Smart Contract
The multi-layer network architecture addresses the challenge of maintaining smart contract states in blockchain systems by using smart contract nodes to synchronize and record states on the blockchain, resulting in improved efficiency and reliability.
Patent Information
- Application Number
- JP2022549738
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-02-19
- Filing Date
- 2021-01-19
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2041-01-19
AI Technical Summary
Existing blockchain systems face challenges in efficiently maintaining and updating the state of smart contracts across a network, leading to potential inconsistencies and inefficiencies.
A multi-layer network architecture is introduced, where the state of smart contracts is maintained by smart contract nodes in intermediate layers, while also being recorded on the blockchain network, ensuring synchronization and immutability.
This approach enhances the efficiency and reliability of smart contract management by maintaining a synchronized and tamper-proof state across the network, improving scalability and reducing the risk of errors.
Smart Images

Figure 0007697957000010 
Figure 0007697957000011 
Figure 0007697957000012
Abstract
Description
Technical Field
[0001] The present disclosure relates to a method of providing smart contracts using blockchain.
Background Art
[0002] A blockchain refers to a form of distributed data structure, and replicas of the blockchain are maintained at each of a plurality of nodes in a peer-to-peer (P2P) network. The blockchain comprises a chain of data blocks, each block comprising one or more transactions. Each transaction may point back to a preceding transaction in a sequence that may span one or more blocks. Transactions may be issued to the network to be included in new blocks. New blocks are created by a process known as "mining", which involves each of a plurality of mining nodes competing to perform a "proof of work", i.e., solving a cryptographic puzzle based on a pool of unprocessed transactions waiting to be included in the block.
[0003] Each node in the network can have any one, two, or all of the three roles of transfer, mining, and storage. Transfer nodes spread transactions across all nodes of the network. Mining nodes execute the mining of transactions into blocks. Storage nodes each store their own copy of the mined blocks of the blockchain. To have a transaction recorded on the blockchain, the party involved sends the transaction to one of the nodes of the network to be spread. Mining nodes that receive the transaction may compete to mine the transaction into a new block. Each node is configured to respect the same node protocol, which includes one or more conditions for the transaction to be valid. Invalid transactions are neither spread nor mined into blocks. Assuming that the transaction is verified and thereby accepted on the blockchain, the transaction (including any user data) will thus remain stored in each of the nodes in the P2P network as an immutable public record.
[0004] Miners who succeed in solving the proof-of-work puzzle to create the latest block are usually rewarded with a new transaction called a "coinbase transaction" that generates a new amount of digital assets. Proof-of-work incentivizes miners not to act fraudulently in the system by including double-spending transactions in their blocks, as it requires a large amount of computing resources to mine a block and blocks containing attempts at double-spending are likely not to be accepted by other nodes.
[0005] In an "output-based" model (sometimes called a UTXO-based model), the data structure of a given transaction has one or more inputs and one or more outputs. Every spendable output has an element that specifies an amount of digital assets, sometimes called a UTXO ("unspent transaction output"). The output may further include a locking script that specifies the conditions for redeeming the output. Each input has a pointer to such an output in a previous transaction and may further include an unlocking script for unlocking the locking script of the indicated output. Thus, consider a pair of transactions, which we call the first transaction and the second transaction (or "target" transaction). The first transaction has at least one output that specifies an amount of digital assets and includes a locking script that defines one or more conditions for unlocking the output. The second target transaction has at least one input that has a pointer to the output of the first transaction and an unlocking script for unlocking the output of the first transaction.
[0006] In such a model, when the second target transaction is sent to the P2P network to be propagated and recorded on the blockchain, one of the criteria for validity applied at each node is that the unlocking script satisfies all of the one or more conditions defined in the locking script of the first transaction. Another criterion is that the output of the first transaction has not yet been redeemed by another earlier valid transaction. Any node that finds that the target transaction is invalid according to any of these conditions will not propagate or include the transaction for mining into the block that will be recorded on the blockchain.
[0007] An alternative type of transaction model is the account-based model. In this case, each transaction defines the amount to be transferred by referring to the absolute account balance, rather than by referring to the UTXOs of previous transactions in the sequence of past transactions. The current state of all accounts is stored by a miner separate from the blockchain and updated periodically.
[0008] Conventionally, transactions in a blockchain are used to carry digital assets, i.e., a number of digital tokens. However, the blockchain can also be utilized to overlay additional functionality on top of the blockchain. For example, the blockchain protocol may allow storing additional user data in the output of a transaction. Modern blockchains have increased the maximum data capacity that can be stored in a single transaction, making it possible to incorporate more complex data. For example, this can be used to store electronic documents, or audio or video data on the blockchain as well.
Prior Art Documents
Patent Documents
[0009]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0010] The present disclosure provides a method such that the state of a smart contract is maintained in a layer of smart contract nodes that is layered around the core of the blockchain network nodes and such that the state is also stored in the blockchain of the blockchain network.
Means for Solving the Problems
[0011] According to one aspect disclosed in this specification, a method for maintaining the state of a smart contract in a multi-layer network is provided. The multi-layer network includes a core layer including one or more core nodes, one or more intermediate layers each including one or more intermediate layer nodes, and one or more outer layers each including one or more outer layer nodes. Each of the core nodes is a node of a blockchain network, one or more of the intermediate layer nodes are smart contract nodes that provide a smart contract service for maintaining the state of the smart contract, and one or more of the outer layer nodes are client nodes of the smart contract service. The method includes recording the state of the smart contract in a record of the state maintained at a first node among one or more smart contract nodes by the first node. In addition, at least a first transaction that similarly records the state is recorded in the blockchain of the blockchain network.
[0012] To assist in the understanding of embodiments of the present disclosure and to show how such embodiments may be implemented, by way of mere example, reference is made to the accompanying drawings.
Brief Description of the Drawings
[0013]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Figure 20
Figure 21
Figure 22
Figure 23
Figure 24
Figure 25
Figure 26
Figure 27
Figure 28
DETAILED DESCRIPTION OF THE INVENTION
[0014] Overview of an Exemplary System FIG. 1 shows an exemplary system 100 for implementing a blockchain 150. The system 100 includes a packet-switched network 101, typically a wide area internetwork such as the Internet. The packet-switched network 101 includes a plurality of nodes 104 adapted to form a peer-to-peer (P2P) overlay network 106 within the packet-switched network 101. Each node 104 of the blockchain network 106 comprises a peer computer device, and different nodes of the nodes 104 belong to different peers. Each node 104 comprises a processing device comprising one or more processors, such as one or more central processing units (CPUs), accelerator processors, application-specific processors, and / or field programmable gate arrays (FPGAs). Each node also comprises a memory, i.e., a computer-readable storage in the form of a non-transitory computer-readable medium. The memory may comprise one or more memory units utilizing one or more memory media, such as magnetic media such as hard disks, electronic media such as solid state drives (SSDs), flash memory or EEPROM, and / or optical media such as optical disk drives.
[0015] The blockchain 150 comprises a chain of blocks of data 151, and each copy of the blockchain 150 is maintained at each of a plurality of nodes in the P2P network 106. Each block 151 in the chain comprises one or more transactions 152, and in this context, a transaction refers to a type of data structure. The nature of the data structure depends on the type of transaction protocol used as part of the transaction model or scheme. A given blockchain typically uses one particular transaction protocol throughout. In one common type of transaction protocol, the data structure of each transaction 152 comprises at least one input and at least one output. Each output specifies an amount of digital assets belonging to a user 103 to which the output is cryptographically locked (requiring the signature of that user to be unlocked and thereby exchanged or consumed). Each input points back to the output of a previous transaction 152, thereby connecting those transactions.
[0016] At least some of the nodes 104 assume the role of forwarding nodes 104F that transfer and thereby spread the transactions 152. At least some of the nodes 104 assume the role of miners 104M that mine the blocks 151. At least some of the nodes 104 assume the role of storage nodes 104S (sometimes also called "full copy" nodes), each of which stores a respective copy of the same blockchain 150 in its respective memory. Each miner node 104M also maintains a pool 154 of transactions 152 that are waiting to be mined into a block 151. A given node 104 may be a forwarding node 104F, a miner 104M, a storage node 104S, or any combination of two or all of these.
[0017] In a given current transaction 152j, the input (or each input) comprises a pointer that references the output of a preceding transaction 152i in the sequence of transactions, which designates that this output will be redeemed or "spent" in the current transaction 152j. Generally, the preceding transaction can be any transaction in the pool 154 or any block 151. The preceding transaction 152i need not necessarily exist at the time the current transaction 152j is created or even at the time it is sent to the network 106, but for the current transaction to be valid, the preceding transaction 152i must exist and be validated. Thus, "preceding" as used herein refers to what precedes in a logical chain connected by pointers and does not necessarily refer to the time of creation or transmission in a chronological sequence, and thus does not necessarily preclude the transactions 152i, 152j from being created or sent out of order (see the following discussion on orphan transactions). The preceding transaction 152i may similarly be referred to as an ancestor transaction or a predecessor transaction.
[0018] The input to the current transaction 152j also comprises the signature of the user 103a whose output from the preceding transaction 152i is the subject of the lock. And the output of the current transaction 152j can be cryptographically locked to a new user 103b. Thus, the current transaction 152j can transfer the amount defined in the input of the preceding transaction 152i to the new user 103b as defined in the output of the current transaction 152j. In some cases, the transaction 152 may have multiple outputs to divide the amount of the input among multiple users, one of whom may be the original user 103a to effect the change. In some cases, the transaction may also have multiple inputs to gather together amounts from multiple outputs of one or more preceding transactions and redistribute them to one or more outputs of the current transaction.
[0019] The above is referred to as an "output-based" transaction protocol and may sometimes also be referred to as an unspent transaction output (UTXO) type protocol (in which case the outputs are called UTXOs). The total balance of a user is not defined by any one number stored on the blockchain. Instead, the user needs a special "wallet" application 105 to reconcile the values of all of that user's UTXOs scattered across many different transactions 152 in the blockchain 151.
[0020] An alternative type of transaction protocol is sometimes referred to as an "account-based" protocol as part of an account-based transaction model. In the account-based case, each transaction defines the amount to be transferred by referring to an absolute account balance rather than by referring to the UTXOs of previous transactions in the sequence of past transactions. The current state of all accounts is stored by the miner separately from the blockchain and updated periodically. In such a system, transactions are ordered using the transaction tally of the account during execution (also called the "position"). This value is signed by the sender as part of the sender's cryptographic signature and hashed as part of the transaction reference calculation. Additionally, an optional data field may also be part of the signed transaction. This data field may point back to previous transactions, for example, if a previous transaction ID is included in the data field.
[0021] For any type of model, when user 103 wishes to execute a new transaction 152j, the user sends the new transaction from their computer terminal 102 to one of the nodes 104 of the P2P authenticity verification network 106 (which today is usually a server or data center, but in principle could be another user terminal). This node 104 verifies whether the transaction is legitimate according to the node protocol applied to each of the nodes 104.
[0022] The details of the node protocol correspond to the type of transaction protocol used in the problem blockchain 150 that together forms the overall transaction model. The node protocol typically requires the node 104 to verify that the cryptographic signature in the new transaction 152j matches the expected signature, where the expected signature depends on the previous transaction 152i in the ordered sequence of transactions 152. In the case of an output-based one, this may include verifying that the user's cryptographic signature included in the input of the new transaction 152j matches the conditions defined in the output of the preceding transaction 152i that the new transaction consumes, which typically includes at least verifying that the cryptographic signature in the input of the new transaction 152j unlocks the output of the previous transaction 152i that the input of the new transaction indicates. In some transaction protocols, this condition may be at least partially defined by custom scripts included in the input and / or output. Alternatively, it may be fixed solely by the node protocol, or by a combination of these. In any case, if the new transaction 152j is valid, the current node forwards it to one or more other nodes of the nodes 104 in the P2P network 106. At least some of these nodes 104 also act as forwarding nodes 104F and apply the same test according to the same node protocol to forward the new transaction 152j to one or more further nodes 104, etc. In this way, new transactions are spread throughout the network of nodes 104.
[0023] In an output-based model, the definition of whether a given output (e.g., UTXO) is consumed is whether it has already been legitimately redeemed by the input of another previous transaction 152j according to the node protocol. Another condition for a transaction to be legitimate is that the output of the previous transaction 152i that the transaction attempts to consume or redeem has not yet been consumed / redeemed by another legitimate transaction. Again, if not legitimate, transaction 152j will not be propagated or recorded on the blockchain. This protects against double-spending, such as a consumer attempting to consume the output of the same transaction more than once.
[0024] In addition to validity checks, at least some of the nodes 104M also compete to first create a block of transactions in a process known as mining, which is assisted by "proof of work". At the mining node 104M, new transactions are added to a pool of legitimate transactions that have not yet appeared in the block. Then, the miner competes to assemble a new legitimate block 151 of transactions 152 from the transaction pool 154 by attempting to solve a cryptographic puzzle. Typically, this involves searching for a nonce value such that when the "nonce" is concatenated with the transaction pool 154 and hashed, the output of the hash meets a certain condition. For example, the certain condition may be that the output of the hash has a certain number of leading 0s predefined. The nature of the hash function is such that it has an output that is unpredictable with respect to its input. Therefore, this search can only be performed by brute force, consuming a large amount of processing resources at each node 104M attempting to solve the puzzle.
[0025] The first minor node 104M attempting to solve the puzzle notifies this to the network 106 and provides a solution as proof that can be easily verified by other nodes 104 in the network (it is straightforward to verify that given a solution to the hash, the output of the hash thereby meets the condition). Then, the pool 154 of transactions for which the winner has solved the puzzle is recorded as new blocks 151 in the blockchain 150 by at least some of the nodes 104 acting as storage nodes 104S, based on the confirmation of the winner's notified solution at each such node. The block pointer 155 is also assigned to the new block 151n that points back to the previously created block 151n-1 in the chain. The proof of work helps reduce the risk of double spending, as creating a new block 151 requires a large amount of effort, and any block containing double spending is likely to be rejected by other nodes 104, motivating the mining node 104M not to allow double spending in its own block. Once created, the block 151 cannot be modified, as the block 151 is recognized and maintained at each of the storage nodes 104S in the P2P network 106 according to the same protocol. The block pointer 155 also imposes a sequential order on the blocks 151. Since the transactions 152 are recorded in the ordered blocks at each storage node 104 in the P2P network 106, this results in an immutable public ledger of the transactions.
[0026] The pool 154 may be referred to as the "memory pool". In this specification, this term is not limited to any particular blockchain, protocol, or model. It refers to a pool of transactions in which the miner has promised not to accept any other transactions that the miner has accepted for mining and attempts to consume the same output.
[0027] At any given time, different miners 104M competing to solve the puzzle may be competing to solve the puzzle based on different snapshots of the unmined transaction pool 154 at any given time, depending on when they started searching for the solution. Note that the first one to solve each puzzle defines which transactions 152 are included in the next new block 151n, and the current pool 154 of unmined transactions is updated. The miner 104M then continues to compete to create blocks from the newly defined prominent pool 154, and so on. There is also a protocol for resolving any "forks" that may occur, where a fork is a situation where two miners 104M solve the puzzle within a very short time of each other, resulting in conflicting views of the blockchain being spread. That is, the tip of the fork that grows the longest becomes the final blockchain 150.
[0028] In most blockchains, the winning miner 104M is automatically rewarded with a special type of new transaction that creates a new amount of digital assets out of nothing (as opposed to a normal transaction that transfers an amount of digital assets from one user to another). Thus, the winning node is said to have "mined" an amount of digital assets. This special type of transaction is sometimes called a "generation" transaction. It automatically forms part of the new block 151n. This reward gives the miner 104M an incentive to participate in the proof-of-work competition. Often, ordinary (non-generation) transactions 152 also specify an additional transaction fee in one of their outputs to further reward the winning miner 104M that created the block 151n in which the transaction was included.
[0029] Due to the computing resources involved in mining, usually, each of at least the minor nodes 104M takes the form of a server with one or more physical server units, or even an entire data center. Each transfer node 104F and / or storage node 104S may also be in the form of a server or a data center. However, in principle, any given node 104 can be in the form of a user terminal or a group of user terminals connected together in a network.
[0030] The memory of each node 104 stores software configured to be executed on the processing device of the node 104 to perform its respective role and handle transactions 152 according to the node protocol. It will be understood that any activities considered to be attributable to the node 104 herein may be performed by software executed on the processing device of each computer device. The node software may be implemented in one or more applications in the application layer, or in a lower layer such as the operating system layer or protocol layer, or any combination thereof. Also, the term "blockchain" as used herein is a general term referring to this type of technology in general and is not limited to any particular proprietary blockchain, protocol, or service.
[0031] Each computer device 102 of a plurality of stakeholders 103 that play the role of consuming users is also connected to the network 101. These play the role of payer and payee in a transaction, but do not necessarily participate in mining or spreading the transaction on behalf of other stakeholders. They do not necessarily execute the mining protocol. Two stakeholders 103 and their respective devices 102, namely the first stakeholder 103a and its respective computer device 102a, and the second stakeholder 103b and its respective computer device 102b, are shown for illustrative purposes. It will be understood that more such stakeholders 103 and their respective computer devices 102 may exist and participate in the system, but for convenience they are not shown. Each stakeholder 103 may be an individual or an organization. Purely by way of example, the first stakeholder 103a is referred to herein as Alice and the second stakeholder 103b is referred to as Bob, but this is not limiting, and it will be understood that any reference herein to Alice or Bob may be replaced by "the first stakeholder" and "the second stakeholder", respectively.
[0032] The computer device 102 of each stakeholder 103 includes respective processing devices that include one or more processors, such as one or more CPUs, GPUs, other accelerator processors, application-specific processors, and / or FPGAs. The computer device 102 of each stakeholder 103 further includes a memory in the form of a non-transitory computer-readable medium, i.e., computer-readable storage. This memory may include one or more memory units that utilize one or more memory media, such as magnetic media like hard disks, SSDs, flash memory, or electronic media like EEPROMs, and / or optical media like optical disk drives. The memory of the computer device 102 of each stakeholder 103 stores software that includes respective instances of at least one client application 105 to be executed on the processing device. It will be understood that any activity that is considered to be attributable to a given stakeholder 103 herein may be performed using the software executed on the processing device of the respective computer device 102. The computer device 102 of each stakeholder 103 includes at least one user terminal, such as a desktop or laptop computer, tablet, smartphone, or wearable device like a smartwatch. The computer device 102 of a given stakeholder 103 may also include one or more other network-connected resources, such as cloud computing resources accessed via the user terminal.
[0033] The client application 105 may first be provided to the computer device 102 of any given stakeholder 103 on a suitable computer-readable storage medium, such as downloaded from a server, for example, or provided on a removable storage device such as a removable SSD, flash memory key, removable EEPROM, removable magnetic disk drive, magnetic floppy disk or tape, optical disk such as a CD or DVD ROM, or removable optical drive.
[0034] The client application 105 has at least a "wallet" function. This has two main functions. One of these is to enable each user stakeholder 103 to create a transaction 152, sign it, and send it so that the transaction 152 is spread across the network of nodes 104 and included in the blockchain 150. The other is to report to each stakeholder the amount of digital assets that each stakeholder currently owns. In an output-based system, this second function involves reconciling the amounts defined in the outputs of various transactions 152 scattered throughout the blockchain 150 belonging to the stakeholder in question.
[0035] Note: Although various client functions may be described as being integrated into a given client application 105, this is not necessarily limiting, and instead, any client function described herein may be implemented in a series of two or more separate applications, for example, interfacing via an API, or in the case where one is a plugin to the other. More generally, client functions may be implemented in the application layer, a lower layer such as an operating system, or any combination thereof. The following is described with respect to the client application 105, but it will be understood that this is not limiting.
[0036] An instance of the client application or software 105 on each computer device 102 is operably coupled to at least one of the forwarding nodes 104F of the P2P network 106. This enables the wallet function of the client 105 to send the transaction 152 to the network 106. The client 105 can also contact one, some, or all of the storage nodes 104 in order to query the blockchain 150 about any transaction for which the respective party 103 is the recipient (or, in an embodiment, since the blockchain 150 is a public institution that provides credibility to some transactions by virtue of its public existence, actually investigate the transactions of other parties in the blockchain 150). The wallet function of each computer device 102 is configured to compose and send the transaction 152 according to the transaction protocol. Each node 104 executes software that validates the transaction 152 according to the node protocol and, in the case of the forwarding nodes 104F, is configured to forward them to spread the transaction 152 across the entire network 106. The transaction protocol and the node protocol correspond to each other, and a given transaction protocol is accompanied by a given node protocol, together implementing a given transaction model. The same transaction protocol is used for all transactions 152 in the blockchain 150 (however, the transaction protocol may allow for various sub-types of transactions therein). The same node protocol is used by all nodes 104 in the network 106 (however, it may handle different sub-types of transactions differently according to the rules defined for that sub-type, and different nodes may undertake different roles and thus implement different corresponding aspects of the protocol).
[0037] As mentioned, the blockchain 150 comprises a chain of blocks 151, each block 151 comprising a set of one or more transactions 152 created by a proof-of-work process as discussed previously. Each block 151 also comprises a block pointer 155 that points back to a previously created block 151 in the chain to define a sequential order to the blocks 151. The blockchain 150 also comprises a pool of legitimate transactions 154 waiting to be included in a new block by the proof-of-work process. Each transaction 152 (other than the genesis transaction) comprises a pointer back to a previous transaction to define an order to the sequence of transactions (note that the sequence of transactions 152 is allowed to branch). The chain of blocks 151 goes back to the genesis block (Gb) 153 that was the first block in the chain. One or more original transactions 152 that were previous in the chain 150 pointed to the genesis block 153 rather than a previous transaction.
[0038] When a given party 103, e.g., Alice, wishes to send a new transaction 152j to be included in the blockchain 150, she composes the new transaction according to the relevant transaction protocol (using the wallet function of her client application 105). She then sends the transaction 152 from the client application 105 to one of the one or more forwarding nodes 104F to which she is connected. For example, this could be the forwarding node 104F that is closest to or best connected to Alice's computer 102. When any given node 104 receives the new transaction 152j, the node 104 handles the new transaction 152j according to the node protocol and its respective role. This involves first ascertaining whether the newly received transaction 152j meets any conditions for it to be "valid," examples of which will be discussed in more detail shortly. In some transaction protocols, the conditions for validity confirmation may be configurable for each transaction by a script included in the transaction 152. Alternatively, this condition may simply be a built-in function of the node protocol, or defined by a combination of the script and the node protocol.
[0039] Under the condition of passing the test for the newly received transaction 152j to be considered valid (i.e., under the condition that it is "validated"), any storage node 104S that receives the transaction 152j adds the newly validated transaction 152 to the pool 154 in the copy of the blockchain 150 maintained at that node 104S. Further, any forwarding node 104F that receives the transaction 152j spreads the validated transaction 152 onwards to one or more other nodes 104 in the P2P network 106. Since each forwarding node 104F applies the same protocol, assuming the transaction 152j is valid, this means that it will soon be spread throughout the entire P2P network 106.
[0040] When the utilization of the pool 154 in a copy of the blockchain 150 maintained in one or more storage nodes 104 is permitted, the minor node 104M starts competing to solve the proof-of-work puzzle for the latest version of the pool 154 that includes the new transaction 152 (it is possible that other miners 104M are still trying to solve the puzzle based on an old view of the pool 154, but the first one to arrive defines where the next new block 151 ends and where the new pool 154 starts, and ultimately, someone solves the puzzle for a part of the pool 154 that includes Alice's transaction 152j). When the proof-of-work is performed on the pool 154 that includes the new transaction 152j, it becomes immutably part of one of the blocks 151 in the blockchain 150. Since each transaction 152 has a pointer back to the previous transaction, the order of the transactions is also immutably recorded.
[0041] Since different nodes 104 first receive different instances of a given transaction, there may be conflicting views on which instance is "valid" before a particular instance is mined into the block 150. At the point when it is mined, all nodes 104 agree that the mined instance is the only valid instance. If a node 104 accepts an instance as valid and then discovers that a second instance is recorded in the blockchain 150, that node 104 must accept this and discard the previously accepted unmined instance (i.e., treat it as invalid).
[0042] UTXO-based model Figure 2 shows an exemplary transaction protocol. This is an example of a UTXO-based protocol. Transaction 152 (abbreviated as "Tx") is the basic data structure of the blockchain 150 (each block 151 includes one or more transactions 152). The following is described with reference to an output-based or "UTXO" - based protocol. However, this is not a limitation to all possible embodiments.
[0043] In a UTXO-based model, each transaction ("Tx") 152 has a data structure that includes one or more inputs 202 and one or more outputs 203. Each output 203 may include an unspent transaction output (UTXO), which can be used as a source for the inputs 202 of another new transaction (if the UTXO has not yet been redeemed). A UTXO contains a value that specifies the amount of digital assets. This represents a certain set number of tokens on the (decentralized) ledger. A UTXO may also include, among other information, the transaction ID of the transaction from which the UTXO originated. The transaction data structure may also include a header 201, which may include an indicator of the sizes of the input field 202 and the output field 203. The header 201 may also include the ID of the transaction. In an embodiment, the transaction ID is the hash of the transaction data (excluding the transaction ID itself) and is stored in the header 201 of the raw transaction 152 issued to the miner 104M.
[0044] Suppose that Alice 103a wishes to create a transaction 152j that transfers a problematic amount of digital assets to Bob 103b. In FIG. 2, Alice's new transaction 152j is labeled "Tx1". Tx1 takes the amount of digital assets locked to Alice in output 203 of the preceding transaction 152i in the sequence and transfers at least a portion of it to Bob. The preceding transaction 152i is labeled "Tx0" in FIG. 2. Tx0 and Tx1 are merely arbitrary labels. They do not necessarily mean that Tx0 is the first transaction of the blockchain 151, nor do they mean that Tx1 is the very next transaction in the pool 154. Tx1 can point back to any preceding (i.e., ancestor) transaction that still has an unspent output 203 locked to Alice.
[0045] The preceding transaction Tx0 may already be validated and included in the blockchain 150 when Alice creates a new transaction Tx1, or at least when she sends it to the network 106. It may already be included in one of the blocks 151 at that point, or it may still be waiting in the pool 154, in which case it will soon be included in a new block 151. Alternatively, Tx0 and Tx1 may be created together and sent to the network 102, or, if the node protocol allows buffering of "orphan" transactions, Tx0 may even be sent after Tx1. The terms "preceding" and "subsequent" as used herein in the context of the sequence of transactions refer to the order of transactions in a sequence as defined by the transaction pointers specified in the transactions (which transaction points back to which other transaction, etc.). They may be equivalently replaced by "predecessor" and "successor", or "ancestor" and "descendant", "parent" and "child", etc. This does not necessarily imply the order in which they are created, the order in which they are sent to the network 106, or the order in which they reach any given node 104. Nevertheless, a subsequent transaction (descendant transaction or "child") that refers to a preceding transaction (ancestor transaction or "parent") is not validated until and unless the parent transaction is validated. A child that reaches the node 104 before the parent is considered an orphan. It may be discarded or buffered for some time while waiting for the parent, depending on the node protocol and / or miner behavior.
[0046] One of one or more outputs 203 of a preceding transaction Tx0 comprises a particular UTXO, herein labeled UTXO0. Each UTXO comprises a value specifying the amount of digital assets represented by the UTXO and a locking script defining conditions that must be satisfied by an unlocking script in an input 202 of a subsequent transaction in order for the subsequent transaction to be valid and thus for the exchange of the UTXO to succeed. Typically, the locking script locks the amount to a particular party (the beneficiary of the transaction containing the locking script). That is, the locking script defines unlocking conditions, which typically include the condition that the unlocking script in the input of a subsequent transaction comprises the cryptographic signature of the party to whom the preceding transaction is locked.
[0047] The locking script (also known as scriptPubKey) is code written in a domain-specific language recognized by the node protocol. A specific example of such a language is called "Script" (with a capital S). The locking script specifies what information is required to consume the transaction output 203, for example, the requirement for Alice's signature. The unlocking script appears in the output of the transaction. The unlocking script (also known as scriptSig) is code written in a domain-specific language that provides the information required to meet the locking script criteria. For example, it may include Bob's signature. The unlocking script appears in the input 202 of the transaction.
[0048] Thus, in the example shown, UTXO0 in the output 203 of Tx0 comprises a locking script [Checksig P A that requires Alice's signature Sig P A for the exchange of UXTO0 to succeed (strictly speaking, for the subsequent transaction attempting to exchange UTXO0 to be valid). [Checksig PA is the public key P from Alice's public-private key pair A The input 202 of Tx1 includes a pointer that points back to Tx1 (e.g., pointed back by its transaction ID TxID0, which is the hash of the entire transaction Tx0 in the embodiment). The input 202 of Tx1 includes an index for identifying UTXO0 within Tx0 to identify UTXO0 from among any other possible outputs of Tx0. The input 202 of Tx1 further includes an unlocking script <Sig P A > that includes Alice's cryptographic signature created by applying Alice's private key from the key pair to a predefined portion of the data (sometimes called the "message" in cryptography). The data (or "message") that needs to be signed by Alice to provide a valid signature may be defined by the locking script, or by the node protocol, or by a combination thereof.
[0049] Depending on the implementation, the required signature may be, for example, a conventional ECDSA (Elliptic Curve Digital Signature Algorithm) signature, a DSA (Digital Signature Algorithm) signature, or an RSA (Rivest-Shamir-Adleman) signature, or any other suitable form of cryptographic signature. The issue of the signature may be implemented, for example, as a standard pay-to-public key (P2PK) puzzle or a P2PK hash (P2PKH) puzzle, or alternatively, an R-puzzle or the like may be implemented instead as a means for the signature. This example uses P2PK for illustration.
[0050] When a new transaction Tx1 reaches node 104, the node applies the node protocol. This involves executing the locking script and the unlocking script together to determine whether the unlocking script meets the conditions defined in the locking script (which may have one or more criteria). In an embodiment, this involves concatenating the two scripts. <Sig P A ><P A >||[Checksig P A Here, "||" represents concatenation, "<...>" means putting data on the stack, and "[...]" is a function included in the unlocking script (in this example, a stack - based language). Equivalently, instead of concatenating the scripts, the scripts may be executed one after another using a common stack. In any case, when executed together, the scripts authenticate that the locking script in the input of Tx1 contains Alice's signature that signs the expected part of the data using Alice's public key P A included in the locking script in the output of Tx0. The expected part of the data itself (the "message") must also be included in Tx0 for this authentication to be performed. In an embodiment, the signed data comprises the entirety of Tx0 (thus, there is no need for a separate element to specify the signed part of the data in plaintext as it was already there).
[0051] Details of authentication using public-private cryptography are familiar to those skilled in the art. Basically, when Alice signs a message by encrypting the message with her private key, given the plaintext of Alice's public key and the message (the unencrypted message), another entity such as node 104 can authenticate that the encrypted version of the message must have been signed by Alice. Signing typically involves hashing the message, signing the hash, and tagging this as the signature onto the plaintext version of the message, thereby enabling any holder of the public key to authenticate the signature. Thus, it should be noted that any reference herein to signing, such as to a particular piece of data or part of a transaction, may in embodiments mean signing the hash of that piece of data or part of the transaction.
[0052] The hash referred to elsewhere in this specification may be implemented by, for example, an SHA (Secure Hash Algorithm) hash function, or an HMAC (Hash-based Message Authentication Code) hash function, or any other suitable form of cryptographic hash function known in the art.
[0053] If the unlocking script in Tx1 meets one or more conditions specified in the locking script of Tx0 (thus, in the example shown, if Alice's signature is provided and authenticated in Tx1), node 104 considers Tx1 to be valid. If node 104 is mining node 104M, this means that node 104 adds Tx1 to the pool 154 of transactions waiting for proof of work. If node 104 is forwarding node 104F, node 104F forwards transaction Tx1 to one or more other nodes 104 in network 106, so it is spread across the entire network. When Tx1 is confirmed to be valid and included in blockchain 150, this defines UTXO0 from Tx0 as being consumed. Note that Tx1 can only be valid if it consumes an unspent transaction output 203. If it attempts to consume an output that has already been consumed by another transaction 152, Tx1 will be invalid even if all other conditions are met. Thus, node 104 also needs to check whether the referenced UTXO in the preceding transaction Tx0 has already been consumed (whether a valid input has already been formed into another valid transaction). This is one reason why imposing the order defined in transaction 152 is important for blockchain 150. In practice, a given node 104 may maintain a separate database that marks the UTXO203 consumed in transaction 152, but ultimately, what defines whether a UTXO has been consumed is whether it has already formed a valid input into another valid transaction in blockchain 150.
[0054] If the total amount specified in all outputs 203 of a given transaction 152 is greater than the total amount indicated by all its inputs 202, this also serves as a basis for invalidity in most transaction models. Thus, such a transaction is not spread and not mined into block 151.
[0055] Note that in a UTXO-based transaction model, a given UTXO must be consumed in its entirety. It is not possible to "leave behind" a portion of the amount defined in the UTXO as being consumed while another portion is not consumed. However, the amount from a UTXO can be split among multiple outputs of the next transaction. For example, the amount defined in UTXO0 within Tx0 can be split among multiple UTX0s within Tx1. Thus, if Alice does not wish to give all of the amount defined in UTXO0 to Bob, she can use the remainder to give herself the change in the second output of Tx1 or pay it to another party.
[0056] In practice, Alice usually needs to include a fee for the winning miner, because today, the reward for generating a transaction alone is usually not sufficient to motivate mining. If Alice does not include a fee for the miner, Tx0 is likely to be rejected by miner node 104M and thus, even if technically valid, will not be propagated and included in blockchain 150 (the miner protocol does not force the miner 104M to accept transaction 152 if it does not wish to). In some protocols, the mining fee does not require a separate, distinct output 203 (i.e., it does not require a separate UTXO). Instead, any difference between the total amount indicated by input 202 and the total amount specified in output 203 of a given transaction 152 is automatically given to the winning miner 104. For example, assume that the pointer to UTXO0 is the only input to Tx1 and Tx1 has a single output, UTXO1. If the amount of digital assets specified in UTXO0 is greater than the amount specified in UTXO1, the difference goes automatically to the winning miner 104M. However, it is not necessarily excluded that, alternatively or in addition, the mining fee can be explicitly specified in its own UTXO among the UTXOs 203 of transaction 152.
[0057] The digital assets of Alice and Bob consist of unspent UTXOs locked to them in any transaction 152 somewhere on the blockchain 150. Thus, typically, the assets of a given party 103 are dispersed across all the UTXOs of the various transactions 152 throughout the blockchain 150. There is no single number that defines the total balance of a given party 103 that is stored anywhere on the blockchain 150. It is the role of the wallet function of the client application 150 to collate together the values of all the various UTXOs that are locked to each party and have not yet been spent in some subsequent transaction. That wallet function can do this by querying a copy of the blockchain 150 stored in any of the storage nodes 104S, for example, the one closest to or best connected to the computer device 102 of each party.
[0058] Note that the script code is often represented schematically (i.e., not in an actual language). For example, [Checksig P A = OP_DUP OP_HASH160 <H(P A )> OP_EQUALVERIFY OP_CHECKSIG is intended as [Checksig P AIt may be written as "OP_...". "OP_..." refers to a specific opcode of the Script language. OP_CHECKSIG (also called "Checksig") is a Script opcode that takes two inputs (a signature and a public key) and verifies the validity of the signature using the Elliptic Curve Digital Signature Algorithm (ECDSA). At runtime, any presence of the signature ('sig') is removed from the script, but additional requirements such as a hash puzzle remain for the transaction verified by the'sig' input. In another example, OP_RETURN is a Script language opcode for creating a non-consumable output of a transaction that can store metadata within the transaction, thereby immutably recording the metadata on the blockchain 150. For example, the metadata may comprise a document that is desired to be stored on the blockchain.
[0059] Signature P A is a digital signature. In an embodiment, this is based on ECDSA using the elliptic curve secp256k1. A digital signature signs specific data. In an embodiment, for a given transaction, the signature signs part of the transaction input and all or part of the transaction output. The specific part of the output it signs depends on the SIGHASH flag. The SIGHASH flag is a 4-byte code included at the end of the signature to select which outputs are signed (and thus fixed at the time of signing).
[0060] The locking script may be called "scriptPubKey", which refers to the fact that it contains the public keys of the parties to whom each transaction is locked. The unlocking script may be called "scriptSig", which refers to the fact that it supplies the corresponding signature. However, more generally, it is not essential in all applications of the blockchain 150 for the condition for redeeming a UTXO to include signature verification. More generally, a scripting language can be used to define any one or more conditions. Therefore, the more general terms "locking script" and "unlocking script" may be preferred.
[0061] Layered Network Layered network structure: A layered network is an overlay network layered on top of a communication channel. For example, the communication channel may be an underlying infrastructure network such as a personal area network, a local area network (e.g., an inter-company P2P network), or a wide area network such as the Internet. In other examples, the layered network may be a network of nodes connected via a wired connection. In yet other examples, the connection may be a wireless connection, such as a Bluetooth or Wi-Fi connection. In some examples, some or all of the above exemplary connections may be used to form the layered network.
[0062] Some or all of the nodes in the network are configured to connect (i.e., join or rejoin) to a multi-layer network according to a connection protocol. The connection protocol may vary according to the specific layer of the network to which the connecting node is connecting (i.e., attempting to join or rejoin). Before the connection protocol is described in detail, a series of exemplary multi-layer networks that may be created or implemented by the connection protocol are described. However, these are merely examples for illustration, and it will be understood that generally any multi-layer network that complies with the connection protocol may be created.
[0063] Figure 3 shows a schematic representation of an example of a multi-layer network (LN) 300. Generally, an LN includes a core network (or core layer) consisting of core nodes 301, and a series of layers (or shells). The core layer is also referred to as the first layer of the LN. The series of layers extends outwardly from the core layer in order from a second layer consisting of second nodes 302 to one or more outer layers. Each outer layer consists of a set of outer nodes 303. Although only one outer layer is shown in Figure 3, it will be understood that the LN may include any number of outer layers. As a specific example, Figure 5 shows an example of an LN500 with five layers, and Figure 6 shows an example of an LN600 with four layers.
[0064] The exemplary LN300 in Figure 3 includes five core nodes 301, six second nodes 302, and eight outer nodes 303. In some LNs 300, the number of nodes may increase with each layer, i.e., the core layer consists of the smallest number of nodes and the outermost layer consists of the largest number of nodes. In other examples, one or more of the layers between the core layer and the outermost layer may consist of the largest number of nodes. In this example, the core layer is the innermost layer of the LN300, the second layer is the middle layer, and the outer layer, which is the only outer layer, is the outermost layer.
[0065] The core layer (network within the LN) in this example forms a complete graph, that is, each core node 301 is connected to each other core node 301. For a core layer of five core nodes 301, in the given example, the core layer requires 10 distinct core connections (i.e., connections between two core nodes). In other examples (e.g., FIG. 4), the core layer may not be a complete graph. The core layer may form a "quasi-complete graph". In a quasi-complete graph, at least one core node 301 is not connected to at least one other core node 301. There may be only one core connection missing. In a particular example of a quasi-complete graph, each core node 301 may be connected to one or more, but not all, of the other core nodes 301.
[0066] The second layer comprises second nodes 302. Note that the term "second node" is used only as a label for nodes 302 that are structurally located in the second layer of the LN300. Each second node 302 is connected to at least one core node 301. In some examples, each second node 302 may be connected to only one core node 301. Alternatively, some or all of the second nodes 302 may be connected to more than one core node 301. For example, some or all of the second nodes 302 may be connected to any core node of the core nodes 301. In the exemplary LN300 of FIG. 3, each core node 301 is connected to two second nodes 302. However, in this example, some of the second nodes 302 (the nodes shown as striped circles) are connected to one core node 301, while some of the second nodes 302 (those shown as white circles and those shown as shaded circles) are connected to two core nodes 301. Second nodes 302 (and outer nodes 303 of the outer layer) that are connected to the same core node 301 are called a "community". For example, each white node together forms one community, each striped node together forms a community, and each shaded node together forms yet another community. The connection between the second node 302 and the core node 301 is called an "ancestor connection" and is shown as a thick dotted line.
[0067] In the example of FIG. 3, each second node 302 is connected to two other second nodes 302. In some examples, some or all of the second nodes 302 may not form connections with other second nodes. For example, some of the second nodes 302 may be connected to other second nodes 302, while some of the second nodes may not be connected to other second nodes 302. These "intra-layer" connections are shown as solid lines between the nodes in FIG. 3.
[0068] The outer layer of FIG. 3 includes outer nodes 303. Here, the term "outer" in "outer layer" is not necessarily limited to the outermost layer of the entire LN network itself, but that is one possibility. Each outer node 303 is connected to at least one second node 302. In some examples, each outer node 303 may be connected to only one second node 302. Alternatively, some or all of the outer nodes 303 may be connected to more than one second node 302. For example, some or all of the outer nodes 303 may be connected to any node of the second node 301. In the exemplary LN 300 of FIG. 3, each outer node 303 is connected to two second nodes 302. Some of the second nodes 302 (i.e., the striped nodes) are connected to two outer nodes 303, and some of the second nodes 302 (i.e., the white nodes and the shaded nodes) are connected to three outer nodes 303.
[0069] In the example of FIG. 3, each outer node 303 is connected to two other outer nodes 303 in the same layer. In some examples, some or all of the outer nodes 303 may not form any connection with other outer nodes 303 in the same layer. Some or all of the outer nodes 303 may form at least one connection with another outer node 303 in the same layer.
[0070] Each outer node 303 is connected to at least one second node 302 and is also connected to at least one core node 301. The connection between the outer node 303 and the core node 301 is called a "core ancestor connection" and is shown as a thin dotted line. Each outer node 303 may be connected to each of the core nodes 301 to which the second nodes 302 of their ancestors are connected. As shown in FIG. 3, each outer node 303 is connected to each of the core nodes 301 to which the second nodes 302 of its ancestors are connected and may not be connected to other core nodes 301. In this case, each outer node 303 belongs to a single community.
[0071] FIG. 4 shows a schematic representation of another example of LN400. Similar to LN300 of FIG. 3, the exemplary LN400 includes a core layer, a second layer, and an outer layer. These exemplary LN300, 400 share the same number of nodes (i.e., 5 core nodes 301, 6 second nodes 302, and 8 outer nodes 303), but include different numbers of connections. For example, in this example, since some connections between core nodes 301 do not exist, the core layer is not a complete graph. Another difference is that two communities (white nodes and shaded nodes) have a single core node 301, while another community (shaded nodes) has three core nodes 301. Yet another difference is that the degree of the nodes in the outer shell of LN400 is 1 here, which is different from the degree of the nodes in the outer shell of LN300 which is 2. That is, in this exemplary LN400, each outer node 303 is connected to a single other outer node 303. Thus, nodes in different layers have different degrees.
[0072] Figure 5 shows a schematic representation of another example of LN500. In this example, only some of the core nodes 301 are connected to the second node and the outer nodes 303. That is, in this example, only some of the core nodes 301 form connections with other core nodes 301. Thus, in this example, LN500 comprises a single community (the shaded nodes). The LN500 of this example comprises five layers: a core layer, a second layer, and a third outer layer. The core layer consists of five core nodes 301 that form a quasi-complete graph. In this example of the quasi-complete graph, only a single core connection is missing. The second layer consists of a single second node 302 that is connected to two core nodes 301. The second layer consists of a single second node 302 that is connected to two core nodes 301. The third layer consists of a single outer node 303 that is connected to the second node 302 via an ancestor connection. The outer node 303 of the third layer is also connected to the two core nodes 301 to which the second node 302 is connected. The outer node 303 is connected to the two core nodes 301 via respective core-ancestor connections. The fourth layer also consists of a single outer node 304. The outer node 304 of the fourth layer is connected to the outer node 303 of the third layer via an ancestor connection and is connected to the second node 302 via an ancestor connection. The outer node 304 of the fourth layer is also connected to the two core nodes 301 to which the second node 302 and the outer node 303 of the third layer are connected. The outer node 304 is connected to the two core nodes 301 via respective core-ancestor connections. Finally, the fifth layer consists of two outer nodes 305. The two outer nodes 305 of the fifth layer are connected to the outer node 304 of the fourth layer, to the outer node 303 of the third layer, and to the second node 302, and each connection is an ancestor connection. The two outer nodes 305 are also connected to the two core nodes 301 via core-ancestor connections. In this exemplary LN500, the nodes of the second layer and the nodes of the outer layer are not connected to any other nodes of the same layer.
[0073] FIG. 6 shows a schematic representation of another example of LN600. This LN comprises two communities of nodes, as indicated by the white and black nodes. In this example, the core layer forms a complete graph (i.e., a network of nodes). Each community comprises a separate set of three core nodes 301. This exemplary LN600 comprises four layers (a core layer, a second layer, and two outer layers). Each node in the outer layer is connected to one node in the preceding layer. As with the exemplary LN500 of FIG. 5, the nodes in the second layer and the outer layer are not connected to any other nodes in the same layer.
[0074] In some embodiments, LN300, 400, 500, 600 (hereinafter referred to simply as "300") may be a "blockchain multi-layer network (BLN)". The term BLN is defined herein as a multi-layer network comprising a blockchain network or at least a part of a blockchain network, such as the blockchain network 106 described with reference to FIG. 1.
[0075] BLN is inspired by the Mandala network and shares some similar features, but is designed to allow a more flexible and desirable connection structure for, for example, services and user networks that utilize the blockchain network 106.
[0076] BLN300 may comprise at least a part of the blockchain network 106 in its core. Generally, the nodes of the multi-layer network are superimposed on an underlying infrastructure network such as the Internet 101. Some or all of the core nodes are nodes 104 of the blockchain network 106. They may comprise mining nodes 104M, storage nodes 104S, or a combination thereof. In an embodiment, each of the core nodes is a mining node 104M and / or a storage node 104S (e.g., a full copy node).
[0077] Each of the outer nodes 303 (or each of the outer nodes of the outermost layer) may be an end - user node that includes a user's computer device. This can be an individual user, or an organization such as a company, academic institution, or government agency. Thus, each outer node 303 may include one or more user terminals and / or a server that includes one or more server units located in one or more locations. Each outer node 303 includes a memory having one or more memory units and a processing device having one or more processing units. These may take either the form of a memory medium and / or a processor, such as those previously discussed in relation to other network elements or user devices. The memory stores client software to be executed on the processing device, and the client software, when executed, is configured to operate the node as a client of a protocol that adheres to a connection protocol, according to any of the following embodiments or similar ones. Optionally, one or more of the end - user nodes may include the user device 103 of the user 102 of the blockchain network 106, and the client software may include a blockchain wallet application 105 or the like.
[0078] Each second node 302 may be in the form of a server comprising one or more physical server units. Each such node comprises a memory comprising one or more memory units and a processing device comprising one or more processing units. These may take either the form of a memory medium and / or a processor, such as those previously discussed with respect to other network elements. The memory stores software adapted to be executed on the processing device of the second node 302. This software, when executed, is configured to comply with a connection protocol according to any of the following embodiments or similar ones. In some embodiments, the software, when executed, is configured to provide a service that operates according to any of the embodiments described below or similar ones.
[0079] In some examples, some or all of the second node 302 may operate a smart contract service. The smart contract service is configured to execute a predefined operation in response to and based on a blockchain transaction transmitted to the smart contract service by one of the other nodes of the LN300, for example by the outer node 303. For example, the smart contract may transmit the blockchain transaction to the core node 301 in response to receiving a specific blockchain transaction from the outer node 303.
[0080] In other examples, some or all of the second node 302 may operate, inter alia, a distributed database. That is, each second node 302 operating a distributed database is configured to store data received from another node of the LN300, for example the outer node 303. The second node 302 that receives and stores the data may also be configured to spread the data to other second nodes 302 that also operate a distributed database.
[0081] Nodes 301, 302, and 303 are configured to form connections with each other at the overlay network level. That is, nodes 301, 302, and 303 of the multi-layer network are configured to follow an overlay network protocol that specifies which connections they can form and which they cannot form with other nodes 301, 302, and 303 of the multi-layer network. Thus, although it may be physically possible (but not necessarily) for all nodes to be connected to each other via an underlying infrastructure (e.g., the Internet), when they are participating as nodes 301, 302, and 303 of the multi-layer network and operating according to the relevant overlay network protocol of the multi-layer network 300, the connections between such nodes 301, 302, and 303 may be more restricted. A connection between two nodes 301, 302, and 303 of the multi-layer network 300 means that those nodes can communicate directly with each other, which, in this context, means that they do not have to perform a hop via another node 301, 302, and 303 of the multi-layer network 300. In the context of an overlay network such as a multi-layer network, "connection" means a connection (i.e., an edge) at the level of the multi-layer network 300 (i.e., at the level of the overlay network protocol of the multi-layer network).
[0082] In an embodiment where LN300 is BLN, some or all of the second nodes 302 may be configured to transmit blockchain transactions to the core nodes 301 to which those second nodes 302 are connected. In some examples, the second nodes 302 may generate blockchain transactions before transmitting the blockchain transactions to the core nodes 301. In other examples, the second nodes 302 may transfer blockchain transactions to the core nodes 301. For example, the second nodes 302 may receive blockchain transactions from the outer nodes 303 and transmit the received blockchain transactions to the core nodes 301. Similarly, a given second node 302 (i.e., some or all of the second nodes) may be configured to obtain blockchain transactions from the core nodes 301 and / or outer nodes 303 to which the given second node 302 is connected.
[0083] Additionally or alternatively, some or all of the outer nodes 303 may be configured to transmit blockchain transactions to the core nodes 301 to which they are connected. The outer nodes 303 may also be configured to transmit blockchain transactions to the second nodes 302 to which they are connected. In some examples, the outer nodes 303 may transmit blockchain transactions to the second nodes 302 and the core nodes 301.
[0084] Some or all of the outer nodes 303 may be configured to transmit blockchain transactions to other outer nodes 303, such as outer nodes in the same layer, or outer nodes in a previous or next layer in an ordered set of layers.
[0085] In an embodiment where the core nodes 301 of the BLN300 each perform the role of the blockchain node 104, some or all of the second nodes 302 and / or the outer nodes 303 may be configured to request confirmation that a given transaction has been accepted in the pool of transactions of the mining node 104M to which a given second node 302 or outer node 303 is connected. The pool 154 (which may sometimes be referred to as a memory pool) comprises transactions that have been validated according to a set of consensus rules of the blockchain network 106. When a transaction (e.g., the "first transaction") is included in the pool 154, the mining node 104M does not accept another transaction (e.g., the "second transaction") that attempts to double-spend the output referenced by the input of the first transaction. Accordingly, the second nodes 302 and / or the outer nodes 303 can query the core nodes 301 to confirm that a transaction (e.g., a transaction issued to the blockchain network 106 by the nodes 302, 303) has been accepted, or to confirm whether a transaction (e.g., a transaction received from another node of the BLN300) is an attempt at double-spending. The core nodes 301 are configured to transmit a response to the request to the requesting nodes 302, 303.
[0086] Additionally or alternatively, the second node 302 and / or the third node 303 may be configured to transmit a request for a Merkle proof of a transaction mined in block 151 of the blockchain 150 to the core node 301. Merkle proofs are familiar to those skilled in the art. A Merkle proof is a sequence of hashes that traces back to the Merkle root. To verify whether a transaction was mined in block 151, nodes 302, 303 take the hash of the transaction, concatenate it with the first hash in the sequence of hashes of the Merkle proof (i.e., the hash partner in the Merkle tree at the same level as the hash of the transaction), and hash the result. This process of concatenation and hashing is repeated until all of the hashes in the Merkle proof are utilized. If the resulting hash is identical to the Merkle root, the transaction must be included in the Merkle tree and thus in block 151. The core node 301 is configured to transmit the Merkle proof to the requesting nodes 302, 303.
[0087] Additionally or alternatively, the second node 302 and / or the third node 303 may be configured to transmit a request for a block header of a given block 151 to the core node 301. Among other data, the block header includes the Merkle root of the transactions to be mined into block 151. The core node 301 is configured to transmit the Merkle proof to the requesting nodes 302, 303.
[0088] In some embodiments, some or all of the core node 301 may be configured to transmit a set of transactions to some or all of the second node 302 and / or some or all of the outer nodes connected to the core node 301. The transactions in the set may share a common attribute. For example, the core node 301 may transmit all transactions containing a specific protocol flag. This flag may be included in the output of the transaction, for example, in a non-consumable output. As another example, the transactions may have a specific (and the same) blockchain address, for example, they may be payable to the same blockchain address. The outer node 303 may have an agreement with the core node 301 that the core node 301 will send any transaction payable to an address associated with the outer node 303. As yet another example, the transactions may have a secondary consensus rule set. That is, the transaction may include more than one control branch in the output, and each control branch is specific to its own consensus rule set. The output may include a first control branch specific to the first rule set and a second control branch specific to the second rule set (these two control branches may be included in an if-else condition). If the nodes 302, 303 are configured to implement the second rule set, the core node 301 may transmit the transaction to the nodes 302, 303. If the nodes 302, 303 are not configured to implement either the first rule set or the second rule set, the core node does not transmit the transaction to the nodes 302, 303.
[0089] The core node 301, which is the mining node 104M, may include an identifier specific to that mining node 104M (e.g., "Miner ID") in the generated transaction (also called the "coinbase" transaction) mined by the mining node 104M into block 151. Other nodes of the BLN300 may use an identifier to identify that mining node 104M on the network.
[0090] Another way to identify nodes 301, 302, 303 of LN300 is by digital certificates. Some or all of nodes 301, 302, 303 may be associated with digital certificates. A digital certificate includes identifiers such as the identifier of each node, for example, the public key associated with that node, the network address of the node (e.g., IP address), and proves it. Nodes of LN300 may use digital certificates of different nodes to connect to that node. For example, the outer node 303 may obtain a digital certificate from the second node 302 and use the identification information of the second node included in the digital certificate to connect to the second node 302.
[0091] Nodes of a given layer may issue digital certificates to nodes of the next layer in the ordered set of layers, that is, the core node 301 may issue a digital certificate to the second node, the second node 302 may issue a digital certificate to the outer node 303 of the first outer layer, and so on. In some examples, nodes of a given layer may issue digital certificates to nodes of the same layer. For example, the second node 302 may issue its respective digital certificate to one or more other second nodes 302.
[0092] Connection protocol: As described above, each node connecting to the multi-layered network 300 may connect according to the connection protocol. That is, the connecting nodes must follow the rules of the connection protocol. The connecting nodes may only form connections permitted by the connection protocol. Other connections may not be formed. In the example, the connecting node may be the core node 301, the second node 302, or the outer node 303. In some examples, each node of the LN300 must follow the connection protocol. In other examples, only the nodes that are connecting to the LN300 for the first time or rejoining the LN300 must follow the connection protocol. FIGS. 3 to 6 show exemplary LN300, 400, 500, 600 established according to the connection protocol.
[0093] Physically speaking, each of the nodes of the LN300 may in some examples be connected at some other level or to each other, for example via the Internet. The connection protocol imposes constraints on which connections can be formed at the overlay network level, i.e., at the multi-layered network level, such that some connections do not exist or are not permitted. Each connecting node of the LN300 is configured to operate according to the overlay level protocol of the LN300 (which includes the connection protocol) that determines which connections a node can form and which connections it cannot form at the overlay level. In other words, a connection is a permitted communication channel such that two nodes are configured to be permitted to form it by their protocols. If a node has a connection to another node, it can communicate with that node without hopping through another node of the multi-layered network, but if it does not have that connection, it cannot communicate and may only communicate by hopping through one or more other nodes that have a connection in between.
[0094] The connection protocol requires that the connecting node connect to at least one node of the preceding (more inner) layer and at least one core node, except for the exception that in some examples the core node may be the innermost layer and thus cannot connect to the preceding layer. In an example where the connecting node is the second node, these two requirements are equivalent. When the connecting node is an outer node of the first outer layer, the connecting node connects to at least the second node 302 and the core node 301.
[0095] The connection protocol may require that the connecting node connect to more than one core node. The connection protocol may further require that the connecting node connect to more than one but not all of the core nodes, for example, all core nodes except one. The connecting node may be a second node that must connect to more than two core nodes. That is, some or all of the second nodes must connect to more than two core nodes (and in some examples, not all of the core nodes).
[0096] The connection protocol may require the connecting node to connect to one or more second nodes. When the connecting node is the second node, this means that the connecting (second) node must connect to one or more different second nodes. When the connecting node is an outer node, the connecting (outer) node must connect to one or more second nodes. The outer node to be connected may be an outer node of the first outer layer, or an outer node of the second layer, etc.
[0097] The connection protocol may require that an outer node connected to a node in a preceding layer be connected to some or all of the core nodes (referred to above as "core ancestors") to which the nodes in the preceding layer are connected. For example, the outer node may be connected to a second node. In that case, the outer node must also be connected to the core nodes to which the second node is connected. If the outer node is connected to more than one second node, the connection protocol may require that the outer node be connected to the core nodes to which each of the second nodes is connected. As another example, an outer node in a second outer layer may be connected to an outer node in a first outer layer. In that example, the connection protocol requires that the outer node in the second outer layer be connected to the core nodes to which the outer node in the first outer layer is connected.
[0098] The connection protocol may require that an outer node connect to one or more (e.g., two) outer nodes in the same outer layer. The connection protocol may require that each outer node connect to one or more outer nodes in the same layer. Alternatively, some outer layers may include outer nodes that form connections to one or more of the same layer, and some outer layers may include outer nodes that do not form connections to one or more of the same layer. The connection protocol may require that each outer node in the same outer layer connect to the same number of different outer nodes in that layer. For example, each outer node in a first outer layer may be required to connect to two outer nodes. Each outer node in a second outer layer may be required to connect to three outer nodes. That is, the number of outer nodes in the same layer to which an outer node is connected may vary between outer layers.
[0099] In some embodiments, the outer nodes of the i-th outer layer (e.g., the third outer layer) may be connected to the outer nodes of the preceding (i - 1)-th layer (e.g., the second outer layer). The connection protocol may require that the outer nodes of the successive (i + 1)-th outer layer (e.g., all outer nodes) be connected to each node of the (i - 1)-th layer to which the outer nodes of the i-th outer layer are connected. For example, the outer node 305 of the fifth layer in LN500 of FIG. 5 is connected to the outer node 304 of the fourth layer and the outer node 303 of the third layer. In some examples, the connection protocol may require that the outer nodes of the (i + 1)-th outer layer be connected to each outer node of each preceding layer to which the outer nodes of the i-th outer layer are connected.
[0100] In embodiments where some or all of the nodes of LN300 are associated with digital certificates, the connection protocol may require that a connecting node be connected only to nodes associated with nodes associated with respective digital certificates. In some embodiments, the connection protocol may require that a connecting node (e.g., an outer node) be connected only to each node (e.g., a second node) when the digital certificate associated with each node is issued by a node of a layer preceding each node (e.g., a core node), or in some examples, by a node of the same layer of each node (e.g., a different second node).
[0101] In some embodiments, the connection protocol may require that a connecting node be able to connect only to the node that issued the connecting node with a digital certificate. That is, connecting to a node comprises receiving a digital certificate from that node.
[0102] The connection protocol enables the construction of a BLN. Like the Mandala network, the BLN is constructed in multiple layers. Unlike the Mandala network, the first layer may form an incomplete graph (e.g., a quasi-complete graph). Another difference between the BLN and the Mandala network is that in the BLN, nodes in each successive layer may have different degrees, a node may be connected to more than one node in the central layer, and / or the degrees of the nodes may vary between layers.
[0103] Preferably, for all nodes outside the central core, (i) each node is connected to m out of n1 nodes in the central core. (ii) each node is connected to nodes in every layer, where g is the total number of layers. (iii) each node is a member of only one community. There are at most n2 communities, where n2 is the number of nodes in the second layer. (iv) each node is connected to every other node by at most 3 hops. This is called the diameter of the graph.
[0104] In a BLN, a "community" is defined as a set of nodes that share exactly the same set of core ancestors. Figure 6 shows a BLN with a network where n1 = 6, m = 3, and g = 4, depicting nodes of two separate communities, a black-node community and a white-node community. The white-node community comprises nodes that are all connected to the 3 nodes on the LHS of the central core, while the black-node community comprises nodes that are all connected to the 3 nodes on the RHS of the central core.
[0105] The characteristic of the Mandala network is that all nodes outside the core layer (i = 1) are connected to exactly one core ancestor (i.e., c i = 1 everywhere). This significantly contributes to the emerging characteristics of the Mandala network. · Network size (N = Σi n i has an average shortest path that asymptotes to a certain constant as · The network size (N = Σ i n i ) becomes sparser as it increases. · Is robust against failures of random nodes.
[0106] The characteristic of the BLN is that all non-core nodes are connected to at least one ancestor. However, the definition of the BLN accepts non-core nodes with a maximum of m connections to core ancestors (i.e., anywhere 1 ≦ c i ≦ m). c i = 1 to 1 ≦ c i ≦ m for the overall generalization, the BLN can be understood as an artifact of the blockchain protocol. The protocol that defines the blockchain system depends on a probabilistic security model. Basically, this means that any participant (node) in the BLN with a given interest in the events recorded in the blockchain 150 must consider the probabilistic security model by connecting to a minimum fraction f of the network hash power, and 100% of the total hash power is distributed among the nodes in the core layer of the BLN. Assuming that the core layer shows a uniform and balanced distribution of hash power among n1 core nodes, the minimum fraction of nodes is f = m / n1 .
[0107] The blockchain protocol shows that the lower bound of the minimum fraction is f = 0.51, but large-scale BLN network participants may require a higher fraction (e.g., f = 0.67) for higher resistance (e.g., against double-spending). The BLN may be characterized by the choice of the parameter m, because this determines the probabilistic security of the behavior for the participants within the BLN, which depends on the specific use case of the requirements of the BLN in question.
[0108] The nodes in the second layer L2 closest to the core rely most strongly on the probabilistic security model of the blockchain protocol, and this dependency may decrease as the layer approaches L g and may decrease as the layer approaches L. The connection protocol may require the nodes in L2 to connect exactly to c2 = m core ancestors, but the nodes in all consecutive layers where i > 2 may connect anywhere within the range of core ancestors 1 << c i ≤ m. In some examples, the nodes in all consecutive layers must connect to m core ancestors.
[0109] Nodes outside the central core of the BLN may have a "SPV-like" connection to the core. This means that those nodes can do the following. a) Send transactions to core nodes b) Ask core nodes whether the transactions have been accepted in the memory pool / block candidates c) Request Merkle proofs of the transactions mined in the block d) Request the latest list of block headers
[0110] These simple and targeted requests are designed to enable the construction of the widest possible range of scalable solutions using the BLN while reducing the burden on the core node 301 as much as possible. Many use cases do not require anything other than the types of connections described above. In some examples, the second node 302 and / or the outer node 303 are configured to be able to perform only the actions a) to d) above. However, other solutions, usually at the enterprise level, may require the core to actively supply more data to the nodes, such as transactions that meet certain criteria. Therefore, actions a) to d) are the minimum requirements for the BLN, but additional data transfers between those nodes and the core are also possible in some examples.
[0111] For nodes operating smart contracts, some nodes may only need activities a) through d) like SPV, while other nodes may need to perform consensus to receive more data from core nodes.
[0112] In some BLNs, users may operate nodes at layer 3 or above, and smart contracts may be operated by nodes at layer 2 or above. It is not practical for a user to continuously "listen" to the blockchain for transactions with a specific output address, because to do so, it is necessary to constantly monitor the blockchain 150 for transactions containing that specific address. Considering that the number of transactions that can be transmitted to the blockchain per unit time continues to increase, such constant monitoring is not realistic for end users. Constantly monitoring the blockchain is common among the wallet architectures of some blockchains, but considering that both the number of transactions issued to the blockchain per unit time and the number of blockchain users are expected to increase dramatically in the future, it is not a scalable solution. Consider the following example. Alice wishes to pay Bob. Alice creates a transaction for the desired amount with the output address that she knows Bob owns. Alice then sends this transaction not directly to Bob, but to the mining network. For Bob to know that the transaction has been accepted, Bob has to "listen" to the blockchain to check whether and when a transaction with his output address has appeared on the network. Bob has to rely on the mining nodes to do this on his behalf. This means that the mining nodes have to keep a record of Bob's address and check whether every transaction they receive matches this address. Note that there is no economic incentive for miners to do this. It can be seen that this quickly becomes unrealistic when considering that miners have to process millions of transactions per second and check whether they match millions of addresses.
[0113] Instead, in BLN, Alice may be directly connected to Bob and can directly send a transaction to Bob. Bob can then send the transaction to the miners in the core and at the same time ask them whether they accept the transaction as valid. Since the transaction includes the miners' fees, the miners have an incentive to accept the transaction and an incentive to confirm whether they have accepted the transaction, thus reducing the risk of building a block that will be isolated. To make the system more secure, Alice may send a Merkle proof of the inputs to her transaction to Bob. Since Bob has a copy of the block header, he may verify these Merkle proofs. This guarantees to Bob that Alice's inputs were part of the blockchain 150 at a certain point in time, and if Alice has already consumed them, in the transaction given by Alice to Bob, Bob will have proof of double spending since he has received a signature from Alice. Note that Bob may be a smart contract (second node) and Alice may be a user (outer node) who wishes to interact with that smart contract. If the smart contract is "lightweight" in the sense that the smart contract operator has not made any specific agreement with the mining nodes to facilitate the processing of the smart contract, the smart contract cannot rely on listening to the blockchain 150 to receive transactions that cause state changes. Alice must send such transactions directly to the smart contract.
[0114] The service provider may operate nodes at layer 2 or above. The case of the service provider is different from that of the user or lightweight smart contract. The service provider may have a commercial agreement with the core mining node or an aggregate of core nodes, and those core nodes then spread a subset of the transactions to the service provider nodes. Such transactions must be easily identifiable and meet certain criteria. For example, · OP_RETURN data with specific protocol flags. For example, the Metanet protocol, the Tokenized protocol, or the digital certificate protocol. · Output addresses that match a small specific set. For example, enterprise-level smart contracts or address whitelists / blacklists. · A secondary consensus rule set indicated by the OP_VER control branch.
[0115] In addition, transactions that follow these rules or are sent to the core identified in other ways as part of the community involved in the service level agreement may have a lower (or even zero) transaction fee. The shortfall may be made up by a higher transaction volume or by revenue in fiat currency under the service level agreement.
[0116] All nodes of BLN300 may be associated with a semi-permanent public key related to their identification information. This public key can enable secure communication and provide a link to the public key used in blockchain transactions either through a deterministic derivation of the identification information key or by signing or encrypting a transaction key using the identification information key.
[0117] Two ways to identify mining core nodes are as follows. 1) Miner ID. A miner may choose to identify itself by adding an identification information key to the input of the coinbase transaction in each block it mines. 2) Network analysis. Some miners choose to remain anonymous. However, even then, it is possible to identify which nodes are building blocks through network analysis, for example, by looking at where new blocks are originating.
[0118] It is important to be able to identify both types of miners so that BLN nodes can ask as many miners as possible whether their transactions have been accepted. Core nodes with a Miner ID can issue digital certificates to layer 2 nodes. This may be because they have a service level agreement with these nodes, or because these nodes have requested a certificate for a fee. In this sense, core nodes can act as a certification authority (CA).
[0119] With or without a certificate from a core node, layer 2 nodes may look for an external CA that should issue a digital certificate. Thus, each layer 2 node may have at least one digital certificate to prove its identity. They may issue certificates to other nodes in layer 2, thereby creating a web of trust among them. Layer 2 nodes may issue certificates to layer 3 nodes, layer 3 nodes may issue certificates to layer 4 nodes, and so on, creating a hierarchy of certificates called a public key infrastructure (PKI).
[0120] In practice, PKI can be used not only for identifying nodes in the BLN, but also for ensuring that the correct BLN structure is followed. For example, if a layer 3 node issues certificates to too many layer 4 nodes, or does not ensure having proper connections to other nodes in the system, the certificate of the layer 3 node may be invalidated. These certificates themselves may be stored in the blockchain 150. This makes the PKI transparent and easily auditable.
[0121] Ordering and Timestamping There may be several application examples that can be implemented using a blockchain where the order of application data is important. To address this, according to embodiments of the present disclosure, one or more nodes of the network may act as a certification service to arbitrate between different items of data sent to the service to determine the final order of the data items, and to ensure that that order is immutably recorded in the blockchain.
[0122] The proof service is implemented at one or more proof nodes. In embodiments, these are nodes of an overlay network that is superimposed on an underlying infrastructure network such as the Internet. However, alternatively, it is not excluded that they may be nodes of an independent network, such as the infrastructure of a private network within an organization. In any case, one or more proof nodes are adapted to receive items of data from one or more client nodes, form a transaction that records the order of the received data items, and transfer these transactions to one or more core nodes for recording to the blockchain 150. The core nodes are the nodes 104 of the blockchain network 106. They may comprise mining nodes 104M, storage nodes 104S, or a combination thereof. In embodiments, each of the core nodes is a mining node 104M and / or a storage node 104S (e.g., a full copy node).
[0123] Each client node may be an end-user node equipped with a user's computer device of a service. This can be an individual user, or an organization such as a company, academic institution, or government agency. Thus, each client node may include one or more user terminals and / or a server having one or more server units located at one or more locations. Each client node includes a memory having one or more memory units and a processing device having one or more processing units. These may take either the form of a memory medium and / or a processor, such as those previously discussed in relation to other network elements or user equipment. The memory stores client software to be executed on the processing device, and the client software, when executed, is configured to operate the node as a client of the proof service provided by the proof node according to any of the following embodiments or the like. Optionally, one or more of the transmission end-user nodes may include the user equipment 103 of the user 102 of the blockchain network 106, and the client software may include a blockchain wallet application 105 or the like. However, not all such transactions need necessarily be compiled in the user's wallet 105, and the proof service may be configured to compile at least some of the transactions on behalf of such end-users.
[0124] The proof node is adapted to provide a proof service that arbitrates between the client node and the core node. Each proof node may be in the form of a server comprising one or more physical server units. Each such node comprises a memory comprising one or more memory units and a processing device comprising one or more processing units. These may take the form of either a memory medium and / or a processor, such as those previously discussed in relation to other network elements. The memory stores proof service software adapted to be executed on the processing device of the proof node. This software, when executed, is configured to provide a proof service that operates according to either the embodiments described below or similar ones. In an embodiment, the identification information of each proof node may be authenticated by a certification authority in order to enable the client node, the core node, and / or other proof service nodes to verify the identification information of the proof node. The identification information of each client node may be authenticated by a certification authority in order to enable the proof service node, the core node, and / or other client nodes to verify the identification information of the client node. The interaction between such nodes for providing or using the proof service may be conditional upon verification. Alternatively or additionally, version management of the nodes may be used as an alternative mechanism for node identification in the overlay network.
[0125] In an embodiment, the above configuration may be implemented in the form of a multi-layer network 700 of the type described, for example, with respect to FIGS. 3 to 6 and as also shown by way of example in FIG. 7. That is, the multi-layer network includes a core network having a core node 701, an intermediate layer around the core, each intermediate layer having one or more intermediate layer nodes 702, and at least one outer layer around the outermost of the intermediate layers, each outer layer having one or more outer layer nodes 703. Here, it should be noted that the term "outer" in "outer layer" is not necessarily limited to the outermost layer of the entire multi-layer network 700 itself, but that is also one possibility. In an embodiment, the multi-layer network 700 of FIG. 7 may be the multi-layer network 300 of FIG. 3, in which case the outer layer nodes of FIG. 7 are the nodes of the third layer of FIG. 3 or FIG. 4, the intermediate layer nodes 702 of FIG. 7 are the nodes 302 of the second layer of FIG. 3 or FIG. 4, and the core node 701 of FIG. 7 may be the core node 301 of FIG. 3 or FIG. 4.
[0126] As discussed with respect to FIGS. 3 to 6, the multi-layer network 700 may be an overlay network superimposed on a physical network or infrastructure network serving as a foundation such as the Internet. In such an embodiment, the nodes 701, 702, 703 are configured to form connections with each other at the overlay network level. That is, the nodes 701, 702, 703 of the multi-layer network are configured to follow an overlay network protocol that specifies which connections they can and cannot form with other nodes 701, 702, 703 of the multi-layer network. Thus, although all nodes may be able to connect to each other physically via the underlying infrastructure (e.g., the Internet), when they participate as nodes 701, 702, 703 of the multi-layer network and operate according to the relevant overlay network protocol of the multi-layer network 700, the connections between such nodes 701, 702, 703 may be more limited. A connection between two nodes 701 / 702 / 703 of the multi-layer network 700 means that those nodes can communicate directly with each other, which in this context means that they do not have to perform a hop via another node 701 / 702 / 703 of the multi-layer network 700. In the context of an overlay network, "connection" means a connection (i.e., an edge) at the level of the overlay network (i.e., the level of the overlay network protocol of the multi-layer network).
[0127] Each intermediate layer node 702 is connected to at least one core node 701 (blockchain network node 104) in the core network. The core network comprises at least a part of the blockchain network 106. In an embodiment, the core network itself may be a complete network.
[0128] In some cases, some of the intermediate layer nodes 702 and / or the outer layer nodes 703 may include peripheral nodes 104 of the blockchain network 106, such as mining nodes 104M other than transfer nodes 104F and / or storage nodes 104S, or nodes other than these. Alternatively, they may include nodes that do not have any role (mining, storage, or transfer) in the blockchain network 106 other than as clients of the blockchain network 106.
[0129] Each outer layer node 703 is connected to at least one of the intermediate layer nodes in at least one intermediate layer. In an embodiment, each outer layer node 703 also has at least one connection to at least one core node 701 (i.e., to the blockchain network 106). In some such embodiments, one or more of the outer layer nodes 703 each have a connection to more than one but not all of the core nodes 701. In an embodiment, the multi-layered network 700 as a whole may be an incomplete network, i.e., each node 701, 702, 703 does not have a connection to each other node at the overlay network level. In an embodiment, each node within a given layer may be connected to at least one other node within the same layer. For example, each node 702 in the intermediate layer may be connected to one or more other nodes within the same intermediate layer, and / or each node 703 in the outer layer may be connected to one or more other nodes within the same outer layer. In an embodiment, connections may also be formed between different intermediate layer nodes 702 in different intermediate layers and / or between different outer layer nodes 703 in different outer layers.
[0130] In an embodiment, the multi-layered network 700 may be configured according to any of the protocol rules or structural features described with respect to FIGS. 3 to 6, each intermediate layer of the intermediate nodes 702 is a layer between the core layer and the outermost layer, and each outer layer of the outer nodes 703 is a layer outside the second layer (the intermediate layer is between the core layer and the outer layer).
[0131] The following embodiments are illustrated in the context of a multi-layer network, but are not limiting, and more generally, it will be understood that a proof node can be any node of any type of overlay network that arbitrates between one or more client nodes of the blockchain network 106 and one or more core nodes 104.
[0132] In an implementation in the multi-layer network 700, at least one of the intermediate nodes 702 in at least one intermediate layer assumes the role of a proof node 702A that provides a proof service. At least one of the outer nodes 703 in the outer layer in at least one outer layer is a client node 703C of the proof service provided by the proof node 702A. Each core node 701 is one of the nodes 104 of the blockchain network 106, preferably a miner 104M and / or a storage node 104S (e.g., a full-copy node). For simplicity of illustration, only two client nodes 703C and two proof nodes 702A are shown in FIG. 7, but it will be understood that there may be more proof nodes. In an embodiment, the client node 703C and the proof node 702A may be part of the same community as each other.
[0133] Client node 703C is a client, at least in that they are clients of the proof service. In an embodiment, the client software executed on one or more of client nodes 703C may further be configured to operate that node 703C as a client of one or more additional services provided by one or more second-layer nodes 702, such as a database service or a smart contract service. And / or, it may be configured to operate that node 703C as a client of one or more core nodes 701 of the blockchain network 106 (e.g., 104M, 104S), such as to enable querying of the blockchain 150.
[0134] Also, the fact that client nodes 703C are described as clients of the proof service (and optionally one or more other services) does not preclude the possibility that these nodes themselves may be providers of one or more additional services to one or more further entities (not shown). For example, client node 703C may comprise the computer equipment of a company that provides online services to customers. As used herein, "end user" means the end user of a particular service in question, and is not necessarily limited to an individual consumer at the end of a commercial supply chain (although this is of course one possibility).
[0135] The following describes a method by which the ordering service entity 702A may use the blockchain 150 to record the order and time in which data elements are received from one or more client nodes 703C. Optionally, the ordering service may perform timestamping.
[0136] This method is first described for a single trusted sequential proof node 702A. This may be modeled as a single intermediate layer (e.g., the second layer) node within a multi-layered network 700 with the core of the blockchain network nodes 104 / 701. A user of this service then becomes a user of an outer layer (e.g., the third layer) node 703C that is directly connected to the service 702A and optionally also connected to the blockchain 150 (by connection to at least one core node 701 within the core).
[0137] When data elements are received from a client node 703C in the outer layer, the intermediate layer timestamping service 702A collects the data elements together in a way that an order is established. After a period, e.g., 0.1 seconds has elapsed, this ordered list of data elements is encapsulated in a transaction and sent via the core 701 to the blockchain 150, where it is immutably recorded. If a timestamp is added to the record, this also records the order over time.
[0138] An exemplary application is to determine a final order between updates, such as to database entries. In this case, each data item received from the client node 703C may represent a respective change (i.e., update) to the state of a database entry. However, such updates are not necessarily commutative, i.e., the order matters. For example, if there are two requests to perform non-commutative operations on data elements, such as matrix multiplication from left to right, the order is important. In another example, one may be a request to delete a file and the other may be a request to read the file. Again, the order in which these requests are applied makes a difference in the result.
[0139] Another exemplary application is to implement smart contracts in an output-based (e.g., UTXO-based) blockchain model. Since UTXO-based transactions, etc., do not originally support smart contracts in the same way as transactions in an account-based model, the functionality of smart contracts needs to be layered on top of the basic transaction model when the smart contract is to be implemented in an output-based model such as a UTXO-based model. In this case, the data items that will be recorded on the blockchain 150 may also represent state changes such as changes in ownership. Again, order is important as it may affect, for example, whether an attempt to assign ownership is valid.
[0140] Another exemplary application is the ordering and timestamping of digital certificates from a Certificate Authority (CA). Digital certificates are used to grant access rights or other electronic permissions and are used, for example, in the SSL / TLS and HTTPS security that underlies the Internet. In 2011, a Dutch CA was compromised by attackers who were thought to be operating from Iran. Fake certificates were issued for important domains and log files were tampered with on the CA's server. If these log files had been stored on the blockchain using an ordering and timestamping service as described below, it would not have been possible to change the log files due to the security provided by proof of work. It is worth noting that the company's HSM private key was compromised in that attack. This highlights the fact that one cannot always rely solely on classical cryptographic protocols to ensure information security and that it may also be beneficial to rely on other mechanisms such as proof of work to make such attacks prohibitively cumbersome.
[0141] In operation, the proof node 702A is adapted to receive a plurality of data items from one or more client nodes 703C via an overlay network connection between an intermediate layer and an outer layer. The data items may here be labeled D by arbitrary terminology. The plurality of data items in question may be received from the same client node 703C or different client nodes 703C, or some may be received from the same client node 703C and some from different client nodes 703C. They may be received directly via the connection between the client node 703C and the proof node 702A, or may be transferred via one or more other nodes of the multi-layer network therebetween (i.e., may be received via more than one hop between the transmitting client node 703C and the proof node 702A).
[0142] The proof node 702A is configured to determine the order of the plurality of data items D, and thus determines a sequence of the plurality of data items. In an embodiment, the determined order is the order of reception of the data items at the proof node 702A. However, it is not excluded that some other arbitration rules may apply. For example, if the data items are timestamped by the client node 703C that transmitted or created them and the proof node 702A trusts these client nodes, the order may be the reported time of transmission or creation rather than the time of reception. As another example, the order may depend on a priority scheme that assigns different weights to different data items.
[0143] Regardless of what the determined order is, the proof node 702A authenticates this order by creating a series of blockchain transactions 152 for recording to the blockchain 150. The proof node 702A generates a series of two or more such transactions, which may be labeled Tx0, Tx1, Tx2... in this specification by arbitrary terminology. The proof node 702A includes in the payload of each successive transaction of the series of transactions Tx an indication of one or more different sets of data items D. The payload may be included in the unspendable output of each respective transaction. Such an output may be made unspendable by an opcode that terminates the locking script of that output, for example OP_RETURN. However, in other transaction protocols, the payload may be included in other ways. The set or sets of one or more data items shown in each successive transaction come after the set shown in the transaction immediately preceding that transaction in the series of transactions, according to the order of the data items determined by the proof node 702A. That is, the order of the transactions in the series of transactions matches the order of the sets in the determined sequence of data items.
[0144] The proof node 702A creates, or otherwise determines, a corresponding series of public / secret key pairs for the series of transactions P1, P2, P3,... The proof node 702A uses the secret key of each key pair to sign the corresponding transaction in the series of transactions
[0145] The proof node 702A Tx0 → Tx1 → Tx2 → Tx3 → … The proof node 702A uses the secret key of each key pair to sign the corresponding transaction in the series of transactions
[0146] Transaction Tx1 includes the signature of P1 in the unlocking script among its inputs, transaction Tx2 includes the signature of P2, and so on. Each transaction also includes a payload that includes an indication of a set of one or more data items D proven by each respective transaction, for example, in an OP_RETURN field. This payload is signed by each signature (in embodiments utilizing a Script language, appropriate SIGHASH flags may be used). The first funding transaction Tx0 is constructed such that it can be unlocked by a signature of P1. It may have an output point 0 with a certain dust value. As an example, Tx1 may be constructed as shown in FIG. 8. All subsequent transactions have the same structure. That is, Tx2 includes a signature using P2 in an input indicating Tx1 for unlocking Tx1 and has a locking script in an output that can be unlocked by a signature of P3, and so on. This signature can be verified by the blockchain network 106 based on the corresponding public key of the key pair. The funding transaction Tx0 may or may not include an indication of a first set of data items (the first set of data items in the sequence may be shown in Tx0 or Tx1).
[0147] Note: The format shown in FIG. 8 ignores transaction fees for simplicity. This can be accounted for by adding additional inputs and outputs to the transaction (e.g., managed by a proof service).
[0148] The OP_RETURN statement includes a payload called data1. This includes data elements D or their indications issued by the user in the order proven by the proof service, among the set proven by Tx1 (and similarly for data2 in Tx2, etc.). Since each transaction signs the hash of the previous transaction, this implies the order of the payloads data1, data2, data3, etc.
[0149] Once a blockchain transaction is accepted by the blockchain network 106, it cannot be double-spent feasibly. It also functions in the form of disclosure of the order proven to the proof service provided by the proof node 702A. This gives the user of the client node 703 the confidence that they cannot retroactively change the position where the data elements appear in the order proven by this certification authority. When such a transaction is mined in block 151, the possibility of the order being changed becomes even lower, because it is computationally expensive to replace the existing block.
[0150] In some embodiments, the set shown in each transaction Tx0, Tx1, Tx2,... consists of only a single data item of the data item D for each transaction (i.e., each data payload indicates only a single respective D). Alternatively, the set shown in each such transaction may comprise a plurality of data items D per transaction (each data payload indicates a different respective set of a plurality of different data items D). In the latter case, the payload information also specifies the order of the data items D within the local set of each transaction. This may be achieved, for example, by an ordered list included in the payload (e.g., an OP_RETURN output), and / or by an index indicating the order mapped to the indication of each D. Examples are shown in FIGS. 9 to 11, which will be discussed in more detail shortly.
[0151] When multiple data items D are shown for each transaction, some basis is needed to determine which data items will be grouped together for each transaction. In principle, any scheme can be used to separate data items between transactions, but in an embodiment, this may be done based on regular time intervals. That is, all data items D received by the attestation node 702A within the first instance of a regular time interval are included in the first transaction in a series of transactions, and all data items D received in the next instance of the regular time interval are shown in the next transaction in the series of transactions, and so on.
[0152] The exact timing of the intervals between transactions may be configured by an implementation. For example, transactions may be issued at intervals of 0.1 seconds.
[0153] Each set of data items may be shown in a transaction simply by explicitly ("in plaintext") including the data items of that set in the payload of each transaction Tx. Alternatively or additionally, they may be shown in a transformed form such as a hash, encrypted form, or r-puzzle. Examples are discussed in more detail with respect to FIGS. 9 through 11. In the context of an ordering attestation service, at a minimum, the "indication" of a data item herein means some information that enables a query node examining a transaction to verify the attested order of the data items. In some cases where the explicit value of a data item D is not explicitly included in the transaction, this may require that the query node has a predetermined knowledge of the value of the data item D and is simply examining the transactions on the chain or in the memory pool 154 of the blockchain node 104 to confirm the expected order of those items.
[0154] In an embodiment, the proving node 702A may also include at least one timestamp in the payload of each transaction Tx0, Tx1, Tx2... in a series of transactions. The timestamp indicates the time at which each data item was received at the proving node 702A. If there is a single data item D for each transaction, this may simply be the time of reception of that data item. If there are multiple data items D for each transaction Tx, each transaction payload may include a single timestamp indicating the arrival time of the set (e.g., the time interval in which they were received), or individual timestamps for each data item D in the set.
[0155] When the proving service issues a transaction containing the user's data to the blockchain 150, in some embodiments, it also sends this transaction to the client node 703 that issued the data item D. This is possible because the user in the outer layer (e.g., layer 3) is directly connected to the proving node 702A in the middle layer (e.g., layer 2). In an embodiment, since the client node 703 is also directly connected to the blockchain mining node 104M and / or the storage node 104S in the core, it may independently verify that the transactions Tx0, Tx1, Tx2... have been accepted by the blockchain network 106. Thus, the client node 703A can query the memory pool 154 of the miner 104M and / or query the record of the actual blockchain 150 on the storage node 104S to confirm that the expected order has been proven. Other third - party nodes may also verify this in a similar manner via any suitable connection in the blockchain network 106. In some embodiments, the query by the client node 703A may be performed via the connection between the client node 703C and the core, using only connections such as the SPV discussed previously with respect to FIGS. 3 - 6.
[0156] Optionally, the proof service may also send to the client node 703C that issued the data item, the chain of transactions preceding the transaction that includes the data of the client node 703C. This is to enable the user to have the confidence that there is no chain of two competing transactions with different orders issued to the blockchain by the service. The length of the chain of transactions must be appropriate for the level of trust required by the user. This trust may be outsourced. For example, a certification authority may authenticate the accuracy of the chain of transactions every hour.
[0157] In an embodiment, client nodes 703C within a layer may also be connected to each other and can send (mined) transactions including them and corresponding Merkle proofs to each other. In an embodiment, since each outer layer (e.g., layer 3) node is independently connected to the blockchain 150, they can verify that the Merkle proofs are correct. This enables users of the outer layer (e.g., layer 3) to agree on the ordering of data with only a minimal amount of temporary trust in the timestamping service before the trust in the proof of work on the blockchain is inherited.
[0158] Below, the OP_RETURN payload data1 is examined in more detail. The goal is for the service to prove the order in which data elements D1, D2, D3,... were received over a time interval. Note that the data elements may represent hash commits of data related to each other. It may be at the discretion of the user whether to choose to publish the data or instead choose to record the hash commit of the data.
[0159] There are several different ways to indicate within a transaction Tx a set of data items D and their relative order. The simplest way is to simply index each element, and since OP_RETURN is signed, this is attested to by a timestamping service. However, there is a smarter way to do this that provides additional evidence of ordering and enables generalization to a decentralized timestamping service.
[0160] Method 1.1: Hash Chain. A unique index i is assigned to each data element D i and an entry H i in the hash chain is created. The value of H i depends on the data element and the previous element of the hash chain. This means that each element of the hash chain must have been created after the previous element, enforcing the order. An example of a hash chain is shown in the table of FIG. 9. This table is included in the payload (data) of the transaction and optionally may or may not include an explicit column of D in the transaction.
[0161] One advantage when the value of D is not explicitly included is that the hash may be smaller than D, so fewer bits need to be stored in the chain. This also means that if the user does not want to disclose the actual value of D, they do not have to be. In any case, whether or not the value of D is explicitly included, another advantage of the hash chain is that it makes it more difficult to change the order. By way of illustration, assume there are 1000 data items D per transaction. Then, to change the order of these data items, 1000 hashes need to be executed, which is computationally cumbersome. Thus, even if the proof node 702A is not fully trusted, this gives the user additional confidence that the order of the data items has not been changed.
[0162] In some embodiments, each data element D iThe timestamp t of the reception i Proof of this may also be included. One way to do this is to include the timestamp in the preimage of each element of the hash chain.
[0163]
Number
[0164] In this case, a column containing the time is also added to the table in FIG. 9.
[0165] The OP_RETURN payload data1 consists of a table such as that shown in FIG. 9. The "Data" column may be omitted to save space or to keep data elements secret. However, note that in that case the only way for someone to prove the order of the hash chain is to know all the data elements.
[0166] Replacing the hash function with HMAC may provide additional security. HMAC is described in RFC2104 and introduces a secret symmetric key into the hashing procedure. This means that only those with knowledge of the secret key may be able to prove the order of the data.
[0167] Method 1.2: Hash Chain with Merkle Tree. This case is similar to the hash chain of FIG. 9, except that instead of publishing the entire hash chain, the hash chain is converted into a Merkle tree and only the root is published. In this case, each data item D in the set is modeled as a leaf of the Merkle tree, and the Merkle root is included as an indication in the transaction. Note that the index of the data is implied by the order in which the data appears in the leaves of the Merkle tree. A Merkle proof can be provided to the user later to enable the user to verify the existence of the data item and its position in the Merkle tree. This method saves space in the transaction, as only 256 bits are required in the OP_RETURN payload for the Merkle root.
[0168] Additionally or alternatively, each data item may be represented in the transaction by its corresponding Merkle proof for its leaf. As is familiar to those skilled in the art, a Merkle tree enables the proof that a given data item is a member of the set, given the Merkle root and Merkle proof for the data item (which is a chain of hashes between the root and the leaf).
[0169] Method 2.1: Chain of Signatures. In this method, a new public key is created for each data element D, and the element is signed with that new public key. This is in line with the requirements in the timestamping protocol outlined in RFC3161.
[0170] Consider the sequence of public keys and signatures shown in FIG. 10. The idea is that each public key is generated based on the preceding data. Similar to the hash chain, each public key (and thus signature) in the sequence can only be created with knowledge of the previous public key in the sequence, thus enforcing the order.
[0171] In a variation of this method, the entries in the table can each be transactions themselves.
[0172] Method 2.2: Chain of r-PUZZLE. R-puzzle is a recently published form of challenge and proof. It provides a method for proving knowledge of a secret without revealing the secret, based on the r part of the ECDSA signature (S, R). https: / / www.youtube.com / watch?v=9EHKvNuRcOA&t=978s and https: / / www.youtube.com / watch?v=CqqTCsLzbEA Please refer to
[0173] The ECDSA (Elliptic Curve Digital Signature Algorithm) signature consists of a pair (S, R), where R is the x-coordinate of the public part of the ephemeral key pair. The same public key is used for each signature, but the ephemeral keys can be concatenated together. This gives the sequence shown in Figure 11. This may be included in the transaction payload (data) instead of, or in addition to, any of the above methods.
[0174] Here, R1 is a random ephemeral key, and <S1, R 1i >(H(D i )) means that the data H(D i ) is signed by P1 using the ephemeral key R 1j .
[0175] Generally, any of methods 1.1, 1.2, 2.1, and / or 2.2, and / or others may be used individually or in combination to indicate the order of the set of data items D in the transaction payload (data).
[0176] Distributed case: The above is described in the scenario where the order proof service is provided by individual nodes 702A. It is also possible to provide such a service through multiple proof nodes 702A.
[0177] For example, consider a situation involving a decentralized proof service that uses a multi-layer network 700 to achieve consensus. In this case, more than one of the intermediate layer nodes 702 (e.g., layer 2 nodes) in FIG. 7 assume the role of proof nodes.
[0178] Assume that the majority of the proof nodes 702A act benevolently and desire to reach a consensus regarding the ordering and timestamping of data disseminated around a community consisting of the proof service nodes 702A and the users 703C (as previously defined). Assume that there are N independent proof service nodes 703A connected to the same subset of m core mining nodes 701 and thus defining the community of the multi-layer network 700. The fact that there are proof nodes 702A in multiple intermediate layers (e.g., layer 2) enables nodes 702 in the intermediate layer (e.g., layer 2) to have many users in the outer layer (e.g., layer 3) connect to them without the load being too high (too many connections) for the intermediate layer nodes.
[0179] Then, in a decentralized scenario such as this, the problem to be addressed is how the intermediate layer proof nodes 702A (e.g., layer 2 nodes) can reach a consensus regarding the order of two data items D1, D2 issued by, for example, two users, even if those data items arrive in a different order at one proof node 702A compared to another proof node.
[0180] One way to address this is to use threshold signatures, i.e., as previously discussed, not just one, but at least M different signatures (M > 1) are required to unlock the transaction Tx. Consider an M-of-N threshold signature system as described as being applied to the proof service nodes 702A. This consists of secret key shares a1, a2,..., a NThis means there are N participating nodes with it. Any subgroup of M participants can generate signature shares that, when combined, provide the signatures of messages that unlock previous transactions in a series of transactions.
[0181] Suppose one of the proof service nodes 702A generates a transaction candidate Tx1 that includes an OP_RETURN payload data1 which is an ordered list of all data elements D it received during a selected period. This node may broadcast the transaction candidate to all other proof service nodes 702A (or at least a portion of them) to request their signature shares for signing the transaction. If they receive at least M signature shares (including its own), the transaction may be issued to the blockchain network 106 and mined into block 151. This ensures that the ordering of the data elements is agreed upon by at least an M-of-N timestamping service in a distributed network.
[0182] How is a single proof node 702A selected to create a transaction? Above, it was assumed that there was only one proof service node 702A that created the transaction candidate Tx1 and that the other proof nodes 702A agreed to it. But what about the next transaction candidate? There are at least two options: (i) there is always one privileged proof node 702A that creates the transaction candidate, or (ii) after each transaction is created, one of the proof nodes 702A is randomly selected to be the next node for creating the next transaction. This could be a pre-determined random sequence or a deterministic random selection based on a seed related to the just-issued transaction Tx1. For example, the seed could be taken to be Tx1. Other distributed arbitration algorithms for distributed computing may also be possible.
[0183] Smart contract FIG. 12 shows an example of a system of smart contracts implemented in a multi-layer network 1200 in accordance with an embodiment disclosed herein.
[0184] The multi-layer network 1200 includes a core network having one or more core nodes 1201, an intermediate layer around the core, each intermediate layer having one or more intermediate layer nodes 1202, and an outer layer around the outermost of the intermediate layers, each outer layer having one or more outer layer nodes 1203. Also, the term "outer" of the "outer layer" is not necessarily limited to the outermost here, but that is also one possibility. The multi-layer network 1200 may be an overlay network superimposed on a physical network or infrastructure network such as the Internet, or alternatively, a stand-alone network such as a private network within an organization.
[0185] The core nodes 1201 are nodes 104 of the blockchain network 106. They may include mining nodes 104M, storage nodes 104S, or a combination thereof. In an embodiment, each of the core nodes is a mining node 104M and / or a storage node 104S (e.g., a full copy node).
[0186] In some cases, some of the intermediate layer nodes 1202 and / or the outer layer nodes 1203 may include peripheral nodes 104 of the blockchain network 106, such as nodes other than mining nodes 104M and / or storage nodes 104S, such as transfer nodes 104F. Alternatively, they may include nodes having no role (mining, storage, or transfer) in the blockchain network 106 other than as clients of the blockchain network 106.
[0187] The intermediate node 1202 comprises a plurality of smart contract nodes 1202SC spanning one or more intermediate layers of the multi-layer network 1200. Among them, the smart contract nodes 1202SC provide smart contract services to the client nodes 1203C. Each of these smart contract nodes 1202SC is configured to maintain a record of the state of one or more smart contracts. In an embodiment, since the state is spread among the smart contract nodes 1202SC, the states of at least some smart contracts are replicated across more than one smart contract node 1202SC. In some cases, each smart contract node 1202SC may store a copy of the state of every smart contract in the system. However, in other embodiments, each smart contract node 1202SC stores the state of only one or some of the smart contracts, and the state of each contract may be replicated across only a part, not all, of the smart contract nodes 1202SC.
[0188] Each smart contract node 1202SC may be in the form of a server comprising one or more physical server units. Each such node comprises a memory comprising one or more memory units and a processing device comprising one or more processing units. These may be in either the form of a memory medium and / or a processor, such as those previously discussed with respect to other network elements. In addition to the database entries themselves, the memory stores database software adapted to be executed by the processing device of the proof node. This software, when executed, is configured to provide a database service operating according to any of the embodiments described below or similar ones.
[0189] In an embodiment, the identification information of each smart contract node 1202SC may be authenticated by a certification authority so that the client node 1203C, the core node 1201, and / or another smart contract node 1202SC or another intermediate layer node (such as the proof service node 702A or the smart contract node) can verify the identification information of the smart contract node 1202SC. The interaction between such nodes may be conditional on verification. For example, the client node 1203C may send a message to the smart contract node 1202SC only on the condition that it has verified the identification information of the smart contract node 1202SC based on a certificate. Additionally or alternatively, node version management may be used as an alternative mechanism for node identification in the overlay network.
[0190] Each of the client nodes 1203C may be an end-user node comprising a user's computer device of the smart contract service. Again, this may be an individual user, or an organization such as a company, academic institution, or government agency. Thus, each client node may comprise one or more user terminals and / or a server comprising one or more server units at one or more locations. Each client node comprises a memory comprising one or more memory units and a processing device comprising one or more processing units. These may be in the form of either a memory medium and / or a processor, such as those previously discussed with respect to other network elements or user equipment. The memory stores client software adapted to be executed on the processing device, and the client software, when executed, configures the node to operate as a client of the smart contract service provided by the smart contract node 1202SC according to any of the following embodiments or similar ones. Optionally, one or more of the transmission end-user nodes may comprise the user equipment 103 of the user 102 of the blockchain network 106, and the client software may comprise a blockchain wallet application 105 or the like.
[0191] In an embodiment, the identification information of each client node 1203C may be authenticated by a certification authority so that the smart contract node 1202SC, other intermediate layer nodes (such as the proof service node 702A or the smart contract node), the core node 1201, and / or other client nodes 1203C can verify the identification information of the client node 1203C. The interaction between such nodes may be conditional on verification. For example, the smart contract node 1202SC may accept a message from the client node 1203C only on the condition that it has verified the identification information of the client node 1203C based on the verification. Alternatively or additionally, node version management may be used as an alternative mechanism for node identification in the overlay network.
[0192] In an embodiment, the multi-layer network 1200 may be configured according to either the protocol rules or the structural features described with respect to FIGS. 3 to 6 and / or FIG. 7. The nodes 1201, 1202, 1203 are configured to form connections with each other at the overlay network level when the multi-layer network 1200 is an overlay network superimposed on an infrastructure network such as the Internet. That is, the nodes 1201, 1202, 1203 of the multi-layer network are configured to follow an overlay network protocol that specifies which connections they can form and which connections they cannot form with other nodes 1201, 1202, 1203 of the multi-layer network.
[0193] For example, in an embodiment, each intermediate layer node 1202 is connected to at least one core node 1201 (blockchain network node 104) in the core network. The core network comprises at least a part of the blockchain network 106. In an embodiment, the core network may itself be a complete network. Each outer layer node 1203 may be connected to at least one of the intermediate layer nodes in at least one intermediate layer. In an embodiment, each outer layer node 1203 also has at least one connection to at least one core node 1201 (i.e., to the blockchain network). In some such embodiments, one or more of the outer layer nodes 1203 each have connections to more than one but not all of the core nodes 1201. In an embodiment, the entire multi-layered network 1200 may be an incomplete network, i.e., each node 1201, 1202, 1203 does not have a connection to each other node at the overlay network level. In an embodiment, each node within a given layer may be connected to at least one other node in the same layer. For example, each node 1202 in the intermediate layer may be connected to one or more other nodes in the same intermediate layer, and / or each node 1203 in the outer layer may be connected to one or more other nodes in the same outer layer. In an embodiment, connections may also be formed between different intermediate layer nodes 1202 in different intermediate layers and / or between different outer layer nodes 1203 in different outer layers.
[0194] A connection between two nodes 1201 / 1202 / 1203 of the multi-layered network 1200 means that those nodes can communicate directly, which in this context means that it may not be necessary to perform a hop via another node 1201 / 1202 / 1203 of the multi-layered network 1200. In the context of an overlay network, "connection" means a connection (i.e., an edge) at the level of the overlay network (i.e., at the level of the overlay network protocol of the multi-layered network).
[0195] For simplicity of illustration, only two client nodes 1203C and two smart contract nodes 1202SC are shown in FIG. 12, but it will be understood that there may be more nodes. In an embodiment, the client nodes 1203C and the smart contract nodes 1202SC may be part of the same community as each other.
[0196] The client nodes 1203C are clients at least in that they are clients of the smart contract service. In an embodiment, the client software executed on one or more of the client nodes 1203C may further be configured to operate the node 1203C as a client of one or more additional services provided by one or more second layer nodes 1202, such as an ordering service or a database service. And / or it may be configured to operate the node 1203C as a client of one or more core nodes 1201 (e.g., 104M, 104S) of the blockchain network 106, such as to enable querying of the blockchain 150. Also, the fact that the client nodes 1203C are described as clients of the smart contract service (and optionally one or more other services) does not preclude the possibility that these nodes themselves may also be providers of one or more additional services to one or more further entities (not shown). For example, the client nodes 1203C may comprise the computer equipment of a company that provides online services to customers over the web.
[0197] In some embodiments, the multi-layer network 1200 of FIG. 12 may be the multi-layer network 300 of FIG. 3 or FIG. 4. In this case, the outer layer nodes 1203 of FIG. 12 are the third layer nodes 303 of FIG. 3 or FIG. 4, the intermediate layer nodes 1202 of FIG. 12 are the second layer nodes 302 of FIG. 3 or FIG. 4, and the core nodes 1201 of FIG. 12 are the core nodes 301 of FIG. 3 or FIG. 4.
[0198] In some embodiments, the multi-layer network 1200 of FIG. 12 may be the multi-layer network 700 of FIG. 7, in which case the outer layer nodes 1203 of FIG. 12 are the outer layer nodes 703 of FIG. 7, the intermediate layer nodes 1202 of FIG. 12 are the intermediate layer nodes 702 of FIG. 7, and the core nodes 1201 of FIG. 12 are the core nodes 701 of FIG. 7. In such embodiments, the proof service of the proof node 702A may be integrated into some or all of the same intermediate layer nodes 702 / 1202 as the smart contract node 1202SC, and / or the proof node 702A may comprise separate intermediate layer nodes 702 / 1202 in the same and / or different intermediate layers within the same and / or different communities.
[0199] In operation, one or more users of one or more client nodes 1203C determine the conditions of the smart contract. This may be negotiated among the users of two or more client nodes 1203C via one or more connections within one or more of the outer layers of the multi-layer network 1200. Alternatively, the conditions may be negotiated separately from the multi-layer network 1200, for example, over the phone or in a face-to-face meeting.
[0200] In any case, one of the nodes 1202 / 1203 in the outer or intermediate layer composes at least a first transaction 152 for recording the state of the smart contract on the blockchain 150. The state may comprise the complete conditions of the contract, or only one or more parameters of the contract, for example, whether the contract is valid or expired, or who the current owner of the rights represented by the contract is.
[0201] In an embodiment, the first transaction is at least partially composed by client node 1203C and is sent directly from client node 1203C to the core layer via one of the connections within the multi-layer network 1200 between client node 1203C and at least one of core nodes 1201. In this case, a separate step is required to inform at least one of the smart contract nodes 1202SC of the state of the smart contract. This can be done by sending a copy of the transaction to the smart contract node 1202SC or by sending a separate message (not in the form of a transaction) informing the smart contract node 1202SC of the relevant state of the smart contract. This can be done via one or more of the connections between the outer layer and the middle layer of the multi-layer network 1200. Another option is for the smart contract node 1202SC to investigate a transaction such as one that is recorded on the blockchain 150 or in the miner's memory pool 154 of the blockchain network 106 through one or more of the nodes 1201(104) of the core layer. This investigation may be performed directly via a connection between the smart contract node 1202SC and one or more of the core nodes 1201 in the core layer, or alternatively, it may be performed via more than one hop to the core.
[0202] In other embodiments, the first transaction is at least partially compiled by client node 1203C and sent to smart contract node 1202SC for transfer to core layer 1201 for recording on blockchain 150. In this case, since smart contract node 1202SC has received the transaction from client 1203C, it knows about the state of the smart contract. Smart contract node 1202SC may receive the transaction directly from client node 1203C via a connection within the multi-layer network 1200 between client 1203C and smart contract node 1202SC. Alternatively, it may be received indirectly via more than one hop within the multi-layer network 1200. Smart contract node 1202SC may transfer the transaction to the core layer directly or indirectly via more than one hop within the multi-layer network between smart contract node 1202SC and one or more of core nodes 1201.
[0203] In a further possible embodiment, the first transaction may be at least partially compiled by smart contract node 1202SC. In this case, smart contract node 1202SC may send the first transaction to the core layer for recording on blockchain 150. It may send the first contract directly to the core via a connection within the multi-layer network 1200 to one or more of core nodes 1201. Alternatively, smart contract node 1202SC may indirectly send the first transaction to the core layer via more than one hop within the multi-layer network 1200.
[0204] In some embodiments, one or more of the conditions of the smart contract may be negotiated by exchanging template versions of the first transaction between two or more client nodes 1203C and / or between one or more of the client nodes 1203C and the smart contract node 1202SC. This negotiation process may involve each party adding their signature to the transaction once they have received the template and approved the conditions of the problem. Some examples will be discussed later. In some such embodiments, the smart contract node 1202SC may determine the relevant state of the smart contract via the template used in the negotiation, even if it does not view the final version of the transaction before it is recorded on the chain.
[0205] By any of the above routes, the smart contract node 1202SC also knows about the state of the smart contract stored in the blockchain 150. It can then record that state in the local records maintained by the smart contract node 1202SC. In some embodiments, the smart contract node 1202SC may also spread the state to one or more other nodes of the smart contract node 1202SC, and they record the state in their own local records. Alternatively, there may be only one smart contract node 1202SC, or there may be multiple smart contract nodes 1202SC in the network 1200, but each may operate independently (without spreading the state between them).
[0206] Any node wishing to check the state of the smart contract can then check the state from the smart contract node 1202SC, or from the blockchain 150 through the core node 1201, or from both.
[0207] For example, in an embodiment, the client node 1203C may contact one of the smart contract nodes 1202SC to query the state of the smart contract without having to read the state from the blockchain 150 and without having to contact the core layer 1201. This reduces traffic with the core layer after the state has been recorded. The state can be queried from either the smart contract node 1202SC that first recorded the state or from a smart contract node 1202SC to which the state has been propagated. The client node 1203C making the query can be one of the parties to the smart contract or a third party having an interest. The query can be made directly via a connection within the multi-layer network 1200 between the client node 1203C making the query and the smart contract node 1202SC being queried or indirectly via more than one hop within the multi-layer network 1200.
[0208] In another exemplary scenario, the client node 1203C or another smart contract node 1202C may query the state of the smart contract from both the smart contract node 1202SC and the core layer node 1201 and compare the results to confirm that there is a consensus. Again, this query may be executed directly via a direct connection between relevant pairs of nodes 1201, 1202SC, 1203C within the multi-layer network 1200 or indirectly via more than one connection (more than one hop).
[0209] The state of the smart contract may be recorded in the first transaction in any one or more of various possible forms. In embodiments, it may be explicitly recorded in the payload of the transaction. Alternatively, the state may be recorded in the payload in a transformed form such as a hash. In the case of a hash, etc., this only enables a node to confirm that the state records a given knowledge of the expected state (the node cannot see the state from the record). This is sometimes referred to as a "hash commitment" of the state. However, in embodiments, the existence of a state transaction in the UTXO set may be interpreted as indicating which state the contract exists in, i.e., this is a non-discrete but continuous event.
[0210] The payload may be included in the unspendable output of the transaction. For example, when using the Script language, the output may be made unspendable by including each locking script, for example, an opcode that ends with OP_RETURN (optionally, also including OP_FALSE before OP_RETURN in the locking script). However, other transaction protocols or scripting languages may provide other means for including application-level payloads (i.e., user data) in the transaction.
[0211] In another example of state information, one or more parties to a smart contract may be recorded in one or more outputs. This may be recorded in the payload of one or more unspendable outputs (e.g., using OP_RETURN or OP_FALSE OP_RETURN), or alternatively, may be recorded by locking one or more spendable outputs to the party in question. For example, to record that A and B are parties to a transaction, one output may be locked to party A and another output may be locked to party B, or one output may be locked to party A and one output may be locked to party T, where T is the trustee of the contract and the operator of the smart contract node 1202SC. In such cases, the public key in the locking script serves as an indicator of the party to the smart contract. At the blockchain level, this key is used for the standard purpose of verifying the unlocking script of any transaction that attempts to spend the first transaction, but at the application level (i.e., as interpreted by the smart contract service and / or client software), this key is used to indicate the state of the contract (e.g., assignor or assignee).
[0212] In another example of state information, one of the outputs of a transaction may include a state puzzle and require a solution to the state puzzle to unlock it. A set of one or more rules for forming the state puzzle may be stored at one of the smart contract nodes 1202SC. The smart contract node 1202C may be configured to compose at least the state puzzle portion of the first transaction based on this set of rules as stored at the smart contract node 1202SC. Some examples of this will be discussed in more detail later.
[0213] In an embodiment, a change in the state of a smart contract may be recorded using a second transaction, for example, to record that the smart contract has expired or to record a change in ownership of a right represented by a contract (such as a bond). The second transaction may be compiled and stored in a manner similar to any of the techniques described above with respect to the first transaction. The new state may be recorded in the second transaction in any of the ways discussed above with respect to the first transaction.
[0214] In some such embodiments, the first and second transactions simply sign two unrelated source transactions (the first and second transactions are not linked together). In this case, the change in state may be represented at the application level rather than at the blockchain level by the information contained in the application payloads (such as OP_RETURN outputs) of the two transactions. The application-level interpretation is assigned to the transactions by the smart contract service and its clients.
[0215] However, in other embodiments, the second transaction does not consume the output of the first transaction. Specifically, the first transaction may include an output with a state puzzle, and the second transaction includes an input that points to that output. The second transaction is required to include the solution to the state puzzle in order to unlock the output of the first transaction. At the blockchain level, this is a requirement for validating the second transaction for recording on the chain. At the application level, this is also interpreted as a condition for recognizing the change in state. The smart contract node 1202SC may record the change in state in its local record of the smart contract state only if the second transaction provides the solution to the state puzzle.
[0216] In an embodiment, two different mechanisms for recording changes in state may both be used, each for recording state information at a different level. To record changes in the initial state of a smart contract in one pair of a first transaction and a second transaction, a state puzzle mechanism is used, and to record changes in the secondary state of a smart contract in another pair of the first transaction and the second transaction, an OP_RETURN payload mechanism is used. For example, the initial state may comprise whether rights such as bonds are valid or expired, and the secondary state may comprise the current ownership of the rights. In such a case, parallel states exist simultaneously. In an embodiment, one state may induce a change in another state. For example, in the case of the initial state and the secondary state, a change in the initial state may affect the secondary state (but not vice versa). Examples of implementing the initial state and the secondary state, as well as changes thereto, will be discussed in more detail later.
[0217] In an embodiment, the smart contract service may be implemented in cooperation with an ordering mechanism such as the ordering service described above to determine the final order in which state changes should be applied. This may be useful, for example, in a situation where various state changes for the same smart contract are being received from different client nodes 1203 and / or being propagated among various smart contract nodes 1202SC.
[0218] In some scenarios, multiple requests to update the same smart contract may be received at the same smart contract node 1202SC. To accommodate this, the smart contract node 1202SC may be configured to apply state changes in a specified order. In some embodiments, the specified order may be based on the time of receipt at the receiving smart contract node 1202SC, or a timestamp added by the sending client node 1203C or the forwarding smart contract node 1202SC. Alternatively, the specified order may be asserted in one or more requests from one of the client nodes 1203C, or in a message from another intermediate node 1202 such as another smart contract node 1202 or the proof service node 702A, or from the core 1201. For example, the order may be asserted in the form of a sorted list of multiple updates, or in the form of an index of the order mapped to each update request.
[0219] In an embodiment, the specified order may be recorded on the blockchain 150 by, for example, the proof service 702A discussed previously. In such an embodiment, the client node 1203C that initiates the state change may obtain the order from the proof service 702A and send this to the smart contract node 1202SC. In this case, the order proof service 702 records the order on the blockchain 150 and returns a message with the specified order to the requesting client node 1203C (which is also the client 703C of the proof service 702A). When the client 1203C makes a request to the smart contract node 1202SC to change the state of the smart contract, it also sends the order obtained from the proof service 702A. The smart contract node 1202SC verifies this against the order recorded on the blockchain (or the miner's memory pool 154) and applies the update in the specified order on the condition that the order sent by the client 1203C matches the order recorded on the chain 150. This verification may be done directly via the connection between the smart contract node 1202SC and the core 1201 or, alternatively, via more than one hop.
[0220] Alternatively, the smart contract node 1202SC that records the state change may read the order directly from the blockchain 150 and apply the order as read from the blockchain 150 (or the miner's memory pool 154).
[0221] In another variation, the proof service 702A can be integrated into one or more of the smart contract nodes 1202SC. In this case, one of the smart contract nodes 1202SC takes on the role of determining the order (and optionally adding a timestamp) and recording this on the blockchain 150. The smart contract node 1202SC responsible for this order may spread the order specified to other smart contract nodes 1202SC around the connections between the nodes in the middle layer. The other smart contract nodes 1202SC may confirm this against the order recorded on the blockchain, or alternatively, may read the order directly from the blockchain 150 (or in the miner's memory pool 154). This may be done directly via the connection between the smart contract node 1202SC and the core 1202, or alternatively via more than one hop.
[0222] To illustrate some of the principles behind the disclosed approach, specific implementations are described here as examples. By way of illustration, reference is made to smart contract nodes implemented in layer 2 and client (user) nodes in layer 3, which can be generalized to any intermediate and outer layers respectively.
[0223] The following presents a use case for a blockchain-based deterministic finite automaton (DFA) using overlay network layers. The network topology follows that defined by the blockchain multi-layer network (BLN) 1200 described above, where the core network consists of full blockchain clients and the outer shell consists of Simplified Payment Verification (SPV) nodes. These secondary SPV nodes follow a special set of sub-rules within the boundary set by the proof-of-work consensus established in the core. The secondary nodes do not need to hold a copy of the blockchain but can instead spread state transitions according to some external data using the SPV paradigm. The network layers can be identified using digital certificates or node version management. An exemplary use case is described that enables different users in primary and secondary financial markets to cause different states using smart contract nodes connected in the BLN topology.
[0224] Terms: The following explains some of the terms used in the exemplary use case.
[0225] Market: Primary Market - The direct public offering of stocks or bonds from an issuer (corporation or government) is considered the primary market. Investment banks handle these transactions, and investors in the primary market are usually large institutional investors who purchase securities in the millions at a time. Since initial demand is difficult to predict, the selling price is set low. This makes the primary market very volatile. There are elaborate regulatory procedures for the issuing financial institutions to sell securities in the primary market.
[0226] Secondary Market - All transactions of securities from the issuer are conducted among investors in the secondary market. This can be done on a stock exchange (e.g., NASDAQ) or over the counter (for bonds). The price of stocks is determined by the demand and supply of buyers and sellers, while in the primary market, the initial price is set by the issuer. After large institutional investors purchase a large amount of securities in the primary market, some purchasers subsequently sell their stocks in the secondary market to make a profit, enabling investors of all sizes to participate. Stocks are one of the most traded securities, but investment banks also trade investment trusts and bonds in the secondary market with corporations and individual investors. On the other hand, some entities also purchase mortgage rights in the secondary market.
[0227] Over the Counter - A decentralized network of dealers is a private alternative to a centralized public exchange. Here, non-standard quantities can be sold, and the price is not made public until the transaction is completed, so it is less transparent compared to an exchange. Bonds are generally traded in the over-the-counter (OTC) secondary market by investment banks mainly because they are more diverse compared to stocks. Broker-dealers negotiate with each other via a computer network and often internally match customer purchases and sales. Bond prices are affected by changing interest rates and credit ratings. OTC trading is most beneficial in terms of the liquidity it provides and adequately protects investors who are considering selling their bonds before maturity. However, since transactions are executed directly between two parties, they are unregulated or do not follow the rules of major exchanges, which may be seen as a matter of debate.
[0228] Financial Entities: A full blockchain client that uses the miner-proof-of-work (PoW) consensus mechanism to store, record, and update transactions on the Bitcoin blockchain.
[0229] Bond issuer - A corporation or government organization that issues new bonds to investors or lenders.
[0230] Underwriter - An institutional investor, such as an investment bank, that acts as a lender to the bond issuer.
[0231] Bond dealer - Investors can trade marketable debt among themselves, but the trades are usually made through bond dealers, or more specifically, through the bond trading desks of major investment dealers. These dealers are at the center of a vast telephone network and computer links that connect all interested participants. Also, dealers have traders who know everything about a group of bonds and are responsible for pricing, or "valuing," the bonds. Dealers provide "liquidity" to bond investors so that they can buy and sell bonds more easily and with limited price concessions. However, dealers can also trade among themselves, either directly or anonymously through bond brokers.
[0232] Bond investor - A user who purchases debt. Depending on the size of the investor, bonds can be purchased directly from dealers in the secondary OTC market or from underwriters.
[0233] Broker - Intermediaries in the secondary market enable anonymous trading among bond dealers.
[0234] Bond trustee - A bond trustee or fiscal agent is a trusted third party hired by the bond issuer to enforce the terms outlined in the financial contract between the bond issuer and the bondholders. The trustee represents the interests of the bondholders.
[0235] Financial contract:: Bond purchase contract - A contract that defines the terms of sale between the bond issuer and the underwriter after private negotiations in the primary bond market. New bonds are generally not sold but are instead sold directly to the underwriter.
[0236] Trust Certificate - A contract that defines the terms of sale between a bond issuer and an investor, i.e., a bondholder, after the successful transaction between related objects in the secondary bond market. The bond purchase contract is made between the issuer and the underwriter of a new issue, while the trust certificate is a contract between the issuer and the trustee representing the interests of the investors.
[0237] Blockchain-based Deterministic Finite Automaton:: A deterministic finite automaton (DFA) is a finite-state machine that accepts or rejects a given sequence of symbols by repeating a sequence of states uniquely determined by that sequence. Given a state and an input, there is only one possible new state (which may be the same state in some cases), making the calculation result (such as that of a contract) unique.
[0238] In WO / 2018 / 078584, the states of the DFA are associated with unspent transaction outputs (UTXOs) on the blockchain. Note that the blockchain network continuously tracks all available UTXOs. WO / 2018 / 078584 uses the example of a zero-coupon bond (ZCB) to implement state transitions. This is a bond sold to investors at a heavily discounted price, and the investors do not receive coupon (interest payments) until the bond matures, i.e., the face amount is paid at a future point in time. ZCBs can be bonds issued by corporations, municipalities, or the Ministry of Finance (government) and are considered a form of long-term investment. Due to the absence of regular interest payments, the financial contract requires only simple state transitions (initial setup and final payment or default), making it easy to implement as a DFA. Table 1 summarizes the key features of the ZCB contract.
[0239] [Table 1]
[0240] DFA Transition Table: A DFA is defined as the finite set {S, I, t, s0, F} using the following elements. · S is a finite set of states that the machine can assume. · I is a finite set of inputs that embody the occurrence of any event or condition related to the contract, such as a payment being made, the expiration of a certificate being reached, the counterparty's default, etc. · t: S × I → S is the transition function. · s0 is the initial state. · F ⊆ S is the set of all possible final results.
[0241] Once all of the above elements are established, the DFA is completely defined by a transition table that specifies the future state for all possible current states and inputs.
[0242] Table 2 shows the transition table for the ZCB contract. The possible states are defined as S = {s0, f0, f1}, which are · the holding state (s0), and · the final states of system F = {f0, f1}, where F is · a normal termination (if it follows the "happy path") or happy end (f0), and · an adverse direction, such as a state leading to litigation (f1).
[0243] The inputs under consideration are I = {r, d, e}, which are · the repayment of the principal at (or before) maturity (r), · the issuer's default at (or before) maturity (d), · the expiration of the contract without repayment (e)
[0244]
Table 2
[0245] Figure 13 shows the transition from the holding state to one of the two final states. The mechanism by which the DFA moves from one state to another may be embodied by a blockchain transaction. Substantially, a blockchain transaction consumes the UTXO associated with a certain state (input of the transaction) and creates the UTXO associated with the next state (output). The "origin" transaction (o), "transition" transactions (t0, t1), and "completion" transactions (c0, c1) are represented by blue triangles in the schematic diagram.
[0246] Blockchain multi-layer network for smart contracts: The present disclosure uses a blockchain multi-layer network (BLN) (e.g., 1200) as described previously to enhance the states in a DFA system, such as those defined for ZCB in WO / 2018 / 078584.
[0247] In some embodiments, the system may adopt the Simplified Payment Verification (SPV) paradigm, by which only the nodes outside the core layer 1201 transfer specific transactions according to the SPV protocol. The system of specialized smart contract nodes 1202SC is linked to the core blockchain network 106 of the "mining nodes" 104, and they reach consensus according to the Proof of Work (PoW), while the former establishes a second layer of consensus (PoW or some other method). This means that the transactions constructed by the secondary nodes remain valid on the main blockchain system. The smart contract nodes 1202SC can transfer states and conditions according to a certain defined state table (external data). If the formats are not the same, the state transition is rejected by the intermediate layer and / or the outer layer of the multi-layer network 1200.
[0248] In WO / 2018 / 078584, the state of the ZCB is derived from the creation and maturity of the bond, i.e., the result after the bond reaches maturity. However, since the ZCB is a long-term investment, there may be constraints on the ZCB. Therefore, investors may choose to sell the bond in the secondary market.
[0249] It should be noted that such transactions do not affect the states in the underlying DFA transition table, i.e., the states defined by the creation and maturity of the new bond. However, there is a reverse dependency, i.e., a change in the state of the DFA affects the transactions in the market. Figure 14 shows how different states coexist in parallel.
[0250] Figure 14 shows the secondary states (in curly brackets) resulting from n transactions of zero-coupon bonds, which are currently in the initial holding state (above) as defined by a blockchain-based DFA.
[0251] Smart contract: A smart contract is simply a contract that uses software to facilitate, verify, or enforce all or part of the negotiation or execution of a contract. In an output-based (e.g., UTXO-based) model, a smart contract entity is a node that connects to the blockchain.
[0252] In the "SPV" paradigm, the nodes outside the core 1201 may not be able to "listen to" the blockchain other than by using the standard SPV protocol, which requires a service-level agreement with the mining nodes to send specific transactions to the nodes, which is not a lightweight solution. When there is no account, the signature key may be continuously updated, and in this case, it should be noted that it becomes difficult to identify transactions that may be related to the smart contract by simply scanning the blockchain.
[0253] In the embodiments disclosed herein, the user of a smart contract directly sends a transaction to the smart contract. Similarly, when the smart contract is caused to create a transaction, the transaction is sent directly to the user (both the user's transaction and the smart contract's transaction should also be sent independently to the blockchain).
[0254] For robustness, an entire layer of smart contract nodes may be required (layer 2 in our network configuration). Smart contract transactions are spread around this layer so that the state of the smart contract can be consistent.
[0255] One reason for using the Blockchain Multilayer Network (BLN) is that it is possible to implement smart contracts. Preferably, there are more than one smart contract nodes 1202SC for robustness and load balancing, and the users in layer 3 directly send transactions to the smart contract in layer 2 so that the system and the SPV are more compatible.
[0256] The smart contract nodes 1202SC may be part of the transaction fee. All smart contract nodes may act together.
[0257] The layer 2 and / or layer 3 nodes may spread the transaction around the community since all desire to agree on the state of the smart contract.
[0258] The layer 2 and / or layer 3 nodes may issue digital certificates identifying themselves and the rules of the contract. This can be a permissionless system where nodes welcome people in as a fee is paid for each transaction.
[0259] Network Topology::An overview of an exemplary network topology is provided in Table 3 below. The miner operates a full node, while the smart contract and the user operate SPV nodes, and they reach consensus based on hash power (PoW). The smart contract nodes reach consensus using a hash puzzle derived from the details outlined in a private bond purchase agreement (BPA). The user reaches an agreement on transactions in the market using a UTXO set membership representing the current bondholders and a transaction containing a digital certificate drafted from a trust instrument (TI).
[0260]
Table 3
[0261] Figure 15 shows the entities specified in Table 3 as nodes connected in a BLN topology. Financial entities trading in both the primary and secondary markets appear as users in layer 3. Therefore, when different users interact with each other, it is desirable for multiple smart contract nodes to support load balancing.
[0262] Multiple communities may also be formed on accounts of various types of financial contracts that can be traded in the secondary market. For example, a certain type of ZCB results from a "strip" bond. This is when an investment bank separates the coupons from a bond and sells them individually, i.e., the remaining strip bond and the coupons are traded separately in the secondary market. Both are associated with the same underlying state that defines the bond's remaining maturity, but different smart contracts are required to reflect the differences in trust instruments (i.e., different agreements with bondholders).
[0263] The process of bond issuance, trading, and settlement: Table 4 lists the objects in an exemplary setup.
[0264]
Table 4
[0265] Figure 16 shows the community of nodes connected in the BLN topology.
[0266] Some exemplary ways of using BLN to record the state and state changes of smart contracts are described here with reference to FIGS. 17 to 19.
[0267] Stage I - Creation of a new bond. This is an example of recording the initial state. Refer to FIG. 17.
[0268] Step S0: Alice, as a member of ABC Inc.'s finance team, hires Trudy to create a DFA structure and prepares a smart contract node that can be associated with this external data.
[0269] Step S1: After private negotiations with Alice, Bob accepts a new bond at BPA.
[0270] Step S2: Alice sets up and broadcasts the origin transaction TxID O based on the conditions described in BPA.
[0271] Step S3: The smart contract node marks the start in state s0 according to the DFA transition table for TxID OCheck the UTXO set for. In some embodiments, as shown in the figure, this is optional and may include the smart contract node (Trudy) querying the core node about the UTXO set. However, this is not limiting, and it is not necessarily required to connect to a mining node or other core node to check the UTXO set. For example, Trudy may maintain its own copy of the UTXO set locally on the smart contract node.
[0272] Step II - Transactions in the market. This is an example of recording a secondary state. Refer to FIG. 18.
[0273] Step S4: Bob creates a transaction template TxID tr to start selling the bond to Dean, and in that template, Bob adds a spendable output indicating the cost of the bond to himself.
[0274] Step S5: Dean adds a spendable output to Trudy in the partially complete TxID tr
[0275] Step S6: Trudy signs the trust certificate (TI) embedded in the null data output.
[0276] Step S7: Dean signs the transaction by adding a payment input for the bond to TxID tr
[0277] Step S8: Bob signs the transaction for approving the sale of the bond.
[0278] Step S9: Bob (or Trudy) broadcasts the complete transaction to the layer 1 node.
[0279] Steps S4 to S9 may be repeated for any layer 3 user trading bonds in the market (e.g., from Dean to Brock, from Brock to Dean, from Dean to Ivan, etc.).
[0280] Stage III - The bond reaches maturity or vice versa. This stage may involve recording the change from the initial state to the secondary state. Refer to Figure 19.
[0281] Initial state: Step 10: Trudy starts the change of state in the financial contract by creating and broadcasting a transition transaction TxID tf to notify the following:[[]] a. Upon bond maturity, ABC Inc. pays the principal amount (input r → state f0), b. ABC Inc. defaults on the payment (input d → state f), or c. The contract expires without a refund (input e → state f1).
[0282] Step S11: Trudy creates and broadcasts a complete transaction
Number
Number
Number
[0283] Secondary state: Step S12: Trudy cancels the UTXO set membership at TxID re in the UTXO set. a. In the case of Step S11a, Trudy creates a payment transaction to the bondholder.
[0284] Comment on Phase I: The trustee stores the transition table externally, creates a hash puzzle for each possible state of the DFA, and securely distributes them to all agents (i.e., smart contract nodes) permitted to participate in the execution of the contract.
[0285] Payments for new bonds can be processed on-chain or off-chain. In the on-chain case, this transaction is independent of subsequent transactions (i.e., not chained), and it should be noted that the creation of the BPA involves private negotiation between the bond issuer and the acceptor.
[0286] Figure 20 shows a schematic diagram of an exemplary origin transaction compliant with WO / 2018 / 078584.
[0287] The conditions of the BPA are embedded in the locking script of the origin transaction shown in Figure 20 as a hash puzzle given by the following table.
[0288] [Table 5]
[0289] When a solution to the hash puzzle is given, the transaction is considered consumed. This causes a change in the state of the contract, which is broadcast and confirmed in the core blockchain network.
[0290] The difference between the input value and the output value in Figure 20 is the fee imposed by the miner and the smart contract node (the latter is explicitly included as output in the last transaction in Figure 27).
[0291] Comment on Step II: The transaction may be in the form of a Merchant Point of Sale Template, (i) Utilize UTXO set membership for the current bondholders, (ii) Provide an economic incentive for the smart contract node to broadcast details of new investments around the network when the TI transaction is mined on the blockchain For this purpose, it includes a null data output for the trust deed contract along with a spendable output to the trustee.
[0292] Note that the trustee consumes the output from the previous "transaction" transaction (if it exists) to indicate a change in ownership according to the UTXO set membership. The trust deed includes the signatures of the trustee acting on behalf of the bond issuer and the new bondholder. The additional transaction input (minimal, i.e., dust amount) includes the signature of the seller to indicate that the sale of the bond has been approved by both parties. In the OTC market, new investors purchase bonds from dealers, and dealers may purchase from brokers, and both dealers and brokers charge a fee in addition to the fee sent to the trustee.
[0293] Figure 21 is a schematic diagram of a partially complete transaction in Step B4. Bob is adding a payment to himself for the sale of the bond.
[0294] Figure 22 is a schematic diagram of a partially complete transaction in Step S5. Dean adds a spendable output addressed to Trudy to handle any future transactions, i.e., revocation of UTXO set membership in this example.
[0295] Figure 23 is a schematic diagram of a partially complete transaction transaction in step S6. Trudy drafts and signs a trust certificate, which is embedded as a digital certificate and includes the signature from the bond issuer.
[0296] Figure 24 is a schematic diagram of a partially complete transaction transaction in step S7. Dean adds an input to pay for the bond.
[0297] Figure 25 is a schematic diagram of a complete transaction transaction in step S8. Bob approves the final transaction and broadcasts it to the blockchain network (or sends it to Trudy for broadcasting).
[0298] Comments on Phase III: Successive transitions regarding the execution of the contract are made by the smart contract nodes. They obtain the solution to the puzzle corresponding to the current state (s0), interact with the world (external state, e.g., maturity date) to receive the appropriate input, read the transition table (or only those parts of it corresponding to the current state), and obtain the puzzle corresponding to the appropriate next state (f f )). They can then issue the transaction to the blockchain, and if they succeed in placing the transaction, they receive a fee and the DFA goes to state f f .
[0299] The difference between the input value and the output value in Figure 20 is the fee imposed by the miner and the smart contract nodes, and the latter is explicitly included as an output in the last transaction of Figure 27. The first output of Figure 27 returns any unused funds to the originator (bond issuer, Alice).
[0300] Figure 27 is a schematic diagram of a transition transaction adapted to WO / 2018 / 078584.
[0301] FIG. 28 is a schematic diagram of a UTXO set cancellation transaction.
[0302] The above shows a BLN topology for facilitating the use of smart contracts and blockchain-based DFAs, etc. A system of dedicated nodes operating under different consensus mechanisms is added to one network topology. Utilizing the SPV paradigm enables lightweight communication between nodes in different layers of the BLN. This concept was illustrated with use cases based on transactions in financial markets to show how different users can effectively transact with each other and with smart contract nodes.
[0303] Conclusion It will be understood that the above embodiments have been described merely as examples. More generally, a method, apparatus, or program may be provided according to any one or more of the following statements.
[0304] Statement 1: A method of maintaining the state of a smart contract in a multi-layered network, the multi-layered network comprising a core layer having one or more core nodes, one or more intermediate layers each having one or more intermediate layer nodes, and one or more outer layers each having one or more outer layer nodes, each of the core nodes being a node of a blockchain network, one or more of the intermediate layer nodes being smart contract nodes that provide a smart contract service for maintaining the state of the smart contract, one or more of the outer layer nodes being client nodes of the smart contract service, the method comprising the step of recording the state of the smart contract in a record of the state maintained in a first smart contract node by a first node among one or more smart contract nodes, and at least a first transaction that also records the state being recorded in a blockchain of the blockchain network.
[0305] It should be understood that "first" in this context is merely an arbitrary label for a given node of the smart contract node and does not necessarily imply any special status with respect to other smart contract nodes.
[0306] Statement 2: One or more smart contract nodes are a plurality of smart contract nodes, and the method comprises the step of spreading the state to a record of the state of the smart contract maintained at other smart contract nodes by a first smart contract node, and spreading is performed via one or more connections between smart contract nodes within one or more intermediate layers of the multi-layer network.
[0307] Statement 3: The method of Statement 1 or 2, wherein a first transaction is transmitted by one of the client nodes to at least one of the core nodes so as to be recorded on the blockchain.
[0308] Statement 4: The method of any preceding statement, comprising the step of transmitting a first transaction from a first smart contract node to at least one of the core nodes so as to be recorded on the blockchain by the first smart contract node.
[0309] Statement 5: The method of Statement 3, wherein the first transaction is transmitted directly to at least one core node via at least one connection within the multi-layer network between the one client node and the core layer.
[0310] Alternatively, it may be transmitted via more than one hop.
[0311] Statement 6: The method comprises the step of receiving, by a first smart contract node, a first transaction from said one of the client nodes at the first smart contract node, and the transmission by the first smart contract node comprises transferring the first transaction to at least one core node, the method of Statement 4.
[0312] Statement 7: The method of Statement 6, wherein either or both of said receiving being performed directly via a connection within a multi-layer network between the first smart contract node and said one of the client nodes, and / or said transferring being performed directly via at least one connection within a multi-layer network between the first smart contract node and the core layer, holds true.
[0313] Alternatively, either or both of the receive leg and the transfer leg may be via more than one hop.
[0314] Statement 8: The method of any preceding statement, wherein the first transaction is initiated by one of the client nodes.
[0315] Statement 9: The method of any of Statements 1 to 7, wherein the first transaction is initiated by the first smart contract node.
[0316] Statement 10: The method of any preceding statement, wherein a record of a state maintained at at least one of the smart contract nodes is made available to at least one of the client nodes.
[0317] Statement 11: The method of Statement 10, wherein making available enables at least one client node to determine the state without the need to query the record on the blockchain.
[0318] Statement 12: The method of Statement 10 or 11, wherein the record is made directly available via a connection within a multi-tier network between at least one smart contract node and at least one client node.
[0319] Alternatively, this may be done via more than one hop.
[0320] Statement 13: The method of any of Statements 10 to 12, comprising the first smart contract node making available to at least one client node a record of a state maintained at the first smart contract node, the first smart contract node performing the making available.
[0321] This may be done directly via a connection within a multi-tier network between the first smart contract node and the client node, or indirectly via more than one hop.
[0322] Statement 14: The method of any of Statements 10 to 13, dependent on Statement 2, wherein a record maintained at at least one other smart contract node to which the state is propagated is made available to at least one client node.
[0323] Again, this may be done directly via a single hop in a multi-tier network or indirectly via multiple hops.
[0324] Statement 15: The method of any preceding statement, wherein at least one smart contract node is adapted to examine a record on a blockchain or in a miner's memory pool to verify the state of a smart contract.
[0325] Statement 16: The method of Statement 15, wherein at least one smart contract node is configured to perform the investigation directly via a connection within a multi-layer network between at least one smart contract node and at least one of the core nodes.
[0326] Statement 17: The method of Statement 15 or 16, wherein the method comprises a first smart contract node performing the investigation.
[0327] Statement 18: The method of Statement 15, 16, or 17, wherein the investigation is performed by another node of the smart contract nodes other than the first smart contract node.
[0328] Statement 19: The method of any of the preceding statements, wherein at least one client node investigates a blockchain or a miner's memory pool to verify the state of a smart contract.
[0329] For example, in an embodiment, this may be a secondary state such as ownership. For example, a client node may verify the UTXO set for the current bondholders.
[0330] Statement 20: The method of Statement 19, wherein the investigation by at least one client node is performed via a direct connection within a multi-layer network between the client node and the core layer.
[0331] Alternatively, this may be done via more than one hop.
[0332] Statement 21: The method of any of the preceding statements, wherein a first transaction comprises one or more inputs, each having a cryptographic signature of each respective party involved with the smart contract.
[0333] Statement 22: The method of any of the preceding statements, wherein the input of the first transaction comprises a cryptographic signature of the operator of the first smart contract node.
[0334] Statement 23: The method of any preceding statement, wherein the first transaction has one or more outputs, each having a locking script that locks the output for each respective party to the smart contract.
[0335] Statement 24: The method of any preceding statement, wherein the first transaction includes an application-level payload having one or more conditions of the smart contract.
[0336] Statement 25: The method of any preceding statement, wherein the method comprises a step of signing, by a first smart contract node, at least a portion of the payload including at least one of the conditions, using a cryptographic key associated with the first smart contract node.
[0337] The method of Statement 24 or 25, wherein the payload is included in a non-consumable output of the first transaction.
[0338] In an embodiment, the non-consumable output may be made non-consumable by including an opcode in each respective locking script of the output that terminates each respective script. For example, this may be an OP_RETURN opcode.
[0339] Statement 27: The method of any preceding statement, wherein recording the state change of the smart contract in a record maintained at the first smart contract node comprises recording a first state of the smart contract and recording a change that is a change compared to the first state, wherein the first state is recorded in a first transaction on the blockchain and the change in state is recorded in a second transaction on the blockchain.
[0340] Statement 28: The output comprises each locking script with a state puzzle such that the first transaction requires a solution to the state puzzle to unlock each locking script. The method comprises the steps of: the first smart contract node using a set of rules stored in the first smart contract node to compose a state puzzle based on the set of rules, and including the state puzzle in the first transaction before recording to the blockchain; and the second transaction having an input indicating each output with a state puzzle, and recording a change in the state of the smart contract in a record maintained at the first smart contract node on condition that the input provides a solution to the state puzzle. The method of Statement 27.
[0341] Statement 29: The method of any preceding statement, wherein the first transaction is negotiated between at least two client nodes via at least one connection within one or more outer layers of a multi-layer network.
[0342] For example, this may include exchanging a template version of a first transaction. In an embodiment, a first user of a first node of two client nodes agrees to a template transaction with a second user of a second node of the two client nodes. This may include, as part of the negotiation, adding respective outputs locked to one of the parties involved. One of the two nodes may also add an output locked to an operator of a first smart contract node. One of the two client nodes then sends this template transaction to a first smart contract node and signs it using a cryptographic signature associated with the smart contract node (e.g., signs the conditions included in the payload). The first smart contract node then returns the signed template to one of the first node and the second node, and the user of that node adds the signature (e.g., to the input) and sends it to the other client node so that the user of that client node can add the signature. One of the client nodes then sends a complete signed transaction including all three signatures to the core layer to be recorded on the blockchain. For example, parties selling rights represented by a contract such as a bond may have an incentive to do this. This last sending step may be directly to the core or via a first smart contract node that forwards it to the core.
[0343] Statement 30: Communication between at least some nodes of a multi-layered network, including one or more of said spreading, transmitting, receiving, forwarding, making available, investigating, and / or negotiating, is performed using a communication protocol, in accordance with any of the methods of Statements 2 to 7, 10 to 20, or 29.
[0344] In an embodiment, the communication protocol may be a communication protocol in which messages are in the form of: a) a transaction sent from a client node to a core node; b) a query from a client node to a core node regarding whether a transaction has been accepted into a miner's memory pool and a corresponding response from the core node; c) a request from a client node to a core node for a Merkle proof that a transaction has been mined into a block and a response from the core node with the Merkle proof; and / or d) a request from a client node to a core node for a list of block headers and a response from the core node with the list of block headers.
[0345] In an embodiment, the relevant client nodes and / or smart contract nodes may be configured to use only a) through d) when communicating via a connection to at least one core node.
[0346] In an embodiment, the protocol may be a SPV protocol.
[0347] In an embodiment, all communication between a client node and a smart contract node may use the protocol. In an embodiment, all communication between different client nodes may use the protocol. In an embodiment, all communication between different smart contract nodes may use the protocol. In an embodiment, all communication between a client node and a core node may use the protocol. In an embodiment, all communication between a smart contract node and a core node may use the protocol.
[0348] In an embodiment, all communication between the outer layer nodes and the intermediate layer nodes may use the protocol. In an embodiment, all communication between different outer layer nodes may use the protocol. In an embodiment, all communication between different intermediate layer nodes may use the protocol. In an embodiment, all communication between the outer layer nodes and the core nodes may use the protocol. In an embodiment, all communication between the intermediate layer nodes and the core nodes may use the protocol.
[0349] Statement 31: The recording of the state in the first smart contract node comprises recording a plurality of state changes, which are also recorded in one or more transactions on the blockchain, and the one or more transactions comprise at least a first transaction, and the method comprises the steps of determining, by the first smart contract node, the order of the state changes, and applying the state changes of the record maintained in the first smart contract node according to the order.
[0350] Statement 32: The method of Statement 31, wherein the determination of the order comprises receiving the order from an ordering service implemented in one or more of the intermediate layer nodes of the multi-layer network.
[0351] In an embodiment, the ordering service node may be part of the same community as the first smart contract node.
[0352] Statement 33: The method of Statement 31 or 32, wherein the order is recorded on the blockchain.
[0353] Statement 34: The method of any preceding statement, wherein the core layer is complete.
[0354] That is, each core node in the core layer has a connection to each other core node in the core layer within the multi-layer network.
[0355] Statement 35: A method of any preceding statement, wherein the multilayer network as a whole is incomplete.
[0356] That is, not every node in every layer has a connection to every other node in every other core layer within the multilayer network. In some such embodiments, even a single node within a given layer may not necessarily have a connection to every other single node within the same layer.
[0357] Statement 36: A computer device comprising a memory having one or more memory units and a processing device having one or more processing units, the memory storing code adapted to be executed on the processing device, the code being configured to operate the computer device as the first smart contract node by executing the method of any preceding statement when executed on the processing device.
[0358] Statement 37: A computer program embodied on a computer-readable storage and configured to execute the method of any of Statements 1 to 35 when executed on one or more processors.
[0359] Statement 38: A method comprising communicating information regarding a smart contract between two or more nodes of a first network using one or more messages of a communication protocol, and causing the state of the smart contract to be stored in a record on a smart contract node of the network providing the smart contract service, wherein the state of the smart contract is also stored in a blockchain of a blockchain network.
[0360] In an embodiment, the communication protocol may be a communication protocol in which messages are in the form of: a) a transaction sent from a client node to a core node; b) a query from a client node to a core node regarding whether a transaction has been accepted into the memory pool of a miner and a corresponding response; c) a request for a Merkle proof that a transaction has been mined into a block and a response comprising the Merkle proof; and / or d) a request for a list of block headers and a response comprising the list of block headers.
[0361] In an embodiment, the communication protocol may be an SPV.
[0362] In an embodiment, the first network may include a core node that is a node of a blockchain network and a non-core node other than a node of the blockchain network. Communication may be performed between non-core nodes or between one non-core node and one core node. The core node and the non-core node may include a smart contract node. The communication may be communication between a smart contract node and one of the core nodes. The method may be executed by a smart contract node. The non-core node may include a client node that is a client of the smart contract node. The communication may be communication between the client node and the smart contract node. The method may be executed by a smart contract node or a client node or a combination thereof.
[0363] In an embodiment, the communication may include negotiating a smart contract, for example, by exchanging a template version of a transaction. The step of causing to be stored may be at least partially based on the communication, for example, based on the negotiation. Alternatively or additionally, the communication may include querying a state of a contract, for example, from a smart contract node or from one of the core nodes.
[0364] A transaction may be sent by one of the smart contract nodes or client nodes so as to be recorded on the blockchain, for example, by sending it to one of the core nodes.
[0365] Statement 39: A computer device comprising a memory having one or more memory units, a processing device having one or more processing units, and a network interface having one or more network interface units, wherein the memory stores code adapted to be executed on the processing device, and the code, when executed on the processing device, configures the computer device to perform the method of Statement 38 including communicating one or more messages via the network interface.
[0366] Statement 40: A computer program embodied on a computer-readable storage configured to perform the method of Statement 38 when executed on one or more processors.
[0367] According to another aspect disclosed herein, a method may be provided that is executed by a client node comprising any operation of the client nodes disclosed herein. According to a further aspect, a client node configured to perform such a method, and a computer program for operating a node as a client node according to such a method may be provided. According to a further aspect, a method may be provided that comprises any one or more operations of the smart contract nodes and any one or more operations of the client nodes. According to yet a further aspect, a corresponding system may be provided.
[0368] Other variations and use cases of the disclosed techniques may become apparent to those skilled in the art given the disclosure of this specification. The scope of this disclosure is limited only by the appended claims, and not by the described embodiments.
Description of Symbols
[0369] 100 System 101 Packet Switching Network, Internet 102 Computer Terminal, Computer Device 102a Computer Device 102b Computer Device 103 User, Related Party 103a First Related Party 103b Second Related Party 104 Node, Peripheral Node 104F Transfer Node 104M Mini Node, Mining Node 104S Storage Node 105 Client Application, Blockchain Wallet Application 106 Peer-to-Peer (P2P) Overlay Network, Blockchain Network, P2P Authentication Network 150 Blockchain 151 Block, Data 152 Transaction 152i Transaction 152j Transaction 153 Genesis Block 154 Pool 155 Block Pointer 201 Header 202 Input Field 203 Output Field 300 LN 301 Core Node 302 Second Node 303 Outer Node 304 Outer Node 305 Outer Node 400 LN, Multi-Layer Network 500 LN, Multi-Layer Network 600 LN, Multi-Layer Network 700 LN, Multi-layer Network 701 Node 702 Node 702A Proof Service Node 703 Node 703C User 1200 LN, Multi-layer Network 1201 Core Node 1202 Intermediate Layer Node 1202SC Smart Contract Node 1203 Outer Layer Node 1203C Client Node
Claims
1. A method for maintaining the state of a smart contract in a multi-layer network, wherein the multi-layer network comprises a core layer having one or more core nodes, one or more intermediate layers each having one or more intermediate layer nodes, and one or more outer layers each having one or more outer layer nodes, each of the core nodes being a node of a blockchain network, one or more of the intermediate layer nodes being smart contract nodes that provide a smart contract service for maintaining the state of the smart contract, one or more of the outer layer nodes being client nodes of the smart contract service, the method comprising, by a first smart contract node among the one or more smart contract nodes, recording the state of the smart contract in a record of the state maintained in the first smart contract node, wherein at least a first transaction that also records the state is recorded in a blockchain of the blockchain network.
2. wherein the one or more smart contract nodes are a plurality of smart contract nodes, and the method comprises, by the first smart contract node, spreading the state to a record of the state of the smart contract maintained in other smart contract nodes, the spreading being performed via one or more connections between smart contract nodes within the one or more intermediate layers of the multi-layer network. The method according to claim 1.
3. transmitted by one of the client nodes to at least one of the core nodes such that the first transaction is recorded in the blockchain, The method according to claim 1 or 2, wherein the first transaction is transmitted directly to the at least one core node via at least one connection within the multi-layer network between the one client node and the core layer.
4. by the first smart contract node, Transmitting the first transaction from the first smart contract node to at least one of the core nodes as recorded in the blockchain; Receiving the first transaction from one of the client nodes at the first smart contract node; comprising; the transmission by the first smart contract node includes transferring the first transaction to the at least one core node; - the receiving is performed directly via a connection within the multi-layer network between the first smart contract node and the one client node, and / or the transferring is performed directly via at least one connection within the multi-layer network between the first smart contract node and the core layer; The method according to any one of claims 1 to 3, wherein one or both of the above are satisfied.
5. The method according to any one of claims 1 to 4, wherein the first transaction is initiated by the first smart contract node.
6. The record of the state maintained at at least one of the smart contract nodes is made available to at least one of the client nodes, The method according to any one of claims 1 to 5, wherein making it available enables the at least one client node to determine the state without querying the record on the blockchain.
7. The method according to claim 6, wherein the record is made directly available via a connection within the multi-layer network between the at least one smart contract node and the at least one client node.
8. The method according to claim 6 or 7, wherein the first smart contract node makes the record of the state maintained at the first smart contract node available to the at least one client node, thereby performing the making available by the first smart contract node.
9. The method according to any one of claims 6 to 8, dependent on claim 2, wherein the record maintained at at least one of the other smart contract nodes to which the state is propagated is made available to the at least one client node.
10. The method according to any one of claims 1 to 9, wherein at least one of the smart contract nodes is adapted to examine the record on the blockchain or in the miner's memory pool to verify the state of the smart contract.
11. The method according to claim 10, wherein the at least one smart contract node is adapted to perform the examination directly via a connection within the multi-layer network between the at least one smart contract node and at least one of the core nodes.
12. The method according to any one of claims 1 to 11, wherein at least one of the client nodes examines the blockchain or the miner's memory pool to verify the state of the smart contract.
13. The method according to claim 12, wherein the examination by the at least one client node is performed via a direct connection within the multi-layer network between the client node and the core layer.
14. The recording of the state to the record maintained at the first smart contract node comprises recording a first state of the smart contract and recording a change in the state of the smart contract that is a change compared to the first state, wherein the first state is recorded in a first transaction on the blockchain and the change in state is recorded in a second transaction on the blockchain. The method according to any one of claims 1 to 13.
15. The first transaction comprises an output comprising each locking script comprising a state puzzle such that the solution of the state puzzle is required to unlock each locking script, and the method is performed by the first smart contract node. Using the set of rules stored in the first smart contract node, compiling the state puzzle based on the set of rules, and including the state puzzle in the first transaction before recording to the blockchain; The method according to claim 14, further comprising: when the second transaction comprises an input indicating each output comprising the state puzzle, and the input provides a solution to the state puzzle, recording the change in the state of the smart contract in the record maintained in the first smart contract node.
16. The method according to any one of claims 1 to 15, wherein the first transaction is negotiated between at least two of the client nodes via at least one connection in one or more outer layers of the multi-layer network.
17. A memory comprising one or more memory units, A processing device comprising one or more processing units A computer device comprising: The memory stores code adapted to be executed on the processing device, and when the code is executed on the processing device, the computer device is configured to operate as the first smart contract node by executing the method according to any one of claims 1 to 16.
18. A computer program embodied on a computer-readable storage and configured to execute the method according to any one of claims 1 to 16 when executed on one or more processors.
19. Communicating information regarding a smart contract between two or more nodes of a first network using one or more messages of a communication protocol, the messages comprising: a) A transaction sent from a client node to a core node; b) A query from a client node to a core node regarding whether a transaction has been accepted into a miner's memory pool, and a corresponding response; c) A request for a Merkle proof that a transaction has been mined into a block, and a response comprising the Merkle proof, and / or d) A request for a list of block headers, and a response comprising said list of block headers A step in the form of The step of causing the state of the smart contract to be stored in a record on a smart contract node of the network providing the smart contract service Comprising A method in which the state of the smart contract is also stored in the blockchain of a blockchain network.
Citation Information
Patent Citations
System and method for implementing deterministic finite automaton (DFA) via blockchain
JP2019522264A
Systems and methods for implementing deterministic finite automata (DFAS) via a blockchain
US20190279197A1
Trustless Stateless Incentivized Remote Node Network Using Minimal Verification Clients
US20190317934A1
Systems and methods for implementing deterministic finite automata (DFAS) via a blockchain
WO2018078584A1