PageSourceSearch

https://elastos-docs.onrender.com/assets/js/eae95122.137918d8.js

js elastos-docs.onrender.com collected 2026-10-03 11:42:03 UTC 13,543 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkelastos_docs=globalThis.webpackChunkelastos_docs||[]).push([[4565],{98450(e,i,n){n.r(i),n.d(i,{assets:()=>c,contentTitle:()=>o,default:()=>h,frontMatter:()=>a,metadata:()=>r,toc:()=>d});const r=JSON.parse('{"id":"blockchain/architecture/cross-chain-protocol","title":"Cross-Chain Protocol","description":"Specification of the Elastos cross-chain bridge protocol including deposit/withdrawal flows, Schnorr signatures, and SPV proofs.","source":"@site/docs/blockchain/architecture/cross-chain-protocol.md","sourceDirName":"blockchain/architecture","slug":"/blockchain/architecture/cross-chain-protocol","permalink":"/blockchain/architecture/cross-chain-protocol","draft":false,"unlisted":false,"tags":[],"version":"current","sidebarPosition":4,"frontMatter":{"type":"reference","sidebar_position":4,"title":"Cross-Chain Protocol","description":"Specification of the Elastos cross-chain bridge protocol including deposit/withdrawal flows, Schnorr signatures, and SPV proofs.","chains":["cross"],"keywords":["Elastos","World Computer","architecture","cross-chain","protocol","bridge","arbiter"],"image":"/img/og-blockchain.jpg"},"sidebar":"blockchainSidebar","previous":{"title":"Sidechain Framework","permalink":"/blockchain/architecture/sidechain-framework"},"next":{"title":"Identity Protocol","permalink":"/blockchain/architecture/identity-protocol"}}');var s=n(74848),t=n(28453);const a={type:"reference",sidebar_position:4,title:"Cross-Chain Protocol",description:"Specification of the Elastos cross-chain bridge protocol including deposit/withdrawal flows, Schnorr signatures, and SPV proofs.",chains:["cross"],keywords:["Elastos","World Computer","architecture","cross-chain","protocol","bridge","arbiter"],image:"/img/og-blockchain.jpg"},o="Cross-Chain Protocol",c={},d=[{value:"Deposit Flow: Main Chain to ESC",id:"deposit-flow-main-chain-to-esc",level:2},{value:"Withdrawal Flow: ESC to Main Chain",id:"withdrawal-flow-esc-to-main-chain",level:2},{value:"Genesis Block Address",id:"genesis-block-address",level:2},{value:"Small Transfer Fast Path",id:"small-transfer-fast-path",level:2},{value:"Schnorr Aggregate Signatures",id:"schnorr-aggregate-signatures",level:2},{value:"SPV Proof Format",id:"spv-proof-format",level:2},{value:"Failed Deposit Return",id:"failed-deposit-return",level:2},{value:"Arbiter Rotation",id:"arbiter-rotation",level:2},{value:"Fees",id:"fees",level:2}];function l(e){const i={admonition:"admonition",code:"code",h1:"h1",h2:"h2",header:"header",li:"li",mermaid:"mermaid",ol:"ol",p:"p",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,t.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(i.header,{children:(0,s.jsx)(i.h1,{id:"cross-chain-protocol",children:"Cross-Chain Protocol"})}),"\n",(0,s.jsx)(i.p,{children:"The Elastos cross-chain bridge moves ELA between the main chain and sidechains (ESC, EID) at a 1:1 ratio. Deposits are trustless (verified via SPV proofs). Withdrawals are semi-trusted (require 2/3+1 of the 12 Council-operated arbiters to sign)."}),"\n",(0,s.jsx)(i.h2,{id:"deposit-flow-main-chain-to-esc",children:"Deposit Flow: Main Chain to ESC"}),"\n",(0,s.jsx)(i.mermaid,{value:"sequenceDiagram\n    participant User\n    participant MainChain as ELA Main Chain\n    participant Arbiter as Arbiter Network\n    participant ESC as ESC Sidechain\n\n    User->>MainChain: TransferCrossChainAsset (0x08)\n    MainChain->>MainChain: Lock ELA at genesis address\n    MainChain->>MainChain: BPoS confirmation (2/3+1)\n    Arbiter->>MainChain: SPV bloom filter detects deposit\n    Arbiter->>ESC: Relay tx hash via RPC\n    ESC->>MainChain: Fetch tx + Merkle proof\n    ESC->>ESC: Verify SPV proof against headers\n    ESC->>ESC: Mint ELA to target address\n    ESC--\x3e>User: ELA available on ESC"}),"\n",(0,s.jsx)(i.p,{children:(0,s.jsx)(i.strong,{children:"Step by step:"})}),"\n",(0,s.jsxs)(i.ol,{children:["\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"User sends deposit tx"})," \u2014 a ",(0,s.jsx)(i.code,{children:"TransferCrossChainAsset"}
1)," (type ",(0,s.jsx)(i.code,{children:"0x08"}),") sends ELA to the ESC genesis block address on the main chain, specifying the target ",(0,s.jsx)(i.code,{children:"0x"})," address in the payload"]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"Main chain confirms"})," \u2014 miners include the tx, BPoS validators confirm with 2/3+1 signatures"]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"Arbiter detects"})," \u2014 the arbiter's SPV module monitors the main chain via bloom filters tuned to sidechain genesis addresses. When a matching tx is found, it's stored locally"]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"On-duty arbiter relays"})," \u2014 when the arbiter becomes on-duty, it calls ",(0,s.jsx)(i.code,{children:"sendrechargetransaction"})," on the ESC node with the main chain tx hash"]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"ESC verifies and mints"})," \u2014 the ESC node fetches the tx and Merkle proof from the main chain, verifies it independently via its SPV light client, checks for duplicates, then mints ELA to the target address"]}),"\n"]}),"\n",(0,s.jsx)(i.admonition,{title:"Trust Model",type:"info",children:(0,s.jsxs)(i.p,{children:["Deposits are ",(0,s.jsx)(i.strong,{children:"trustless"})," \u2014 the ESC node independently verifies the SPV proof. The arbiter only notifies; it cannot forge a deposit."]})}),"\n",(0,s.jsx)(i.h2,{id:"withdrawal-flow-esc-to-main-chain",children:"Withdrawal Flow: ESC to Main Chain"}),"\n",(0,s.jsx)(i.mermaid,{value:"sequenceDiagram\n    participant User\n    participant ESC as ESC Sidechain\n    participant Arbiter as Arbiter Network\n    participant MainChain as ELA Main Chain\n\n    User->>ESC: Send ELA to withdraw contract\n    ESC->>ESC: Burn ELA, emit event\n    Arbiter->>ESC: Poll for withdrawals\n    Arbiter->>Arbiter: Construct WithdrawFromSideChain tx\n    Arbiter->>Arbiter: Collect 2/3+1 signatures\n    Arbiter->>MainChain: Submit signed withdrawal tx\n    MainChain->>MainChain: Validate multi-sig\n    MainChain--\x3e>User: ELA at main chain address"}),"\n",(0,s.jsx)(i.p,{children:(0,s.jsx)(i.strong,{children:"Step by step:"})}),"\n",(0,s.jsxs)(i.ol,{children:["\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"User burns ELA on ESC"})," \u2014 sends ELA to the cross-chain contract address, specifying the target main chain address"]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"Arbiter detects"})," \u2014 polls ESC via ",(0,s.jsx)(i.code,{children:"getwithdrawtransactionsbyheight"})," RPC, waits for 6 block confirmations"]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"On-duty arbiter builds tx"})," \u2014 constructs a ",(0,s.jsx)(i.code,{children:"WithdrawFromSideChain"})," (type ",(0,s.jsx)(i.code,{children:"0x07"}),") transaction on the main chain, spending UTXOs from the genesis block address"]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"Multi-sig collection"})," \u2014 the on-duty arbiter broadcasts a proposal to the arbiter network; each arbiter validates and returns its signature; 2/3+1 signatures are required"]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"Main chain confirms"})," \u2014 the signed tx is broadcast and included in a main chain block, releasing ELA from the genesis address to the user"]}),"\n"]}),"\n",(0,s.jsx)(i.admonition,{title:"Trust Model",type:"warning",children:(0,s.jsxs)(i.p,{children:["Withdrawals are ",(0,s.jsx)(i.strong,{children:"semi-trusted"})," \u2014 2/3+1 of the 12 Council-operated arbiters must collude for a fraudulent withdrawal."]})}),"\n",(0,s.jsx)(i.h2,{id:"genesis-block-address",children:"Genesis Block Address"}),"\n",(0,s.jsx)(i.p,{children:"Each sidechain has a unique deposit address on the main chain, derived deterministically from the sidechain's genesis block hash. This address has no known private key \u2014 it functions as a provable escrow controlled only by the arbiter multi-sig."}),"\n",(0,s.jsx)(i.h2,{id:"small-transfer-fast-path",children:"Small Transfer Fast Path"}),"\n",(0,s.jsxs)(i.p,{children:["Transfers below ",(0,s.jsx)(i.co
1de,{children:"SmallCrossTransferThreshold"})," (default: 1 ELA) use a simplified single-signature path where only the on-duty arbiter signs. This is a convenience-vs-security trade-off for low-value transfers."]}),"\n",(0,s.jsx)(i.admonition,{type:"danger",children:(0,s.jsx)(i.p,{children:"A single compromised arbiter can approve fraudulent small withdrawals."})}),"\n",(0,s.jsx)(i.h2,{id:"schnorr-aggregate-signatures",children:"Schnorr Aggregate Signatures"}),"\n",(0,s.jsxs)(i.p,{children:["Introduced at ",(0,s.jsx)(i.code,{children:"SchnorrStartHeight"})," to replace classic M-of-N multi-sig. Produces a single 64-byte signature instead of N individual signatures."]}),"\n",(0,s.jsxs)(i.p,{children:[(0,s.jsx)(i.strong,{children:"Curve:"})," NIST P-256 (secp256r1)"]}),"\n",(0,s.jsx)(i.p,{children:"The protocol runs in three phases:"}),"\n",(0,s.jsxs)(i.ol,{children:["\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"Nonce generation"})," \u2014 each participating arbiter generates a random nonce and computes the corresponding public nonce point ",(0,s.jsx)(i.code,{children:"R_i = k_i * G"})]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"R-value collection"})," \u2014 the on-duty arbiter broadcasts a request; each arbiter responds with its ",(0,s.jsx)(i.code,{children:"(R_x, R_y, P_x, P_y)"}),". After collecting enough responses, the aggregate challenge is computed: ",(0,s.jsx)(i.code,{children:"e = SHA256(R_aggregate || P_aggregate || message)"})]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.strong,{children:"S-value collection"})," \u2014 each arbiter computes its partial signature ",(0,s.jsx)(i.code,{children:"s_i = k_i + e * privateKey_i"})," and returns it. The final signature is ",(0,s.jsx)(i.code,{children:"[R_x || sum(s_i) mod N]"})," (64 bytes)"]}),"\n"]}),"\n",(0,s.jsx)(i.h2,{id:"spv-proof-format",children:"SPV Proof Format"}),"\n",(0,s.jsx)(i.p,{children:"SPV proofs consist of a Merkle path from the transaction to the block header's Merkle root:"}),"\n",(0,s.jsxs)(i.table,{children:[(0,s.jsx)(i.thead,{children:(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.th,{children:"Field"}),(0,s.jsx)(i.th,{children:"Description"})]})}),(0,s.jsxs)(i.tbody,{children:[(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.td,{children:"BlockHash"}),(0,s.jsx)(i.td,{children:"Block containing the transaction"})]}),(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.td,{children:"Height"}),(0,s.jsx)(i.td,{children:"Block height"})]}),(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.td,{children:"Transactions"}),(0,s.jsx)(i.td,{children:"Total transactions in the block"})]}),(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.td,{children:"Hashes"}),(0,s.jsx)(i.td,{children:"Merkle path hashes"})]}),(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.td,{children:"Flags"}),(0,s.jsx)(i.td,{children:"Bit flags for path traversal"})]})]})]}),"\n",(0,s.jsx)(i.p,{children:"Verification rebuilds the partial Merkle tree and compares the computed root against the block header. Includes CVE-2012-2459 protection against duplicate hash attacks."}),"\n",(0,s.jsx)(i.p,{children:"The arbiter's SPV client uses BIP37-style bloom filters (MurmurHash3) to efficiently monitor the main chain for sidechain-related transactions."}),"\n",(0,s.jsx)(i.h2,{id:"failed-deposit-return",children:"Failed Deposit Return"}),"\n",(0,s.jsxs)(i.p,{children:["If a deposit fails on the sidechain (e.g., invalid payload), the arbiter creates a ",(0,s.jsx)(i.code,{children:"ReturnSideChainDepositCoin"})," (type ",(0,s.jsx)(i.code,{children:"0x51"}),") transaction on the main chain, returning ELA to the original sender. This requires the same 2/3+1 multi-sig as withdrawals."]}),"\n",(0,s.jsx)(i.h2,{id:"arbiter-rotation",children:"Arbiter Rotation"}),"\n",(0,s.jsxs)(i.table,{children:[(0,s.jsx)(i.thead,{children:(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.th,{children:"Height Range"}),(0,s.jsx)(i.th,{children:"Arbiter Set"})]})}),(0,s.jsxs)(i.tbody,{children:[(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.td,{children:"Before CRC-Only DPoS"}),(0,s.jsx)(i.td,{children:"5 original cross-chain arbiters"})]}),(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.td,{children:"CRC-Only to BPoS"}),(0,s.jsx)(i.td,{children:"12 Council arbiters"})]}),(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.td,{children:"After BPoS activation"}),(0,s.jsx)(i.td,{children:"Full BPoS validator set"})]})]})]}),"\n",(0,s.jsx)(i.p,{children:"When the on-duty arbiter changes, it processes all pending deposits, withdrawals, NFT operations, and failed deposit returns."}),"\n",(0,s.jsx)(i.h2,{id:"fees",children:"Fees"}),"\n",(0,s.jsxs)(i.p,{children:["Cross-chain fee minimum: ",(0,s.jsx)(i.strong,{children:"10,000 sela"})," (0.0001 ELA) per cross-chain output. The exchange rate between chains is 1:1."]})]})}function h(e={}){const{wrapper:i}={...(0,t.R)(),...e.components};return i?(0,s.jsx)(i,{...e,children:(0,s.jsx)(l,{...e})}):l(e)}},28453(e,i,n){n.d(i,{R:()=>a,x:()=>o});var r=n(96540);const s={},t=r.createContext(s);function a(e){const i=r.useContext(t);return r.useMemo(function(){return"function"==typeof e?e(i):{...i,...e}},[i,e])}function o(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:a(e.components),r.createElement(t.Provider,{value:i},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.