Hyperledger Fabric通道账本权限疑问:能否限制成员访问范围?
Let’s break down your questions one by one to clear up the confusion:
1. Are ledgers fully consistent across all channel members?
Absolutely. Every member of a Hyperledger Fabric channel maintains an identical copy of the channel’s ledger. This is because all channel participants are part of the same consensus process—transactions must be endorsed by sufficient channel members, ordered by the channel’s ordering service, and validated by every peer in the channel before being committed to the ledger. There’s no divergence in the ledger state or transaction history for any valid channel member.
2. Will a transaction from participant 1 to 2 appear in participant 3’s ledger (same channel C), but not in 4-n’s (not in C)?
Exactly right. Here’s why:
- Transactions submitted to channel C are processed only by the members of C. Once ordered, the block containing the transaction is distributed to all peers in C—so participant 3’s peer will receive and commit the block, adding the transaction to their ledger.
- Participants 4 through n aren’t part of channel C, so they have no access to the channel’s block data, ordering service, or peer network for C. Their ledgers will never include any transactions from channel C.
3. Can we restrict participant 2 from recording a transaction between 1 and 3 (within the same channel C)?
You can’t entirely prevent participant 2 from seeing that a transaction occurred (since all channel members receive the same blocks, which include basic transaction metadata like transaction ID and timestamp). However, you can hide the sensitive content of the transaction from participant 2 using Hyperledger Fabric’s Private Data Collections (PDCs).
Here’s how it works:
- Define a private data collection that’s only accessible to participants 1 and 3.
- When 1 and 3 execute their transaction, the sensitive data (like transaction amounts or confidential details) is stored in this private collection instead of the channel’s public ledger.
- All channel members (including 2) will see a hash of the private data in the public ledger (to maintain overall ledger integrity), but only 1 and 3 can retrieve and view the actual private data from their local peers.
This gives you granular privacy control within a channel without needing to create a new channel for every subset of participants.
内容的提问来源于stack exchange,提问作者the_lost_one

