Highly scalable permissioned block chains
Abstract
Technologies are shown for function level permissions control for smart contract execution to implement permissions policy on a blockchain. Permissions control rules control function calls at a system level utilizing function boundary detection instrumentation in a kernel that executes smart contracts. The detection instrumentation generates a call stack that represents a chain of function calls in the kernel for a smart contract. The permissions control rules are applied to the call stack to implement permissions control policy. Permissions control rules can use dynamic state data in the function call chain. If the dynamic state data observed in function call chains does not meet the requirements defined in the permissions control rules, then the function call can be blocked from executing or completing execution. The permissions control rules can be generated for a variety of different entities, such as a domain, user or resource.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method comprising:
detecting, in a kernel for smart contract execution of a blockchain, a function call by one or more methods of a smart contract on the blockchain; adding the function call to a function call stack for the smart contract; checking the function call stack against a set of function level permissions control rules that define one or more permitted or prohibited function calls; and blocking execution of the function call based on determining the function call stack includes one or more function calls that are not permitted under the set of function level permissions control rules.
2 . The computer-implemented method of claim 1 , wherein the function call stack includes each function called during execution of the smart contract; wherein the set of function level permissions control rules further includes at least one permissions control rule that defines a sequence of function calls; and wherein checking the function call stack against the set of function level permissions control rules further comprises checking the function call stack against the sequence of function calls.
3 . The computer-implemented method of claim 1 , wherein the method further comprises:
defining the set of function level permissions control rules; and storing the set of function level permissions control rules in one or more blocks of a second blockchain.
4 . The computer-implemented method of claim 3 , wherein checking the function call stack against the set of function level permissions control rules comprises accessing the set of function level permissions control rules from the one or more blocks of the second blockchain.
5 . The computer-implemented method of claim 3 , wherein the method further comprises:
modifying the set of function level permissions control rules to provide a modified set of function level permission control rules; creating one or more additional blocks that include the modified set of function level permissions control rules; and adding the one or more additional blocks to the second blockchain.
6 . The computer-implemented method of claim 1 , wherein the method further comprises:
defining the set of function level permissions control rules for a domain; determining that the function call is related to the domain; obtaining the set of function level permissions control rules for the domain; and wherein checking the function call stack against the set of function level permissions control rules comprises checking the function call stack against the set of function level permissions control rules for the domain.
7 . The computer-implemented method of claim 1 , wherein the set of function level permissions control rules corresponds to one or more selected from the following: a user identifier for an originator of the function call, a resource identifier for a computer resource that is a subject of the function call, and a domain identifier.
8 . One or more computer storage media storing computer-useable instructions that, when used by a computing device, cause the computing device to perform operations, the operations comprising:
detecting, in a kernel for smart contract execution of a blockchain, a function call by one or more methods of a smart contract on the blockchain; adding the function call to a function call stack for the smart contract; checking the function call stack against a set of function level permissions control rules that define one or more permitted or prohibited function calls; and blocking execution of the function call based on determining the function call stack includes one or more function calls that are not permitted under the set of function level permissions control rules.
9 . The one or more computer storage media of claim 8 , wherein the function call stack includes each function called during execution of the smart contract; wherein the set of function level permissions control rules further includes at least one permissions control rule that defines a sequence of function calls; and wherein checking the function call stack against the set of function level permissions control rules further comprises checking the function call stack against the sequence of function calls.
10 . The one or more computer storage media of claim 8 , wherein the operations further comprise:
defining the set of function level permissions control rules; and storing the set of function level permissions control rules in one or more blocks of a second blockchain.
11 . The one or more computer storage media of claim 10 , wherein checking the function call stack against the set of function level permissions control rules comprises accessing the set of function level permissions control rules from the one or more blocks of the second blockchain.
12 . The one or more computer storage media of claim 10 , wherein the operations further comprise:
modifying the set of function level permissions control rules to provide a modified set of function level permission control rules; creating one or more additional blocks that include the modified set of function level permissions control rules; and adding the one or more additional blocks to the second blockchain.
13 . The one or more computer storage media of claim 8 , wherein the operations further comprise:
defining the set of function level permissions control rules for a domain; determining that the function call is related to the domain; obtaining the set of function level permissions control rules for the domain; and wherein checking the function call stack against the set of function level permissions control rules comprises checking the function call stack against the set of function level permissions control rules for the domain.
14 . The one or more computer storage media of claim 8 , wherein the set of function level permissions control rules corresponds to one or more selected from the following:
a user identifier for an originator of the function call, a resource identifier for a computer resource that is a subject of the function call, and a domain identifier.
15 . A computer system comprising:
a processor; and a computer storage medium storing computer-useable instructions that, when used by the processor, causes the computer system to perform operations comprising: detecting, in a kernel for smart contract execution of a blockchain, a function call by one or more methods of a smart contract on the blockchain; adding the function call to a function call stack for the smart contract; checking the function call stack against a set of function level permissions control rules that define one or more permitted or prohibited function calls; and blocking execution of the function call based on determining the function call stack includes one or more function calls that are not permitted under the set of function level permissions control rules.
16 . The computer system of claim 15 , wherein the function call stack includes each function called during execution of the smart contract; wherein the set of function level permissions control rules further includes at least one permissions control rule that defines a sequence of function calls; and wherein checking the function call stack against the set of function level permissions control rules further comprises checking the function call stack against the sequence of function calls.
17 . The computer system of claim 15 , wherein the operations further comprise:
defining the set of function level permissions control rules; and storing the set of function level permissions control rules in one or more blocks of a second blockchain.
18 . The computer system of claim 17 , wherein checking the function call stack against the set of function level permissions control rules comprises accessing the set of function level permissions control rules from the one or more blocks of the second blockchain.
19 . The computer system of claim 17 , wherein the operations further comprise:
modifying the set of function level permissions control rules to provide a modified set of function level permission control rules; creating one or more additional blocks that include the modified set of function level permissions control rules; and adding the one or more additional blocks to the second blockchain.
20 . The computer system of claim 15 , wherein the operations further comprise:
defining the set of function level permissions control rules for a domain; determining that the function call is related to the domain; obtaining the set of function level permissions control rules for the domain; and wherein checking the function call stack against the set of function level permissions control rules comprises checking the function call stack against the set of function level permissions control rules for the domain.Join the waitlist — get patent alerts
Track US2024028711A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.