User Tracking Method, Device, Medium and Electronic Device Based on Zero-Knowledge Proof
Through the user tracking method based on zero-knowledge proof, the problems of high labor consumption, low efficiency and difficulty in privacy protection in infectious disease tracking are solved, and fast, accurate and compliant user tracking is achieved.
Patent Information
- Application Number
- CN202111475235.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-03
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2041-12-03
AI Technical Summary
In the process of infectious disease tracking, the existing technology has problems such as high manpower consumption, low tracking efficiency, and data protection and privacy, making it difficult to effectively track large-scale, fast and privacy-protected user.
The user tracking method based on zero-knowledge proof is adopted, and the special personnel identity identification published by the tracking management platform is obtained, and the user contact person list is compared with the client's locally stored, and the zero-knowledge proof is generated and verified to determine whether the user is the target tracking user.
On the premise of protecting user privacy, users' contact history is quickly and accurately verified, which improves tracking efficiency and ensures legal compliance and user trust in the tracking process.
Smart Images

Figure CN114400101B_ABST
Abstract
Description
Technical Field
[0001] One or more embodiments of the present application relate to the field of information technology, and in particular, to a user tracking method, device, medium and electronic device based on zero-knowledge proof. Background Art
[0002] In order to cut off the transmission chain of infectious diseases, it is necessary to conduct infectious disease contact tracing. Usually, it is necessary to send specially organized tracking staff to track and check the people on the list of contacts provided by the infectious disease infected person one by one, so as to finally determine the target tracking user.
[0003] However, the above process not only requires a lot of manpower, but also has low tracking efficiency, which may lead to the emergence of new transmission chains due to untimely tracking. In addition, the list of contacts provided by the infectious disease infected person may have omissions, which may also lead to the problem of continued spread of infectious diseases.
[0004] Therefore, tracking can be carried out through the rational use of information technology tools, which can not only save manpower and material resources, but also help to carry out large-scale tracking and make tracking more effective.
[0005] At present, although contact tracing can be carried out with the help of information technology tools, for example, an APP can be installed on the user's mobile phone to collect the user's location information, generate the user's activity trajectory, and determine whether the user is a contact by comparing the activity trajectory.
[0006] However, in the process of collecting user-related information, user data protection and privacy issues will be involved. If user data is used in violation of regulations or user privacy is leaked, users will refuse to provide relevant information, which is not conducive to tracking work.
[0007] Therefore, it is necessary to ensure that no relevant laws are violated during the tracking process and to ensure that the digital tools used for tracking comply with relevant legal provisions; secondly, during the tracking process, users need to be informed in a clear and transparent manner how to process, store and use data to avoid user misunderstandings and at the same time facilitate user active participation; in addition, the tracking management platform is also required to manage data security and protect user privacy. Summary of the invention
[0008] In view of this, the present application provides a user tracking method and device based on zero-knowledge proof, so as to verify the user's contact history and achieve target user tracking under the premise of protecting the user's privacy.
[0009] Specifically, the present application is implemented through the following technical solutions:
[0010] First aspect, the present application proposes a user tracking method based on zero-knowledge proof, which is applied to a client, and the client is connected to a tracking management platform; the method includes:
[0011] Obtain the identity identifier of a special person published by the tracking management platform;
[0012] Compare it with the list of user contact persons stored locally in the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes the identity identifiers corresponding to other users whose contact distance with the user reaches a threshold;
[0013] If there is, generate a zero-knowledge proof that the user is the target tracking user based on a preset zero-knowledge proof algorithm, and send the zero-knowledge proof to the tracking management platform, so that the tracking management platform verifies the zero-knowledge proof based on the zero-knowledge proof algorithm, and determines the user as the target tracking user when the verification passes.
[0014] Second aspect, the present application also proposes a user tracking method based on zero-knowledge proof, which is applied to a tracking management platform, and the tracking management platform is connected to a client; the method includes:
[0015] Publish the identity identifier of a special person, so that when the client obtains the identity identifier of the special person, compare it with the list of user contact persons stored locally in the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes the identity identifiers corresponding to other users whose contact distance with the user reaches a threshold;
[0016] Receive the zero-knowledge proof that the user is the target tracking user generated by the client based on a preset zero-knowledge proof algorithm, verify the zero-knowledge proof based on the zero-knowledge proof algorithm, and determine the user as the target tracking user when the verification passes.
[0017] Third aspect, the present application proposes a user tracking device based on zero-knowledge proof, which is applied to a client, and the client is connected to a tracking management platform; the device includes:
[0018] An obtaining unit, which obtains the identity identifier of a special person published by the tracking management platform;
[0019] A comparison unit compares with the list of user contact persons locally stored in the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes identity identifiers corresponding to other users whose contact distance with the user reaches a threshold value.
[0020] A generating unit, if there is a coincidence, generates a zero-knowledge proof that the user is the target tracking user based on a preset zero-knowledge proof algorithm, and sends the zero-knowledge proof to the tracking management platform, so that the tracking management platform verifies the zero-knowledge proof based on the zero-knowledge proof algorithm, and determines the user as the target tracking user when the verification passes.
[0021] Fourthly, the present application also proposes a user tracking device based on zero-knowledge proof, which is applied to a tracking management platform, and the tracking management platform is connected to a client; the device includes:
[0022] A publishing unit publishes the identity identifier of the special person, so that when the client obtains the identity identifier of the special person, it compares with the list of user contact persons locally stored in the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes identity identifiers corresponding to other users whose contact distance with the user reaches a threshold value.
[0023] A verification unit receives the zero-knowledge proof that the user is the target tracking user generated by the client based on a preset zero-knowledge proof algorithm, verifies the zero-knowledge proof based on the zero-knowledge proof algorithm, and determines the user as the target tracking user when the verification passes.
[0024] The technical solutions provided by the embodiments of the present application may include the following beneficial effects:
[0025] On the one hand, by obtaining the identity identifier of the special person published by the tracking management platform and comparing it with the list of user contact persons locally stored in the client, the existing risks can be understood in a timely manner, and a quick response can be made when a risk is detected, notifying relevant personnel or units to take measures as soon as possible; on the other hand, by verifying the zero-knowledge proof that the user is the target tracking user, the contact history of the user can be verified on the premise of protecting the privacy information of the user's social contacts, and it can be determined whether the user is really the target tracking user, ensuring the authenticity and reliability of the tracking of the target user.
[0026] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 is a flowchart of a user tracking method based on zero - knowledge proof shown in an exemplary embodiment of the present application;
[0028] Figure 2 is a schematic diagram of a user tracking method based on zero - knowledge proof shown in an exemplary embodiment of the present application;
[0029] Figure 3 is a schematic diagram of an application scenario of a user tracking method based on zero - knowledge proof shown in an exemplary embodiment of the present application;
[0030] Figure 4 is a flowchart of another user tracking method based on zero - knowledge proof shown in an exemplary embodiment of the present application;
[0031] Figure 5 is a schematic diagram of the process of a user tracking method based on zero - knowledge proof shown in an exemplary embodiment of the present application;
[0032] Figure 6 is a hardware structure diagram of an electronic device where a user tracking device based on zero - knowledge proof shown in an exemplary embodiment of the present application is located;
[0033] Figure 7 is a block diagram of a user tracking device based on zero - knowledge proof shown in an exemplary embodiment of the present application;
[0034] Figure 8 is a block diagram of another user tracking device based on zero - knowledge proof shown in an exemplary embodiment of the present application. Detailed implementation manners
[0035] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are only examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0036] It should be noted that: In other implementation manners, the steps of the corresponding methods are not necessarily executed in the order shown and described in this application. In some other implementation manners, the steps included in the method may be more or fewer than those described in this application. In addition, a single step described in this application may be decomposed into multiple steps for description in other implementation manners; and multiple steps described in this application may also be combined into a single step for description in other implementation manners.
[0037] It should also be noted that the term "comprise", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, commodity or device comprising said element.
[0038] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms "a", "said" and "the" used in this application and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0039] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to a determination".
[0040] In view of this, this application provides a technical solution for protecting user privacy and verifying the contact history of users by using zero-knowledge proof during user tracking, so as to achieve the tracking of target users.
[0041] In implementation, the client connected to the tracking management platform may obtain the identity identifier of a special person released by the tracking management platform.
[0042] Then, it is compared with the list of user contact persons locally stored in the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes the identity identifiers corresponding to other users whose contact distance with the user reaches a threshold.
[0043] If there is, a zero-knowledge proof that the user is the target tracking user is generated based on a preset zero-knowledge proof algorithm, and the zero-knowledge proof is sent to the tracking management platform for the tracking management platform to verify the zero-knowledge proof based on the zero-knowledge proof algorithm and determine the user as the target tracking user when the verification passes.
[0044] Through the above technical solutions, on the one hand, by obtaining the identity identifier of a special person released by the tracking management platform and comparing it with the list of user contact persons locally stored on the client side, the existing risks can be understood in a timely manner, and when a risk is detected, a quick response can be made to notify relevant personnel or units to take measures as soon as possible; on the other hand, by using zero-knowledge proof to verify that the user is the target tracking user, the contact history of the user can be verified on the premise of protecting the privacy information of the user's social contacts, so as to determine whether the user is really the target tracking user and ensure the authenticity and reliability of the tracking of the target user.
[0045] Next, the embodiments of the present application will be described in detail.
[0046] Please refer to Figure 1 , Figure 1 which is a flowchart of a user tracking method based on zero-knowledge proof shown in an exemplary embodiment of the present application. As Figure 1 shown, the method is applied to the client side, and the client side is connected to the tracking management platform, and includes the following steps:
[0047] Step 101: Obtain the identity identifier of the special person released by the tracking management platform;
[0048] Step 102: Compare it with the list of user contact persons locally stored on the client side to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes the identity identifiers corresponding to other users whose contact distance with the user reaches the threshold;
[0049] Step 103: If there is, generate a zero-knowledge proof that the user is the target tracking user based on a preset zero-knowledge proof algorithm, and send the zero-knowledge proof to the tracking management platform, so that the tracking management platform verifies the zero-knowledge proof based on the zero-knowledge proof algorithm, and determines the user as the target tracking user when the verification passes.
[0050] It should be noted that the above client can be a client installed on a mobile terminal, such as an APP installed on a user's smart phone or client software installed on a laptop computer, and the present application does not limit what kind of mobile terminal it is.
[0051] In addition, the above client can be a client developed by the tracking management platform or a client certified by the tracking management platform, and the present application does not limit this.
[0052] The tracking management platform can be controlled by an authoritative party, and the authoritative party can be a government agency or an industry organization. In this article, the authoritative party is not limited to a specific organization or individual.
[0053] In addition, there can be multiple authoritative parties, each responsible for different services. For example, the authoritative party that issues the identity identifiers of special personnel, or the authoritative party that interfaces with the target-tracking users. This application does not make any limitations in this regard.
[0054] In this embodiment, the client can obtain the identity identifiers of special personnel released by the tracking management platform.
[0055] Among them, when the tracking management platform releases the identity identifiers of special personnel, it can be released regularly based on a preset time, or can be released in a timely manner after confirming the special personnel. This application does not make any limitations in this regard.
[0056] In one example, the mobile terminal installed with the client can obtain, through the network, the list of identity identifiers of special personnel released by the tracking management platform, and this list contains the identity identifiers of all the released special personnel.
[0057] In another example, the above-mentioned client can also listen to the release events of the tracking management platform and obtain them in a timely manner every time the tracking management platform releases the identity identifiers of special personnel.
[0058] In an illustrated implementation manner, the special personnel include infectious disease patients, the users include potential infectious disease contacts, and the target-tracking users include confirmed infectious disease contacts.
[0059] The tracking management platform can, by releasing the identity identifiers of infectious disease patients, enable users to timely understand the existing risks through the client and confirm whether they have come into contact with infectious disease patients, that is, whether they are infectious disease contacts. Among them, before determining whether a user is an infectious disease contact, the user can be identified as a potential infectious disease contact.
[0060] In order to further cut off the infectious disease transmission chain and implement more stringent detection, the special personnel can be defined as infectious disease patients and infectious disease contacts. When releasing, the infectious disease patients and infectious disease contacts can be released separately, or can be released together.
[0061] In an illustrated implementation manner, the identity identifier of the infectious disease patient, and / or the identity identifier of the infectious disease contact.
[0062] For example, the identity identifier of the special personnel can be the identity identifier of the infectious disease patient; it can also be the identity identifier of the infectious disease contact; it can also be the identity identifier of the infectious disease patient and the identity identifier of the infectious disease contact.
[0063] In addition to the infectious disease tracking scenario of the above example, the present application can also be used in various other tracking scenarios. The present application does not limit what specific scenarios it is used in, and those skilled in the art can apply the above technical solutions as needed.
[0064] It should be noted that in addition to confirming the target tracking user through the technical solutions of the above steps 101 to 103, when the user has been confirmed as a special person or a target tracking user offline, the user's identity identifier can be directly sent to the tracking management platform, so that after the tracking management platform determines that the user is a target tracking user or a special person, the user's identity identifier is published.
[0065] In an illustrated embodiment, the user's identity identifier is sent to the tracking management platform, so that after the tracking management platform determines that the user is a target tracking user or the special person, the user's identity identifier is published.
[0066] For example, when a user is diagnosed as an infectious disease infected person offline, the user's identity identifier can be directly sent to the tracking management platform. After the tracking management platform verifies and confirms according to the user's diagnosis record or by the staff, the user's identity identifier is published as the identity identifier of a special person.
[0067] Another example is that if the user knows an infectious disease infected person and knows that he himself belongs to an infectious disease contact before the tracking management platform publishes the identity identifier of the infectious disease infected person, then the user can report the identity identifier through the client, and after the tracking management platform verifies and confirms according to the user's contact record or by the staff, the user's identity identifier is published.
[0068] When generating the identity identifier of the above special person and the user's identity identifier, in order to protect privacy information, a preset generation algorithm can be called to generate a random anonymous identifier.
[0069] For example, the data digest of information such as the user's ID number or mobile phone number can be used as the identity identifier.
[0070] Furthermore, in order to facilitate tracking and sort out the contact timeline, a random anonymous identifier can also be generated for the user based on a preset time period by calling a preset generation algorithm.
[0071] In an illustrated embodiment, the above identity identifier can be a random anonymous identifier generated for the user by the client based on a preset time period by calling a preset generation algorithm.
[0072] For example, the client can call a preset generation algorithm at fixed intervals or according to preset time points to generate a random anonymous identifier for the user based on the current timestamp and user-related information as the user's identity identifier.
[0073] After the above process, the user's final identity identifier can be sent and stored in the form of an identity identifier list.
[0074] It can be understood that when the tracking management platform publishes the identity identifiers of special personnel, it can obtain the identity identifier list generated by the client used by the special personnel for publication.
[0075] For example, when a user is diagnosed as an infectious disease infected person offline, the identity identifier list generated by the client in the past few days can be sent to the tracking management platform for publication by the tracking management platform.
[0076] In this embodiment, the obtained identity identifiers of special personnel can be compared with the user contact personnel list stored locally on the client to determine whether there are identity identifiers in the user contact personnel list that coincide with the identity identifiers of special personnel. Among them, the user contact personnel list includes the identity identifiers corresponding to other users whose contact distance with the user reaches the threshold.
[0077] As can be seen from the foregoing, the client can generate its own identity identifier list for the user, store the identity identifier list, and send the identity identifier list to the tracking management platform. Since the identity identifiers in the identity identifier list are random anonymous identifiers, user privacy can be protected to a certain extent.
[0078] In addition, the client can also generate a user contact personnel list, which records the identity identifiers corresponding to other users whose contact distance with the user reaches the threshold.
[0079] For example, assume that the identity identifier list of infectious disease infected persons published by the tracking management platform is SID1B, SID2B, ……, SIDnB, and the identity identifiers in this list are generated by the client used by the infectious disease infected persons for the infected persons. After the user obtains the above identity identifier list of infectious disease infected persons, it is compared with the user contact personnel list stored locally on the client used by the user, and the two lists are cross-matched.
[0080] Continuing with the example, assume that the list of users the user has come into contact with is SID1C, SID2B, SID3C, SID5D... Then, it can be determined that SID2B is the identity identifier that exists in both lists, indicating that the user has come into contact with an infectious disease patient. Then, the client can notify the user that they have come into contact with an infectious disease patient, prompt the user to take isolation measures, and trigger subsequent step 103, inform the tracking and management platform that the user has a contact history, and send it to the tracking and management platform after generating a zero-knowledge proof.
[0081] When the client constructs the above list of users the user has come into contact with, the determination rules for contact can be set by those skilled in the art based on the strictness of the tracking.
[0082] Preferably, in one of the illustrated embodiments, the client can establish communication with the clients of other users through short-range wireless communication technology; receive the identity identifiers of other users sent by the clients of other users; when the contact distance between the user and the other user is within a preset first distance threshold range, add the identity identifier of the other user to the list of users the user has come into contact with stored locally by the client; or, when the contact distance between the user and the other user is within a preset second distance threshold range and the contact duration reaches a preset time threshold, add the identity identifier of the other user to the list of users the user has come into contact with stored locally by the client; wherein, the first distance threshold is less than the second distance threshold.
[0083] Among them, this application does not limit which short-range wireless communication technology to use, and those skilled in the art can adopt based on Bluetooth technology, Wi-Fi technology, RFID non-contact radio frequency identification technology, or NFC near-field communication technology according to actual needs.
[0084] For example, please refer to Figure 2 , Figure 2 is a schematic diagram of a user tracking method based on zero-knowledge proof shown in an exemplary embodiment of this application. Among them, assume that the client where user A is located is client A, and the clients corresponding to user B, user C, and user D are client B, client C, and client D respectively, and the devices where the above four clients are located have their Bluetooth functions enabled.
[0085] As Figure 2 shown, assume that client B, client C, and client D are all within the maximum Bluetooth communication distance of the device where client A is located. Then, client A can establish communication with client B, client C, and client D, and receive the identity identifiers corresponding to user B, user C, and user D sent by client B, client C, and client D respectively.
[0086] Next, client A needs to determine whether to add the identity identifiers corresponding to users B, C, and D to the contact list of user A based on a preset contact determination rule.
[0087] As Figure 2 shown, since the contact distance between user A and user B is within the preset first distance threshold range, the identity identifier SID1B of user B can be added to the user contact list stored locally on the client of user A.
[0088] Since the contact distance between user A and user C is within the preset second distance threshold range, and because the first distance threshold is less than the second distance threshold, it is also necessary to additionally determine whether the contact distance between user A and user C has reached the preset time threshold. If so, the identity identifier SID2C of user C can be added to the user contact list stored locally on the client of user A.
[0089] Since user D is outside the second distance threshold range of user A, although client A can establish communication with client D, since user D does not meet the contact determination rule, it does not belong to the contacts of user A, and the identity identifier SID3D of user C does not need to be added to the contact list of user A.
[0090] Therefore, Figure 2 the identity identifiers included in the contact list of user A shown are SID1B and SID2C.
[0091] Similarly, in an illustrated embodiment, the client can send the identity identifier of the user to the clients of the other users, so that the clients of the other users can determine whether to store the identity identifier of the user based on the contact distance between the user and the other users.
[0092] Continuing with the example, as Figure 2 shown, client A can also send the identity identifier SID1A of user A to clients B, C, and D, so that clients B, C, and D can respectively determine whether to store the identity identifier of user A based on the above judgment process of client A. The specific process can refer to the above text and will not be elaborated here.
[0093] In addition, when the client establishes communication with the clients of other users through short-range wireless communication technology, it can also record the time point when the communication connection is established and the time point when the communication connection is disconnected.
[0094] It can be understood that, as Figure 2 shown, clients B, C, and D can also establish communication connections with each other. The specific process can refer to the description of client A above and will not be elaborated here.
[0095] It should be noted that since the user contact list records the user's social activity information, which belongs to the user's privacy information, it also needs to be protected.
[0096] In this embodiment, in response to finding the identity identifier of the special person in the user contact list locally stored on the client in the above step 102, the subsequent step 103 is triggered.
[0097] In this embodiment, a zero-knowledge proof that the user is the target tracking user can be generated based on a preset zero-knowledge proof algorithm, and the zero-knowledge proof is sent to the tracking management platform, so that the tracking management platform verifies the zero-knowledge proof based on the zero-knowledge proof algorithm, and determines the user as the target tracking user when the verification is passed.
[0098] Among them, zero-knowledge proof is a probability-based verification method, which means that the prover makes the verifier believe that a certain assertion is true, and no knowledge other than "the assertion is true" is leaked during the whole process.
[0099] That is to say, zero-knowledge proof means that the prover can, without providing any useful knowledge to the verifier, make the verifier believe that a certain assertion is correct by providing publicly available information. As the name implies, zero-knowledge proof can prove that the assertion is correct without leaking any knowledge, that is, the knowledge provided to the outside world is zero.
[0100] In practical applications, developers can obtain a proof generation program for the prover to generate proofs and a proof verification program for the verifier to verify proofs through zero-knowledge proof development tools.
[0101] For example, the client, as the prover, can input privacy information and publicly available information into the proof generation program to generate a zero-knowledge proof that the user is the target tracking user, and send the zero-knowledge proof to the tracking management platform. And the tracking management platform, as the verifier, can obtain the publicly available information provided by the client and input the publicly available information into the proof verification program to implement the verification of the zero-knowledge proof. In the above process, the client can make the tracking management platform believe that the user is the target tracking user without disclosing any knowledge, that is, the identity identifier of the special person exists in the user contact list.
[0102] Among them, in order to prevent the forgery of publicly available information and ensure the authenticity of publicly available information, the client can send the publicly available information to the tracking management platform for storage before generating the zero-knowledge proof. Further, in order to ensure the integrity of the transmission of publicly available information and at the same time ensure the efficiency of verification, the publicly available information can be stored in the form of a Merkle tree.
[0103] It should be noted that, in order to protect the privacy information of users' social activities, a second Merkle tree can be constructed based on the list of user contact persons stored locally on the client and sent to the tracking management platform as publicly available information.
[0104] In an illustrated embodiment, a first Merkle tree can be constructed based on the list of user identity identifiers stored locally on the client; wherein, the list of user identity identifiers includes a set of random anonymous identifiers generated by the user's client for the user; a second Merkle tree is constructed based on the list of user contact persons stored locally on the client; the first Merkle tree and the second Merkle tree are sent to the tracking management platform for storage; wherein, the tracking management platform also stores the third Merkle tree constructed based on the list of identity identifiers of the special persons; the list of identity identifiers of the special persons includes a set of random anonymous identifiers generated by the special person's client for the special person.
[0105] For example, the client can be sent to the management platform for storage according to a preset rule. For example, the above first Merkle tree and second Merkle tree can be sent to the tracking management platform for storage at regular intervals, or in response to different preset logics, the first Merkle tree and the second Merkle tree can be sent to the tracking management platform for storage respectively. This application does not make any limitations in this regard, and those skilled in the art can set it according to their needs.
[0106] In addition, regarding how to construct the above Merkle tree, those skilled in the art can easily implement it, and this application will not elaborate on it.
[0107] In an example, according to the foregoing, when a user is diagnosed as an infectious disease infected person offline, the list of the user's own identity identifiers generated by the client in the past few days can be sent to the tracking management platform. The tracking management platform compares it according to the first Merkle tree constructed based on the list of user identity identifiers stored in advance to verify whether the list of identity identifiers sent by the user is true. After confirming that the user is an infectious disease infected person, the list of the user's identity identifiers is published as the list of identity identifiers of special persons.
[0108] In another example, as can be seen from the foregoing, when the user confirms that the identity identifier of an infectious disease infected person exists in the user's contact list, a zero-knowledge proof that the user is a contact of the infectious disease needs to be generated. To verify the authenticity of the second Merkle tree and the third Merkle tree, which are publicly available information, the tracing management platform can compare the second Merkle tree and the third Merkle tree provided by the client with the second Merkle tree and the third Merkle tree pre-stored in the tracing management platform. Among them, the client can also only provide the root values of the second Merkle tree and the third Merkle tree, and the tracing management platform calculates the corresponding root values of the second Merkle tree and the third Merkle tree pre-stored respectively, and compares them to confirm the authenticity of the second Merkle tree and the third Merkle tree as publicly available information.
[0109] To improve the efficiency of the zero-knowledge proof, a Merkle proof can be made based on the above Merkle tree, that is, it is proved that the overlapping identity identifiers in step 102 exist in the second Merkle tree and the third Merkle tree respectively. Therefore, the zero-knowledge proof can include a first Merkle proof that the identity identifier of the special person exists in the second Merkle tree, and a second Merkle proof that the identity identifier of the special person exists in the third Merkle tree.
[0110] In an illustrated embodiment, the above zero-knowledge proof may include a Merkle proof.
[0111] Furthermore, the user contact list, the identity identifier list of the special person, the second Merkle tree, and the third Merkle tree can be input into the proof generation program corresponding to the preset zero-knowledge proof algorithm to generate a zero-knowledge proof that the user is the target tracing user; wherein, the zero-knowledge proof includes a first Merkle proof that the identity identifier of the special person exists in the second Merkle tree, and a second Merkle proof that the identity identifier of the special person exists in the third Merkle tree; determine the root value of the second Merkle tree constructed based on the user contact list; determine the root value of the third Merkle tree constructed based on the identity identifier list of the special person; and send the zero-knowledge proof, the root value of the second Merkle tree, and the root value of the third Merkle tree to the tracing management platform.
[0112] For example, the user contact list ListC-A is SID1C, SID2B, SID3C, SID5D..., the second Merkle tree constructed based on the user contact list is MerkleRootC-A, the identity identifier list of the special person ListS-B is SID1B, SID2B,..., SIDnB, and the third Merkle tree constructed based on the identity identifier list of the special person is MerkleRootS-B.
[0113] Then the client can input the user contact person list ListC-A, the identity identifier list ListS-B of special persons, the second Merkle tree MerkleRootC-A, and the third Merkle tree input MerkleRootS-B into the proof generation program ProofGen corresponding to the preset zero-knowledge proof algorithm to generate the zero-knowledge proof Proof that the user is the target tracking user, that is, Proof = ProofGen(ListC-A, ListS-B, MerkleRootC-A, MerkleRootS-B).
[0114] Then, the client can determine the root value of MerkleRootC-A and the root value of MerkleRootS-B and send them to the tracking management platform.
[0115] In an illustrated embodiment, the tracking management platform can determine whether there are the pre-stored second Merkle tree and the third Merkle tree based on the received root value of the second Merkle tree and the root value of the third Merkle tree; if so, input the zero-knowledge proof, the root value of the second Merkle tree, and the root value of the third Merkle tree into the proof verification program corresponding to the preset zero-knowledge proof algorithm to verify the correctness of the zero-knowledge proof.
[0116] Continuing with the example, after receiving the above zero-knowledge proof Proof, the root value of MerkleRootC-A, and the root value of MerkleRootS-B, the tracking management platform can first verify the root value of MerkleRootC-A and the root value of MerkleRootS-B to determine whether there is a Merkle tree with the same root value in the pre-stored Merkle trees, and verify the reliability of the root values of the Merkle trees sent by the client.
[0117] Then it can verify the correctness of the zero-knowledge proof Proof, input the zero-knowledge proof, the root value of MerkleRootC-A, and the root value of MerkleRootS-B into the proof verification program ProofVerify corresponding to the preset zero-knowledge proof algorithm to determine the result Result of the zero-knowledge proof verification, that is, Result = ProofVerify(Proof, MerkleRootC-A, MerkleRootS-B).
[0118] Among them, if Result is True, it means that the user has had contact with special persons and belongs to the target tracking user, and further measures need to be taken, while if Result is False, it means that the user is not the target tracking user.
[0119] It should be noted that the specific principle of Merkel's proof will not be elaborated here, which does not affect those skilled in the art to implement the technical solution to be protected by this application according to this specification.
[0120] In addition to pre-storing the above Merkel tree in the tracking management platform, the characteristics of the blockchain can also be utilized to store the data involved in the above technical solution on the chain for evidence, and obtain relevant data from the chain.
[0121] Furthermore, in an illustrated embodiment, the above client and tracking management platform can be connected to the blockchain.
[0122] The above client can respectively publish the first Merkel tree and the second Merkel tree to the blockchain for evidence storage, so that the tracking management platform can obtain the first Merkel tree and the second Merkel tree from the blockchain.
[0123] Similarly, the tracking management platform can respectively publish the identity identifier of special personnel and the third Merkel tree to the blockchain for evidence storage.
[0124] It can be understood that the above blockchain can store the first Merkel tree and the second Merkel tree published by the client; it can also store the identity identifier of special personnel published by the tracking management platform and the third Merkel tree.
[0125] Please refer to Figure 3 , Figure 3 which is a schematic diagram of an application scenario of a user tracking method based on zero-knowledge proof shown in an exemplary embodiment of this application.
[0126] Among them, the client can store the first Merkel tree and the second Merkel tree on the chain according to a preset rule or time period. Among them, the first Merkel tree is constructed based on a list of user identity identifiers composed of randomly generated anonymous identifiers for users, and the second Merkel tree is constructed based on a list of user contact personnel stored locally by the client.
[0127] As Figure 3 shown, the first Merkel tree MerkleRootA1 and the second Merkel tree MerkleRootA2 corresponding to user A, as well as the first Merkel tree MerkleRootB1 and the second Merkel tree MerkleRootB2 corresponding to user B are stored on the blockchain. In addition, the list of identity identifiers ListC1 of special personnel published by the tracking management platform and the third Merkel tree MerkleRootC3 corresponding to ListC1 are also stored on the blockchain.
[0128] In one example, when user A is diagnosed as an infectious disease patient offline, the user can send the list of user identity identifiers ListA1 for the past few days to the tracking and management platform through the client. The tracking and management platform can obtain the corresponding Merkle tree MerkleRootA1 of this user from the blockchain. By comparing the list of user identity identifiers ListA1 with the Merkle tree MerkleRootA1 obtained from the blockchain, the authenticity of the list of identity identifiers ListA1 sent by the user is determined. After confirming the authenticity, the list of identity identifiers ListA1 of the user is published as the list of identity identifiers of special personnel to the blockchain.
[0129] In another example, user B can listen to the publishing events on the blockchain through the client, obtain the list of identity identifiers ListC1 of special personnel published by the tracking and management platform from the blockchain, and compare it with the list of user's contact personnel ListB2 stored locally. Assuming that the comparison result shows that there is an overlapping identity identifier SID5C, then user B can generate a zero-knowledge proof with user B as the target tracking user through the client.
[0130] Next, continue to take user B as an example to describe the generation and verification process of the zero-knowledge proof.
[0131] When generating the zero-knowledge proof, user B can also obtain the corresponding third Merkle tree MerkleRootC3 of the list of identity identifiers ListC1 of special personnel published by the tracking and management platform from the blockchain through the client, and input the list of user B's contact personnel ListB2, the list of identity identifiers ListC1 of special personnel, the second Merkle tree MerkleRootB2 corresponding to user B, and the third Merkle tree MerkleRootC3 corresponding to special personnel into the proof generation program corresponding to the preset zero-knowledge proof algorithm to generate a zero-knowledge proof with user B as the target tracking user.
[0132] Among them, the zero-knowledge proof contains two Merkle proofs, namely the first Merkle proof that the identity identifier SID5C of special personnel exists in the second Merkle tree MerkleRootB2, and the second Merkle proof that the identity identifier SID5C of special personnel exists in the third Merkle tree MerkleRootC3. That is, the identity identifier of special personnel exists not only in the list of user B's contact personnel ListB2, but also in the list of identity identifiers ListC1 of special personnel.
[0133] Furthermore, the generated zero-knowledge proof, the root value of MerkleRootB2, and the root value of MerkleRootC3 can be sent to the tracking and management platform for the tracking and management platform to verify the reliability of the data and the zero-knowledge proof respectively.
[0134] The tracking management platform can, in response to the received root values of MerkleRootB2 and MerkleRootC3, obtain MerkleRootB2 and MerkleRootC3 from the chain, calculate the root values of MerkleRootB2 and MerkleRootC3, compare the calculated results with the received root values respectively. When the comparison passes, it indicates that the data is true and reliable, and the zero-knowledge proof verification can continue. When the comparison fails, it indicates that the data is unreliable and there is no need to perform zero-knowledge proof.
[0135] Then, when verifying the zero-knowledge proof, the tracking management platform can input the zero-knowledge proof, the root value of MerkleRootB2, and the root value of MerkleRootC3 into the proof verification program corresponding to the preset zero-knowledge proof algorithm to verify the correctness of the zero-knowledge proof.
[0136] If the above zero-knowledge proof verification passes, it can be confirmed that user B is the target tracking user.
[0137] Furthermore, the tracking management platform can require user B to upload the user identity list ListB1, obtain the Merkle tree MerkleRootB1 corresponding to user B stored on the chain for comparison. After the comparison is successful, the identity list ListB1 of user B is published as the identity list of special personnel.
[0138] In the above technical solution, on the one hand, by obtaining the identity list of special personnel published by the tracking management platform and comparing it with the user contact list stored locally on the client, the existing risks can be understood in a timely manner, and a quick response can be made when risks are detected to notify relevant personnel or units to take measures as soon as possible. On the other hand, by verifying the user as the target tracking user through zero-knowledge proof, the contact history of the user can be verified on the premise of protecting the privacy information of the user's social contacts to determine whether the user is really the target tracking user, ensuring the authenticity and reliability of the tracking of the target user.
[0139] Please refer to Figure 4 , Figure 4 which is a flowchart of another user tracking method based on zero-knowledge proof shown in an exemplary embodiment of the present application. As Figure 4 shown, the method is applied to a tracking management platform, and the tracking management platform is connected to the client, including the following steps:
[0140] Step 401: Publish the identity identifier of a special person, so that when the client obtains the identity identifier of the special person, it compares it with the list of user contact persons stored locally by the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes the identity identifiers corresponding to other users whose contact distance with the user reaches a threshold value;
[0141] Step 402: Receive the zero-knowledge proof that the user is the target tracking user generated by the client based on a preset zero-knowledge proof algorithm, verify the zero-knowledge proof based on the zero-knowledge proof algorithm, and determine the user as the target tracking user when the verification passes.
[0142] In this embodiment, the tracking management platform may publish the identity identifier of a special person, so that when the client obtains the identity identifier of the special person, it compares it with the list of user contact persons stored locally by the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person.
[0143] Wherein, the list of user contact persons includes the identity identifiers corresponding to other users whose contact distance with the user reaches a threshold value.
[0144] In an illustrated implementation manner, the above-mentioned tracking management platform may receive the identity identifier of the user, and after determining that the user is the target tracking user or the special person, publish the identity identifier of the user.
[0145] In an illustrated implementation manner, the special person includes an infectious disease infected person, the user includes a potential infectious disease contact person, and the target tracking user includes a confirmed infectious disease contact person.
[0146] In an illustrated implementation manner, the identity identifier of the special person includes:
[0147] The identity identifier of the infectious disease infected person, and / or the identity identifier of the infectious disease contact person.
[0148] In an illustrated implementation manner, the identity identifier includes a random anonymous identifier generated by the client for the user based on a preset time period by invoking a preset generation algorithm.
[0149] In an illustrated implementation manner, the above-mentioned tracking management platform may store the first Merkle tree and the second Merkle tree sent by the client.
[0150] Among them, the first Merkle tree is constructed based on the list of user identity identifiers stored locally on the client; the list of user identity identifiers includes a set of random anonymous identifiers generated by the user's client for the user; the second Merkle tree is constructed based on the list of user contact persons stored locally on the client.
[0151] Further, the above-mentioned tracking management platform can also store the third Merkle tree constructed based on the list of identity identifiers of the special persons.
[0152] Among them, the list of identity identifiers of the special persons includes a set of random anonymous identifiers generated by the client of the special persons for the special persons.
[0153] In this embodiment, the tracking management platform can receive the zero-knowledge proof that the user is the target tracking user generated by the client based on a preset zero-knowledge proof algorithm, verify the zero-knowledge proof based on the zero-knowledge proof algorithm, and determine the user as the target tracking user when the verification passes.
[0154] In an illustrated implementation manner, the zero-knowledge proof includes a Merkle proof.
[0155] Further, the above-mentioned tracking management platform can receive the zero-knowledge proof, the root value of the second Merkle tree, and the root value of the third Merkle tree.
[0156] Among them, the zero-knowledge proof includes the first Merkle proof that the identity identifier of the special person exists in the second Merkle tree, and the second Merkle proof that the identity identifier of the special person exists in the third Merkle tree; the root value of the second Merkle tree is determined based on the second Merkle tree constructed based on the list of user contact persons; the root value of the third Merkle tree is determined based on the third Merkle tree constructed based on the list of identity identifiers of the special persons.
[0157] In an illustrated implementation manner, the above-mentioned tracking management platform can determine whether the pre-stored second Merkle tree and third Merkle tree exist based on the received root value of the second Merkle tree and the root value of the third Merkle tree; if they exist, input the zero-knowledge proof, the root value of the second Merkle tree, and the root value of the third Merkle tree into the proof verification program corresponding to the preset zero-knowledge proof algorithm to verify the correctness of the zero-knowledge proof.
[0158] In one of the illustrated embodiments, the above-mentioned tracking management platform may receive the identity identification list of the user. After determining that the user is a target tracking user or the special person, a Merkle tree is constructed based on the received identity identification list of the user and compared with the pre-stored first Merkle tree. If they are consistent, the user is regarded as the target tracking user or the special person, and the identity identification list of the user is published.
[0159] In one of the illustrated embodiments, the client and the tracking management platform may be connected to the blockchain. The first Merkle tree and the second Merkle tree published by the client are stored on the blockchain.
[0160] Furthermore, the tracking management platform may separately publish the identity identification of the special person and the third Merkle tree to the blockchain for deposit.
[0161] In the above technical solutions, on the one hand, by obtaining the identity identification of the special person published by the tracking management platform and comparing it with the list of user contact persons locally stored by the client, the existing risks can be understood in a timely manner, and when risks are detected, a quick response can be made to notify relevant personnel or units to take measures as soon as possible. On the other hand, by verifying through zero-knowledge proof that the user is a target tracking user, the contact history of the user can be verified on the premise of protecting the privacy information of the user's social contacts, and it can be determined whether the user is really a target tracking user, ensuring the authenticity and reliability of the tracking of the target user.
[0162] The specific details of the above-mentioned user tracking method based on zero-knowledge proof applied to the tracking management platform have been described in detail in the process of the user tracking method based on zero-knowledge proof applied to the client described above. Those skilled in the art can refer to the relevant descriptions of the user tracking method based on zero-knowledge proof applied to the client, and will not be elaborated here.
[0163] Combined with the above Figure 3 application scenario schematic diagram of a user tracking method based on zero-knowledge proof provided in Figure 2 and Figure 4 the flowchart of the user tracking method based on zero-knowledge proof provided in Figure 5 please refer to Figure 5 which is a schematic flowchart of a user tracking method based on zero-knowledge proof shown in an exemplary embodiment of the present application. This method can be applied to the scenario of tracking contacts of infectious diseases and includes the following steps:
[0164] Among them, client A can be used to support and execute Figure 5 the method flow steps S501, S502, S505 and S508 shown inFigure 5 For the method flow steps shown in Figure 5 , S503, S504, S506, and S512 - S515, the infectious disease tracking and management platform can be used to support and execute Figure 5 the method flow steps S507, S509 - S511, and S516 - S522 shown in Figure 5 .
[0165] The following will be described from three aspects: client A, client B, and the infectious disease tracking and management platform. As Figure 5 shown, assume that user A is an infected person diagnosed offline, and user B is a contact of an infectious disease confirmed through online tracking. Figure 5 Please refer to steps S501 - S504. Client A and client B will respectively generate a user identity list and a user contact list locally.
[0166] As described above, the client can generate two identity lists for the user. One is the user identity list, which can record the random anonymous identifier generated by the client for the user based on a preset time period and by calling a preset generation algorithm. The other is the contact list, which can record the identity identifiers corresponding to other users whose contact distance with the user reaches a threshold.
[0167]
[0168] Step S501: Generate the identity list ListA1 of user A.
[0169] Step S502: Generate the contact list ListA2 of user A.
[0170] Step S503: Generate the identity list ListB1 of user B.
[0171] Step S504: Generate the contact list ListB2 of user B.
[0172] Figure 2 Among them, the generation rules of the user identity list can be referred to the description of the foregoing embodiments, and the generation rules of the contact list can be referred to the description of the embodiments shown in Figure 2
[0173] Please refer to steps S505 - S507. Client A, client B, and the infectious disease tracking and management platform can initiate a publishing transaction to the blockchain, send the corresponding data to the blockchain, so that the blockchain, in response to the publishing transaction, publishes the received data to the blockchain for evidence storage.
[0174] Among them, a smart contract can also be deployed on the blockchain. This smart contract is used to manage the above - mentioned data. The blockchain can, in response to the above - mentioned publishing transaction, call the publishing logic in the smart contract to publish the above - mentioned data to the blockchain for evidence storage.
[0175] Step S505: Client A can store the MerkleRootA1 and MerkleRootA2 on the blockchain for evidence.
[0176] Among them, MerkleRootA1 is constructed by Client A based on ListA1, and MerkleRootA2 is constructed by Client A based on ListA2.
[0177] Step S506: Client B can store the MerkleRootB1 and MerkleRootB2 on the blockchain for evidence.
[0178] Among them, MerkleRootB1 is constructed by Client B based on ListB1, and MerkleRootB2 is constructed by Client B based on ListB2.
[0179] It should be noted that Client A and Client B can store the data on the blockchain for evidence based on a preset time period, or can store the data on the blockchain in response to a preset trigger rule.
[0180] Step S507: The infectious disease tracking and management platform can store ListC1 and the corresponding MerkleRootC3 of ListC1 on the blockchain for evidence.
[0181] For the infectious disease tracking and management platform, it can publish the identity identification list ListC1 of infectious disease infected persons regularly based on a preset time, or can publish ListC1 in a timely manner after confirming the infectious disease infected persons, and at the same time of publishing ListC1, it can store the corresponding MerkleRootC3 of ListC1 on the blockchain for evidence.
[0182] Please refer to Steps S508 - S511, which describe the process after User A is diagnosed with an infectious disease offline.
[0183] Step S508: After User A is diagnosed with an infectious disease offline, User A can send ListA1 to the infectious disease tracking and management platform for publishing, but the infectious disease tracking and management platform will verify the reliability of ListA1 before publishing.
[0184] Step S509: The infectious disease tracking and management platform can obtain MerkleRootA1 from the blockchain.
[0185] Step S510: The infectious disease tracking and management platform can compare ListA1 with MerkleRootA1 to determine the reliability of ListA1 sent by User A.
[0186] Step S511: The infectious disease tracking and management platform can publish ListA1 to the blockchain after the comparison is successful.
[0187] Please refer to steps S512 - S515, which describe the process where user B monitors the identity identifiers of infectious disease patients online and generates a zero - knowledge proof after confirming contact with the patients.
[0188] Step S512: Client B can obtain ListC1 of the patients released by the infectious disease tracking and management platform, and can also obtain MerkleRootC3 corresponding to ListC1.
[0189] The above - mentioned blockchain can deploy a smart contract, and generate an event for the release of infectious disease patients after the infectious disease tracking and management platform releases ListC1. Client B can listen for and respond to this event for the release of infectious disease patients to obtain ListC1.
[0190] Step S513: Client B can match the obtained ListC1 of the patients with the contact list ListB2 of user B to determine whether there are overlapping identity identifiers of the patients in ListC1.
[0191] Step S514: Generate a zero - knowledge proof with user B as the target tracking user.
[0192] As described above, when there are overlapping identity identifiers of the patients in ListC1 and ListB2, ListC1 and MerkleRootC3 obtained from the chain, as well as ListB2 and MerkleRootB2 locally stored by client B, can be input into the proof generation program corresponding to the preset zero - knowledge proof algorithm to generate a zero - knowledge proof with user B as the target tracking user.
[0193] Step S515: Client B can send the zero - knowledge proof, the root value of MerkleRootB2, and the root value of MerkleRootC3 to the infectious disease tracking and management platform.
[0194] As described above, since MerkleRootB2 and MerkleRootC3 are public parameters for generating the zero - knowledge proof, they can be sent as publicly available information to the verifier for verification. For privacy protection considerations, based on the characteristics of the Merkle tree, the root values corresponding to MerkleRootB2 and MerkleRootC3 can be calculated for verification.
[0195] Next, please refer to steps S516 - S518, which describe the process of the infectious disease tracking and management platform verifying the above - mentioned zero - knowledge proof.
[0196] After receiving the above zero-knowledge proof, the root value of MerkleRootB2, and the root value of MerkleRootC3, the infectious disease tracking and management platform can first verify the reliability of the root value of MerkleRootB2 and the root value of MerkleRootC3.
[0197] Step S516: Obtain MerkleRootB2 and MerkleRootC3.
[0198] Step S517: Compare the root value of MerkleRootB2 with the root value of MerkleRootB2, and compare the root value of MerkleRootC3 with the root value of MerkleRootC3.
[0199] If both comparisons are successful, it indicates that the data sent by User B is true and reliable and has not been forged.
[0200] Step S518: The infectious disease tracking and management platform verifies the above zero-knowledge proof.
[0201] The infectious disease tracking and management platform can input the zero-knowledge proof, the root value of MerkleRootB2, and the root value of MerkleRootC3 into the proof verification program corresponding to the preset zero-knowledge proof algorithm to verify the correctness of the zero-knowledge proof.
[0202] Next, please refer to steps S519 - S522, which describe the process after the zero-knowledge proof is verified.
[0203] Step S519: Obtain ListB1.
[0204] After the infectious disease tracking and management platform confirms that the user is an infectious disease contact, that is, the target tracking user, it can notify User B to upload ListB1.
[0205] Next, similar to steps S509 - S511, the infectious disease tracking and management platform needs to verify the reliability of ListB1 uploaded by User B and publish ListB1 after the verification passes.
[0206] Step S520: The infectious disease tracking and management platform can obtain MerkleRootB1 from the blockchain.
[0207] Step S521: The infectious disease tracking and management platform can compare ListB1 with MerkleRootB1 to determine the reliability of ListB1 sent by User B.
[0208] Step S522: The infectious disease tracking and management platform can publish ListB1 to the blockchain after the comparison is successful.
[0209] It should be noted that the infectious disease tracking and management platform can also publish infectious disease infected persons and infectious disease contacts as different types, and set different priorities to facilitate the allocation of resources for tracking. In addition, for infectious disease infected persons, warning levels can be set according to the disease severity level, and for infectious disease contacts, they can be classified according to different contact degrees. This application does not make any limitations in this regard, and those skilled in the art can choose according to their needs.
[0210] It can be understood that by dividing different publication types, it is not only beneficial to the resource allocation of the infectious disease tracking and management platform, but also enables users to take different response measures according to different risk levels. Further, it can more effectively trace the transmission chain and timely detect mutant viruses with stronger transmission capabilities.
[0211] In the above technical solutions, on the one hand, by obtaining the identity identifier of special personnel published by the tracking and management platform and comparing it with the list of user contact personnel stored locally on the client, the existing risks can be timely understood, and when risks are detected, a quick response can be made to notify relevant personnel or units to take measures as soon as possible; on the other hand, by verifying the user as the target tracking user through zero-knowledge proof, the contact history of the user can be verified on the premise of protecting the user's social contact privacy information to determine whether the user is really the target tracking user, ensuring the authenticity and reliability of the tracking of the target user.
[0212] Corresponding to the above method embodiment, the present application also provides an embodiment of a device.
[0213] Corresponding to the above method embodiment, the present application also provides an embodiment of a user tracking device based on zero-knowledge proof. The embodiment of the user tracking device based on zero-knowledge proof of the present application can be applied to an electronic device. The device embodiment can be implemented by software, or by hardware or a combination of software and hardware. Taking software implementation as an example, as a logically meaningful device, it is formed by the processor of the electronic device where it is located reading the corresponding computer program instructions in the non-volatile memory into the memory for operation. From the hardware level, as Figure 6 shown, it is a hardware structure diagram of an electronic device where a user tracking device based on zero-knowledge proof shown in an exemplary embodiment of the present application. In addition to Figure 6 the shown processor, memory, network interface, and non-volatile memory, the electronic device where the device is located in the embodiment usually also includes other hardware according to the actual functions of the electronic device, which will not be elaborated here.
[0214] Please refer to Figure 7 , Figure 7It is a block diagram of a user tracking device based on zero - knowledge proof shown in an exemplary embodiment of the present application. As Figure 7 shown, the user tracking device 700 based on zero - knowledge proof can be applied in the Figure 6 electronic device shown above, and includes:
[0215] An acquisition unit 701, which acquires the identity identifier of a special person released by the tracking management platform;
[0216] A comparison unit 702, which compares with the list of user contact persons stored locally in the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes the identity identifiers corresponding to other users whose contact distance with the user reaches a threshold;
[0217] A generation unit 703, if there is a coincidence, generates a zero - knowledge proof that the user is the target tracking user based on a preset zero - knowledge proof algorithm, and sends the zero - knowledge proof to the tracking management platform, so that the tracking management platform verifies the zero - knowledge proof based on the zero - knowledge proof algorithm, and determines the user as the target tracking user when the verification passes.
[0218] Among them, the above - mentioned client is docked with the tracking management platform.
[0219] In one embodiment, the device 700 further includes:
[0220] A publishing unit 704, which sends the identity identifier of the user to the tracking management platform, so that the tracking management platform publishes the identity identifier of the user after determining that the user is the target tracking user or the special person.
[0221] In one embodiment, the special person includes an infectious disease infected person, the user includes a potential infectious disease contact person, and the target tracking user includes a confirmed infectious disease contact person.
[0222] In one embodiment, the identity identifier of the special person includes:
[0223] The identity identifier of the infectious disease infected person, and / or the identity identifier of the infectious disease contact person.
[0224] In one embodiment, the identity identifier includes a random anonymous identifier generated by the client for the user based on a preset time period and a preset generation algorithm.
[0225] In one embodiment, the device 700 further includes:
[0226] A communication unit 705, through which the client establishes communication with the clients of other users via short-range wireless communication technology;
[0227] A receiving unit 706, which receives the identity identifiers of other users sent by the clients of other users;
[0228] A first judgment unit 707, when the contact distance between the user and the other user is within a preset first distance threshold range, adds the identity identifier of the other user to the list of user contact persons stored locally on the client; or,
[0229] A second judgment unit 708, when the contact distance between the user and the other user is within a preset second distance threshold range and the contact duration reaches a preset time threshold, adds the identity identifier of the other user to the list of user contact persons stored locally on the client; wherein, the first distance threshold is less than the second distance threshold.
[0230] In one embodiment, the device 700 further includes:
[0231] A first sending unit 709, the client sends the identity identifier of the user to the client of the other user, so that the client of the other user determines whether to store the identity identifier of the user based on the contact distance between the user and the other user.
[0232] In one embodiment, the device 700 further includes:
[0233] A first construction unit 710, which constructs a first Merkle tree based on the list of identity identifiers of the user stored locally on the client; wherein, the list of identity identifiers of the user includes a set of random anonymous identifiers generated by the client of the user for the user;
[0234] A second construction unit 711, which constructs a second Merkle tree based on the list of user contact persons stored locally on the client;
[0235] A second sending unit 712, which sends the first Merkle tree and the second Merkle tree to the tracking management platform for storage; wherein, the tracking management platform also stores the third Merkle tree constructed based on the list of identity identifiers of the special persons; the list of identity identifiers of the special persons includes a set of random anonymous identifiers generated by the client of the special persons for the special persons.
[0236] In one embodiment, the zero-knowledge proof includes a Merkle proof;
[0237] The generating unit 703 further:
[0238] Input the user contact person list, the identity identifier list of the special person, the second Merkle tree, and the third Merkle tree into the proof generation program corresponding to the preset zero-knowledge proof algorithm to generate a zero-knowledge proof that the user is the target tracked user; wherein, the zero-knowledge proof includes a first Merkle proof that the identity identifier of the special person exists in the second Merkle tree, and a second Merkle proof that the identity identifier of the special person exists in the third Merkle tree;
[0239] Determine the root value of the second Merkle tree constructed based on the user contact person list;
[0240] Determine the root value of the third Merkle tree constructed based on the identity identifier list of the special person;
[0241] Send the zero-knowledge proof, the root value of the second Merkle tree, and the root value of the third Merkle tree to the tracking management platform.
[0242] In one embodiment, the client and the tracking management platform are connected to the blockchain; the identity identifiers of the special persons published by the tracking management platform and the third Merkle tree are stored on the blockchain;
[0243] The apparatus 700 further includes:
[0244] A blockchain uploading unit 713 that publishes the first Merkle tree and the second Merkle tree by the client to the blockchain for storage, so that the tracking management platform can obtain the first Merkle tree and the second Merkle tree from the blockchain.
[0245] Please refer to Figure 8 , Figure 8 which is a block diagram of another user tracking apparatus based on zero-knowledge proof shown in an exemplary embodiment of the present application. As Figure 8 shown, the user tracking apparatus 800 based on zero-knowledge proof can be applied to the electronic device shown in the foregoing Figure 6 and includes:
[0246] A publishing unit 801 that publishes the identity identifiers of special persons, so that when the client obtains the identity identifiers of the special persons, it compares them with the user contact person list stored locally by the client to determine whether there are identity identifiers in the user contact person list that coincide with the identity identifiers of the special persons; wherein, the user contact person list includes the identity identifiers corresponding to other users whose contact distance with the user reaches a threshold;
[0247] The verification unit 802 receives the zero-knowledge proof that the user is the target tracking user generated by the client based on a preset zero-knowledge proof algorithm, verifies the zero-knowledge proof based on the zero-knowledge proof algorithm, and determines the user as the target tracking user when the verification is passed.
[0248] Among them, the tracking management platform is docked with the client.
[0249] In one embodiment, the device 800 further includes:
[0250] The receiving unit 803 receives the identity identifier of the user, and publishes the identity identifier of the user after determining that the user is the target tracking user or the special person.
[0251] In one embodiment, the special person includes an infectious disease infected person, the user includes a potential infectious disease contact, and the target tracking user includes a confirmed infectious disease contact.
[0252] In one embodiment, the identity identifier of the special person includes:
[0253] The identity identifier of the infectious disease infected person, and / or the identity identifier of the infectious disease contact.
[0254] In one embodiment, the identity identifier includes a random anonymous identifier generated by the client for the user based on a preset time period by invoking a preset generation algorithm.
[0255] In one embodiment, the device 800 further includes:
[0256] The first storage unit 804 stores the first Merkle tree and the second Merkle tree sent by the client; wherein, the first Merkle tree is constructed based on the list of identity identifiers of the users stored locally by the client; the list of identity identifiers of the users includes a set of random anonymous identifiers generated by the client of the users for the users; the second Merkle tree is constructed based on the list of user contact persons stored locally by the client;
[0257] The second storage unit 805 stores the third Merkle tree constructed based on the list of identity identifiers of the special persons; wherein, the list of identity identifiers of the special persons includes a set of random anonymous identifiers generated by the client of the special persons for the special persons.
[0258] In one embodiment, the zero-knowledge proof includes a Merkle proof;
[0259] The verification unit 802 further:
[0260] Receive the zero-knowledge proof, the root value of the second Merkle tree, and the root value of the third Merkle tree; wherein, the zero-knowledge proof includes a first Merkle proof that the identity identifier of the special person exists in the second Merkle tree, and a second Merkle proof that the identity identifier of the special person exists in the third Merkle tree; the root value of the second Merkle tree is determined based on the second Merkle tree constructed from the user contact list; the root value of the third Merkle tree is determined based on the third Merkle tree constructed from the identity identifier list of the special person.
[0261] In one embodiment, the verification unit 802 further:
[0262] Based on the received root value of the second Merkle tree and the root value of the third Merkle tree, determine whether there are pre-stored second Merkle tree and third Merkle tree;
[0263] If so, input the zero-knowledge proof, the root value of the second Merkle tree, and the root value of the third Merkle tree into the proof verification program corresponding to the preset zero-knowledge proof algorithm to verify the correctness of the zero-knowledge proof.
[0264] In one embodiment, the receiving unit 803 further:
[0265] Receive the identity identifier list of the user, and after determining that the user is a target tracking user or the special person, construct a Merkle tree based on the received identity identifier list of the user, and compare it with the pre-stored first Merkle tree;
[0266] If they are consistent, regard the user as a target tracking user or the special person, and publish the identity identifier list of the user.
[0267] In one embodiment, the client and the tracking management platform are connected to the blockchain; the first Merkle tree and the second Merkle tree published by the client are stored on the blockchain;
[0268] The device 800 further includes:
[0269] A second publishing unit 806, the tracking management platform publishes the identity identifier of the special person and the third Merkle tree to the blockchain for storage respectively.
[0270] Each embodiment in this application is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the client device embodiments and apparatus embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, reference can be made to the description of the method embodiments.
[0271] For the apparatus embodiments, since they basically correspond to the method embodiments, for the relevant parts, reference can be made to the description of the method embodiments. The apparatus embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this application. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0272] The apparatuses, devices, modules or modules illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, and the specific form of the computer can be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver device, a game console, a tablet computer, a wearable device, or a combination of any several of these devices.
[0273] Corresponding to the above method embodiments, this specification also provides an embodiment of an electronic device. The electronic device includes: a processor and a memory for storing machine-executable instructions; wherein, the processor and the memory are generally connected to each other through an internal bus. In other possible implementation manners, the device may further include an external interface to be able to communicate with other devices or components.
[0274] In this embodiment, by reading and executing the machine-executable instructions stored in the memory corresponding to the user authentication logic, the processor is caused to:
[0275] Obtain the identity identifier of a special person published by the tracking management platform;
[0276] Compare it with the list of user contact persons locally stored on the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes the identity identifiers corresponding to other users whose contact distance with the user reaches a threshold;
[0277] If it exists, generate a zero-knowledge proof that the user is the target tracking user based on a preset zero-knowledge proof algorithm, and send the zero-knowledge proof to the tracking management platform, so that the tracking management platform verifies the zero-knowledge proof based on the zero-knowledge proof algorithm, and determines the user as the target tracking user when the verification passes.
[0278] Corresponding to the above method embodiments, this specification also provides an embodiment of another electronic device. The electronic device includes: a processor and a memory for storing machine-executable instructions; wherein, the processor and the memory are generally interconnected through an internal bus. In other possible implementation manners, the device may further include an external interface to be able to communicate with other devices or components.
[0279] In this embodiment, by reading and executing the machine-executable instructions stored in the memory corresponding to the user authentication logic, the processor is prompted to:
[0280] Publish the identity identifier of a special person, so that when the client obtains the identity identifier of the special person, it compares it with the list of user contact persons stored locally by the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes the identity identifiers corresponding to other users whose contact distance with the user reaches a threshold.
[0281] Receive the zero-knowledge proof that the user is the target tracking user generated by the client based on a preset zero-knowledge proof algorithm, verify the zero-knowledge proof based on the zero-knowledge proof algorithm, and determine the user as the target tracking user when the verification passes.
[0282] Corresponding to the above method embodiments, an embodiment of this specification also provides a computer-readable storage medium, on which a computer program is stored. When these computer programs are run by a processor, they execute the various steps of the user tracking method based on zero-knowledge proof in the embodiments of this specification. For a detailed description of the various steps of the above user tracking method based on zero-knowledge proof, please refer to the previous content and will not be repeated.
[0283] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0284] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.
[0285] A computer-readable medium includes both permanent and non-permanent, removable and non-removable media and can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data.
[0286] Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information accessible by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0287] Those skilled in the art will appreciate that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, the embodiments of this specification can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.
[0288] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of this application. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include known common knowledge or conventional technical means in this technical field that are not disclosed in this application. The specification and examples are only to be considered as exemplary, and the true scope and spirit of this application are pointed out by the following claims.
[0289] It should be understood that this application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is only limited by the appended claims.
[0290] The above are only the preferred embodiments of this application and are not intended to limit this application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application shall be included within the scope of protection of this application.
Claims
1. A user tracking method based on zero - knowledge proof, which is applied to a client, and the client is connected to a tracking management platform; the method includes: Obtain the identity identifier of the special person released by the tracking management platform; Compare it with the list of user contact persons stored locally on the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes the identity identifiers corresponding to other users whose contact distance with the user reaches a threshold; the identity identifier includes a random anonymous identifier generated by invoking a preset generation algorithm; If there is, input the list of user contact persons, the list of identity identifiers of the special person, the second Merkle tree constructed based on the list of user contact persons, and the third Merkle tree constructed based on the list of identity identifiers of the special person into the proof generation program corresponding to the preset zero-knowledge proof algorithm to generate a zero-knowledge proof that the user is the target tracking user, and send the zero-knowledge proof to the tracking management platform, so that the tracking management platform verifies the zero-knowledge proof based on the zero-knowledge proof algorithm, and determines the user as the target tracking user when the verification passes.
2. The method according to claim 1, the method further includes: Send the identity identifier of the user to the tracking management platform, so that the tracking management platform publishes the identity identifier of the user after determining that the user is the target tracking user or the special person.
3. The method according to claim 1, where the special personnel include infectious disease patients, the users include potential infectious disease contacts, and the target tracked users include confirmed infectious disease contacts.
4. The method according to claim 3, the identity identifier of the special personnel includes: The identity identifier of the infectious disease infected person, and / or the identity identifier of the infectious disease contact person.
5. The method according to claim 1, the identity identifier includes a random anonymous identifier generated by the client for the user based on a preset time period by invoking a preset generation algorithm.
6. The method according to claim 1, the method further includes: The client establishes communication with the clients of other users through short-range wireless communication technology; Receive the identity identifiers of other users sent by the clients of other users; When the contact distance between the user and the other user is within the preset first distance threshold range, add the identity identifier of the other user to the list of user contact persons stored locally on the client; Or, When the contact distance between the user and the other user is within the preset second distance threshold range and the contact duration reaches the preset time threshold, add the identity identifier of the other user to the list of user contact persons stored locally on the client; wherein, the first distance threshold is less than the second distance threshold.
7. The method according to claim 6, the method further includes: The client sends the identity identifier of the user to the client of the other user, so that the client of the other user determines whether to store the identity identifier of the user based on the contact distance between the user and the other user.
8. The method according to claim 1, the method further includes: Construct a first Merkle tree based on the list of identity identifiers of the user stored locally on the client; wherein, the list of identity identifiers of the user includes a set of random anonymous identifiers generated by the client of the user for the user; Construct the second Merkle tree based on the list of user contact persons stored locally on the client; Send the first Merkle tree and the second Merkle tree to the tracking management platform for storage; wherein, the tracking management platform also stores the third Merkle tree constructed based on the list of identity identifiers of the special person; the list of identity identifiers of the special person includes a set of random anonymous identifiers generated by the client of the special person for the special person.
9. The method according to claim 8, the zero - knowledge proof includes a Merkle proof; the zero - knowledge proof includes a first Merkle proof that the identity identifier of the special personnel exists in the second Merkle tree, and a second Merkle proof that the identity identifier of the special personnel exists in the third Merkle tree; Sending the zero-knowledge proof to the tracking management platform includes: Determining the root value of the second Merkle tree constructed based on the user contact person list; Determining the root value of the third Merkle tree constructed based on the identity identifier list of the special persons; Sending the zero-knowledge proof, the root value of the second Merkle tree, and the root value of the third Merkle tree to the tracking management platform.
10. The method according to claim 8 or 9, wherein the client and the tracking management platform are connected to a blockchain; the identity identifier of the special personnel issued by the tracking management platform and the third Merkle tree are stored on the blockchain. The method further includes: The client publishes the first Merkle tree and the second Merkle tree to the blockchain for evidence storage respectively, so that the tracking management platform can obtain the first Merkle tree and the second Merkle tree from the blockchain.
11. A user tracking method based on zero-knowledge proof, which is applied to a tracking management platform that is connected to a client; the method includes: Publishing the identity identifiers of the special persons, so that when the client obtains the identity identifiers of the special persons, it compares them with the user contact person list stored locally by the client to determine whether there are identity identifiers in the user contact person list that coincide with the identity identifiers of the special persons; wherein, the user contact person list includes identity identifiers corresponding to other users whose contact distance with the user reaches the threshold; the identity identifier includes a random anonymous identifier generated by invoking a preset generation algorithm; Receiving the zero-knowledge proof that the user is the target tracking user sent by the client; wherein, the zero-knowledge proof is a zero-knowledge proof generated by the client inputting the user contact person list, the identity identifier list of the special persons, the second Merkle tree constructed based on the user contact person list, and the third Merkle tree constructed based on the identity identifier list of the special persons into a proof generation program corresponding to a preset zero-knowledge proof algorithm; Verifying the zero-knowledge proof based on the zero-knowledge proof algorithm, and determining the user as the target tracking user when the verification passes.
12. The method according to claim 11, wherein the method further includes: Receiving the identity identifier of the user, and publishing the identity identifier of the user after determining that the user is the target tracking user or the special person.
13. The method according to claim 11, wherein the special personnel include infectious disease patients, the users include potential infectious disease contacts, and the target tracking users include confirmed infectious disease contacts.
14. The method according to claim 13, wherein the identity identifier of the special personnel includes: The identity identifier of the infectious disease infected person, and / or the identity identifier of the infectious disease contact person.
15. The method according to claim 11, wherein the identity identifier includes a random anonymous identifier generated by the client for the user based on a preset time period by invoking a preset generation algorithm.
16. The method according to claim 12, wherein the method further includes: Storing the first Merkle tree and the second Merkle tree sent by the client; wherein, the first Merkle tree is constructed based on the identity identifier list of the user stored locally by the client; the identity identifier list of the user includes a set of random anonymous identifiers generated by the client of the user for the user; the second Merkle tree is constructed based on the user contact person list stored locally by the client; Storing the third Merkle tree constructed based on the identity identifier list of the special persons; wherein, the identity identifier list of the special persons includes a set of random anonymous identifiers generated by the client of the special persons for the special persons.
17. The method according to claim 16, wherein the zero-knowledge proof includes a Merkle proof; the zero-knowledge proof includes a first Merkle proof that the identity identifier of the special personnel exists in the second Merkle tree and a second Merkle proof that the identity identifier of the special personnel exists in the third Merkle tree; The receiving of the zero-knowledge proof that the user sent by the client is a target tracking user includes: Receiving the zero-knowledge proof, the root value of the second Merkle tree, and the root value of the third Merkle tree; wherein, the root value of the second Merkle tree is determined based on the second Merkle tree constructed based on the user contact person list; the root value of the third Merkle tree is determined based on the third Merkle tree constructed based on the identity identifier list of the special persons.
18. The method according to claim 17, wherein verifying the zero-knowledge proof based on the zero-knowledge proof algorithm includes: Based on the received root values of the second Merkle tree and the third Merkle tree, determine whether the second Merkle tree and the third Merkle tree are pre-stored; If they exist, input the zero-knowledge proof, the root value of the second Merkle tree, and the root value of the third Merkle tree into the proof verification program corresponding to the preset zero-knowledge proof algorithm to verify the correctness of the zero-knowledge proof.
19. The method according to claim 16, wherein receiving the identity identifier of the user, and after determining that the user is a target tracking user or the special person, publishing the identity identifier of the user includes: Receive the list of user identity identifiers. After determining that the user is a target tracking user or the special person, construct a Merkle tree based on the received list of user identity identifiers and compare it with the pre-stored first Merkle tree; If they are consistent, regard the user as the target tracking user or the special person and publish the list of user identity identifiers.
20. The method according to any one of claims 16-19, wherein the client and the tracking management platform are connected to a blockchain; the first Merkle tree and the second Merkle tree published by the client are stored on the blockchain; The method further includes: The tracking management platform publishes the identity identifier of the special person and the third Merkle tree to the blockchain for evidence storage respectively.
21. A user tracking device based on zero-knowledge proof, which is applied to a client, and the client is connected to a tracking management platform; the device includes: An acquisition unit acquires the identity identifier of the special person published by the tracking management platform; A comparison unit compares it with the list of user contact persons locally stored on the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes identity identifiers corresponding to other users whose contact distance with the user reaches a threshold; the identity identifier includes a random anonymous identifier generated by invoking a preset generation algorithm; A generation unit, if there is a coincidence, inputs the list of user contact persons, the list of identity identifiers of the special person, the second Merkle tree constructed based on the list of user contact persons, and the third Merkle tree constructed based on the list of identity identifiers of the special person into the proof generation program corresponding to the preset zero-knowledge proof algorithm to generate a zero-knowledge proof that the user is a target tracking user, and sends the zero-knowledge proof to the tracking management platform, so that the tracking management platform verifies the zero-knowledge proof based on the zero-knowledge proof algorithm and determines the user as a target tracking user when the verification passes.
22. A user tracking device based on zero-knowledge proof, which is applied to a tracking management platform, and the tracking management platform is connected to a client; the device includes: A publishing unit publishes the identity identifier of the special person, so that when the client acquires the identity identifier of the special person, it compares it with the list of user contact persons locally stored on the client to determine whether there is an identity identifier in the list of user contact persons that coincides with the identity identifier of the special person; wherein, the list of user contact persons includes identity identifiers corresponding to other users whose contact distance with the user reaches a threshold; the identity identifier includes a random anonymous identifier generated by invoking a preset generation algorithm; A verification unit that receives the zero-knowledge proof sent by the client that the user is the target tracking user; wherein, the zero-knowledge proof is generated by the client inputting the user contact list, the identity identifier list of the special personnel, the second Merkle tree constructed based on the user contact list, and the third Merkle tree constructed based on the identity identifier list of the special personnel into a proof generation program corresponding to a preset zero-knowledge proof algorithm; verifies the zero-knowledge proof based on the zero-knowledge proof algorithm, and determines the user as the target tracking user when the verification is passed.
23. A computer-readable storage medium, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method according to any one of claims 1-20 are implemented.
24. An electronic device, including: A processor; A memory for storing processor-executable instructions; Wherein, the processor realizes the method according to any one of claims 1-20 by running the executable instructions.
Citation Information
Patent Citations
Close contact person judgment method and device
CN111711925A
Epidemic prevention and control method and device, electronic equipment and storage medium
CN112382400A