VDF construction method, chip, use, product, apparatus, and medium

By designing the one-way reversible function S component and optimizing the calculation and verification stage of VDF, the problem of too small reverse logic delay in the hardware implementation of the VDF algorithm is solved, and significant computational delay gain and quantum attack resistance are achieved, which is suitable for blockchain consensus and other applications.

WO2025138380A1PCT designated stage expired Publication Date: 2025-07-03BEIJING RED & BLUE TREE TECHNOLOGY CO LTD

Patent Information

Application Number
PCT/CN2024/074026
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-03-23
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

In the hardware implementation of existing VDF algorithms, the problem that the reverse logic calculation delay is significantly smaller than the forward logic calculation delay, which is difficult to meet the industry's requirements for parallel acceleration, and the initialization parameter stage is complex and the ability to resist quantum attacks is insufficient.

Method used

The one-way reversible function S component is adopted to define a function whose forward logic delay is significantly greater than the reverse logic delay, combined with a intermediate state and F(A, B)=S(A0⊕Ab, △) structure, the calculation and verification stage of VDF is optimized, and the combination of serial circuits and parallel circuits is adopted to reduce the initialization stage and enhance the resistance to quantum attacks.

Benefits of technology

The significant gain of VDF computing delay is greater than VDF-1 computing delay is realized, the initialization process is simplified, and the ability to resist quantum attacks is improved. It is suitable for blockchain consensus, random beacon, replica proof and other applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024074026_03072025_PF_FP_ABST
    Figure CN2024074026_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a VDF (initial state, t), comprising: a one-way invertible function S component directly or indirectly constructing the VDF, wherein the S component is defined as an invertible function where a computation delay of forward logic is significantly greater than that of reverse logic; a computation phase: a intermediate states, and / or F(A0, Ab)=S(A0⊕Ab, △) indirectly constructing the VDF; and a verification phase: receiving the initial state and a+1 states, preferably completing a+1 VDF-1 verification tasks by means of parallel (a+1)*(b?b:1) S-1 logic verifications. A VDF construction with salt is preferred; the S component preferably has a structure of F(A, B)=g(A⊕B), wherein g-1 uses sparse tap design. Disclosed are proposed industrial standards VDF32 and VDF8192. The present invention achieves the effects of no initialization parameter phase (Setup); quantum-resistant design; and entropy preservation. Disclosed related uses comprise a randomness beacon, a portal website, a proof-of-replication, a storage service terminal, a cloud computing terminal, two types of blockchain systems, Token encoding and verification, and automatic commitment opening. To support industrial implementation, further disclosed are a VDF computing apparatus, a VDF verification apparatus, a medium, and a chip.
Need to check novelty before this filing date? Find Prior Art

Description

VDF Construction Method, Chip, Application, Product, Device and Medium Technical Field The present invention relates to the fields of computer science and blockchain, and more particularly to a VDF construction method, a chip, an application, a product, a device and a medium. Background Art 1. In 2018, the Verifiable Delay Function (VDF) was first presented by Professor Dan Boneh of cryptography at Stanford University and others in their paper "Verifiable Delay Function, VDF". VDF is a function that is not easily accelerated in parallel but can be verified quickly. VDF is a function that can prove the passage of time. Well-known applications include, at least, random beacon primitives, replica proof primitives, proof of time primitives, and blockchain pos consensus. 2. The modular large integer consecutive square algorithm and the zk-snake algorithm have been studied and applied. Both algorithms require three stages, namely, the initialization parameter stage (Setup), the calculation stage (Eval), and the verification stage (Verify). The three stages are equivalent to the three roles of a multi-party protocol for computer information security; they also correspond to three devices of an entity, namely, a device for implementing initialization parameters, a device for implementing VDF calculation, and a device for implementing VDF result verification. 3. In 2019, Ethereum and Filecoin invested tens of millions of dollars to support VDF algorithm research and ASIC hardware implementation. The research purpose of Ethereum is to implement the beacon chain and then migrate from pow consensus to pos consensus based on the beacon chain. The search websites guided are ethresear.ch and www.vdfalliance.org. 4. All VDF construction, evaluation, and engineering implementation must be supported by ASIC technology and hardware circuit design technology, involving parallel algorithm optimization, hardware wiring technology, and circuit process libraries, etc. The parallel algorithms referred to are: hardware Euclidean algorithm, look-ahead carry technology for fixed-point addition, Chapter 1 "Low level algorithms" of "fxtbook". Technical Problem Due to the complexity of the invention process and the abundance of the invention content, in order to facilitate understanding, ☆ is marked at the most important points as a guide and hint. The inventor found that the reverse logic calculation delay of the non-linear recursive structures F(A, B)=S -1 (A⊕B) and F(A, B)=S(A)⊕B is significantly less than the forward logic calculation delay, where the reverse logic implementation is a number of S-box structures placed in parallel; A in the above recursive equation is the latest symbol, and B is the earliest symbol. The recursive equation can be more specifically expressed as the forward logic of VDF as VDF({A, …, B’, B}, 1) = {S -1 (A⊕B), A, …, B’} and VDF({A, …, B’, B}, 1) = {S(A) ⊕B, A, …, B’}. Because Intel has AES algorithm instructions, therefore, the reverse motion logic for specifically implementing A17 = S(A16)⊕A0 is A0 = A17⊕S(A16), where S is the AES algorithm S-box. Obviously, the number of symbols in this example is 17; The recurrence equation represents the serial forward logic: VDFaes({A16, A15, …, A1, A0},1) = {S(A16)⊕A0, A16, …, A1}. The recurrence equation represents the parallel reverse logic: VDFaes -1 ({A32, A31, …, A17, A16}, 16) = VDFaes -16 ({A32, A31, …, A17, A16}, 1) = {A16, A32⊕S(A31), …, A18⊕S(A17), A17⊕S(A16)} = {A16, A15, …, A1, A0}. From the formal analysis of the above two sets of state recurrence equations, it can be known that VDFaes(, 16) corresponds to a serial circuit with a depth of 16 and a width of 1, and the actual delay is 16 S(Ai + 16)⊕Ai. VDF -1 (, 16) corresponds to a parallel circuit with a width of 16 and a depth of 1, and the actual delay is 1 S(Ai + 1)⊕Ai. The inventor uses the vaesenclast instruction and vpshufb instruction of the Intel processor to implement the 16-beat reverse motion logic VDF -16 (, 1) only requires 5 instructions. More specifically, the 5 instructions are paired when running. The inventor found that: ☆ This kind of structure where the forward logic corresponds to a serial circuit and the reverse logic corresponds to a parallel circuit meets the basic requirements of the VDF primitive. The inventor believes that the above properties are a new technical route for constructing VDF. Now the single-chip integrated transistors have already exceeded tens of billions, so the chip integration density can support the parallel requirements of the described new technical route. In order to continue the research and design a VDF that can be widely used in the industry, the inventor attempts to increase the number of recurrence symbols in the above model and simultaneously evaluate multiple technical parameters; the evaluated parameters include VDF and VDF -1The implementation overhead of hardware circuits and Intel processors, the evaluation of the anti-parallel optimization capability of VDF calculation models, the evaluation of the fastest possible industrial implementation of VDF, VDF and VDF -1 The computational time delay ratio at the circuit level. The recursive models evaluated are A32=S(A31)⊕A0, A33=S(A32)⊕A0, A64=S(A63)⊕A0, A65=S(A64)⊕A0, A1024=S(A1023)⊕A0, A1024=S(A1023⊕A0), A8192=S(A8191⊕A0), etc. Through self-evaluation, the inventor found four problems: 1. The pre-table acceleration technology invented by the inventor (details are in the term explanation) can significantly accelerate the above VDF model. The larger the number of levels, the more obvious the acceleration effect. 2. Because the hardware implementation overhead of the s-box of the AES algorithm is large, it is not friendly as an industrial standard. 3. F(A, B)=S -1 (A⊕B), where S is the gain effect of sparse tap design, and the design gain is obtained from two aspects: F(A, B) structure and sparse tap design. 4. For the design with a large number of input and output bytes of A8192=S(A8191⊕A0), a △ beat splitting technique should be added. The main idea is to first construct a beacon type VDF', and then define Ab+1=F(A0, Ab)= VDF'(A0⊕Ab, △) to construct a replica proof type VDF. Using the △ beat splitting technology has at least two benefits: benefit 1. The acceleration capability against pre-made tables is improved. Benefit 2. The hot spots calculated in the △ clock are concentrated in the area corresponding to the beacon type VDF', which is beneficial to VDF and VDF -1 Hardware implementation and VDF -1 The inte processor implementation is more friendly and efficient. Aiming at the industrial realization of serial circuits corresponding to forward logic and parallel circuits corresponding to reverse logic, the inventor proposes, based on the above research results and in accordance with circuit evaluation standards and industrial application standards, that the constructed VDF should meet the following three evaluation standards, which are also equivalent to the technical problems to be solved by the present invention. Because the three evaluation standards are very important, they are hereinafter referred to as ☆ parameter guidelines. The standard for circuit evaluation refers to providing the minimum delay implementation plan and evaluation of a given algorithm at the circuit level without considering the area cost; related skills and knowledge include basic hardware wiring programming skills and basic wiring effect evaluation skills, and necessary parallel algorithm optimization and evaluation techniques; at the theoretical level, it is a known fact that most combinatorial optimizations are NP-complete, and for a specific VDF or a specific VDF -1 The difficulty of providing circuit-level parallel optimization implementation and its evaluation results can be imagined, so the circuit-level evaluation results related to the present invention may not be optimal, such as the theoretical indicator 8clk of VDF32. The following are 3 parameter guidelines. 1: VDF is not easily accelerated in parallel and requires theoretical demonstration or self-evaluation support in theory. 2: VDF / VDF -1 The theoretical gain is at least three orders of magnitude; That is to say, the theoretical calculation delay of VDF is greater than or equal to 1000 times the theoretical calculation delay of VDF -1 The inventor's setting basis reference is that a beacon-type VDF can be used for blockchain consensus, and 1000 times should be the lowest safety index recognized by the industry; on the one hand, the greater the theoretical gain, the better the user experience in the verification stage, so the theoretical gain cannot be too small; on the other hand, it is necessary to initially evaluate the delay ratio of the theoretically fastest VDF calculation circuit and the actual VDF calculation circuit in the same period, that is, the safety redundancy index. Obviously, the higher the safety redundancy index, the worse the user experience in the verification stage under the same theoretical gain. Therefore, the safety redundancy index also determines that the theoretical gain should preferably not be less than 1000. 3: VDF / VDF -1 The industrial engineering gain index of is basically consistent with the above Article 2; The above two technical indicators in Article 2 and Article 3 should be about the same, otherwise Article 2 above will be meaningless and the evaluation model of Article 2 must be corrected. Technical solution In response to the above achievements and three parameter guidelines, the inventor first refined the first important component of the present invention, the one-way reversible function. The inventor believes that without considering pre-built table acceleration and other optimizations, the forward logic delay of the F(A, B) structure is approximately N times the reverse logic delay, where N + 1 is the number of symbols. Based on the properties of the F(A, B) structure, the inventor defines a function whose forward logic calculation delay is significantly greater than the reverse logic calculation delay as a one-way reversible function. The inventor found that in addition to the F(A, B) structure, the following three structural components also have one-way reversibility: 1) the reverse function is the x t structure, 2) the forward function is the discrete logarithm, 3) the reverse function is the sparse tap design. Based on one or any combination of the above 4 methods, components can directly or indirectly construct VDF, and the calculation delay of the constructed VDF can be significantly greater than the calculation delay of VDF -1 The calculation delay, and more detailed explanations are in the term explanations and related embodiments in the specific implementation part. Based on the above research results, the inventor designed a 32-byte-width VDF, namely VDF32, to be used as the beacon application standard. The design gain of VDF32 reaches 34.6 (13 * 8 / 3). ☆ Referring to the second item of the parameter guide, the inventor found that the design gain of the beacon-type VDF does not meet the industrial application standard. To increase the gain, the inventor created a technology with a intermediate states as evidence for the verification stage. The technical feature is to receive the initial state and a + 1 states, and decompose it into a + 1 VDFs in the direction from the result to the initial state. -1 Verification task. The gain refers to the forward logic calculation delay divided by the reverse logic delay. For the replica-proof VDF, the construction method recommended by the inventor is to first construct a beacon-type VDF', and then define the structure of the replica-proof VDF as Ab+1 = F(A0, Ab) = VDF'(A0 ⊕ Ab, △). The description of the recurrence equation is that the replica-proof VDF({Ab,..., A1, A0}, 1 * △) = {VDF'(A0 ⊕ Ab, △), Ab,..., A1}. The actual gain is b times the gain corresponding to VDF'(). The beacon-type VDF refers to the one with a smaller output byte count, typically 32 bytes; the replica-proof VDF refers to the one with a larger output byte count, typically 8192 or 2M bytes. The total gain of the VDF of the present invention consists of three parts: the gain contributed by the S delay divided by the S -1 delay, the (b?b:1)-fold gain contributed by F(A, B) = S(A0 ⊕ Ab, △), and the a + 1-fold gain contributed by the a intermediate states. The main idea of the verification stage is to use several Ss -1 in parallel for logical verification to implement the verification subtasks of a + 1 VDFs -1 . Two points are added to the above content. The present invention stipulates that a and b cannot both be 0 at the same time; b being 0 means that the S component directly constructs the VDF; a being 0 means that there is only 1 state of the VDF result in the verification stage. △ is the granularity parameter, which can greatly improve the wire delay evaluation and wire delay evaluation of the actual circuit implementation; imagine that when △ degenerates to 1, when the width of the VDF is very large, such as 8192 bytes or 2M bytes, whether it is the circuit implementation or the multi-core multi-threaded implementation, the distance between the latest symbol A and the earliest symbol B is bound to be very far, resulting in extremely frequent data communication; therefore, setting a relatively large △ granularity results in the core area of the calculation circuit being restricted to a very small area within △ clocks, and at this time there is no communication overhead. The corresponding effect of the multi-core multi-threaded implementation is that there is no inter-process communication. More specific indicators are that it is restricted within the calculation logics of VDF' and VDF' -1 with the input-output width. Therefore, a relatively large △ granularity is beneficial to the hardware wiring implementation and also beneficial to the multi-core multi-threaded processor to implement the VDF or VDF -1 , and is more beneficial to the evaluation of the second and third items of the parameter guide. Considering the effects generated by △ above, when the number of symbols is very large, a relatively large △ granularity design is preferably recommended. ☆☆In summary, the inventive concept of the VDF construction method is that the one-way reversible function S directly or indirectly serves as the VDF, and the delay of the forward logic VDF is defined to be greater than that of the reverse logic VDF -1 Delay; a intermediate states improve the design gain of the VDF, and / or, the VDF is indirectly constructed by the structure of F(A0, Ab)=S(A0⊕Ab, △), where t is divisible by △*b; in the verification stage, the initial state and a + 1 states are received, and the decomposition is carried out into a + 1 VDFs from the result to the initial state direction -1 Verification task, the core verification algorithm is preferably (a + 1)*(b?b:1) parallel Ss -1 Logical verification completes the a + 1 VDFs -1 Verification task, the verification passing criterion is the a + 1 VDFs -1 All verification tasks pass. Using (a + 1)*(b?b:1) Ss in parallel -1 The logical gain obtained from (a + 1)*(b?b:1)*S is both the invention purpose and the invention effect. This effect also responds to the second item of the parameter guidance. ☆☆Another statement of the inventive concept of the present invention is that VDF(initial state, t) is a VDF directly constructed by S or a VDF indirectly constructed by F(A0, Ab)=S(A0⊕Ab, △), t is divisible by △*b, where S is a one-way reversible function component; in the verification stage, the initial state and a + 1 states are received and divided into a + 1 VDFs in parallel -1 Verification task; therefore, the calculation stage corresponds to a serial circuit device of S logic connected by a cascade structure with a depth of (a + 1)*(b?b:1), and the verification stage corresponds to a parallel circuit of S connected by a parallel structure with a width of (a + 1)*(b?b:1) -1 Logical parallel circuit device; generally, a serial circuit defined by a state recurrence equation and a parallel circuit corresponding to the serial circuit. The so-called VDF design gain is the ratio of the critical path delay of the serial circuit to that of the parallel circuit. A more specific technical index formula is (a + 1)*(b?b:1)*S logic delay / S -1 Logical delay; compared with the second item of the parameter guidance, the technical index formula clearly expresses the details of the gains contributed by the three necessary technical features of the present invention respectively. Once again, it is reminded that the second item of the parameter guidance is also one of the invention purposes of the present invention. It is pointed out in advance that VDF and VDF -1The industrial engineering implementation mainly refers to implementing the serial circuit corresponding to the calculation stage and the parallel circuit corresponding to the verification stage based on the state automata technology. There are detailed implementation examples and FPGA actual test result evaluations in the specific implementation part. The evaluation results can prove that the examples basically meet the third item of the parameter guidelines. Here, the serial circuit defined by the state recurrence equation and its corresponding parallel circuit are explained. According to the second and third items of the parameter guidelines, although the circuit and the VDF recurrence relationship are defined by the recurrence equation, the evaluation does not include the overhead of updating the register state, and even the overhead of wire delay is ignored in the evaluation. By the same token, the following salt parameter controls the VDF movement, which is generally defined or described in combination with the recurrence equation. However, the evaluation result of salt at the circuit layer may be that there is only area consumption and no time delay consumption; because the circuit implementation is almost the most highly parallel engineering implementation, the actual calculation overhead related to salt is submerged in the consumption of the VDF and the longest calculation path of the VDF. -1 The consumption of the longest calculation path. ☆8 A chip, which includes a VDF or VDF -1 calculation module, a receiving module, and an output module. The receiving module initializes the calculation module after receiving the input of the calculation module. The calculation module is responsible for calculating the VDF or VDF -1 , and the output module is responsible for outputting the calculation result. ☆9 A serial communication chip, more specifically, it also includes an rx pin and a tx pin that conform to the serial protocol. The control command and the calculation module input pass through the rx pin, and the calculation result output is implemented by the tx pin. The advantages of the serial communication chip are as follows: 1. Fewer pins, so it is friendly to chip packaging and circuit manufacturing; 2. Serial port call is a particularly general and economical bus solution; 3. It conforms to the hierarchical model, and the software layer call and the hardware chip development are separated. Especially when the serial port instruction set is standardized, the economic effect is more obvious. ☆10 In the embodiment and its related drawings part, the design and test results of the serial communication chip integrating the VDF8192 hardware module and the VDF8192 -1 hardware module are disclosed in detail, thereby proving that the VDF and VDF -1 can be implemented by FPGA engineering. After refinement, the structural design of the serial communication chip is disclosed below. The chip internally includes two types of calculation modules and two components. The two types of calculation modules are respectively: the VDF8192 calculation module based on the state automata and the VDF8192 -1 calculation module; and the two components are respectively: the serial port decoding and instruction decoding execution component and the multi-functional automatic encoding and output component; According to the signal control flow direction, the decomposition structure of the serial port decoding and instruction decoding execution component is in the following order: the serial port decoding sub-module connected to the rx pin, the instruction decoding and execution sub-module, and the 256-bit input register sub-module; According to the signal control flow direction, the decomposition structure of the multi-functional automatic encoding and output component is in the following order: the output buffer register sub-module, the multi-byte automatic encoder sub-module, and the serial port encoding output sub-module connected to the tx pin; Moreover, the mutual control relationship between the calculation module and the component is: The serial port decoding and instruction decoding execution component receives external instructions from the rx pin, and the serial port decoding and instruction decoding execution component translates the external instructions into: instruction code, data encoding, and address encoding, where each address encoding is associated with a specified VDF8192 -1 calculation module or VDF8192 calculation module, and the data encoding is buffered into the 256-bit input register sub-module; According to the specification of the address encoding, the specified VDF8192 -1 module or VDF8192 module receives the excitation control signals of the instruction code and the data encoding, and according to the excitation control signals, realizes the initial state initialization, start calculation, and pause calculation and other functions of the VDF8192 -1 module or VDF8192 module realizes the VDF or VDF -1 initial state initialization, start calculation, and pause calculation and other functions; The instruction code also excites and controls the multi-functional automatic encoding and output component, thereby realizing the state register output of the VDF8192 -1 module or VDF8192 module; the specific output steps are as follows: first buffer the state of the calculation module specified by the address encoding into the output buffer register sub-module, and then output the information of the output buffer register sub-module to the tx pin according to the serial port encoding level signal under timing control. The VDF constructed based on the present invention includes the following related industrial applications and industrial products: ☆11 A method for applying a randomness beacon. The VDF function of the present invention uses the blockchain entropy value as the input of the VDF, and the VDF output is used as the randomness beacon. The following constructs a practical randomness beacon by combining the bit coin block hash with the VDF32 algorithm, and calculates the threshold t from the working frequency of the fastest transistor in the current process. The inventor recommends 254 intermediate states, which just reuse the 255 parallel VDF32 -1 calculation logics of the VDF8192 -1 module; a is the total gain of the 254 intermediate states, which is also exactly equal to the gain of the VDF8192, both are 8823.0 (255 * 34.6). Define VDF32 (Bitcoin block hash, salt, t) as a random beacon, where salt is the lower 128 bits or 256 bits of Bitcoin block hash - 1. Assume the fastest transistor characteristic frequency of the current process is 1 Thz, select a safety redundancy of 3 times, and the Bitcoin block generation interval is 10 minutes. Let t be the safety threshold, set up an equation, and solve the equation to obtain. This threshold is sufficient to ensure that even the fastest circuit of the current process cannot calculate VDF32(, 1800T) within 10 minutes; Invention effect: If t is greater than the safety threshold, the output of the random beacon is non - forgeable. Assume that the working frequency of ASIC transistors in a certain circuit process library is 50G; The time taken for the circuit to calculate VDF32 (Bitcoin block hash, salt, 1800T) is 36000 seconds, and 36000 seconds is equal to 10 hours; Deduce that the actual beacon generation delay is 10 hours. Assume VDF32 -1 The working frequency of ASIC transistors is also 50G; Select the number of intermediate states to be 0, and deduce that the actual verification time is 1040.5 seconds (36000 / 34.6). If the number of intermediate states is 254, deduce that the actual verification time is 4.08 seconds (1040.5 / 255). Announce VDF32 (Bitcoin block hash, salt, 1800T) to the world through a portal website. The effect of this website: The website provides trusted random numbers for lottery drawing to the world, and these random numbers can be used for lottery drawing of members of the court collegiate bench, competition lottery drawing, and challenge value lottery drawing for interactive zero - knowledge proof. ☆12 Synthesize and refine the relevant technologies of the portal website, and disclose a portal website that publishes a random beacon with VDF as the output and data that can verify the random beacon, where VDF conforms to the definition of the present invention. The portal website is an Internet address, and the form of the Internet address includes but is not limited to web sites, APP applets, and applets derived from well - known APP platforms. The data that can verify the random beacon includes a intermediate states, the initial state, and evidence of the source of the initial state entropy. ☆13 A coding and decoding method for replica proof applications, including input parameters of replica numbers and coding blocks, including the VDF with salt constructed by the present invention, where salt is associated with the replica number; The encoding process of the replica proof is VDF (coding block, replica number); The decoding process of the replica proof is VDF -1 (encoding result, replica number). Replica proof is a basic primitive of blockchain and cryptography. The encoded block can be a diary or log, or an object of a storage service similar to Filecoin. For example, VDF2M(encoded content, salt, t) is defined as the replica proof standard, where salt is the replica number. The encoded content block of VDF2M is 2M bytes long, with a theoretical gate delay gain of 2.25M. The theoretical effect is that under the same circuit process, it takes 26 days to encrypt and 1 second to decrypt. ☆14 A storage service terminal, whose storage and download objects are VDF(encoded block, replica number) related to replica proof; s141: Receive the download request from the customer, s142: Return or direct the download of VDF(encoded block, replica number) according to the download request. It is feasible to direct the download type of storage service terminal. The storage service terminal is a portal website, which responds to user requests and returns the specified VDF encoding or returns the URL link pointing to the VDF storage. To solve the problem of difficult calculation of VDF and VDF for weak computing terminals, cloud computing terminal technology was invented. The main idea is to upload the VDF or VDF calculation tasks of weak computing terminals to the cloud computing service terminal, which is calculated by the computing power of the cloud computing terminal, and the cloud computing results are returned to the weak computing terminal through the network. Here, the author strongly recommends 2 kinds of technologies to hide calculation secrets, and takes VDF32 and VDF8192 as examples to illustrate the basic idea. -1 For the problem of difficult calculation of VDF and VDF for weak computing terminals, cloud computing terminal technology was invented. The main idea is to upload the VDF or VDF calculation tasks of weak computing terminals to the cloud computing service terminal, which is calculated by the computing power of the cloud computing terminal, and the cloud computing results are returned to the weak computing terminal through the network. Here, the author strongly recommends 2 kinds of technologies to hide calculation secrets, and takes VDF32 and VDF8192 as examples to illustrate the basic idea. -1 Calculate the task and upload it to the cloud computing service terminal, which is calculated by the cloud computing terminal's computing power, and the cloud computing result is returned to the weak computing terminal through the network. Here, the author strongly recommends 2 kinds of technologies to hide calculation secrets, and takes VDF32 and VDF8192 as examples to illustrate the basic idea. 1. Before uploading, the weak computing terminal pre-calculates each small VDF-type task for 2048 * 13 * r beats, where r is a positive or negative integer with a relatively small absolute value. After downloading the corresponding calculation results, calculate -r * 2048 * 13 beats to eliminate the influence of r; 2. For VDF8129 -1 or VDF2M -1 The input author also suggests reordering 255 VDF32 -1 or VDF8129 -1 Input to reorder and hide the calculation technology to hide the calculation content. ☆15 Disclose a cloud computing terminal, including a VDF or VDF -1 Calculation module, network receiving module and network sending module, where the VDF conforms to the definition of the present invention; S151: The network receiving module receives the input from the customer through the network; S152: The calculation module calls VDF or VDF -1 To calculate the input of S151; S153: The network sending module returns the calculation result of S152 to the customer through the network. A typical scenario of cooperation between a thin client and a cloud computing terminal is as follows: The VDF standards are VDF32, VDF8192, and VDF2M. Mobile phones are weak computing terminals, and the computing power service provider is the entity operating the cloud computing terminal. The mobile phone is installed with a module that hides computing secrets. The mobile phone can use the cloud computing terminal to implement the verification function of the random beacon, the encoding function of the replica proof, and the decoding function of the replica proof. If the mobile phone does not trust the cloud computing terminal, it can activate the hidden computing module, which can hide the content of the original computing power request. On the other hand, the stripping hidden module on the mobile phone side receives the response result of the cloud computing terminal and then calculates the correct calculation result. ☆16 To support the VDF-based POS consensus, Ethereum once invested tens of millions of dollars in supporting VDF algorithm research. The VDF constructed based on the present invention discloses a blockchain system, including the VDF module of the present invention; the blockchain accounting right is determined by the VDF output, and the VDF input is associated with the entropy value of the previous block. The essence of this invention is that the trusted random beacon determines the accounting right, so the consensus result is publicly trusted. The construction of the random beacon, the setting of security redundancy, and the calculation of verification effects can refer to the example of VDF32 as the random beacon above. ☆17 A blockchain system for associating the consumption time of casting a new block includes a time parameter t and also includes the VDF module of the present invention. The new block hash is associated with VDF(last block hash, t). The meaning of the new block hash being associated with VDF(last block hash, t) is that the last block hash is used as the initial state of the VDF, and after t beats, the VDF is used as an element of the new block header or directly as the block header. Invention effect: The VDF is equivalent to the crystal oscillator or clock in the digital world, which can prove that it takes time t to cast a new block; it will be very difficult to forge a blockchain, especially a consortium chain, because several VDFs(, t) must be consumed. It is possible to directly use the VDF as the block header because the VDF with salt is sufficient to construct a password-secure hash value function module. As long as △ is large enough, VDF(, △, salt) is a high-strength password-secure hash value. The information encoding of the block header can be changed into multiple salts, and the new block hash can be obtained through continuous VDF(, △, salt). For specific elaboration, see the specific embodiments. ☆18 Based on the above blockchain system, preferably use the VDF with salt, where the salt is a trusted time synchronization evidence. Examples of trusted time synchronization evidence include the latest Bitcoin hash, Ethereum block hash, or trusted consortium chain hash. Trusted time-stamping evidence is digital space evidence that can prove the most recent timestamped data. It is recommended to use only 1 piece of trusted time-stamping evidence during the process of minting a new block, because the more associated trusted evidence there is, the greater the storage space consumed. The inventor particularly recommends periodically or irregularly depositing the hash of the new block of the present invention into a blockchain with trusted time-stamping again. After deposition, the evidence information will be retained; the effect of this operation is that the evidence chains of mutual time-stamping between the two blockchains can prove that the time-stamping operation of the blockchain of the present invention is trustworthy and cannot be forged. Another explanation of the inventive effect of introducing trusted time-stamping evidence: It is equivalent to defining the time-stamping function of GPS or Beidou in the digital world. The birth time of the new block header hash is equal to the time-stamped time plus t, where t is proved by VDF(, t). ☆19 To strongly associate a Token with the minting time t, an encoding and verification encoding method for the Token is invented, including an encoding stage and a verification stage; the encoding stage corresponds to the calculation stage of VDF, and the verification stage corresponds to the verification stage of VDF; where VDF is the VDF constructed by the present invention. The following operations are performed in the encoding stage: Calculate and present VDF(seed, t) and a intermediate states, where seed is associated with the ID of the Token. The following operations are performed in the verification stage: Receive seed and a + 1 states; and, Parallelly use several S -1 Logically implement VDF -1 (seed, t) verification task. Inventive effect: Since VDF is a proof of the passage of time, seed and VDF(seed, t) together can prove that it takes t beats to mint the Token, that is, the birthday parameter is t. The association method seed = hash(identification features of the Token) also satisfies ID = hash(seed, resource data corresponding to the Token). The following uses the example of Non-Fungible Tokens (NFTs) to prove the feasibility of the method. Suppose an NFT identifier is a picture; seed = sha2(binary encoding of the picture); and then define ID = sha2(seed, other resource data of the Token). Once the picture is born, continuously calculate VDF32(seed, t), where the parameter t is equivalent to the birthday of the picture. The prover calculates and presents ID, and then calculates and presents VDF32(seed, t), the birthday parameter t, and a intermediate states; in the verification stage, the verifier uses VDF -1The module proves that the birthday of the picture corresponding to the minted ID is t. It should be noted that the IDs of Tokens and NFTs are a type of global identifier, and can be interpreted with reference to the REC721 and ERC1155 standards. ☆20 Except for the copy certification applications and random beacon applications related to the background technology. The inventor invented a new application with the nature of a time capsule. An automatic open commitment and verification commitment method, characterized by including a commitment stage and a verification stage, wherein the commitment stage corresponds to VDF -1 (, t) calculation, and the verification stage corresponds to VDF (, t) calculation. The VDF is a VDF constructed by any method in claims 1-7, and the t is a time parameter; the steps of the commitment stage and the verification stage are as follows: Commitment stage: S201: X = VDF -1 (commitment content, t); S202: Send X and t to the verifier; Verification stage: S203: Receive the said X and t, and calculate VDF(X, t) to obtain the commitment content. The effect of this new application is a time capsule that can be automatically opened in the digital world. To open the time capsule, it is necessary to consume the time parameter t in the digital space. The invention content also includes the following two devices. The two devices can complete the calculation logic independently, and it is also recommended to complete the calculation logic with the support of a third party. The previously described cloud computing terminal and hidden computing technology are a way to achieve the calculation logic with the support of a third party; for another example, the calculation device or verification device calls a previously described one including VDF or VDF -1 The calculation module chip is also a way to achieve the support. There are many specific equipment forms, including but not limited to, the write block device of the blockchain system, the read block of the blockchain system and the device including VDF -1 The equipment forms also include mobile phones, pads, computers, cloud computing servers, the blockchain system of the present invention, the random beacon distribution website of the present invention, ukeys or acceleration cards including the chips of the present invention, the commitment device or verification device for automatically opening commitments. ☆21 Disclose a VDF calculation device. The VDF calculation device executes the VDF calculation stage of the present invention. The calculation device inputs the initial state and t, and the output is the VDF result and a intermediate states; when a is 0, the VDF is of the structure F(A0, Ab)=S(A0⊕Ab, △); the VDF calculation module can be completed independently by the device or can be realized with the support of a third party. ☆22 Disclose a VDF verification device. The VDF calculation device executes the VDF verification stage of the present invention. The device realizes (a + 1) VDFs-1 The sub-task verification task, the input of the verification device is the initial state, the result, and a intermediate states, and the output is the judgment result; the VDF verification module can be independently completed by the device or implemented with the support of a third party. ☆23 To implement applications such as information storage, information exchange, information distribution, and on-site protection related to VDF, it is necessary to obtain the support of the storage function of the medium. In the most typical scenario, the implementation entity in the calculation stage transfers the initial state, t, the VDF result, and a intermediate states to the implementation entity in the verification stage. Disclose a medium on which binary data is stored, and the encoded content of the binary data is VDF and / or the input, output, or intermediate state of VDF -1 ; where the VDF conforms to the definition of the present invention. The evidence storage medium includes but is not limited to computer storage media, cloud storage, paper, etc., and the specific implementation manners are described in more detail. Since the content stored in the medium is generally encapsulated by a certain protocol or encoded by a certain computer encoding rule, these encodings include but are not limited to ASCII encoding, BASE64 encoding, binary DER encoding, a certain channel encoding, or even a certain block cipher, so the meaning of the encoded content is the essential content after removing the above encodings. Beneficial effects The effects of the present invention also include: 1. Different from the background art, the VDF of the present invention does not require an initialization parameter stage (Setup); for example, the successive squaring method must generate a secret modulus N in the initialization parameter stage; 2. Based on the high-order nonlinear iterative design principle, different from the public key algorithm principles of the successive squaring method and the zk-snark method in the background art, so the VDF of the present invention is designed against quantum attacks; 3. Entropy preservation, that is, VDF -1 exists. From this property, a new application of the time capsule is obtained inherently. The main idea is to use the VDF -1 module in the commitment stage and automatically open the VDF module in the commitment stage. Referring to the second item of the parameter guidance for comparison, when the input and output widths of the VDF are relatively small, it is necessary to use a states to obtain a sufficiently high design gain. Another special case is that when the input and output widths of the VDF are particularly large, even if a degenerates to 0, a VDF with a large gain exists (such as the structure of F(A0, Ab)=S(A0⊕Ab, △), and b is large). It can be considered that the larger the gain index of the comprehensive contribution of (a + 1)*(b?b:1), the larger the amount of data received in the verification stage; the larger the amount of data, the corresponding parallel S in the verification stage -1The more logic there is, the greater the resulting design gain of the VDF. Referring to the theoretical design metrics of the optimal integrated examples VDF32, VDF8192, and VDF2M, the design gain metric in the verification phase is basically equivalent to the number of bytes of the received data volume in the verification phase. That is, when receiving 32 bytes, there is a gain of approximately 32 times, and when receiving 2 20 bytes, there is a gain of 2 20 times. Because the larger a and b are, the faster the verification speed in the verification phase; according to the technical metrics of the embodiment, a data volume with a byte width of (a + 1)*b*S can provide a total gain (hereinafter referred to as the total gain) with a byte width of (a + 1)*(b?b:1)*S. In the industrial parameter evaluation phase, both the total gain parameter and the security redundancy parameter are very important. The disadvantage of setting the total gain too large is that the verifier must accept a large amount of data volume, and the disadvantage of setting the total gain too small is that a large amount of computing time must be consumed in the verification phase. Generally, in the theoretical design phase, the gate delay metric is used to evaluate the theoretical total gain. The theoretical total gain parameter can cover the possibility that the actual gain of the actual ASIC chip becomes smaller. The actual gain in industry is the ratio of the computing speeds of the actual circuits of VDF -1 and VDF. The theoretical total gain also needs to cover security redundancy. The minimum standard for security redundancy is to define the hardware execution speed of the VDF of the currently recognized fastest circuit process library in the world. Generally, it is evaluated by combining the current fastest transistor process library, the VDF achievements of circuit-level parallel optimization engineers, and wiring engineers. The disadvantage of setting the security redundancy too large is that the verifier must consume a large amount of computing time, especially leading to an increase in the number of delayed blocks in the consensus of the blockchain system based on VDF consensus; setting the security redundancy too small results in the risk of cheating in the most risky beacon-like applications. If the VDF computing speed of some laboratories or chip manufacturers secretly breaks through the publicly recognized fastest VDF speed, those non-public high-speed VDF computing modules have the possibility of being cheated in theory for beacon-like industrial applications. ☆2 The one-way reversible function S component is an essential technical feature of the present invention. Its one-wayness lies in a reversible function with slow forward calculation and fast reverse calculation. More specifically, the critical path time of the forward logic should be significantly greater than the critical path time of the reverse logic. The inventor first designed and evaluated VDF32 based on the F(A, B) structure. The recursive relationship of VDF32 is A16 = g(~(~A15&A14)&A13)⊕A0), where g -1 is a sparse tap design. To guide the design of more one-way components, the inventor proposed and summarized four basic methods. The inventor believes that to design a one-way reversible function, either start from the structure to find the one-way design gain, or start from the algorithm to find the one-way design gain; the sparse tap design and the F(A, B) structure belong to structural contributions, discrete logarithm and x tIt belongs to the contribution at the algorithm level. In comparison with the first item of the parameter guidelines, many examples, derivations, and conclusions are given in this specification for the evaluation results of the structural contribution. Therefore, the inventor believes that in order to align with the first item of the parameter guidelines, the design of the structural contribution is preferably recommended. In addition to the four basic methods and their combinations, other methods for constructing one-way reversible functions are not excluded. The four basic methods for constructing one-way reversible functions and their combinations belong to the content of the present invention, and the description can be found in the specific implementation manners. 1) The forward feedback function is designed with the structure of F(A, B), where A is the earliest symbol and B is the latest symbol; 2) The reverse logic includes a sparse tap design; 3) The reverse logic function includes an x t power design, where t is the smallest integer to ensure reversibility and non-linearity; 4) The forward logic function includes a discrete logarithm function. The meaning of the basic method is a one-way reversible function S constructed by using one or a combination of four components. The criterion for judging whether S or VDF is one-way is that the time delay of the critical path of VDF should be significantly greater than the time delay of the critical path of VDF -1 The specific implementation manners and Figure 13 will give more guidelines. The inventor found that adding the input parameter salt can significantly improve the cryptographic security of VDF. Since the VDF output is associated with the salt information, the algebraic expression of the VDF output must be more complex, and increasing the salt entropy value significantly improves the anti-collision and anti-precomputation acceleration capabilities. The inventor preferably recommends that salti is a linear shift register or an additive congruence design. It should be noted that adding salt to increase the anti-analysis ability is a common technique in the field of computer security. For example, adding salt to the password library in Unix improves the anti-analysis ability of passwords. Referring to the salt design of VDF32, an excellent salt design can achieve only circuit area consumption without delay consumption. The design guidelines given by the inventor are that the frequency of salt controlling the corresponding register of VDF is smaller than the frequency of VDF symbol update, and the exclusive OR operation of 1 bit of salt is connected to the calculation logic with a shorter calculation delay path time of VDF. -1 ☆3 It is preferably recommended to use a VDF with a salt parameter, which is characterized in that salti changes the output of the i-th beat of VDF in an entropy-preserving manner or the salti entropy value operates together with the one-way reversible function S, where salti is the state of salt at the i-th beat. It should be explained that the statement that salti changes the output of the i-th beat of VDF is only for the convenience of the public to simply understand, and it does not limit that salti strictly corresponds to the i-th beat of VDF. The salt of VDF32 actually corresponds to the i*13-th beat; another essential explanation is that in the recursive calculation process of VDF, the state is changed by salti in an entropy-preserving manner. ​In summary, three issues need to be noted when constructing salt: 1. It must be easy to obtain salti; 2. The forward calculation delay of salti should be less than the calculation delay of VDF; 3. The reverse calculation delay of salti should be less than the calculation delay of VDF. -1 If salt is regarded as the block cipher key and the initial state is regarded as the plaintext, the VDF output at this time is equivalent to the block cipher ciphertext output. At this time, VDF(initial state, salt) is a block cipher with slow encryption and fast decryption, which exactly meets the requirements of the industrial copy-proof primitive. The inventors found that when the input-output space of S is very small, the gain contributed by F(A, B)=S(A⊕B) is very large but the anti-parallel acceleration ability is very weak. For example, it can be significantly accelerated by the "precomputation table acceleration technology" that can be explained by terms; on the contrary, when S directly constructs VDF, where S -1 is a sparse tap and the implementation of S reaches the minimum delay index. At this time, the VDF can be proven not to be parallel accelerated, but the gain contributed by this design is very small. The so-called sparse tap means that each output is only associated with 2 to 3 taps, but its inverse function is associated with all taps or basically all input taps for each output. The advantages of the sparse tap design are: 1. It has inherent gain; 2. The hardware implementation saves area particularly. The inventors particularly recommend the design where S reaches the minimum delay index, that is, the gate delay of each gate. Here, the implementation of looking up large tables is not included. At this time, the gate delay of S reaches the optimum; the optimal embodiment VDF32 is a typical structure of F(A, B)=S(A⊕B), and its S reaches the minimum delay index. From this, it is deduced that the gate delay gain of VDF32 reaches 34.6 (13*8 / 3). ☆4 In order to obtain a better trade-off index between anti-parallel acceleration and the total gain size; the construction method preferably recommended by the inventors is: the S component is of the structure F(A, B)=g(A⊕B), and g is defined -1 as a sparse tap design; the S component directly constructs the VDF for beacon-like applications or indirectly constructs the VDF for copy-proof applications through F(A0, Ab)=S(A0⊕Ab, △), where t is divisible by △*b. ☆5 Therefore, the construction scheme that takes into account the advantages of salt is: the S component is of the structure F(A, B)=g(A⊕B), and g is defined -1 as a sparse tap design; an input parameter salt is added, and salti changes the register corresponding to the S component in an entropy-preserving manner; the S component directly constructs the VDF or indirectly constructs the VDF through F(A0, Ab)=S(A0⊕Ab, △), where t is divisible by △*b. In order to interface with industrial random beacon applications and replica proof applications, three embodiments of VDF32, VDF8192, and VDF2M are designed more specifically. Among them, it is recommended that VDF32 interface with random beacon applications, and VDF8192 and VDF2M interface with replica proof applications. ☆6☆7 The comprehensive optimal embodiments VDF32, VDF8192, and VDF2M all have the structure of F(A, B)= S(A⊕B); more specifically, VDF8192 and VDF2M have the structure of F(A, B)= S(A⊕B, △). It is recommended that VDF32 interface with random beacon primitives, and it is recommended that VDF8192 and VDF2M interface with replica proof primitives. The design index of VDF32 is 8clk for every 1 symbol update, and its corresponding VDF32 -1 circuit implementation is 3clk for every 13 symbols, so the design gain of VDF32 is 34.6 (13*8 / 3). VDF32 is a typical structure of F(A, B)=g(A⊕B), where g -1 is an optimized sparse tap design; in order to improve the anti-parallel ability of VDF, while slightly sacrificing the gain, let 3 adjacent A participate in the F(A, B) operation; so the state recurrence equation of VDF32 is VDF32({A15, A14, …, A0},1)={g(~(~A15&A14)&A13)⊕A0)⊕the recycled constant table, A14, …, A1}. Other parameters of VDF32 are also as follows: the block width is 32 bytes, the highest bit of A15 is XORed with salt[0] every 13 S operations, and salt is circularly shifted once every 16*13 beats. The above content will be described in detail in the specific implementation section in combination with the drawings. Regarding VDF32 as a one-way reversible function, VDF8192({A255, …, A0}) is defined accordingly, where A256 = VDF32(A0⊕A255, △, salt), so there is a 255-fold gain of VDF32, and the block width is 8192 bytes; regarding VDF8192 as a one-way reversible function, VDF2M({A255, …, A0}) is defined accordingly, A256 = VDF8192(A0⊕A255, △, salt), so there is a 255-fold gain of VDF8192, and the block width is 2 20 bytes. The detailed parameter descriptions of VDF32, VDF8192, and VDF2M are in the specific implementation chapter. In line with the 3rd item of the above parameter guidance. The inventor completed VDF32(, 13,) and VDF32 on EP3C25Q240 (an FPGA of Altera Corporation, belonging to the CycloneIII series) based on the state automaton model -16(, 13,) Hardware module synthesis and result verification. The fmax index synthesized by Quartus II Version 9.0 is that for VDF32(, 13,) it corresponds to 15.42 MHz, and for VDF32 -16 (, 13,) it corresponds to 27.23 MHz, and the calculated actual gain is 28.25; it basically matches the theoretical value of 34.6. Description of the Drawings Some specific embodiments of the present application will be described in detail hereinafter with reference to the drawings in an exemplary rather than restrictive manner. The same reference numerals in the drawings denote the same or similar components or parts. Those skilled in the art should understand that the drawings of the present invention essentially describe the connection relationship and timing control relationship of the circuit. In the drawings: FIG. 1 is a schematic diagram of the calculation stage and verification stage of a middle state of a necessary technical feature of the present invention; FIG. 2 is a schematic diagram of the calculation stage and verification stage of the structure F(A0, Ab)=S(A0⊕Ab, △) of a necessary technical feature of the present invention; FIG. 3 is a schematic diagram of the calculation stage of the VDF32 embodiment and clk analysis; Supplementary note, register update expression: {Ai, Ai-1, ……, Ai-15}<- {g((~(~Ai&Ai-1)&Ai-2)⊕Ai-15)⊕constant table i%13, Ai, ……, Ai-14}; FIG. 4 is a schematic diagram of the verification stage of the VDF32 embodiment and clk analysis; Supplementary note, register update expression: {Ai, Ai-1, ……, Ai-15}<- {Ai-13, Ai-14, Ai-15, Ai-16……, Ai-28}; FIG. 5 is the g of VDF32 -1 and the hardware wiring diagram of g; FIG. 6 is the circuit schematic diagram and delay analysis of VDF8192 and VDF8192 -1 ; FIG. 7 is the hardware construction drawing of VDF8192; FIG. 8 is the hardware construction drawing of VDF8192 -1 ; FIG. 9 is the hardware structure diagram of the serial port chip of the VDF8192 embodiment and / or VDF8192 -1 ; FIG. 10 is the instruction set of the serial port chip of the embodiment; FIG. 11 is a derivative structure example of two F(A, B) structures; Figure 12 is a schematic diagram of two-stage pre-table acceleration for A17 = S(A16 ⊕ A0); Figure 13 is 2 61 An embodiment of the discrete logarithm F(A, Ai-3) structure in the domain; Figure 14 is a schematic diagram of the structure of a blockchain system with a VDF clock function for Bitcoin timekeeping in an embodiment; Figure 15 is a schematic diagram of the industrial ecosystem related to the present invention. Embodiments of the present invention In order to enable those skilled in the art to better understand the present disclosure solution, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present disclosure. To understand the content of this specification faster and better, the following reading guide is given. It is recommended that readers first refer to Figures 3, 4, and 6, and give priority to reading the content related to the circuits, design principles, and design gain calculations based on recursive expressions in Embodiments VDF32, VDF8192, and VDF2M. On the basis of the above reading, for an important route for engineering implementation, Figures 7, 8, 9, and 10 should be referred to again to read the hardware implementation details and implementation effects of VDF32, VDF32 -1 VDF8192, VDF8192 -1 . On the basis of the above reading, for another important route regarding the interpretation of how to design VDF in a larger protection scope, especially the interpretation of the F(A, B) structure, the explanations of the necessary technical features and the statements and summary refinements of various one-way reversible components should be referred to again in Figures 1, 2, 11, and 13. To state the inventive concept and technical solution, the following terms are defined first: 1. One-way reversible function S A necessary technical feature of the present invention, this component directly or indirectly constructs a VDF, and its one-way definition is a reversible function with slow forward calculation and fast reverse calculation. The key point of construction is that the time delay of the critical path of S should be significantly greater than the time delay of the critical path of S -1 The time delay of the critical path, and the time delay of the critical path already includes the achievements of circuit-level parallel optimization and the achievements of circuit wiring engineers. The gain of S refers to the calculation time of S divided by S -1For the calculation time, the gain of S is divided into theoretical evaluation, especially the gate delay evaluation index, and the gain obtained from the actual hardware circuit. The meaning of the four basic methods is to construct a VDF using one of the four components or a combination thereof. Many design references are given in Figure 13 and the detailed implementation. According to the definition of unidirectionality, other unidirectional function constructions are not excluded as long as they meet the three parameter guidelines in the invention content to construct a VDF. 2. a intermediate state technology One of the essential technical features of the present invention. For the principle and effect of serial calculation and parallel verification, refer to Figure 1. Figure 1 can prove that the calculation stage corresponds to (a + 1) serial tasks of the VDF type, and the verification stage corresponds to (a + 1) VDF -1 type parallel tasks. The principle is a method to increase the verification speed by increasing data complexity and hardware cost. The main feature is that during the VDF calculation process, a intermediate states are used as evidence according to the principle of uniform division. During the verification stage, (a + 1) VDF -1 verification tasks are simultaneously and parallelly opened for fast verification. The technical effect is that the (a + 1) times hardware cost and (a + 1) times data cost are increased to (a + 1) times the verification speed, that is, the gain is increased to (a + 1) times. a being 0 means that the intermediate state technology is not used. It should be noted that the situation described in Figure 1 is when t is exactly divisible by (a + 1). For the case where t is not divisible by (a + 1), refer to Figure 1 and execute according to the principle of uniform division. 3. F(A, B) structure A special case of the F(A, B) structure, F(A0, Ab)=S(A0⊕Ab, △), is one of the essential technical features of the present invention. For the design principle and effect of F(A0, Ab)=S(A0⊕Ab, △), refer to Figure 2. Figure 2 can prove that for every △*b beats of calculation, the calculation stage is equivalent to a cascaded structure S logic serial circuit with a depth of b and a width of 1, and the verification stage is equivalent to a parallel structure S -1 logic parallel circuit with a depth of 1 and a width of b. For a more specific performance analysis, for the VDF, that is, the forward logic, every time b symbols are updated, it consumes b S(△) delays. For the VDF -1 that is, the reverse logic, every time b symbols are updated, it only consumes 1 S -1 (△) delay. For a more specific embodiment, Figure 6 gives the circuit implementation and delay of the VDF8192 module and the VDF8192 -1 module; the VDF8192 circuit is essentially a state automaton based on a VDF32 module. Every time 1 △ unit operation is completed, it updates 1 symbol with a length of 32 bytes and consumes 1 VDF32(, △,) delay; the VDF8192 -1 circuit is essentially based on 255 VDF32 -1The state automaton of the module updates every 255 △ unit operations. Consuming 1 VDF32 for every 255 symbols with a length of 32 bytes -1 (, △,) latency. State the benefits of increasing △, which increases the computational granularity. Increasing △ will make the core hardware code focus on the S(△) operation. The wire delay consumption within the range {A0, …, Ab} can be theoretically ignored; more importantly, if S corresponds to a standard similar to VDF32, then the industrial standard module defined by F(A0, Ab)=S(A0⊕Ab, △) directly supports S(△) and multiple S -1 (△) operations. The structural effect of F(A, B) is that the design gain of Ai+1 = F(Ai, Ai-N-1)=S(Ai) ⊕Ai-N-1 is N-1 times, and the design gain of Ai+1 = S(Ai⊕Ai-N-1) is (N-1)*Gain times, where Gain is the ratio of the calculation delay of S to the calculation delay of S -1 The larger the interval between the latest symbol and the smallest symbol, the better. The concept of F(A, B) includes but is not limited to changing the ⊕ operator to the + operator. To improve resistance to precomputation acceleration, in addition to Ai, symbols such as Ai-1 and Ai-2 also participate in the operation. The F(A, B) structure can either independently construct a one-way reversible function S and then directly construct a VDF, or construct a VDF with a larger input / output byte based on a VDF with a smaller input / output. The structure should not be limited to a single recursion Ai+1 = F(Ai, Ai-N-1)=S(Ai) ⊕Ai-N-1 or Ai+1 = F(Ai, Ai-N-1)=S(Ai⊕Ai-N-1), where B is the earliest symbol. More design guidelines will be given in conjunction with Figure 11 in the specific implementation part. All these design results and guidelines are equivalent implementation methods based on the design idea of the F(A, B) structure. Finally, two discrimination criteria for the F(A, B) structure are specifically proposed: 1. The new symbol is equal to the output of the non-linear function that combines some of the latest symbols and some of the earliest symbols; 2. The time delay of the critical path of the reviewed VDF should be significantly greater than the time delay of the critical path of the VDF -1 For better understanding of the significance of the two discrimination criteria as the final judgment criteria, first give a counterexample that does not meet the second criterion of the proposed standard. Define Ai+1=F(Ai, B)=S(B) ⊕Ai. It is easy to verify that the gate delay of the forward logic critical path is greater than the gate delay index of the reverse logic critical path. Therefore, Ai+1=F(Ai, B)=S(B) ⊕Ai cannot be used as a VDF design. 4. Sparse taps A design of a preferred one-way reversible function. Since the design gain is relatively small, the inventor does not recommend directly constructing a VDF; it is preferred to construct a VDF with better gain indicators in combination with the structure of F(A0, Ab)=S(A0⊕Ab), where S -1 is a sparse tap design. It is defined that the output taps are only associated with 2 to 3 input taps, but the output of the inverse transformation is associated with all or substantially all input taps. The sparse taps have two advantages: 1. They inherently have gate delay and wire delay gains, where the gate delay is not less than log2 of the number of taps; 2. The sparse design is friendly to both hardware implementation and software implementation. When the number of taps is small, it can be screened by a computer, and the basic criterion for screening is that the inverse function conforms to the basic definition; the preferred methods and results are stated in the specific implementation manners. 5. Gate delay To evaluate the gate delay of the critical path at the theoretical level, it is specifically stipulated that the gate delays of binary operation gates such as AND, OR, ANDN (i.e., ~AND), XOR, XNOR, etc. are 1 clk, and the gate delay of a multi-input AND gate is 1 clk. By analyzing the VDF and VDF -1 critical path, the total number of clk can be deduced, and then the theoretical gain based on the gate delay can be deduced. For the actual VDF and VDF -1 The critical path of the hardware circuit includes not only the gate delay but also the wire delay. Of course, the actual gains of physical ASICs and FPGAs need to be actually tested or evaluated by a circuit synthesizer, and their gate delay parameters are necessarily related to the hardware technology library. Given the current fastest transistor characteristic frequency, the theoretical safety threshold of 1-cycle VDF can be deduced from the total number of clk of the VDF critical path. Therefore, the gate delay parameters correspond to the parameter evaluation of the digital space and also to the evaluation of the physical hardware parameters. 6. Creating a pre-table for acceleration A technology solution for trading area for speed in the forward logic of the F(A, B) structure, which defines AN+1 = S(AN⊕A0). To quickly calculate A2N, it is divided into two segments for parallel calculation. For the specific principle and effect, refer to Figure 12. It is defined that A17 = S(A16⊕A0), where the input and output of S are 8 bits. To solve the problem of quickly obtaining the symbol A32 from {A16,..., A0}. The calculation path from A17 to A23 is the first segment, and the calculation path from A23 to A32 is the second segment. Since there are 256 possible values for A23, then 256 calculation paths can be simultaneously started in parallel for the second segment path and the first segment path to create a pre-table for acceleration; after A23 is calculated, A32 is just calculated. Just select the correct A32 according to the calculation result of A23. The more segments there are, the smaller the symbol space, and the better the effect of creating a pre-table for acceleration. The inventor also proposed a method to resist this technology, which is to let more of the latest symbols participate in the operation. For example, the design concept of VDF32 is to let 3 of the latest symbols participate in the VDF operation. Although the theoretical gain is reduced from 15 times to 13 times, the ability to resist pre-table acceleration is increased to the space covered by 3 symbols, that is, 2 48 of the space (2 16 *2 16 *2 16 ). "Creating a pre-table for acceleration" is a parallel acceleration technology invented by the inventor with reference to the principle of carry look-ahead in fixed-point addition for possible defects in the F(A, B) structure. The inventor's view is that although VDF is formally defined as a function that is not easily parallel-accelerated, it cannot be asserted that a given VDF cannot be parallel-accelerated by parallel technology. Scientists in the field of parallel algorithms and engineers in the field of hardware wiring have a natural preference for scientific research on parallel acceleration and parallel optimization, and there have been a large number of scientific research results. Therefore, the wisdom of scientists and engineers cannot be underestimated. Therefore, the inventor cannot rule out more and better parallel optimization results for the F(A, B) structure. Finally, the inventor believes that the nominal design index of 8 clk for each symbol in the VDF32 standard still needs to be tested by time. Comprehensive optimal embodiment: VDF32({A15, A14,..., A0}, t, salt), This embodiment is related to Figure 3. Figure 3 is essentially a schematic diagram of the calculation stage of VDF32 defined according to the recursive relationship of VDF32(, 1,). The description of the number of symbols, symbol width, recursive equation of the circuit, and the movement and control relationship of salt is as follows. VDF32 is a VDF directly constructed by S components, and its parameter definitions are as follows: salt is 128 bits or 256 bits; 1) t is equal to 128 * 16 * 13 * k, where k is a natural number; 2) {A15, A14,..., A0}, each symbol is 16 bits; 3) VDF32({A15, A14, …, A0}, 1) = {g(~(~A15 & A14) & A13) ⊕ A0) ⊕ the recycled constant table, A15, …, A1}, 4) g -1 The Verilog code of (i) is {( {i[3:0], i[14:4]} & {~i[7:0], ~i[14:8]} ) ^ i[14:0], i

[0015] }; 5) The salt parameter is: the highest bit of the 256-bit register is XORed with salt[0] every 13 symbols updated, and salt is left-circularly shifted once every 16 * 13 symbols; The final output of VDF32: {A15+t, A14+t, …, At}. The above is the VDF32 serial circuit defined by the recursive relationship. The theoretical gain is that there is no wire delay and the overhead of updating the register. The above VDF32-related parameters essentially describe the VDF serial circuit and the parallel circuit of 13 g logics corresponding to VDF -1 Just like the Verilog code describes a physical hardware, the essential content of the defined physical hardware is the control relationship of the module and the update logic of the register driven by the clock. The numbering order of the modules is generally set in a way that is convenient for reading. In addition, it is possible to directly implement the executable hardware logic based on VDF32(, 1,) according to the above parameters, but it is not recommended in terms of execution speed; to implement VDF32 faster, it is recommended to use the state automaton code based on VDF(, 13,). In short, the numbering of the above-described VDF32 parameters is only for convenient reading and there is no execution order restriction. The relationship between the parameters of VDF32 and the fast hardware code and physical hardware logic of the entity is a guiding relationship and a defining relationship, not a simple correspondence relationship. Referring to the clk path analysis in Figures 3 and 4, the gate delay ratio of VDF and VDF -1 is 8 / 3, and the parallel provides a 13-fold gain. Therefore, the total design gain of VDF32 is 34.67 (13 * 8 / 3). It should be noted that from the "hardware wiring diagram of g -1 and g" in Figure 5, it is deduced that the implementation of the g logic using the binary tree architecture consumes 5 clk (4 + 1), and g consumes 2 clk. Therefore, the calculation path of VDF32 -1 is {Ai+1, Ai, Ai-1, Ai-2} to Ai-15, that is, Ai-15 = g -1 (Ai+1) ⊕ (~(~Ai & Ai-1) & Ai-2); g -1 consumes 2 gate delays, so the closed-loop path of VDF32 -1 is 3 gate delays. The latest symbol has 3 participating in the operation, so the index for resisting pre-table acceleration is 2 48 。The design of 3 symbols also contributes 2 clk to the VDF calculation stage. When calculating VDF -1 stage, the 2 clk related to 3 symbols and the calculation of g -1 consume 2 clk because the circuit-level parallel merging effect is 2 clk. The above conclusions can be referred to in Figure 3 and Figure 4 of the attached drawings. For password security, a 13-cycle reusable constant table shown in Figure 3 is designed. The effect is equivalent to the round constant tables of block cipher algorithms and hash algorithms. The purpose of this design is to make the VDF expression more complex and irregular. The evaluation of the circuit implementation is that the constant table does not increase the hardware overhead and clk consumption. State the Salt design concept of VDF32: VDF32 -1 's core circuit is 13 juxtaposed Ai-15 = g(Ai+1) ⊕ (~(~Ai&Ai-1)&Ai-2) calculation logics, where the subscript i is adjacent. So whether it is implemented by a multi-core processor or hardware wiring, VDF32 -1 is fast and economical, in order to keep the speed of hardware and software. It is stipulated that every 13 beats, salt[0] modifies the highest bit of the register in the ⊕ manner once, and every 13*16 beats, salt is cyclically shifted once. The reason why salt adopts simple cyclic shift instead of complex linear recursion with a larger period is to dock and hide the calculation task during standard industrialization. The inventor preferably recommends using state machine technology to implement the serial circuit corresponding to the calculation stage and the parallel circuit corresponding to the verification stage. The state machine is divided into a register bank module, a combinational logic module for VDF or VDF -1 calculation, a counter and a control circuit associated with t; among them, the register bank is related to the initial state, intermediate state, and result. Figures 3 and 4 of the attached drawings are only schematic diagrams explaining the recursive relationship. The schematic diagrams are used to evaluate the clk consumed by updating symbols, and the schematic diagrams cannot reflect the actual wire delay consumption and register update consumption; more specifically, Figure 3 corresponds to the VDF32(,1,) combinational logic, and Figure 4 corresponds to VDF32 -1 (,13,) combinational logic. Therefore, the combinational logic module in the specific implementation must have a large enough calculation granularity. The inventor coded and tested the state machine code based on VDF32 -8 (,13,), VDF32 -16 (,13,) and VDF(,13,). Here, the VDF -8 module is a cascade of 8 VDF -1 hardware logics. On the EP3C25Q240 hardware, the maximum working clock of the automatic state machine actually synthesized by Quartus II Version 9.0 is as follows; VDF32 (, 13, ), 15.42 MHz; VDF32 2 (, 13, ), 7.08 MHz; VDF32 -1 (, 13, ), 130.65 Mhz; VDF32 -8 (, 13, ), 45.37 Mhz; VDF32 -16 (, 13, ), 27.23 MHz. The above fmax results can prove that increasing the computational granularity of combinational logic is more conducive to the hardware synthesizer generating higher-quality code. The engineering explanation of the above implementation principle is that the pipeline is one of the most commonly used technologies in hardware implementation. Increasing the pipeline registers to cut combinational logic can improve the main frequency and throughput, but the minimum computational latency index deteriorates. However, the main idea of the implementation method of the present invention is the opposite. For more specific operations, in order to optimize the computational latency index, a technical method of reducing pipeline registers and aggregating larger combinational logic is adopted, and the effect is to reduce the main frequency but optimize the minimum computational latency index. For the serial circuit and parallel circuit corresponding to the present invention, there is no wire delay and the overhead of updating registers in its theoretical design and performance discussion, but in actual circuit wiring, there indeed exists such a situation. The larger the computational granularity of combinational logic, the smaller the actual synthesized wire delay and the performance index of updating register delay. Of course, when the computational granularity is large to a certain extent, the marginal effect of implementation will occur, that is, increasing the computational granularity contributes little or no contribution to the improvement of computational speed. For example, the above parameters of 15.42 MHz and 7.08 MHz can prove this. Although the above synthesis results and the analysis of the results come from the fmax index of the synthesizer of Altera Corporation, it is also basically applicable to other models of fpga and ASIC circuit synthesizers. Because the basic principle of all synthesizers is to simplify circuit logic and optimize wiring according to the device library parameters, increasing the computational granularity of combinational logic is beneficial to both the clock index and the improvement of actual computational speed. In short, as long as the computational granularity of combinational logic is large enough, the gain index of the hardware circuit implementation should be basically consistent with the theoretical design gain, that is, the third item in the parameter guidance holds. The working principle of the state automaton of the closed loop is described below taking VDF32 (initial state, t, salt) as an example; Step 1) Register group <- initial state, cnt <- t / 13; Step 2) Register group <- VDF32(register group, 13, salt); cnt = cnt - 1; Step 3) If cnt is not 0, continue with Step 2). Step 4) Halt and output the register set (i.e., VDF(initial state, t)). In addition, the inventor wrote VDF32 using Intel's AVX2 instructions -1 for the (, 13, 0) module code, and the core code has 30 AVX2 instructions. On a single core of an i7-4770 with a turbo frequency of 3.9G, it takes 5.273 seconds to complete 10 9 VDF32 -1 (, 13, 0) calculations; From this, it can be inferred that 30 instructions actually consume 22.56 clks of the CPU with the contribution of instruction pairing, and 1.90X10 8 VDFs per second -1 . This result shows that multi-core CPUs, especially those with multimedia instructions, can well support multiple VDF32 -1 operations; It can also prove that VDF32 -1 design performs excellently on various platforms. Compared with the VDF32 implemented based on a state automaton -16 with an index of 27.23Mhz, it can be considered that the medium and low-speed EP3C25Q240 (FPGA model) performs better than general high-performance processors. Comprehensive optimal embodiment: VDF8192({A255, A254,..., A0}, t, salt), with the parameters defined as follows: 1) t is equal to △ * 255 * k, where k is a relatively small natural number; 2) Input 8192 bytes, which are divided into 256 symbols from A255 to A0, with each symbol being 32 bytes; 3) VDF8192({A255, A254,..., A0}, △, salt) = {VDF32(A255 ⊕ A0, △, salt), A255,..., A1}. Output: {A255 * k + 255, A255 * k + 254,..., A255 * k}. Comprehensive optimal embodiment: VDF2M({A255, A254,..., A0}, t, salt), with the parameters defined as follows: 1) t is equal to △ * 255 * 255 * k; k is a relatively small natural number; 2) Input 2 21 bytes, which are divided into 256 symbols from A255 to A0, with each symbol being 8192 bytes; 3) VDF2M({A255,..., A0}, △ * 255, salt) = {VDF8192(A255 ⊕ A0, △ * 255, salt), A255,..., A1}. Output: {A255 + 255*k, A254 + 255*k, …, A255*k} The above are the VDF8192 and VDF2M serial circuits defined by the parameters of the recursive relationship. The theoretical gain is that there is no wire delay and the overhead of updating registers. The above parameters essentially describe the VDF and VDF -1 The corresponding circuits, and their numbers are only for convenient reading and there is no restriction on the execution order VDF8192(, 255*△, ) and VDF8192 -1 The corresponding circuit of (, 255*△, ) should refer to Figure 2. Among them, VDF8192(, 255*△, ) corresponds to a serial circuit with a cascade structure of depth 255 and width 1, and the serial unit is VDF32(, △, ); among them, VDF8192 -1 (, 255*△, ) corresponds to a parallel circuit with a width of 255 and a depth of 1, and the parallel units are VDF32 -1 (, △, ). So the theoretical gain of VDF8192 is 255 times that of VDF32, that is, 255*34.6. It should be noted that VDF32(, △, ) and VDF32 -1 (, △, ) respectively correspond to the serial circuit and the parallel circuit from the perspective of the inventive concept, and correspond to the above-mentioned calculation circuit based on the state automaton model in the specific industrial implementation VDF8192 and VDF8192 -1 The hardware implementation principle and effect of should refer to Figure 6. First, state the forward logic. The upper circuit VDF8192(, △, ) in Figure 6 can achieve the result of the VDF8192(, 255*△, ) combinational circuit by moving 255 symbols. The overall structure of the upper circuit VDF8192(, △, ) in Figure 6 is an automaton of 256 symbols, and the update of the symbols nests a VDF32 timing calculation circuit. More specifically, the S(△) logic unit in Figure 2 corresponds to VDF32(A255⊕A0, △, salt) in the upper part of Figure 6, and the hardware implementation of the specific automaton model of VDF32(A255⊕A0, △, salt) in Figure 6 corresponds to VDF32(st

[0255] , 13, salt[0]) in Figure 7. It has been stated before that the actual synthesis effect on a certain FPGA in Figure 7 is that fmax is 15.42MHz. Then state the reverse logic. The lower circuit VDF8192 in Figure 6 -1 is actually a parallel circuit with a width of 255, and each parallel unit is VDF32 -1 (, △, salt). More specifically, 255 (here b is defined as 255) Ss in Figure 2 -1(△) The logic unit corresponds to 255 VDF32s in the lower figure of Figure 6 -1 (, △, salt), 255 VDF32s in Figure 6 -1 The hardware implementation of the specific automaton model of (, △, salt) corresponds to 255 VDF32s in Figure 8 -8 (st[i], 13, salt[0]), where i ranges from 1 to 255. The VDF32s in Figure 8 have been described previously -8 The actual synthesis effect of (, 13,) on a certain FPGA is fmax = 45.37Mhz. It should be noted that since the △ particles are generally set relatively large, theoretically, the ⊕ calculation delay overhead of the circuit VDF8192 in the lower figure of Figure 6 -1 can be ignored. To reduce the wiring overhead of hardware such as FPGA, it is recommended to implement the ⊕ operation outside the calculation chip. Therefore, Figure 8 does not include the 255 ⊕ operations in the lower figure of Figure 6. It should be pointed out that the b S(△) cascade structures in the upper figure of Figure 2 are only for the principle explanation of the present invention and the evaluation of the b S(△) delays. From the calculation path analysis from Ab to A2b - 1, it can be known that only one S(△) is active at each moment, and the inputs and outputs of the remaining S(△) do not change. Therefore, industrial implementations all refer to the implementation including one S(△) logic in the upper figure of Figure 6. More specifically, the calculation core of VDF8192 is one VDF32. Similarly, the calculation core of VDF2M is still one VDF32. If the VDF8192 module and VDF2M are implemented with multiple cores and multiple threads, it will be found that they can only work in the way of 1 physical core and 1 thread. If the VDF8192 -1 (, △ * 255,) and VDF2M -1 (, △ * 255 * 255,) will find that the calculation delay is basically equal to that of VDF32 -1 (, △,). VDF8192 -1 (, △ * 255,) The implementation method is to first start 255 physical cores and 255 threads simultaneously to implement 255 VDF32s without any communication -1 (, △,). After barrier synchronization, run the ⊕ logic in the lower figure of Figure 2. Since VDF2M -1 consists of 255 parallel VDF8192s -1 Therefore, VDF2M -1 (, △ * 255 * 255,) The implementation method is to first start 255 * 255 physical cores and 255 * 255 threads simultaneously to implement 255 * 255 VDF32s without any communication -1 (, △,). After barrier synchronization, follow the guidance in the lower figure of Figure 2 to do two - layer ⊕ logic. First, do VDF32-1 The associated ⊕ logical operation is performed, and then VDF8192 is carried out -1 The associated ⊕ logical operation. The above VDF8192 -1 and VDF2M -1 The statement of the multi-core and multi-thread implementation can prove that the inventive concept is the VDF serial calculation circuit VDF -1 The essence of the invention of the parallel calculation circuit. Through the above analysis and the fmax of FPGA synthesis, the calculation delay of VDF8192 (, 255*13*10 9 , ) and VDF8192 -1 (, 255*13*10 9 , ) is calculated, where △ is 13*10 9 . The delay of VDF8192 (, 255*13*10 9 , ): 255*13*10 9 / 13 / 15.42MHz = 16536.96 seconds; VDF8192 -1 (, 255*13*10 9 , ) delay: 255*13*10 9 / 8 / 255 / 13 / 45.37Mhz = 2.76 seconds. Therefore, the actual gain is 6002.3 (16536.96 / 2.76), which is basically consistent with the theoretical gain of 8823 (34.6*255). Because the fmax of VDF32 -16 (, 13, ) is 27.23Mhz, so, using VDF32 -16 module of VDF8192 -1 (, 255*13*10 9 , ) calculation delay: 255*13*10 9 / 16 / 255 / 13 / 27.23Mhz = 2.30 seconds; Therefore, the actual gain improvement is 7204.8 (16536.96 / 2.30), which also conforms to Article 3 of the parameter guide. The hardware implementation principles and effects of VDF8192 and VDF8192 -1 can be referred to in Figure 6. In order to solve the calculation requirements of VDF32 and multiple VDF32 -1 at the same time, based on the principle of hardware reuse, the inventor preferably recommends VDF8192 and VDF8192 -1 as the industrial hardware module standard, where VDF8192 contains 1 VDF32 calculation circuit, and VDF8192 -1 contains 255 parallel working VDF32-1 Computing circuit. It should be noted that when the a parameter corresponding to VDF32 is not greater than 254, the VDF8192 module directly supports the computing task of outputting a + 1 intermediate states for VDF32 (initial state, t), and VDF8192 -1 directly supports a + 1 VDF32s -1 verification subtasks; if a is greater than 254, only the pause output step needs to be added. The specific implementation of multiplexing is "cmd[0]? St[0]:0" in Figure 7, so the multiplexing design is simple and feasible. Figure 7 and Figure 8 are specific engineering construction drawings corresponding to Figure 6. The basic principle is a larger-scale state automaton constructed by VDF32(, 13,) and VDF32 -8 (, 13,). In order to allow the core module to overclock independently, the VDF8192 module corresponding to Figure 7 and the VDF8192 -1 module corresponding to Figure 8 are both independently clocked designs. The intermediate results are buffered by registers, and the logic of register iterative update is related to VDF32 or VDF32 -1 . One implementation method of independent clock is to associate 1 bit for synchronizing bits and a cmd backup register for the read and write of cmd, and the read and write control timing refers to the SPI asynchronous bus. The inventor completed the entity implementation of the available VDF8192 module using Verilog language according to the guidance of Figure 7, and completed the entity implementation of the available VDF8192 -1 module using Verilog language according to the guidance of Figure 8. The VDF8192 module corresponding to Figure 7 can complete the calculation results of 255 symbols in the upper part of Figure 6, and minor adjustments are required for actual calls and result utilization; the VDF8192 -1 module corresponding to Figure 8 essentially completes 255 VDF32(, △,) excluding ⊕ in the lower part of Figure 6 -1 operation logic, and adjustments for the lack of 255 ⊕ are required during actual calls. First, through Modelsim SE simulation testing, the inventor designed and debugged a serial communication and control module. This serial module can initialize the initial state function, control operation, control pause, and output calculation results through the serial port by combining a custom instruction set (see Figure 10 in detail) for the VDF8192 and VDF8192 -1 modules. The inventor integrated the serial communication and control module, VDF8192 module, and VDF8192 -1 module on the FPGA. By connecting the FPGA through the computer serial port, the hardware test results are completely consistent with the simulation results, thus proving that the VDF8192 module and VDF8192 -1 module can be engineered and standardized. VDF2M and VDF2M -1 The hardware circuit and delay index of the VDF32 module can be implemented and evaluated by referring to FIG6. -1 Module replaced with VDF8192 and VDF8192 -1 That’s it. VDF2M is actually composed of a VDF8192 and 255 8192-byte registers. The logic of register update is VDF2M ({A255, A254, A0}, △, salt) = {VDF8192 (A255⊕A0, △, salt), A255, …, A1}. VDF2M -1 The core logic is 255 parallel VDF8192 -1 Hardware logic. It should be noted that when k related to VDF8192 and VDF2M is equal to 1, the unencrypted information needs to be patched, and 1 / 256 symbols are not encoded; a reference scheme is to first add the latest code modulo 2 to the uncoded area, and then encrypt it in EBC mode according to VDF32 (, 128*13*16*2, salt). The following is a detailed description of a specific project implementation. The solid boxes in Figures 7 and 8 represent the actual register group and the actual combinational logic module of the automatic state machine, and the dotted boxes represent the instructions for controlling the movement of the state machine. The basic structure is: {cmd, ping-pong bit, pause bit, k <k_end ,t< t_end}控制的状态机,闭环计算电路是模块的核心。附图7是VDF8192的硬件施工图,主体结构是st

[0255] <-VDF32(st

[0255] ,13,salt[0])构成的闭环计算电路。附图8:是VDF8192 -1 Hardware construction drawing, the main structure is 255 st[i]<-VDF32 -1 (st[i], 13*8, salt[0]), where i ranges from 1 to 255. VDF8192 is only associated with cmd=1. -1 Only associated with cmd=2. Input: {cmd[2:0],in256[255:0],fast_clk}, where fast_clk is an independent clock, cmd is asynchronous control, and in256 input is connected to salt and st

[0255] ; Main output: {oldest[255:0], newest[255:0], pause bit, t, k}; Module internal registers: pause bit, ping-pong bit, t, k; { St

[0255] ,…,St[1],St[0]}. The basic working principle of the module is: 1. Input parameters are put into the internal register stack through cmd and in256; 2. The closed-loop calculation circuit is started or paused through cmd; 3. The final result or intermediate result is output to the output terminal through cmd. As with the background VDF, it is encouraged to use the module through fast_clk overclocking. VDF8192 -1 The working steps of the module are basically the same as those of the VDF8192 module; the working steps of the VDF8192 module are as follows. 1. First set in256, cmd=4, set {k<-0, t<-0, k_end<-255, t_end<-△ / 13, salt<-initial state of salt}; 2. Perform 255 consecutive in256, cmd=6, cmd=5 operations to initialize the 255-block input of VDF8192 to {st

[0255] , …st[1]}; 3. cmd=7, open the closed-loop calculation circuit; 4. Determine whether the calculation task is completed: judgment standard k <k_end标志位,判断方法中断或定时查询技术; 5. Calculation end or breakpoint protection: Run cmd=6 and cmd=5 commands 255 times in a row, and the oldest terminal will output all the results of st; The above modules have standard functions such as task pause, breakpoint protection, and breakpoint restart, which can realize the migration of computing tasks between hardware modules. It should be noted that the VDF8192 corresponding to Figure 8 -1 The hardware module is a version with 255 ⊕ operations removed. The computing unit of FIG8 is 255 VDF32 -1 The hardware computing unit corresponds to cmd[2] in FIG10 . Because there are no 255 ⊕ operations, the register and combinational circuit overhead is saved, and the clock is synthesized to be faster during the evaluation phase. Because executing 255 ⊕ operations is an extremely low-frequency event, the operation of the low-frequency event has little effect on the total delay even if it is executed outside the chip, so removing the version with 255 ⊕ operations does not affect industrial applications. Corresponding to cmd[3] in Figure 10, the complete VDF8192 -1 The hardware module also requires {BakSt

[0255] , …, BakSt[0]} and 255 ⊕ operators, where {BakSt

[0255] , …, BakSt[0]} is 256 32-byte registers; According to the instructions in Figure 2, the control relationship is added as follows: At t == 0: Execute {Bakst

[0255] , …, Bakst[0]} <- {St

[0255] , …, St[0]} When t >= t_end: Execute {St

[0255] , …, St[0]} <- {BakSt[0], St

[0255] ^ BakSt

[0254] , …, St[1] ^ BakSt[0]}. To better understand the invocation and calculation process of the hardware module corresponding to Figure 7, an example is given to describe the actual invocation process of VDF8192({256, 255, …, 2, 1}, 255 * 13 * 10 9 , salt), where △ is 13 * 10 9 . First, the computer sends the initial state and relevant control commands to the rx pin corresponding to EP3C25Q240 through the serial port. The serial port decoding module inside EP3C25Q240 will extract the data and control commands, and these data and control commands will be connected to the VDF8192 module inside EP3C25Q240. The VDF8192 module will perform the operations in the following 4 steps. Step 1: Instruction sequence related to cmd = 4: Initialize {k <- 0, t <- 0, k_end <- 255, t_end <- △ / 13}; Step 2: Instruction sequence related to cmd = 5. Initialize 255 st sequences through right shift instructions, and finally fill the results as follows; {st

[0255] , st

[0254] , …, st[0]} <= {256, 255, …, 2, 1}; Step 3: First cmd = 7, then execute cmd = 1 to start the VDF operation mode. According to the state changes of t and k, the changes of {t, k, st} are tracked in detail below, and the detailed working process of the state machine is described accordingly. t k {st

[0255] , st

[0254] , …, st[1], st[0]}: 0 0 {256 ⊕ 1, 256, …, 3, 2} 1 to △ / 13 0 {VDF32((256 ⊕ 1), t), 256, …, 2}, where A256 = VDF32((256 ⊕ 1), △ / 13) 0 1 {(A256 ⊕ 2), A256, …, 3} 1 to △ / 13 1 {VDF32((A256 ⊕ 2), t), A256, …, 3}, where A257 = VDF32((A256 ⊕ 2), △ / 13) …… 0 254 {(A509 ⊕ 255), A509, …, A256, 256} 1 to △ / 13 254 {VDF32((A509 ⊕ 255), t), A509, …, A256, 256}, where A510 = VDF32((A509 ⊕ 255), △ / 13) So, the result of {st

[0255] , …, st[0]} is {A510, A509, …, A256, 256}. 0 255 At this time, k >= k_end, so stop the operation and stop updating {t, k, st[*]}. Here, the time consumption of step 3 is estimated. The main frequency of 15.42MHz corresponds to 16536.96 seconds; Step 4: Detect that k >= k_end, the VDF calculation ends. Through cmd = 7, then execute 255 loops of cmd = 5. Through the Oldest hardware connection in Figure 7, output {A510, A509, …, A256, 256} of the register bank. Finally, the serial port receiver on the computer side outputs through the serial port tx in Figure 9, receives and decodes {A510, …, A256, 256}. The above results have been verified by the physical hardware, which can prove that the VDF8192 hardware logic in Figure 7 can be implemented on the FPGA. The above 4 steps are implemented through the cmd register of the hardware module when calling the VDF8192 hardware logic in Figure 7. A test call platform includes three hardware components: a computer installed with a general serial port debugging software, a USB serial port communication cable, and an EP3C25Q240 with the program downloaded. Among them, the EP3C25Q240 is connected to the computer through the serial port communication cable. The hardware program module of the EP3C25Q240 corresponds to the implementation in Figure 9, and 1 complete VDF8192 hardware module is called by the overall logic in Figure 9. The test call method of the general serial port debugging software is to send serial port instructions to the EP3C25Q240 hardware through the serial port debugging software window. The return of the EP3C25Q240 can be directly displayed in the serial port debugging software window. The definition of the serial port instruction set directly refers to Figure 10. After the serial port instruction set is received by the EP3C25Q240 corresponding to the module in Figure 9 and decoded, some operation codes and address codes control the cmd control register of the VDF8192. Integrated VDF8192 hardware module and / or VDF8192 -1 Serial port chip of the hardware module Chip pins: {rx, tx, clk_uart, fast_clk_fwd and / or fast_clk_inv}; internal chip structure: serial port decoder, instruction set decoding and execution, 256bit input register, page number address register, several VDF or VDF -1 Modules, output registers and multi-byte serial port transmission components. For more specific implementation, refer to Figure 9. There are several VDF8192 or VDF8192 in the middle area inside the chip -1 Modules, each module is assigned an address denoted as id, the VDF8192 module is associated with fast_clk_fwd, VDF8192 -1 is associated with fast_clk_inv. The rx signal passes through the serial port decoder and the instruction decoding and execution module to implement data input, start or pause logic for the specified id module. In the pause state, the output is {oldest[255:0], newest[255:0], pause bit, t, k, …}; the output function is implemented by the multi-byte automatic encoder and the serial port encoding component. Figure 10 shows the instruction set: The instructions are mainly divided into 4 categories. 1. Extract 7-bit data and update it to the input register. 2. Asynchronously write to the cmd[id] register. 3. The output of the id module is output to tx through serial port encoding, and other instructions such as updating the id page number bit of the input register. 4. Other instructions. See the serial port instruction set table for details. Technical effects of the serial port chip, especially the standardized chip: 1) The concept of hierarchical structure, with the software call layer and the hardware implementation layer independent. 2) The number of chip pins is very small, which is very friendly to chip packaging and the manufacturing of electronic devices. 3) Only need to adjust the Clk_uart clock, and the chip can be called as a medium and low-speed peripheral, and the chip can also be called as a high-speed chip. 4) Support multi-chip parallel connection. Parallel connection methods: 1. All pins are connected in parallel. 2. The addresses of the modules in each chip do not conflict. The effect of parallel connection is beneficial to the standardization of chip use and the yield of chips. The inventor implemented the VDF8192 module and VDF8192 in verilog according to the above statements and the references in Figure 7 and Figure 8 -1The module is first simulated and tested using Modelsim SE software, and then verified and evaluated for clk metrics on the FPGA. The engineering implementation and verification results are as follows: The serial port chip corresponding to Figure 9 is synthesized and verified using the FPGA device EP3C25Q240. The serial port chip contains 3 logic modules, namely, the serial port synthesis module, VDF, and VDF -1 , and 3 independent clocks. Among them, one VDF8192 (core logic VDF32(, 13, salt[0]) module) consumes 2525 cells, and fmax = 15.42 Mhz; another VDF8192 (core logic VDF32(, 13*2, salt[0]) module) consumes 4554 cells, and fmax = 7.08 Mhz; the register groups {St

[0254] , …, St[0]} of the two VDF8192s are automatically synthesized into the internal RAM of the FPGA for implementation. In addition, one of the VDF8192s -1 (core logic 4 VDF32s -8 (, 13, salt[0]) module) consumes 13735 cells, and fmax = 45.37 M. One set of serial port decoding, execution, encoder, and serial port decoding modules consumes 1464 cells, and fmax = 134.0 Mhz. The following is the main structure of the serial port chip refined according to Figure 9 and the above statements. Referring to the regional dividing lines in Figure 9, the chip internally includes the following 2 calculation modules and 2 components; the 2 calculation modules are respectively the VDF8192 calculation module based on the state automaton and the VDF8192 -1 calculation module based on the state automaton; referring to Figure 9, the 2 components are respectively the serial port decoding and instruction decoding execution component and the multi-functional automatic encoding and output component; according to the signal control flow direction, the decomposition structure of the serial port decoding and instruction decoding execution component is, in sequence, the serial port decoding sub-module connected to the rx pin, the instruction decoding and execution sub-module, and the 256bit input register sub-module; according to the signal control flow direction, the decomposition structure of the multi-functional automatic encoding and output component is, in sequence, the output buffer register sub-module, the multi-byte automatic encoder sub-module, and the serial port encoding output sub-module connected to the tx pin; the mutual control relationship between the modules and components refers to the statements in the invention content section. The VDF8192 module standard and the VDF8192 -1 module standard in the above embodiments can be generalized to the general sense of VDF and VDF -1 modules. The serial port chip integrating VDF8192 and / or VDF8192 -1 can prove multiple VDFs or VDFs in the general sense -1The module can be integrated into the internal of the serial control chip. Additionally, through asynchronous communication techniques, VDF and VDF -1 Cross-clock design is completely feasible. The inventor believes that the standardized VDF8192 and / or VDF8192 -1 In addition to being controlled and called by the serial port logic, the VDF8192 and / or VDF8192 -1 module can also be called by a general-purpose processor as a standard coprocessor component; the main idea is that the input, output, and cmd register settings of the VDF8192 and / or VDF8192 -1 module are implemented by the general-purpose processor, and the addresses of the coprocessing correspond to different VDF8192 and / or VDF8192 -1 entities. A blockchain system with a VDF clock function for Bitcoin timing in an embodiment Referring to Figure 14, the structure of the blockchain system is defined as follows: The 128-byte block header includes: the hash of the previous block, the Merkel tree, the evidence of consensus, the blockchain timestamp, the time parameter t, the latest timing data, X; 2. Block hash = VDF32(VDF32(VDF32(VDF32(X, salt1, △), salt2, △), salt3, △), salt4, △); where {salt1, salt2, salt3, salt4} is the block header excluding X, and △ is 256 * 13 * 16; 3. X = VDF(previous block, timing data, t), where the timing data is the Bitcoin block hash. The main structure of this embodiment is that the new block hash is equal to VDF32(VDF32(previous block hash, t, Bitcoin authorization information), a smaller △, information of the new block header); this structure can prove two effects, 1. Constructing a new block associates VDF32(previous block hash, t); 2. Associating the Bitcoin timing information through the salt input to VDF32(, t, ). The inventor believes that the VDF(previous block information, t, trusted timing information) of the present invention can empower the blockchain system in the digital world with a trusted time measurement. The trusted timing information is equivalent to GPS or Beidou timing in the real world, and VDF(, t, ) is equivalent to a clock in the real world. Generally, the block hash of a blockchain is defined as hash(block header), but the feature of this embodiment is to directly construct the block hash using VDF32(, salt, △). Obviously, there is no need to define other cryptographic hashes. To achieve the above two effects that are basically the same as this embodiment, the method of defining the association should not be limited to this embodiment. For example, VDF(previous block hash, t, the timing information of Bitcoin) can be used as one item of the new block header or one item of the new blockchain record. The g of VDF32 -1 The design process and the selection criteria for sparse taps g -1 (i) is a typical sparse tap component with an input-output width of 16 bits, and its Verilog code is {( {i[3:0],i[14:4]} &{~i[7:0],~i[14:8]} )^i[14:0],i

[0015] }. The following details the computer-aided optimization criteria and methods, which can be used as the selection criteria and guidelines for sparse tap components. The inventor first defines three mandatory criteria for g -1 ; (1) The inverse transformation of g -1 exists; (2) Each output bit of g -1 is only associated with 2 or 3 input bits; (3) Each output bit of g is associated with all or almost all input bits; The inventor then defines two recommended criteria for g -1 ; (4) For g, an economical and fastest circuit implementation should be given; the fastest means that its circuit reaches the minimum delay index, i.e., the design of the number of gate delays, and economical means that the circuit implementation does not include implementations that consume a large amount of circuits, such as looking up large tables. (5) To be compatible with existing industrial habits and computer coding habits, the input-output width of g should be selected as 8, 16, 32, 64, 128 bits, 256 bits. When the input-output width of g -1 is 15 bits, the inventor finds a batch of designs that meet the above conditions (1) to (4). The specific method is to first construct a function expression that meets condition (2), such as the expression g -1 (x, i, j)=~(x>>>i)&(x>>>j) ⊕x, where >>> is the cyclic shift symbol. Exhaust all 224 possible combinations of i and j, and 26 of them meet condition (1). First, eliminate the g -1 (x, i, j) that does not meet (3), such as g -1(x, 3, 9) =~(x >>> 3) & (x >>> 9) ⊕ x. Each output bit of g(x) is only associated with 5 input bits. Then, eliminate the suspected g that does not meet (4). -1 (x, i, j), such as g -1 (x, 4, 8) =~(x >>> 4) & (x >>> 8) ⊕ x. The algebraic expression of the corresponding g(x) is relatively complex. Specifically, the output of g(x) is equal to the modulo 2 addition of 15 minterms. Because g -1 (x, 8, 4) =~(x >>> 8) & (x >>> 4) ⊕ x meets items (1) to (5), so g -1 (x, 8, 4) is a preferred result. The expression of the least significant bit of g({t14, t13, …, t0}) is t0 ⊕ t4 ⊕ (t4 & t8) ⊕ (t4 & t12) ⊕ (t1 & t4 & t12) ⊕ (t4 & t5 & t12) ⊕ (t4 & t5 & t9 & t12) ⊕ (t4 & t5 & t12 & t13) ⊕ (t2 & t4 & t5 & t12 & t13) ⊕ (t4 & t5 & t6 & t12 & t13) ⊕ (t4 & t5 & t6 & t10 & t12 & t13) ⊕ (t4 & t5 & t6 & t12 & t13 & t14) ⊕ (t3 & t4 & t5 & t6 & t12 & t13 & t14) ⊕ (t4 & t5 & t6 & t7 & t12 & t13 & t14) ⊕ (t4 & t5 & t6 & t7 & t11 & t12 & t13 & t14). Through the cyclic shift property, the remaining output bits of g can also be deduced from the above formula. The above 15-minterm expression can prove that each input of g is associated with all 15 input bits; the circuit built by the binary tree can prove that only 5 clk (1 + 4) are required to complete the calculation of g based on the minterm expression, that is, g -1 (x, 8, 4) =~(x >>> 8) & (x >>> 4) ⊕ x meets the fifth item. When g -1 has an input-output width of 16 bits, no g -1 (x, i, j) =~(x >>> i) & (x >>> j) ⊕ x that meets the above condition (1) is found by exhausting the combinations of i and j. More specifically, for the g -1 (x, i, j) model, when the number of input-output bits is equal to odd lengths such as 15, 17, 31, etc., many g -1 (x, i, j) meet conditions (1) to (5), but when the number of input-output bits is equal to even numbers such as 8, 10, 16, etc., all g -1 (x, i, j) do not meet condition (1). On the premise that the input-output width is 16 bits and meets condition (2), the inventor attempts to construct more possible g -1(x) model, the main idea is to use a limited combination of shift instructions, circular shift instructions, exhaustive bit inversion instructions, XOR instructions, and AND instructions; then for these g that meet condition (2) -1 (x) Screening of conditions (1) to (5) compared to g -1 (x[15:0], 8, 4) fully meets the above five criteria, and the computer selection results of 16-bit functions are not ideal. Therefore, based on the compromise idea in industrial design, the inventor uses g -1 (x[15:0], 8, 4) and 1 pass-through bit are spliced ​​into the g component for the sparse tap of VDF32; refer to the clk consumption standard of the term explanation content of "gate delay" in the detailed implementation method part, and Figure 5 corresponds to the 16-bit g -1 The hardware wiring diagram of g and the calculation flow diagram of Figure 5 can prove that g -1 The circuit delay is equal to 2 clks, while the maximum circuit delay of g can reach 5 clks. Figure 5 can also be used as a guide for writing hardware code. In addition, salt[0] is combined with the only pass-through bit through the ⊕ operation. Since the 16-bit g consumes 2 clks, salt[0] controls VDF32 or VDF32 -1 The actual overhead is submerged in 2 clks. Benchmarking Parameter Guidelines 1, compared to x t Or the S component of discrete logarithm function, the inventors prefer sparse tap design component or S component of F(A, B) structure. Although x -t and discrete logarithms are recognized to be unidirectional, but how to evaluate x -t The time consumption of operations and discrete logarithm operations is very difficult, and the difficulty lies in proving the fact that it is not easy to be accelerated in parallel. According to the evaluation and analysis results stated in this description, for example, the design indicator of VDF32 is 8 clks per symbol, among which the key component g (x[15:0], 8, 4) of level 15 has reached the theoretical minimum value of 5 clks. The sparse tap design and F(A, B) structure can be evaluated by the evaluation model, so it basically meets the first parameter guideline. The basic method means to construct VDF using one of the four components and any combination thereof. The following VDF1, VDF3, VDF1_log and VDF2_log embodiments can prove that only one component is sufficient to construct VDF. The remaining embodiments can also construct VDF using a combination of two component technologies. The final criterion for judging VDF is that the time delay of the critical path is significantly greater than that of VDF. -1 Critical path time delay. VDF1, VDF2 and VDF3 are constructed using the reverse logic function x t VDF implementation of the component. tRefers to t that can guarantee the minimum non-linearity and invertibility over a finite field or a finite ring. Generally, it is considered that x -t is one more hardware Euclidean inversion operation than x t . Therefore, a prime modulus that is very favorable for modular arithmetic is generally preferred; for the construction of a finite field, a finite field constructed with a special irreducible polynomial of three terms such as x 127 ⊕X⊕1 is generally selected. The following parameters essentially describe the circuit, and the numbers associated with the parameters have no order restrictions for execution. VDF1({A0}, salt, t), 1. The number of series, i.e., the number of symbols, is 1, and the symbol unit of 255 bits essentially represents the non-zero elements of modulo 2 255 -19. 2. F(Ai) = Ai + 1 = (temp - 1 + salti) mod (2 255 -20) + 1, where temp = (Ai -5 Mod(2 255 -19); 3. The recursive method for defining salt is additive congruence, i.e., salti = (salti + C) mod 2 255; 4. Run for t cycles and output {At}. VDF2({A7,..., A0}, t), 1. The symbol unit is 31 bits, which essentially represents the elements of the 2 31 -1 element field, and the number of symbols is 8; 2. The feedback function is Ai + 1 = F(Ai, Ai - 7), where F(A, B) = (S0(A) + B) 5 mod 2 31 -1, where the non-linear transformation S0(A) = (A >> 14) ⊕ A ⊕ 20051114 is defined; 3. Run for t cycles and output {At + 7,..., At} VDF3({A0}, salt, t), 1. The symbol unit is 127 bits, which essentially represents the non-zero elements of the 2 127 element field, and the number of symbols is 1; 2. The feedback function is Ai + 1 = F(Ai); where F(A) = (A 3 mod (x 127 ⊕X⊕1) >>> 7) ⊕ salt, >>> represents the operation of cyclic right shift; 3. Run for t cycles and output {At}. VDF1_log, VDF1_log, and VDF1_log are VDF embodiments where the function is the discrete logarithm. The main idea is to first create a finite field, define the symbol space as the non-zero elements in the finite field, and adjust the domain of definition each time a discrete logarithm is calculated because the discrete logarithm of 1 is 0, but 0 has no discrete logarithm. It is recommended to select different primitive elements by the latest symbol or salt. VDF1_log({A0}, salt, t) 1) Specification: series 1, symbol unit 255 bits, actually representing modulo 2 255 non-zero elements of -19; 2) F(Ai) = Ai+1 = 1 + log salti控选一个本原元 Ai; 3) The recursive method for defining salt is additive congruence, i.e., salti = (salti + C) mod 2 255 ; 4) Run for t cycles and output {At}. VDF2_log({A0}, salt, t), 1) Both salt and the initial state are non-zero elements in the field of 2 127 ; 2) Shift register parameters, symbol unit 127 bits, actually representing non-zero elements in the field of 2 127 with 1 symbol; 3) Field construction polynomial x 127 ⊕ X ⊕ 1; 4) Ai+1 <= log salti控选一个本原元 Ai +1 ; 5) Salti <= salti+1; 6) Calculate according to steps 3 and 4 for t cycles and output {At}. VDF3_log({A3, A2, A1, A0}, t), refer to Figure 13 1) Symbol unit 61 bits, actually representing the field of 2 61 elements with 4 symbols; 2) Field construction polynomial, x61 ⊕ x16 ⊕ x15 ⊕ x ⊕ 1; 3) Feedback function Ai+1 = F(Ai, Ai-3); where F(A, B) = 1 + log Ai控选一个本原元 Ai-3; 4) Run for t cycles and output {At+3, At+2, At+1, At}. The F(A, B) structure is a structural design method preferably recommended by the inventor. The F(A, B) structure described in the present invention should not be limited to the single-body F(A, B)=S(A)⊕B-type recursion or the single-body F(A, B)= S(A⊕B)-type recursion. The main idea of the A’=F(A, B) structure also includes the compounding of multiple F(A, B) structures, but it is necessary to ensure that the distance between the latest symbol near A and the earliest symbol near B is as large as possible; the purpose and effect of the main idea design are stated below; because the greater the distance, the reverse logic B=F -1 (A’, A) realizes VDF -1 The greater the parallel ability of the functional module; because the greater the parallel ability, the greater the design gain. The method of structure compounding can refer to the double-body compounding and wider promotion regarding Figure 11 below. The main technical feature is that the latest symbol of the active motion body combines with the latest symbol of the controlled motion body to exert an influence on the new symbol of the controlled motion body. The compound motion should have entropy preservation, that is, VDF -1 exists, VDF -1 corresponding to the parallel circuit based on the reverse logic B=F -1 (A’, A). Figure 9 corresponds to the above embodiment. The symbol A20 of the M-level F(A, B)-type non-linear recursive state machine controls the motion of the N-level F(A, B)-type non-linear recursive state machine. The latest symbol recursive expression of the upper figure in Figure 9 is as follows: {A2 M-1 ,…,A20}<- { S2(A2 M-1 ) ⊕A2 0 , A2 M-1 ,…,A21}; {A1 N-1 ,…,A10}<- { S1(A1 N-1 ) ⊕A10⊕A20, A1 N-1 ,…,A11}; Figure 9 corresponds to the following embodiment. The motion of the M-level F(A, B)-type linear recursive state machine is controlled by the symbol A10 of the N-level F(A, B)-type non-linear recursive state machine. The latest symbol recursive expression of the lower figure in Figure 9 is as follows: {A2 M-1 ,…,A20}<- { A2 M-1 ⊕A20⊕A1 0 , A2 M-1 ,…,A21}; {A1 N-1 ,…,A10}<- { S1(A1 N-1 ⊕A10), A1N-1 ,…, A11}; For the two recursive models corresponding to Figure 11, the latest symbol of an actively moving F(A, B) recursive state machine merges with the latest symbol of a controlled-motion F(A, B) recursive state machine, which affects the new symbol of the controlled-motion F(A, B) recursive state machine. Continuing to generalize the dual-body composite structure in Figure 11, for example, the motions of two recursive state machines are mutually controlled by two latest symbols. Continuing to generalize based on the design concept of controlled and mutually controlled motions, the scale of the two recursive state machines is expanded to three or more. Based on the design results of the above main idea, a more complex F(A, B) structure can be designed. For example, a, b, c, and d are the mutual controls of four F(A, B)=S(A⊕B)-type recursive state machines, where the latest symbol of a controls the motion of b, the latest symbol of b controls the motion of c, the latest symbol of c controls the motion of d, and the latest symbol of d controls the motion of a. All of the above control operations are entropy-preserving, i.e., VDF -1 Exists. All of the above designs such as controlled motion, mutual control motion, and multiple structure composites conform to the generalized definition of the F(A, B) structure and the above main idea, and should be considered equivalent designs of the single-body F(A, B) structure. The VDF32(,1,) recursive relationship in Figure 3 essentially describes the VDF32 circuit. Similarly, the state automaton model in Figure 11 does not include wire delay consumption and update register consumption; the composite design derived from Figure 11 and its derivatives essentially also describe the VDF circuit using a recursive state machine model. Additionally, B = F -1 The (A’, A) recursive relationship essentially corresponds to VDF -1 circuit, more specifically a parallel structure circuit. Finally, comparing with the two judgment criteria in the term explanation of the F(A, B) structure, the composite type of the two F(A, B) structures in Figure 11 conforms to the above A’ = F(A, B) structure design, and its reverse B = F -1 The (A’, A) can be accelerated by parallel hardware logic, so it meets the two criteria, that is, it has the property that the VDF calculation delay is greater than the VDF -1 calculation delay. The VDF and VDF of the present invention -1 The industrial implementation of the module is not limited to common implementation methods such as ASIC, FPGA, multi-core cpu, GPU, etc. based on electromagnetic principles. With future technological breakthroughs, implementing VDF or VDF using a functional computing chip or device based on photon or quantum principles -1 also falls within the scope of protection. To better understand the industrial ecosystem based on the VDF of the present invention, the inventor has drawn Figure 15 as an application guide. Figure 15 mainly includes a blockchain system empowered by the VDF of the present invention, a random beacon portal based on VDF32, a storage service terminal providing VDF8192 and VDF2M replica proof download services, and a cloud computing terminal providing computing power services. There are three ways for the VDF of the present invention to empower the blockchain system: 1. The consensus result is determined by the result of VDF32; 2. The Token of the blockchain is associated with VDF32(, t); 3. The new block is associated with VDF32 (the information of the previous block, t). The cloud computing terminal is a computing power server that can provide VDF or VDF -1 computing power support for weak computing terminals such as mobile phones and pads. As indicated by the guidance of the relevant content of the mobile phone in Figure 15, the original request first undergoes an appropriate hiding transformation of the original request computing task through a hiding module. For the received response, the hiding removal module on the mobile phone side removes the aforementioned hiding transformation through an inverse transformation, and the correct response result is obtained after removal. The methods and basic ideas of hiding and removing hiding are described in the invention content. Figure 15 indicates three common computing power implementation methods, namely: 1. Dedicated chips; 2. Multicore processors, especially multicore processors with Intel's multimedia instruction set or GPUs; 3. Computing devices based on cloud computing terminals. These computing power implementation methods support the computing power requirements of a verification device and also support the decoding requirements of VDF replica proof data. To illustrate the third-party support implementation of the VDF computing device or VDF verification device, an embodiment of a VDF8192 verification device is given as an example. The VDF8192 verification device consists of a software processing module and an Intel multicore processor; In addition to the input sub-module and output sub-module related to the business, the software processing module also includes a VDF8192 verification device sub-module, and the corresponding function of the VDF8192 verification device sub-module is VDF8192 -1 computing; To implement VDF8192 -1 The VDF8192 verification device sub-module has 4 calling options for VDF8192 computing. Option 1 is to call the serial port chip of VDF8192 with a standard interface through the USB serial port; -1 Option 2 is to call a remote cloud computing terminal through the network; Option 3 is to call the local graphics card GPU computing resources to implement VDF8192 -1 computing; Option 4 is to call the Intel multicore processor through multi-core and multi-thread technology to implement VDF8192 -1 computing; The Intel multicore processor, on the one hand, provides support for the operation of the software processing module, and on the other hand, provides multiple physical core supports for calling Option 4. In summary, any one of call options 1 to 3 of the embodiments belongs to the third-party support implementation method. From the perspective of the encoded content dimension, the medium involved in the present invention includes three cases: input, output, or intermediate state; because the VDF of the present invention has entropy preservation, a logical output exactly corresponds to its inverse logical input; in addition to a intermediate states, on-site protection and breakpoint protection data also belong to the category of generalized intermediate states. In summary, the initial state, result, a intermediate states, on-site protection and breakpoint protection data, etc. associated with the VDF and VDF -1 modules are all within the scope of protection. It should be based on the data to associate or support various industrial applications, computing devices, verification devices, and computing engines of the present invention. The relevant standards can refer to the industrial ecosystem diagram in Figure 15. According to the output examples of VDF, there are VDF32 (blockchain entropy value) for beacon applications and VDF2M (encoded block) for replica proofs. According to the VDF -1 output example, there is VDF8192 for time capsule applications -1 (the committed content of the time capsule), and the cloud terminal response result in Figure 15. Relevant examples are the data of time capsule applications. For the committer, it is VDF -1 (commitment, t), and for the verifier, this data is exactly the initial state of the VDF. Another demonstration is that the VDF encoding returned by the storage service terminal in Figure 15 in response to the request is exactly the initial state of the VDF for the client. -1 An example is given to illustrate how the medium supports on-site protection and breakpoint protection. As is well known, the Cpu uses process on-site protection and process on-site recovery technologies to enable 1 Cpu core to serve multiple computing task requests through Cpu time sharing, and it can also migrate the computing tasks of 1 Cpu core to another physical core of the Cpu core to continue running. The VDF8192 modules in Figure 7 and the VDF8192 -1 modules in Figure 8 can actually achieve similar functions above. Taking Figure 7 as an example, the principle is described. First, suspend the calculation of VDF8192 through a series of cmd = 6 commands, and then through a series of cmd = 5 commands, output the on-site content of the register groups st and {k, t} as on-site protection and breakpoint protection data to the medium for storage. At an appropriate time, pour the data stored in the medium into a VDF8192 hardware logic of the same standard through a series of cmd = 5 commands, and then use a series of cmd = 1 commands to reactivate the computing task. Therefore, the medium stores on-site protection and breakpoint protection data related to VDF or VDF -1 computing, which also belongs to the protection scope of the present invention. From the perspective of hardware entities, the medium of the present invention includes at least three entities: 1. computer storage media, 2. paper media, and 3. cloud notarization services. Among them, computer storage media include permanent and non-permanent, removable and non-removable media, and information storage can be achieved by any method or technology. The physical entities of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. Generally, VDF computing devices, VDF verification devices, and computing engine devices need to use computer storage media to implement applications such as buffering, exchanging, and protecting the intermediate state of original data and results. Typical entities of cloud notarization services include network hard drives, web-based network storage, or network distribution servers. Finally, the following examples illustrate the industrial forms related to the medium: 1) Data related to VDF32 or intermediate state data is printed on a paper carrier; 2) On a cloud storage server of a USB flash drive or a network hard drive, the stored content is blockchain-related data empowered by the present invention. Because the design parameters of VDF32, VDF8192, and VDF2M consider the trade-off and synthesis of the following three design indicators, as a comprehensive construction result that takes into account the three parameters, it is not excessive to be named the comprehensive optimal embodiment; benchmarking against the three parameter guidelines described in the invention content and the derivation process of the VDF32 gain of 8clk mentioned above, the comprehensive technical indicators of the VDF series constructed by the present invention are that it can be preliminarily proved that VDF32, VDF8192, and VDF2M have strong anti-parallel capabilities during the calculation stage. During the verification stage, VDF / VDF -1 The design gain and the industrial implementation gain are approximately equal to the amount of data in bytes received during the verification stage. As is well known, many industrial indicators are mutually antagonistic, and only by sacrificing one indicator can another indicator be made better. The three indicators related to the embodiments of the present invention are no exception. The three indicators announced by the inventor are: 1) The greater the anti-parallel capability of VDF, the better, and the best result is that it is proved that it cannot be optimized in parallel; 2) The greater the theoretical design gain of VDF, that is, the second quantitative indicator of the parameter guidelines; 3) In order to support hidden calculation, the salt period should not be too large. The following analysis and reasoning of the inventor can prove that the above three indicators have the property of not being able to be achieved simultaneously, and there is indeed an antagonistic relationship in the design. 1) The input and output widths of the VDF are the same, and the above-mentioned indicators 1 and 2 are mutually antagonistic. The following is a comparison of the technical indicators of the VDF32_4.5 and VDF32 standards; 2) If the period of the salt is very large, for example, the salt is an m-sequence recursion, the VDF actually becomes a high-strength cryptographic sequence similar to grain. It can be considered that the theoretical anti-prediction and anti-analysis capabilities of the VDF increase, but a too large period cannot support the hidden calculation function; that is, the above-mentioned indicators 1 and 3 are mutually antagonistic; 3) By adding more late symbols like VDF32, the theoretical value of the anti-parallelism ability of the VDF continues to increase, but the theoretical gain provided by the F(A, B) structure becomes smaller, which is equivalent to the above-mentioned indicators 1 and 2 being mutually antagonistic; 4) If the VDF8192 or VDF2M adopts the composite structure of two single F(A, B) in Figure 11, because the structure is complex and the expression is more complex, it can be considered that the anti-parallelism ability and anti-cryptanalysis ability of the VDF increase, but the design gain is at least reduced to half of the original, which is equivalent to the above-mentioned indicators 1 and 2 being mutually antagonistic. Based on the research and analysis results of the above-mentioned antagonistic relationships, and based on the construction method of the parallel circuit corresponding to the serial circuit verification stage in the calculation stage, the following three new embodiments VDF32_4.5, VDF8192_126, and VDF8192_126_plus are given. The main feature of these embodiments is to sacrifice the gain index in exchange for stronger anti-parallelism ability and anti-analysis and anti-prediction abilities. The embodiment VDF32_4.5 is a VDF with the best anti-parallelism design based on a 255-bit sparse tap. Referring to the aforementioned preferred g-function standard of VDF32, when the input and output are 255 bits, there is a high probability that g -1 (x, i, j) = ~(x >>> i) & (x >>> j) ⊕ x, where each output bit of g(x, i, j) is associated with 255 input bits, and the output of g(x) is equal to the modulo 2 sum of 255 minterms. According to the binary tree calculation structure, the theoretical calculation delay of g is 9 clk, and the calculation delay of g -1 is 2 clk, so the design gain is 4.5 (9 / 2). Similar to the g-function construction of the VDF32 standard, a direct-through bit is added to the 255-level g(x, i, j), and the direct-through bit is associated with the salt-related bit, thereby constructing the VDF32_4.5(,, salt) with 32-byte input and output. The gain of this VDF is also 4.5. The comparison result is that the VDF32 standard gain index of 34.6 is better than the 4.5 index, but the anti-parallelism ability of this VDF32_4.5 reaches the optimum, that is, it cannot be parallel accelerated. The following is the parameter description of VDF32_4.5. Ignoring the parameter coding order, the parameter definitions are as follows. Example: VDF32_4.5(A0, t, salt) salt is 128 or 256 bits, and the movement mode is basically the same as that of VDF32; 1) t is equal to 16 * k, where k is a natural number; 2) 1 symbol, with a symbol width of 256 bits; 3) The recurrence relation is VDF32_4.5(A, 1) = {g(A[254:0], i, j), A

[0255] }; 4) Where g -1 (x, i, j) = (~(x >>> i) & (x >>> j)) ⊕ x; 5) Every 16 times the VDF moves, salt is circularly shifted to the left by 1 bit; before the VDF moves, salt[0] is subjected to an exclusive OR operation with the symbol A bit modulo 2; Output: {At}. Referring to Figure 11 below, define a VDF8192_126 with main parameters similar to VDF8192; the main structure is a composite of two sets of F(A, B) structures, where 127 symbols are selected from N and 129 symbols are selected from M, and S2 corresponds to VDF32_4.5. The main parameters of VDF8192 are as follows. VDF8192_126_plus is an upgraded version of VDF8192_126, and its main feature is that the earliest symbols of the two sets of F(A, B) structures are exchanged and controlled with each other. Example: VDF8192_126({A2 128 , …, A20}, {A1 126 , …, A10}, t, salt), ignoring the parameter coding order, the parameter definitions are as follows: 1) t is equal to 200 * △ * k, where k is a relatively small natural number; 2) The first group has 129 symbols, the second group has 127 symbols, for a total of 256 symbols, and each symbol is 32 bytes; 3) The recurrence relation of VDF8192_126({A2 128 , …, A20}, {A1 126 , …, A10}, △, salt) is: The first group: {A2 128 ⊕ A20 ⊕ A1 0 , A2 128 , …, A21}, The second group: {VDF32_4.5(A1 126 ⊕ A10, △, salt), A1126 ,…,A11}; Output: {A2 128+t ,…,A2 t}, {A1 126+t ,…,A1 t}. Example: VDF8192_126_plus({A2 128 ,…,A20}, {A1 126 ,…,A10}, t, salt), regardless of the parameter coding order. The parameter definitions are as follows: 1) t is equal to 200 * △ * k, where k is a relatively small natural number; 2) The first group has 129 symbols, the second group has 127 symbols, for a total of 256 symbols, and each symbol is 32 bytes; 3) The recurrence relation of VDF8192_126_plus({A2 128 ,…,A20}, {A1 126 ,…,A10}, △, salt) is: First group: { A2 128 ⊕A20⊕A1 0 , A2 128 ,…,A21}, Second group: { VDF32_4.5 (A1 126 ⊕A10⊕A21, △, salt), A1 126 ,…,A11}; Output: {A2 128+t ,…,A2 t}, {A1 126+t ,…,A1 t}. To examine the parallelism of the reverse logic, first analyze the earliest and latest symbols of VDF8192_126 and VDF8192_126_plus. According to the guidance of Figure 11, the latest symbols are A2 128 and A1 126 , and the earliest symbols are A20, A10, and A21. To analyze the parallelism of VDF -1 , the recurrence relation of VDF8192_126 -1 is organized as follows: First group reverse logic: A2 0+j ⊕A1 0+j <- A2 128+j ⊕A2 129+j ; Second group reverse logic: A1 0+i <- VDF32_4.5 -1(A1 127+i ⊕A1 126+i , △, salt). Since the second group of VDF8192_126 is not controlled by the first group of information, and the second group contains the S(, △, ) component without large-delay calculations in the first group, the calculation delay is contributed by the second group; calculating VDF8192_126 and VDF8192_126 -1 The method is to first calculate the second group of VDF or VDF -1 , and then quickly calculate the state of the first group according to the second group of VDF or VDF -1 result. Therefore, the gain evaluation of VDF8192_126 -1 only needs to discuss the second group. According to the 127 symbols of the second group, the total theoretical gain of VDF8192_126 is deduced to be 567 (126 * 4.5). To analyze the parallel ability of VDF -1 , the recursive relationship of VDF8192_126_plus -1 is sorted out as follows: The reverse logic of the first group: A2 0+j ⊕A1 0+j <- A2 128+j ⊕A2 129+j ; The reverse logic of the second group: A1 0+i ⊕A2 1+i <- VDF32_4.5 -1 (A1 127+i ⊕A1 126+i , △, salt). Let i and j be equal to t. Note that the corresponding parallel logic can be expanded within the range from t to t - 125. From this, the simultaneous parallel ability of the two groups is deduced to be 126, that is; therefore, the design gain of VDF8192_126_plus is also 567 (126 * 4.5). Therefore, compared with VDF8192, the logic control of VDF8192_126 and VDF8192_126_plus is more complex, and finally, better anti-parallel ability, anti-analysis and anti-prediction ability are obtained at the cost of sacrificing the design gain of VDF design. Based on the design analysis of the above embodiments, more embodiments can be designed under the guidance of the inventive concept, and the three design indicators of these embodiments must also restrict and compromise with each other. On the other hand, FIGS. 7, 8, 9, 10 and their related circuit designs of the present invention can also provide guidance for industrial implementation. The gist of the present invention is to realize the VDF circuit of the serial structure and the VDF of the parallel structure through the combination of three necessary technical features -1Circuit, VDF circuit with serial structure and VDF with parallel structure -1 The indicators of the circuit comply with Articles 2 and 3 of the parameter guidelines. On this basis, making changes such as adding low-frequency transformation or minor changes, although the form is more complex in state recursion, in essence, it does not destroy the combination of the three necessary technical features to produce the technical effects of Articles 2 and 3 of the parameter guidelines (i.e., the gain of VDF / VDF -1 is large enough). Therefore, changes such as adding low-frequency transformation or minor changes also fall within the protection scope of the present invention. Examples of low-frequency transformation are, for VDF constructed with the F(A, B) structure, in order to improve the anti-analysis ability, after 1 time (or multiple times) of VDF -1 operation (, △*b), a fast entropy-preserving transformation is performed on the result. When △ is very large, obviously the entropy-preserving transformation is an operation with low-frequency nature. For easy understanding, refer to the VDF in the verification stage in the following figure of Figure 2 -1 ({A2b-1,…,Ab}, △*b) corresponding to {Ab,…,A0}, and a fast entropy-preserving transformation is performed on {Ab,…,A0}. Examples of the entropy-preserving transformation include performing block cipher encryption once within the range of {Ab,…,A0}. Examples of minor changes are, in order to improve the anti-analysis and anti-parallel capabilities, making the input and output of VDF32 and VDF32_4.5 with a 32-byte width constructed by cascade logic. Regarding the control and movement part of the salt for VDF32, the following parameters are more suitable for industrial standardization, engineering, and block cipher formalization. The previous VDF32 scheme was that every 16 times, salt[0] was logically combined with VDF32(, 13,), and the salt was circularly shifted 1 time. The recommended parameter is that every 24 times is logically combined with VDF32(, 13,), and the salt is linearly encoded 1 time, where the encoding method is and The factors of 24 are 1, 2, 3, 4, 6, 8, 12, and 24, and the multiple between adjacent factors is very small, only 4 / 3 or 3 / 2; so the 24-layer design is more friendly to circuit wiring engineers. The periods of both linear encoders are 480, so the compatibility between 128bit and 256bit is more beneficial to standardization, and the linear code weight is also better than that of circular shift linear encoding. In order to have better industrial practicality, the above parameters are specifically disclosed for VDF32. The above description is only a preferred embodiment of the present application and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the concept of the present application. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present application. Industrial applicability The previously disclosed VDF32 and VDF8192 are the comprehensive results of comprehensive anti-parallelism and maximizing the gain, and are also the proposed industrial standards. The applications disclosed in this specification include random beacon applications, portal websites, copy certification applications, storage service terminals, cloud computing terminals, two VDF-related blockchain systems, Token encoding and verification encoding methods, and automatically opening commitments. To support industrial applications and implementation, this specification also discloses a VDF calculation device, a VDF verification device, a medium, and a chip.

Claims

1. A method for constructing a VDF, the input parameters including an initial state and a time parameter t, and the output being VDF(initial state, t), characterized in that, Including: An S component of a one-way reversible function that directly or indirectly constructs a VDF, where the definition of the S component is a reversible function whose forward logic calculation delay is significantly greater than the reverse logic calculation delay; Perform the following operations during the calculation phase: a intermediate states of the VDF calculation process, and / or, F(A0, Ab)=S(A0⊕Ab, △) indirectly constructs a VDF, where t is divisible by △*b; Perform the following operations during the verification phase: Receive the initial state and a + 1 states; and, use several S's in parallel -1 Logically implement a + 1 VDFs -1 Verification task.

2. The VDF construction method according to claim 1, wherein The S component is one of the following four basic methods or any combination; The forward feedback function is designed in the structure of F(A, B), where A is the earliest symbol and B is the latest symbol; the reverse logic function includes a sparse tap design; the reverse logic function contains an x t -power design, where t is the smallest integer to ensure reversibility and non-linearity; the forward logic function contains a discrete logarithm function.

3. The method for constructing a VDF according to claim 1 or 2, characterized in that, Increase the VDF input parameter salt, and salti changes the corresponding register of the VDF at the i-th beat or the salti entropy value controls the one-way reversible function S operation in an entropy-preserving manner, where salti is the i-th beat state of salt.

4. The method for constructing a VDF according to claim 1 or 2, characterized in that, The S component has a structure of F(A, B) = g(A⊕B), where g -1 is designed for sparse taps.

5. The method for constructing a VDF according to claim 4, characterized in that, Increase the input parameter salt, and salti changes the register corresponding to the S component in an entropy-preserving manner, where salti is the i-th beat state of salt.

6. The method for constructing a VDF according to claim 5, wherein, The VDF is VDF32({A15, A14, …, A0}, t, salt), where salt is 128bit or 256bit; The parameter definitions are as follows: t is equal to 128*16*13*k, where k is a natural number; {A15, A14, …, A0} is the input, and each symbol is 16bit; The state recurrence equation is: VDF32({A15, A14, …, A0}, 1)={g(~(~A15&A14)&A13)⊕A0)⊕the recycled constant table, A15, …, A1}; The said g -1 (i)'s Verilog code is: {({i[3:0], i[14:4]} & {~i[7:0], ~i[14:8]} )^i[14:0], i[15]}; The salt parameter is the exclusive OR of the highest bit of the 256bit register for every 13 symbols updated by VDF32 with salt[0], and salt is left-circular shifted once for every 16*13 symbols updated; The VDF32 output result: {A15+t, A14+t, …, At}.

7. The method for constructing a VDF according to claim 5, wherein The VDF is VDF8192({A255, A254, …, A0}, t, salt), and the S component is VDF32; The parameter definitions are as follows: t is equal to △*255*k, where k is a relatively small natural number; the input is 8192 bytes, which are divided into 256 symbols from A255 to A0, and each symbol is 32 bytes; The state recurrence equation is: VDF8192({A255, A254, …, A0}, △, salt)={VDF32(A255⊕A0, △, salt), A255, …, A1}; The VDF8192 output result: {A255*k +255, A255*k+254, …, A255*k}.

8. A chip including a VDF calculation module constructed by any of the methods in claims 1-7, and a VDF -1 module, characterized in that The chip includes the VDF or the VDF -1 computing module.

9. The chip according to claim 8, comprising an rx pin and a tx pin compliant with the serial port protocol, characterized in that, The control command and calculation input are input through the rx pin, and the calculation result is output through the tx pin.

10. The chip according to claim 9, characterized in that, The chip internally includes two types of computing modules and two components. The two types of computing modules are respectively: the VDF8192 computing module based on a state automaton and the VDF8192 -1 computing module; and the two components are respectively: a serial port decoding and instruction decoding execution component and a multi-functional automatic encoding and output component; According to the signal control flow direction, the decomposition structure of the serial port decoding and instruction decoding execution component is in sequence: the serial port decoding sub-module connected to the rx pin, the instruction decoding and execution sub-module, and the 256bit input register sub-module; According to the signal control flow direction, the decomposition structure of the multifunctional automatic encoding and output component is in sequence: an output buffer register sub-module, a multi-byte automatic encoder sub-module, and a serial port encoding output sub-module connected to the tx pin; Moreover, the mutual control relationship between the computing module and the component is: The serial port decoding and instruction decoding execution component receives external instructions from the rx pin, and the serial port decoding and instruction decoding execution component translates the external instructions into: instruction codes, data encodings, and address encodings, where each address encoding is associated with a specified VDF8192 -1 computing module or VDF8192 computing module, and the data encoding is buffered into the 256-bit input register sub-module; According to the specification of the address coding, the designated VDF8192 -1 The module or the VDF8192 module receives the instruction code and the excitation control signal of the data coding, and according to the excitation control signal, realizes the VDF8192 -1 The module or the VDF8192 module realizes the functions of initial state initialization, start calculation, and pause calculation of the VDF or VDF -1 ; The instruction code also stimulates control of the multifunctional automatic encoding and output component, thereby implementing the VDF8192 -1 module or the status register output of the VDF8192 module; the specific output steps are as follows: first, buffer the status of the calculation module specified by the address encoding into the output buffer register sub-module, and then, under timing control, output the information of the output buffer register sub-module to the tx pin according to the serial port encoding level signal.

11. A method for applying a random beacon, characterized in that, It includes a VDF constructed by any of the methods in claims 1-7. The blockchain entropy value is used as the initial state input of the VDF, and the VDF output is used as a random beacon.

12. A portal website, characterized in that, The portal website publishes the random beacon output by the VDF and the data that can verify the random beacon, where the VDF is a VDF constructed by any of the methods in claims 1-7.

13. A coding and decoding method for a copy certification application, including a copy number and a coding block, further including a VDF constructed by the method of claim 3, 6 or 7, wherein the salt is associated with the copy number; the coding process of the copy certification is a VDF, wherein the input parameters of the VDF are the coding block and the copy number; the decoding process of the copy certification is a VDF -1 , wherein the VDF -1 's input parameters are the coding result and the copy number.

14. A storage service terminal, characterized in that, The storage service terminal stores and downloads the object which is the encoding result of claim 13, that is, VDF (encoding block, copy number); Among them, the steps for executing the download command are as follows: s141: Receive the download request from the customer, s142: Return or direct the download of the encoding result according to the download request.

15. A cloud computing terminal, characterized in that, including a VDF or VDF -1 a calculation module, a network receiving module, and a network sending module, where the VDF is a VDF constructed by any of the methods in claims 1-7; Among them, the steps for executing the computing power service command are as follows: S151: The network acceptance module accepts the input from the customer through the network; S152: The computing module calls a VDF or a VDF -1 Perform a calculation on the input of S151; S153: The network sending module returns the calculation result of S152 to the customer through the network.

16. A blockchain system in which VDF participates in consensus, characterized in that, The blockchain accounting right is determined by the output of the VDF. The VDF input is associated with the entropy value of the previous block, where the VDF is a VDF constructed by any of the methods in claims 1-7.

17. A blockchain system for associating time consumption in a new casting block, characterized in that, The new block hash is associated with VDF (the previous block hash, t); where t is a time parameter and the VDF is a VDF constructed by any of the methods in claims 1-7; 18. The blockchain system according to claim 17, wherein Select a VDF with a salt parameter. The VDF with a salt parameter is a VDF constructed by any of the methods in claims 3, 5, or 6; where the salt is associated with a trusted time evidence.

19. A method for encoding and verifying an encoding of a Token, characterized in that, It includes an encoding stage and a verification stage; the encoding stage corresponds to the calculation stage of the VDF, and the verification stage corresponds to the verification stage of the VDF; where the VDF is a VDF constructed by any of the methods in claims 1-7; In the encoding stage, the following operations are performed: Calculate and present VDF (seed, t) and a intermediate states, where seed is associated with the ID of the Token; In the verification phase, the following operations are performed: receive a seed and a + 1 states; and, in parallel, use a number of S -1 Logical implementation of VDF -1 (seed, t) verification task 20. A method for automatically opening a commitment and verifying a commitment, characterized in that, It includes a commitment phase and a verification phase, where the commitment phase corresponds to the VDF -1 (, t) calculation, and the verification phase corresponds to the VDF (, t) calculation. The VDF is a VDF constructed by any method in claims 1-7, and the t is a time parameter. The steps of the commitment phase and the verification phase are as follows: Commitment stage: S201: X = VDF -1 (Commitment content, t); S202: Send X and t to the verifier; Verification stage: S203: Receive the X and t, and calculate VDF (X, t) to obtain the committed content.

21. A VDF calculation device, characterized in that, It includes a VDF calculation module, and the VDF calculation module realizes the function of the calculation stage of the VDF constructed by any of the construction methods in claims 1 to 7; The input of the computing device is the initial state and t, and the output is the result and a intermediate states; The VDF calculation module can be independently completed by the computing device or can be realized with the support of a third party.

22. A VDF verification device, characterized in that, It includes a VDF verification module, and the VDF verification module realizes the function of the verification stage of the VDF constructed by any of the construction methods in claims 1 to 7; The input of the verification device is the initial state, the result, and a intermediate states, and the output is a judgment result; The VDF verification module can be independently completed by the verification device or can be realized with the support of a third party.

23. A medium on which binary data is stored, characterized in that, The encoded content of the binary data is VDF and / or VDF -1 input, output or intermediate state, where the VDF is constructed by any of the methods recited in claims 1-7.

Citation Information

Patent Citations

  • Distributed lottery system and method based on verifiable delay function

    CN112527244A

  • Block chain consensus system and method based on distributed verifiable delay function

    CN112988894A

  • Method and system for generating random number based on decentralized verifiable delay function

    CN113407156A

  • VDF construction method, chip, application, product, device and medium

    CN117669475A

  • Preventing denial-of-service attacks in decentralized edge networks using verifiable delay functions (VDFs)

    US11089051B1

Cited By

  • Password-based certifiable security identity authentication method and system

    CN120856324A