the target product data and sequentially obtains a data block as the current data block.
[0052] The second transaction's secure area generates the key corresponding to the current data block, which serves as the current key, and generates a commitment corresponding to the current key, which serves as the current commitment.
[0053] The second transaction end uses the current key to encrypt the current data block, obtains the current encrypted data block, and sends the current encrypted data block and the current commitment to the first transaction end;
[0054] The first transaction client generates an unsigned commitment transaction corresponding to the current data block, which serves as the current commitment transaction;
[0055] The first transaction terminal uses the adapter signature algorithm, its own private key, and the current commitment to pre-sign the current commitment transaction, and then sends the current commitment transaction with the pre-signature of the first transaction terminal to the second transaction terminal.
[0056] The second transaction end adapts the current key to the pre-signature of the first transaction end in the current commitment transaction, and signs the current commitment transaction with its own private key to obtain a valid current commitment transaction;
[0057] The first transaction terminal requests the current key from the second transaction terminal, and decrypts the current encrypted data block using the current key to obtain the current data block;
[0058] Once all data blocks of the target product data have been traversed, and the first transaction end has obtained all data blocks of the target product data, the second transaction end submits the valid commitment transaction corresponding to the last data block to the blockchain.
[0059] Furthermore, the current commitment transaction is signed using an adapter signature algorithm based on elliptic curve digital signature. After both parties have completed the off-chain transaction of all data blocks of the target product data, the second transaction end submits the valid commitment transaction generated by the last data block transaction to the blockchain, completing the final on-chain digital currency settlement.
[0060] In an optional embodiment, the first transaction terminal pre-signs the current commitment transaction using a first algorithm, and the second transaction terminal signs the current commitment transaction with the pre-signature of the first transaction terminal using a second algorithm.
[0061] The first algorithm is:
[0062] k Si =Random(q);
[0063] K Si =K i ·k Si ;r Si =f(K Si );
[0064]
[0066] d i '=(d i ”,π' Si );
[0067] The second algorithm is:
[0068]
[0069] π Si =(r Si ,s Si );
[0070] k Di =Random(q);
[0071] K Di =k Di ·G;r Di =f(K Di );
[0072]
[0073] π Di =(r Di ,s Di );
[0074] d i =(d” i,π Si ,π Di );
[0075] Where, d i "Indicates an unsigned current commitment transaction, d" i 'Indicates a current commitment transaction pre-signed by the first transaction party, d i Indicates a valid current commitment transaction; K i Indicates the current commitment, K i =k i ·G,k i The key represents the current key, and G represents the base point of the preset elliptic curve; sk S This represents the private key of the first transaction, π' Si This represents the pre-signature of the first transaction, π. Si Indicates a valid signature; sk D This represents the private key of the second transaction, π. Di This represents the signature of the second transaction; Random() represents the random number function, f() represents the function used to calculate the x-coordinate of a point on a preset elliptic curve, and h() represents the hash function.
[0076] Furthermore, the second transaction terminal encrypts and transmits the transaction object to the first transaction terminal, and collaborates with the first transaction terminal to generate a commitment transaction, submitting the commitment transaction to the blockchain, and also includes:
[0077] If the second transaction party fails to deliver the current key to the first transaction party, or delivers an incorrect key, the second transaction party will submit the valid current commitment transaction to the blockchain.
[0078] The first transaction terminal obtains a valid current commitment transaction from the blockchain, extracts the current key from the signature of the valid current commitment transaction through pre-signing, and decrypts the current encrypted data block using the extracted current key to obtain the current data block.
[0079] As described above, ensuring that the first transaction end can obtain the corresponding key guarantees that the first transaction end will not suffer losses.
[0080] The present invention also proposes a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method described above.
[0081] Example 1
[0082] Please refer to Figure 2-4 The first embodiment of the present invention is: an on-chain and off-chain collaborative transaction method that can be applied to the scenario of large-scale data exchange in intelligent connected vehicles.
[0083] In this embodiment, the transaction object (i.e., target product data) is intelligent connected vehicle data (such as driving data, including location data, vehicle condition data sensed by onboard sensors, etc.) as an example. The demand side is a service provider that needs intelligent connected vehicle data. The service provider's device ( Figure 2-4 Service provider S in the middle acts as the first transaction end, and uses intelligent connected vehicle data collection equipment ( Figure 2-4 The device terminal D in the middle serves as the second transaction terminal.
[0084] To ensure the secure, efficient, and fair exchange of data in intelligent connected vehicles, this embodiment uses adapter signatures, blockchain smart contracts, and trusted hardware technology to implement the exchange and safeguard the exchange process.
[0085] like Figure 2 As shown, this embodiment mainly includes two stages: exchange preparation and exchange execution. The exchange preparation mainly includes two steps: data verification and currency locking.
[0086] Before data verification, the second transaction terminal also needs to be verified. Specifically, the first transaction terminal (i.e., the device terminal of the service provider that needs intelligent connected vehicle data, hereinafter referred to as the service provider) can query the blockchain to check whether the second transaction terminal (i.e., the intelligent connected vehicle data collection device) has any security violations or data loss records before the query deadline. If there are no security violations or data loss records, the second transaction terminal is considered trustworthy; otherwise, it is considered that the second transaction terminal may have been attacked, and the transaction is terminated directly.
[0087] Then, the first and second trading terminals agree on the hash of the target product data and the expected transaction amount. The first trading terminal submits the hash value of the target product data to the second trading terminal, which verifies whether the target product data and its hash value match within the second trading terminal's secure area. Specifically, refer to... Figure 2 In steps 1.1-1.3, service provider S queries the required target product data from the blockchain and submits the hash value of the target product data to the secure area of device D. Device D obtains the target product data from the ordinary area and then determines whether the hash value of the obtained target product data matches the hash value submitted by service provider S. If they match, the verification is considered successful; otherwise, the verification fails.
[0088] In other words, after reaching an agreement on the exchange, the two parties first agree on the hash value of the target intelligent connected vehicle data product, and submit the hash value and the target intelligent connected vehicle data product to a secure area for verification. They also agree on the correspondence between the exchange content and the digital currency to ensure the predictability of the exchange for both parties.
[0089] This embodiment uses a secure zone operating within the intelligent connected vehicle data acquisition device as a proxy to provide efficient verification services to service providers. The local trusted hardware first generates a report containing the secure zone's identity information, status, and code metrics. Upon receiving an authentication request from a service provider, the secure zone generates a remote authentication assertion statement through an authentication operation and sends it to the service provider. The service provider verifies the hardware signature to determine if the assertion statement was generated by a reliable processor and verifies whether the metrics in the assertion statement match the publicly available secure exchange protocol code. After successful authentication, the service provider sends the hash value of the target intelligent connected vehicle data product to the secure zone. Subsequently, the secure zone publishes this hash value to the ordinary zone of the intelligent connected vehicle data acquisition device and requests the corresponding intelligent connected vehicle data product data. The ordinary zone of the intelligent connected vehicle data acquisition device then transmits the intelligent connected vehicle data product data that satisfies the hash value to the secure zone for verification.
[0090] If the verification passes, the target product data will be segmented within the secure area of the second transaction terminal. (Refer to...) Figure 2 In section 1.4, in this embodiment, the target product data X is divided into n data blocks {x1, x2, ..., xn}. n In practical applications, data can be segmented based on data type. The size of each data block may not be consistent, but it generally will not deviate too much.
[0091] Then comes the cryptocurrency locking stage. After verification, the service provider needs to submit the expected cryptocurrency to the blockchain for a period of time, during which time the secure exchange of intelligent connected vehicle data products is completed to ensure fairness. For Turing-complete blockchains, the exchanging parties can directly implement the time-limited cryptocurrency locking function through smart contracts, while this is more difficult for non-Turing-complete blockchains. This embodiment involves transaction transactions in various scenarios, requiring the support of a Turing-complete blockchain; therefore, it mainly discusses implementing time-limited cryptocurrency locking on a Turing-complete blockchain.
[0092] For example, multi-signature addresses and smart contracts can be used to lock up cryptocurrency with a specified time limit. After generating the multi-signature address (D, S), the service provider generates a locking transaction and submits it to the blockchain, transferring a predetermined amount of cryptocurrency into the multi-signature address for locking. To ensure that the service provider does not lose the cryptocurrency locked in the multi-signature address due to the intelligent connected vehicle data collection equipment refusing to respond (i.e., ensuring the timeliness of the exchange), the service provider typically uses the smart contract functionality provided by a Turing-complete blockchain to generate the locking transaction. This smart contract introduces a lock-up period; if the cryptocurrency in the multi-signature address has not been used by the end of the lock-up period, the service provider can directly retrieve the funds in that address.
[0093] In other words, by using smart contracts designed in a Turing-complete blockchain, a transfer mechanism can be implemented, allowing service providers to retrieve all the digital currency locked in the multi-signature address after the lock-up period expires.
[0094] Specifically, refer to Figure 2 Sections 2.1-2.2 and 2.2 in the text. Figure 3 In this embodiment, the first transaction terminal first generates a transaction that transfers the digital currency corresponding to the transaction amount (such as 10 RMB coins) to the resigned address, which is called a locked transaction. Figure 3 In the transaction, gray text with white text and a black border indicates that it has been signed, while white text with black text and a black border indicates that the signature is required for the expenditure output. After a locked transaction is generated, the first transaction client does not directly submit the locked transaction to the blockchain. Instead, it first generates a reversal transaction with the second transaction client, which includes a lock time. Only then does the first transaction client publish the locked transaction and transfer the corresponding cryptocurrency to the multi-signature address (D, S). Due to the lock time, the reversal transaction does not take effect immediately. It will only be accepted by the blockchain miners after the lock time has elapsed. For example, assuming the lock time is 1000 blocks, the reversal transaction will only be accepted by the blockchain miners after the locked transaction has been confirmed by the blockchain for 1000 blocks.
[0095] During the lock-up period, the two parties can securely exchange target product data and complete the payment by updating the allocation of RMB coins in the multi-signature address (D,S) off-chain, thus entering the exchange execution phase.
[0096] In this embodiment, since the target product data is divided into n data blocks, the second transaction end can deliver the target product data to the first transaction end in blocks via a proprietary transmission protocol. To ensure the fairness of the exchange, both parties use an adapter signature scheme based on ECDSA (Elliptic Curve Digital Signature Algorithm) to sign a commitment transaction to achieve a fair exchange. During the exchange execution phase, whenever the first transaction end receives an encrypted data block E... i The two parties collaborate to generate a commitment transaction. i This updates the RMB allocation in the multi-signature address, completing the off-chain payment. Among them, E i =Enc(k i x i ), Enc() represents the encoding function, x i k represents the i-th data block of the target product data. i Represents the i-th data block x i The corresponding keys are 1 ≤ i ≤ n. For example, suppose we commit to transaction d. i-1The RMB coins in the multi-signature address are allocated according to the principle of 5 RMB coins for the first transaction terminal and 5 RMB coins for the second transaction terminal. The first transaction terminal is used to purchase the i-th data block x. i A payment of 1 RMB is required to complete the transaction. i The RMB coins in the multi-signature address are allocated as follows: 4 RMB coins for the first transaction and 6 RMB coins for the second transaction. Furthermore, the two parties exchanging the funds can use adapter signature technology to combine the signature of the first transaction with the key k. i Binding, when the second transaction end submits a commitment transaction d to the blockchain i When settling RMB coins in a multi-signature address, the first transaction end can extract k from it. i Thus, the encrypted data block E i Decrypt to obtain the i-th data block x i .
[0097] Before detailing the exchange execution process, let's first introduce the ECDSA signature algorithm. The ECDSA signature algorithm (Elliptic Curve Digital Signature Algorithm) includes three steps: key generation, signing, and authentication. Specifically, after selecting an elliptic curve, a base point G in the curve, and a prime number q, the signer uses a key generation algorithm to generate the public-private key pair required for signing. For example, the signer uses a random number sk as the private key, 1 ≤ sk ≤ q, and pk = sk·G as the public key. Then, the signer uses the private key sk and the random number k to sign the message m, obtaining the signature π = (r, s) of message m, where 2 ≤ k ≤ q, and s = k. -1 ·(h(m)+r·sk), where h() represents the hash function, r=f(p) and P=k·G, and the function f(P) is used to calculate the x-coordinate of point P on the elliptic curve. After obtaining the message m and its signature π, the verifier verifies the validity of the signature through the signature verification equation, i.e., f(s) -1 ·h(m)·G+s -1 If r is true, the signature can be authenticated; otherwise, the signature is rejected.
[0098] The exchange execution process is then detailed, using one of the data blocks x of the target product data. i Let's take a transaction as an example. First, data block x is generated in the secure area of the second transaction endpoint. i Corresponding key k i And calculate commitment K i =k i ·G, where G is the base point G in the given elliptic curve. Then, refer to... Figure 2 Sections 3.1-3.2 describe the secure area of the second transaction endpoint using key k. i For data block xi Encryption is performed to obtain encrypted data block E. i and encrypted data block E i and commitment K i Send to the first transaction endpoint. Optionally, the second transaction endpoint can process data block x. i The corresponding key k is generated during the transaction. i and commitment K i Alternatively, keys and commitments for each data block can be generated in advance.
[0099] Then, the first and second trading terminals collaborate to generate a commitment transaction d. i Specifically, such as Figure 4 As shown, firstly, service provider S generates an unsigned commitment transaction d. i ", and invoke the adapter signature algorithm, using the private key sk it holds. S And promise K i Regarding the committed transaction d i "Perform pre-signing to generate a π' with the service provider's pre-signature." Si Commitment transaction d i '( Figure 4 In the transaction details, a gray background with white dots, white text, and a black border indicates that the transaction has been pre-signed.
[0100] The process of generating a pre-signed commitment transaction is shown in Algorithm 1.
[0101] Algorithm 1:
[0102] Input: sk S d i K i
[0103] Output: d i '=(d i ”π' Si )
[0104] 1.k Si =Random(q)
[0105] 2.K Si =K i ·k Si ;r Si =f(K Si )
[0106] 3.
[0107] 4.
[0109] 5. return d i'=(d” i ,π' Si )
[0110] Specifically, first, generate a random number k in the finite field [2, q]. Si Then, based on ECDSA-based adapter signature technology, the service provider uses a random number k. Si and commitment K i The r part of generating the signature Si In order to fulfill the promise K i Insert it into the signature. Then, use r. Si Generate the s part of the pre-signed part Thus, the presignature π' is obtained. Si Finally, the service provider generates a pre-signed commitment transaction d. i ', and d i Send to the intelligent connected vehicle data acquisition equipment.
[0111] In the pre-signature, r Si =f(k) i ·k Si Therefore, the signature cannot pass the ECDSA verification equation, i.e., the pre-signature π'. Si This is not a valid signature, and the transaction cannot be verified by blockchain miners. Therefore, upon receiving the pre-signed commitment transaction d... i After that, the intelligent connected vehicle data collection device only uses its private key sk D Signed i This is not enough to make the transaction effective; commitment K is also required. i The corresponding key k i The pre-signature is adapted and converted into a valid signature, thereby generating a commitment transaction acceptable to blockchain miners and completing the off-chain payment. The process of generating a valid commitment transaction is shown in Algorithm 2.
[0112] Algorithm 2:
[0113] Input: d i '=(d i ”π' si ), K i ,sk D
[0114] Output: d i =(d i ”π' Si , π Di )
[0115] 1.
[0116] 2.π Si =(rSi ,s Si )
[0117] 3.k Di =Random(q)
[0118] 4.K Di =k Di ·G;r Di =f(K Di )
[0119] 5.
[0120] 6.π Di =(r Di ,s Di )
[0121] 7. return d i =(d” i ,π Si ,π Di )
[0122] Specifically, firstly, the intelligent connected vehicle data acquisition equipment will promise K i The corresponding key k i Insert into pre-signed π' Si The s part In this process, a pre-signature is converted into a valid ECDSA signature. Si , π Si The equation can be verified using ECDSA signature verification:
[0123]
[0124] In the key k i Insert into the service provider's pre-signed π' Si Obtain a valid ECDSA signature from the service provider. Si Subsequently, the intelligent connected vehicle data collection device uses its private key sk D Generate signature π Di Complete the promised transaction d i The generation of data block x is thus completed. i Off-chain payments.
[0125] Finally, the first trading party obtains the commitment K. i The corresponding key k i and using key k i Decrypt encrypted data block E i Data block x is obtained i .
[0126] Specifically, the service provider requests the key k from the intelligent connected vehicle data collection equipment. i If the intelligent connected vehicle data acquisition device uses the correct key k i It was sent to the service provider, and then through K i After verification, the service provider can use k i For encrypted data block E i Decryption is performed to obtain data block x. i .
[0127] After exchanging the data block, the two parties can repeat the above operation to continue the fair exchange of subsequent data blocks until the service provider obtains the entire intelligent connected vehicle data product X. That is, according to the above method, by traversing each data block of the target product data, the off-chain transactions of each data block are completed sequentially. When the first transaction party obtains the entire target product data X, the second transaction party will immediately submit the latest transaction commitment d to the blockchain. n This completes the final on-chain digital currency settlement.
[0128] Furthermore, if the intelligent connected vehicle data collection equipment fails to deliver the key k to the service provider... i If an incorrect key is delivered, the intelligent connected vehicle data acquisition device will invalidate the promised transaction. i By submitting to the blockchain, service providers can submit committed transactions to the blockchain using data collection devices in intelligent connected vehicles. i Then, obtain the committed transaction d from the blockchain. i and using pre-signed π' Si From transaction d i signature π Si Extract the key k i Thus decrypting the encrypted data block E i Data block x is obtained i In this case, no further transactions of data blocks will be conducted.
[0129] In other application scenarios, it's not always necessary to complete all data blocks in a transaction. If an issue arises in the most recent transaction, or if the requesting party decides they no longer need the subsequent data blocks, the final on-chain settlement can proceed directly. For example, if an issue arises when the transaction reaches the m-th data block, or if the requesting party no longer needs the remaining data blocks, the commitment transaction d corresponding to the (m-1)-th data block can be directly settled. m-1 Submitting to the blockchain for settlement is more flexible, fits real-world transaction scenarios, and only requires paying the on-chain fee once.
[0130] This embodiment has the following advantages:
[0131] 1. Involving on-chain and off-chain collaboration, the target product data is segmented before the transaction. On-chain processing and confirmation are only required at the start and settlement of the protocol. Transactions in between can be conducted off-chain using private protocols for data exchange, thus improving transaction throughput. This is suitable for large-scale data exchange scenarios in the Internet of Vehicles. Furthermore, since on-chain processing is only required at the start and end, or if the transaction is no longer desired, on-chain settlement can be performed based on the exchanged records, thus reducing transaction fees. At the same time, it does not involve modification of the core consensus algorithm of the blockchain, making it applicable to all blockchains and exhibiting good compatibility with different blockchains.
[0132] 2. By using trusted hardware, the two parties can conduct direct peer-to-peer transactions without relying on a third party. Data storage, verification, encryption, and operation are all carried out in the secure area of trusted hardware, ensuring high reliability.
[0133] 3. It not only considers the case of successful transactions, but also designs the case of transaction cancellation in the case of failed transactions, thus ensuring the atomicity and fairness of transactions.
[0134] Example 2
[0135] This embodiment is a computer-readable storage medium corresponding to the above embodiments, on which a computer program is stored. When the program is executed by a processor, it implements the various steps of the on-chain and off-chain collaborative transaction method as described in the above embodiments, and can achieve the same technical effect, which will not be repeated here.
[0136] In summary, the on-chain and off-chain collaborative transaction method and computer-readable storage medium provided by this invention can improve transaction throughput, reduce transaction fees, ensure the atomicity and fairness of transactions, have high credibility, effectively guarantee transaction security, be applicable to all blockchains, and have good compatibility with different blockchains.
[0137] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent modifications made based on the content of the present invention specification and drawings, or direct or indirect applications in related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A method for on-chain and off-chain collaborative transactions, characterized in that, include: The first and second transaction terminals agree on the transaction objects and transaction amounts, and verify the transaction objects. The first transaction terminal is the equipment terminal of the demand side of the transaction objects, and the second transaction terminal is the equipment terminal of the supply side of the transaction objects. If the verification is successful, the first transaction terminal will submit the digital currency corresponding to the transaction amount to the blockchain for locking; The second transaction terminal encrypts and transmits the transaction object to the first transaction terminal, and collaborates with the first transaction terminal to generate a commitment transaction. The commitment transaction is then submitted to the blockchain to update the allocation of digital currency in the blockchain.
2. The on-chain and off-chain collaborative transaction method according to claim 1, characterized in that, Before the first and second transaction terminals agree on the transaction partners and transaction amount, and before verifying the transaction partners, the process also includes: The first transaction terminal verifies the second transaction terminal. If the verification is successful, the first and second transaction terminals agree on the transaction object and transaction amount, and the transaction object is verified.
3. The on-chain and off-chain collaborative transaction method according to claim 2, characterized in that, The first transaction terminal verifies the second transaction terminal, including: The first transaction terminal uses the blockchain to query whether the second transaction terminal has any security violations or data loss records; If there are no security violations or data loss records on the device, the verification is considered successful.
4. The on-chain and off-chain collaborative transaction method according to claim 1, characterized in that, The transaction object includes target product data; The verification of the transaction object includes: The first transaction terminal queries the target product data through the blockchain and submits the hash value of the target product data to the secure area of the second transaction terminal. The second transaction terminal's secure zone retrieves the target product data from the ordinary zone and determines whether the hash value of the retrieved target product data matches the hash value submitted by the first transaction terminal. If a match is found, the verification is considered successful.
5. The on-chain and off-chain collaborative transaction method according to claim 1, characterized in that, The first transaction terminal submits the digital currency corresponding to the transaction amount to the blockchain for locking, including: Generate multi-signature addresses corresponding to the first and second transaction terminals; The first transaction terminal generates a locked transaction, which is a transaction that transfers the digital currency corresponding to the transaction amount into the multi-signature address. The second transaction terminal generates a cancellation transaction and submits it to the blockchain. The cancellation transaction is accompanied by a lock-up period, which is a preset duration. The first transaction client submits the locked transaction to the blockchain.
6. The on-chain and off-chain collaborative transaction method according to claim 1, characterized in that, The transaction object includes target product data; After the first and second transaction terminals agree on the transaction partners and transaction amount, and verify the transaction partners, the process further includes: If the verification is successful, the second transaction terminal will segment the target product data to obtain a preset number of data blocks.
7. The on-chain and off-chain collaborative transaction method according to claim 6, characterized in that, The second transaction terminal encrypts and transmits the transaction object to the first transaction terminal, and collaborates with the first transaction terminal to generate a commitment transaction, and submits the commitment transaction to the blockchain, including: The second transaction terminal iterates through each data block of the target product data and sequentially obtains a data block as the current data block. The second transaction's secure area generates the key corresponding to the current data block, which serves as the current key, and generates a commitment corresponding to the current key, which serves as the current commitment. The second transaction end uses the current key to encrypt the current data block, obtains the current encrypted data block, and sends the current encrypted data block and the current commitment to the first transaction end; The first transaction client generates an unsigned commitment transaction corresponding to the current data block, which serves as the current commitment transaction; The first transaction endpoint, using the adapter signature algorithm, pre-signs the current commitment transaction using its own private key and the current commitment, and then sends the pre-signed current commitment transaction to [the target endpoint]. Second transaction terminal; The second transaction end adapts the current key to the pre-signature of the first transaction end in the current commitment transaction, and signs the current commitment transaction with its own private key to obtain a valid current commitment transaction; The first transaction terminal requests the current key from the second transaction terminal, and decrypts the current encrypted data block using the current key to obtain the current data block; Once all data blocks of the target product data have been traversed, and the first transaction end has obtained all data blocks of the target product data, the second transaction end submits the valid commitment transaction corresponding to the last data block to the blockchain.
8. The on-chain and off-chain collaborative transaction method according to claim 7, characterized in that, The current committed transaction is signed using an adapter signature algorithm based on elliptic curve digital signature algorithm.
9. The on-chain and off-chain collaborative transaction method according to claim 7, characterized in that, The second transaction terminal encrypts and transmits the transaction object to the first transaction terminal, and collaborates with the first transaction terminal to generate a commitment transaction, submitting the commitment transaction to the blockchain, and also includes: If the second transaction party fails to deliver the current key to the first transaction party, or delivers an incorrect key, the second transaction party will submit the valid current commitment transaction to the blockchain. The first transaction terminal obtains a valid current commitment transaction from the blockchain, extracts the current key from the signature of the valid current commitment transaction through pre-signing, and decrypts the current encrypted data block using the extracted current key to obtain the current data block.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1-9.
Citation Information
Patent Citations
Electronic resource transaction method and device, electronic equipment and readable storage medium
CN116245646A