Packed secret sharing-based general non-interactive zero-knowledge proof method and system

By adopting multi-party secure computing and packaging secret sharing methods in the zero-knowledge proof system, the problem of difficult to construct an efficient, quantum-resistant, and algebraic structure-free general non-interactive zero-knowledge proof system in the prior art is solved, and an efficient and size-optimized zero-knowledge proof system is realized.

WO2025112287A1PCT designated stage expired Publication Date: 2025-06-05INST OF SOFTWARE - CHINESE ACAD OF SCI
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/091592
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-30
Filing Date
2024-05-08
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

The prior art is difficult to construct a general non-interactive zero-knowledge proof system that is efficient, does not require rewinding of the proof problem circuit, can resist quantum computer attacks, and does not rely on any algebraic structure.

Method used

A general non-interactive zero-knowledge proof system is constructed through the pre-computing stage, proofing stage and verification stage, and a verifiable random linear transformation pair and packaging secret sharing algorithm is used to construct a general non-interactive zero-knowledge proof system through the pre-computing stage, the proofing stage and the verification stage.

Benefits of technology

An efficient, dimensional optimization zero-knowledge proof system is realized. It only needs to run the circuit corresponding to the proven problem once, and can resist quantum computer attacks and does not rely on any algebraic structure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024091592_05062025_PF_FP_ABST
    Figure CN2024091592_05062025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to the field of security protocols. Disclosed are a packed secret sharing-based general non-interactive zero-knowledge proof method and system. The method comprises: at a pre-computation stage, a prover and a verifier run a pre-processing algorithm to generate a verifiable random linear transformation pair required in a proof stage; in the proof stage, the prover runs a proof algorithm, computes a proof π, and sends the proof π to the verifier; and in a verification stage, the verifier runs a verification algorithm on the basis of the proof π and a corresponding common input, and verifies the correctness of execution of an arithmetic circuit C(w, x). According to the present invention, only an underlying MPC protocol needs to be run once, and the protocol can resist quantum computer attacks and does not depend on any algebraic structure. In addition, the protocol design scheme of the present invention is efficient and achievable, the proof time of the key knowledge proof of a lattice-based key encapsulation mechanism Kyber512 is only 1.08 seconds, the preprocessing time is 1.3 seconds, and the verification time is 1.16 seconds.
Need to check novelty before this filing date? Find Prior Art

Description

A universal non-interactive zero-knowledge proof method and system based on packaged secret sharing Technical Field

[0001] The present invention belongs to the field of security protocols and discloses a universal non-interactive zero-knowledge proof method and system based on multi-party secure computing and packaged secret sharing. Background Art

[0002] Zero-knowledge proofs and their non-interactive variants are the most fundamental and common theoretical and practical proofs in cryptography. Non-Interactive Zero-Knowledge Arguments of Knowledge (NIZKAoK) is a protocol that enables a computationally bounded prover to convince a verifier that they know evidence for a certain assertion without revealing any further information about the evidence. Zero-knowledge proof protocols have become an essential component of real-world cryptographic applications. For example, a certificate authority (CA) may require an applicant to provide a NIZKAoK as proof of knowledge of a key to prevent malicious key attacks.

[0003] Extensive research has been conducted on constructing NIZKs based on standard assumptions such as factorization and groups with bilinear maps. With the continuous emergence of new technologies such as big data, cloud computing, the Internet of Things, artificial intelligence, and blockchain, as well as the development of quantum computing, the functionality and practical application of non-interactive zero-knowledge proof protocols for specific problems under classical models have failed to meet the requirements of a wide range of real-world application scenarios. Therefore, in order to achieve a universal non-interactive zero-knowledge proof protocol for any problem that is resistant to quantum computing attacks while avoiding the limitations of multiple interactions in practical applications, the research on quantum-resistant universal non-interactive zero-knowledge proof protocols has become a key development direction for zero-knowledge proofs since their inception.

[0004] Recent research has also shown that NIZK, a protocol for proving arbitrary NP (Nondeterministic Polynomially) languages, can also be constructed using lattice-based assumptions. This protocol is particularly desirable because lattice-based assumptions are considered difficult under quantum computer models. While this work has already achieved exciting new feasibility based on lattice assumptions, our understanding of how to optimize the efficiency of such constructions remains in its infancy.

[0005] An efficient and feasible approach to constructing quantum-resistant, general-purpose non-interactive zero-knowledge proof systems is to use the "MPC-in-the-head" paradigm (MPCitH). Existing zero-knowledge proofs based on the MPCitH paradigm are all based on secure MPC (Multi-Party Computation) protocols under a semi-honest model. When constructing NIZKs from an n-party semi-honest MPC, a robustness violation requires a cheating prover to produce at least one pair of inconsistent replicas. The probability of detecting cheating by randomly revealing the replicas of two participants is 1 / n. To achieve negligible integrity errors, the NIZK prover must repeatedly run the MPC protocol corresponding to the required proof statement O(λ) times, where λ is a security parameter. Recently, a series of impressive works have demonstrated the great potential of constructing efficient NIZKs from semi-honest, secure MPC protocols for various applications, but the problem of excessive rewinds remains unresolved. Therefore, while this approach is highly efficient, it suffers from the problem of large proof size.

[0006] Therefore, how to construct an efficient, general non-interactive zero-knowledge proof system based on multi-party secure computation that does not require rewinding the proof problem circuit, can resist quantum computer attacks, and does not rely on any algebraic structure remains an open problem.

[0007] Summary of the Invention

[0008] To address the challenges of the prior art, the present invention aims to provide a universal non-interactive zero-knowledge proof method and system based on multi-party secure computation and packaged secret sharing. This method is efficient, size-optimized, requires only a single execution of the circuit corresponding to the problem being proved, is resistant to quantum computer attacks, and does not rely on any algebraic structure. Furthermore, the present invention provides a key zero-knowledge proof technology for the Kyber algorithm, a standard post-quantum algorithm.

[0009] The present invention provides a universal non-interactive zero-knowledge proof method based on multi-party secure computation and packaged secret sharing, comprising a pre-computation phase, a proof phase, and a verification phase;

[0010] In the pre-computation phase, the prover and verifier run the pre-processing algorithm to generate the verifiable random linear transformation pairs required in the proof phase;

[0011] In the proof phase, the prover runs the proof algorithm, packages the evidence w, and then runs the arithmetic circuit C(w,x) based on the packaged secret shared value, the statement x, and the random linear transformation pair generated in the pre-computation phase. It then calculates the proof π and sends the proof π to the verifier.

[0012] In the verification phase, the verifier runs the verification algorithm based on the proof π and the corresponding public input to verify the correctness of the execution of the arithmetic circuit C(w,x).

[0013] Furthermore, the universal non-interactive zero-knowledge proof method of the present invention proposes a new proof framework. The proof framework is mainly divided into three parts: pre-calculation phase, proof phase and verification phase. For any NP language class in It is a description of the well-known NP problem with statement x and evidence w. Assume that the corresponding arithmetic circuit is denoted by C(x,w)=1, and the arithmetic circuit C contains the linear transformation The number of linear transformation gates is v, where is a matrix corresponding to the linear transformation, and v is a natural number.

[0014] First, the prover and the verifier interactively run the first phase: the pre-computation phase, to generate the verifiable random linear transformation pairs required for the second phase, the proof phase, i.e., the remaining v linear transformation pairs among the N verifiable linear transformation pairs described in the subsequent step (2).

[0015] The second phase, the proof phase, is run by the prover. Based on the evidence w, the prover performs a packaged secret sharing algorithm on the evidence w. The packaged secret sharing algorithm is similar to the Shamir secret sharing algorithm, except that a secret sharing polynomial contains multiple secrets. Then, based on the packaged secret sharing value of the evidence w and the statement x and the verifiable random linear transformation pair generated in the pre-calculation phase, the prover runs the circuit C(w,x), as shown in step (3), which contains an addition gate, a multiplication gate, and a linear transformation gate, and calculates the challenge value based on the commitment value of the copy of the generated secret sharing value. Finally, the prover outputs a proof based on the challenge value, which proves the copy information of some participants in the arithmetic circuit C(x,w) calculated by the prover, which contains: a copy of the circuit multiplication gate, a copy of the linear transformation gate, and a verifiable random linear transformation pair generated in the pre-calculation phase. The proof is finally sent to the verifier.

[0016] The third phase, verification, is run by the verifier. Based on the proof π and the corresponding public input, the verifier runs the verification algorithm. The correctness of the circuit execution is verified using the copies of the multiplication gate and linear transformation gate included in the proof. The verifier also recalculates the circuit's output based on the commitments of the open users and verifies that the output satisfies C(x, w) = 1.

[0017] Furthermore, the present invention does not rely on any algebraic structure and can be constructed based on any group, ring and its corresponding algebraic assumptions. At the same time, the present invention includes any zero-knowledge proof protocol constructed using packaged secret sharing and the MPCitH paradigm.

[0018] Furthermore, the universal non-interactive zero-knowledge proof method of the present invention proposes a new zero-knowledge proof pre-computation stage. Assume that the linear transformation required in the proof process is denoted by the matrix The pre-computation phase consists of the following steps:

[0019] The prover first randomly selects k+v+1 random vectors f of length l j ,j∈0,1,…,k+v. Then the prover is for each vector f j The generation order is d, the package secret sharing [f j ], where the i-th package secret sharing value is recorded as [f j ](i). Further, the prover calculates Then the prover is for each Packed secret sharing with generation order d Afterwards, the prover calculates the commitment value of the packaged secret share Among them H com is a hash function. Further, the prover calculates k+v random challenge values ​​α1,…,α k+v ←H C (Com1,..,Com N ), where H C is a hash function, N represents the output length of secret sharing, k is the parameter for the number of challenge values ​​to ensure the security of the algorithm, and v is the number of linear transformation gates required for the subsequent proof circuit. The prover calculates: and For all i∈1,…,k+v, calculate [r i ]and The prover then applies the linear transformation to Sent to the verifier, the verifier verifies f j and Whether it satisfies the linear transformation relationship If the verification succeeds, the verifier believes that the prover generated f honestly. j and Then, the prover uses the remaining v sets of linear transformation pairs that were not sent to the verifier during the pre-computation phase Used as the secret shared value to perform subsequent linear gate operations.

[0020] Furthermore, in the pre-calculation phase, the method used in the present invention generates a verifiable random linear transformation pair The protocol covers any method for generating the required verifiable random linear transformation pairs. The present invention description only uses the above method to generate the corresponding verifiable random linear transformation pairs as an example to introduce the method of the present invention.

[0021] Furthermore, the universal non-interactive zero-knowledge proof method of the present invention proposes a new proof algorithm. The prover uses the evidence w and the unopened v linear transformation pairs generated in the pre-computation phase. Run the proof algorithm, which includes:

[0022] 3.1) The prover first applies the d-order package secret sharing algorithm to the evidence w and calculates the package secret sharing value [w] d ←PSS(w), where the function PSS represents the Packed Secret Sharing Function, which takes as input a set of l-length secret values ​​to be shared and outputs N secret sharing values ​​related to the set of secrets. This algorithm is well known. For the Packed Secret Sharing Function PSS, assume that its threshold value is t, the number of secrets to be shared is l, and its order d satisfies: d = t + l + 1. The Packed Secret Sharing Function first selects a d-order polynomial F(x) that satisfies: F(-i) = w i ,i∈[1,l],w i Represents the i-th element of the evidence vector w, and then randomly selects t+1 points q i Satisfies: F(i)=q i ,i∈[0,t]. According to the interpolation polynomial F(x), the secret sharing value is calculated as PSS(w)=[w] d =(F(1),F(2),…,F(N)).

[0023] 3.2) The prover shares the secret value [w] based on the evidence package d Computational NP Language The corresponding arithmetic circuit C(x,w)=1, which includes:

[0024] 3.2.1) Addition gate Add([e],[f]): For any two elements e,f∈F in the packaged secret sharing circuit that need to be added, q :The prover calculates the addition gate as [d]=[e]+[f], where F q The elements are taken from the set between {0,1,...,q-1}, q represents the modulus of the underlying computational domain F, and the output of the final addition gate is [d].

[0025] 3.2.2) Linear Transformation Gate For the i-th linear transformation gate of the circuit, the packaged secret shared value [g i ] and the corresponding linear transformation matrix The prover uses the i-th linear transformation pair generated in the pre-computation phase First, the prover calculates [g i ]+[r i ], and then get g according to the package secret sharing reconstruction algorithm i +r i , where the reconstruction algorithm is to recover the secret polynomial based on Lagrange interpolation and then obtain the secret value. The prover performs a linear transformation on the matrix as needed calculate Then re-share the secret to get according to and the other element of the linear transformation pair The prover calls the addition gate to calculate Finally, the prover outputs the packaged secret shared value after linear transformation

[0026] 3.2.3) Multiplication gate Multi([g i ],[h i ]): For the multiplication gate calculation of the circuit, that is, according to [g i ] and [h i ]Calculate [g i *h i ], since the secret sharing value is of order d, first calculate [z i ]=[g i ]×[h i ], at this time [z i ] is the 2d-order secret sharing value, denoted as [z i ] 2d , then the prover reconstructs z i , further, the prover re-calculates z using the packaged secret sharing algorithm i The corresponding d-order secret sharing value [z i ] d . Then the prover calculates [u i ] 2d =[z i ] d -[z i ] 2d , we can get that at this time [u i ] 2d The corresponding secret sharing value is all 0. Finally, the prover outputs the result of the multiplication gate [z i ] d And the corresponding verification value [u i ] 2d .

[0027] 3.3) The prover runs the output gate, which contains N copies of the secret shared value [V] = (V1,…,V N ). Each V i Contains the message generated by running each packaged secret sharing operation gate, that is, Where [w](i) represents the i-th component of the packaged secret shared by w. Then the prover calculates its commitment value com1 = H com (V1),…,com N =H com (V N ). It is then sent to the validator.

[0028] 3.4) The verifier receives the commitment value (com1, com2, ..., com N ), randomly select a challenge set t represents the number of commitments that need to be opened, and then the set is sent to the prover.

[0029] 3.5) The prover opens the corresponding commitment value based on the challenge set received and sends it to the verifier. Sent to the verifier as proof π.

[0030] 3.6) Furthermore, the above general interactive zero-knowledge proof protocol can be converted into a non-interactive zero-knowledge proof protocol based on the universal Fiat-Shamir transformation. Non-interactive zero-knowledge proof is of great significance in the context of executing a large number of cryptographic protocols in a large network. Through this protocol, the execution time of the protocol can be significantly reduced and the operation efficiency of the protocol can be improved. The prover generates a copy [V] = (V1,…,V N ), the prover calculates its commitment value com1 = H com (V1),…,com N =H com (V N ). Further, the prover calls the hash function to calculate its challenge value The challenge value calculated The prover opens the corresponding commitment value as proof:

[0031] Furthermore, the universal non-interactive zero-knowledge proof method of the present invention proposes a new verification algorithm. Based on the proof π and the corresponding public input, the verifier sequentially runs the following verification algorithm:

[0032] 4.1) The verifier opens Recalculate Then reconstruct the k package secret sharing values ​​to obtain Furthermore, the verifier verifies whether it satisfies the relationship: If yes, then continue to perform subsequent verification; if no, then terminate the verification algorithm.

[0033] 4.2) The verifier verifies the correctness of the multiplication gate execution: The verifier recalculates [u i ] 2d . Combined with the user's [u i ] 2d Reconstruct and verify whether the N values ​​belong to the same secret sharing polynomial and whether the reconstructed packaged secret values ​​are all 0. If so, continue to perform subsequent verification; if not, terminate the verification algorithm.

[0034] 4.3) The verifier verifies whether all commitment values ​​are opened correctly: The verifier verifies the Recalculate Combined with the proof Where "\" means removing the subset from the set N For the remaining elements, the verifier recalculates H c (com1,com2,…,com N ) and determine whether it is equal to If yes, then continue to perform subsequent verification; if no, then terminate the verification algorithm.

[0035] 4.4) Finally, the verifier uses the opened secret value and Recalculate the running result of circuit C and determine whether it is equal to 1. If so, output verification passed, if not, terminate the verification algorithm.

[0036] The present invention also provides a universal non-interactive zero-knowledge proof system based on packaged secret sharing, which includes:

[0037] The pre-computation module is used to run the pre-processing algorithm, where the prover and verifier interact to generate the verifiable random linear transformation pairs required in the proof phase.

[0038] The proof module is used to run the proof algorithm. The prover packages the evidence w and secretly shares it. Based on the packaged secret shared value, the statement x, and the random linear transformation pair generated in the pre-computation phase, the arithmetic circuit C(w,x) is run to calculate the proof π and send the proof π to the verifier.

[0039] The verification module is used to run the verification algorithm, and the verifier verifies the correctness of the execution of the arithmetic circuit C(w,x) based on the proof π and the corresponding public input.

[0040] The advantages of the present invention are as follows:

[0041] The zero-knowledge proof system of the present invention is highly efficient. Compared to similar non-interactive zero-knowledge proofs based on multi-party secure computation, the present invention only requires running the circuit to prove the problem once, and the proof size per gate is amortized to O(1). This supports proofs for large-scale batch circuits and is resistant to quantum computer attacks. Furthermore, the framework of the present invention does not rely on any algebraic structure. Furthermore, this method is the first quantum-resistant zero-knowledge proof protocol that can prove large-scale problems on lattices and can be implemented in seconds.

[0042] The present invention only requires running the underlying MPC protocol once, is resistant to quantum computer attacks, and does not rely on any algebraic structure. Furthermore, the protocol design is efficient and feasible. Proving key knowledge for the lattice-based key encapsulation mechanism Kyber512 takes only 1.08 seconds, 1.3 seconds for preprocessing, and 1.16 seconds for verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 is a flowchart of the three stages of the quantum-resistant non-interactive zero-knowledge proof method based on multi-party secure computation and packaged secret sharing.

[0044] Figure 2 is a schematic diagram of the module structure of a quantum-resistant non-interactive zero-knowledge proof system based on multi-party secure computing and packaged secret sharing. DETAILED DESCRIPTION

[0045] The present invention will be described in further detail below with reference to the accompanying drawings. The examples given are only used to explain the present invention and are not used to limit the scope of the present invention.

[0046] The present invention does not rely on any algebraic structure, and can be constructed based on any group, ring and its corresponding algebraic assumption. q The method for generating a verifiable random linear transformation pair protocol used in the present invention covers any method for generating a required verifiable random linear transformation pair protocol, wherein the linear transformation A verifiable random linear transformation pair is a pair (a, b) that satisfies The following only takes the “Cut-and-Choose” method to generate corresponding verifiable random linear transformation pairs as an example, and describes the method of the present invention in conjunction with FIG1 .

[0047] 1. Pre-calculation stage: pre-processing algorithm

[0048] The preprocessing algorithm of zero-knowledge proof is run by two parties, the prover P and the verifier V. Finally, the prover generates the linear transformation required by the multiplication gate in the proof phase. The specific protocol flow is as follows:

[0049] (1) The prover first randomly selects k+v+1 random vectors f of length l j ,j∈0,1,…,k+v. Then the prover is for every f j The generation order is d, the package secret sharing [f j ], where the i-th shared value is recorded as [f j ](i). Further, the prover calculates Then the prover is for each Packed secret sharing with generation order d Afterwards, the prover calculates its commitment value Furthermore, the prover calculates k+v random challenge values ​​α1,…,α k+v ←H C (Com1,..,Com N ). For each set of secret sharing values The prover calculates: and For all i∈1,…,k+v, calculate [r i ]and The prover will then Sent to the validator,

[0050] (2) The verifier receives the linear transformation pair Reconstruct the k package secret sharing values ​​and get Furthermore, the verifier verifies whether it satisfies the linear transformation relationship If the verification succeeds, the verifier believes that the prover generated f honestly. j and Then, the prover uses the remaining v sets of linear transformation pairs that were not sent to the verifier during the pre-computation phase Used as the secret shared value to perform subsequent linear gate operations.

[0051] 2. Proof Phase: Proof Algorithm

[0052] For any NP language class Its corresponding arithmetic circuit C(x,w)=1, about linear transformation The number of linear transformation gates is v, where v is a positive integer. The prover has evidence w, the NP problem statement x, and v unopened linear transformation pairs generated by pre-calculation (as shown by the linear transformation pairs generated by the pre-processing algorithm above), while the verifier only has the NP problem statement x.

[0053] The prover uses the evidence w to calculate the v linear transformation pairs generated in the pre-computation phase that have not been opened. Run the proof algorithm:

[0054] (1) The prover first performs a d-order packaged secret sharing algorithm on the evidence w and calculates [w] d ←PSS(w), where the function PSS represents the packaged secret sharing function, which inputs a set of secret values ​​to be shared with length l and outputs N secret sharing values ​​about the set of secrets. For the packaged secret sharing function PSS, assume that its threshold value is t, the number of secrets to be shared is l, and its order d satisfies: d = t + l + 1. The function first selects a d-order polynomial F(x) that satisfies: F(-i) = w i ,i∈[1,l], then randomly select t+1 points q i Satisfies: f(i) = q i ,i∈[0,t]. According to the interpolation polynomial F(x), the secret sharing value is calculated as PSS(w)=[w] d =(F(1),F(2),…,F(N)).

[0055] (2) The prover shares the value [w] based on the packaged secret of the evidence d Computational NP Language The corresponding arithmetic circuit C(x,w)=1:

[0056] a) Addition gate Add([e],[f]): For any two elements e,f∈F in the packaged secret sharing circuit that need to be added, q :The prover calculates the addition gate as [d]=[e]+[f], where f w The elements are taken from the set between {0,1,...,q-1}, and the output of the final addition gate is [d];

[0057] b) Linear transformation gate For the i-th linear transformation gate of the circuit, the packaged secret shared value [g i ] and the corresponding linear transformation matrix The prover uses the i-th linear transformation pair generated in the pre-computation phase (as shown in (2) pre-computation phase) First, the prover calculates [g i ]+[r i ], and then reconstruct to get g i +r i The prover performs linear transformations on the matrix as needed. calculate Then re-share the secret to get according to and the other element of the linear variation The prover calls the addition gate to calculate Finally, the prover outputs the packaged secret shared value after linear transformation

[0058] c) Multiplication gate Multi([g i ],[h i ]): For the circuit that needs to perform multiplication gate operations [g i ],[h i ], since the secret sharing value is of order d, the present invention first calculates [z i ]=[g i ]×[h i ], at this time [z i ] is the 2d-order secret sharing value, denoted as [z i ] 2d , then the prover reconstructs z i , further, the prover re-calculates z using the packaged secret sharing algorithm i The corresponding d-order secret sharing value [z i ] d . Then the prover calculates [u i ] 2d =[z i ] d -[z i ] 2d , we can get that at this time [u i ] 2d The corresponding secret sharing value is all 0. Finally, the prover outputs the result of the multiplication gate [z i ] d And the corresponding verification value [u i ] 2d .

[0059] (3) The prover runs the output gate, which contains N copies of the secret shared value [V] = (V1,…,v N ). Each V i Contains the message generated by running each packaged secret sharing operation gate, that is, The prover then calculates its commitment value com1 = H com (V1),…,com N =H com (V N ). It is then sent to the validator.

[0060] (4) The verifier receives the commitment value (com1, com2, ..., com N ), randomly select a challenge set This set is then sent to the prover.

[0061] (5) The prover opens the corresponding commitment value based on the challenge set received and sends it to the verifier. Sent to the verifier as proof.

[0062] (6) Furthermore, according to the universal Fiat-Shamir transformation, the present invention can convert the above universal interactive zero-knowledge proof protocol into a non-interactive zero-knowledge proof protocol. The prover generates the copy [V] = (V1, ..., V n ), the prover calculates its commitment value com1 = H com (V1),…,com N =H com (V n ). Further, the prover calls the hash function to calculate its challenge value The challenge value calculated The prover opens the corresponding commitment value as proof:

[0063] 3. Verification Phase: Verification Algorithm

[0064] (1) The verifier opens Recalculate Then reconstruct the k package secret sharing values ​​to obtain Furthermore, the verifier verifies whether it satisfies the relationship:

[0065] (2) The verifier verifies the correctness of the multiplication gate execution: The verifier recalculates [u] according to the secret value [w](i) opened in the proof π i ] 2d . Combined with the user's [u i ] 2d Reconstruct and verify whether the N values ​​belong to the same secret sharing polynomial and whether the reconstructed packaged secret values ​​are all 0.

[0066] (3) The verifier verifies whether all commitment values ​​are opened correctly: The verifier verifies whether all commitment values ​​are opened correctly. Recalculate Combined with the proof The verifier recalculates H c (com1,com2,…,com n ) and determine whether it is equal to

[0067] (4) Finally, the verifier uses the opened secret value and Recalculate the operating result of circuit C and determine whether it is equal to 1.

[0068] The present invention does not rely on any algebraic structure, and can construct the universal non-interactive zero-knowledge proof method and system of the present invention based on any group, ring and its corresponding algebraic assumption. q The method and system of the present invention are introduced with reference to the domain as an example.

[0069] The present invention covers technical solutions of any zero-knowledge proof protocol framework, such as a verification circuit in which a prover runs an MPC protocol using a packed secret sharing scheme based on the MPCitH framework.

[0070] During the pre-calculation phase, the linear transformation pair generation protocol used in the present invention encompasses any method for generating the desired linear transformation pairs. This description uses the "Cut-and-Choose" method to generate the corresponding linear transformation pairs as an example to illustrate the present invention's method.

[0071] Experimental results:

[0072] The present inventors developed an experiment using this algorithm module. The algorithm module was implemented in C++17. Polynomial and vector operations in the protocol were implemented using the NTL 11.5.12 and GNU Multiple Precision Arithmetic 6.2.13 libraries. The SHA256 and SHAKE256 algorithms from the OpenSSL library were selected as the random oracle model. Performance benchmarks were conducted on a 14-inch Apple MacBook Pro laptop powered by an Apple Silicon M1 Pro (3.2GHz), with 10 cores and 16GB of memory.

[0073] Experiment 1: Kyber512. Assume (k, v) = (70, 4). For Kyber512 and the NIZKAoK system of our invention, we choose modular rank k = 2 and η = 2, q = 3329, and (N, t, l) = (1454, 150, 256). This method achieves a proof time of only 1.08 seconds, with preprocessing time of 1.3 seconds and verification time of 1.16 seconds. Specifically, proving a linear relationship takes 0.2 seconds, while proving the range of the secret vector takes 0.88 seconds.

[0074] Experiment 2: Frodo640. Assume (k, v) = (90, 8). For Frodo640 and the NIZKAOK system of the present invention, choose n = 640, n = 8, q = 215, and (n, t, l) = (2500, 250, 640). This method achieves a proof time of 12.81 seconds, including 6.5 seconds of preprocessing time and 7.3 seconds of verification time. Specifically, proving the linear relationship takes 0.2 seconds, and proving the secret vector range takes 12.61 seconds.

[0075] Another embodiment of the present invention provides a universal non-interactive zero-knowledge proof system based on packaged secret sharing, as shown in FIG2 , which includes:

[0076] The pre-computation module is used to run the pre-processing algorithm, where the prover and verifier interact to generate the verifiable random linear transformation pairs required in the proof phase.

[0077] The proof module is used to run the proof algorithm. The prover packages the evidence w and secretly shares it. Based on the packaged secret shared value, the statement x, and the random linear transformation pair generated in the pre-computation phase, the arithmetic circuit C(w,x) is run to calculate the proof π and send the proof π to the verifier. The arithmetic circuit includes a multiplication gate module, an addition gate module, and a linear transformation gate module.

[0078] The verification module is used to run the verification algorithm, and the verifier verifies the correctness of the execution of the arithmetic circuit C(w,x) based on the proof π and the corresponding public input.

[0079] The specific implementation process of each module refers to the above description of the method of the present invention.

[0080] Another embodiment of the present invention provides a computer device (computer, server, smart phone, etc.), which includes a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program includes instructions for executing each step in the method of the present invention.

[0081] Another embodiment of the present invention provides a computer-readable storage medium (such as ROM / RAM, magnetic disk, optical disk), wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the steps of the method of the present invention are implemented.

[0082] While specific embodiments of the present invention have been disclosed for illustrative purposes, intended to facilitate understanding and implementation of the present invention, those skilled in the art will appreciate that various substitutions, variations, and modifications are possible without departing from the spirit and scope of the present invention and the appended claims. Therefore, the present invention should not be limited to the disclosure of the preferred embodiments, and the scope of protection claimed in the present invention shall be determined by the scope of the claims.

Claims

1. A general non-interactive zero-knowledge proof method based on packaged secret sharing, characterized in that: It includes pre-calculation phase, proof phase and verification phase; In the pre-computation phase, the prover and verifier run the pre-processing algorithm to generate the verifiable random linear transformation pairs required in the proof phase; In the proof phase, the prover runs the proof algorithm, packages the evidence w for secret sharing, runs the arithmetic circuit C(w,x) based on the packaged secret sharing value, statement x, and the random linear transformation pair generated in the pre-computation phase, and calculates the proof π, which is then sent to the verifier. In the verification phase, the verifier runs the verification algorithm based on the proof π and the corresponding public input to verify the correctness of the execution of the arithmetic circuit C(w,x).

2. The method according to claim 1, characterized in that The preprocessing algorithm includes: Assume that the linear transformation required in the proof phase is denoted by the matrix The prover first randomly selects k+v+1 random vectors f of length l j , j∈0,1,…,k+v, then for each vector f j Generate a package secret sharing of order d [f j ], where the i-th shared value is recorded as [f j ](i), then calculate And for each Packed secret sharing with generation order d The prover calculates the commitment value of the packaged secret share Among them, H com is a hash function, and calculates k+v random challenge values ​​α1,…,α k+v ←H C (Com1, ..,Com N ), where H C is a hash function, N represents the output length of the secret sharing; For each set of secret sharing values Prover calculation and Then the linear transformation Sent to the verifier, the verifier verifies f j and Whether it satisfies the linear transformation relationship If the verification succeeds, the verifier believes that the prover generated f honestly. j and The remaining v sets of linear transformation pairs that have not been sent to the verifier during the pre-computation phase Used by the prover to perform subsequent linear gate operations.

3. The method according to claim 2, characterized in that The proof algorithm includes: 1) The prover applies the d-order package secret sharing algorithm to the evidence w and calculates the package secret sharing value [w] d ←PSS(w), where the function PSS represents the packing secret sharing function; 2) The prover shares the value [w] according to the packaged secret d Computation on NP languages The corresponding arithmetic circuit C(x,w)=1; 3) The prover runs the output gate, which contains N copies of the secret shared value [V] = (V1,…,V N ), each V i Contains running Each message generated by the package secret sharing operation gate is then calculated by the prover to be its commitment value com1 = H com (V1),…,com N =H com (V N ) and sends it to the verifier; 4) The verifier receives the commitment value (com1, com2, ..., com N ), randomly select a challenge set This challenge set is then sent to the prover; 5) The prover opens the corresponding commitment value according to the received challenge set and sends it to the verifier. Sent as proof to the verifier; 6) According to the general Fiat-Shamir transformation, the interactive zero-knowledge proof protocol is converted into a non-interactive zero-knowledge proof protocol, wherein the non-interactive zero-knowledge proof protocol comprises: the prover performs a zero-knowledge proof according to [V] = (V1, ..., V N ) Calculate its commitment value com1 = H com (V1),…,com N =h com (V N ), and then the prover calls the hash function to calculate its challenge value Then according to the challenge value The prover opens the corresponding commitment value as proof:

4. The method according to claim 3, characterized in that The arithmetic circuit comprises: Addition gate Add([e],[f]): For any two elements e, f∈F in the circuit that need to perform addition gate operation q :The prover calculates the addition gate as [d] = [e] + [f], where F q is a set whose elements are taken from {0,1,...,q-1}, q represents the modulus of the underlying computational domain F, and the output of the final addition gate is [d]; Linear Transformation Gate For the packaged secret sharing value [g i ] and the corresponding linear transformation matrix The prover uses the i-th linear transformation pair generated in the pre-computation phase First calculate [g i ]+[r i ], and then use the packaged secret sharing reconstruction algorithm to get g i +r i , then calculate Then re-share the secret to get Then according to and the other element of the linear transformation Call the addition gate to calculate The final output is the packaged secret sharing value after linear transformation Multiplication gate Multi([g i ],[h i ]): For the multiplication gate of the circuit, according to [g i ] and [h i ]Calculate [g i *h i ], first calculate [z i ]=[g i ]×[h i ], at this time [z i ] is the 2d-order secret sharing value, denoted as [z i ] 2d , and then reconstruct to get z i , and then re-calculate z using the packaged secret sharing algorithm i The corresponding d-order secret sharing value [z i ] d , then the prover calculates [u i ] 2d =[z i ] d -[z i ] 2d , at this time [u i ] 2d The corresponding secret sharing value is all 0, and the final output is the result of the multiplication gate [z i ] d and the corresponding verification value [u i ] 2d .

5. The method according to claim 3 or 4, characterized in that: The verification algorithm includes: 1) The verifier opens Recalculate Then reconstruct the k packaged secret sharing values ​​to obtain The verifier then verifies that the relation is satisfied: in the case of, Then continue to perform subsequent verification, if not, terminate the verification algorithm; 2) The verifier verifies the correctness of the execution of the multiplication gate: The verifier recalculates [u i ] 2d , combined with the unopened user's [u i ] 2d Reconstruct and verify whether the N values ​​belong to the same secret sharing polynomial and whether the reconstructed packaged secret values ​​are all 0; if yes, continue to perform subsequent verification, if not, terminate the verification algorithm; 3) The verifier verifies whether all the commitment values ​​are opened correctly: the verifier Recalculate Combined with the proof Recalculate H c (com1,com2,…,com N ) and determine whether it is equal to If yes, then continue to perform subsequent verification, if not, then terminate the verification algorithm; 4) The verifier uses the opened secret value and Recalculate the running result of circuit C and determine whether it is equal to 1. If so, the output verification is passed. If not, terminate the verification algorithm.

6. A general non-interactive zero-knowledge proof system based on packaged secret sharing, characterized in that: include: The pre-computation module is used to run the pre-processing algorithm, and the prover and the verifier interact to generate the verifiable random linear transformation pairs required in the proof phase; The proof module is used to run the proof algorithm. The prover packages the evidence w and shares it secretly. According to the packaged secret sharing value, the statement x, and the random linear transformation pair generated in the pre-calculation phase, the arithmetic circuit C(w,x) is run, and the proof π is calculated and sent to the verifier. The verification module is used to run the verification algorithm, and the verifier verifies the correctness of the execution of the arithmetic circuit C(w,x) based on the proof π and the corresponding public input.

7. A computer device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program comprises instructions for executing the method according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Universal non-interactive zero-knowledge proving method and system

    CN116112181A

  • Redistribution of secret sharing

    CN116391346A