System and method for non-parallelized mining on proof-of-work block chain network

A non-parallelizable mining algorithm using sequential operations addresses the challenges of maintaining blockchain network security and decentralization by ensuring all miners compute a deterministic proof of work solution, reducing resource costs and preventing centralization.

JP2025100540AActive Publication Date: 2025-07-03NCHAIN LICENSING AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025037406
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2019-05-16
Filing Date
2025-03-10
Publication Date
2025-07-03
Estimated Expiration
2040-04-28

AI Technical Summary

Technical Problem

Existing blockchain networks face challenges in maintaining consensus and security while reducing computational resource costs, energy usage, and hardware imbalances that lead to potential centralization.

Method used

Implementing a non-parallelizable mining algorithm that uses essentially sequential operations, such as recursive functions and modular exponentiation, to secure and establish consensus in the blockchain network, ensuring all miners compute a deterministic proof of work solution before adding blocks.

Benefits of technology

This approach maintains network security and decentralization by making it difficult for any entity to dominate the network, reduces computational resource requirements, and prevents centralization, while ensuring consistent block generation times.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025100540000001_ABST
    Figure 2025100540000001_ABST
Patent Text Reader

Abstract

To provide a method of preserving the consensus mechanism and security.SOLUTION: The present disclosure provides methods and systems for ensuring the security of a block chain and an associated network, and for enabling the establishment of consensus regarding a state of the block chain. A method of the disclosure may be implemented by one or more nodes on a block chain network, using a non-parallelizable algorithm to calculate an output based on a computational difficulty parameter, a hash of at least one block chain transaction, and / or a hash of at least one block chain block header. The non-parallelizable, inherently sequential algorithm comprises at least one of the following operations or a combination thereof: a recursive operation, a modular exponentiation and / or a repeated squaring operation.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to methods and systems for improving the processing efficiency, reliability, security, and resource requirements for computational tasks executed within a network. The present disclosure is particularly suitable for use related to, but not limited to, blockchain-related mining, verification, and resource transfer.

Background Art

[0002] As used herein, the term "blockchain" is used to include all forms of electronic computer-based distributed ledgers. These include consensus-based blockchain and transaction chain technologies, permissioned and non-permissioned ledgers, shared ledgers, public blockchains and private blockchains, and variations thereof. The most widely known application of blockchain technology is the Bitcoin ledger, although other blockchain implementations have been proposed and developed. Although Bitcoin may be referenced herein for purposes of convenience and illustration, it should be noted that the present disclosure is not limited to use with the Bitcoin blockchain, and alternative blockchain implementations and protocols fall within the scope of the present disclosure. The term "user" may refer to a human or a processor-based resource herein. The term "Bitcoin" is used herein to include any version or variation derived from or based on the Bitcoin protocol.

[0003] A blockchain is a peer-to-peer electronic ledger implemented as a computer-based decentralized distributed system composed of blocks, where each block is composed of transactions. Each transaction is a data structure that encodes the transfer of control of digital assets / resources among participants in a blockchain system and includes at least one input and at least one output. Each block contains the hash of the previous block for that block and, together, forms a chain to create a permanent and immutable record of all transactions written to the blockchain from its beginning. Transactions contain a small program called a script embedded within their inputs and outputs that specifies how and by whom the output of the transaction can be accessed. On the Bitcoin platform, these scripts are written using a stack-based scripting language.

[0004] For a transaction to be written into the blockchain, the transaction must be "validated". Nodes on the network ("miners") ensure that each transaction is valid, and invalid transactions are rejected from the network. The software client installed on the node checks whether the transaction complies with the protocol rules of the blockchain, and similarly executes the locking script and the corresponding unlocking script to perform this validation operation on unspent transactions. If the execution of the locking script and the unlocking script evaluates to TRUE, the transaction is valid. Therefore, for a transaction to be written into the blockchain, the transaction must: i) be validated by the first node that receives the transaction, and if the transaction is validated, the mining node relays it to other nodes in the network; ii) be added to a new block constructed by the miner; and iii) be mined, i.e., added to the public ledger of past transactions.

[0005] To build a new block, miners compete by performing resource-intensive work, with the goal of first finding a solution to a calculation (a "proof of work" called "PoW" or "nonce" in the art), sometimes referred to as a "puzzle" or "challenge" in the relevant technical field. The difficulty of the puzzle can be adjusted over time so as to affect the rate at which new blocks are added to the blockchain. This is done using a variable difficulty parameter that affects how difficult it is to find a solution, such that the protocol can maintain an average time between new blocks at a relatively consistent rate as the network's hash power changes. In Bitcoin, miners use the SHA256 hash algorithm to find PoW, which produces a hash value that is less than or equal to the current difficulty level (parameter) set by the network protocol when hashed.

[0006] If a miner is the first to find a PoW for the current puzzle, that miner generates a new block, which is then broadcast in a message to other miners on the network. The new block must contain a verifiable PoW if other miners are to accept it as valid. Thus, mining provides a consensus mechanism that ensures that nodes on the network are synchronized and approve with respect to the legitimate and current state of the blockchain. Mining also protects against some types of potential network attacks and provides security to the network.

[0007] In the early stages of Bitcoin, the computational requirements for mining were small enough that miners could use general-purpose computers equipped with standard CPUs. However, miners using more powerful computers have a competitive advantage over those using less powerful ones. This incentive, combined with the historical increase in puzzle difficulty, has led to the widespread use of application-specific integrated circuit (ASIC) mining devices. Moreover, groups of ASIC devices can be connected to share the work involved in finding PoW solutions. In such cases, different machines can be used to try different PoW nonces or ranges thereof. Thus, the mining algorithm can be parallelized across devices.

[0008] However, more powerful devices are more expensive and require more energy for operation and cooling. Some have argued that the hardware imbalance fosters the potential concentration of mining power within the network, leading to possible drawbacks or vulnerabilities. These concerns have prompted interest in the development of "ASIC-resistant" mining solutions. However, the proposed solutions involve modifications to the PoW algorithm to change the collision-resistant SHA256 hash algorithm into a so-called "bandwidth-intensive" function, and the results are limited or controversial.

[0009] Therefore, it is necessary to solve the (at least) technical problem of how to maintain the consensus mechanism and security provided by competing nodes on the blockchain network while reducing the required costs, energy usage, and computational resources and maintaining the advantages of a decentralized network.

[0010] The present disclosure addresses at least these technical concerns by providing aspects and embodiments comprising non-parallelised mining (NPM) techniques, hardware and software configurations, networking techniques and methods, and combinations thereof, using non-parallelisable consensus mechanisms. The present disclosure may use essentially sequential algorithms to provide security to a blockchain and to establish consensus in the state of the blockchain.

[0011] As used herein, the term "sequential algorithm" is used to refer to an algorithm that must be executed sequentially from start to finish without other processes running in parallel. Examples include iterative numerical methods such as Newton's method (Lipson, John D., "Newton's method: a great algebraic algorithm", Proceedings of the Third ACM Symposium on Symbolic and Algebraic Manipulation, ACM, 1976), and algorithms that can be mathematically expressed using recurrence relations.

[0012] The term "essentially sequential" (or "non-parallelisable", as it may also be referred to herein) algorithm is used herein to refer to a sequential algorithm that cannot be optimised using parallelisable routines / subroutines. Although the phrase is not strictly defined within the art, the definition used herein (see the following detailed description in "adjustable difficult mining functions") should be noted to be consistent with the intuitive use of the terms and definitions that exist in the literature (Greenlaw, Raymond, "A model classifying algorithms as inherently sequential with applications to graph searching", Information and Computation 97.2 (1992): 133-149).

PRIOR ART DOCUMENTS

NON-PATENT DOCUMENTS

[0013] [Non-Patent Document 1] Lipson, John D., "Newton's method: a great algebraic algorithm", Proceedings of the Third ACM Symposium on Symbolic and Algebraic Manipulation, ACM, 1976 [Non-Patent Document 2] Greenlaw, Raymond, "A model classifying algorithms as inherently sequential with applications to graph searching", Information and Computation 97.2 (1992): 133 - 149 [Non-Patent Document 3] Rivest, Ronald L., Adi Shamir, and David A. Wagner, "Time-lock puzzles and timed-release crypto", (1996) [Summary of the Invention] [Means for Solving the Problems]

[0014] Referring to FIG. 1, the present disclosure provides an alternative and improved system and method for blockchain mining. A non-parallelizable mining function or algorithm is used to mine blockchain transactions (UTXOs) that are to be added to the blockchain ledger.

[0015] In summary, this can be achieved by the following. [Step 1]: Identify one or more transactions (UTXOs) from a plurality of states of transactions (UTXOs). This plurality of states may be a mempool by the blockchain protocol, blockchain protocol, and blockchain network related to the blockchain. In one or more embodiments, this is a proof-of-work blockchain / protocol / network. [Step 2]: If applicable, generate a reward transaction (TX0) according to the protocol. [Step 3]: Generate a notation R for the selected transaction (i.e., block). [Step 4]: Use a non-parallelizable mining algorithm to provide a computational output C that is a proof of the computational solution for the block. This may also be referred to as a proof-of-work solution. [Step 5]: Send a message to the nodes on the blockchain network, where the message comprises the notation, the solution C, and TX0 (if applicable). [Step 6]: Upon receiving the message, the network nodes attempt to verify the block. If verified by the majority of the miners on the network, the block is added to the blockchain; otherwise, the block is rejected and not added to the blockchain.

[0016] Next, by way of example only and with reference to the accompanying drawings, aspects and embodiments of the present disclosure are described.

Brief Description of the Drawings

[0017]

Figure 1

Figure 2

Modes for Carrying Out the Invention

[0018] Here, an aspect of the present disclosure is described that has a generalized structure for a public chronological ledger of transaction data, sometimes referred to as a non-parallelizable mining (NPM) blockchain. It comprises the following elements. I. Transactions existing within the block, II. Blocks comprising a set of transactions, and III. Encrypted links between the blocks.

[0019] When taken together, these elements combine to form a blockchain ledger, such that all transaction data is aggregated into blocks of a standard format where consecutive blocks are related to each other, forming a chain by including an encrypted link (e.g., a hash) to the previous block.

[0020] Components of the Exemplary Embodiment Next, components that may be utilized in accordance with one or more embodiments of the present disclosure, and terms used herein to refer to them, will be described.

[0021] A blockchain transaction (TX) is a standardized data structure that encodes the transfer of some digital assets or resources from a first party to a second party. At a high level, each transaction comprises inputs and outputs. Each input of a transaction specifies the following information. i. A pointer to a record, i.e., a previous output on the ledger where the digital asset exists. ii. An unlocking condition that gives the sender (i.e., the first party) the authority to transfer (i.e., consume) the ownership of the asset. This is typically a digital signature or a secret known only to the first party.

[0022] Each output of a transaction specifies the following information. i. The recipient (i.e., the second party) to whom the ownership of the digital asset is transferred. ii. A locking condition that specifies how the recipient may unlock it next and thus "consume" the digital asset.

[0023] Each transaction to be recorded on the blockchain ledger is assigned a unique identifier. The identifier chosen for use with one or more exemplary embodiments herein is referred to as a transaction identifier. The identifier is a hash of the transaction TX and a second parameter X. Y(TX,X)=H(TX||X)

[0024] The parameter X is the hash of the previous block header. The transaction also includes a timestamp T that depends on when the transaction was first created, rather than when the miner / network node first saw them. TX including.

[0025] In addition, each transaction includes a timestamp to indicate when they were created. The non-parallelized mining algorithm used by the blockchain embodiments described in this disclosure uses timestamped transactions.

[0026] The reward transaction, denoted TX0, is the first transaction in each block and distributes newly minted NPM coins to the miner who first creates a valid block. Except for the fact that it can have only one input, the reward transaction is structurally identical to a standard transaction as described above. This is because the total reward for mining a block is interpreted as a combination of a standard block reward and a transaction fee. This means that there is no need for a "input" in the normal sense, and thus the input field is null and can be used to store any data. Note also that generally, the reward transaction, being always the first transaction in the block, does not require a timestamp.

[0027] A block (B) is a standardized data structure that aggregates a set of transactions and is added to a public blockchain digital ledger. At a high level, each block comprises a set S of standard transactions, a single reward transaction, and a block header. The transaction set S is S := {TX1, TX2,..., TX N} a complete set of N transactions contained within the block, written as

[0028] The reward transaction TX0 may be included in each block and is used to give a reward to the miner responsible for adding that block to the blockchain. This transaction is not considered part of the transaction set S even if they are both included in the same block. According to one or more protocols, it should be noted that if a predetermined mining threshold has been reached, the reward transaction may not need to be included in the block or may be stopped from being included.

[0029] The block header Φ may comprise many fields of data related to the block of transactions it contains, such as the block number, the time the block was added to the blockchain, or the version of the blockchain protocol rules being used. However, the important elements that must appear in the block header are i. The cryptographic link X, ii. The representation R := G(TX0, S) of TX0 and the transaction set S (where G is an algorithm), and iii. The computational solution for the mining algorithm

Number

[0030] The requirements for algorithm G are that it must take as input the entire set S of transactions in a block plus the reward transaction TX0, and it must return a single value R that can be used to represent these N + 1 transactions. A suitable choice for G turns out to be the Merkle tree generation algorithm, where R will correspond to the Merkle root.

[0031] The cryptographic link can take one of many forms, such as a digital signature or a hash digest. For the purposes of this specification, and for ease of reference, by way of example, cryptographic link X is considered to be the hash of the previous block header.

[0032] Computational solution [Number] (i.e., C) is a value that should be interpreted as the output of a non-parallelized mining technique / algorithm. This solution must be computed before the block can be added to the blockchain and represents a proof of computation without which the block cannot be considered valid. The PoC solution described herein can be seen as similar to the Bitcoin PoW puzzle solution, i.e., a "nonce". It may also be referred to as C herein. This PoC solution is a global solution to a computationally difficult but deterministic problem that is solved by the nodes implementing the embodiments of the present disclosure.

[0033] In order to connect blocks in a meaningful way such that the blocks form an immutable chain, there needs to be a way to link one block to the next. This is achieved by constructing a cryptographic link X between a block and its immediate predecessor. The required properties of such a cryptographic link are as follows. i. Each link must be one-way. ii. Each link must connect exactly two blocks. iii. Each pair of connected blocks must appear consecutively in the blockchain.

[0034] These features form the basis for choosing the cryptographic link X such that it is the hash of the previous block header, and the cryptographic link X is X i := H(Φ i-1 ) defined as such, where the index i indicates the block number. Here, again, the one-way cryptographic hash function is denoted by H. Each new block, as it is formed, must include within its own block header Φ i the hash of the previous block header H(Φ i-1 ). The term "previous block" is used herein to mean the most recently appended block that should be successfully appended to the blockchain. This means that, working backwards through the chain until the first block B0 is reached, each new block is successively and directly connected to the last block.

[0035] The rules governing the state of the NPM blockchain are called its protocol rules. These rules can be summarized as follows. i. The format of transactions, ii. The format of blocks, iii. The rules for validating transactions, iv. The rules for validating blocks, and v. The way in which new blocks are added to the ledger (via the mining process).

[0036] Validation of Transactions In the most common case, a valid transaction must be in a standard format acceptable under the protocol rules. The general rules for transactions are as follows. · The total input value must be greater than or equal to the total output value. · The transaction timestamp must be less than or equal to the block timestamp.

[0037] According to the embodiments of the NPM blockchain system disclosed in this specification, no further conditions need to be imposed for a transaction to be valid. However, one or more embodiments of the NPM blockchain may require additional validation rules that can be imposed on transactions, such as a maximum size or maximum transfer of digital assets per transaction, limitations on the number of inputs / outputs, and requirements on input data and output data, so that digital asset ownership can be correctly established.

[0038] Block Validation A valid block must include the following. i. A set S of exactly N standard transactions:={TX1, TX2,..., TX N}, ii. Exactly one reward transaction T0, iii. A valid cryptographic link X to the previous block, iv. A notation R that matches the transaction set S and TX0, and v. A valid proof of computation C.

[0039] A block is valid and may be added to the blockchain if it meets all five of these criteria. Note that at any given time, there may be several valid candidate blocks, which differ only in the reward transaction and who the mining reward is paid to. This situation occurs when multiple miners independently calculate a proper PoC proof C.

[0040] The mining process serves to determine which of these many candidate blocks, i.e., the candidate blocks from each successful miner, will be added to the blockchain. In short, there is always a miner who "first" finds the proof of computation C, which is their block with their reward transaction that is added to the blockchain according to the mining algorithm of the protocol. Next, attention is directed to the description of the non-parallelizable mining (NPM) method that can be used by the NPM mining nodes and NPM blockchain embodiments disclosed herein.

[0041] Non-parallelizable consensus mechanism Embodiments of the present disclosure utilize mining techniques to non-centrally obtain consensus in the state of the blockchain. Nodes implementing this technique use a non-parallelizable (essentially sequential, or also called "embarrassingly sequential") algorithm to add new blocks to the blockchain. Also, consensus in the state of the blockchain is obtained at regular intervals.

[0042] This ensures that the entire network can approve new blocks using an algorithm that is not inferior to parallel computing, avoiding at least the above technical difficulties. In turn, this makes it difficult for any entity or group mining through CPU clustering or imbalance in hardware to increase their dominance (and thus potential control) of the network.

[0043] The non-parallelizable mining approach requires that all miners on the network compete to first find the PoC solution for the candidate block. These nodes adopt protocol rules that can include at least the following requirements. 1. Miners attempt to mine exactly N transactions in a block, where N is a predetermined constant. 2. Miners attempt to mine the same candidate blocks within each cycle. 3. Mining cycle time: a. The expected value for the mining cycle time is always longer than the block validation time. b. There is a random dispersion within the mining cycle time. 4. As will be described in more detail below, the network latency is sufficiently small.

[0044] Obtaining prior agreement Miners need to approve the same set of transactions to be included in their candidate blocks. In other words, miners approve the set and order of transactions to be included in their candidate blocks. To achieve this, nodes implement at least the following rules. · Each transaction is timestamped at the time of creation. · All transactions are ordered by their timestamps. · The protocol can identify the moment represented by the timestamp for each candidate block. For block B i this timestamp is called T Bi .

[0045] To prevent malicious users from choosing timestamps that are much earlier than necessary, the protocol according to one embodiment of the present disclosure requires nodes to reject any transaction having a timestamp earlier than the previous block timestamp already recorded on the blockchain, i.e., added to the blockchain. This ensures that all miners have the same set of transactions in their candidate blocks, except for the reward transaction (which can be seen as similar to the coinbase transaction in Bitcoin).

[0046] Common transaction set According to one or more embodiments, all mining nodes on the network have the same set of transactions (dynamic memory pool) to be included in the next block. This ensures that all miners attempt to mine a block containing the same transactions (other than the reward transaction). This requires at least the following conditions. · Each transaction is timestamped at the time of creation. · All transactions are ordered by their timestamps (global transaction ordering). · T Bi All transactions having a timestamp earlier than that of block B i must be included in it.

[0047] The number N of transactions mined in each block B i is equal to the total number of transactions (and validated) found between i This will be explained in more detail below.

Number

[0048] Adjustable Difficulty Mining Function

[0049] The difficulty is estimated by the number of operations performed in the mining function. A standard mining function can be defined as follows. F(Y1,…,Y F(Y1,…,Y N ,X,t) However, {Y1,...,Y N} is a set of N transaction identifiers, X is the previous block hash, and t is the difficulty parameter included in the block header. Important features of the mining protocol or mining function disclosed herein include the following. · Non-parallelizable algorithm: The algorithm requires the calculation of intermediate outputs that can only be executed sequentially, not in parallel. The calculation of intermediate outputs takes an input that is the output of the previous intermediate calculation and in turn provides that result / output to the subsequent intermediate calculation. This may be repeated until a stop condition is encountered. · Adjustable computational difficulty uses the integer parameter t. · The input includes transaction identifiers / block header hashes and difficulty parameters. · Calculating F requires the target number K of arithmetic operations.

[0050] A canonical example of a non-parallelizable algorithm is recursive, where the output of a function is used as an input in the next instantiation of the same or another function. Another example is modular exponentiation or repeated squaring. See Rivest, Ronald L., Adi Shamir, and David A. Wagner, "Time-lock puzzles and timed-release crypto", (1996).

[0051] An example of an algorithm that uses both recursion and modular exponentiation is provided as follows by way of example. {Y0,...,Y N}, on the premise that

Equation

Equation

[0052] Mining operation target The global transaction set and the mining function require the miner to perform K arithmetic operations, where K=K(N,t) is true.

[0053] This ensures that the block generation time T G is consistent and can be controlled by the network. Assuming that F is a function with N recursions, K is linear in N, the difficulty parameter t is adjustable and does not directly depend on the transactions, and as a result, a wide range of K values can be obtained.

[0054] As an example, using F as described above, assume the difficulty is t = 1000. At this time, calculating F requires 2×1000 = 2000 repeated squaring operations for each Y iS , so K = O(2000N). Alternatively, when t = 1, K = O(2N). t can be adjusted and included in the block header.

[0055] Example 1: Maximum number of transactions per block One implementation of the mining technique requires at most N transactions in a block, where N is a constant value. By fixing N, the variability of K can be controlled through t alone.

[0056] This will increase the miner's computing time and reduce their probability of being the first miner to successfully mine a block, so it is worth noting that miners are not motivated to include more than N transactions in a block.

[0057] Dummy transaction identifier If the number of available transactions in the memory pool is less than N, a dummy transaction identifier can be defined. Assume that the total number of transactions in the memory pool is n (n ≤ N) with transaction identifiers Y1,..., Y n Assume it is associated with n. Create a sequence of dummy transaction identifiers as a hash chain generated by using Y n as a seed. Y n+i+1 = H(Y n+i ||X)

[0058] These dummy transaction identifiers are then used as input together with standard transaction identifiers in the mining function. Note that the dummy transaction identifiers can only be generated sequentially.

[0059] Example 2: Variable number of transactions per block An alternative implementation allows for a variable N value by fixing

Number

[0060] Network latency Network latency should preferably be negligible or reasonably close to 0. This means that messages sent from one mining node to another are propagated across the entire network within a short time period. More specifically, the message transmission time should be much shorter than the distributed mining cycle time among miners, Network latency << σ 2 (T G ) where σ 2 (T G ) is the variance of the block generation time for the network. Recall that this variance is just the difference in the sequential calculation speeds among miners. If the first miner, Alice, obtains a successful proof of the solution before the second miner, Bob (due to the mining cycle variance), it is almost certain that Alice will need to be able to propagate her solution to Bob within a short enough time that it is unlikely Bob will find the solution before receiving Alice's solution message.

[0061] Mining cycle Composition of candidate block ~ Miner Alice Referring to Figure 1,

Number

Number

Number

[0062] By setting a wide range of transaction times, fluctuations in block generation time are allowed. B i The block timestamp for is less than the upper limit of the transaction time window, that is,

Number

[0063] If the block generation time exceeds 3E(T G ), then ~although that is extremely unlikely~ the transaction must not be excluded / relayed by the network within the time range

Number

[0064] She then proceeds as follows. 2. Step 2: Alice constructs the reward transaction TX0. Note that this step is optional since the reward transaction does not always have to be included in the block. 3. Step 3: If the reward transaction is to be included, Alice calculates the notation R of all transactions in the block excluding the reward transaction. 4. Step 4: Alice mines the block by performing one embodiment of a non-parallelizable mining technique as follows.

Number

Number

[0065] Note: For clarity and ease of understanding, the exemplary mining function described above was used. However, generally, Step 2 is the execution of F to find the proof of computation C.

[0066] Verification To verify h(C), the miner must find the proof of computation solution C. Upon receiving Alice's PoC message, other miners continue their work to find their own solutions. When a miner finds his own solution, he can compare it with Alice's solution and perform the verification of her version of C. He does this by constructing Alice's block by adding her reward transaction and comparing the hash value of the block header with h(B i ) and if they are equal, Bob deletes all other threads of the computation and continues to compute the thread that assumes Alice's block is a proper block. If they are not equal, Bob finds the thread of the next received Y M value that matches the hash value and continues from that thread.

[0067] Bob is motivated to mine new blocks as quickly as Alice, otherwise Alice can create the longest chain to claim all the rewards.

[0068] Mining cycle time Block generation time Block generation cycle time T iG is the time spent by some i-th miner to generate a block using the proposed mining function F, as indicated by T i G The block generation time is the time spent by a given miner to compute a proper proof C of the calculation for a candidate block.

[0069] This cycle time T i G is assumed to be a continuous normal distribution random variable. The expected value, variance, and standard deviation in the mining cycle time are shown as follows, respectively. E(T G ), σ 2 (T G ), σ(T G ).

[0070] The block generation time is a parameter of the mining technique, meaning that the expected value can be scaled to the duration according to the implementation form. For example, it may be desirable to set E(T G ) ~ 10 minutes for one implementation form and E(T G ) ~ 1 minute for another implementation form. In either case, according to the set of inequalities E(T G ) ∝ m, m ∝ N, m ∝ t the expected time is scaled by increasing the number of operations m performed in the mining technique, where N is the number of transactions in the block and t is the difficulty parameter.

[0071] Block validation time Consider two miners M A and M B attempting to mine the same candidate block. The observed times spent by these miners to successfully mine the block are T A G and T B GShown by, both of which are governed by the normal distribution defined above.

[0072] For a given cycle, T A G <T B G in the case of, M A is the first miner who should successfully mine the candidate block by definition. The first miner M A calculates and broadcasts their proof of calculation C A If a given block is successfully mined by calculating and broadcasting it, the second miner M B (and all other miners) independently completes the mining cycle and validates the block by verifying that the proof provided by M A is equal to their independently calculated proof of calculation C B . C B =C A In the case of, the block is considered valid by the second miner. The time spent by the second miner M B to perform this validation process is

Number

Number

[0073] For a sufficiently large network of miners, the block validation time

Number

[0074] T j G Assuming that 99.7% of among are within 3 standard deviations of E(T G ), then [Number] the following approximation can be made.

[0075] Given the assumption of the minimum generation time described above, the expected block time can be calculated as [Number] and the standard deviation [Number] means that the range for the activation time is [Number] which means that in the worst case, that is, (i) M A completes the mining algorithm first and M B completes the algorithm as late as possible [RHS condition], and (ii) M A completes the mining algorithm at any time and M B completes the algorithm only a short time later [LHS condition], can be understood to limit the activation time.

[0076] Thus, in one or more embodiments of the present mining algorithm, the block generation time scale T i G is significantly larger than the block validation time scale

Number

Number

Number

[0077] Thus, for the participating network nodes, the variance in the block generation time is significantly shorter than the expected block generation time itself. Given that the expected variance is on the order of seconds and the reference expected time of E(T G ) ~ 10 minutes, this is a reasonable assumption.

[0078] In practice, the mining technique can result in one of three common scenarios. From the perspectives of honest miners Alice and Bob, denoted as M A and M B respectively, these scenarios are detailed. To show how miners behave and interact with each other during a typical non-parallelized mining cycle, a malicious third miner M M (Mallory) is also included.

[0079] Scenario 1: First, Alice successfully mines and broadcasts a valid block Without hearing about any other successfully mined blocks, Alice independently reaches the end of a mining cycle and broadcasts her block to the network.

[0080] Alice first receives a valid block from Bob Alice receives a block from another miner, Bob. She continues to mine her own block while validating Bob's block in parallel.

[0081] Note that mining and validation are only done in parallel - the mining algorithm itself is not parallelizable. Assume T A G >T α G Using, Alice can validate Bob's block before mining an alternative.

[0082] Alice first receives an invalid block from Mallory Alice receives a block from a malicious miner, Mallory. She continues to mine her own block while validating Mallory's block in parallel. Note that mining and validation are only done in parallel - the mining algorithm itself is not parallelizable at any point.

[0083] Possibility of DoS attacks Assuming that a miner is required to open a new thread each time it sends a proof-of-work solution, there is a possibility of abuse such as a denial-of-service attack. This can be addressed by applying some rules or restrictions. 1. Only one PoC message per miner can be accepted by other nodes. 2. A mining node can only accept a PoC message after sufficient time has elapsed since the last block was mined on the network.

[0084] One or more known spam defenses can be used to prevent individual miners from being forced to open a large number of computational threads.

[0085] Exemplary, enumerated embodiments of the present disclosure: 1. A computer or blockchain implementation (mining) method, comprising a computationally difficult parameter, the hash of at least one blockchain transaction, and / or the hash of at least one blockchain block header using a non-parallelizable algorithm to calculate an output based on.

[0086] Non-parallelizable algorithms may sometimes be referred to as sequential algorithms or essentially sequential algorithms. The output may be a value. The output may be a solution to a puzzle (which may alternatively be referred to as a "challenge", "computational challenge", or "problem"). The output may be the output of a function or method. The algorithm may be executed by one or more nodes of a blockchain network. These may be mining nodes. As inputs to the algorithm, computationally difficult parameters as well as transaction hashes and block header hashes may be used. Other inputs may also be provided to the algorithm. The output may be provided to a node on the blockchain.

[0087] The method may be described as a blockchain security method, a blockchain mining method, a non-parallelizable consensus mechanism / method, a blockchain consensus method, and / or a blockchain implementation block generation method.

[0088] 2. The method according to 1, further comprising the step of sending the output, or the notation that is or may be the output, to a network of blockchain nodes. The notation of the output may comprise the hash of the output. The node may be a mining node of the blockchain network.

[0089] 3. The method according to 1 or 2, wherein the non-parallelizable algorithm for obtaining the output may comprise at least one of the following operations, namely, recursive operation, remainder, exponentiation by squaring and may comprise at least one of them.

[0090] Therefore, the NPM algorithm may comprise the execution of one, all, or some combinations of these operations and / or may require it.

[0091] 4. The method according to any combination of 1 to 3, comprising the step of selecting at least one blockchain transaction from a set of blockchain transactions, wherein at least one blockchain transaction is selected based on a timestamp provided in at least one blockchain transaction.

[0092] The set of blockchain transactions or the "many states" may be referred to as the "mempool". The mempool may be configured and / or used as described above. The mempool may comprise blockchain transactions with at least one unspent output (UTXO). The same mempool may be shared or accessible by all (mining) nodes on the blockchain network. One or more of the nodes may have a copy of the set of nodes themselves.

[0093] A method according to 5.4, wherein at least one selected blockchain transaction may comprise a timestamp derivable or identifiable from the state of the blockchain.

[0094] A method according to 6.4 or 6.5, wherein at least one selected transaction may comprise a timestamp later than the timestamp of the block or blockchain transaction recorded on the blockchain.

[0095] A method according to 6.4, 6.5, or 6.6, further comprising the step of calculating a representation of at least one selected blockchain transaction. The representation of at least one selected blockchain transaction may be a hash or may comprise a hash.

[0096] A method according to any combination of 1 to 7, comprising the step of receiving a representation of an output at a second blockchain network node from a first blockchain network node. The method may also comprise verifying the (received) output at the second blockchain network node. The step of verifying the output may comprise comparing the received output (or a version thereof) with a verification output calculated by the second blockchain node, wherein the second blockchain node calculates the verification output using the same non-parallelizable algorithm and the same input as the first blockchain node.

[0097] A method according to 6.8, wherein the step of verifying the output at the second blockchain network node comprises calculating the output at the second blockchain network node, generating a representation of the output at the second blockchain network node, Comparing notations generated at a second blockchain network node with notations received from a first blockchain network node may be provided.

[0098] 10. A method by any combination of 1 to 9, wherein the computational difficulty parameter is a value that affects, determines, and / or controls the number of operations required by a non-parallelizable algorithm to compute an output.

[0099] 11. A method by any combination of 1 to 10, wherein the non-parallelizable algorithm i) requires the computation of one or more intermediate values to compute an output, and / or ii) cannot be executed by a plurality of parallelized computing resources.

[0100] 12. A method by any combination of 1 to 11, comprising the step of generating a blockchain block comprising one or more blockchain transactions.

[0101] 13. The method according to 12, further comprising the step of adding the blockchain block to the blockchain. This may be achieved as described above using an encryption link to associate the newly generated block with the previous (last) block recorded (i.e., added to the blockchain) on the blockchain.

[0102] According to another aspect of the present disclosure, there is provided a computer-implemented system configured to perform any method step or combination of method steps described or claimed herein. A blockchain system (network) comprising a plurality of computer-implemented nodes is provided, and each node in the blockchain network comprises a processor, A memory containing executable instructions, which, as a result of execution by a processor, cause the system to execute any variant of the computer-implemented method claimed or described herein.

[0103] The network may be configured to operate using a blockchain protocol as described herein.

[0104] According to another aspect, there is provided a non-transitory computer-readable storage medium storing executable instructions that, as a result of being executed by a processor of a computer system, cause the computer system to execute any version of the computer-implemented method claimed or described herein.

[0105] Next, referring to FIG. 2, there is provided an exemplary simplified block diagram of a computing device 2600 that may be used to practice at least one embodiment of the present disclosure. In various embodiments, the computing device 2600 may be used to implement any of the systems exemplified and described above. For example, the computing device 2600 may be configured for use as a web server or one or more processors or computing devices for implementing a host responsible for providing a payment service or a payment client entity related to a payment service or a payor or payee payment client entity. Thus, the computing device 2600 may be a portable computing device, a personal computer, or any electronic computing device. As shown in FIG. 2, the computing device 2600 may include one or more processors together with a memory controller (collectively labeled 2602) configured to communicate with a storage subsystem 2606 including one or more levels of cache memory as well as main memory 2608 and persistent storage 2610. The main memory 2608 may include, as illustrated, dynamic random access memory (DRAM) 2618 and read-only memory (ROM) 2620. The storage subsystem 2606 and the cache memory 2602 may be used for storing information such as details related to transactions and blocks as described in the present disclosure. The processor 2602 may be utilized to provide the steps or functions of any embodiment as described in the present disclosure.

[0106] The processor 2602 may also be able to communicate with one or more user interface input devices 2612, one or more user interface output devices 2614, and a network interface subsystem 2616.

[0107] The bus subsystem 2604 may provide a mechanism for enabling various components and subsystems of the computing device 2600 to communicate with each other as intended. Although the bus subsystem 2604 is schematically illustrated as a single bus, alternative embodiments of the bus subsystem may utilize multiple buses.

[0108] The network interface subsystem 2616 may provide an interface to other computing devices and networks. The network interface subsystem 2616 may function as an interface for receiving data from and transmitting data to other systems from the computing device 2600. For example, the network interface subsystem 2616 may enable a data technician to connect the device to a network, such that the data technician may be able to send data to and receive data from the device while located at a remote location such as a data center.

[0109] The user interface input device 2612 may include one or more user input devices such as a keyboard, an integrated mouse, a trackball, a touchpad, or a pointing device such as a graphics tablet, a scanner, a barcode scanner, a touch screen incorporated within a display, an audio input device such as a voice recognition system, a microphone, and other types of input devices. Generally, the use of the term "input device" shall include all possible types of devices and mechanisms for inputting information into the computing device 2600.

[0110] One or more user interface output devices 2614 may include, for example, a display subsystem, a printer, or a non-visual display such as an audio output device. The display subsystem may be, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), a flat panel device such as a light emitting diode (LED) display, or a projection device or other display device. Generally, the use of the term "output device" is intended to include all possible types of devices and mechanisms for outputting information from the computing device 2600. One or more user interface output devices 2614 may be used, for example, to present a user interface to facilitate user interaction with an application that performs the processes described and variations thereof when such interaction may be appropriate.

[0111] The memory subsystem 2606 may provide a computer-readable storage medium for storing basic programming and data structures that may provide the functionality of at least one embodiment of the present disclosure. Applications (programs, code modules, instructions) may provide the functionality of one or more embodiments of the present disclosure when executed by one or more processors and may be stored within the memory subsystem 2606. These application modules or instructions may be executed by one or more processors 2602. The memory subsystem 2606 may additionally provide a repository for storing data used in accordance with the present disclosure. For example, main memory 2608 and cache memory 2602 may provide volatile storage for programs and data. Persistent storage device 2610 may provide persistent (non-volatile) storage for programs and data and may include flash memory, one or more solid state drives, one or more magnetic hard disk drives, one or more floppy disk drives with associated removable media, one or more optical drives (e.g., CD-ROM or DVD or Blue-Ray) drives with associated removable media, and other similar storage media. Such programs and data may include programs for performing the steps of one or more embodiments as described in the present disclosure, as well as data related to transactions and blocks as described in the present disclosure.

[0112] The computing device 2600 can be of various types, including a portable computer device, a tablet computer, a workstation, or any other device described below. Additionally, the computing device 2600 can include another device that may be connected to the computing device 2600 through one or more ports (e.g., USB, headphone jack, Lightning connector, etc.). The device that may be connected to the computing device 2600 can include a plurality of ports configured to receive an optical fiber connector. Thus, this device may be configured to convert an optical signal into an electrical signal that may be transmitted through the port connecting the device to the computing device 2600 for processing. Due to the ever-changing nature of computers and networks, the description of the computing device 2600 shown in FIG. 2 is intended only as an example for showing a preferred embodiment of the device. Many other configurations are possible with more or fewer components than the system shown in FIG. 2.

[0113] Note that the above embodiments are illustrative of the present disclosure rather than limiting it, and those skilled in the art can design many alternative embodiments without departing from the scope of the present disclosure as defined by the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The terms such as "comprising" and "comprises" do not exclude the presence of elements or steps other than those recited in any claim or specification as a whole. In this specification, "comprises" means "includes or consists of", and "comprising" means "including or consisting of". Throughout this specification, the word "comprise", or variations such as "includes", "comprises", or "comprising", is understood not to exclude any other element, integer, or step, or group of elements, integers, or steps, but to imply the inclusion of the recited element, integer, or step, or group of elements, integers, or steps. Reference to a singular element does not exclude reference to plural such elements, and vice versa. The present disclosure may be implemented by hardware comprising several different elements, and preferably by a computer suitably programmed. In device claims listing several means, several of these means may be embodied by one and the same piece of hardware. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage.

Explanation of Signs

[0114] 2600 Computing device 2602 Processor 2604 Bus subsystem 2606 Memory Subsystem 2608 Main Memory 2610 Persistent Memory Device 2612 User Interface Input Device 2614 User Interface Output Device 2616 Network Interface Subsystem 2618 Dynamic Random Access Memory (DRAM) 2620 Read Only Memory (ROM)

Claims

1. A computer-implemented method, a computationally difficult parameter, the hash of at least one blockchain transaction, and / or the hash of at least one blockchain block header using a non-parallelizable algorithm to calculate an output (4) based on A computer-implemented method comprising the steps.

2. The method according to claim 1, further comprising the step of sending the output or a representation of the output to a network of blockchain nodes (5).

3. The non-parallelizable algorithm is a recursive operation, a remainder, a repeated squaring operation The method according to claim 1 or 2, comprising at least one of the operations.

4. Selecting at least one blockchain transaction from a set of blockchain transactions, wherein the at least one blockchain transaction is selected based on a timestamp provided within the at least one blockchain transaction, The method according to any one of claims 1 to 3.

5. The method according to claim 4, wherein the at least one selected blockchain transaction comprises a timestamp derivable or identifiable from the state of the blockchain.

6. The method according to claim 4 or 5, wherein the at least one selected transaction comprises a timestamp later than the timestamp of a block or blockchain transaction recorded on the blockchain.

7. The method according to claim 4, 5, or 6, further comprising the step of calculating a representation (3) of the at least one selected blockchain transaction.

8. Receiving, at a second blockchain network node, a representation of the output from a first blockchain network node, and verifying the output at the second blockchain network node The method according to any one of claims 1 to 7.

9. The step of verifying the output at the second blockchain network node comprises calculating the output at the second blockchain network node, generating, at the second blockchain network node, a notation of the output; comparing, at the second blockchain network node, the notation generated at the second blockchain network node with the notation received from the first blockchain network node; The method according to claim 8, comprising the steps of.

10. The method according to any one of claims 1 to 9, wherein the computationally difficult parameter is a value that affects or controls the number of operations required by the non-parallelizable algorithm to compute the output.

11. The non-parallelizable algorithm is iii) requires the calculation of one or more intermediate values to calculate the output, and / or iv) cannot be executed by a plurality of parallelized computing resources, The method according to any one of claims 1 to 10.

12. A blockchain network comprising a plurality of nodes, wherein each node in the blockchain network a processor; a memory containing executable instructions, the executable instructions causing the processor to execute, as a result of execution by the processor, the computer-implemented method according to any one of claims 1 to 11 in the system; a memory A blockchain network comprising.

13. A non-transitory computer-readable storage medium storing executable instructions that, as a result of execution by a processor of a computer system, cause the computer system to execute the computer-implemented method according to any one of claims 1 to 11.