New energy revenue settlement data privacy protection method based on zero knowledge proof
Through the combined design of zero-knowledge proof and hash commitment value, the problems of privacy leakage and multi-party verification of new energy income settlement data on the blockchain are solved, the privacy protection and trusted settlement of sensitive data are achieved, and the system security and efficiency are improved.
Patent Information
- Application Number
- CN202511204284.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-27
- Publication Date
- 2025-10-17
AI Technical Summary
The openness and transparency of existing new energy revenue settlement data on the blockchain leads to the risk of sensitive information leakage, and multi-party verification is difficult, making it difficult to achieve trusted settlement while ensuring data privacy.
A zero-knowledge proof-based method is adopted to generate a hash commitment value by segmenting and noise-adding sensitive data, construct a zero-knowledge proof circuit, generate a zero-knowledge proof π, and verify it on the blockchain. Combined with the ZK-Rollup aggregation optimization algorithm, the privacy protection of sensitive data and multi-party trusted verification are achieved.
It effectively avoids the leakage of sensitive data, ensures the transparency and credibility of settlement results, reduces on-chain verification costs, and improves data compliance and system scalability in new energy settlement scenarios.
Smart Images

Figure CN120805189A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of blockchain data security and cryptography, and particularly relates to a new energy income settlement data privacy protection method based on zero-knowledge proof. BACKGROUND
[0002] New energy power generation, especially distributed photovoltaic and wind power projects, has a complex settlement process of power generation income and involves multiple participants, such as power generation parties, grid agents / operators and terminal power customers. In order to improve the transparency and credibility of the entire settlement process, recording settlement data on the blockchain has become an increasingly concerned solution in the industry.
[0003] However, the existing method of directly chaining new energy income settlement data has significant technical defects. The inherent open and transparent nature of the blockchain ledger results in a serious privacy leakage risk of sensitive income settlement data once it is chained. For example, in the agent operation mode, the income distribution ratio and specific income amount of different customers are commercial secrets. If they are openly chained in plaintext, the financial situation and income details of each customer will be directly exposed, which may lead to the exploration and analysis of competitors, and even result in data misuse. The power generation data is usually recorded in detail in the form of time series, such as daily or hourly power. Directly exposing these fine-grained data will further expose the user's power consumption behavior patterns, which are also sensitive information and should not be openly disclosed in plaintext. Therefore, while ensuring that the settlement results can be verified by multiple parties, effectively protecting these sensitive data from being leaked has become a key technical problem to be solved. SUMMARY
[0004] The present application aims to at least solve one of the technical problems existing in the prior art. To this end, the present application provides a new energy income settlement data privacy protection method based on zero-knowledge proof, which is used to solve the technical problems of privacy risk of sensitive data on the chain, multi-party verification demand and data segment privacy protection in new energy income settlement.
[0005] To achieve the above-mentioned purpose, the technical scheme adopted by the present application is as follows: In a first aspect, a new energy income settlement data privacy protection method based on zero-knowledge proof is provided, comprising: S1, obtaining sensitive data of node income settlement, segmenting the sensitive data to obtain a plurality of hash commitment values; wherein the sensitive data is power generation, income distribution ratio and income and expenditure amount; S2, constructing a zero-knowledge proof-circuit based on the hash commitment values; S3, generating a zero-knowledge proof π using the hash commitment values and the zero-knowledge proof-circuit; S4, verifying the zero-knowledge proof π on the blockchain to obtain a verification result, wherein the verification result is encrypted data provided to multiple parties for settlement; S5, collecting sensitive data of the income settlement of multiple nodes through a ZK-Rollup aggregation optimization algorithm, and generating a single zero-knowledge proof π based on the collected data to improve system security and settlement efficiency.
[0006] Based on the above technical solutions, in the new energy income settlement data privacy protection method provided in the application, the sensitive data is confused and the total amount is preserved through time segmentation and zero-sum disturbance mechanism, and the verifiable on-chain data fingerprint is constructed based on the anti-quantum hash commitment, thereby avoiding the information loss risk of the traditional data desensitization scheme. At the same time, the data consistency, rationality of combination and correctness of result are automatically checked through the three-layer zero-knowledge verification circuit, effectively eliminating the data security hazards of multi-party cooperation; finally, the on-chain verification cost is compressed to the constant level based on the batch proof technology, forming a full closed loop process from privacy protection to verifiable settlement, which guarantees the safety of business secrets while achieving efficient distributed verification, significantly improving the data compliance and system scalability in the multi-subject new energy settlement scenario.
[0007] In combination with the first aspect, in a possible implementation manner, the sensitive data is processed by segmentation, including: The power generation amount in the sensitive data is divided into a plurality of data segments according to a fixed time period; A random noise disturbance value is added to each data segment; wherein the last noise disturbance value is the opposite of the sum of all noise disturbance values; Hash calculation is performed on each data segment after adding noise to generate corresponding hash commitment values.
[0008] In combination with the first aspect, in a possible implementation manner, the hash calculation adopts a hash function resistant to quantum attacks; wherein the anti-quantum hash function includes a post-quantum secure algorithm based on SHA-3 or Keccak.
[0009] In combination with the first aspect, in a possible implementation manner, the zero-knowledge proof-circuit is constructed, including: Verifying the power generation data consistency, the income distribution proportion correctness and the income distribution result calculation accuracy as the circuit logic of the zero-knowledge proof-circuit; Defining the sensitive data as the secret input of the zero-knowledge proof-circuit; Defining the public data as the public input of the zero-knowledge proof-circuit, wherein the public data is the hash commitment value, the hash salt value and the number of hash commitment values on the chain.
[0010] In combination with the first aspect, in a possible implementation manner, the power generation data consistency is a consistency result obtained by verifying, after recalculating a hash value of the data segment and the hash salt value, the hash commitment value on the chain. The revenue distribution proportion correctness is a correctness result obtained by verifying, after explicitly summing the revenue distribution proportion, a pre-threshold value. The revenue distribution result calculation accuracy is an accuracy result obtained by verifying, after calculating the revenue amount that should be distributed to each party according to the power generation and the revenue distribution proportion, the income and expenditure amount.
[0011] In combination with the first aspect, in a possible implementation manner, verifying the zero-knowledge proof π on the blockchain includes: The zero-knowledge proof π is submitted to a verification module of a target blockchain; wherein the target blockchain includes a public chain platform supporting a smart contract or a consortium chain platform supporting a chain code; Zero-knowledge proof verification logic is executed through the smart contract or the chain code of the target blockchain.
[0012] In combination with the first aspect, in a possible implementation manner, the verification result is a confirmation that the power generation data is not tampered with, the revenue distribution proportion meets the agreement, and the revenue distribution result calculation is correct.
[0013] In combination with the first aspect, in a possible implementation manner, the hash commitment value is stored on the blockchain and used for verifying the power generation data consistency.
[0014] Secondly, a new energy revenue settlement data privacy protection device based on zero-knowledge proof is provided, which includes a communication unit and a processing unit. The communication unit is configured to obtain sensitive data of node revenue settlement, and configured to submit a zero-knowledge proof π to a blockchain smart contract or a verification service. The processing unit is configured to preprocess the sensitive data of node revenue settlement to obtain a hash commitment value, construct a zero-knowledge proof-circuit based on the hash commitment value, generate a zero-knowledge proof π by using the hash commitment value and the zero-knowledge proof-circuit, and verify the zero-knowledge proof π on the blockchain to obtain a multi-party settlement verification result that does not leak sensitive data. The device integrates security design against quantum attacks, multi-chain compatibility, and ZK-Rollup aggregation optimization measures to improve the system security and settlement efficiency of the device.
[0015] In a third aspect, the present application provides a new energy income settlement data privacy protection device based on zero-knowledge proof, comprising: a processor and a storage medium; the storage medium comprises instructions, and the processor is configured to execute the instructions to implement the method described in the first aspect and any possible implementation manner of the first aspect. The new energy income settlement data privacy protection device based on zero-knowledge proof can be an electronic device or a chip in an electronic device.
[0016] In a fourth aspect, the present application provides a new energy income settlement data privacy protection system based on zero-knowledge proof, comprising: a data preprocessing module, a zero-knowledge proof construction module and a settlement verification module; wherein the data preprocessing module is configured to obtain sensitive data of node income settlement, and obtain a hash commitment value after preprocessing; the zero-knowledge proof construction module is configured to construct a zero-knowledge proof-circuit based on the hash commitment value, and generate a zero-knowledge proof π by using the hash commitment value and the zero-knowledge proof-circuit; and the settlement verification module is configured to verify the zero-knowledge proof π on a block chain to obtain a multi-party settlement verification result without leaking sensitive data.
[0017] In a fifth aspect, the present application provides a computer readable storage medium, and the computer readable storage medium stores instructions, when the instructions are executed on a new energy income settlement data privacy protection device based on zero-knowledge proof, the new energy income settlement data privacy protection device based on zero-knowledge proof executes the method described in the first aspect and any possible implementation manner of the first aspect.
[0018] In a sixth aspect, the present application provides a computer program product comprising instructions, when the computer program product is executed on a new energy income settlement data privacy protection device based on zero-knowledge proof, the new energy income settlement data privacy protection device based on zero-knowledge proof executes the method described in the first aspect and any possible implementation manner of the first aspect.
[0019] Compared with the prior art, the present application has the following advantages: 1. By combining the design of "data segmentation confusion + zero-knowledge proof", only the hash commitment value is stored on the chain instead of the sensitive plaintext, which fundamentally avoids the risk of leakage of data such as power generation and income distribution ratio. At the same time, the zero-knowledge proof-circuit supports the participation of power generation, power grid agent, supervision party and other parties to independently verify the correctness of the settlement result without obtaining the original data. The circuit verifies the consistency of the power generation with the commitment on the chain, the compliance of the distribution ratio sum and the accuracy of the account distribution calculation, to ensure that the settlement process is traceable and tamper-proof. This mechanism breaks the traditional contradiction between "privacy protection" and "trusted verification", so that multiple parties can reach a consensus in a blockchain environment without mutual trust, and improve the transparency and credibility of new energy income settlement.
[0020] 2. Three-layer obfuscation mechanism of "segmentation + noise injection + hash": The original power generation is divided into segments according to time period or value interval, and the single segment data value is disturbed by injecting random noise, while the noise accumulation sum is zero to maintain the total power unchanged. This prevents the exposure of user power consumption behavior patterns and ensures that the total data can be used for settlement verification. For example, after the power segment is divided by day and the noise is added, the hash commitment published on the chain can only verify the data integrity and cannot restore the real value. The balanced design of each segment of noise ensures that the total power generation is consistent with the original data, avoiding distortion of settlement data due to privacy protection, and meeting the dual needs of "privacy protection" and "data credibility" for new energy settlement.
[0021] 3. Anti-quantum hash algorithms such as SHA-3 and zero-knowledge proof frameworks such as STARK are used to avoid quantum computing threats, while the proof verification module can be deployed on public chains such as Ethereum and Polygon, and consortium chains such as Fabric. By aggregating nodes to generate batch zero-knowledge proofs, the verification cost of N settlement is reduced from O(N) to O(1), ensuring the security of the scheme in future technology environment, the universality in diversified chain environment, and the settlement efficiency and scalability in large-scale scenarios. BRIEF DESCRIPTION OF DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed in the embodiment or prior art description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0023] Figure 1 A system architecture diagram of a new energy income settlement data privacy protection system provided by an embodiment of the present application.
[0024] Figure 2 A flowchart of a new energy income settlement data privacy protection method provided by an embodiment of the present application.
[0025] Figure 3 A power generation data segmentation obfuscation processing flowchart provided by an embodiment of the present application.
[0026] Figure 4 A benefit allocation zero-knowledge proof-circuit logic framework diagram provided by an embodiment of the present application.
[0027] Figure 5 A structure diagram of a new energy income settlement data privacy protection device based on zero-knowledge proof provided by an embodiment of the present application.
[0028] Figure 6A hardware structure diagram of a new energy income settlement data privacy protection device based on zero-knowledge proof is provided for an embodiment of the application. DETAILED DESCRIPTION
[0029] In the description of the present application, unless otherwise specified, " / " means "or", for example, A / B can mean A or B. "And / or" in this paper is only a description of the relationship between the associated objects, which means that there can be three relationships, for example, A and / or B, which can mean: A exists alone, A and B exist together, and B exists alone. In addition, "at least one" means one or more, and "multiple" means two or more. "First", "second", etc. do not limit the quantity and execution order, and "first", "second", etc. do not necessarily mean different.
[0030] It should be noted that in the present application, "exemplary" or "for example" means to serve as an example, illustration or description. Any embodiment or design scheme described as "exemplary" or "for example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the use of "exemplary" or "for example" is intended to present the relevant concept in a specific manner.
[0031] The new energy income settlement data privacy protection method based on zero-knowledge proof provided by the embodiments of the present application can be applied to Figure 1 The new energy income settlement data privacy protection system based on zero-knowledge proof shown in the figure. As Figure 1 The privacy protection system 100 includes a data acquisition device 10, an edge server 20, a blockchain network node 30 and a data storage 40.
[0032] Among them, The data acquisition device 10 is deployed at the new energy power generation site or the data interaction point, and is used to collect the hourly / daily power generation data of the power generation party in real time, and obtain the income distribution proportion and specific amount of original sensitive data of the power grid agent and other participants. The data acquisition device 10 transmits the original sensitive data to the edge server 20 through the transmission channel.
[0033] The edge server 20 is used for receiving original sensitive data and performing segmented processing on the sensitive data: dividing the sensitive data into multiple segments according to a time period, adding random noise disturbance to each segment, and adjusting the value of a subsequent segment to ensure that the cumulative effect of all disturbance values on the total sum is zero; calculating a hash commitment value for each data segment after adding noise; and constructing a zero-knowledge proof-circuit, taking the original power generation data segment, the noise correction value, the income distribution ratio and the calculated income amount of each party as secret inputs, and taking the hash commitment value and the like as public inputs, to generate a zero-knowledge proof π. In addition, the edge server 20 implements ZK-Rollup aggregation optimization, generates a single zero-knowledge proof π for the settlement data of multiple periods or multiple power plants in batches, so as to reduce the on-chain verification overhead.
[0034] The blockchain network node 30 is connected with the edge server 20, and is used for receiving the zero-knowledge proof π and the hash commitment value generated by the edge server 20. The blockchain network node 30 is deployed on a blockchain network, and performs on-chain verification on the zero-knowledge proof π, checks the consistency of the power generation with the on-chain commitment, the compliance of the distribution ratio and the correctness of the account settlement calculation. Once the verification is passed, the blockchain network node 30 stores the settlement result on the chain for evidence, and feeds back the verification state to the edge server 20, to form a settlement closed loop.
[0035] The data storage 40 is used for storing the power generation data and the proof-related parameters after privacy protection processing. The data storage 40 is used for encrypted storage of original power generation data segments, noise correction values and the like sensitive information; is also used for public storage of on-chain hash commitment values and auxiliary information; buffers intermediate state data of the zero-knowledge proof-circuit and public parameters of the hash algorithm, and provides data calling support for real-time calculation of the edge server 20.
[0036] To solve the technical problems of privacy leakage of sensitive data on the chain, difficulty in multi-party verification of settlement results and insufficient privacy processing of segmented power generation data in the prior art, the embodiment of the present application provides a method for privacy protection of new energy income settlement data based on zero-knowledge proof
[0037] The method for privacy protection of new energy income settlement data based on zero-knowledge proof includes: obtaining original new energy income settlement sensitive data, and obtaining a hash commitment value after preprocessing; constructing a zero-knowledge proof-circuit based on the hash commitment value; generating a zero-knowledge proof π by using the hash commitment value and the zero-knowledge proof-circuit; and verifying the zero-knowledge proof π on a blockchain to obtain a multi-party settlement verification result without leaking sensitive data. Based on this, the present application can: solve the privacy risk of sensitive data on the chain; meet the demand for multi-party verification of settlement results; realize privacy processing of segmented power generation data; and improve system security and settlement efficiency.
[0038] As shown in Figure 2 The method for privacy protection of new energy income settlement data based on zero-knowledge proof provided by the embodiment of the present application includes: S1, obtain sensitive data of node income settlement, segment the sensitive data, and obtain a plurality of hash commitment values; wherein the sensitive data is power generation, income distribution ratio and income and expenditure amount; S2, based on the hash commitment value, construct zero-knowledge proof-circuit; S3, generate zero-knowledge proof π by using the hash commitment value and zero-knowledge proof-circuit; S4, verify the zero-knowledge proof π on the blockchain to obtain a verification result, wherein the verification result is encrypted data provided to multiple parties for settlement; S5, collect sensitive data of income settlement of multiple nodes by ZK-Rollup aggregation optimization algorithm, and generate a single zero-knowledge proof π based on the collected data, and improve system security and settlement efficiency.
[0039] Based on the above technical solution, the new energy income settlement data privacy protection method based on zero-knowledge proof provided by the application realizes sensitive data confusion and total amount preservation through time segmentation and zero-sum disturbance mechanism. Specifically, the original new energy power generation and other sensitive data are divided into fragments according to fixed time periods, random noise disturbance that can be offset is added to each fragment and the total sum is ensured to be unchanged, then hash calculation is performed to generate commitment value, so that only the hash commitment value of the commitment value is stored on the chain. This method combines anti-quantum hash commitment to build a verifiable on-chain data fingerprint, effectively avoiding the information loss risk that may be caused by traditional data desensitization scheme. At the same time, through three-layer zero-knowledge verification circuit, data consistency, rationality of segmentation and correctness of result are automatically checked. Specifically, a zero-knowledge proof-circuit is constructed, which can verify the consistency of power generation data and on-chain commitment, the sum of income distribution ratio meets the expectation and agreement, and the calculation correctness of income distribution result, so as to effectively eliminate the data security hidden danger of multi-party cooperation. Finally, based on batch proof technology, the on-chain verification cost is compressed to constant level, and through the idea of ZK-Rollup, multiple settlement data are aggregated to generate a single zero-knowledge proof, realizing batch verification, reducing the on-chain verification cost of N settlement from O(N) to O(1), forming a full closed loop process from privacy protection to verifiable settlement. The application guarantees the safety of business secrets while achieving efficient distributed verification, significantly improving data compliance and system scalability in the multi-subject new energy settlement scenario.
[0040] In addition, in the embodiments of the present application, the preprocessing process of S1 aims to privacy enhancement processing, so that sensitive data is not directly exposed in plaintext information in on-chain storage and verification. Among them, the random noise disturbance is similar to the noise injection in differential privacy, which blurs the real power value of each time segment without affecting the accuracy of the total power generation. The hash commitment value as the encrypted fingerprint of the data has anti-collision property and one-wayness, so that the plaintext of the original sensitive data cannot be inferred from the commitment value on the chain. The construction of the zero-knowledge proof-circuit in S2 requires deep knowledge of cryptography and professional circuit compilation tools to ensure the efficiency and security of the circuit. The generation of zero-knowledge proof π in S3 is a key link of privacy protection, which enables the prover to prove to the verifier that he has secret information that meets certain rules without disclosing the sensitive data itself. The efficiency of the on-chain verification process in S4 is extremely high and does not depend on the transmission of plaintext of sensitive data, thereby realizing the transparency and multi-party trusted verification of the settlement result, while ensuring data privacy.
[0041] In a possible implementation manner of the embodiments of the present application, in combination with Figure 2 As shown in the figure, the above S1 can be implemented by the following S11, S12 and S13, which will be described in detail below. Figure 3 S11, the power generation in the sensitive data is divided into several data segments according to a fixed time period.
[0042] In some implementation manners, data segmentation is to divide the original power generation data (for example, the total power generation of a month) into smaller fixed time periods (for example, days) for fine-grained division. For example, if the original data is the total power generation of a photovoltaic power station in a month, it can be divided into 30 daily power generation data segments. In this way, the range and granularity of information disclosed by each data segment can be limited, thereby improving privacy and avoiding exposure of the entire data of a long time span.
[0043] For example, the original power generation data is the total power generation of a month, which can be divided into 30 segments according to the daily power generation. For example, the power generation of the i-th day .
[0044] S12, a random noise disturbance value is added to each data segment.
[0045] In some implementations, after the data segmentation S11 is completed, a randomly generated noise value is added to each data segment (e.g., daily power generation value). This noise value can be positive or negative, and its amplitude is usually within a pre-set small threshold range. The injection of such noise aims to obscure the true value of each data segment and further hide its precise details. The key is that all added noise values should cancel each other out after accumulation, i.e., the sum is zero, to ensure that the final total power generation data remains consistent with the original value and does not affect the accuracy of macro settlement.
[0046] It should be noted that this noise injection method is similar to the mechanism in differential privacy, which maintains the statistical properties of the overall data while not revealing the precise information of the data.
[0047] For example, a random noise is added to each segment to obtain . The sum of all noise values is designed to be zero, for example, by adjusting the noise of the last segment to offset the accumulated bias of the previous segments, to ensure .
[0048] S13, hash calculation is performed on each data segment after adding noise to generate the corresponding hash commitment value.
[0049] In some implementations, after adding noise to the data segments in S12, a secure cryptographic hash function is used to perform hash calculation on each noise-added data segment. This will generate a fixed-length hash value, i.e., the corresponding hash commitment value. The hash commitment value serves as an encrypted fingerprint of the data segment, with one-wayness (the original value cannot be retrieved from the hash value) and collision resistance (it is difficult to find different inputs that generate the same hash value). Ultimately, these hash commitment values will be stored on the blockchain as privacy-protected data, along with necessary auxiliary information (such as segment identification, hash salt value, etc.).
[0050] It should be noted that this step is crucial to ensuring the privacy of data on the chain. Even if the data on the chain is public, attackers cannot restore the noise-added segment value from the hash commitment value, let alone restore the original sensitive data.
[0051] For example, the hash value of each is calculated as its hash commitment value on the chain. The original and are saved offline by the data owner for subsequent generation of zero-knowledge proofs.
[0052] In one possible implementation, in combination with Figure 2 , such as Figure 4As shown, the hash calculation above adopts a hash function resistant to quantum attacks; wherein the quantum-resistant hash function includes a post-quantum secure algorithm based on SHA-3 or Keccak.
[0053] In a possible implementation manner, in combination with Figure 2 As shown, the S2 can be implemented through the following S21, S22 and S23, which are specifically described as follows: Figure 4 As shown, the S2 can be implemented through the following S21, S22 and S23, which are specifically described as follows: S21, taking the consistency of the verification power generation data, the correctness of the income distribution ratio, and the accuracy of the income distribution result calculation as the circuit logic of the zero-knowledge proof-circuit.
[0054] In some implementation manners, the core of the present step is to ensure the authenticity of the power generation data, the rationality of the distribution ratio, and the accuracy of the final distribution amount, and to convert this goal into a series of arithmetic operations and logic gates that can be executed by a computer program. These operations and logic gates will eventually be compiled into arithmetic circuits in the form of R1CS (Rank 1 Constraint System). For example, a multiplication operation (power generation multiplied by ratio) will be represented as a constraint form of .
[0055] It should be noted that this process is the basis of zero-knowledge proof technology, which abstracts the verification process of business logic into mathematical problems that can be processed by cryptographic systems.
[0056] S22, defining the sensitive data as secret inputs of the zero-knowledge proof-circuit.
[0057] In some implementation manners, secret inputs are sensitive data that need to be possessed by the prover but cannot be directly known by the verifier during the proof process. For the new energy income settlement scene, these secret inputs usually include: original power generation data segments, correction values for noise cancellation, specific income distribution ratios of each party, and final income amounts of each party calculated based on these secret data. These data are kept off-chain by the data owner and input into the circuit as private credentials when generating the zero-knowledge proof π.
[0058] For example, if the original power generation of a power station is divided into , the corresponding noise is , the income distribution ratio is , and the income amount of each party is , M is the number of income parties, and these will be used as secret inputs.
[0059] S23, define the public data as the public input of the zero-knowledge proof-circuit, wherein the public data is the hash commitment value, the hash salt value and the number of hash commitment values publicly stored on the chain.
[0060] In some implementations, the public input is the public data known to both the prover and the verifier during the proof process, which is usually stored on the blockchain. For the new energy revenue settlement scenario, the public input usually includes the hash commitment value, the hash salt value, the segment identification information, the random number generation seed and the data segment size and number information publicly stored on the chain after preprocessing by S1. These public inputs enable the verifier to verify the correctness of the calculation by comparing the zero-knowledge proof π and these public information without accessing the secret input.
[0061] For example, the hash commitment values H( ), H( ),..., H( ) publicly stored on the chain will serve as the public input.
[0062] In a possible implementation, the zero-knowledge proof verification logic described above can be implemented by S31, S32 and S33 as follows, which will be described in detail below: S31, the power generation data consistency is the consistency result obtained by verifying the hash value recalculated from the data segment and its hash salt value with the hash commitment value on the chain.
[0063] In some implementations, the circuit recalculates the hash value of the data segment according to the secret input and the public input, and compares the recalculated hash value with the hash commitment value publicly stored on the chain. If the two are inconsistent, the verification fails, indicating that the original power generation data may have been tampered with.
[0064] It should be noted that this is the first line of defense to ensure the integrity and authenticity of the data for chain settlement.
[0065] S32, the correct proportion of the revenue distribution is the correctness result obtained by verifying the sum of the explicit revenue distribution proportions with the pre-set threshold value.
[0066] In some implementations, the circuit first determines the revenue distribution proportions, which are agreed upon by the parties in advance and embedded in the circuit or as part of the public input. The circuit calculates the sum of all these revenue distribution proportions, and verifies this sum with the pre-agreed target value (e.g. 1, or 100%). If the sum does not conform to the agreed value, or any one proportion does not conform to the pre-set constant, the proof is invalid. This guarantees the fairness and transparency of the revenue distribution, preventing the proportions from being tampered with privately.
[0067] It should be pointed out that this logic ensures that the rules on profit distribution are not violated.
[0068] S33. The accuracy of the profit distribution calculation results is the accuracy result obtained by calculating the profit amount to be allocated to each party based on the power generation and profit distribution ratio, and verifying it with the income and expenditure amounts.
[0069] In some implementations, the circuit recalculates the profit amounts to be distributed to each party based on the secretly input power generation data and profit distribution ratios. These internally calculated profit amounts are rigorously compared with the secretly input distribution results. The proof is considered successful only if all calculated results are identical to the provided results.
[0070] It should be noted that this is a key verification step to ensure the correctness of the final flow of funds, avoiding calculation errors or fraud.
[0071] In one possible implementation, the zero-knowledge proof π is an output result obtained by performing arithmetic constraint calculation on a zero-knowledge proof circuit after receiving a secret input and a public input.
[0072] In some implementations, the core output of a ZKP system is a zero-knowledge proof, π, a compact and unforgeable cryptographic credential. It contains no information about the secret input, but allows the verifier to quickly verify that the secret input satisfies all constraints of the circuit. The zero-knowledge proof π is typically a very short cryptographic string that can be efficiently transmitted and verified on the blockchain.
[0073] In one possible implementation, the method for obtaining the multi-party settlement verification result can be specifically implemented through the following S41, S42 and S43, which are specifically described below: S41, confirming that the power generation data has not been tampered with; In some implementations, when the on-chain verification process is passed, the system determines or is convinced that the submitted power generation data is consistent with the hash commitment value stored on the chain after calculation, and no tampering has occurred, thereby ensuring the integrity and authenticity of the data.
[0074] S42 Confirmation that the profit distribution ratio is in compliance with the agreement; In some implementations, after on-chain verification is passed, the system determines or is convinced that the profit distribution ratios used by each party in the settlement process are exactly the same as the ratios agreed in advance and written into the zero-knowledge proof-circuit, and that the sum of all ratios is as expected and has not been modified without authorization.
[0075] S43 confirms that the profit distribution result is calculated correctly.
[0076] In some implementations, when the on-chain verification is passed, the system determines or is convinced that the final revenue sharing amount of each participant is indeed calculated according to the real power generation data and the correct revenue sharing ratio, and is consistent with the sharing result, without any calculation error or fraudulent behavior.
[0077] In one possible implementation, the zero-knowledge proof π can be verified by the following S51 and S52, which will be described in detail as follows: S51, submit the zero-knowledge proof π to a verification module of a target blockchain; wherein the target blockchain includes a public chain platform supporting a smart contract or a consortium chain platform supporting a chain code; Wherein the zero-knowledge proof π and the public input data are designed to be submitted to the verification module of a plurality of target blockchain platforms.
[0078] In some implementations, the target blockchain can include a public chain platform supporting a smart contract, such as Ethereum or Polygon, at this time, the proof verification module can execute the verification algorithm of the zero-knowledge succinct non-interactive argument of knowledge (ZK-SNARK) by deploying the smart contract code.
[0079] It should be noted that the target blockchain can also be a consortium chain platform supporting a chain code or a plug-in form, such as Fabri, and the verification logic can be integrated into the chain code or the plug-in. Since the design of the zero-knowledge proof π itself is relatively independent of the underlying blockchain environment, as long as the target blockchain environment provides basic support for cryptographic primitives, such as hash calculation and elliptic curve operation, the present scheme can be transplanted and deployed.
[0080] S52, execute the zero-knowledge proof verification logic through the smart contract or the chain code of the target blockchain.
[0081] Wherein the verification module of the target blockchain is designed to be able to execute the zero-knowledge proof verification logic.
[0082] In some implementations, for a public chain platform supporting a smart contract, such as Ethereum or Polygon, the zero-knowledge proof verification logic can be executed through the smart contract code deployed on the chain. The smart contract will receive the submitted zero-knowledge proof π and the public input data, and run the verification algorithm on the chain to confirm the validity of the proof.
[0083] It should be noted that for a consortium chain or a permissioned chain environment such as Fabric, the zero-knowledge proof verification logic can be integrated and executed in the form of a chain code or a plug-in.
[0084] In a possible implementation manner, the hash commitment value is stored on the blockchain as a basis for subsequent verification of correctness of the income distribution ratio. The hash commitment value has anti-collision and one-wayness, and the original sensitive data plaintext cannot be deduced from the hash commitment value.
[0085] As another preferred embodiment, the application also collects several sensitive data of income settlement through a ZK-Rollup aggregation optimization algorithm; the ZK-Rollup aggregation optimization algorithm can collect sensitive data of multiple nodes to generate a single zero-knowledge proof π, since the single zero-knowledge proof π contains all collected settlement items, the on-chain verification cost of N settlement is reduced, and the settlement efficiency is improved.
[0086] It should be noted that the node here can be a management center of a time period or each power generation device.
[0087] The above describes the scheme of the embodiments of the application mainly from the perspective of device implementation. It can be understood that each device, for example, the new energy income settlement data privacy protection device based on zero-knowledge proof, contains at least one of the corresponding hardware structure and software module for implementing each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the application can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the application.
[0088] The embodiments of the application can divide the new energy income settlement data privacy protection device based on zero-knowledge proof into functional units according to the above method examples, for example, each functional unit can be divided according to each function, or two or more functions can be integrated in one processing unit. The integrated unit can be realized in the form of hardware or software functional unit. It should be noted that the division of units in the embodiments of the application is illustrative, and is only a logical functional division. Actual implementation can have another division manner.
[0089] In the case of using integrated units, Figure 5 A possible structure schematic diagram of the new energy income settlement data privacy protection device based on zero-knowledge proof (denoted as privacy protection device 50) involved in the above embodiments is shown, which includes a processing unit 501 and a communication unit 502, and can also include a storage unit 503. Figure 5The illustrated structural diagram can be used to illustrate the structure of the privacy protection device involved in the above-embodiment.
[0090] When Figure 5 The illustrated structural diagram is used to illustrate the structure of the privacy protection device involved in the above-embodiment, the processing unit 501 is used to control and manage the action of the privacy protection device, the communication unit 502 is used for the privacy protection device to communicate with other devices, and the storage unit 503 is used to store the program code and data of the privacy protection device.
[0091] For example, the communication unit 502 is used to obtain sensitive data of node income settlement and submit zero-knowledge proof π to a blockchain smart contract or a verification service; the processing unit 501 is used to preprocess the sensitive data of node income settlement to obtain a hash commitment value; construct a zero-knowledge proof-circuit based on the hash commitment value; generate zero-knowledge proof π by using the hash commitment value and the zero-knowledge proof-circuit; verify the zero-knowledge proof π on the blockchain to obtain a multi-party settlement verification result that does not leak sensitive data; and integrate security design against quantum attacks, multi-chain compatibility, and ZK-Rollup aggregation optimization measures to improve the system security and settlement efficiency of the privacy protection device.
[0092] In a possible implementation manner, the processing unit 501 is further used to perform segmented processing on the sensitive data: divide the sensitive data into multiple segments according to a time period, add random noise disturbance to each segment, and adjust the value of a subsequent segment to ensure that the cumulative effect of all disturbance values on the total sum is zero; calculate the hash commitment value of each data segment after adding noise; construct a zero-knowledge proof-circuit, take the original power generation data segment, the noise correction value, the income distribution ratio, and the calculated income amount of each party as secret inputs, and take the hash commitment value and the like as public inputs, and generate zero-knowledge proof π.
[0093] In a possible implementation manner, the communication unit 502 is further used to receive the zero-knowledge proof π and the hash commitment value generated by the edge server, and the processing unit 501 is further used to perform on-chain verification of the zero-knowledge proof π, and check the consistency of the power generation and the on-chain commitment, the compliance of the distribution ratio, and the correctness of the account distribution calculation.
[0094] The processing unit 501 can be a processor or a controller, and the communication unit 502 can be a communication interface, a transceiver, a transceiver, a transceiver circuit, a transceiver device, etc. The communication interface is collectively referred to, and can include one or more interfaces. The storage unit 503 can be a memory. When the privacy protection device 50 is a chip, the processing unit 501 can be a processor or a controller, and the communication unit 502 can be an input interface and / or an output interface, a pin or a circuit, etc. The storage unit 503 can be a storage unit (for example, a register, a cache, etc.) within the chip, or a storage unit (for example, a read-only memory, a random access memory) located outside the chip.
[0095] The communication unit can also be referred to as a transceiver unit. The antenna and control circuit with transceiver function in the privacy protection device 50 can be regarded as the communication unit 502 of the privacy protection device 50, and the processor with processing function can be regarded as the processing unit 501 of the privacy protection device 50. Optionally, the device for realizing the receiving function in the communication unit 502 can be regarded as a communication unit, which is used to execute the receiving steps in the embodiments of the application, and the communication unit can be a receiver, a receiver, a receiving circuit, etc. The device for realizing the sending function in the communication unit 502 can be regarded as a sending unit, which is used to execute the sending steps in the embodiments of the application, and the sending unit can be a transmitter, a sender, a sending circuit, etc.
[0096] Figure 5 The integrated units in the above embodiments can be stored in a computer readable storage medium if they are realized in the form of software function modules and sold or used as independent products. Based on such understanding, the technical solutions of the embodiments of the application can be embodied in the form of software product, and the computer software product is stored in a storage medium, including a plurality of instructions for causing a computer device or a processor to execute all or part of the steps of the methods described in the embodiments of the application. The storage medium storing the computer software product includes a U disk, a mobile hard disk, a read-only memory, a random access memory, a magnetic disk or an optical disk, and various media that can store program codes.
[0097] Figure 5 The units in the above embodiments can also be referred to as modules, for example, the processing unit can be referred to as a processing module. The embodiments of the application also provide a hardware structure diagram of a new energy income settlement data privacy protection device based on zero-knowledge proof (referred to as privacy protection device 60), which is shown in Figure 6 The privacy protection device 60 includes a processor 601, and optionally further includes a memory 602 connected with the processor 601.
[0098] In the first possible implementation, referring to Figure 6The privacy protection apparatus 60 further includes a transceiver 603. The processor 601, the memory 602, and the transceiver 603 are connected through a bus. The transceiver 603 is configured to communicate with other devices or communication networks. Optionally, the transceiver 603 can include a transmitter and a receiver. The device in the transceiver 603 for implementing the receiving function can be regarded as a receiver, and the receiver is configured to perform the steps of receiving in the embodiments of the present application. The device in the transceiver 603 for implementing the sending function can be regarded as a transmitter, and the transmitter is configured to perform the steps of sending in the embodiments of the present application.
[0099] Based on the first possible implementation manner, Figure 6 The structural schematic diagram shown can be used to show the structure of the privacy protection apparatus involved in the above embodiments.
[0100] In the privacy protection apparatus 60, Figure 6 The system chip in the privacy protection apparatus can also be shown. In this case, the actions performed by the privacy protection apparatus can be implemented by the system chip, and the specific actions performed can be referred to in the above, and will not be described herein again.
[0101] In the implementation process, each step in the method provided by the embodiment can be completed by the integrated logic circuit of hardware in the processor or the instruction in the form of software. The steps of the method disclosed in the embodiment of the present application can be directly embodied as the execution completed by the hardware processor, or the execution completed by the combination of hardware and software modules in the processor.
[0102] The processor in the present application can include but is not limited to at least one of the following: a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a microcontroller (MCU), or an artificial intelligence processor, and various computing devices running software, each of which can include one or more cores for executing software instructions to perform operations or processing. The processor can be a separate semiconductor chip, or can be integrated with other circuits as a semiconductor chip, for example, can be integrated with other circuits to form a SoC (system on chip), or can be integrated as a built-in processor in an ASIC. The ASIC integrated with the processor can be packaged separately or packaged together with other circuits. In addition to including cores for executing software instructions to perform operations or processing, the processor can further include necessary hardware accelerators, such as field programmable gate arrays (FPGAs), PLDs (programmable logic devices), or logic circuits implementing special logic operations.
[0103] The memory in the embodiments of the present application can include at least one of the following types: a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, and can also be an electrically erasable programmable read-only memory (EEPROM). In some scenarios, the memory can also be a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and capable of being accessed by a computer, but is not limited thereto.
[0104] The embodiments of the present application also provide a computer readable storage medium including instructions, which, when executed on a computer, cause the computer to perform any of the above methods.
[0105] The embodiments of the present application also provide a computer program product including instructions, which, when executed on a computer, cause the computer to perform any of the above methods.
[0106] The embodiments of the present application also provide a chip including a processor and an interface circuit, the interface circuit being coupled with the processor, the processor being configured to execute computer programs or instructions to implement the above method, and the interface circuit being configured to communicate with other modules outside the chip.
[0107] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be accessed by a computer or data storage device including one or more servers, data centers, etc. integrated with the medium. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.
[0108] Although the application has been described in connection with various embodiments thereof, it will be understood that the application is capable of further modifications and that this application is intended to cover any and all such variations, using the scope of the claims. In the claims, the term comprising does not exclude the presence of other elements or steps than those claimed. The term substituate does not exclude the presence of additional such substituate than those claimed. The term "consisting essentially of" does not exclude the presence of additional substituate that do not materially affect the basic and novel characteristics of the application. The term "a" or "an" does not exclude the presence of more than one, unless otherwise stated. A single processor or other unit can fulfil the functions of several items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage.
[0109] Although the application has been described in connection with specific embodiments thereof, it will be understood that it is capable of further modifications and this application is intended to cover any and all such variations, using the scope of the claims. The disclosure of the present application is directed to all novel and nonobvious combinations and subcombinations of the various elements described. In particular, this application contemplates that in some embodiments, one or more of the following features can be implemented:
Claims
1. A privacy protection method for new energy revenue settlement data based on zero-knowledge proof, characterized in that: include: Acquire sensitive data related to node revenue settlement, segment the sensitive data, and obtain several hash commitment values; the sensitive data includes power generation, revenue distribution ratio, and revenue and expenditure amounts; Constructing a zero-knowledge proof circuit based on the hash commitment value; Generate a zero-knowledge proof π using the hash commitment value and the zero-knowledge proof-circuit; The zero-knowledge proof π is verified on the blockchain to obtain a verification result, wherein the verification result is encrypted data provided to multiple parties for settlement.
2. The privacy protection method for new energy income settlement data based on zero-knowledge proof according to claim 1 is characterized in that: Also includes: The sensitive data of revenue settlement of multiple nodes is collected through the ZK-Rollup aggregation optimization algorithm, and a single zero-knowledge proof π is generated based on the collected data.
3. The privacy protection method for new energy income settlement data based on zero-knowledge proof according to claim 1 is characterized in that: The sensitive data is segmented and processed, including: Dividing the power generation in the sensitive data into a plurality of data segments according to a fixed time period; Adding a random noise disturbance value to each of the data segments; Perform hash calculation on each noisy data fragment to generate the corresponding hash commitment value.
4. The method for protecting privacy of new energy income settlement data based on zero-knowledge proof according to claim 3 is characterized in that: The hash calculation adopts a hash function that is resistant to quantum attacks; wherein the quantum-resistant hash function includes a post-quantum security algorithm based on SHA-3 or Keccak.
5. The privacy protection method for new energy income settlement data based on zero-knowledge proof according to claim 1 is characterized in that: The zero-knowledge proof circuit construction includes: Verifying the consistency of power generation data, the correctness of the profit distribution ratio, and the accuracy of the profit split calculation results will be used as the circuit logic of the zero-knowledge proof circuit; defining the sensitive data as a secret input to a zero-knowledge proof-circuit; Public data is defined as the public input of the zero-knowledge proof-circuit, wherein the public data is the hash commitment value, hash salt value and the number of hash commitment values disclosed on the chain.
6. A method for protecting privacy of new energy income settlement data based on zero-knowledge proof according to claim 5, characterized in that: The consistency of the power generation data is the consistency result obtained by recalculating the hash value of the data fragment and its hash salt value and verifying it with the hash commitment value on the chain; The accuracy of the profit distribution ratio is the accuracy result obtained by clarifying the profit distribution ratio and summing it, and then verifying it with the pre-set threshold; The accuracy of the profit sharing calculation result is the accuracy result obtained by calculating the profit amount to be allocated to each party based on the power generation and the profit distribution ratio, and verifying it with the income and expenditure amounts.
7. The method for protecting privacy of new energy income settlement data based on zero-knowledge proof according to claim 1, characterized in that: The verification of the zero-knowledge proof π on the blockchain includes: Submitting the zero-knowledge proof π to a verification module of a target blockchain; wherein the target blockchain includes a public blockchain platform that supports smart contracts or a consortium blockchain platform that supports chaincodes; The zero-knowledge proof verification logic is executed through the smart contract or chain code of the target blockchain.
8. The method for protecting privacy of new energy income settlement data based on zero-knowledge proof according to claim 1, characterized in that: The verification result is a confirmation that the power generation data has not been tampered with, the profit distribution ratio complies with the agreement, and the profit distribution result calculation is correct.
9. The method for protecting privacy of new energy income settlement data based on zero-knowledge proof according to claim 1, characterized in that: The hash commitment value is stored on the blockchain and is used to verify the consistency of the power generation data.
10. A privacy protection device, characterized in that: include: a communication unit and a processing unit; The communication unit is used to obtain sensitive data for node revenue settlement and submit zero-knowledge proof π to the blockchain smart contract or verification service; The processing unit is used to Preprocessing the sensitive data of the node revenue settlement to obtain a hash commitment value; Constructing a zero-knowledge proof circuit based on the hash commitment value; Generate a zero-knowledge proof π using the hash commitment value and the zero-knowledge proof-circuit; Verify the zero-knowledge proof π on the blockchain to obtain a multi-party settlement verification result that does not disclose sensitive data; The device integrates anti-quantum attack security design, multi-chain compatibility and ZK-Rollup aggregation optimization measures to improve the system security and settlement efficiency of the device.
Citation Information
Cited By
Article information verification method and system based on zero-knowledge proof and block chain
CN121530749A
Internet big data processing financial system
CN121682865A
An internet big data processing financial system
CN121682865B