A decentralized cross-chain-based electronic voucher management method
Patent Information
- Application Number
- CN202611126457.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-28
- Publication Date
- 2026-09-18
AI Technical Summary
在上述跨链数据传输过程中存在如下问题:末端供应商节点的计算与存储能力有限,难以同步上层网络的全量账本以独立追溯电子凭证的层级来源;电子凭证在逐级拆分中应严格满足额度守恒,任一中间主体均不得在传输与拆分过程中篡改谱系或放大额度
1、本发明在分级区块链网络的跨链数据传输过程中实现了额度数据的隐私保护与防篡改防超发的统一;针对在传输链路中不应暴露额度明文、又须可信校验逐级拆分额度守恒的问题,在每一次拆分时为父凭证额度、各子凭证额度与驻留额度分别构建加法同态承诺,并以第一证明数据表征父额度等于各子额度与驻留额度之和的等量关系、以第二证明数据表征各额度的非负属性,二者组合为守恒证明。由此,跨链传输链路中对外呈现的仅为承诺值与守恒证明,对未持有该凭证承诺开启信息的跨链验证方而言,真实额度明文不被暴露。
Smart Images

Figure CN122783218A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, specifically to a decentralized cross-chain-based electronic credential management method. Background Technology
[0002] Construction projects typically involve a multi-tiered, cross-entity collaborative network comprised of the construction company, Tier 1 suppliers, Tier 2 suppliers, and ultimately, end-user suppliers. In this scenario, the construction company issues electronic vouchers representing accounts receivable rights based on its creditworthiness. These vouchers must be split and transferred tier by tier from Tier 1 to Tier 2 suppliers, down to the end-user suppliers, and undergo cross-chain data transmission and verification between different blockchain networks. Due to the numerous supply chain layers and the independent affiliations of participating entities, each level of entity is often deployed on different blockchain networks, necessitating cross-chain data transmission for the splitting and transfer of electronic vouchers. The following problems arise during this cross-chain data transmission process: end-user supplier nodes have limited computing and storage capabilities, making it difficult to synchronize the full ledger of the upper-layer network to independently trace the hierarchical origin of electronic vouchers; and electronic vouchers must strictly adhere to the principle of value conservation during the hierarchical splitting process, ensuring that no intermediate entity can tamper with the genealogy or inflate the value during transmission and splitting.
[0003] Existing centralized evidence storage platforms or single-chain evidence storage methods either rely on trusted third parties, which poses risks of single-point trust and single-point failure, or require end nodes to synchronize all data, which is difficult to adapt to their limited resource conditions. Furthermore, while hiding the plaintext of the quota, it is difficult to perform reliable verification of the conservation of quotas split at each level.
[0004] Therefore, it is necessary to solve how to enable end nodes to reliably verify the hierarchical lineage integrity of the target electronic certificate and the conservation of quotas in the step-by-step splitting process during cross-chain data transmission in a hierarchical blockchain network, thereby preventing lineage tampering and quota over-issuance during cross-chain transmission and splitting.
[0005] To address this, a decentralized cross-chain-based electronic credential management method is proposed. Summary of the Invention
[0006] The purpose of this invention is to provide an electronic certificate management method based on decentralized cross-chain, which obtains the vertical authentication path, original homomorphic commitment and corresponding conservation proof based on the version sequence identifier; confirms the integrity of the genealogy by comparing the aggregate digest value of the corresponding version of the main chain layer, and verifies the conservation of resource quota.
[0007] To achieve the above objectives, the present invention provides the following technical solution: A decentralized cross-chain-based electronic certificate management method, applied to a hierarchical blockchain network consisting of a main chain layer, a consortium chain layer, and a side chain layer, is characterized by comprising: When the source document is transferred to the lower layer for splitting, an additive homomorphic commitment and conservation proof of resource quota are constructed for each sub-document. The conservation proof, without exposing the plaintext, represents that the sum of the resource quota of each sub-document and the resident quota is equal to the resource quota of the parent document. The source credential, sub-credential, and splitting relationship are mapped to a genealogical authentication structure, and parent and child nodes are associated through cryptographic digests. Each node independently stores its original homomorphic commitment and aggregates the original homomorphic commitments and aggregated digest values of all direct child nodes to obtain the aggregated digest value of the node. The initial aggregate digest value of the top-level root node corresponding to the source certificate is anchored to the main chain layer. When the aggregate digest value is updated upward due to subsequent splitting, the updated top-level root node aggregate digest value is combined with the version sequence identifier and incrementally anchored to the main chain layer. When the underlying node to be verified performs cross-chain verification of the target sub-credential, it obtains the vertical authentication path to the top root node, the original homomorphic commitment, and the corresponding conservation proof based on the version sequence identifier; it confirms the integrity of the genealogy by comparing the aggregate digest value of the corresponding version of the main chain layer, and verifies the conservation of resource quota hop by hop based on the original homomorphic commitment.
[0008] During the process of the source voucher being transferred down level by level, the voucher to be split is recorded as the parent voucher, the vouchers obtained from the split are recorded as child vouchers, and the source voucher serves as the parent voucher for the first split. The initial resource limit of the parent credential is obtained as basic feature data; the basic feature data is processed based on the additive homomorphic commitment algorithm to obtain the original homomorphic commitment of the parent layer; Based on the splitting and transfer instructions, the segmentation parameters are extracted, and the basic feature data is logically mapped to the segmentation parameters to output multiple sub-voucher feature data and corresponding resident feature data. The sub-certificate feature data and the residency feature data are respectively input into the additive homomorphic commitment algorithm, and the sub-layer original homomorphic commitment and residency original homomorphic commitment of each sub-certificate are output accordingly. Based on the parent layer's original homomorphic commitment, each sub-layer's original homomorphic commitment, and the resident original homomorphic commitment, combined with the parent voucher limit, each sub-voucher limit, the resident limit, and the corresponding commitment random factor, the first proof data representing the numerical equality relationship and the second proof data representing the numerical non-negative attribute are generated. The first proof data and the second proof data are combined to generate the conservation proof.
[0009] The process of associating parent and child nodes using cryptographic digests includes: Obtain the source certificate issued by the main chain layer as the top-level root node structure data; when the source certificate sinks to the consortium chain layer or side chain layer and a splitting action occurs, extract the parent-child flow trajectory data associated with the splitting action; Based on the parent-child flow trajectory data, a descending derived child node data block is constructed in the genealogical authentication structure, and the original homomorphic commitment and aggregated digest value of the sub-layer within the derived child node data block are obtained. Byte concatenation and hash compression are performed on the original homomorphic commitments of all child layers belonging to the same parent node and the aggregate digest values of each child node to generate the aggregate digest value of the parent node; The aggregated summary value is used as the association anchor point for upward transmission and written into the data block of the directly corresponding parent node, thus establishing an irreversible topological relationship of recursive binding between upper-level nodes and lower-level nodes.
[0010] In the consortium blockchain layer or the sidechain layer, a first space block is allocated for storing the underlying computation parameters, and a second space block is allocated for storing the topology verification parameters. Write the uncompressed original homomorphic commitments generated by this node into the first space block as the input source for performing homomorphic balance verification; receive multiple lower-level original homomorphic commitments fed back from the lower-level nodes across the chain, hash and compress the multiple lower-level original homomorphic commitments to obtain the aggregated digest value of the compressed state, and write it into the second space block; When a cross-chain verification request is received, the node retrieves its computational data from the first spatial block and retrieves the upward-propagated structural verification data from the second spatial block, outputting a decoupled dual-track traceability data stream.
[0011] The process of incrementally anchoring to the main chain layer includes: Extract the initial aggregate digest value recorded for the first time in the main chain layer, assign the genesis timestamp as the basic sequence identifier and solidify it on the chain; when the consortium chain layer or side chain layer adds a split, obtain the underlying node data that triggers the change, and reconstruct it level by level from bottom to top along the vertical path of the genealogy authentication structure to derive the updated top-level root node aggregate digest value. Generate a time-incrementing derivative sequence identifier as a version sequence identifier, and concatenate it with the updated top-level root node aggregate digest value to form the main chain incremental record message; The incremental record message of the main chain is submitted to the main chain layer for consensus verification, and a reverse addressing pointer pointing to the historical sequence identifier is output in the main chain layer ledger to establish a data foundation for multi-state coexistence.
[0012] When the underlying node to be verified performs cross-chain verification of the target sub-credential, the process of obtaining the vertical authentication path to the top-level root node, the original homomorphic commitment, and the corresponding conservation proof based on the version sequence identifier includes: By deploying the underlying nodes to be verified in the sidechain layer, the time status tag carried by the target sub-credential is extracted; a cross-chain addressing instruction is generated based on the time status tag and sent to the main chain layer, and the version sequence identifier matching the feedback is received; the version sequence identifier and the network location data of the target sub-credential are used as traceability request features, and a fixed-point capture instruction is initiated in reverse step by step to the cross-chain relay gateway of the consortium chain layer. Based on the fixed-point capture instruction, all the original homomorphic commitment parameters of the main trunk on the vertical authentication path are extracted from bottom to top, and the original homomorphic commitments of each sibling node and the aggregate digest value corresponding to each sibling node are extracted to complete the hash topology, and the vertical authentication path is spliced and output. Extract the single-step conservation proof corresponding to each parent-child splitting action in the vertical authentication path and merge them into a corresponding conservation proof set; temporarily store the obtained data in the local cache of the side chain layer as input credentials for dual-track rights confirmation verification.
[0013] The process of verifying genealogical integrity by comparing the aggregated digest values of the corresponding versions in the main chain layer, and then checking resource conservation hop-by-hop based on the original homomorphic commitment, includes: In the local cache of the sidechain layer, the original homomorphic commitment parameters of the backbone in the vertical authentication path are retrieved as the initial iteration input value; combined with the original homomorphic commitments of each sibling node and the aggregated digest value corresponding to each sibling node, the upward layer-by-layer hash compression iterative calculation is performed according to the deterministic sorting, field encoding and hash compression rules consistent with the construction of the genealogical authentication structure. The top-level deduced root summary value is compared with the authoritative aggregated summary value recorded in the main chain layer. If the top-level deduced root summary value is consistent with the authoritative aggregated summary value, a genealogical integrity confirmation identifier is generated. After obtaining the confirmation identifier, the nodes of each level in the vertical authentication path are disassembled hop by hop, and the original homomorphic commitment of the parent layer and the original homomorphic commitment of each related sub-layer are obtained for each transition level. The corresponding conservation proof set is then used to input the homomorphic balance verification. When the equality signal is output throughout the entire link, a legality confirmation signal is generated and broadcast.
[0014] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. This invention achieves a unified approach to privacy protection and anti-tampering / anti-over-issuance of quota data during cross-chain data transmission in a hierarchical blockchain network. Addressing the issue of not exposing the plaintext quota in the transmission link while requiring trusted verification of quota conservation through hierarchical splitting, this invention constructs additive homomorphic commitments for the parent credential quota, each child credential quota, and the resident quota at each split. A first proof data characterizes the equivalence relationship where the parent quota equals the sum of each child quota and the resident quota, and a second proof data characterizes the non-negativity of each quota. The combination of these two forms the conservation proof. Therefore, only the commitment value and the conservation proof are presented externally in the cross-chain transmission link. For cross-chain verifiers who do not hold the commitment activation information for this credential, the true plaintext quota is not exposed.
[0015] 2. Addressing the core issues of limited resources at end nodes and the difficulty in synchronizing the entire ledger, this invention maps source credentials, sub-credentials, and splitting relationships into a genealogical authentication structure. Each node stores its own commitments and aggregates the commitments and aggregated digest values of all its direct child nodes to obtain its own aggregated digest value, enabling any underlying change to propagate step-by-step to the top-level root node. During verification, the end node retrieves a vertical authentication path from the node containing the target sub-credential to the top-level root node, necessary sibling node commitments, and conservation proofs corresponding to each split along the way, based on the version sequence identifier. The root digest can be reconstructed locally, and dual-track verification of structure and value can be completed, effectively adapting to the limited computation and storage conditions of end nodes.
[0016] 3. In response to the characteristics of numerous orders and frequent splits in the supply chain, where the root state needs to be updated level by level, this invention combines the top-level root node's aggregated summary value with a version sequence identifier that increases over time and incrementally anchors it to the main chain layer in an append-only manner. This does not overwrite existing records, and a reverse addressing pointer pointing to the previous version is written into the main chain layer ledger. This makes each historical root state linked according to the version sequence into a traceable multi-state coexistence data base, avoiding verification mismatch caused by root state updates and improving availability and historical traceability in high-frequency split scenarios. Attached Figure Description
[0017] Figure 1 This is a flowchart illustrating an electronic certificate management method based on decentralized cross-chain technology according to the present invention. Figure 2 This is a schematic diagram of the conservation proof of the present invention; Figure 3 This is a schematic diagram of the dual-track traceability data flow of the present invention. Detailed Implementation
[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] Example 1: This invention proposes a decentralized cross-chain-based electronic credential management method, the process of which is as follows: Figure 1 As shown, this is applied to a hierarchical blockchain network consisting of a main chain layer, a consortium chain layer, and a side chain layer, including: When the source document is transferred to the lower layer for splitting, an additive homomorphic commitment and conservation proof of resource quota are constructed for each sub-document. The conservation proof, without exposing the plaintext, represents that the sum of the resource quota of each sub-document and the resident quota is equal to the resource quota of the parent document. The source credential, sub-credential, and splitting relationship are mapped to a genealogical authentication structure, and parent and child nodes are associated through cryptographic digests. Each node independently stores its original homomorphic commitment and aggregates the homomorphic commitments and aggregate digest values of all direct child nodes to obtain the aggregate digest value of the node. The initial aggregate digest value of the top-level root node corresponding to the source certificate is anchored to the main chain layer. When the aggregate digest value is updated upward due to subsequent splitting, the updated top-level root node aggregate digest value is combined with the version sequence identifier and incrementally anchored to the main chain layer. When the underlying node to be verified performs cross-chain verification of the target sub-credential, it obtains the vertical authentication path to the top root node, the original homomorphic commitment, and the corresponding conservation proof based on the version sequence identifier; it confirms the integrity of the genealogy by comparing the aggregate digest value of the corresponding version of the main chain layer, and verifies the conservation of resource quota hop by hop based on the original homomorphic commitment.
[0020] The preferred process for proving conservation is as follows: Figure 2 As shown; During the process of the source voucher being transferred down level by level, the voucher to be split is recorded as the parent voucher, the vouchers obtained from the split are recorded as child vouchers, and the source voucher serves as the parent voucher for the first split. The initial resource limit of the parent credential is obtained as basic feature data; the basic feature data is processed based on the additive homomorphic commitment algorithm to obtain the original homomorphic commitment of the parent layer; Based on the splitting and transfer instructions, the segmentation parameters are extracted, and the basic feature data is logically mapped to the segmentation parameters to output multiple sub-voucher feature data and corresponding resident feature data. The sub-certificate feature data and the residency feature data are respectively input into the additive homomorphic commitment algorithm, and the sub-layer original homomorphic commitment and residency original homomorphic commitment of each sub-certificate are output accordingly. Based on the parent layer's original homomorphic commitment, each sub-layer's original homomorphic commitment, and the resident original homomorphic commitment, combined with the parent voucher limit, each sub-voucher limit, the resident limit, and the corresponding commitment random factor, the first proof data representing the numerical equality relationship and the second proof data representing the numerical non-negative attribute are generated. The first proof data and the second proof data are combined to generate the conservation proof.
[0021] The preset upper limit is determined based on the group order of the cyclic group used in the additive homomorphic commitment algorithm, so that the parent voucher limit, the limits of each child voucher, the resident limit, and the cumulative limit in any homomorphic merging process are all less than the group order.
[0022] When any node performs a downward split on its parent voucher, the specific construction process of the conservation proof is as follows: The node takes the initial resource quota of the parent voucher as the basic feature data; the node extracts the splitting parameters from the splitting flow instruction, the splitting parameters representing the quota or proportion allocated to each sub-voucher; the node performs logical mapping accordingly, the logical mapping referring to the operation of splitting and calculating the basic feature data according to the splitting parameters to obtain the feature data and resident feature data of each sub-voucher; specifically, the resident quota is calculated by subtracting the sum of the allocated quotas of each sub-voucher from the basic feature data, and the feature data and resident feature data of each sub-voucher are output; when the splitting parameters are given in the form of proportions, the node multiplies the parent voucher quota by each proportion and rounds down by the smallest resource unit to obtain the feature data of each sub-voucher, and the remainder generated by rounding is included in the resident feature data to ensure that the sum of the feature data and resident feature data of each sub-voucher is strictly equal to the basic feature data, forming the plaintext basis of the conservation equation.
[0023] The basic feature data is the plaintext value of the initial resource limit of the parent certificate; the sub-certificate feature data is the plaintext value of the resource limit allocated to each sub-certificate according to the splitting parameters; the resident feature data is the plaintext value of the resident limit that is not allocated to the lower level after the parent certificate is split and is retained in this node; all of the above feature data are the plaintext limits generated by the additive homomorphic commitment, and the sum of the sub-certificate feature data and the resident feature data is equal to the basic feature data.
[0024] Subsequently, each node selects a commitment random factor for the parent voucher limit, each child voucher limit, and the resident limit, and inputs them sequentially into the additive homomorphic commitment algorithm, outputting the parent layer original homomorphic commitment, each child layer original homomorphic commitment, and the resident original homomorphic commitment. To support subsequent equal-quantity verification, the node selects the random factor such that the parent layer random factor equals the sum of all child layer random factors and the resident random factor. The additive homomorphic commitment algorithm adopts a commitment mechanism based on the elliptic curve discrete logarithm problem: two independent generators on the elliptic curve are selected, and scalar multiplication is performed on the two generators with the resource limit and the commitment random factor, and then the results are added. The resulting curve point is the original homomorphic commitment for that limit. The sum of the two original homomorphic commitments corresponds to the commitment generated by the sum of their committed limits and the sum of the random factors, thus possessing additive homomorphism. In this embodiment, the additive homomorphic commitment algorithm selects an elliptic curve cyclic group of order with a preset large prime number, selects a first generator, and generates a second generator from public parameters using a hash-to-curve algorithm, ensuring that no entity knows the discrete logarithmic relationship between the first and second generators. The resource quota is encoded as a non-negative integer less than the group order, and the commitment random factor is uniformly and randomly selected from one to a range of group order minus one. The original homomorphic commitment is taken as the scalar product of the quota and the first generator, plus the scalar product of the random factor and the second generator. The commitment value is serialized in a compressed curve point format. Furthermore, the aforementioned elliptic curve cyclic group can be a prime-order cyclic group satisfying a preset security strength. The hash-to-curve algorithm, commitment value serialization encoding, and challenge domain separation labels in proof generation are all uniformly determined by public parameters. All resource quotas are encoded as integers with the smallest resource unit, and the preset number of bits ensures that the maximum value represented by the binary bit sequence is not less than the preset quota upper limit, and the preset quota upper limit is less than the group order of the cyclic group.
[0025] The configuration of the random factor is the key to the validity of the first proof data. The basis for this is that in the additive homomorphic commitment, the combined result of the commitment value depends on both the sum of the amount and the sum of the random factor. Only when the sum of the random factors is equal can the equality of the combined commitment result uniquely correspond to the equality of the sum of the amount.
[0026] Next, the node generates first proof data based on the above-mentioned plaintext quota and the corresponding random factor. This evidence confirms that under the selected random factor configuration, the parent commitment is indeed equal to the combined result of each sub-level and the residency commitment, thereby indirectly confirming that the parent quota is equal to the sum of each sub-quota and the residency quota. The specific amount mentioned above does not appear in the publicly available data.
[0027] Specifically, the first proof data is a non-interactive zero-knowledge equality proof generated based on the original homomorphic commitment opening relationship: the prover uses the parent certificate limit, the limits of each child certificate, the resident limit, and the corresponding commitment random factor as private witnesses, and the parent layer original homomorphic commitment, the original homomorphic commitments of each child layer, and the resident original homomorphic commitment as public inputs, proving the existence of the above private witnesses such that each original homomorphic commitment satisfies the generation relationship of the preset commitment algorithm, the parent certificate limit equals the sum of the limits of each child certificate and the resident limit, and the parent layer commitment random factor equals the sum of the random factors of each child layer commitment and the random factor of the resident commitment; the first proof data does not disclose any commitment random factor or the plaintext of the limit itself, and the verifier verifies whether the above equation holds based on the public commitment, the proof response value, and the challenge value generated by the hash function in a non-interactive manner. The challenge value is calculated by applying a preset hash function to the public input and the proof commitment value in a non-interactive manner, that is, using the Fiat-Shamir transformation to convert the interactive proof into a non-interactive proof.
[0028] The node then generates second proof data for each sub-credential limit and resident limit based on its plaintext and random factor, confirming that each limit is non-negative and does not exceed a preset limit upper limit. The preset limit upper limit is not less than the initial resource limit of the source credential, and ensures that the cumulative value of the merged original homomorphic commitments in any split does not exceed the modulus of the commitment operation, thus avoiding the construction of a superficially conserved pseudo-equivalence relationship due to modulo looping. The principle of setting the non-negativity constraint is that the commitment merging operation is performed within a finite value range. If the value range is not constrained, an attacker can make a certain sub-limit negative, thus superficially satisfying the equality relationship while amplifying other limits. The second proof data is a necessary step to plug this vulnerability.
[0029] As a specific implementation, the second proof data is generated using a commitment-based interval proof method: The node expands the amount to be proven into a bit sequence of a preset number of bits, selects a blind factor for each bit value and generates a bit commitment, and generates evidence confirming that the committed value is zero or one; then, the commitments are weighted and merged according to their bit weights, so that the merged result is bound to the original homomorphic commitment of the amount; based on the commitments, the evidence of each bit value being zero or one, and the original homomorphic commitment of the amount, the verifier is certain that the amount is composed of bits with values of zero or one combined according to their bit weights, thus being certain that the amount is between zero and a preset upper limit, but the specific value of the amount cannot be known. The preset number of bits ensures that the maximum value that the binary bit sequence can represent is not less than the preset upper limit of the amount, and the preset upper limit of the amount is less than the group order of the cyclic group used in the commitment operation; the above interval proof is performed on each sub-certificate amount and the resident amount, and the verifier merges each commitment according to its bit weight in a fixed order from low to high bits, and verifies the binding relationship between the merged result and the original homomorphic commitment of the amount.
[0030] Finally, the node combines the first and second proof data into a conservation proof, which serves as the external verification basis for the legality of this splitting action and is carried down along with the commitment and business flow. To ensure that each sub-certificate can continue the above-mentioned configuration of the sum of random factors and generate the next level conservation proof when it is split again as a parent certificate, the parent node transmits the plaintext of the amount of each sub-certificate and the corresponding commitment random factor as commitment opening information through an encrypted channel to the corresponding sub-nodes; the sub-nodes only hold this opening information locally and only disclose the commitment value to the outside world.
[0031] This invention introduces a residency quota and incorporates it into a unified conservation equation, enabling any proportion of partial splitting to undergo conservation verification without exposing plaintext, thus avoiding quota stagnation caused by partial transfers. By setting the parent layer random factor equal to the sum of the random factors of each child layer and the residency quota, the equality of the committed merging result uniquely corresponds to the equality of the sum of quotas, thereby achieving equality constraints with the first proof data. By combining the first proof data and the second proof data into a conservation proof, each split is constrained by both the equality relationship and the non-negativity attribute, providing a reliable and unified input basis for subsequent hop-by-hop conservation verification.
[0032] Preferably, the process of associating parent and child nodes through cryptographic digests includes: Obtain the source certificate issued by the main chain layer as the top-level root node structure data; when the source certificate sinks to the consortium chain layer or side chain layer and a splitting action occurs, extract the parent-child flow trajectory data associated with the splitting action; Based on the parent-child flow trajectory data, a descending derived child node data block is constructed in the genealogical authentication structure, and the original homomorphic commitment and aggregated digest value of the sub-layer within the derived child node data block are obtained. Byte concatenation and hash compression are performed on the original homomorphic commitments of all child layers belonging to the same parent node and the aggregate digest values of each child node to generate the aggregate digest value of the parent node; The aggregated summary value is used as the association anchor point for upward transmission and written into the data block of the directly corresponding parent node, thus establishing an irreversible topological relationship of recursive binding between upper-level nodes and lower-level nodes.
[0033] The "aggregation" of several original homomorphic commitments and aggregated digest values refers to the operation of concatenating the bytes according to a deterministic order and then inputting them into a one-way hash function for compression.
[0034] The specific process of constructing and aggregating the genealogical authentication structure is as follows: First, the source certificate issued by the main chain layer is taken as the top-level root node, which records the original homomorphic commitment corresponding to the source certificate's value. When a node splits the certificates it holds, the node extracts the parent-child flow trajectory data of the split action. The parent-child flow trajectory data records the allocation relationship between the parent node and each child certificate. Based on this, the node adds a derived child node data block for each child certificate under the parent node in the structure, and writes the corresponding sub-layer original homomorphic commitment of the child certificate's value to each derived child node data block. Each split at one level extends downwards in the structure by one level, so that the hierarchical depth of the structure corresponds to the cross-chain flow depth. The derived child node data block includes at least the node identifier, parent node identifier, certificate identifier, chain layer identifier, split sequence number, original homomorphic commitment, aggregate digest value, conservation proof index, version sequence identifier, time status label, and node status marker. The node status flag is used to characterize the current status of the sub-certificate corresponding to the node, and its value includes at least unconfirmed, confirmed, and reversed. After the node completes operations such as splitting, confirmation financing, and reverse reversal and is incrementally anchored, the node status flag is updated accordingly.
[0035] Subsequently, the aggregate digest value is generated layer by layer. For any parent node with direct child nodes, all its direct child nodes are deterministically sorted according to their node identifiers. Then, the original homomorphic commitments of each direct child node and the aggregate digest value of the direct child node itself are concatenated into a single byte sequence according to the sorting and length prefix encoding method, with the node identifier, original homomorphic commitment, and child node aggregate digest value fields in ascending order. Child nodes under the same parent node are arranged in ascending order of node identifier. This byte sequence is compressed by a preset one-way hash function, and a fixed-length feature code is output as the aggregate digest value of the parent node and written into the parent node's data block. The aggregate digest value of leaf nodes is the fixed feature code specified by the public parameters. The node identifier is generated by concatenating the parent node identifier and the split sequence number of the child node in this split, and is unique and comparable across the entire network. As an alternative implementation, the hash value of the original homomorphic commitment of the child node can also be used as the node identifier.
[0036] For leaf nodes that do not yet have direct child nodes, their aggregate digest value is taken as the agreed-upon default leaf value. This default leaf value is a fixed feature code pre-agreed across the entire network, used to ensure that the leaf layer has a definite input when participating in upper-layer hash compression. The above generation starts from the bottom-level node and repeats layer by layer upwards until the aggregate digest value of the top-level root node is generated.
[0037] As can be seen from the above process, since the aggregated digest value of each parent node simultaneously incorporates the commitments and aggregated digest values of its direct child nodes, when the commitment of any bottom-level node changes, the change will progressively alter the aggregated digest values at each level along the parent-child hierarchy until the aggregated digest value of the top-level root node is changed. Deterministic ordering ensures that the same group of child nodes generates consistent aggregated digest values at any node, thus avoiding inconsistencies in digests caused by differences in splicing order. This layer-by-layer recursive binding relationship provides the structural foundation for subsequently reconstructing the root digest from bottom to top based on the vertical authentication path and comparing it with the authority value of the main chain layer.
[0038] This invention achieves bottom-up, layer-by-layer recursive binding by defining the aggregated digest value of each parent node as a common hash compression of the commitments of all its direct child nodes and the aggregated digest values of each child node. This ensures that any change in a lower-level credential will necessarily propagate to the top-level root node digest, thus allowing a single authoritative root digest to represent the integrity of all lower-level states. Deterministic sorting and unified encoding rules ensure that the same group of child nodes generates consistent digests at different nodes, eliminating verification ambiguities caused by different splicing orders. The convention of default values for leaves ensures that the leaf layer has definite input when participating in upper-level compression, guaranteeing the reproducibility of recursive calculations. This makes the genealogical relationship intuitive and traceable, laying the foundation for reconstructing and verifying the root digest.
[0039] The preferred dual-track traceability data flow process is as follows: Figure 3 As shown; In the consortium blockchain layer or the sidechain layer, a first space block is allocated for storing the underlying computation parameters, and a second space block is allocated for storing the topology verification parameters. Write the uncompressed original homomorphic commitments generated by this node into the first space block as the input source for performing homomorphic balance verification; receive multiple lower-level original homomorphic commitments fed back from the lower-level nodes across the chain, hash and compress the multiple lower-level original homomorphic commitments to obtain the aggregated digest value of the compressed state, and write it into the second space block; When a cross-chain verification request is received, the node retrieves its computational data from the first spatial block and retrieves the upward-propagated structural verification data from the second spatial block, outputting a decoupled dual-track traceability data stream.
[0040] In any node of the consortium blockchain layer or sidechain layer, the dual-track storage is implemented as follows: The node divides its physical storage unit into two non-overlapping storage areas, designated as the first space block and the second space block, respectively. After generating the original homomorphic commitment corresponding to the node's credential limit at this layer, the node writes the uncompressed commitment into the first space block, which serves as the input source for subsequent homomorphic balance verification. Specifically, when it is necessary to verify whether the node's parent commitment is equal to the merged result of its child commitments and resident commitments, the corresponding commitment is retrieved from the first space block to participate in the merge operation. The first and second space blocks are two logical storage areas in the node's local state database, both using a combination of node identifier, version sequence identifier, and credential identifier as the index key. The first space block stores the original homomorphic commitment and its conservation proof index, while the second space block stores the aggregated digest value, the child node sorting list, and the on-chain version identifier, allowing for rapid retrieval for numerical verification and structural verification, respectively.
[0041] After receiving multiple underlying homomorphic commitments from its directly associated lower-level nodes via cross-chain feedback, a node hashes and compresses these commitments along with their aggregated digest values to obtain its own aggregated digest value. This aggregated digest value is then written into the second space block as structural verification data for upward propagation. When the upper layer initiates a cross-chain verification request to this node, the node's processing logic retrieves only the node's own homomorphic commitments and other computational data from the first space block for numerical verification, and only the aggregated digest value and other structural verification data from the second space block for topological verification. These two data streams are read separately from different storage areas, without overlap, thus outputting a decoupled dual-track traceability data stream. This decoupling allows numerical verification and structural verification to be performed independently and in parallel, and the data organization and retrieval of one track does not affect the other.
[0042] This invention decouples computational verification data streams from structural verification data streams at the data organization level by dividing nodes into first and second spatial blocks according to data usage. This allows for the separate storage and retrieval of original homomorphic commitments (which can participate in algebraic merging) and aggregated digest values (compressed by one-way hashing and cannot be further computed). The decoupling uses different index keys to store numerical verification data and structural verification data separately, and these are called separately during the verification process. This ensures that numerical verification and structural verification each retrieve their corresponding data, avoiding errors in the verification process caused by mixing the two and improving the clarity and maintainability of the dual-track verification.
[0043] Preferably, the process of incrementally anchoring to the main chain layer includes: Extract the initial aggregate digest value recorded for the first time in the main chain layer, assign the genesis timestamp as the basic sequence identifier and solidify it on the chain; when the consortium chain layer or side chain layer adds a split, obtain the underlying node data that triggers the change, and reconstruct it level by level from bottom to top along the vertical path of the genealogy authentication structure to derive the updated top-level root node aggregate digest value. Generate a time-incrementing derivative sequence identifier as a version sequence identifier, and concatenate it with the updated top-level root node aggregate digest value to form the main chain incremental record message; The incremental record message of the main chain is submitted to the main chain layer for consensus verification, and a reverse addressing pointer pointing to the historical sequence identifier is output in the main chain layer ledger to establish a data foundation for multi-state coexistence.
[0044] The specific implementation process of incremental anchoring is as follows: When the source credential is issued at the main chain layer, the main chain layer records the initial aggregate digest value of the top-level root node and assigns it a genesis timestamp as the basic sequence identifier, completing the first on-chain solidification. This record constitutes the starting point of the version sequence. Subsequently, whenever a split is added to the consortium chain layer or side chain layer, triggering a change in the underlying state, the node takes the data of the underlying node that triggered the change, and reconstructs it level by level from bottom to top along the vertical path of the genealogical authentication structure. The aggregate digest values of each layer along the path from the changed node to the top-level root node are recalculated in turn to obtain the updated aggregate digest value of the top-level root node.
[0045] Subsequently, a time-incrementing derivative sequence identifier is generated as the version sequence identifier for this update. This version sequence identifier is concatenated with the updated top-level root node aggregate digest value, compiled into a main chain incremental record message, and submitted to the main chain layer for consensus verification. After being uploaded to the chain, a reverse addressing pointer pointing to its predecessor version record is written into the new version record. In this way, each version in the main chain layer is linked into a traceable version sequence according to the reverse addressing pointer order, with multiple historical root states coexisting. Since the version order is ultimately determined by the main chain layer consensus, after a node obtains the version sequence identifier assigned by the consensus through splitting and uploading to the chain, the main chain layer backfills and anchors the correspondence between the identifier of the sub-credential and the version sequence identifier; the end node first matches candidate versions based on the time status tag carried by the sub-credential, and then uniquely determines the consensus version sequence identifier based on the backfilled correspondence, avoiding version mismatch caused by inconsistency between local time and consensus order.
[0046] When the end-point node to be verified subsequently initiates verification of the target sub-credential, the time status tag includes at least two of the following: the version sequence identifier confirmed by the main chain layer consensus, the block height, and the credential identifier. Based on this time status tag and the mapping relationship between the credential identifier and the version sequence identifier backfilled by the main chain layer, the end-point node to be verified uniquely matches and locates the corresponding version in the main chain layer. The authoritative root digest value corresponding to this version is used as the comparison benchmark, thereby avoiding the mismatch problem caused by multiple updates to the root state failing to match historical states. As a preferred implementation, an anchoring window can also be set, accumulating multiple consecutive split changes within the window before reconstructing and submitting them in a single batch for anchoring, thus decoupling the number of main chain writes from the underlying splitting frequency.
[0047] This invention uses incremental anchoring in an append-only manner and assigns a version sequence identifier that increments over time to each top-level root state update. Combined with reverse addressing pointers, these versions are linked into a traceable version sequence. This allows root state changes caused by frequent splitting at the lower level to be versioned and retained without overwriting in the main chain layer, forming a data foundation for multi-state coexistence. Therefore, any certificate issued or split at any historical moment can be located to its corresponding authoritative root state based on its time status tag, serving as a comparison benchmark and alleviating the problem of mismatch between root digests and historical certificates due to frequent updates.
[0048] Preferably, when the underlying node to be verified performs cross-chain verification of the target sub-credential, the process of obtaining the vertical authentication path to the top-level root node, the original homomorphic commitment, and the corresponding conservation proof based on the version sequence identifier includes: By deploying the underlying nodes to be verified in the sidechain layer, the time status tag carried by the target sub-credential is extracted; a cross-chain addressing instruction is generated based on the time status tag and sent to the main chain layer, and the version sequence identifier matching the feedback is received; the version sequence identifier and the network location data of the target sub-credential are used as traceability request features, and a fixed-point capture instruction is initiated in reverse step by step to the cross-chain relay gateway of the consortium chain layer. Based on the fixed-point capture instruction, all the original homomorphic commitment parameters of the main trunk on the vertical authentication path are extracted from bottom to top, and the original homomorphic commitments of each sibling node and the aggregate digest value corresponding to each sibling node are extracted to complete the hash topology, and the vertical authentication path is spliced and output. Extract the single-step conservation proof corresponding to each parent-child splitting action in the vertical authentication path and merge them into a corresponding conservation proof set; temporarily store the obtained data in the local cache of the side chain layer as input credentials for dual-track rights confirmation verification.
[0049] The hash topology refers to the hash topology structure formed by the aggregate digest values of each node in the genealogical authentication structure according to the parent-child hierarchical relationship; completing the hash topology refers to supplementing the original homomorphic commitments and their aggregate digest values of the missing sibling nodes in the reconstruction of the aggregate digest values of each layer along the way.
[0050] The original homomorphic commitment of the backbone refers to the original homomorphic commitment of each node at each level in the vertical authentication path.
[0051] Taking the cross-chain verification initiated by the end node to be verified against the target sub-credential as the object, the specific implementation of the capture process is as follows: The node to be verified, deployed at the sidechain layer, first extracts the time status tag carried by the target sub-credential, generates a cross-chain addressing instruction based on the time status tag, and sends it to the main chain layer. The main chain layer matches the time status tag in the version sequence and returns the corresponding version sequence identifier. The node to be verified uses this version sequence identifier and its own network location data as the traceability request feature, and reverses the process step by step to initiate a targeted capture instruction to the cross-chain relay gateway of the consortium blockchain layer.
[0052] The network location data refers to the addressing information used to locate the node where the target sub-credential is located in the hierarchical blockchain network. It includes at least the chain identifier of the chain layer where the target sub-credential is located, the node identifier of the node, and the network address of the node in its chain network. Based on the network location data, the node to be verified determines the forwarding path of each cross-chain relay gateway when initiating a reverse hierarchical fixed-point capture command.
[0053] Based on this fixed-point capture instruction, the core homomorphic commitments of each level are extracted from the bottom up along the vertical authentication path, starting from the layer where the node to be verified is located, up to the commitment of the top-level root node. Simultaneously, at each level along the path, the homomorphic commitments and aggregated digest values of each sibling node belonging to the same parent node as the core node are extracted. The reason for extracting sibling node parameters is that reconstructing the aggregated digest value of a parent node requires the commitments and aggregated digest values of all its direct child nodes, while the core commitment is only the commitment of one of its child nodes; without sibling node parameters, the aggregated digest value cannot be calculated at that level. The core commitments and corresponding sibling node parameters of each level are then concatenated hierarchically to output the vertical authentication path.
[0054] Subsequently, the single-step conservation proofs corresponding to each parent-child split action traversed by the vertical authentication path are extracted and merged into a corresponding conservation proof set, ensuring that each hop in the path has a corresponding conservation verification basis. Finally, the vertical authentication path and the corresponding conservation proof set are temporarily stored in the local cache of the sidechain layer as input credentials for subsequent dual-track rights confirmation verification. Throughout the entire fetching process, the node to be verified only fetches the vertical path related to its origin, the necessary sibling node parameters, and the conservation proofs corresponding to each split along the way, without needing to synchronize the full ledger of the consortium chain layer and the main chain layer.
[0055] This invention enables end-point nodes to accurately locate the corresponding authoritative version in the main chain layer based on the time status tag of the target sub-credential. Based on this, they can retrieve only a vertical authentication path from the target node to the top-level root node, necessary sibling node parameters, and conservation proofs corresponding to each split along the path, without synchronizing the entire upper-layer ledger. This reduces the storage and cross-chain bandwidth overhead for end-point nodes. The vertical authentication path includes both backbone commitments and sibling node commitments, ensuring that the aggregate digest value can be completely reconstructed at each level. The single-step conservation proof set is organized piecemeal according to the splitting action, ensuring that each hop-by-hop numerical verification is based on evidence at every hop of the path. Since the cross-chain relay gateway only acts as a data relay and does not provide trust endorsement, the credibility of the retrieved data is ultimately guaranteed by the independent comparison of the authoritative value in the main chain layer. Therefore, the decentralized nature and security of the retrieval process coexist, providing complete data preparation for end-point nodes to independently and lightweightly complete trusted traceability.
[0056] Preferably, the process of verifying genealogical integrity by comparing the aggregated digest values of the corresponding versions of the main chain layer, and verifying resource conservation hop-by-hop based on the original homomorphic commitment, includes: In the local cache of the sidechain layer, the original homomorphic commitment parameters of the backbone in the vertical authentication path are retrieved as the initial iteration input value; combined with the original homomorphic commitments of each sibling node, the top-level derivation root digest value is reconstructed by performing upward layer-by-layer hash compression iterative calculation. The top-level deduced root summary value is compared with the authoritative aggregated summary value recorded in the main chain layer. If the top-level deduced root summary value is consistent with the authoritative aggregated summary value, a genealogical integrity confirmation identifier is generated. After obtaining the confirmation identifier, the nodes of each level in the vertical authentication path are disassembled hop by hop, and the original homomorphic commitment of the parent layer and the original homomorphic commitment of each related sub-layer are obtained for each transition level. The corresponding conservation proof set is then used to input the homomorphic balance verification. When the equality signal is output throughout the entire link, a legality confirmation signal is generated and broadcast.
[0057] Specifically, reconstructing the top-level derivation root digest value involves combining the original homomorphic commitments of each sibling node and the aggregate digest value corresponding to each sibling node, and performing iterative calculations of hash compression layer by layer upwards according to the deterministic sorting, field encoding and hash compression consistent with the construction of the genealogy authentication structure, to reconstruct the top-level derivation root digest value.
[0058] The specific implementation of dual-track rights confirmation verification is divided into two parts: structural track and numerical track.
[0059] In terms of the structural track, the node to be verified retrieves the main homomorphic commitment and sibling node parameters from the local cache of the sidechain layer. Using the commitment of the node containing the target sub-credential as the initial iteration input, and combining it with the commitments and aggregate digest values of each sibling node in the same layer, it performs hash compression according to the deterministic sorting and splicing rules consistent with those used when constructing the genealogical authentication structure, recalculating the aggregate digest value of its parent node. Then, using this recalculated parent node aggregate digest value along with the parent node's commitment, and combining it with the parameters of each sibling node in the previous layer, it continues to hash and compress upwards, iterating layer by layer until the aggregate digest value of the top-level root node is recalculated, i.e., the top-level deduced root digest value. Subsequently, the top-level deduced root digest value is compared with the corresponding version authoritative aggregate digest value obtained from the autonomous chain layer, checking byte by byte for equality. If a digest consistency signal is output, it indicates that the structural topology from the target node to the root node has not been tampered with, generating a genealogical integrity confirmation identifier.
[0060] In terms of numerical trajectory, after obtaining the genealogical integrity confirmation identifier, the node blocks of each level in the vertical authentication path are disassembled hop by hop. For each hop, the parent layer original homomorphic commitment, all child layer original homomorphic commitments and resident original homomorphic commitments of the hop are retrieved from the first spatial block, and the single-step conservation proof corresponding to the hop is taken and input into the homomorphic balance verification. The homomorphic balance verification refers to: according to the additive homomorphic property of the original homomorphic commitments, merging the child layer original homomorphic commitments and resident original homomorphic commitments of the hop according to the predetermined merging rules, judging whether the merging result is equal to the parent layer original homomorphic commitment of the hop, and confirming the equality relationship between the parent quota and each child quota and resident quota according to the first proof data in the conservation proof, and confirming that each child quota and resident quota are non-negative according to the second proof data; when the above judgment and confirmation are both passed, the equality signal of the hop is output.
[0061] Finally, it is determined whether each hop in the entire link outputs an equality signal. If all hops are true and the structural track has already confirmed the integrity of the spectrum, the source of the target sub-credential is determined to be genuine and the entire link is conserved, and a legality confirmation signal is generated and broadcast. If the structural track comparison is inconsistent, or if the equality of any hop in the numerical track is not true, then no confirmation is granted. Thus, the structural track intercepts structural tampering implemented by forging or replacing sub-node sets, and the numerical track intercepts numerical over-issuance implemented by constructing negative numbers or amplifying quotas. The two tracks complement each other to jointly ensure the reliability of the confirmation conclusion.
[0062] This invention employs an orthogonal dual-track mechanism for rights confirmation: the structural track reconstructs the top-level root digest from bottom to top according to the vertical authentication path and compares it with the main chain layer's authority value to confirm that the topology from the target sub-credential to the root node has not been tampered with; the numerical track performs homomorphic balance verification hop-by-hop after the structural confirmation, confirming that each hop satisfies the requirement of equal and non-negative quotas based on conservation proofs. Rights confirmation is granted only after both pass. The structural track is used to detect the replacement of lineage nodes or digest inconsistencies, while the numerical track is used to detect the invalidity of the equal quota relationship or non-negativity constraint, thus covering two types of risks: structural tampering and quota over-issuance. By correcting the easily misunderstood hash collision representation to a digest consistency comparison, it is more accurate in cryptographic semantics.
[0063] Example 2: This invention can be applied to cross-chain electronic voucher management in engineering construction scenarios. The construction company, located on the main chain layer, issues source vouchers representing accounts receivable rights based on its creditworthiness. First-tier suppliers, located on the consortium chain layer, receive the source vouchers and, based on actual procurement transactions, split them into payments to multiple second-tier suppliers, retaining the unallocated portion as a resident credit line. Second-tier suppliers and end-product suppliers, such as labor subcontractors, building material suppliers, and equipment leasing companies, located on the side chain layer, hold sub-vouchers derived from these splits and often use them to apply for financing from financial institutions. This scenario has the following characteristics: engineering construction involves a large variety of supplies and a large number of orders, with frequent splits often occurring in batches within the same period; transaction amounts at each level are trade secrets and need to be hidden during cross-chain transmission; accounts receivable periods are long, with the risk of credit line refunds due to returns and quality recalls; end-product suppliers have limited resources and face the risk of repeated financing with the same sub-voucher; suppliers at the same level are often competitors and unwilling to disclose their supply relationships with the same upstream entity.
[0064] With dual-track orthogonal verification for structural anti-tampering and numerical anti-over-issuance as the main line, the quota is hidden by additive homomorphic commitment during each split and the quota is constrained by conservation proof in the hidden state; the split relationship is mapped to a genealogical authentication structure that is recursively bound layer by layer to ensure the authenticity of the source; the top root state is combined with the version sequence identifier and incrementally anchored to the main chain layer to ensure historical traceability; the end node captures the vertical authentication path and conservation proof as needed and completes dual-track rights confirmation locally to ensure lightweight and independence.
[0065] In addition to the technology of Embodiment 1, the present invention also includes the following steps; Furthermore, when a parent voucher performs a batch split on more than a preset number of sub-vouchers within the same settlement period, the second proof data of the amount and resident amount of each sub-voucher in the batch split is aggregated into a single batch non-negative proof data: using the amount and resident amount of each sub-voucher and its committed random factor as input, each non-negative evidence component is generated according to a unified interval proof method, and each non-negative evidence component is merged into a batch non-negative proof data according to a predetermined aggregation rule; when the end node verifies, a batch verification is used instead of a non-negative verification of each sub-voucher in the batch split, and the data volume and verification overhead of the batch non-negative proof data are both less than the sum of each non-negative evidence component.
[0066] In the engineering construction supply chain, Tier 1 suppliers often split payments to a large number of Tier 2 suppliers simultaneously within the same settlement cycle. If non-negative second proof data is generated and verified for each sub-certificate amount, the end node needs to perform interval proof verification for each transaction during cross-chain verification, and the computational overhead increases linearly with the number of sub-certificates. In specific implementation, when the number of splits of the same parent certificate within the same settlement cycle reaches a preset threshold, the node first generates non-negative evidence components for the amount and resident amount of each sub-certificate in the batch of splits based on plaintext and random factors, respectively. Then, according to a predetermined aggregation rule, the components are compressed and merged into a batch of non-negative proof data, which, together with the first proof data, forms the conservation proof for the batch of splits and is carried down with the certificate. When the end node performs numerical track verification, it only needs to perform a batch non-negative verification once for the batch split to confirm that all sub-quotas and resident quotas in the batch are non-negative, instead of verifying each item individually. Thus, while maintaining the non-negative constraint strength, in the implementation method of aggregation based on inner product proof, the amount of batch non-negative proof data for the batch split is lower than the sum of the amount of non-negative proof data for each item. The specific computational cost of its batch verification depends on the aggregation parameters and batch size used.
[0067] One specific implementation of the predetermined aggregation rule is aggregation based on inner product argument: A node concatenates the bit commitments and bit value evidence of each sub-certificate amount and resident amount in the batch split into a single vector, arranged according to a uniform bit weight. An inner product argument is then used to confirm that all components in this vector satisfy the constraint of taking values of zero or one. The resulting single inner product argument result is the batch non-negative proof data, and its data size increases logarithmically with the number of amounts in the batch split. During verification by the terminal node, only this single inner product argument result needs to be validated once to confirm that all sub-amounts and resident amounts in the batch split are between zero and a preset upper limit. There is no need to validate each amount individually; therefore, the data volume and validation overhead of the batch non-negative proof data are both less than the sum of the non-negative evidence components.
[0068] This design addresses the high-frequency, batch-based splitting characteristics of the supply chain by replacing individual non-negative proofs with batch non-negative proofs. This reduces the amount of non-negative proof data transmitted by the end node in the batch splitting and alleviates the data overhead caused by individual interval proofs. The actual verification overhead can be determined by the batch size and aggregation parameters.
[0069] Furthermore, the consortium blockchain layer cross-chain relay gateway consists of a threshold relay set composed of multiple cross-chain relay nodes. When the node to be verified initiates a targeted crawling instruction, the cross-chain relay nodes in the threshold relay set that exceed a preset threshold number return the backbone homomorphic commitment and sibling node homomorphic commitment of the corresponding level in the vertical authentication path, and attach their respective relay signatures to the returned data. The node to be verified only adopts the vertical authentication path when it receives a return result that reaches the threshold number and has consistent signatures for the same data content; otherwise, it determines that the crawling result is unreliable and re-initiates the crawling.
[0070] In the engineering construction supply chain, Tier 1 suppliers often simultaneously assume the function of relaying credential data to their downstream partners. A single relay node may have an incentive to refuse service or conceal parameters from its sibling nodes, such as concealing the commitments of sibling nodes from competing suppliers at the same level to hinder the completion of the hash topology at the end. In practical implementation, the consortium blockchain layer deploys multiple independent cross-chain relay nodes to form a threshold relay set, with a predetermined threshold number. After the end-user node to be verified initiates a targeted fetching instruction, each cross-chain relay node in the threshold relay set extracts the corresponding level's backbone homomorphic commitment and sibling node homomorphic commitment according to the instruction, calculates and appends its own relay signature to the extracted data, and returns it. The end-user node to be verified collects the returned results. Only when the threshold number of relay nodes provides consistent and valid signatures for the same level and data content is the data adopted as part of the vertical authentication path. If the returned results are insufficient or inconsistent, it is determined that there is relay concealment or tampering, and a new fetching attempt is initiated to the threshold relay set.
[0071] The threshold relay set includes several cross-chain relay nodes that have registered and recorded public keys through the consortium blockchain layer. The threshold number is set to be more than half the total number of relay nodes. The node to be verified only adopts the data at that level when it receives a return result that is not less than the threshold number and has a valid signature for the same level and the same data content, and whose digest is consistent. If the return result is inconsistent or less than the threshold number, the fetching is re-initiated based on the authoritative aggregate digest value already anchored by the main chain layer, and the abnormal relay node identifier is recorded.
[0072] This design replaces a single relay gateway with threshold multi-relay, ensuring that denial of service or concealment / tampering by any relay node does not affect the credibility and availability of the crawling results. It eliminates the risk of concealing peer data that may exist in the supply chain with single-point relay, and enhances the robustness of the crawling process while maintaining decentralization.
[0073] Furthermore, as an alternative implementation to the aforementioned node identifier, this embodiment uses the hash value of the original homomorphic commitment of each child node as the node identifier of that child node in the genealogical authentication structure for deterministic sorting; when the cross-chain relay gateway returns the original homomorphic commitment of the sibling node, it only returns the homomorphic commitment of the sibling node necessary for participating in the reconstruction of the aggregate digest value and its hash value as the node identifier, without returning the identity information and network location data of the supplier corresponding to the sibling node; the node to be verified completes the hash topology and reconstructs the aggregate digest value with the homomorphic commitment of the sibling node and its hash value, but cannot associate the homomorphic commitment of the sibling node with the supplier identity corresponding to other sub-credentials at the same level.
[0074] In the engineering construction supply chain, multiple second-tier suppliers under a first-tier supplier are often competitors. Each party does not want its competitors at the same level to know about its supply relationship with the first-tier supplier. However, when reconstructing the aggregated digest value, the end node needs to obtain commitments from its sibling nodes at the same level, posing a privacy risk of inferring the identity of the same-level supplier through the sibling node's commitment. In its implementation, the genealogical authentication structure, when constructing derived child nodes, does not use the supplier's identity as the node identifier. Instead, it uses the hash value obtained by one-way hashing the homomorphic commitment of the child node as the node identifier, and performs deterministic sorting and concatenation based on this. When the cross-chain relay gateway responds to the fetching command, it only returns the backbone node commitment, as well as the homomorphic commitment of the sibling nodes necessary to complete the hash topology, and their hash values as node identifiers, for each level along the way. It does not return any identity information or network location data related to the supplier corresponding to the sibling node.
[0075] The end nodes complete the topology and reconstruct the aggregated summary value accordingly, which can complete the structure track verification normally. The returned data does not contain the identity information and network location data of the corresponding suppliers of the sibling nodes, which reduces the risk that the verification party will directly know the identity of the peer suppliers from the field content level. Side channel risks such as request time and number of peer branches are controlled separately by the deployment strategy.
[0076] This design uses the commitment hash value as the node identifier and strips away the identity and location information of sibling nodes. This prevents the end node from identifying the identity of peer suppliers while completing the genealogy structure verification, thus protecting the privacy of the supply relationship between competing peer suppliers in the supply chain and compensating for the privacy leakage of peer structure information during the verification process.
[0077] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A decentralized cross-chain-based electronic certificate management method, applied to a hierarchical blockchain network consisting of a main chain layer, a consortium chain layer, and a side chain layer, characterized in that... include: When the source document is transferred to the lower layer for splitting, an additive homomorphic commitment and conservation proof of resource quota are constructed for each sub-document. The conservation proof, without exposing the plaintext, represents that the sum of the resource quota of each sub-document and the resident quota is equal to the resource quota of the parent document. The source credential, sub-credential, and splitting relationship are mapped to a genealogical authentication structure, and parent and child nodes are associated through cryptographic digests. Each node independently stores its original homomorphic commitment and aggregates the original homomorphic commitments and aggregated digest values of all direct child nodes to obtain the aggregated digest value of the node. The initial aggregate digest value of the top-level root node corresponding to the source certificate is anchored to the main chain layer. When the aggregate digest value is updated upward due to subsequent splitting, the updated top-level root node aggregate digest value is combined with the version sequence identifier and incrementally anchored to the main chain layer. When the underlying node to be verified performs cross-chain verification of the target sub-credential, it obtains the vertical authentication path to the top root node, the original homomorphic commitment, and the corresponding conservation proof based on the version sequence identifier; it confirms the integrity of the genealogy by comparing the aggregate digest value of the corresponding version of the main chain layer, and verifies the conservation of resource quota hop by hop based on the original homomorphic commitment.
2. The method for managing electronic credentials based on decentralized cross-chain as described in claim 1, characterized in that: During the process of the source voucher being transferred down level by level, the voucher to be split is recorded as the parent voucher, the vouchers obtained from the split are recorded as child vouchers, and the source voucher serves as the parent voucher for the first split. Obtain the initial resource limit of the parent credential as basic feature data; process the basic feature data to obtain the original homomorphic commitment of the parent layer; Extract the segmentation parameters based on the splitting and transfer instructions, perform logical mapping between the basic feature data and the segmentation parameters, and output the sub-voucher feature data and the corresponding resident feature data. The sub-certificate feature data and the residency feature data are respectively input into the additive homomorphic commitment algorithm, and the sub-layer original homomorphic commitment and residency original homomorphic commitment of each sub-certificate are output accordingly. Based on the parent layer's original homomorphic commitment, each sub-layer's original homomorphic commitment, and the resident original homomorphic commitment, combined with the parent voucher limit, each sub-voucher limit, the resident limit, and the corresponding commitment random factor, the first proof data representing the numerical equality relationship and the second proof data representing the numerical non-negative attribute are generated. The first proof data and the second proof data are combined to generate the conservation proof.
3. The method for managing electronic credentials based on decentralized cross-chain as described in claim 1, characterized in that: The process of associating parent and child nodes using cryptographic digests includes: Obtain the source certificate issued by the main chain layer as the top-level root node structure data; when the source certificate sinks to the consortium chain layer or side chain layer and a splitting action occurs, extract the parent-child flow trajectory data associated with the splitting action; Based on the parent-child flow trajectory data, a descending derived child node data block is constructed in the genealogical authentication structure, and the original homomorphic commitment and aggregated digest value of the sub-layer within the derived child node data block are obtained. Byte concatenation and hash compression are performed on the original homomorphic commitments of all child layers belonging to the same parent node and the aggregate digest values of each child node to generate the aggregate digest value of the parent node; The aggregated summary value is used as the association anchor point for upward transmission and written into the data block of the directly corresponding parent node, thus establishing an irreversible topological relationship of recursive binding between upper-level nodes and lower-level nodes.
4. The method for managing electronic credentials based on decentralized cross-chain as described in claim 1, characterized in that: In the consortium blockchain layer or the sidechain layer, a first space block is allocated for storing the underlying computation parameters, and a second space block is allocated for storing the topology verification parameters. Write the uncompressed original homomorphic commitments generated by this node into the first space block as the input source for performing homomorphic balance verification; receive multiple lower-level original homomorphic commitments fed back from the lower-level nodes across the chain, hash and compress the multiple lower-level original homomorphic commitments to obtain the aggregated digest value of the compressed state, and write it into the second space block; When a cross-chain verification request is received, the node retrieves its computational data from the first spatial block and retrieves the upward-propagated structural verification data from the second spatial block, outputting a decoupled dual-track traceability data stream.
5. The method for managing electronic credentials based on decentralized cross-chain as described in claim 1, characterized in that: The process of incrementally anchoring to the main chain layer includes: Extract the initial aggregate digest value recorded for the first time in the main chain layer, assign the genesis timestamp as the basic sequence identifier and solidify it on the chain; when the consortium chain layer or side chain layer adds a split, obtain the underlying node data that triggers the change, and reconstruct it level by level from bottom to top along the vertical path of the genealogy authentication structure to derive the updated top-level root node aggregate digest value. Generate a time-incrementing derivative sequence identifier as a version sequence identifier, and concatenate it with the updated top-level root node aggregate digest value to form the main chain incremental record message; The incremental record message of the main chain is submitted to the main chain layer for consensus verification, and a reverse addressing pointer pointing to the historical sequence identifier is output in the main chain layer ledger to establish a data foundation for multi-state coexistence.
6. The method for managing electronic credentials based on decentralized cross-chain as described in claim 1, characterized in that: When the underlying node to be verified performs cross-chain verification of the target sub-credential, the process of obtaining the vertical authentication path to the top-level root node, the original homomorphic commitment, and the corresponding conservation proof based on the version sequence identifier includes: By deploying the underlying nodes to be verified in the sidechain layer, the time status tag carried by the target sub-credential is extracted; a cross-chain addressing instruction is generated based on the time status tag and sent to the main chain layer, and the version sequence identifier matching the feedback is received; the version sequence identifier and the network location data of the target sub-credential are used as traceability request features, and a fixed-point capture instruction is initiated in reverse step by step to the cross-chain relay gateway of the consortium chain layer. Based on the fixed-point capture instruction, all the original homomorphic commitment parameters of the main trunk on the vertical authentication path are extracted from bottom to top, and the original homomorphic commitments of each sibling node and the aggregate digest value corresponding to each sibling node are extracted to complete the hash topology, and the vertical authentication path is spliced and output. Extract the single-step conservation proof corresponding to each parent-child splitting action in the vertical authentication path and merge them into a corresponding conservation proof set; temporarily store the obtained data in the local cache of the side chain layer as input credentials for dual-track rights confirmation verification.
7. The method for managing electronic credentials based on decentralized cross-chain as described in claim 6, characterized in that: The process of verifying genealogical integrity by comparing the aggregated digest values of the corresponding versions in the main chain layer, and then checking resource conservation hop-by-hop based on the original homomorphic commitment, includes: In the local cache of the sidechain layer, the original homomorphic commitment parameters of the backbone in the vertical authentication path are retrieved as the initial iteration input value; combined with the original homomorphic commitments of each sibling node and the aggregated digest value corresponding to each sibling node, the upward layer-by-layer hash compression iterative calculation is performed according to the deterministic sorting, field encoding and hash compression rules consistent with the construction of the genealogical authentication structure. The top-level deduced root summary value is compared with the authoritative aggregated summary value recorded in the main chain layer. If the top-level deduced root summary value is consistent with the authoritative aggregated summary value, a genealogical integrity confirmation identifier is generated. After obtaining the confirmation identifier, the nodes of each level in the vertical authentication path are disassembled hop by hop, and the original homomorphic commitment of the parent layer and the original homomorphic commitment of each related sub-layer are obtained for each transition level. Homomorphic balance verification is performed in combination with the corresponding conservation proof set. When the equality signal is output throughout the entire link, a legality confirmation signal is generated and broadcast.