Computer-implemented system and method for implementing zero-knowledge proofs

By using the public key elliptic curve specification in the homomorphic commitment function, the circuit satisfactory is proved, and the problems of computational complexity and large evidence in the prior art are solved, and efficient zero-knowledge verification of composite statements is achieved.

CN111886831BActive Publication Date: 2025-06-13NCHAIN HLDG LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN201980020846.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-03-23
Filing Date
2019-03-18
Publication Date
2025-06-13
Estimated Expiration
2039-03-18

AI Technical Summary

Technical Problem

The existing zero-knowledge proof system has problems such as high computational complexity, large evidence size and reliance on strong assumptions when proving statements involving encrypted elliptic curve key operations.

Method used

By using the public key elliptic curve specification to demonstrate circuit satisfactoriness in the homomorphic commitment function, the use of bilinear pair-friendly elliptic curves is avoided, thereby reducing computational cost and evidence size.

Benefits of technology

Effective zero-knowledge verification of composite statements is realized, reducing proof size and calculation costs, and zero-knowledge proofs for hashed images and elliptic curve private keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111886831B_ABST
    Figure CN111886831B_ABST
Patent Text Reader

Abstract

The present invention relates to efficient zero - knowledge verification of a composite statement that involves both arithmetic - circuit satisfiability and a subordinate statement (key - statement proof) regarding the validity of a public key. The method enables a prover to prove the particular statement in zero - knowledge. More specifically, the present invention relates to a computer - implemented method for achieving zero - knowledge proof or verification of a statement (S), in which the prover proves to a verifier that the statement is true while keeping secret a witness (w) for the statement. The present invention also relates to a corresponding method employed by the verifier for verifying the proof. The method includes the prover sending to the verifier a data set including the statement that for a given functional - circuit output and an elliptic - curve point, the functional - circuit input is equal to the corresponding elliptic - curve - point multiplier. The data includes individual wire commitments and / or batch commitments, inputs, and outputs for the circuit for the statement. The prover may include in the data the specification of the elliptic curve or each elliptic curve used in the statement, or the specification of the elliptic curve or each elliptic curve used in the statement has been shared in advance. Then, in response to a challenge from the verifier, the prover sends openings. Alternatively, the prover additionally includes a proof key. Using the data received from the prover, the verifier is able to determine that the circuit is satisfied, compute the elliptic - curve point, and verify the statement, thereby determining that the prover holds a witness for the statement. Upon receiving the data, the verifier determines by computation that the data conforms to the statement.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification generally relates to computer-implemented methods and systems suitable for implementation in a computer processor (e.g., a node of a blockchain network) or a group of such processors. An improved method of generating a proof is provided that enables efficient zero-knowledge verification of a statement. The method is suitable for incorporation into existing discrete-logarithm-based zero-knowledge proof protocols for circuit satisfiability that do not require the use of bilinear-pairing-friendly elliptic curves. The present invention is particularly suitable for, but not limited to, methods performed by a prover for preparing a proof and methods performed by a verifier for verifying a proof, as well as collaboration between two or more participants. One of the parties can prove knowledge of a key or statement without revealing the statement, in order to effect a secure trustless exchange between the participants. Background Art

[0002] In this document, the term "blockchain" is used to include all forms of electronic, computer-based, distributed ledgers. These include consensus-based blockchain and transaction chain technologies, permissioned and unpermissioned ledgers, shared ledgers, and variations thereof.

[0003] The term "user" can refer to human- or processor-based resources in this document. A blockchain is a peer-to-peer electronic ledger that is implemented as a computer-based decentralized, distributed system that consists of blocks, which in turn consist of transactions.

[0004] Each transaction is a data structure that encodes the transfer of control of digital assets between participants in a blockchain system and includes at least one input and at least one output. Each block contains the hash value of the previous block, such that the blocks are linked together to create a permanent, immutable record of all transactions that have been written to the blockchain since its establishment. Transactions contain small programs called scripts that are embedded in the inputs and outputs of the transaction, which specify how and who can access the outputs of the transaction.

[0005] Furthermore, in this document, reference is made to the structure of known zero-knowledge proof protocols and systems that use arithmetic circuits. A blockchain provides a decentralized and permissionless global mechanism that implements a solution to the problem of fair exchange between two mutually trustless parties without the need for third-party arbitration or escrow. Fair exchange of data or information in the exchange of economic rewards or information such as digital goods is embodied in what is known as zero-knowledge or with payment (ZKCP) [Maxwell 2016]in the trading agreement. In ZKCP, only when the payment is confirmed, the specified data is transferred from the seller to the buyer, and only when the specified data is valid according to the sales conditions, the payment from the buyer to the seller is completed. The details of such an agreement are known [Campanelli 2017] , but it is essentially based on the combination of hash time-locked contracts (HTLCs) and zero-knowledge proofs, which simultaneously verify that certain cryptographic information ("digital goods") is valid / correct, and verify that the "password" for decrypting this information is the data that must be revealed on the blockchain to claim payment.

[0006] The central component of the ZKCP protocol is the zero-knowledge proof for a series of subordinate statements regarding the validity or correctness of data / information, the validity of keys, and their corresponding hash values. Such complex composite statements require an efficient zero-knowledge proof system for general computation: essentially, this enables one party to run an arbitrary program with a secret input and then prove to the other party that the program accepted the input as valid and that the program was executed correctly—without revealing any information about the secret input or program execution. In known ZKCP examples, the general zero-knowledge proof system employed has been based on the Pinocchio protocol [Parno 2016] and the succinct non-interactive argument of knowledge (SNARKs) framework implemented in the C++ libsnark library [Libsnark 2016] .

[0007] Zero-knowledge SNARK (zkSNARK) provides a way to prove the validity of an arbitrary computation in zero knowledge, where the arbitrary computation can be represented as an arithmetic circuit. Two main distinguishing properties of zkSNARKs are that they are non-interactive (the prover sends the proof to the verifier in one go) and succinct (the proof is small and easy to verify). However, they have significant limitations:

[0008] - Proof generation is extremely computationally demanding.

[0009] - The proof keys are very large and proportional to the circuit size.

[0010] - They rely on strong and untested cryptographic assumptions (i.e., knowledge of the exponentiation assumption and the pairing-based assumption).

[0011] - For any given program (circuit), they require a common reference string (CRS) computed by a third party that must be trusted to remove the setup parameters. Any party knowing the setup parameters has the ability to create forged proofs.

[0012] To date, no attempts have been made to construct a zkSNARK to prove statements involving arbitrary cryptographic elliptic curve key operations, but it is assumed that such a zkSNARK would consist of arithmetic circuits with hundreds of thousands or millions of gates, and therefore proof generation time would take minutes and the size of the proving key would be hundreds of megabytes. Technical Background

[0014] The basic system for interactive zero-knowledge proofs can use a ∑ (Sigma) protocol, which includes many communication steps between the prover and the verifier. In general, the ∑ protocol includes 3 moves: the prover sends an initial commitment (a) to the verifier, then the verifier responds with a random challenge (x), and finally the prover answers with a final response or "opening" (z). The verifier then accepts or rejects the statement based on the transcript (a, x, z).

[0015] The ∑ protocol can be used to prove knowledge of a witness (w) known only to the prover or to prove a statement about a witness (w) known only to the prover. The protocol is zero-knowledge if no information about the witness or the secret is revealed to the verifier other than the fact that the statement about the witness is true. [Bootle 2015] .

[0016] At the heart of many interactive zero-knowledge protocols is a commitment scheme, which is used for arithmetic circuit satisfiability. Commitments enable a prover to commit to a secret value in advance, and later verifiably reveal (disclose) the secret value. A commitment scheme has two main properties. First, it is hidden - the commitment keeps the value secret. Second, it is binding - only the commitment to the original committed value is disclosed. Pedersen commitment [Bootle 2015] The scheme involves two elliptic curve generator points: a set of primes of order p known to all parties G and F in . The field of prime numbers generated by the committer The secure random number r in , and then computes (via elliptic curve addition / multiplication) the commitment to the secret value s:

[0017] Com(s,r)=s×G+r×F

[0018] Here, × represents the elliptic curve point multiplication.

[0019] The promiser can fully disclose the promise (i.e., the promise can be verified) at a later stage by providing the values ​​s and r. The promiser can also disclose the promise in response to a specific challenge value as part of the ∑ protocol, without revealing the secret s or the random number r.

[0020] The Pedersen commitment is additively homomorphic, which means that (on an elliptic curve) adding two commitments results in a commitment to the sum of the committed values, i.e.:

[0021] (s 1 ×G + r 1 ×F) + (s 2 ×G + r 2 ×F) = (s 1 + s 2 )×G + (r 1 + r 2 )×F

[0022] A proof of arithmetic circuit satisfiability can be achieved in "zero knowledge". An arithmetic circuit (over a field ) is a virtual construction of arithmetic gates connected (forming a directed acyclic graph) by wires, which can perform arbitrarily complex calculations, where the calculations are limited to integer operations and must also have no data-dependent loops or mutable state.

[0023] Each gate has two input wires and one output wire and performs a multiplication (×) or addition (+) operation on the inputs. Figure 1a A schematic of a multiplication gate is shown with a left wire input (w L ) and a right wire input (w R ) and a wire output (w O ), while Figure 1b a schematic of a simple arithmetic circuit is shown, which has three gates, three input wires ((w 1 、w 2 、w 3 ), one output wire (w 6 ) and two internal wires (w 5 、w 6 ).

[0024] In fact, a complete circuit has free input wires and free output wires that define the external (circuit) input values and output values. A legal assignment is to limit the values of the wires to those that satisfy the circuit, i.e., to assign a value to each wire, where the output of each gate correctly corresponds to the product or sum of the inputs (i.e., the gates are consistent).

[0025] For a given arithmetic circuit, the prover can prove to the verifier that they know a legal assignment for the circuit without revealing the wire values in the following way: First, commit to each wire value in the legal assignment (using Pedersen commitments), and then for each gate in the circuit (which can be executed in parallel), execute a specific Σ-protocol with the verifier using the wire values as witnesses. These Σ-protocols utilize the homomorphic property of Pedersen commitments, as described below.

[0026] To produce a proof (a proof that the circuit is satisfied), initially, the prover generates commitments for each wire w i in the circuit (i = 1, …, n, where n is the number of wires) and sends them to the verifier:

[0027] W i = Com(w i , r i )

[0028] For each "addition" gate in the circuit ( Figure 1b one is shown in zero ), execute the Σ L -protocol: This involves proving (in zero knowledge) that w R + w O - w L = 0 (i.e., the addition gate is satisfied: the input wires w R and w O equal the output wire w b ). This includes the following steps:

[0029] 1. The prover generates a commitment to zero: B = Com(0, r L ) and sends it to the verifier.

[0030] 2. The verifier responds with a random challenge value:

[0031] 3. Then the prover calculates the opening value: z = x(r R + r O - r B ) + r L

[0032] and sends it to the verifier. 4. As a proof that w R + w O - w L = 0, the verifier checks that Com(0, z) = x × (W R + W O - W B B represents a curve point, similar to a public key; B = r x F + 0 x G

[0034] r B represents the corresponding paired private key.

[0035] For each "multiplication" gate (as Figure 1a shown), execute the Σ prod protocol: This involves proving (in zero - knowledge) for each multiplication gate that w L ·w R = w O (i.e., the multiplication gate is satisfied).

[0036] 1. The prover generates 5 random blinding values:

[0037] 2. The prover computes C 1 = Com(t 1 , t 3 ), C 2 = Com(t 2 , t 5 ), and C 3 = t 1 ×W R + t 4 ×F, and then sends them to the verifier.

[0038] 3. The verifier responds with a random challenge value:

[0039] 4. The prover computes the public values:

[0040] e 1 = w L x + t 1

[0041] e 2 = w R x + t 2

[0042] z 1 = r L x + t 3

[0043] z 2 = r R x + t 5

[0044] z 3 = (r O - w L r R )x + t 4

[0045] and sends them to the verifier.

[0046] 5. Then, as w L ·w R = w O For the proof of, the verifier checks the following equations:

[0047] Com(e 1 , z 1 ) = x × W L + C 1

[0048] Com(e 2 , z 2 ) = x × W R + C 2

[0049] e 1 × W R + z 3 × F = x × W O + C 3 .

[0050] Σ zero protocol and Σ prod protocol can run in parallel to verify each gate in the circuit, and the same verifier challenge value (x) can be used for all gates.

[0051] For example, consider Figure 1b the circuit in: To enable the prover to prove to the verifier in zero - knowledge that they know a legal assignment (i.e., the wire values satisfy the circuit), the prover initially sends the wire commitments (W 1 , …, W 6 ) for each gate and Σ - protocol commitments (which are one additional commitment for each addition gate and five for each multiplication gate) to the verifier.

[0052] Then, the verifier responds with a random challenge and the prover computes the public values (one for each addition and five for each multiplication) for each gate and sends them back to the verifier. Then, the verifier performs Σ - protocol checks to verify:

[0053] w 1 ·w 2 = w 4

[0054] w 4 ·w 5 = w 6

[0055] w 2 + w 3 = w 5

[0056] And thus, the commitments W 1 , …, W6 corresponding to the satisfied wire value w 1 ,…,w 6 。

[0057] If the prover wants to show that, in addition to the satisfied circuit, a particular wire also has a particular value, they can fully disclose the commitment to the relevant wire. In this example, the prover can additionally send the value w 6 and r 6 (then the verifier can confirm that W 6 = Com(w 6 ,r 6 )) to demonstrate that w 6 is the actual output from a particular legal assignment.

[0058] Figure 1b The example in is a trivial circuit. In fact, useful circuits consist of more gates. Of particular interest is the arithmetic circuit for the SHA-256 hash function - this circuit enables the prover to demonstrate that they know the pre-image (input) of the SHA-256 function that hashes to a particular (output) value without revealing the pre-image. One of the most efficient implementations of the circuit for the SHA-256 algorithm consists of 27,904 arithmetic gates [Zcash 2016] . Then, to prove knowledge of the SHA-256 pre-image, it would be necessary to send approximately 5MB of data in both the initial commitment and the opening round of the above protocol, and approximately 200,000 elliptic curve operations would be required for both the prover and the verifier (each operation taking a few seconds on the processor).

[0059] Several methods have been developed to significantly improve the performance of the parallel ∑-protocol method for proving arithmetic circuit satisfiability. The known methods [Bootle 2016][Groth 2009] involve batching commitments to circuit wire values to significantly reduce the size of the data that must be sent from the prover to the verifier (i.e., reduce the communication complexity). These methods achieve a communication complexity reduction from to or for the proof system.

[0060] Again, as a comparison for proving the satisfiability of the same SHA circuit, the size of the proof key for protocol [Bootle 2016] is only 5KB, and the key generation time is 180ms. The proof size is 24KB and takes approximately 4 seconds to generate, and the proof also takes approximately 4 seconds to verify.

[0061] These methods are not fully described here, except to set out the main vector batch protocols employed in the steps described below. This follows the same properties as the standard Pedersen commitment, but committing to n elements (m = m 1 ,…,m n ) requires sending only a single group element:

[0062] 1. The prover and verifier agree on a group element

[0063] 2. The prover generates n random numbers

[0064] 3. The prover computes the points K i = x i × F (for i = 1,…,n). These values form the proof key PrK sent to the verifier.

[0065] 4. The prover generates random values:

[0066] 5. The prover computes the commitment:

[0067]

[0068] and sends it to the verifier. SUMMARY OF THE INVENTION

[0069] Generally, the present invention resides in a computer-implemented method for achieving zero-knowledge proof or verification of statements. A prover can use the method herein to prove to a verifier that a statement is true while keeping the witness for the statement confidential. These statements are composite statements that involve both arithmetic circuit satisfiability and subordinate statements (key statement proofs) regarding the validity of public keys.

[0070] The method herein can be used in known protocols for circuit satisfiability, such as existing zero-knowledge proof protocols based on discrete logarithms. The method is particularly suitable for protocols that do not require the use of bilinear pairing-friendly elliptic curves.

[0071] In the method, the prover sends a data set including the statement to the verifier, where the statement is that for a given functional circuit output and an elliptic curve point, the functional circuit input is equal to the corresponding elliptic curve point multiplier. The data includes individual wire commitments and / or batch commitments, inputs, and outputs for the circuit for the statement. The prover can include in the data the specification of the elliptic curve or each elliptic curve used in the statement, or the specification of the elliptic curve or each elliptic curve used in the statement has been shared in advance. Then, in response to a challenge from the verifier, the prover sends the disclosure. Alternatively, the prover additionally includes the proof key.

[0072] Using the data received from the prover, the verifier can determine that the circuit is satisfied and verify the statement, thereby determining that the prover holds a witness to the statement. Elliptic curve points can also be calculated. When receiving the data, the verifier determines by calculation that the data conforms to the statement. The present invention is particularly suitable for equivalent zero-knowledge proofs of hash preimages and elliptic curve private keys.

[0073] Accordingly, in accordance with the present invention, there is provided a method and system as defined in the appended claims.

[0074] Accordingly, it is desirable to provide a computer-implemented method that is a computer-implemented method for implementing a zero-knowledge proof or verification of a statement, in which a prover proves to a verifier that the statement is true while keeping secret a witness (W) to the statement. The proof can be an explicit proof.

[0075] There can be provided a computer-implemented method for implementing a zero-knowledge proof or verification of a statement (S), in which a prover proves to a verifier that the statement is true while keeping secret a witness (w) to the statement, the method comprising:

[0076] The prover sends to the verifier the following:

[0077] A statement (S) represented by an arithmetic circuit having m gates and n wires, the arithmetic circuit being configured to implement a functional circuit and determine whether, for a given functional circuit output (h) and an elliptic curve point (P), the functional circuit inputs (s) to the wires of the functional circuit are equal to the corresponding elliptic curve point multipliers (s);

[0078] Individual wire commitments and / or batch commitments for the wires of the circuit;

[0079] The functional circuit output (h);

[0080] A proof key (PrK),

[0081] This enables the verifier to determine that the circuit is satisfied and calculate the elliptic curve point (P) and verify the statement, thereby determining that the prover has a witness (w) to the statement.

[0082] The method includes: the prover sending a data set to the verifier. The data set includes a statement having an arithmetic circuit, the arithmetic circuit having m gates and n wires, the arithmetic circuit being configured to implement a functional circuit and determine whether, for a given functional circuit output (h) and an elliptic curve point (P), the functional circuit inputs (s) to the functional circuit or the wires in the functional circuit are equal to the corresponding elliptic curve point multipliers (s). The functional circuit can be a circuit that implements the function of a hash function. The preimage of the hash function circuit or the wires in the function circuit can be equal to the corresponding elliptic curve point multiplier.

[0083] The data also includes individual wire commitments and / or batch commitments. The commitment or each commitment can be an encrypted wire input and output for the gates of the circuit. The data also includes an input. The input operation is the public disclosure of a key for a wire [elliptic curve point (P)] of an arithmetic circuit. Either the prover or the verifier can name the wire. The input or key disclosure can be for the first wire in the circuit. The data also includes the functional circuit output. The specification of the elliptic curve or each elliptic curve used in the statement can be included in the data.

[0084] After sending the data, the prover receives a challenge value from the verifier and responds publicly. The public disclosure can be a value statement according to the ∑ (sigma) protocol. The public value can be for each gate of the circuit such that the verifier can determine that the statement is true and calculate the elliptic curve point.

[0085] As an alternative to waiting for the challenge, the prover can additionally send a proof key to the verifier. The proof key can be generated from the data that is part of the proof. The proof key can be a hash value of one or more random numbers used in the proof.

[0086] The data sent to the verifier enables the verifier to determine that the circuit is satisfied, calculate the elliptic curve point, and verify the statement, thereby determining that the prover has a witness for the statement.

[0087] The sent data set and / or the public disclosure of the challenge sent to the verifier can act like a key created independently of the verifier. The challenge from the verifier is similar to determining the identity of the prover and the integrity of the key.

[0088] The input or key disclosure can be for the first wire in the arithmetic circuit. However, preferably, a random wire is selected because it is more difficult for the proof to know the intermediate wire than the first wire. Also, selecting any wire other than the first wire is more robust and prevents a malicious third party from discovering the proof or witness.

[0089] It is also desirable to provide a complementary computer-implemented method, which is a computer-implemented method for implementing a zero-knowledge proof or verification of a statement, in which the verifier verifies that the statement is true by analyzing the data received from the prover without knowing the witness (w) for the statement. Clearly, the method of the present invention extends to the peer actions taken by the verifier in a plug-socket manner. The present invention extends to the overall cooperation between the prover and the verifier.

[0090] The prover can send individual wire commitments and communicate with the verifier using a ∑ (Sigma) protocol to prove knowledge of the witness. When receiving an individual wire commitment from the prover, the verifier can communicate with the prover using the ∑ protocol to confirm that the prover has knowledge of the witness.

[0091] In addition to or as an alternative to waiting for the challenge value, the prover can send a random value to the verifier to enable the verifier to determine that the statement is true and compute an elliptic curve point. When receiving data from the prover, the verifier can alternatively receive a random value to enable the verifier to determine that the statement is true and compute an elliptic curve point. The random value can be a function of at least one commitment. The function can be a hash function.

[0092] The random value or the challenge can be replaced to improve the convenience and efficiency of the process. There is also a risk associated with the verifier generating a non-random challenge in an attempt to extract information about the witness. Moreover, replacing the challenge value with a random value provided by the prover converts the method from an interactive method to a non-interactive method. The prover can generate a proof that can be independently and publicly verified offline. The random value can be the output from a hash function. Replacing the random value (x) with the output of the hash value from one or more commitments utilizes the Fiat-Shamir principle.

[0093] The random value can be computed by hashing the concatenation of all commitments generated by the prover and sent to the verifier.

[0094] The commitment can be:

[0095] W i =Com(w i ,r i )

[0096] where

[0097] Com is the commitment to the functional circuit,

[0098] w i is the wire value,

[0099] r i is a random number, i.e., for each wire commitment, the random number is different, and

[0100] i is the wire name,

[0101] such that

[0102] Com(w,r) = w×G + r×F

[0103] where

[0104] F and G are elliptic curve points.

[0105] The input of line l in the arithmetic circuit can be:

[0106] ko = r l x F,

[0107] where

[0108] ko is the input with the key made public,

[0109] r l is a random number, and

[0110] F is a point on the elliptic curve.

[0111] The line can be the first line in the circuit.

[0112] The verifier can confirm that the circuit is satisfied and can calculate the public key of line l through elliptic curve point subtraction:

[0113] pk l = Com(w l ,r l ) - ko l

[0114] The prover can send batch commitments of lines and generate random numbers to calculate the elliptic curve points of each line, thus forming a proof key.

[0115] The batch commitments for the witnesses can be

[0116]

[0117] where

[0118] r is the random number generated by the prover,

[0119] The prover calculates the commitment of the vector w i (for i = 1,..., n) of the line value w, where w n will have the key made public,

[0120] K i is the calculated elliptic curve point,

[0121] w i is the line value, where w n has the key made public,

[0122] F is a point on the elliptic curve.

[0123] The input of line n in the arithmetic circuit is:

[0124]

[0125] where

[0126] ko n is the input where the secret key is made public,

[0127] r is a random number, and

[0128] F is a point on the elliptic curve.

[0129] The input can be for the first line.

[0130] The verifier can calculate the public key made public for the key statement line through elliptic curve arithmetic:

[0131] pk n = Com(w) - ko n

[0132] Additionally, the prover can send a fully public commitment to at least one line. The method can use Pedersen commitment. The statement can only use one arithmetic circuit for the functional circuit. The functional circuit can implement a hash function, and preferably is the SHA-256 hash function.

[0133] The method can be used by the prover to achieve zero-knowledge or accountable transactions for data (e.g., encryption keys), where the prover contacts the verifier to confirm the data to be provided and the data to be received, and establishes a communication channel with the verifier (the channel can be public), the prover receives the elliptic curve public key pk B from the verifier, B where the verifier has generated the elliptic curve public key pk B from a secure random secret key sk

[0134] pk V = sk V × G, and G is the elliptic curve,

[0135] The prover ensures to provide a locking value i for the data such that

[0136] data = pk V + i × G

[0137] The prover can perform a search for the required pattern in the Base58-encoded address obtained by changing i. The prover sends its public key pk P and the output f(i) from the functional circuit to the verifier, where pk P = i × G, and the input to the functional circuit (e.g., preimage) is the locking value i.

[0138] The prover can send a statement proof to the verifier, which proves to the verifier that the input to the functional circuit is related to pk Pthe corresponding private key, enabling the verifier to verify the proof and confirm that the address corresponding to pk = pk V + pk P matches the agreed pattern, thereby determining that the complete private key capable of deriving data from the locked value i is known and that the locked value i is the functional circuit input to the functional circuit.

[0139] The prover can receive the transaction Tx from the verifier 1 , where the transaction Tx 1 contains an output that contains the data to be received, which can be accessed through the signature from the prover and the functional circuit input i. The transaction can be a hashed time-locked function.

[0140] The prover can sign and broadcast the transaction on the blockchain where the transaction is mined into a block, enabling the prover to access the data of the output from the transaction Tx 2 by providing a second transaction Tx 1 whose output data, where the second transaction Tx 2 provides its signature and value i to unlock the transaction, and then the transaction is revealed on the blockchain, enabling the verifier to identify the locked value I and access the data provided by the prover, where

[0141] sk = sk B + i,

[0142] where pk = sk × G

[0143] The transaction can be fully atomic and trustless: the buyer can pay only when the buyer provides a valid value i that is publicly revealed on the blockchain. Due to the splitting of the private key, the value exposed on the blockchain is useless to anyone else and does not compromise the security of the complete private key.

[0144] A computer-implemented method can involve: the prover performing a trustless fair exchange of data with the verifier (without a third-party centralized exchange). This can be described as a cross-chain atomic exchange or atomic transaction, as the fair exchange nature is referred to in this context: both parties either complete their transactions or neither does. Such an exchange can be performed between blockchains that support script functionality that implements hashed and time-locked contracts.

[0145] The prover accesses first data on a first blockchain, and the verifier accesses second data existing on a second blockchain, and the prover and the verifier reach an agreement on exchanging the data. The method includes: The prover generates a key pair for the second blockchain, sends the public key to the verifier, and retains the private key; The prover receives the verifier's public key for the first blockchain, where the verifier has generated a key pair for the first blockchain and retained the private key; The prover sends a statement, one or more commitments, input or key disclosure, and the output of the functional circuit, as well as the elliptic curve specification.

[0146] The prover can create a first blockchain transaction Tx A , the transaction Tx A sends the first data to a public public key address and broadcasts the transaction on the first blockchain network, where the address is defined by the sum of the input and the verifier's public key. The prover can access the data after 24 hours from the exchange without further exchange.

[0147] The prover can verify a second blockchain transaction Tx B , the transaction is created by the verifier on the second blockchain network and broadcast on the second blockchain network after the first blockchain transaction Tx A is included in the first blockchain. The transaction sends the second data to the prover's public key address, which can be accessed by the prover using a valid signature for the prover's public key address and the value of the functional circuit input used to determine the output of the functional circuit. The verifier can access the data after 24 hours from the exchange without further exchange.

[0148] The prover confirms that the second blockchain transaction Tx B is included on the second blockchain and accesses the second data by providing its signature and the value of the functional circuit input as the output of the functional circuit, enabling the verifier to observe the value of the functional circuit input used to determine the output of the functional circuit and access the first data by providing a signature using the private key (for P C , which is s B +s from the homomorphic property of elliptic curve point multiplication).

[0149] As described above, each action of the prover requires a corresponding action of the verifier to verify the proof. The present invention extends to methods or actions performed by the verifier. Accordingly, there is provided a computer-implemented method for achieving zero-knowledge proof or verification of a statement, in which the prover proves (preferably explicitly) to the verifier that the statement is true while keeping the witness of the statement confidential, the method comprising: the verifier receiving from the prover: a statement having an arithmetic circuit having m gates and n wires configured to implement a functional circuit (preferably a hash function), and determining whether the functional circuit input or preimage of the function is equal to the elliptic curve point multiplier for a given functional circuit, and preferably a specified functional circuit, output, and elliptic curve point. The verifier also receives: individual wire commitments and / or batch commitments for the wires of the circuit, which are encrypted wire inputs and outputs; inputs or keys for the wires (preferably wires other than the first wire) in the arithmetic circuit are made public; and the functional circuit output (h). The verifier may also receive the elliptic curve or the specification of each elliptic curve used in the statement. The verifier may send a challenge value to the prover and then receive the disclosure. The disclosure may proceed according to the Σ protocol and include the values of each gate of the circuit, which enable the verifier to determine that the statement is true and calculate the elliptic curve point. Additionally or alternatively, the verifier may receive a proof key from the prover.

[0150] The verifier then determines that the circuit is satisfied, calculates the elliptic curve point (P) and verifies the statement, thereby determining that the prover holds the witness (w) of the statement.

[0151] This can be achieved by proving in zero knowledge that the prover knows the values of each gate of the statement circuit using the Sigma protocol (if the proof is interactive) or using the proof key (if the Fiat-Shamir heuristic is used). The verifier may receive from the prover the Σ_zero and Σ_prod commitments for each gate, a response using the challenge value, receive the disclosure value from the prover and check the commitments. The verifier may confirm that the circuit is satisfied by calculating the public key for wire l via elliptic curve point subtraction. The verifier may confirm that each public key for each wire matches the (one or more) keys specified in the statement. The verifier may determine that the fully disclosed wires match the values that may be specified in the statement to complete the verification.

[0152] There is also a desire to provide a computer-readable storage medium comprising computer-executable instructions that, when executed, configure a processor to perform a method performed by a prover, a verifier, or a collaborative prover and verifier.

[0153] It is also desirable to provide an electronic device including: an interface device; one or more processors coupled to the interface device; a memory coupled to the one or more processors, on which computer-executable instructions are stored, and when the computer-executable instructions are executed, the one or more processors are configured to execute the methods claimed herein. It is also desirable to provide a node of a blockchain network, which is configured to execute the claimed methods. It is also desirable to provide a blockchain network having, such as, nodes. BRIEF DESCRIPTION OF THE DRAWINGS

[0154] The basic system for interactive zero-knowledge proofs has been described above in the technical background section, where Figure 1a and Figure 1b describe a basic system for interactive zero-knowledge proofs, where Figure 1a is a schematic diagram of a multiplication gate having a left wire input, a right wire input, and one wire output, while Figure 1b is a schematic diagram of an arithmetic circuit having three gates, three input wires, one output wire, and two internal wires.

[0155] Aspects of the present invention will become apparent from and will be elucidated with reference to the embodiments described herein. The embodiments of the present invention will now be described only by way of example and with reference to the accompanying drawings, in which:

[0156] Figure 2 is a schematic diagram of a composite circuit for a statement, which composite circuit includes an arithmetic circuit for a hash function and an elliptic curve multiplication;

[0157] Figure 3 is an alternative schematic diagram of the arithmetic circuit of the composite statement of FIG. 1, where only one arithmetic circuit is required;

[0158] Figure 4 is a schematic diagram of an arithmetic circuit having four gates and five wires, where the public key of the wire is revealed or made public from a wire commitment having a key public value;

[0159] Figure 5 is a schematic representation of the data for a proof of a statement S exchanged between a prover and a verifier, the statement having a circuit description and the first wire having a corresponding public key;

[0160] Figure 6 is an alternative schematic representation of the data exchanged between the prover and the verifier; and

[0161] Figure 7 is a schematic diagram of the checks performed when the circuit verified by the verifier Figure 4 is satisfied, where the input wires have the required public keys and the hash value of the output wire has the required value. DETAILED DESCRIPTION

[0162] General Overview

[0163] The present invention enables efficient zero - knowledge verification of a composite statement that involves both arithmetic - circuit satisfiability and a sub - statement (key - statement proof) regarding the validity of a public key. A public - key elliptic - curve specification is employed in a homomorphic commitment function to prove circuit satisfiability. This enables proving a public - key statement corresponding to a private key used as a circuit input and / or output in an efficient manner.

[0164] The proof size and computational cost for generating a proof for a statement involving both circuit satisfiability and an elliptic - curve key - pair can be significantly reduced. The method herein can be easily incorporated into existing discrete - logarithm - based zero - knowledge proof protocols for circuit satisfiability without using bilinear - pairing - friendly elliptic curves.

[0165] Two applications of the method related to transactions of fair exchange between two parties on a blockchain are described. The first application involves zero - knowledge contingent payments for the trustless sale of an outsourced address, which requires a zero - knowledge proof of the equality of a SHA256 hash pre - image and an elliptic - curve secret key. The second application involves enhancing the security of cross - chain atomic swaps, which requires proving that a SHA256 hash pre - image is equal to an unknown private key (using a supplied public key) multiplied by a supplied random number (nonce).

[0166] General Scheme

[0167] The present invention relates to a method that enables proving a specific class of composite statements that involve a relationship with an elliptic - curve public - key / private - key pair (based on elliptic - curve point multiplication).

[0168] Using zkSNARKs to prove statements involving arbitrary encrypted elliptic - curve key operations is considered impractical, and thus, the method uses information about the elliptic - curve public key that is directly extracted from the 'homomorphic hiding' (or commitment scheme) used in constructing a proof for general circuit satisfiability. The specific type of elliptic curve involved in the statements of the method is the same as the elliptic curve used in the circuit commitment scheme.

[0169] However, the SNARK method involves pairing operations and thus requires special bilinear - pairing - friendly elliptic curves. Since the elliptic curves used on some blockchains are not compatible with bilinear - pairing - friendly elliptic curves, the use of zk - SNARKs is precluded.

[0170] Thus, the method of the present invention is compatible with alternative protocols for proving arithmetic - circuit satisfiability that do not rely on pairings and have fewer cryptographic assumptions. Overall, the method of the present invention is more efficient than zkSNARKS as it requires less computation and reduces the size of the proof for trustless - exchange applications.

[0171] For example, the schematic diagram of the composite circuit representing the following "Statement 1" Figure 2 contains sub-circuits for both a hash function and an elliptic curve multiplication. In Figure 2 , the schematic diagram has three inputs: a secret key "s" with a corresponding paired public key "P" and a value "h" that is the hash value of the secret key "s". The schematic diagram contains two arithmetic circuits, where the first arithmetic circuit performs hashing on the secret key, and the second arithmetic circuit performs elliptic curve multiplication on the secret key. The output of the circuit is compared with the input.

[0172] Note that the internal gates are for illustrative purposes only. The circuit checks that the output of the hash is equal to the elliptic curve (EC) public key. Only the inputs "h", "P", and the output are fully revealed to the verifier. All other values are encrypted.

[0173] Statement 1

[0174] "Given the output h of a hash function (H) and an elliptic curve point P (public key),

[0175] then the preimage s of the hash (i.e., h = H(s)) is equal to the elliptic curve point multiplier (private key, i.e., P = s × G, where G is the elliptic curve generator point)"

[0176] This method enables the prover to prove this specific statement in zero knowledge. Examples of applications that benefit from this method will be described below in connection with the trustless exchange of data and anonymous and secure cross-chain atomic swaps.

[0177] For example, using the following pseudocode function, the verification of the truth of Statement 1 is determinable. The pseudocode function takes the inputs "h", "P", and "s" and outputs "1" if the statement is true and "0" otherwise:

[0178]

[0179] According to Figure 2 , verifying "Statement 1" in zero knowledge (i.e., the prover uses the zkSNARK system to keep the value of "s" secret from the verifier) would require arithmetic circuits for both the hash function and the elliptic curve point multiplication.

[0180] Although arithmetic circuits for the SHA-256 hash function have been widely used and optimized and typically contain fewer than 30,000 multiplication gates, there are no known examples in the literature of implementing arithmetic circuits for cryptographic elliptic curve point multiplication. Even if such circuits were known, they would be impractical due to their size and complexity and the inclusion of more gates.

[0181] AsFigure 2 As shown, the method operates using a complete arithmetic circuit for a single hash function, Figure 2 with an arithmetic circuit for composite statement 1 using key statement proof and only one arithmetic circuit for the hash function. The circuit checks whether the output of the hash is correct and whether the public key is equal to the EC-encrypted input (key statement proof). The values highlighted in blue (i.e., the input "h", "P", and output "1") are revealed to the verifier, and all other values are encrypted.

[0182] Using Figure 3 the circuit, the prover can clearly prove that the secret key "s" hashes to "h" and that the corresponding public key "P" of the key pair is equal to "s × G", where G is the elliptic curve generator point. The secret key "s" is the preimage of the hash or the input to the function and is not revealed to the verifier when proving the statement.

[0183] Notably, verifying that "s × G" equals "P" can be extracted from the circuit proof at a negligible additional computational cost by employing the required elliptic curve in a commitment scheme as part of the proof protocol. Such an operation is called "key statement proof" and uses a commitment disclosure procedure called "key disclosure".

[0184] Technical Effects

[0185] Known zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARKs) are implementations of general proof systems for arithmetic circuit satisfiability. In the SNARK framework, a statement encoded as an arithmetic circuit is transformed into a construct called a quadratic arithmetic program (QAP), which consists of a set of polynomial equations. The statement is then proven by demonstrating the validity of this set of equations at a single point. The main advantage of the SNARK method is that the verifier only needs to perform a few elliptic curve (pairing) operations (taking a few milliseconds), and the proof is very small (288 bytes) and independent of the circuit size.

[0186] The very small proof and verification times achieved by the SNARK method come at the cost of a trusted setup, non-standard cryptographic assumptions, and a heavier computational burden borne by the prover. The SNARK method also requires the use of elliptic curve bilinear pairings. However, using computationally feasible bilinear pairings requires the use of special "pairing-friendly" elliptic curves. This rules out the use of many standard cryptographic elliptic curve parameter sets. Then, statements involving general elliptic curve point multiplications must use explicit circuits (which can be very large).

[0187] By comparison with the ∑-protocol method for proving the satisfiability of the SHA circuit described in the previous section, using the SNARK (Pinocchio) framework, generating the proof key will take approximately 10 seconds and the size of the proof key will be approximately 7MB, and the proof will also take approximately 10 seconds to generate. However, the size of the proof is 288B and it only takes approximately 5 milliseconds to verify [Bootle 2016] .

[0188] In addition, incorporating explicit elliptic curve multiplication (key statements) into the circuit multiplies (multiply) both the proof key size and the proof generation time by at least one order of magnitude.

[0189] The present invention implements zero-knowledge proofs of statements that simultaneously involve elliptic curve public-private key relationships and general arithmetic circuit satisfiability. In addition to proving the satisfiability of arithmetic circuits, this can be achieved at negligible computational cost and avoids the need to create explicit arithmetic circuits for elliptic curve point multiplication operations that would greatly increase the computational cost of the proof.

[0190] Implementation

[0191] The implementation of the present invention is described below for zero-knowledge proof systems based on batch and non-batch commitments.

[0192] In the example, the zero-knowledge proof protocol involves two parties: the prover (P) and the verifier (V). The purpose of the protocol is for the prover to convince the verifier that a given statement is true while keeping the information about the witness of the statement confidential. The statement consists of an arithmetic circuit with m gates and n wires and a subsidiary assertion about one or more elliptic curve public keys pk l corresponding to one or more circuit wire values, where the subscript l is the wire index of the key statement. In addition, the statement may also include assertions about fully public (common) wire values (i.e., the public inputs / outputs of the circuit).

[0193] The one or more elliptic curve public keys specified in the statement correspond to a target elliptic curve specification (which is defined by a complete set of elliptic curve parameters: ).

[0194] In one case, these parameters are defined by the specification of secp256k1 [SEC 2010] which includes the base generator point G. In addition to specifying the base point, the statement must also specify a second point F (where F = f × G and f is The value of f must be provably random or a "nothing up my sleeve" number, such as the first 256 bits of the binary representation of π, because allowing the prover to freely choose f would enable them to generate forged proofs.

[0195] Regarding Figure 4 describes both batched and unbatched commitments, Figure 4 is a representative arithmetic circuit with four gates and five wires. The input wire (w 1 ) makes its public key from the wire commitment W with the value 'key public' ko 1 being revealed or made public. 1

[0196] Implementation - Individual wire commitments

[0197] Take Figure 4 as an example, 'key public' is an individual commitment for each wire in the circuit. These commitments are created by the prover and sent to the verifier. These key publics follow the known Σ - protocol for arithmetic - circuit satisfiability. Figure 5 shows the data exchanged between the prover and the verifier.

[0198] Satisfiability is achieved through multiple steps including the following:

[0199] 1. Each wire i (i = 1,..., n) of the circuit is committed to with a Pedersen commitment:

[0200] W i = Com(w i , r i )

[0201] where

[0202] Com(w, r) = w×G + r×F

[0203] 2. For a circuit wire l that requires a proof (key - statement proof) for its corresponding public key, the prover also sends the key public:

[0204] ko l = r l ×F

[0205] 3. Optionally, if a circuit wire j needs to be publicly revealed (fully - public wire), the prover sends a full - opening tuple:

[0206] (w j , r j )

[0207] 4. Then use the Σ protocol to prove in zero knowledge that each gate of the circuit is satisfied, which involves the prover computing and sending Σ zero and Σ prod commitments (i.e., for B or C 1 , C 2 , C 3 respectively), and the verifier replies with a challenge value (x), then the prover sends the public values (the z - value and the e - value), and then the verifier checks the commitments.

[0208] 5. Once the verifier confirms that the circuit is satisfied, the verifier then computes the public key of line l by elliptic curve point subtraction:

[0209] pk l = Com(w l , r l ) - ko l

[0210] 6. Then, the verifier confirms that each pk l matches the (one or more) keys specified in the statement (and the fully public lines match the specified values) to complete the verification.

[0211] Implementation details - separate line commitments

[0212] Continue Figure 4 , providing explicit examples of separate commitments and verification that detail the example, which describes verifying the satisfiability of a simple arithmetic circuit using both a key statement proof for one of the lines and a full disclosure of another line.

[0213] As Figure 4 shown in the circuit has 5 lines w i (i = 1, …, 5) and 4 gates g j (j = 1, …, 4). Gates 1 and 3 are addition gates, and gates 2 and 4 are multiplication gates.

[0214] The prover and the verifier agree on a statement that includes the circuit, the value of line 5 and the public key of line 1, as well as the elliptic curve and commitment specifications. The statement that the prover wants to prove to the verifier is:

[0215] "I know an assignment that satisfies the circuit (i.e., the line values that satisfy all gates where line 1 has the public key P (i.e., P = w 1 ×G), and line 5 has the value h (i.e., w n = h)"

[0216] The values of lines 1 to 4 are not disclosed. Then, the prover and the verifier proceed asFigure 6 interact as shown below:

[0217] 1. The prover generates 5 random blinding values (r 1 , …, r 5 ), and then calculates 5 linear commitments (W 1 , …, W 5 ) and sends these to the verifier.

[0218] 2. The prover calculates the key disclosure for line 1: ko 1 = r 1 × F and sends it to the verifier.

[0219] 3. The prover sends the complete disclosure information for line 5 (w 5 , r 5 ) to the verifier.

[0220] 4. For the addition gates (g 1 and g 3 ), the prover generates commitments to zero (using random nonces r B1 and r B3 ): B 1 = Com(0, r B1 ) and B 3 = Com(0, r B3 ) and sends them to the verifier.

[0221] 5. For the multiplication gates (g 2 and g 4 ), the prover will generate commitments as follows:

[0222] For gate 2:

[0223] C 12 = Com(t 12 , t 32 ),

[0224] C 2 = Com(t 22 , t 52 ), and

[0225] C 3 = t 12 × W 1 + t 42 × F

[0226] For gate 4:

[0227] C 14 = Com(t 14 , t 34 ),

[0228] C 2 = Com(t 24 , t 54 ), and

[0229] C 3 = t 14 × W 3 + t 44 × F

[0230] where t xx is a random blind random number. The prover sends these commitments to the verifier.

[0231] 6. Then the verifier generates a random challenge value x and sends it to the prover. Alternatively, the prover can use the Fiat-Shamir heuristic to generate the value x by hashing the concatenation of all commitments.

[0232] 7. For addition gates (g 1 and g 3 ), the prover calculates the following publicly and sends it to the verifier:

[0233] z 1 = x(r 1 + r 1 - r 2 ) + r B1

[0234] z 3 = x(r 2 + r 1 - r 4 ) + r B3

[0235] 8. For multiplication gates (g 2 and g 4 ), the prover calculates the following publicly and sends it to the verifier:

[0236] e 12 = w 1 x + t 12

[0237] e 22 = w 2 x + t 22

[0238] z 12 = r 1 x + t 32

[0239] z 22 = r 2 x + t 52

[0240] z32 = (r 3 - w 1 r 2 )x + t 42

[0241] e 14 = w 3 x + t 14

[0242] e 24 = w 4 x + t 24

[0243] z 14 = r 3 x + t 34

[0244] z 24 = r 4 x + t 54

[0245] z 34 = (r 5 - w 3 r 4 )x + t 44

[0246] 9. Finally, the verifier checks the equality. If these pass, the proof is verified.

[0247] The verification performed by the verifier is outlined in Figure 7 where the checks within the inner box will verify that the circuit is satisfied and the first line has the required public key and line 5 has the required value.

[0248] Figure 5 and 6 The challenge "x" in

[0249] provides an interactive proof where the communication passes back and forth between the prover and the verifier.

[0250] This interaction may be convenient when zero - knowledge or with - payment (ZKCP) occurs because the seller and the buyer may not be available or online at the same time. Additionally, the proof by the buyer (verifier) may be desired to be publicly verifiable, for example, it may be part of an advertisement for a digital good.

[0251] To address these issues, the Fiat-Shamir heuristic is applied, which replaces the random challenge value "x" with the output of the hash value of the commitments made by the prover. In the random oracle model (where the output of the cryptographic hash function is considered truly random), the prover cannot cheat, and the verifier can check the generated challenge value.

[0252] Thus, the example can be improved by converting the interactive proof system into a non-interactive proof system using the Fiat-Shamir heuristic method, and the prover can generate proofs that can be verified offline independently and publicly.

[0253] More specifically, the challenge value (x) is replaced with the value calculated by hashing (using, for example, SHA-256) the concatenation of all the commitments generated by the prover (i.e., all the wire commitments for the sum gates and product gates respectively, and all the B and C 1 、C 2 、C 3 commitments).

[0254] Implementation - Batched Vector Commitments

[0255] For a compressed proof system for circuit satisfiability involving batches of vector commitments [Bootle 2016,Groth 2009] the method described below is used, where the method is capable of extracting key statement proofs from batched circuit wire commitments.

[0256] To avoid repetition, the entire process is not described, and the following steps focus on the generation of batched wire commitments and demonstrate that they contain the specified public keys. In the steps below, the batched commitments are generated as follows, where wire l will be provided with a key public - n wires are batched together in the vector commitment.

[0257] 1. The prover generates n - 1 random numbers

[0258] 2. The prover calculates the elliptic curve point K i =x i ×G (for i = 1, …, n - 1).

[0259] These values plus K n =G form the proof key PrK sent to the verifier.

[0260] 3. The prover generates random values:

[0261] 4. The prover calculates the commitment to the vector w of wire values w i (for i = 1, …, n), where w n is to be key public:

[0262]

[0263] and send it to the verifier.

[0264] 5. The prover also sends the key disclosure for the vector commitment:

[0265]

[0266] 6. The verifier calculates the public key disclosure of the key statement line through elliptic curve arithmetic:

[0267] pk n = Com(W) - ko n Summary of the Invention

[0269] Proofs of equality of hash pre-images and elliptic curve private keys can be used in numerous applications. Two applications are described below, which outline specific examples of constructing zero-knowledge proofs of key statements for the applications.

[0270] For the purpose of example applications, the following statement S is a more specific version of the above statement 1, where "Given a SHA-256 hash function (H) with a public output h and a public point P on the secp256k1 elliptic curve, the secret pre-image s of the hash (i.e., h = H(s)) is equal to the elliptic curve point multiplier (i.e., the corresponding private key, i.e., P = s × G)"

[0271] In the provided example, the statement consists of a single arithmetic circuit for the SHA-256 hash function (with n wires w i (i = 1,..., n) and m gates) and the assertion that the input wire (w 1 ) is the private key of the public point P and the output wire (w n ) is equal to h, i.e.:

[0272] By wire AND w 1 × G = P AND w n is satisfied

[0273] Therefore, to fully verify the statement, the prover must use a secp256k1-based commitment scheme to demonstrate to the verifier that they know a satisfying assignment for the SHA256 circuit, and then only provide the key disclosure for wire 1 (ko 1 ) and the full disclosure for wire n (w n , r n ). The verifier does not get the values of the input wires (w 1 ) nor does it get anything other than the fully disclosed output wire wn Values of any other line other than

[0274] Application I

[0275] As described in the implementation section above, an example of the present invention can be applied to the ZKCP of the outsourcing address, which represents the data to be exchanged for payment or access to resources.

[0276] The address is encoded in a human-readable alphanumeric format (Base58 encoding) to make it easy to disclose, copy, and transcribe. 1. The buyer and the seller reach an agreement on the required pattern (Str) and price and establish a communication channel that does not need to be protected.

[0277] 2. The buyer generates a secure random secret key sk B and the corresponding elliptic curve public key, where the public key pk B = sk B ×G

[0278] 3. The buyer sends pk B to the seller.

[0279] 4. Then, the seller performs a search for the required pattern in the Base58-encoded addresses derived by changing i from pk = pk B + i×G.

[0280] 5. When an address with the required pattern is found, the seller saves the value of i, signals the buyer, and then sends them pk s = i×G and the SHA256 hash H(i).

[0281] 6. The seller also provides the buyer with a proof that the preimage of H(i) is the private key corresponding to pk s as described in the example above.

[0282] 7. The buyer verifies the proof and also confirms that the address corresponding to pk = pk B + pk s matches the agreed pattern. At this point (by virtue of the proof), the buyer knows that learning the value of i will enable them to derive the complete private key for the address (sk B + i), and the specific value of i hashes to h = H(i).

[0283] 8. Then, the buyer constructs a hash time-locked contract (HTLC) transaction Tx 1 , which contains an output that contains the agreed-upon fee (a). This output can be unlocked in two ways:

[0284] i. Unlock it at any time using the signature and hash preimage i from the seller.

[0285] ii. Unlocking with a signature from the buyer after a specified time by using, for example, the CHECKLOCKTIMEVERIFY (OP_CLTV) script opcode, which can be used to prevent the output from being spent before a specified time or block height.

[0286] 9. The buyer then signs the transaction and broadcasts it to the blockchain where it is mined as a block.

[0287] 10. Once confirmed, the seller can provide the transaction Tx 2 Come to Tx 1 The transaction Tx 2 Its signature and value i are provided to unlock the hash lock, which is then revealed on the blockchain.

[0288] 11. The buyer can calculate the final address private key sk = sk B +i, where pk = sk × G

[0289] 12. If the buyer fails to provide the value i before the specified OP_CLTV time, the seller can provide his signature to reclaim the fee (to prevent losing fees due to an uncooperative buyer).

[0290] The transaction is thus completely atomic and trustless: the buyer can only pay if he provides a valid value i that is publicly disclosed on the blockchain. Due to the splitting of the private key, this value is useless to anyone else and the security of the full private key is not compromised.

[0291] General Applications

[0292] The present invention is applicable to zero-knowledge proof or verification of a statement (S), in which the prover proves to the verifier that the statement is true while keeping the witness (w) of the statement secret. The secret can be processed by a function such as a hash function, but the secret additionally includes cryptographic elliptic curve key operations, such as the validity of the statement about the public key. In the above example, the method of the present invention has been used to implement a trustless ZKCP for addresses. This can also be applied to, for example: the derivation of passwords; the verification of valid machine-readable documents, such as passports or identity cards; or other such confidential transactions.

[0293] It should be noted that the above-mentioned embodiments illustrate rather than limit the invention, and that those skilled in the art will be able to design many alternative embodiments without departing from the scope of the invention as defined by the appended claims.

[0294] In a claim, any reference signs placed in parentheses shall not be construed as limiting the claim. Words such as "comprising" and "including" do not exclude the presence of elements or steps other than those listed in any claim or the entire specification. In this specification, "comprising" means "comprising or consisting of" and "including" means "including or consisting of".

[0295] A singular reference to an element does not exclude a plural reference to such elements and vice versa. The present invention may be implemented by means of hardware comprising several distinct elements and by means of a suitably programmed computer.

[0296] In a device claim enumerating several devices, several of these devices may be implemented by one and the same item of hardware. The fact that certain measures are recited in mutually different dependent claims does not mean that a combination of these measures cannot be used advantageously.

[0297] References

[0298] [Campanelli 2017]Campanelli,Matteo,et al."Zero-knowledge contingent payments revisited:Attacks and payments for services."Commun.ACM(2017).[Maxwell 2016] https: / / github.com / zcash-hackworks / pay-to-sudoku

[0299] [Parno 2016]Parno,Bryan,et al."Pinocchio:Nearly practical verifiable computation."Security and Privacy(SP),2013IEEE Symposium on.IEEE,2013.[Libsnark 2016] https: / / github.com / scipr-lab / libsnark

[0300] [Bootle 2015]Bootle, Jonathan, et al. "Efficient zero-knowledge proof systems." Foundations of Security Analysis and Design VIII. Springer, Cham, 2015. 1-31. [Groth 2009]Groth, Jens. "Linear Algebra with Sub-linear Zero-Knowledge Arguments." CRYPTO. Vol. 5677. 2009.

[0301] [Bootle 2016]Bootle, Jonathan, et al. "Efficient zero-knowledge arguments for arithmetic circuits in the discrete log setting." Annual International Conference on the Theory and Applications of Cryptographic Techniques. Springer, Berlin, Heidelberg, 2016.

[0302] [SEC 2010]Standards for Efficient Cryptography(SEC)(Certicom Research, http: / / www.secg.org / sec2-v2.pd

Claims

1. A computer-implemented method for implementing zero-knowledge proof or verification of a statement (S), wherein wherein a prover proves to a verifier that the statement is true while keeping a witness (w) of the statement confidential, the method comprising: the prover sending data to the verifier, the data including: a statement (S) represented by an arithmetic circuit having m gates and n wires, the arithmetic circuit being configured to implement a functional circuit and determine whether a functional circuit input (s) to the wires of the functional circuit is equal to a corresponding elliptic curve point multiplier (s) for a given functional circuit output (h) and an elliptic curve point (P); individual wire commitments and / or batch commitments for the wires of the circuit; a functional circuit output (h); and a proof key (PrK), wherein the data enables the verifier to determine that the circuit is satisfied and calculate the elliptic curve point (P) and verify the statement, thereby determining that the prover has a witness (w) of the statement, wherein the method is used by the prover to implement zero-knowledge or with transactions for the data, wherein the prover contacts the verifier to confirm the data to be provided and the data to be received and establishes a communication channel with the verifier, The prover receives an elliptic curve public key pk from the verifier V , where the verifier has generated the elliptic curve public key pk from a secure random secret key sk V V , where​ pk V = sk V × G, and G is an elliptic curve point the prover ensures that a locked value i is to be provided for the data such that Data = pk V + i × G and the prover sends its public key pk to the verifier P and the output f(i) from the functional circuit, where P pk = i × G and the functional circuit input is the locked value i The prover sends the proof of statement (S) to the verifier, and the proof of statement (S) proves to the verifier that the input to the functional circuit is the private key corresponding to pk P corresponding private key So that the verifier can verify the proof and confirm that the address corresponding to pk = pk V + pk P matches the agreed pattern, thereby determining that knowing the locked value i can derive the complete private key (sk V + i) of the data, and determining that the locked value i is the functional circuit input i to the functional circuit The prover receives transaction Tx from the verifier 1 , where the transaction Tx 1 includes an output that includes data to be received, and the data is accessed by a signature from the prover and a functional circuit input i The prover signs and broadcasts a transaction on the blockchain where the transaction is mined into a block, enabling the prover to access the data of the output from transaction Tx 2 by providing a second transaction Tx 1 The second transaction Tx 2 provides its signature and value i to unlock the transaction, and then the transaction is revealed on the blockchain So that the verifier can identify the locked value i and access the data provided by the prover, where sk = sk V + i, where pk = sk × G, sk represents the final private key, and pk represents the public key corresponding to sk.

2. The computer-implemented method according to claim 1, wherein the prover sends individual wire commitments and communicates with the verifier using a Σ protocol to prove knowledge of the witness (w).

3. The computer-implemented method according to claim 1 or 2, wherein the prover receives a challenge value (x) from the verifier and responds publicly.

4. The computer-implemented method according to claim 1 or 2, wherein the prover sends a random value (x) to the verifier such that the verifier can determine that the statement is true and calculate the elliptic curve point (P).

5. The computer-implemented method according to claim 4, wherein the random value (x) is a function of at least one commitment.

6. The computer-implemented method according to claim 4, wherein the random value (x) is calculated by hashing the concatenation of all commitments generated by the prover and sent to the verifier.

7. The computer-implemented method according to claim 1, wherein The said commitment W i is as follows: W i = Com(w i ,r i ) where Com is a commitment to the functional circuit, w i is the line value, r i is a random number, which is different for each wire commitment, and i is a wire name, such that Com(w,r) = w × G + r × F where F and G are elliptic curve points, w is a vector, r is a random number generated by the prover.

8. The computer-implemented method according to claim 7, wherein the input for wire l in the arithmetic circuit is: ko = r l x F, where ko is the publicly known input of the key, r l is a random number, and F is a point on the elliptic curve.

9. The computer-implemented method according to claim 8, wherein the verifier confirms that the circuit is satisfied and can calculate the public key of wire l by elliptic curve point subtraction: pk l = Com(w l , r l ) - ko l 。 10. The computer-implemented method according to claim 1, wherein The prover sends batches of wire commitments and generates random numbers to compute elliptic curve points for each wire, thereby forming a proof key (PrK).

11. The computer-implemented method according to claim 10, wherein, the batch commitment for the witness is where r is a random number generated by the prover, The prover computes the line value w i Commitments of the vector w for (i = 1, …, n), Among them, w n will be made public by the key, K i is a calculated elliptic curve point w i is the line value, where w n is the key that is made public and F is a point on the elliptic curve.

12. The computer-implemented method according to claim 11, wherein, the input for wire n in the arithmetic circuit is: where ko n is the input with the key made public, r is a random number, and F is a point on the elliptic curve.

13. The computer-implemented method according to claim 12, wherein, the verifier computes the public key disclosure of the key statement wire via elliptic curve arithmetic: pk n = Com(w) - ko n .

14. The computer-implemented method according to claim 1, wherein, the prover additionally sends a fully public commitment to at least one wire.

15. The computer-implemented method according to claim 1, wherein, the method uses Pedersen commitments.

16. The computer-implemented method according to claim 1, wherein, the statement uses only one arithmetic circuit for the functional circuit.

17. The computer-implemented method according to claim 1, wherein, the functional circuit implements a hash function.

18. The computer-implemented method according to claim 17, wherein, the hash function is a SHA-256 hash function.

19. The computer-implemented method according to claim 1, wherein, the data is an encryption key.

20. The computer-implemented method according to claim 1, wherein, the prover and the verifier perform a trustless fair exchange of data, where the prover has access to first data on a first blockchain, and the verifier has access to second data existing on a second blockchain, and the prover and the verifier agree to exchange the data, the method comprising: The prover generates a key pair for the second blockchain, sends the public key (P A ) to the verifier, and retains the private key (s A ); The prover receives the verifier's public key (P B ) for the first blockchain, where the verifier has generated a key pair for the first blockchain and retained the private key (s B ). The prover sends a statement (S), one or more commitments, an input (P x ), and the functional circuit output (h), as well as the elliptic curve specification; The prover creates a first blockchain transaction Tx A , the first blockchain transaction Tx A sends the first data to a public key address (P c ), and broadcasts the transaction on the first blockchain network, the address being defined by the sum of the input (P x ) and the public key of the verifier (P B ) P C = P B + P x The prover verifies the second blockchain transaction Tx B , which is created and broadcast on the second blockchain network by the verifier after the first blockchain transaction Tx A is included in the first blockchain, and the transaction sends the second data to the public key address (P A ) of the prover, and the public key address (P A ) is accessible to the prover using the following: The public key address (P A ) of the prover with a valid signature (s A ), and as a value of the functional circuit input preimage for determining the output (h) of the functional circuit, and the prover confirms that the second blockchain transaction Tx B is included on the second blockchain and accesses the second data by providing its signature (s A ) and the value of the functional circuit input as the output (h) of the functional circuit Thus enabling the verifier to observe the values of the functional circuit inputs used to determine the output (h) of the functional circuit and access the first data by providing a signature using the private key of P C , where the private key of P C is s B + s from the homomorphic property of elliptic curve point multiplication.

21. A computer-readable storage medium comprising computer-executable instructions that, when executed, configure a processor to perform the method according to any one of claims 1 to 20.

22. An electronic device, comprising: an interface device; one or more processors coupled to the interface device; a memory coupled to the one or more processors, having computer-executable instructions stored thereon that, when executed, configure the one or more processors to perform the method according to any one of claims 1 to 20.

23. A node of a blockchain network, the node being configured to perform the method according to any one of claims 1 to 20.

24. A blockchain network having the node according to claim 23.