An Auction Tracing Method and Implementation System Based on Ethereum Privacy Protection

By using secret sharing and commitment technology on the Ethereum platform, combined with blockchain smart contracts and incentive mechanisms, the privacy protection and fairness of bids won by the auction system is solved, and the non-repudiation of user behavior and the efficient operation of the system is achieved.

CN113962714BActive Publication Date: 2025-06-20JIANGSU UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111332702.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-11
Publication Date
2025-06-20
Estimated Expiration
2041-11-11

AI Technical Summary

Technical Problem

The existing auction system has shortcomings in terms of privacy protection and fairness assurance of the standard value, resulting in user privacy leakage, fairness issues and waste of system resources.

Method used

Ethereum-based privacy protection auction traceability method is adopted to realize privacy protection of information on and off-chain information through secret sharing and commitment technology, and combine blockchain's smart contracts and incentive mechanisms to automatically implement punishment measures to ensure the fairness of auctions and the non-deniability of user behavior.

Benefits of technology

It realizes the privacy protection of the standard value, auction fairness and user behavior that is not refusal, reduces the interaction between users and auctioneers, and reduces the operating costs and complexity of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113962714B_ABST
    Figure CN113962714B_ABST
Patent Text Reader

Abstract

The present invention discloses an auction tracing method and an implementation system based on Ethereum privacy protection, comprising an off-chain auction allocation layer and an on-chain tracing evidence layer, and performs user registration based on secret sharing and commitment to realize on-chain and off-chain information privacy protection, while allowing the tracing of violating users in the dispute stage; for malicious user violations and auctioneer collusion, the violation tracing and punishment under privacy protection conditions are realized through dispute resolution; the present invention reduces the interaction between users and auctioneers; different from auction schemes that completely rely on blockchain smart contracts, the present invention ensures the privacy protection of bid values ​​in auctions, as well as the protection of privacy information such as geographic location in special auction environments such as crowdsourcing and spectrum.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the blockchain technology, and particularly relates to an auction traceability method and an implementation system based on Ethereum privacy protection. Background Art

[0002] The need for the authenticity of auctions prompts users (sellers or buyers) to use their true valuations of items as their bids, that is, the bid values in the bidding information. However, the true valuation information belongs to the private information of users, may be related to the actual economic situation of users, and may reflect the profits that users can obtain by winning the auction items. If the historical bid value information is leaked, malicious auction parties may manipulate the auction using the historical bid values to increase their own profits; bidders may change their bids to obtain greater profits, thus violating the authenticity of the auction. An auction system lacking bid value privacy protection may affect user participation.

[0003] On the other hand, without the guarantee of auction fairness, malicious users may withdraw from the auction midway to avoid unsatisfactory payment amounts, resulting in losses for honest users and waste of auction system resources. In addition, the lack of fairness guarantee leads to difficulties in the execution of auction results, that is, mutually distrustful buyers and sellers may refuse to deliver the auction items or the auction payments first, hindering the clearing of the auction market. Therefore, in order to ensure auction fairness, it is necessary to achieve non-repudiation of user behavior and credible traceability demonstration.

[0004] The bid value privacy protection based on a single auction center completely relies on a trusted auction center, and is prone to single point failures; such systems generally use encryption to achieve privacy protection, but it is difficult to determine the auction results based on encrypted information, and the auction calculation is complex and costly. Currently, most auction schemes use two-party secure computing between the auction center and the auction agent instead of a single auction center, generally based on the semi-honest assumption, that is, there is no collusion between the auction center and the auction agent, but they will infer the user privacy information through the information collected during the protocol operation. The auction center and the auction agent strictly comply with the auction protocol to execute operations, but if the auction party (auction center or auction agent) violates the auction protocol specifications, such as colluding or determining illegal winners, the user privacy or auction fairness cannot be guaranteed.

[0005] As a distributed reliable system, the blockchain solves the problem of decentralized trust through a consensus mechanism. Once the blockchain smart contract is deployed, it automatically executes according to the contract trigger conditions, excluding human operation factors. With the help of blockchain technology, the defects existing in the auction schemes based on a single or multiple auction parties can be well solved. Through the blockchain-based incentive mechanism, it is urged that the auction parties honestly execute according to the auction protocol specifications. If it is found that there are operations violating the protocol, the smart contract will automatically execute penalty measures.

[0006] However, the public transparency of the blockchain itself is in opposition to the privacy protection requirements of the auction bid value. Moreover, due to the operating cost problem of smart contracts and the performance problem of the blockchain, blockchain smart contracts are not suitable for large-scale complex operations. Therefore, it is very difficult to implement an auction for bid value privacy protection completely relying on blockchain smart contracts; and in the auction system for bid value privacy protection, the possibility of bidders reneging after winning the bid increases, making it more difficult to trace and demonstrate.

[0007] Currently, for the two-sided auction widely used in electronic auctions, there is no solution that can fully achieve the non-repudiation and traceability issues in the privacy-protected two-sided auction, including that the winning bidders (including sellers and buyers) cannot deny their bids (bid values), cannot refuse the completion and delivery of the auction results; the auctioneer cannot deny the valid bid values of the winners and cannot violate the auction agreement operations. To address the above issues, this solution proposes a blockchain-based tracing method and combines a two-way incentive mechanism of violation punishment and compliance reward to encourage users to execute according to the auction agreement specifications and ensure the normal operation of the system. Summary of the Invention

[0008] Object of the Invention: The object of the present invention is to solve the deficiencies existing in the prior art and provide an auction tracing method and implementation system based on Ethereum privacy protection.

[0009] Technical Solution: An auction tracing method based on Ethereum privacy protection of the present invention includes a preparation stage, an auction stage, and a dispute stage;

[0010] The preparation stage includes:

[0011] Initialization, that is: initialize and publish system parameters

[0012] PK ABRs 、 and are the public keys of the market supervision department ABRs, the auctioneer and the auctioneer respectively. H: The market supervision department ABRs generates a transaction Tr_Init to publish a smart contract SC_Tracing. The data area of the transaction Tr_Init contains the smart contract code; each transaction contains information such as the sender address, the receiver address, and the data. The receiver address being empty triggers the creation of a contract; G is a cyclic group of order q, and the generators P, Q ∈ G;

[0013] The auction starts, i.e., the market supervision department ABRs generates a transaction Tr_Start to start the auction. The start-auction function in the smart contract is triggered through the data area of the transaction Tr_Start. The data area of the transaction Tr_Start includes the item to be auctioned, the bidding range [min, max], and the user's minimum margin D u and the auctioneer pledges D A ; Start the timer Timer for this auction and wait for users to register; D u >>max;

[0014] User registration, i.e., the user registers with the smart contract within the time T_finishRegistration; then submits a bid commitment to the smart contract and pledges; To save time and cost, user registration and bid commitment are completed in the same transaction and submitted before the time T_finishRegistration; Here, the user U i includes the seller and the buyer

[0015] The auction phase includes:

[0016] User bidding, i.e., before the bidding deadline T_finishBidding, the user reveals the bidding information ran1, ran2 to the auctioneer for verifying the bid commitment; Here, the auctioneer A includes the auction center and the auction agent

[0017] Auction allocation, i.e., after the bidding deadline T_finishBidding, the auction center and the auction agent start to execute the auction process; First, batch signature verification is performed on the received user bidding information, i.e., verifying whether the equation Σ i (s i )·G = Σ i (R i ) + Σ i (c i ·PK i ) holds; U represents the seller, the buyer, and the user (the seller and the buyer are not distinguished here), and i represents user i; PK i refers to the public key of user i; (R i , s i ) is the Schnorr signature of user i, and c i is a parameter in signature generation and verification;

[0018] If it holds, then verify the user's bid according to the on-chain information and ran1, ran2, i.e., verify the equations and

[0019] and are the bid commitments of the user. Here, the bid verification is based on the seller as an example: V m represents the marked value of the seller (the marked value of the buyer is Bn;), and are the bid commitments of the seller. Since the auction process is based on two-party secure computation, the seller performs secret sharing on the bid / marked value to generate two secret shares and makes commitments respectively. The auctioneer performs operations on one secret share respectively; and If it holds, for the bidding users who pass the signature and commitment verification, the winner and the transaction price are determined through operations such as secure data operation, secure comparison, and secure sorting of secret sharing;

[0020] Result submission. Before the time T_finishAuction, the auction center

[0021] and the auction agent and publish the auction results to the blockchain respectively. The transaction data area contains the winning seller, the public keys of the buyer, and the secret share of the transaction price;

[0022] The result announcement smart contract determines the identity of the winner and the transaction price according to the results submitted by the auction center and the auction agent and the information on the chain:

[0023]

[0024]

[0025] Among them, and represent the identities of the winning buyer and seller respectively. ω represents a certain winner, and P b , P s represent the transaction prices of the buyer and the seller respectively; is the result of the transaction price (the secret share of the transaction price) obtained by the auctioneer and through two-party secure computation respectively;

[0026] If the auction result is not received after the time T_finishAuction, the pledges of the auction center and the auction agent will be confiscated and evenly distributed to the users, and the users' pledges will be refunded. The auction will end and this auction will be declared a failure;

[0027] The dispute phase includes:

[0028] Dispute submission, that is, after the auction results are announced and before the time T_finishQuestioning, the user submits an objection statement to the blockchain smart contract, Tr_Dispute = (Addr_U i ,Addr_SC,Data,Gas);

[0029] Addr_U i , Addr_SC, Data and Gas represent the sender address, receiver address, data area and the maximum amount of Gas allowed to be consumed by this transaction. It is recommended to remove the Gas parameter in all transactions because it has no specific impact on this solution. The information contained in Data is the parameters that trigger the corresponding functions of the smart contract;

[0030] in, U represents sellers, buyers and users (sellers and buyers are not distinguished here), respectively. B n ,U i represents the mth seller, nth buyer and ith user;

[0031] Data includes objection type (questioningResult / nonPaying / nonDelivering), bid commitment verification parameters, and the latter two of the three objection types submit the non-paying / delivering user public key and proof proo;

[0032] Smart contract processing and result demonstration, that is, the smart contract automatically executes dispute resolution based on the submitted objection statement, on-chain information, or proof information submitted by the auction center and auction agent; and publicly demonstrates the processing results.

[0033] The present invention performs user registration based on secret sharing and commitment, realizes the privacy protection of information on and off the chain, and allows the tracing of violating users in the dispute stage; for malicious users' refusal to execute auction results and change bid values ​​and other violations and auctioneers' collusion, the dispute resolution method is used to realize the tracing and punishment of violations under privacy protection conditions; the present invention reduces the interaction between users and auctioneers, ensures the privacy protection of bid values ​​in auctions, and the protection of privacy information such as geographic location in special auction environments such as crowdsourcing and spectrum.

[0034] Further, in the initialization stage, the market supervision department releases the smart contract SC_Tracing, i.e., generating a transaction Tr_Init(Addr_ABRs, Blank, Data, Gas); where the recipient address is empty, triggering the creation of a contract, and the data area contains the contract code.

[0035] After the successful deployment of the smart contract, define the data structures used by the smart contract, including the seller list List_Sellers, the buyer list List_Buyers, the commitment list List_Commitments, the winner lists (Winners_Seller, Winners_Buyer), the transaction prices (Price_Seller, Price_Buyer), and a set of timer commitment deadlines T_finishRegistration, the auction deadline T_finishBidding, the result submission deadline T_finishAuction, the objection submission deadline T_finishQuestioning, and the auction end time T_closeAuction; the functions of the smart contract include: starting the auction, user registration, dispute handling, pledging, penalty, and redemption.

[0036] Further, the specific content of the user registration of the seller is as follows:

[0037] (1), Generate bid information and perform secret sharing on the bid: Select a random number Calculate two corresponding secret shares of the auctioneer A:

[0038]

[0039] Then generate the seller's private key Calculate the corresponding public key

[0040] (2), Make a commitment to the bid: Select a random number Calculate

[0041] (3), Encrypt the user identity information using the public key PK ABRs of the market supervision department, and encrypt the bid shares respectively with the auctioneer's key,

[0042] (4), Generate a transaction Data includes the user identity public key Bid commitment and bid share

[0043]

[0044] Buyer Perform steps (1) to (4) to generate a transaction

[0045] (5) After the user registration information is uploaded to the blockchain, if the current time Timer is less than T_finishRegistration, the user registration function is triggered. First, check whether the pledged amount meets the requirement Deposit≥Du, and whether the user's account balance can pay the pledge ledger[U i ≥Deposit. If so, transfer Deposit from the user's account ledger[U i to the pledge pool DepositPool[U i , and store the user's identity and public key in the corresponding user list, store the bid commitment and secret share; otherwise, the user registration fails.

[0046] Furthermore, during the auction allocation process, through secret sharing data security operations, security comparison and security sorting operations,

[0047] Sort the buyers / sellers in non-increasing / non-decreasing order according to the bid values respectively, and determine

[0048] K = arg max k≤min(M,N) (B k ≥V k and B k ≠B k-1 );

[0049] B k and V k represent the bid values of the buyer and the seller respectively. During the allocation process, first sort all the seller bid values in non-decreasing order and all the buyer bid values in non-increasing order; B k 、B k-1 represent the kth and (k - 1)th buyer bid values after sorting, and V k represents the kth seller bid value;

[0050] The first K - 1 sellers and buyers are the winners, and the amounts to be paid by the buyer and the seller are P b = B K , P s = V K .

[0051] Finally, determine the winners and the transaction price.

[0052] Further, the specific process of submitting the result is as follows:

[0053] Auction center and auction agent publish the auction result to the blockchain respectively before time T_finishAuction:

[0054]

[0055]

[0056]

[0057]

[0058] W b and ω represent the number of winning buyers and the ω-th winning buyer.

[0059] Further, the specific content of the dispute handling includes:

[0060] (1) If the on-chain time Timer of the user dispute information Tr_Dispute is less than T_finishQuestioning, trigger the dispute handling function DisputeResolution;

[0061] (2) In the dispute handling process, first judge the dispute type type according to the Data information in the transaction. If it is questioningResult, execute step (3); if it is nonPaying / nonDelivering, execute step (10);

[0062] (3) Calculate the user commitment according to the commitment parameters ran1 and ran2 submitted in the user objection statement and to calculate the user commitment

[0063] (4) Search the user commitment table according to the user public key to determine the user commitment in the registration stage Compare the operation result obtained in step (3) with the bid commitment in the registration stage to see if they are consistent;

[0064] (5) If they are inconsistent, it means the user has changed the bid. Then call the punishment function Punishment to punish the user for the violation of changing the bid That is, if the user has the behavior of changing the bid value, confiscate the user's γ1 deposit; jump to step (11);

[0065] (6) If they are consistent, it indicates that the user follows the auction agreement without changing the bid value. Require the auction center and the auction agent to submit a proof of compliance for auction allocation and pricing: V m Denotes the seller 's bid value, B i Denotes the buyer's bid value;

[0066]

[0067]

[0068]

[0069]

[0070] That is, prove that the seller's bid is within the bid range and not greater than the transaction price, or the buyer's bid is within the bid range and not less than the transaction price;

[0071] (7) Verify the auctioneer's proof ZKP.Verify(proof). If the verification passes, that is, the auctioneer's behavior is compliant, the user who submits the dispute is responsible for the cost of the dispute handling process, that is, confiscate the user U i 's pledge γ2, Punishment(U i , γ2), and jump to step (11);

[0072] (9) If the proof submitted by the auction center and the auction agent is incorrect, that is, the auctioneer does not follow the auction agreement specifications during the allocation and pricing process, there are violations or collusions, then punish the auctioneer by confiscating all pledges, End the objection handling and declare the auction failed, and jump to step (11);

[0073] (10) Verify the proof submitted by the user. If it is determined that the buyer has not paid the auction price / the seller has not delivered the auction item, then pay the auction price from the user U j 's pledge to the user U i , and punish the violating user U j , confiscate the pledge γ3, Punishment(U j , γ3); if the user cannot prove that the buyer has not paid the auction price / the seller has not delivered the auction item, the user who submits the dispute is responsible for the dispute handling cost, Punishment(U i , γ4);

[0074] (11) After the dispute handling result reaches a consensus, it is chained. The market supervision department ABRs determines the anonymous identity of the violating user according to the handling result and obtains the real identity of the violating user using the private key to deal with the violating user;

[0075] If the time limit for raising an objection is exceeded, the smart contract will automatically refund the stake and distribute the tokens in the penalty pool to compliant users, ending the auction.

[0076] The present invention also discloses a system for realizing an auction tracing method based on Ethereum privacy protection, comprising a user U i , auctioneer A, Ethereum nodes and market supervision departments ABRs; among them, user U i Including sellers and buyers Auctioneer A includes auction center and auction agents The market supervision department releases a smart contract and starts the auction; buyers and sellers register with the contract within the specified time and make bid commitments and pledges. The auctioneer pledges to the smart contract, and then the sellers and buyers submit bidding information to the auctioneer. The auctioneer needs to obtain some bidding information from the chain, such as bid commitments; the auctioneer allocates the auction based on the security calculation of the two parties and submits the results to the smart contract; the smart contract announces the auction results; buyers or sellers submit disputes over the auction results or disputes over the execution of the auction results, and the smart contract automatically handles the disputes and publicizes the results.

[0077] Beneficial effects: Compared with the prior art, the present invention has the following advantages:

[0078] (1) The present invention combines cryptography and blockchain to propose a privacy-preserving auction tracing system with a double-layer structure on-chain and off-chain. Unlike the existing solution using a trusted computing module, which requires a challenge-response relationship between the user and the trusted computing module to ensure the security of the trusted computing module, the present invention reduces the interaction between the user and the auctioneer.

[0079] (2) Different from the existing solutions that completely rely on blockchain smart contracts, the present invention ensures the privacy protection of the bid value in the auction, as well as the privacy protection of information such as geographic location in crowdsourcing and spectrum auctions.

[0080] (3) The present invention realizes lightweight privacy-preserving auction traceability based on encryption, secret sharing, commitment and signature technologies. It realizes trusted traceability demonstration based on blockchain while adding fewer on-chain operations and additional communication overhead, thus resolving the contradiction between anonymity and traceability, and between privacy protection and non-repudiation in privacy-preserving auctions. Compared with privacy-preserving auction schemes based on homomorphic encryption, or auction schemes that completely rely on blockchain smart contracts and do not implement privacy protection, the present invention has obvious advantages.

[0081] (4) The present invention combines blockchain technology, leverages the trustworthy transparency of blockchain and the automated execution of smart contracts to achieve dispute resolution, violation penalties and compliance rewards that are independent of trusted third parties. At the same time, the relevant market supervision and management departments can trace the identities of violating users, providing reliable on-chain evidence for further management operations. BRIEF DESCRIPTION OF THE DRAWINGS

[0082] Figure 1 It is a schematic diagram of the system model of the present invention;

[0083] Figure 2 It is a schematic diagram of the entity interaction timing of the present invention;

[0084] Figure 3 A registration protocol diagram of the present invention;

[0085] Figure 4 Schematic diagram of the dispute resolution process of this embodiment. DETAILED DESCRIPTION

[0086] The technical solution of the present invention is described in detail below, but the protection scope of the present invention is not limited to the embodiments.

[0087] Embodiment 1:

[0088] like Figure 1 As shown, the system of the auction tracing method based on Ethereum privacy protection in this embodiment involves the following entities: Ethereum Peer node, users (sellers and buyers), auctioneers (auction center and auction agent), market supervision department; it includes three stages: preparation stage, auction stage and dispute stage, wherein the preparation stage includes initialization, auction start and user registration; the auction stage includes user bidding, auction allocation, result submission and result announcement; the dispute stage includes dispute submission, smart contract processing and result demonstration.

[0089] The interaction process between entities in the above stages is as follows: Figure 2 shown.

[0090] This embodiment takes the spectrum auction application scenario as an example. The buyer's bidding information of the spectrum auction includes not only the identity and the bid value, but also the location information and the usage radius.

[0091] With respect to spectrum auction, each step in the three stages of this embodiment is specifically described.

[0092] Step 1: Initialization, including system parameter initialization and smart contract release

[0093] Generate a cyclic group G of order q, then select a generator P∈G; select a hash function H: Publish system public parameters

[0094] The market supervision department generates the transaction Tr_Init (Addr_ABRs, Blank, Data, Gas) and publishes the smart contract SC_Tracing. The data area contains the contract code. After the contract is successfully deployed, the data structure used by the contract is defined: seller list List_Sellers, buyer list List_Buyers, commitment list List_Commitments, winner list (Winners_Seller, Winners_Buyer), transaction price (Price_Seller, Price_Buyer), and a set of timers commitment deadline T_finishRegistration, auction deadline T_finishBidding, result submission deadline T_finishAuction, objection submission deadline T_finishQuestioning, auction end time T_closeAuction.

[0095] Step 2: Start the auction

[0096] The market supervision department generates the transaction Tr_Start (Addr_A, Addr_SC, Data, Gas), announces the spectrum to be auctioned, the bidding range [min, max], the user's minimum guarantee amount Du (Du ≥ max), and the auction center and auction agent pledge amount D A The smart contract initializes each list and timer, starts the timer Timer, deducts the auction center and auction agent pledge D A (i.e., executing two transactions, from the auction center and auction agents Account transfer D A To the pledge pool and Waiting for user registration.

[0097] Step 3: User Registration

[0098] Take sellers as an example. Before the commitment deadline T_finishRegistration, register with the smart contract, submit a bid commitment and make a pledge:

[0099] (1) Generate a private key Calculate the corresponding public key Generate bid information and share the bid secretly: select a random number Calculating secret shares

[0100] (2) Commit to the bid: Select a random number Calculation

[0101] (3) Encrypt the identity information with the public key of the market supervision department, Encrypt the bid shares with the auctioneer's key respectively,

[0102] (4) Generate a transaction Data includes the user identity Public key Bid commitment And bid shares

[0103] Buyer Perform the same operation to generate a transaction

[0104] (5) After the user registration information is chained, if the current time Timer is less than T_finishRegistration, the user registration function is triggered. First, check whether the pledged amount meets the requirements Deposit≥Du, and whether the user account balance can pay the pledge ledger[U i ≥Deposit. If so, transfer Deposit from the user account ledger[U i to the pledge pool DepositPool[U i , and store the user identity and public key in the corresponding user list, store the bid commitment and secret shares; otherwise, the user registration fails.

[0105] Step 4: Before the auction deadline T_finishBidding, the user reveals ran1 and ran2 to the auctioneer for bid commitment verification. Taking the buyer as an example:

[0106] (1) Generate auction information

[0107] (2) Select random numbers Calculate:

[0108]

[0109]

[0110] (3) Sign And : Select a random number Calculate:

[0111] R1 = r1·G, R2 = r2·G

[0112]

[0113]

[0114]

[0115]

[0116] Send To the auction center And the auction agent

[0117] Step 5: After the auction deadline T_finishBidding, the auction center and the auction agent start to execute the auction process.

[0118] ① First, conduct batch signature verification on the received user auction information

[0119] Σ i (s i )·G = Σ i (R i ) + Σ i (c i ·PK i )

[0120] If there are Num signatures, Num - 1 dot product operations can be saved.

[0121] ② After the signature verification passes, the auction center And the auction agent Verify the user's bid according to the information on the chain and ran1, ran2:

[0122] ③ For the auction users who pass the signature and commitment verification, group the buyers through secret sharing data security operations, secure comparison, and secure sorting, and determine

[0123] K = arg max k≤min(T,N) (GB k ≥V k and GB k ≠GB k-1 )

[0124] The first K - 1 sellers and buyer groups are the winners, and the amounts to be paid by the buyer group and the seller are P b = B K , P s = V K. Then, users with bids too low to cover the transaction price within the buyer group are excluded, and the remaining buyers are the winners.

[0125] Step 6: Auction Center and Auction Agent Before time T_finishAuction, respectively publish the auction results to the blockchain:

[0126]

[0127]

[0128]

[0129]

[0130] Step 7: The smart contract determines the winner's identity and transaction price based on the information of the auction center and the auction agent:

[0131]

[0132]

[0133] If the auction results are not received after time T_finishAuction, confiscate the pledges of the auction center and the auction agent, distribute them equally among the users and return the users' pledges, end the auction and announce that this auction has failed.

[0134] Step 8: After the auction results are announced and before time T_finishQuestioning, users submit a dispute statement to the blockchain smart contract, Tr_Dispute = (Addr_U i , Addr_SC, Data, Gas), where Data includes three types of dispute types type (questioningResult / nonPaying / nonDelivering), bid commitment verification parameters (for the latter two dispute types, the public keys and proofs of non-paying / delivering users are submitted).

[0135] Step 9: The smart contract automatically executes dispute handling based on the parameters submitted in the dispute statement, on-chain information, and the proofs submitted by the auction party; and publishes and demonstrates the handling results. The specific process of the dispute handling algorithm is as follows:

[0136] (1) If the on-chain time Timer of the user dispute information Tr_Dispute is less than T_finishQuestioning, the dispute handling function is triggered;

[0137] (2) In the dispute handling process, first determine the dispute type type according to the Data information. For questioningResult, execute (3); for nonPaying / nonDelivering, execute (10);

[0138] (3) Search the user commitment table according to the user identity and public key to determine the user bid commitment

[0139] (4) Calculate the user secret share commitment according to the commitment parameters submitted in the user objection statement, and compare whether the operation result is consistent with the bid commitment in the registration phase;

[0140] (5) If they are inconsistent, it means the user has changed the bid information, punish the user Punishment(U i , γ1), and jump to (11);

[0141] (6) If they are consistent, it means the user follows the auction agreement and has not changed the bid value. Then require the auction center and the auction agent to submit the allocation process and pricing compliance certificates respectively:

[0142]

[0143]

[0144]

[0145]

[0146] (7) Verify the auctioneer's proof ZKP.Verify(proof). If the verification passes, that is, the auctioneer's behavior is compliant, punish the user Punishment(U i , γ2), and jump to (11);

[0147] (9) If the proofs submitted by the auction center and the auction agent are incorrect, that is, the auctioneer fails to execute according to the auction agreement specifications, be responsible for the auction failure. End the objection handling and declare the auction failure, and jump to (11);

[0148] (10) Check the user's proof. If it is determined that the buyer has not paid the auction price / the seller has not delivered the auction item, then pay the auction price from the user U j pledge to the corresponding user U i , and punish the user Uj Confiscation of Pledge Punishment j ,γ3); If the user cannot prove that the buyer has not paid the auction price / the seller has not delivered the auction item, then Punishment(U i , γ4);

[0149] (11) After reaching consensus, the dispute resolution results are uploaded to the blockchain, and ABRs can further handle the offending users based on the resolution results;

[0150] (12) If the time limit for raising an objection is exceeded, the smart contract will automatically return the stake and distribute the tokens in the penalty pool to compliant users, ending the auction.

[0151] It can be seen from the above embodiments that, firstly, in the preparation stage of the present invention, the user submits a bid commitment and makes a pledge, which provides a basis for judging whether the user has changed his bid value in the dispute resolution stage, and traces and punishes the user's withdrawal from the auction or refusal to execute payment or delivery and other violations; in the dispute resolution process, the auctioneer is required to provide compliance proof of the allocation and pricing process to prevent the auctioneer from collusion or other malicious behavior. Secondly, the present invention realizes the privacy of information such as user identity, bid value, location, etc. on and off the chain during user registration, bidding and allocation through cryptographic algorithms such as encryption, secret sharing, Pedersen commitment and signature, and realizes non-repudiation auction under privacy protection conditions.

Claims

1. An auction tracing method based on Ethereum privacy protection, characterized in that: It includes a preparation stage, an auction stage, and a dispute stage; The preparation stage includes: Initialization, i.e., initialize and publish system parameters PK ABRs , and Market supervision departments ABRs, auction centers and auction agents The public key of the market supervision department ABRs generates transaction Tr_Init and publishes the smart contract SC_Tracing; the data area of ​​transaction Tr_Init contains the smart contract code; each transaction contains the sender address, receiver address and data; the auction center and auction agents Together they form the auctioneer A; H is a hash function; G is a cyclic group of order q, with generators P and Q∈G; The auction starts, i.e., the market supervision department ABRs generates a transaction Tr_Start to start the auction. The start auction function in the smart contract is triggered by the data area of the transaction Tr_Start. The data area of the transaction Tr_Start includes the item to be auctioned, the bidding range [min, max], the user's minimum deposit D u and the auctioneer's pledge D A ; Start timing for this auction and wait for users to register; D u >> max; User registration, that is: the user registers with the smart contract within the commitment deadline T_finishRegistration; then submits a bid commitment to the smart contract and makes a pledge; the user registration and the bid commitment are completed in the same transaction and submitted before the commitment deadline T_finishRegistration; here, user U includes both sellers and buyers. Denote the seller, the buyer, and the user respectively, using to represent the m-th seller, the n-th buyer, and the i-th user respectively. Seller The specific steps for user registration are as follows: Step 1, generating bid information and performing secret sharing on the bid: Select a random number Calculate respectively the auction center and the auction agent of the two corresponding secret shares: Then generate the seller's private key Calculate the corresponding public key Step 2. Make a commitment to the bid: Select a random number Calculate and represents the seller's bid commitment, V m represents the seller's valuation; Step 3: Use the public key PK of the market supervision department to encrypt the user's true identity information and encrypt the secret share with the public key of the auction center ABRs and the public key of the auction agent respectively to obtain the corresponding bid shares: ​​ Step 4, generate transaction Tr_Regist, and the data area of transaction Tr_Regist includes user identity public key bid commitment and bid share Buyer Perform steps 1 to 4 to generate transaction Tr_RegistCommit; Step 5. After the user registration information is uploaded to the blockchain, if the current time is less than T_finishRegistration, trigger the user registration function, and check whether the pledged amount meets the requirement Deposit≥D u , and whether the user's account balance can cover the pledge. If both conditions are met, transfer the pledged amount from the user's account to the pledge pool, store the user's identity and public key in the corresponding user list, and store the bid commitment and secret share; otherwise, the user registration fails; The auction stage includes: User bidding, that is: before the bidding deadline T_finishBidding, the user reveals the bidding information to the auctioneer for verifying the bid commitment; Auction allocation, that is: after the auction deadline T_finishBidding, the auction center and the auction agent start to execute the auction process; first, batch signature verification is performed on the received user bidding information, that is, verifying whether the equation Σ i (s i )·G = Σ i (R i ) + Σ i (c i ·PK i ) holds; i represents user i; PK i refers to the public key of user i; (R i , s i ) is the Schnorr signature of user i, and c i is a parameter in signature generation and verification; If the batch signature verification holds, verify the user's bid based on the on-chain information and ran1, ran2, that is, verify the equations and If the user bid verification is successful, for the bidding users who pass the signature and commitment verification, the winner and the transaction price are determined through secure operations of secret sharing, secure comparison, and secure sorting; Result submission, i.e., before the result submission deadline T_finishAuction, the auction center and the auction agent respectively publish the auction results and to the blockchain. The auction transaction data area contains the winning seller, the public keys of the buyer, and the secret share of the transaction price; The results are announced, that is: The smart contract determines the winner's identity and transaction price based on the results and on-chain information submitted by the auction center and the auction agent : and represent the identities of the winning buyer and seller respectively, ω represents a certain winner, P b , P s represent the transaction prices of the buyer and seller respectively; where is the transaction price result obtained by the auctioneer based on two-party secure computation If the auction result is not received after time T_finishAuction, confiscate the pledges of auction center A1 and the auction agent pledge, divide it equally among the users and return the users' pledges, end the auction and announce that the auction has failed; The dispute stage includes: Dispute submission, that is, after the auction results are announced and before the objection submission deadline T_finishQuestioning, the user submits an objection statement Tr_Dispute to the blockchain smart contract. Tr_Dispute includes Addr_U i ,Addr_SC,Data,Gas;Addr_U i , Addr_SC, Data and Gas respectively represent the sender address, receiver address, data area and the maximum amount of Gas allowed to be consumed by this transaction; Data includes the dispute type and bid commitment verification parameters; the dispute type includes questioningResult, nonPaying, nonDelivering; Smart contract processing and result demonstration, that is: the smart contract automatically executes dispute handling according to the submitted objection statement, on-chain information, or proof information submitted by the auction center and the auction agent; and publishes and demonstrates the processing result; the specific steps of dispute handling include: S1. If the on-chain time of the user dispute statement Tr_Dispute is less than T_finishQuestioning, the dispute handling function is triggered; S2. During the dispute handling process, judge the dispute type according to the information in the objection statement. If it is questioningResult, execute step S3; if it is nonPaying or nonDelivering, execute step S10; S3. Calculate the user commitment based on the commitment parameters submitted in the user objection statement and to calculate the user commitment S4. According to the user's public key to search for the user commitment table and determine the user commitment in the registration phase Compare whether the operation result obtained in step S3 is consistent with the bid commitment in the registration phase; S5. If they are inconsistent, it means the user has changed the bid. Then call the penalty function to punish the user for the violation of changing the bid. That is, if the user has the behavior of changing the bid value, confiscate the user's γ1 deposit; jump to step S11; S6. If they are consistent, it means the user has followed the auction agreement and has not changed the bid value. Require the auction center and the auction agent to submit proof of auction allocation and pricing compliance: that is, prove that the seller's bid is within the bid range and not greater than the transaction price, or the buyer's bid is within the bid range and not less than the transaction price; S7. Verify the auctioneer's proof. If the verification is passed, that is, the auctioneer's behavior is compliant, the user who submits the dispute shall be responsible for the expenses of the dispute handling process, that is, confiscate the user's i pledge γ2 and jump to step S11; S9. If the proof submitted by the auction center and the auction agent is incorrect, that is, the auctioneer has not followed the auction agreement specifications during the allocation and pricing process, there are violations or collusion, then punish the auctioneer by confiscating all the pledges, end the objection handling and declare the auction failed, jump to step S11; S10. Verify the proof submitted by the user. If it is determined that the buyer has not paid the auction price or the seller has not delivered the auction item, pay the auction price to user U j from the pledge i and punish the violating user U j , confiscate the pledge γ3. If the user cannot prove that the buyer has not paid the auction price or the seller has not delivered the auction item, submit that the disputing user is responsible for the dispute handling expenses; S11. After the dispute handling result reaches a consensus, it is uploaded to the blockchain. The market supervision department ABRs determines the anonymous identity of the violating user based on the handling result and uses the private key to obtain the real identity of the violating user to deal with the violating user; If the time limit for raising objections is exceeded, the smart contract automatically refunds the pledges and distributes the tokens in the penalty pool to the compliant users, ending the auction.

2. The auction tracing method based on Ethereum privacy protection according to claim 1, characterized in that: In the initialization stage, the market supervision department issues the smart contract SC_Tracing, that is, a transaction Tr_Init is generated; the receiving address is empty, triggering the creation of the contract, and the data area contains the contract code; After the successful deployment of the smart contract, define the data structures used by the smart contract, including the seller list List_Sellers, the buyer list List_Buyers, the commitment list List_Commitments, the winner list, the transaction price, and a set of timer commitment deadlines T_finishRegistration, the auction deadline T_finishBidding, the result submission deadline T_finishAuction, the objection submission deadline T_finishQuestioning, and the auction end time T_closeAuction; the functions of the smart contract include: starting the auction, user registration, dispute handling, pledge, penalty, and redemption.

3. The auction tracing method based on Ethereum privacy protection according to claim 1, characterized in that: During the auction allocation process, through secret sharing data security operations, secure comparison, and secure sorting operations, First, sort all the seller bids in non-decreasing order and all the buyer bids in non-increasing order during the allocation process; K = arg max k≤min(M,N) ; B k ≥V k and B k ≠B k-1 ; B k and B k-1 represent the k-th and (k - 1)-th buyer bid values after sorting, and V k represents the k-th seller bid value; the first K - 1 sellers and buyers are the winners; Finally, determine the winner and the transaction price.

4. The auction tracing method based on Ethereum privacy protection according to claim 1, characterized in that: The specific process of the result submission is as follows: Auction Center and Auction Agent Before the result submission deadline T_finishAuction, publish the auction results to the blockchain respectively: W b represents the number of winning buyers, W s represents the number of winning sellers, and ω represents the ω-th winner.

5. A system for implementing the auction tracing method based on Ethereum privacy protection according to any one of claims 1 to 4, characterized in that: Including user U i , auctioneer A, Ethereum nodes, and market supervision department ABRs; among them, user U i Includes sellers and buyers The auctioneer A includes an auction center and an auction agent The market supervision department releases a smart contract and starts the auction; the buyer and the seller register with the contract within the specified time and make a bid commitment and a pledge. The auctioneer pledges to the smart contract, and then the seller and the buyer submit bidding information to the auctioneer. The auctioneer needs to obtain some bidding information from the chain. The auctioneer conducts an auction allocation based on two-party secure computing and submits the result to the smart contract; the smart contract announces the auction result; the buyer or the seller submits a dispute over the auction result or the execution of the auction result, and the smart contract automatically processes the dispute and publicizes the processing result.

Citation Information

Patent Citations

  • Auction method and system based on hybrid blockchain

    CN112700314A

  • Secure control of transactions using blockchain

    US20190205873A1