Method and apparatus for data validation

By encoding the function information of arithmetic circuits and using interactive verification protocols, and leveraging polynomial commitment and summation verification protocols, the problem of low efficiency in verifying computation results in multi-party collaborations is solved, achieving efficient and verifiable computation.

CN114676464BActive Publication Date: 2026-06-05ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
Filing Date
2022-02-11
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

Existing technologies struggle to efficiently verify the correctness of calculation results in collaborative data analysis and processing involving multiple parties, resulting in low verifiable computational efficiency.

Method used

By obtaining the function information of the target arithmetic circuit, and using polynomial commitment and summation proof protocols, we encode one round of the execution process of the arithmetic circuit to prove the correctness of the calculation result.

Benefits of technology

It enables efficient verification of the correctness of calculation results with low computational overhead, thus improving the efficiency of verifiable computation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114676464B_ABST
    Figure CN114676464B_ABST
Patent Text Reader

Abstract

The embodiments of the present specification provide a data verification method and device. According to the method, a computing device first acquires function information of a target function group of a target arithmetic circuit, wherein the target arithmetic circuit is used to perform a target computing task instructed by a verification device, and the target function group is used to describe a circuit structure of the target arithmetic circuit. The computing device determines a first function according to a current computing process of the target computing task, wherein the first function is used to describe input and output values of each gate in the target arithmetic circuit in the current computing process. Then, the computing device proves that the first function satisfies a plurality of preset constraint relationships by performing an interactive argument protocol with the verification device, thereby proving the correctness of the current computing process, wherein the plurality of constraint relationships include a constraint relationship between the first function and the function information of the target function group.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to one or more embodiments in the field of secure data computing, and more particularly to methods and apparatus for data verification. Background Technology

[0002] In collaborative data analysis scenarios involving multiple parties, data security and privacy protection are receiving increasing attention. Privacy-preserving computation is a technology that resolves the conflict between data privacy and data value extraction. Verifiable computation technology guarantees the correctness of privacy-preserving computation, meaning that it ensures that a participant V can publicly verify that the computation result returned by another participant P is "according to the prior requirements of both parties and is indeed calculated by P (not an incorrect value)," and that the cost of verification for V is far less than the cost of its own computation.

[0003] Verifiable computing technology is widely used in distributed scenarios such as blockchain and privacy-preserving machine learning. For example, to address the computational bottleneck of blockchain smart contracts, blockchain nodes can migrate the computational tasks corresponding to smart contracts to untrusted off-chain computing nodes. After completing the computational task, the off-chain computing node generates a proof of the computation's correctness and submits the computation result and proof to the node device. Based on the proof, the node device efficiently verifies the correctness of the computation result. Through verifiable computing technology, the computational workload of resource-constrained smart contracts is effectively transferred to off-chain computing nodes with more computational resources.

[0004] Therefore, we hope to provide an improved solution that can more efficiently verify the correctness of calculation results, thereby improving the efficiency of verifiable calculations. Summary of the Invention

[0005] This specification describes one or more embodiments of a data verification method and apparatus that can efficiently prove and verify the correctness of calculation results, thereby improving the efficiency of verifiable calculations.

[0006] According to the first aspect, a method for data verification is provided, performed via a computing device, comprising:

[0007] Obtain function information of the target function group of the target arithmetic circuit, wherein the target arithmetic circuit is used to execute the target calculation task indicated by the verification device, and the target function group is used to describe the circuit structure of the target arithmetic circuit;

[0008] Based on the current calculation process of the target calculation task, a first function is determined. The first function is used to describe the input and output values ​​of each gate in the target arithmetic circuit during the current calculation process.

[0009] By executing an interactive verification protocol with the verification device, the first function is proven to satisfy several preset constraints, thereby proving the correctness of the current calculation process. The constraints include the constraints between the function information of the first function and the target function group.

[0010] In one implementation, the input to the first function is a 1-bit encoded string, the 1 bit comprising a first bit group and a second bit group, the first bit group indicating a gate number or circuit input number, and the second bit group indicating a gate input / output port or circuit input port.

[0011] In one implementation, the target function group includes a second function and a third function, wherein the second function is used to encode the gate type of each gate in the target arithmetic circuit; and the third function is used to encode the connection relationship of each wire in the target arithmetic circuit.

[0012] According to one embodiment, the target arithmetic circuit includes a first wire corresponding to a plurality of encoded strings, which form a set of encoded strings; the third function satisfies that the function value for the first encoded string is equal to the mapping value of a predefined mapping function for the second encoded string, wherein the first and second encoded strings are obtained by iterating through the set of encoded strings.

[0013] According to one embodiment, obtaining function information of the target function group of the target arithmetic circuit specifically includes: generating the target arithmetic circuit according to the target computation task, and determining the function information of the target function group according to the circuit structure of the target arithmetic circuit.

[0014] According to another embodiment, obtaining the function information of the target function group of the target arithmetic circuit includes: obtaining the function information of the target function group pre-sent by the verification device.

[0015] Furthermore, the function information of the aforementioned objective function group may include a second commitment value and a third commitment value, wherein the second commitment value is a commitment value calculated using a polynomial commitment protocol for a second polynomial corresponding to the second function; and the third commitment value is a commitment value calculated using a polynomial commitment protocol for a third polynomial corresponding to the third function.

[0016] In one implementation, the plurality of constraint relationships include a first constraint relationship characterizing the relationship between the inputs and outputs of each gate, which is expressed as a first equation formed by operations between the first function and the second function; correspondingly, proving that the first function satisfies a plurality of preset constraint relationships includes:

[0017] Based on the first polynomial and the second polynomial corresponding to the first function and the second function respectively, the first equation is rewritten as a form in which the summation of the first combined polynomial is 0.

[0018] Achieve first challenge count;

[0019] The verification device invokes a summation proof protocol to verify whether the calculated value obtained by substituting the first challenge number into the first combined polynomial is 0.

[0020] In one implementation, the plurality of constraint relationships includes a second constraint relationship, which indicates the consistency between the first function and the fourth function when the first bit group indicates the input number of the circuit. The fourth function is held by the verification device and is used to describe the input values ​​of each input port of the target arithmetic circuit in this round of calculation. Correspondingly, proving that the first function satisfies a plurality of preset constraint relationships includes:

[0021] Obtain the second challenge number;

[0022] The verification device invokes a polynomial commitment protocol to prove that substituting the second challenge number into the calculated value of the first polynomial is equal to substituting it into the calculated value of the fourth polynomial, wherein the first polynomial is an extension polynomial of the first function, and the fourth polynomial is an extension polynomial of the fourth function.

[0023] In one embodiment, the plurality of constraint relationships includes a third constraint relationship characterizing the equality of the values ​​at both ends of the conductor, the third constraint relationship being expressed as a third equation formed by mapping function operations between the first function and the third function; correspondingly, proving that the first function satisfies a plurality of preset constraint relationships includes:

[0024] Get a random array;

[0025] A ratio polynomial is determined, wherein one of the numerator and denominator polynomials is obtained based on the random array, the first polynomial corresponding to the first function, and the third polynomial corresponding to the third function, and the other is obtained based on the random array, the first polynomial, and the mapping polynomial corresponding to the mapping function;

[0026] The difference polynomial is obtained by determining the difference between the product of the ratio polynomial and the denominator polynomial and the numerator polynomial.

[0027] According to the third equation, the verification device invokes the summation proof protocol to prove that the product of the ratio polynomial with respect to all inputs is 1; and to prove that the product of the difference polynomial with respect to any input is 0.

[0028] Furthermore, in one embodiment, proving that the product of the ratio polynomial over all inputs is 1 specifically includes: obtaining a value vector and a value function describing the value vector based on the evaluation of the ratio polynomial over all inputs; determining an auxiliary function based on the iterative relationship of multiplying the values ​​using the value function as the iterative basis, such that the function value of the auxiliary function for a specific input is the product of all elements of the value vector; calling a polynomial commitment protocol with the verification device to verify whether the evaluation of the auxiliary polynomial corresponding to the auxiliary function for the specific input is 1; rewriting the iterative relationship into a form where the summation of the second combination polynomial is 0; obtaining a third challenge number; and calling a summation proof protocol with the verification device to verify whether the calculated value obtained by substituting the third challenge number into the summation of the second combination polynomial is 0.

[0029] In one embodiment, proving that the difference polynomial evaluates to 0 for any input specifically includes: rewriting the assumption that the difference polynomial evaluates to 0 for any input into a form where the summation of the third combination polynomial is 0; obtaining a fourth challenge number; and calling a summation proof protocol with the verification device to verify whether the calculated value obtained by substituting the fourth challenge number into the summation of the third combination polynomial is 0.

[0030] In one implementation, the constraint relationships include a fourth constraint relationship, which indicates that the output of the final output gate of the target arithmetic circuit is a preset value; correspondingly, proving that the first function satisfies the preset constraint relationships includes:

[0031] Determine the gate number of the final output gate, and combine the gate number with the second bit group indicating the gate output port to form the target input value;

[0032] The verification device invokes a polynomial commitment protocol to prove that the result of substituting the target input value into the first polynomial corresponding to the first function is the preset value.

[0033] In one scenario, the verification device is a node device in the blockchain, the computing device is an off-chain computing device, and the target computing task corresponds to the contract logic of a smart contract in the blockchain.

[0034] In another scenario, the verification device is a participant in privacy-preserving federated learning; the target computation task corresponds to model computation.

[0035] According to the second aspect, a data verification apparatus is provided, deployed in a computing device, comprising:

[0036] The acquisition unit is configured to acquire function information of the target function group of the target arithmetic circuit, wherein the target arithmetic circuit is used to execute the target calculation task indicated by the verification device, and the target function group is used to describe the circuit structure of the target arithmetic circuit.

[0037] The determining unit is configured to determine a first function based on the current round of calculation of the target calculation task, wherein the first function is used to describe the input and output values ​​of each gate in the target arithmetic circuit during the current round of calculation.

[0038] The proof unit is configured to prove that the first function satisfies several preset constraints by executing an interactive proof protocol with the verification device, thereby proving the correctness of the current calculation process, wherein the several constraints include the constraint relationship between the function information of the first function and the target function group.

[0039] According to a third aspect, a computing device is provided, including a memory and a processor, characterized in that the memory stores executable code, and when the processor executes the executable code, it implements the method of the first aspect.

[0040] According to the methods and apparatus provided in the embodiments of this specification, one round of execution of an arithmetic circuit is encoded using a multivariate single function, the number of which is only the size of the arithmetic circuit plus a small constant. Based on this, a computing device can utilize polynomial commitment and summation proof protocols to prove the correctness of computational results to a verification device with low computational overhead, thereby achieving efficient and verifiable computation. Attached Figure Description

[0041] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0042] Figure 1 A schematic diagram illustrating verifiable calculations performed by both parties according to one embodiment is shown;

[0043] Figure 2 This illustrates an example of encoding arithmetic circuits as function representations;

[0044] Figure 3 This illustrates a data verification method according to one embodiment;

[0045] Figure 4 The flowchart illustrates the steps of a computing device to prove a first constraint relationship according to one embodiment;

[0046] Figure 5 This illustrates the steps of a computing device to prove a third constraint relationship according to one embodiment;

[0047] Figure 6 A schematic diagram of a data verification apparatus according to one embodiment is shown. Detailed Implementation

[0048] The solution provided in this specification will now be described with reference to the accompanying drawings.

[0049] As mentioned earlier, for the sake of privacy protection and data security, in scenarios where multiple parties jointly conduct data analysis and processing, verifiable computation methods are adopted to ensure the correctness of privacy-preserving computations.

[0050] Figure 1 A schematic diagram illustrating verifiable calculations performed by both parties according to one embodiment is shown. Figure 1 In the example, the two parties performing the verifiable computation are denoted as the computing device and the verifying device. The verifying device can delegate a specific computational task T (or computational logic) to the computing device for computation. In one round of computation, after the computing device executes the computational task based on the input data of this round and obtains the computational result, it generates a result proof. This result proof allows the verifying device to verify that the computational result is indeed the correct result obtained by executing the above computational task for the input data of this round. Thus, the computing device acts as the prover (Prover), denoted as device Pr; and the verifying device acts as the verifier (Verifier), denoted as device Ve.

[0051] In a specific scenario example, the verification device Ve can be a node device on the blockchain, the computing device Pr can be an off-chain computing device, such as a computing platform or computing cluster, and the delegated computing task can be the contract logic of a smart contract in the blockchain. The input data in a round of computing can be the input parameters specified in a transaction that calls the smart contract.

[0052] For example, the verification device Ve can be a participant in privacy-preserving federated learning, holding the privacy data required for model training or prediction. This privacy data can be the privacy data of samples, such as user personal information, user facial images, or model privacy data composed of model parameters. The computing device Pr can be another participant, or a computing platform or cluster outside of the participants. To protect privacy, the verification device Ve can encrypt its privacy data and delegate homomorphic operations to the computing device Pr based on the encrypted data. The delegated computing task can be a homomorphic operation corresponding to the model computation during the model training or prediction process.

[0053] In other scenarios, the verification device Ve and the computing device Pr can also perform other scenario-specific functions, which will not be listed here. The specific implementation methods of the verification device Ve and the computing device Pr are not limited here.

[0054] To achieve the verifiable computation process described above, in the preparation phase, the computation task T is first converted into the form of an arithmetic circuit C. This conversion process can be performed by the verification device Ve, or jointly by the verification device and the computation device Pr. The resulting arithmetic circuit C can be considered as a logic circuit used to execute the computation task T. This circuit consists of several interconnected basic arithmetic gates, which can include multiplication gates, addition gates, and other gates that perform basic arithmetic operations. After determining the arithmetic circuit C, a circuit structure description function can be constructed. This function is used to encode and describe the circuit structure of the arithmetic circuit C, such as the number and type of gates, and the circuit connection relationships.

[0055] In one round of computation, the computing device Pr performs the computation using the arithmetic circuit C based on the input data of that round. The computation function for that round is determined based on the input and output values ​​of each gate in the arithmetic circuit C during that round of computation. In the embodiments of this specification, the input and output values ​​of each gate in the encoding circuit are used as a single function (the computation function for that round).

[0056] Then, the computing device Pr and the verification device Ve execute an interactive verification protocol, thereby proving to Ve that the computation function and the circuit structure description function in this round conform to predetermined constraints. These constraints may include at least a portion of gate constraints, wire constraints, input constraints, and output constraints. When the verification device Ve confirms that the above constraints are satisfied, it can determine that the computation result in this round is the correct result of the computing device Pr performing the agreed computation task on the input data in this round, thus realizing a verifiable computation process.

[0057] The encoding process of the arithmetic circuit C is described below.

[0058] It can be understood that for any computational task T, the process of mapping input data D to output y can be represented by a function f, i.e., y = f(D). Furthermore, this process can be converted into another function g, such that g(D, y) returns a preset value, typically 1. Converting the process of function g into arithmetic logic yields the corresponding arithmetic circuit C, where C(D, y) = 1.

[0059] In one embodiment, the verification device Ve converts the computational task T it wishes to delegate into an arithmetic circuit C and sends the circuit structure information of the arithmetic circuit C to the computing device Pr. Alternatively, the verification device Ve sends the computational task T to the computing device Pr, and both devices use an agreed-upon circuit conversion algorithm to convert the computational task T into a common arithmetic circuit C, thereby obtaining the circuit structure information for both devices.

[0060] Assuming the number of arithmetic gates in the converted arithmetic circuit is |C| and the number of circuit inputs is |I|, let m = log₂|C| and k = log₂|I|. Then, an m-bit string can uniquely represent a gate, and a k-bit string can uniquely represent a circuit input. Based on this, a l-bit string can represent a wire or an input in the circuit. This l-bit string can be divided into a first bit group and a second bit group. The first bit group indicates the gate number or circuit input number. Therefore, the number of bits in the first bit group can be the larger of the aforementioned m-bit and k-bit strings, i.e. The second bit group is used to indicate the gate's input / output port or the circuit's input port.

[0061] Following the method described above for encoding wires in a circuit as 1 bit, the first function can be defined as follows: As a round of computation function, the function input u:{0,1} l This refers to the aforementioned 1-bit representation of the wire. The function output value is the calculated value of this wire in one round of calculation, which belongs to a finite field. (Decimal). Therefore, the first function can be used to characterize the mapping between each wire in the circuit and its calculated value in a round of computation, that is, to describe the input and output values ​​of each gate in a round of computation.

[0062] In one embodiment, the second bit group is set to 2 bits. In this case, various values ​​of a 2-bit bit array can be used to indicate different ports of the gate / circuit. Specifically, in one example, 00 represents the left input port of the gate; 01 represents the right input port; 10 represents the output port; and 11 represents the input port. Correspondingly, in a specific example, the first function P mentioned above can specifically include the following form:

[0063] Describe the left input value of the gate with number x (represented in m bits);

[0064] Describe the right input value for the door with number x;

[0065] Describe the output value of the gate with number x;

[0066] Describe the circuit input value numbered z (represented by k bits).

[0067] 0 in the above formula l-m-2 / 0 l-k-2 This indicates the number of zeros that may need to be added when m and k are not equal.

[0068] It should be understood and explained that the second bit group above can also use other bit numbers to identify different ports; when using 2 bits to identify ports, other correspondences different from the above examples can also be used for identification, such as using 01 and 10 to identify the right and left input ports of the gate respectively, and using 11 to represent the output port of the gate, etc., without limitation here.

[0069] Thus, based on the number of gates and the number of circuit inputs in the arithmetic circuit C, l can be determined. The wires in the circuit are represented by a string of l bits. The input and output values ​​of each gate in the circuit in one round of calculation are described by a single mapping function P.

[0070] Furthermore, a second function S can be defined to encode the gate types of each gate in the arithmetic circuit C. In one embodiment, the arithmetic circuit is limited to containing only two gate types: addition gates and multiplication gates. Other computations can be decomposed into combinations of addition and multiplication. In this case, the second function S can be expressed as: S:{0,1} m →{0,1}, which maps the m-bit encoded gate numbers to two gate types represented by 0 and 1. More specifically, the second function S can be expressed as:

[0071] S(x)→0, x∈{0,1} m : This indicates that the gate with the number x (represented by m bits) is an addition gate;

[0072] S(x)→1, x∈{0,1} m : indicates that the gate with the number x (represented in m bits) is a multiplication gate.

[0073] Based on the circuit structure of arithmetic circuit C, a third function can also be defined. u:{0,1} l This function is used to encode the connection relationships of various wires in an arithmetic circuit C. As mentioned earlier, when defining the first function, a 1-bit string u represents a wire in the circuit. It's important to note that, according to the 1-bit encoding method described above, the same wire can have multiple encoded strings. For example, if the output of gate A is the input of gate B, then encoded string a can be obtained from the output of gate A, and encoded string b can be obtained from the input of gate B. Based on this, the third function W can be used to describe the connection relationships of wires, that is, to limit the connection relationships by specifying that wires with different numbers (encoded strings) are essentially the same wire, or to limit the connection relationships by specifying that the values ​​at both ends of the same wire are equal.

[0074] In one embodiment, a mapping function H can be introduced to map an 1-bit encoded string to its decimal representation. This mapping function serves as an aid in defining a third function. Specifically, assuming an arithmetic circuit C contains a wire, based on the wire's various connections within the circuit, the wire can be determined to have multiple encoded strings {u1, u2, ..., un}, forming a set of encoded strings, where each encoded string is an 1-bit string. To describe the wire connection relationships, the third function W can be defined as follows: the function value for the first encoded string in the set is equal to the mapping value of the mapping function H for the second encoded string, where the first and second encoded strings are obtained by iteratively traversing the set. This iterative traversal means that every encoded string in the set should be traversed, and each encoded string serves as both the first and second encoded strings. For example, suppose a wire has a set of encoded strings formed by three encoded strings {a, b, c}. Then the encoding of the third function W must satisfy: W(a)=H(b), W(b)=H(c), W(c)=H(a).

[0075] In addition, a fourth function V can be defined to describe the input values ​​of each input port of the circuit in a round of calculation.

[0076] Specifically, the fourth function V can be expressed as:

[0077] This represents the input value of the circuit input port numbered z (in k bits).

[0078] The following example of a specific circuit illustrates the specific encoding format of each of the above functions.

[0079] Figure 2 An example of encoding an arithmetic circuit as a function representation is shown. Figure 2 The upper part shows an example of an arithmetic circuit C, which consists of addition and multiplication gates connected together. Specifically, the circuit contains four gates (g0-g3) and four circuit inputs (i0-i3). d0-d3 represent the input values ​​corresponding to the four circuit inputs in a certain round of operation. Therefore, the number of arithmetic gates |C| = 4, the number of circuit inputs |I| = 4, so m = 2, k = 2, and with the second bit group taking 2 bits, l = max{m+2,k+2} = 4.

[0080] Figure 2 The lower half shows the function encoded for the above circuit.

[0081] Specifically, box 10 shows the function representation of the first function P. For example, according to the aforementioned encoding rules of the first function P for the gate ports, P(00,g0) represents the value of the left input port of the gate numbered g0, therefore, P(00,g0) = d0; similarly, P(01,g0) represents the value of the right input port of the gate numbered g0, therefore, P(01,g0) = d1. Thus, the above function encoding can be performed for the input / output ports of each gate in the circuit. For the circuit input port, as mentioned above, when the second bit group is 11, it represents the circuit input; therefore, P(11,i0) represents the value of the circuit input port numbered i0, therefore, P(11,i0) = d0. Thus, the above function encoding can be performed for each input port in the circuit. In this way, the first function P is encoded as a series of equations to represent the input and output values ​​of each gate in one round of calculation.

[0082] Box 20 shows the encoding form of the second function S. In box 20, 1 and 0 are used to represent multiplication gates and addition gates, respectively. Thus, S(g0) = 1 indicates that the gate numbered g0 is a multiplication gate, S(g1) = 0 indicates that the gate numbered g1 is an addition gate, and so on. In this way, the gate type of each gate in circuit C is described by the second function S.

[0083] Box 30 shows the encoding form of the third function W. Here, a mapping function H is used as an auxiliary to iteratively construct the relationship between the third function and the mapping function for different encoded strings of the same conductor.

[0084] For example, the wire corresponding to circuit input i0 also serves as the left input of gate g0. When used as the left input of gate g0, this wire can be encoded as the first encoded string (00, g0), and when used as a circuit input, it can be encoded as the second encoded string (11, i0). Thus, the relationship between the third function W and the mapping function H can be constructed iteratively for these two encoded strings: W(00, g0) = H(11, i0); W(11, i0) = H(00, g0).

[0085] For example, the wire corresponding to circuit input i1 serves as both the right-hand input of gate g0 and the left-hand input of gate g1. Therefore, for this wire, three encoded strings can be obtained: (01, g0), (11, i1), and (00, g1). The relationship between the third function W and the mapping function H can be constructed iteratively from these three encoded strings, resulting in:

[0086] W(01,g0)=H(11,i1); W(11,i1)=H(00,g1); W(00,g1)=H(01,g0)

[0087] Thus, the connection relationship of each wire in circuit C is described by the third function W.

[0088] Furthermore, box 40 shows the encoded form of the fourth function V, which describes the input values ​​of each circuit input port in a round of calculation.

[0089] The above defines several functions for the arithmetic circuit C and its calculation process. The second function S and the third function W are determined based on the circuit structure, while the first function P and the fourth function V are determined for a single round of calculation. When the arithmetic circuit C is used to perform calculations on the input data for a single round, as agreed upon, these functions will satisfy several circuit-related constraints.

[0090] These multiple constraints include gate constraints, which characterize the constraints between the inputs and outputs of each gate. Specifically, if the gate type is an addition gate, it should satisfy the condition that the left input + right input = output value; if the gate type is a multiplication gate, it should satisfy the condition that the left input multiplied by the right input equals the output value. This constraint relationship can be expressed as:

[0091]

[0092] S(x)·(P(00,0 l-m-2 ,x)·P(01,0 l-m-2 ,x))+(1-S(x))·(P(00,0 l-m-2 ,x)+P(01,0 l -m-2 ,x))=P(10,0 l-m-2 ,x) (1)

[0093] That is, the gate constraint relationship can be expressed as an equation formed by operations between the first function P and the second function S.

[0094] The circuit-related constraints mentioned above can also include input constraints, used to ensure that any input in a round of calculation is consistent in the first function P and the fourth function V. This constraint can be expressed as:

[0095]

[0096] The input constraint relationship can be expressed as the equality relationship between the first function P and the fourth function V for a specific input.

[0097] Furthermore, the aforementioned constraints also include wire constraints, used to ensure that the values ​​at both ends of each wire in the circuit are equal. For any wire in the circuit, assuming that there are at least two encoded strings, u and v, based on the connection at both ends, then according to the principle of equal values ​​at both ends of the wire, P(u) = P(v). And according to the encoding method of the aforementioned third function W, we have W(u) = H(v), therefore, Among them, H -1This represents the inverse operation function of the mapping function H. This indicates that further function operations are applied. Therefore, the wire constraint relationship can be expressed as:

[0098]

[0099] Therefore, the wire constraint relationship can be expressed as an equation formed by the mapping function H between the first function P and the third function W.

[0100] Furthermore, if the first function P represents the correct computation process, then the following output constraint relationship should also be satisfied:

[0101] P(10,0 l-m-2 ,o)=1 (4)

[0102] In equation (4), “o” represents the number of the final output gate of the circuit. According to the previous definition of circuit C: C(D, y) = 1, the output value of output gate “o” should be 1.

[0103] Based on the above description, if the computing device performs calculations using the arithmetic circuit C on a given round of input data as agreed, then the resulting functions will at least satisfy the gate constraint relationship shown in formula (1), the input constraint relationship shown in formula (2), the wire constraint relationship shown in formula (3), and the output constraint relationship shown in formula (4). Therefore, the verification device can, when necessary, selectively choose a portion or all of these constraint relationships for a given round of computation for verification, thereby determining whether the computing device has performed the calculations as agreed.

[0104] Before describing the specific verification process, a brief introduction will be given to the basic protocols and existing basic tools used in the verification.

[0105] (I) On the polynomial extension:

[0106] In some scenarios, it is often necessary to represent functions in polynomial form, a process known as polynomial extension. Specifically, suppose g: If g is a function, then the low-degree polynomial extension of function g is a low-degree polynomial with m variables. satisfy

[0107] Furthermore, the Multilinear Polynomial Extension (MLE) is proposed. The MLE is a low-degree polynomial extension whose result is a multilinear polynomial. Given a function Z: Its MLE is a unique multilinear polynomial. The calculation method is as follows here, It is a function The MLE (Mean Exceeding Expectations) can be applied to any function Z that maps an m-bit string to a finite field, resulting in a polynomial.

[0108] (II) Regarding the sum-check proof protocol:

[0109] The Sum-check proof protocol is a two-way interactive protocol used by the prover (Prover, Pr) to prove a formula to the verifier (Verifier, Ve). The expression is valid. After multiple rounds of interaction, the verification of the expression is ultimately reduced to Ve verifying G(r) = T′, where r is a value randomly selected by Ve, and T′ is the new target value. G(r) needs to be calculated by Ve or obtained by accessing an Oracle for the polynomial G.

[0110] (III) Regarding polynomial commitments:

[0111] Polynomial commitment is used by both parties to verify a polynomial, and it includes four algorithms: PC = (Setup, Commit, Open, Eval).

[0112] Setup creation algorithm: pp←Setup(1) λ ,m): Input security parameter λ, number of polynomial variables m, output public parameter pp;

[0113] Commit algorithm: (C; r) ← Commit(pp; G): Input m-variable polynomial G, output commitment C; r is the randomly selected secret value used for the commitment;

[0114] Open verification algorithm: b←Open(pp,C,G,r): Open commitment C and verify whether the polynomial of commitment C is a polynomial G;

[0115] Eval evaluation algorithm: b←Eval(pp,C,t,y,m;G,r): Proof protocol between Prover and Verifier, used by Prover to prove to Verifier G(t)=y.

[0116] Based on these fundamental protocols and tools, combined with, for example Figure 2 The circuit coding method shown enables the computing device to efficiently prove the correctness of the calculation to the verification device.

[0117] Figure 3 This illustrates a data verification method according to one embodiment, executed by a computing device. This computing device can be implemented as any apparatus, device, platform, or cluster of devices with computing and processing capabilities. The following describes... Figure 3 The specific execution process of each step shown is described in detail.

[0118] First, in step 31, the computing device obtains the function information of the target function group of the target arithmetic circuit C, wherein the target arithmetic circuit C is used to execute the target calculation task T indicated by the verification device, and the target function group is used to describe the circuit structure of the target arithmetic circuit C.

[0119] As mentioned earlier, the process of transforming the target computation task T into an arithmetic circuit C can be performed by the verification device or jointly by the verification device and the computing device. Based on the obtained arithmetic circuit C, the encoding of a set of target functions to describe the circuit structure of the arithmetic circuit C can also be performed by the verification device or jointly by both. According to the aforementioned introduction to the encoding of circuit-related functions, the set of target functions used to describe the circuit structure can include a second function S for encoding gate types and a third function W for encoding wire connection relationships.

[0120] Therefore, in one implementation, the computing device can pre-generate a target arithmetic circuit C based on the target computation task T, and determine a target function set, such as a second function S and a third function W, based on the circuit structure of the target arithmetic circuit C. This function determination process can be performed only once during the preparatory stage. Before each subsequent computation, in step 31, it is only necessary to obtain the function information of the pre-determined target function set (e.g., the second and third functions). This function information may include the encoded forms of the second function S and the third function W, or, alternatively, the polynomials obtained after MLE extension, such as the extended polynomials corresponding to the second function S, the third function W, and their associated mapping functions H.

[0121] In another embodiment, during the preparation phase, the verification device generates a target arithmetic circuit C based on the target computation task T. Based on the circuit structure of the target arithmetic circuit C, a target function set is determined, which may include, for example, a second function S, a third function W, and their associated mapping function H. In one example, the verification device may send the function encoding form of the aforementioned target function set as function information to the computation device.

[0122] In another example, the verification device further performs MLE expansion on each function of the aforementioned target function group to obtain the polynomials corresponding to each function, such as the expanded polynomials corresponding to the second function S, the third function W, and its associated mapping function H. The verification device sends the polynomials corresponding to each of the above functions as function information to the computing device. Accordingly, in step 31, the computing device can read the polynomials of each pre-received function as function information for the target function group.

[0123] In yet another example, to further reduce communication, the verification device utilizes a polynomial commitment protocol, targeting the second polynomial corresponding to the second function. The second commitment value was calculated. in, Similarly, for the third polynomial corresponding to the third function W The third commitment value was calculated. in, Understandably, since the third function W uses an auxiliary mapping function H, the verification device can also calculate the commitment value for the polynomial of the mapping function H, thus obtaining the commitment value. in, The verification device sends the polynomial commitment values ​​of each of the above functions to the computing device. Correspondingly, in step 31, the computing device can read the polynomial commitment values ​​of each function in the pre-received target function group as function information, where the commitment values ​​are calculated using the polynomial commitment protocol for the extended polynomial of the corresponding function. In some embodiments of the data verification process, the open verification algorithm in the polynomial commitment protocol can be performed based on these commitment values ​​to verify the corresponding polynomial, and then subsequent calculations can be performed based on the verified polynomial.

[0124] Thus, for each round of calculation, the computing device can obtain function information for the target function set used to describe the circuit structure.

[0125] On the other hand, the computing device needs to execute the current round of calculation for the target computing task T based on the current round input data indicated by the verification device. That is, the current round input data is used as the circuit input of the arithmetic circuit C, and the current round output is obtained through the calculation of each gate.

[0126] Based on this, in step 32, the computing device can determine a first function P according to the current round of computing process of the target computing task. The first function P is used to describe the input and output values ​​of each gate in the target arithmetic circuit C during the current round of computing.

[0127] As mentioned earlier, the encoding method of the first function P is as previously combined with... Figure 2 The above will not be repeated. Using this single function P, with a 1-bit input string as the input variable, the input / output ports of all gates in the circuit are encoded.

[0128] In one embodiment, after determining the first function P, the computing device uses MLE extension to obtain the first polynomial corresponding to the first function P. Furthermore, in one example, the computing device uses a polynomial commitment protocol to calculate a first commitment value corresponding to a first polynomial: Then the first commitment value Send to the verification device.

[0129] Based on this, in step 33, the computing device performs an interactive verification protocol with the verification device to prove that the first function P satisfies several preset constraints, thereby proving the correctness of this round of calculation; wherein the several constraints include the constraint relationship between the function information of the first function P and the target function group.

[0130] As mentioned earlier, if the computing device performs the current calculation using the arithmetic circuit C as agreed, then the resulting first function P should satisfy the aforementioned four constraint relationships: the gate constraint relationship formed with the second function as shown in formula (1), the input constraint relationship formed with the fourth function V as shown in formula (2), the wire constraint relationship formed with the third function W as shown in formula (3), and the output constraint relationship that it should satisfy as shown in formula (4). In practice, the verification device can perform data verification for each round of calculation, or it can select a certain round of calculation for data verification in a "sampling" manner. During data verification, the verification device can verify all of the above constraint relationships, or it can selectively select a portion of these constraint relationships for verification in a "sampling" manner, thereby determining whether the computing device has performed the current calculation as agreed.

[0131] The following describes the verification process for each constraint relationship.

[0132] For the gate constraint relationship shown in formula (1), in order to facilitate the subsequent use of the sum-check protocol, it can be transformed into the first polynomial corresponding to the first function P. The second polynomial corresponding to the second function S Relationship between them:

[0133]

[0134] Based on this, an intermediate function can be defined:

[0135]

[0136] Based on the above intermediate function definition relation We can see that if t∈{0,1} m ,but If the t equals 0 or 1, then Q1(t) = F(t); if but It can be regarded as a finite field The random value in the matrix. At this point, Q1(t) can be considered as a random linear combination of F(x), then if Q1(t) = 0, that is, Q1(t) is a zero polynomial, then for any x∈{0,1} m F(x) = 0. That is, equation (5) holds.

[0137] According to the Schwartz-Zippel lemma, to verify Q1(t) = 0, it is only necessary to randomly select Verify whether Q1(τ) is equal to 0. Therefore, verifying the constraint relationship in formula (1) is transformed into, using the sum-check protocol, the computing device proving to the verification device:

[0138] Figure 4 The flowchart illustrates the steps of proving a first constraint relationship using a computing device according to one embodiment. This first constraint relationship characterizes the constraint relationship between the inputs and outputs of various gates in an arithmetic circuit, i.e., a gate constraint relationship. The first constraint relationship can be expressed as a first equation formed by operations between a first function P and a second function S, for example, as shown in formula (1). Figure 4 The steps and procedures can be understood as Figure 3 The sub-step of step 33.

[0139] like Figure 4 As shown, in order to prove the above first constraint relationship, in step 41, the computing device calculates the first polynomial corresponding to the first function P and the second function S respectively. Second polynomial The first equation can be rewritten as a summation of zero over the first combinatorial polynomial. As an example, the first equation can be the relationship between the first function P and the second function S as shown in formula (1), and the first combinatorial polynomial can be the one described above. In

[0140] Then, in step 42, the computing device obtains a first challenge number τ1. In one embodiment, the verification device may randomly select this first challenge number and send it to the computing device.

[0141] Therefore, in step 43, the computing device and the verification device invoke the summation proof protocol to verify whether the calculated value obtained by substituting the first challenge number τ1 into the first combination polynomial and summing is 0, that is, to verify whether Q1(τ1) is 0. Specifically, the computing device can determine the target polynomial for verification as the aforementioned first combination polynomial: Then, both the computing device and the verification device invoke the sum-check protocol to verify. Whether it is valid or not.

[0142] Based on the foregoing explanation of the sum-check protocol, the summation result of any objective polynomial G(x) is... The verification can ultimately be reduced to the verifier verifying G(r) = T′, where r is a value randomly selected by the verifier, and T′ is the new target value. According to the standard sum-check protocol, G(r) needs to be calculated by the verifier. In the case of step 43 above, the target polynomial G(x) is the first combined polynomial mentioned above. The verification device needs to calculate And determine whether it is equal to the new target value T1, thus verifying Whether it is valid or not.

[0143] To further reduce the computational burden on the verification device, in one embodiment, in step 43 above, the computing device and the verification device utilize a polynomial commitment protocol to convert the polynomial evaluation (i.e., computation) originally performed on the verification device into a separate process. ), and then transferred to the computing device side.

[0144] Specifically, the polynomial is evaluated according to the definition of the first combinatorial polynomial. The following evaluations are involved: That is, the first random number r1 is substituted as the gate number into the second polynomial corresponding to the second function. The evaluation process involves using the first random number as the gate number, combining it with the indicator bit string corresponding to each gate port to form each input value, and then substituting it into the first polynomial corresponding to the first function. The evaluation of .

[0145] Specifically, the computing and verification devices can perform summation verification through the following process:

[0146] (1) Both the computing device and the verification device are working on the second polynomial. The evaluation algorithm in the polynomial commitment is invoked with the first random number r1. The argument is to substitute the first random number r1 as the gate number into the second polynomial. The result of the evaluation is the first value s1, that is:

[0147] (2) The computing and verification devices call the evaluation algorithm for the first polynomial and the first random number. The argument is that the first input value, formed by combining the gate number corresponding to the first random number with the indicator bit string (i.e., 00) corresponding to the left input port of the gate, is substituted into the first polynomial. The result of the evaluation is the second value s2, that is:

[0148] (3) The computing and verification devices call the evaluation algorithm for the first polynomial and the first random number. The argument is that the second input value, formed by combining the gate number corresponding to the first random number with the indicator bit string (i.e., 01) corresponding to the right port of the gate, is substituted into the first polynomial. The result of the evaluation is the third value s3, that is:

[0149] (4) The computing and verification devices call the evaluation algorithm for the first polynomial and the first random number. The argument is that the third input value, formed by combining the gate number corresponding to the first random number with the indicator bit string (i.e., 10) corresponding to the gate output port, is substituted into the first polynomial. The result of the evaluation is the fourth value s4, that is:

[0150] Next, based on the first to fourth values ​​and the form of the first combination polynomial, the verification device can easily obtain the value of the first combination polynomial for the first random number. Then, by verifying whether the calculated value is equal to the new target value T1, the verification is performed. Does it hold true? If it does, then formula (5) holds true, and the gate constraint relationship corresponding to formula (1) holds true.

[0151] As mentioned earlier, formula (2) shows the input constraint relationship, which is the constraint relationship between the first function and the fourth function. It should be noted that the fourth function also depends on the single round of calculation. Specifically, for this round of calculation, the verification device determines the input data for this round, and then the verification device can determine the fourth function V for this round based on the input data of this round.

[0152] For easier verification, formula (2) can be transformed into the first polynomial corresponding to the first function P. The fourth polynomial corresponding to the fourth function V Relationship:

[0153]

[0154] To verify formula (7), the verification device can randomly obtain a challenge number, called the second challenge number τ2, and send it to the computing device. The computing device then obtains this second challenge number. Next, the computing device and the verification device invoke the polynomial commitment protocol to prove that substituting the second challenge number into the calculated value of the first polynomial is equal to substituting it into the calculated value of the fourth polynomial.

[0155] Specifically, the computing and verification devices invoke the evaluation algorithm for the first polynomial and the second challenge number. The argument is that the input value formed by combining the circuit input number corresponding to the second challenge number τ2 with the indicator bit string (i.e., 11) corresponding to the circuit input port is substituted into the first polynomial. The result of the evaluation is the fifth value s5, which proves: Then, the verification device calculates the value of the fourth polynomial by substituting the second challenge number into it. Verify that the evaluated value is equal to the fifth value mentioned above: If they are equal, the computing device proves that the input constraints are satisfied.

[0156] For the wire constraint relationship shown in formula (3), it can be equivalently transformed into the operation between the corresponding polynomials, as shown in the following formula (8):

[0157]

[0158] However, formula (8) contains function inverse operations, which is not conducive to verification using existing protocols. Therefore, it is further evolved.

[0159] Assuming two random numbers And take any l-bit input u, The ratio polynomial L1(u) and the difference polynomial L2(u) are defined as follows:

[0160]

[0161]

[0162] Due to the cyclic relationship between the third function W and the mapping function H during encoding, it is easy to prove that the validity of formula (8) is equivalent to the validity of both formulas one and two in the following set of formulas (11):

[0163]

[0164] For equation (11), L1(u) can be defined as u∈{0,1} l Let v be the value vector formed by evaluating the Boolean cube. Define v(u) as the value function describing the value vector v. Specifically, Where v k =L1(H -1 (k)). Thus, the validity of the first argument is transformed into the validity of the second argument (12):

[0165]

[0166] To demonstrate (12), an auxiliary function f can be defined based on the iterative relationship of iterative multiplication of values: The iterative relationship is expressed as follows:

[0167]

[0168] At the same time, this makes the auxiliary function satisfy f(1,1,…,1,0)=1.

[0169] Based on the iterative relationship (13) above, the values ​​of the auxiliary function f under each input are obtained iteratively. The descriptive vector of the auxiliary function f can then be expressed as: It can be seen that the function value for a specific input (1,1,…,1,0) is exactly the product of all elements of the value vector v (the second-to-last element of the description vector of f). Thus, f(1,1,…,1,0)=1 is equivalent to formula (12).

[0170] To verify the correctness of function f, in addition to verifying f(1,1,…,1,0)=1, it is also necessary to verify the conformity of function f with respect to the iterative relation (13). For this purpose, we can define... Validate the number of challenges selected randomly. The condition Q2τ = 0 is satisfied. Thus, it can be verified that f1,u = f(u,0)·f(u,1).

[0171] Furthermore, it is necessary to prove f(0,u) = v(u). In practice, this proof can be combined with the proof of Equation 2.

[0172] Specifically, for equation two, a similar approach to verifying equation (1) can be adopted. Specifically, we can define: Verification for randomly selected Is Q3(τ) equal to 0? To calculate Q3(τ) = 0, a sum-check protocol can be used, whereby the computing device proves to the verification device: According to equation (10), L2(u) depends on L1(u), and L1(u) is equivalent to v(u); therefore, in the process of proving Q3(τ)=0, f(0,u) can be used to replace v(u), thereby indirectly proving the validity of f(0,u)=v(u) while proving equation two.

[0173] The above describes the verification approach for conductor constraint relationships. Based on this approach, the specific verification process is described.

[0174] Figure 5 The flowchart illustrates the steps for proving a third constraint relationship using a computing device according to one embodiment. This third constraint relationship characterizes the constraint relationship where the values ​​at both ends of a wire in an arithmetic circuit are equal, i.e., a wire constraint relationship. The wire constraint relationship can be expressed as a third equation formed between a first function P and a third function W via a mapping function H, as shown in, for example, equation (3). Figure 5 The steps and procedures can be understood as Figure 3 The sub-step of step 33.

[0175] like Figure 5As shown, to prove the aforementioned third constraint relationship, in step 51, the computing device obtains a random array, such as random numbers β and σ. In one embodiment, these two random numbers can be randomly generated by the verification device and sent to the computing device.

[0176] In step 52, the computing device determines a ratio polynomial L1(u), one of the numerator and denominator polynomials of which is based on the first polynomial corresponding to the first function P in the random array. The third polynomial corresponding to the third function W We obtain another one based on the random array and the first polynomial. The mapping polynomial corresponding to the mapping function H get.

[0177] In one embodiment, the ratio polynomial L1(u) can be determined according to the aforementioned formula (9). In this example, the numerator polynomial is... The denominator polynomial is

[0178] In another embodiment, the numerator and denominator in formula (9) can be interchanged to form a ratio polynomial; or, the numerator and denominator can be multiplied by a certain coefficient or other transformations that do not affect the result, and the transformation result can be used as a ratio polynomial.

[0179] Furthermore, in step 53, the computing device determines the difference between the product of the ratio polynomial and the denominator polynomial and the numerator polynomial, thus obtaining the difference polynomial L2(u).

[0180] When the ratio polynomial is determined according to formula (9), the difference polynomial L2(u) as shown in formula (10) can be obtained accordingly, that is:

[0181] Next, in step 54, the computing device, according to the third equation, invokes the summation proof protocol with the verification device to prove that the product of the ratio polynomial L1(u) with respect to all inputs is 1; and to prove that the product of the difference polynomial L2(u) with respect to any input is 0. That is, to prove equations one and two in formula (11) respectively.

[0182] The proof that the product of all evaluations of the ratio polynomial L1(u) is 1, i.e. the proof of equation one in (11), includes the following process.

[0183] (a) First, the computing device evaluates the ratio polynomial L1(u) over all inputs to obtain the value vector v and the value function v(u) describing the value vector.

[0184] (ii) Next, based on the value function v(u) as the iterative basis, an auxiliary function f is determined based on the iterative relationship of multiplying the values, such that the function value of the auxiliary function f for a specific input is the product of all elements of the value vector v. Specifically, in one example, the above iterative relationship can be as shown in formula (13), in which case the specific input is (1,1,…,1,0).

[0185] It is understandable that, for the sake of computational alignment, given the auxiliary function f, the computing device can extend its MLE to an auxiliary polynomial. Furthermore, the computing device can also calculate the commitment value of the auxiliary polynomial through a polynomial commitment protocol. It is sent to the verification device for verification and for subsequent calculations.

[0186] (iii) Based on this, the computing device can invoke a polynomial commitment protocol with the verification device to verify the auxiliary polynomial corresponding to the auxiliary function f. The evaluation checks whether the value of a specific input is 1. Specifically, both the computing device and the verification device invoke the evaluation algorithm of the multinomial commitment protocol. Argument

[0187] In addition, the computing device must prove that the auxiliary function f conforms to the aforementioned iterative relationship (13).

[0188] (iv) Therefore, the computing device rewrites the iterative relation as a summation of zero over the second combinatorial polynomial. Specifically, the above formula (13) can be rewritten as:

[0189]

[0190] The second combinatorial polynomial is:

[0191] (v) In order to prove formula (14) to the verification device, the verification device may generate a third challenge number τ3 and send it to the computing device. Thus, the computing device obtains the third challenge number τ3.

[0192] (vi) Thus, the computing device can call the sum-check protocol with the verification device to verify whether the calculated value obtained by substituting the third challenge number τ3 into the second combination polynomial is 0, that is, to verify Q2(τ3)=0, thereby verifying the aforementioned formula (14).

[0193] It is understandable that the final step of the sum-check protocol can be reduced to the verification device calculating the second combination polynomial. Evaluating a random number r2 Is it equal to a certain target value T2? To further reduce the computational burden on the verification equipment, in the final step of executing the sum-check protocol, the computing and verification equipment utilize a multinomial commitment protocol to convert the polynomial evaluation (i.e., calculation) originally performed on the verification equipment into a new value. ), and then transferred to the computing device side.

[0194] Specifically, the polynomial is evaluated according to the definition of the second combinatorial polynomial. The evaluation of the auxiliary polynomial involves three input cases in the iterative relation: Therefore, a polynomial commitment protocol can be used to verify the three evaluations of the auxiliary polynomial under the three inputs formed based on r², thereby obtaining the polynomial evaluation results.

[0195] More specifically, in step (vi) above, the computing device and the verification device can perform summation verification through the following process:

[0196] (1) Both the computing device and the verification device invoke the evaluation algorithm in the polynomial commitment. The argument substitutes the first input (1, r2) formed based on the second random number r2 into the auxiliary polynomial. The result of the evaluation is the sixth value s6, that is:

[0197] (2) The computing and verification devices invoke the evaluation algorithm in the polynomial commitment. The argument substitutes the second input (r2,0) formed based on the second random number r2 into the auxiliary polynomial. The result of the evaluation is the seventh value, s7, that is:

[0198] (3) The computing and verification devices invoke the evaluation algorithm in the polynomial commitment. The argument substitutes the third input (r2,1) formed based on the second random number r2 into the auxiliary polynomial. The result of the evaluation is the eighth value s8, that is:

[0199] Next, based on the sixth to eighth values ​​mentioned above, and the form of the second combination polynomial, the verification device can easily obtain the value of the second combination polynomial for the second random number. Then, by verifying whether the calculated value is equal to the target value T″, the verification is performed. Is it true? If it is true, then formula (14) is true, and the iterative relationship and correctness of the auxiliary function f are verified.

[0200] The above describes the proof process of Equation 1 in Formula (11).

[0201] The proof of formula (11) by the computing device includes the following process.

[0202] (i) The assumption that the aforementioned difference polynomial L2(u) evaluates to 0 for any input is rewritten as the form that the summation of the third combination polynomial is 0.

[0203] Specifically, it can be defined as follows: The third combination polynomial is shown in equation (15) below:

[0204]

[0205] Thus, if the summation Q3(t) of the third combinatorial polynomial is 0, then L2(u) is 0 for any input.

[0206] (ii) The computing device obtains the fourth challenge number τ4. Similarly, this fourth challenge number τ4 can be randomly selected by the verification device and sent to the computing device.

[0207] (III) The computing device and the verification device invoke the sum-check protocol to verify whether the calculated value obtained by substituting the fourth challenge number τ4 into the third combination polynomial is 0. That is, both parties invoke the sum-check protocol to verify that Q3(τ4) = 0.

[0208] Similarly, the execution of the final step of the sum-check protocol in step (iii) can be reduced to the verification device calculating the third combination polynomial. Evaluate a random number r3 (called the third random number). Is it equal to a certain target value T3? To further reduce the computational burden on the verification equipment, in the final step of executing the sum-check protocol, the computing and verification equipment utilize a multinomial commitment protocol to convert the polynomial evaluation (i.e., calculation) originally performed on the verification equipment into a new one. ), and then transferred to the computing device side.

[0209] Specifically, the polynomial is evaluated according to the definition of the third combinatorial polynomial. This involves substituting the third random number r3 into the auxiliary polynomial, the first polynomial, the mapping polynomial, and the third polynomial respectively to evaluate them. Therefore, the above four evaluations can be verified individually using a polynomial commitment protocol, thereby obtaining the polynomial evaluation results.

[0210] More specifically, in step (iii) above, the computing device and the verification device can perform summation verification through the following process:

[0211] (1) Both the computing device and the verification device invoke the evaluation algorithm in the polynomial commitment. The argument is to substitute the third random number r3 into the auxiliary polynomial. The result of the evaluation is the ninth value s9, that is:

[0212] (2) The computing and verification devices invoke the evaluation algorithm in the polynomial commitment. The argument is to substitute the third random number r3 into the first polynomial corresponding to the first function. The result of the evaluation is the tenth value s. 10 ,Right now:

[0213] (3) The computing and verification devices invoke the evaluation algorithm in the polynomial commitment. The argument is to substitute the third random number r3 into the mapping polynomial corresponding to the mapping function. The result of the evaluation is the eleventh value s. 11 ,Right now:

[0214] (4) The computing and verification devices invoke the evaluation algorithm in the polynomial commitment. The argument is to substitute the third random number r3 into the third polynomial corresponding to the third function. The result of the evaluation is the twelfth value s. 12 ,Right now:

[0215] Next, based on the aforementioned ninth to twelfth values ​​and the definition of the third combination polynomial, the verification device can easily obtain the value of the third combination polynomial for the third random number. Then, by verifying whether the calculated value is equal to the target value T3, the verification is performed. Does it hold true? If it does, then equation two of formula (11) holds true.

[0216] If both Equation 1 and Equation 2 in Equation (11) are true, it means that the wire constraint relationship shown in Equation (3) or Equation (8) is true.

[0217] For the fourth constraint relationship shown in formula (4), i.e., the output constraint relationship, the computing device can determine the final output gate number o and, through the polynomial commitment protocol, prove to the verification device that the output value of the first function for gate number o is 1. Specifically, the computing device and the verification device, for the first polynomial... Gate number 'o', call the evaluation algorithm The argument is that the input value formed by combining the gate number 0 with the indicator bit string (i.e., 10) corresponding to the gate output port is substituted into the first polynomial. The result of the evaluation is 1, which proves the following: Thus, the proof of the output constraint relationship is achieved.

[0218] Through the above methods, the gate constraint relationship, input constraint relationship, wire constraint relationship and output constraint relationship between the first function P and other functions are proved, and thus the correctness of the calculation in this round using the arithmetic circuit C is proven.

[0219] As can be seen, when encoding the arithmetic circuit C, a single round of execution of the arithmetic circuit is encoded using a multivariable (l-bit) single function (the first function). The number of multivariables is only log|C|, the size of the arithmetic circuit, plus a small constant (e.g., 2). When encoding with an input string u of log|C|+2 bits, the proof process is implemented using a multivariable, multilinear polynomial with log|C|+2 variables. This approach makes the prover's computational cost linearly dependent on the circuit size (O(|C|)), because the computational cost of evaluating a polynomial with log|C|+2 variables is 2^{log|C|+2}=4|C|. Thus, the computational cost of the proof is greatly reduced.

[0220] In the above embodiments, the computing device interacts with the verification device to obtain challenge numbers and random numbers, such as challenge numbers τ1, τ2, τ3, and random numbers β, σ, etc., and performs subsequent verification processes based on these challenge numbers / random numbers. To simplify communication, the acquisition of the challenge numbers / random numbers can also be achieved in a non-interactive manner. Specifically, the computing device and the verification device can agree on some data generators, such as pseudo-random number generators, hash function-based generators, etc. Using the agreed-upon generator, based on the same data source, the same random numbers can be generated. Thus, when a challenge number is needed, the computing device can generate the challenge number / random number based on the agreed-upon generator and a data source available to both parties. This data source can be data that the computing device can only obtain up to the previous step, such as the calculation result of the previous step, to ensure that neither party can calculate the challenge number or random number in advance. In a specific example, both parties generate a common challenge number / random number through Fiat-Shamir transformation. In this way, the computing device and the verification device can obtain common challenge numbers and random numbers in a non-interactive manner, simplifying communication and further improving verification efficiency.

[0221] According to another embodiment, a data verification apparatus is also provided, which is deployed in a computing device that can be any device, platform, or cluster with computing and processing capabilities. Figure 6 A schematic diagram of a data verification apparatus according to one embodiment is shown. Figure 6 As shown, the device 600 includes:

[0222] The acquisition unit 61 is configured to acquire function information of the target function group of the target arithmetic circuit, wherein the target arithmetic circuit is used to execute the target calculation task indicated by the verification device, and the target function group is used to describe the circuit structure of the target arithmetic circuit.

[0223] The determining unit 62 is configured to determine a first function based on the current round of calculation of the target calculation task. The first function is used to describe the input and output values ​​of each gate in the target arithmetic circuit during the current round of calculation.

[0224] The proof unit 63 is configured to prove that the first function satisfies a number of preset constraints by executing an interactive proof protocol with the verification device, thereby proving the correctness of the current calculation process, wherein the number of constraints includes the constraint relationship between the function information of the first function and the target function group.

[0225] Through the above-described devices, the computing device performs... Figure 3 The illustrated process steps demonstrate to the verification equipment the correctness of its calculation results. For a detailed explanation of the process execution, please refer to the foregoing. Figures 3 to 5 The description will not be repeated here.

[0226] According to another embodiment, a computer-readable storage medium is also provided, on which a computer program is stored, which, when executed in a computer, causes the computer to perform a combination Figure 3 The method described.

[0227] According to another embodiment, a computing device is also provided, including a memory and a processor, wherein executable code is stored in the memory, and when the processor executes the executable code, it implements a combination... Figure 3 The method described.

[0228] Those skilled in the art will recognize that, in one or more of the examples above, the functions described in this invention can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.

[0229] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of the present invention should be included within the scope of protection of the present invention.

Claims

1. A data verification method, executed via a computing device, comprising: Obtain function information of the target function group of the target arithmetic circuit, wherein the target arithmetic circuit is used to execute the target calculation task indicated by the verification device, and the target function group is used to describe the circuit structure of the target arithmetic circuit; Based on the current calculation process of the target calculation task, a first function is determined. The first function is used to describe the input and output values ​​of each gate in the target arithmetic circuit during the current calculation process. By executing an interactive verification protocol with the verification device, the first function is proven to satisfy several preset constraints, thereby proving the correctness of the current calculation process. The constraints include the constraints between the function information of the first function and the target function group.

2. The method according to claim 1, wherein, The input to the first function is a 1-bit encoded string, which includes a first bit group and a second bit group. The first bit group indicates the gate number or circuit input number, and the second bit group indicates the gate input / output port or circuit input port.

3. The method according to claim 1, wherein, The target function group includes a second function and a third function. The second function is used to encode the gate type of each gate in the target arithmetic circuit; the third function is used to encode the connection relationship of each wire in the target arithmetic circuit.

4. The method according to claim 3, wherein, The target arithmetic circuit includes a first wire, which corresponds to a plurality of encoded strings, forming a set of encoded strings; the third function satisfies that the function value for the first encoded string is equal to the mapping value of a predefined mapping function for the second encoded string, wherein the first and second encoded strings are obtained by iterating through the set of encoded strings.

5. The method according to claim 1, wherein, Obtain the function information of the target function set of the target arithmetic circuit, including: The target arithmetic circuit is generated based on the target computation task, and the function information of the target function group is determined based on the circuit structure of the target arithmetic circuit.

6. The method according to claim 3, wherein, Obtain the function information of the target function set of the target arithmetic circuit, including: Obtain the function information of the target function group that has been pre-sent by the verification device.

7. The method according to claim 6, wherein, The function information of the target function group includes a second commitment value and a third commitment value, wherein the second commitment value is a commitment value calculated using a polynomial commitment protocol for a second polynomial corresponding to the second function; and the third commitment value is a commitment value calculated using a polynomial commitment protocol for a third polynomial corresponding to the third function.

8. The method according to claim 3, wherein, The plurality of constraint relationships include a first constraint relationship characterizing the relationship between the input and output of each gate, which is expressed as a first equation formed by the operation between the first function and the second function; Prove that the first function satisfies several preset constraints, including: Based on the first polynomial and the second polynomial corresponding to the first function and the second function respectively, the first equation is rewritten as a form in which the summation of the first combined polynomial is 0. Achieve first challenge count; The verification device invokes a summation proof protocol to verify whether the calculated value obtained by substituting the first challenge number into the first combined polynomial is 0.

9. The method according to claim 8, wherein, Verifying whether the calculated value obtained by substituting the first challenge number into the first combined polynomial and summing it is 0 includes: The verification device invokes the evaluation algorithm in the polynomial commitment protocol to prove that substituting the first random number as the gate number into the evaluation result of the second polynomial is the first value. The verification device invokes the evaluation algorithm in the polynomial commitment protocol to prove that the result of substituting multiple specific values ​​into the first polynomial is multiple target values; the multiple specific values ​​are formed by combining the first random number as the gate number with the indicator bit string corresponding to each gate port; so that the verification device verifies whether the calculated value is 0 based on the first value and the multiple target values.

10. The method according to claim 2, wherein, The plurality of constraint relationships include a second constraint relationship, which indicates the consistency between the first function and the fourth function when the first bit group indicates the input number of the circuit. The fourth function is held by the verification device and is used to describe the input values ​​of each input port of the target arithmetic circuit in this round of calculation. Prove that the first function satisfies several preset constraints, including: Obtain the second challenge number; The verification device invokes a polynomial commitment protocol to prove that substituting the second challenge number into the calculated value of the first polynomial is equal to substituting it into the calculated value of the fourth polynomial, wherein the first polynomial is an extension polynomial of the first function, and the fourth polynomial is an extension polynomial of the fourth function.

11. The method according to claim 3, wherein, The plurality of constraint relationships include a third constraint relationship characterizing that the values ​​at both ends of the conductor are equal, and the third constraint relationship is expressed as a third equation formed by the mapping function operation between the first function and the third function; Prove that the first function satisfies several preset constraints, including: Get a random array; A ratio polynomial is determined, wherein one of the numerator and denominator polynomials is obtained based on the random array, the first polynomial corresponding to the first function, and the third polynomial corresponding to the third function, and the other is obtained based on the random array, the first polynomial, and the mapping polynomial corresponding to the mapping function; The difference polynomial is obtained by determining the difference between the product of the ratio polynomial and the denominator polynomial and the numerator polynomial. According to the third equation, the verification device invokes the summation proof protocol to prove that the product of the ratio polynomial with respect to all inputs is 1; and to prove that the product of the difference polynomial with respect to any input is 0.

12. The method according to claim 11, wherein, Prove that the product of the ratio polynomial over all inputs is 1, including: The value vector and the value function describing the value vector are obtained by evaluating the ratio polynomial over all inputs. Based on the value function as the iterative basis, an auxiliary function is determined based on the iterative relationship of multiplying the values, such that the function value of the auxiliary function for a specific input is the product of all elements of the value vector; The verification device invokes a polynomial commitment protocol to verify whether the value of the auxiliary polynomial corresponding to the auxiliary function for the specific input is 1; The iterative relationship is rewritten as a form in which the summation of the second combinatorial polynomial is 0. Achieve third challenge number; The verification device invokes a summation proof protocol to verify whether the calculated value obtained by substituting the third challenge number into the second combined polynomial is 0.

13. The method according to claim 12, wherein, Verifying whether the calculated value obtained by substituting the third challenge number into the second combination polynomial and summing it is 0 includes: The verification device invokes the evaluation algorithm in the polynomial commitment protocol to prove that the result of substituting the three inputs involved in the iterative relationship, which are formed based on the second random number, into the auxiliary polynomial is three target values; thus, the verification device verifies whether the calculated value is 0 based on the three target values.

14. The method according to claim 11, wherein, Prove that the difference polynomial evaluates to 0 for any input, including: The assumption that the difference polynomial evaluates to 0 for any input is rewritten as the form that the summation of the third combination polynomial is 0. Obtain the fourth challenge number; The verification device invokes a summation proof protocol to verify whether the calculated value obtained by substituting the fourth challenge number into the third combination polynomial is 0.

15. The method according to claim 2, wherein, The plurality of constraint relationships include a fourth constraint relationship, which indicates that the output of the final output gate of the target arithmetic circuit is a preset value; Prove that the first function satisfies several preset constraints, including: Determine the gate number of the final output gate, and combine the gate number with the second bit group indicating the gate output port to form the target input value; The verification device invokes a polynomial commitment protocol to prove that the result of substituting the target input value into the first polynomial corresponding to the first function is the preset value.

16. The method according to claim 1, wherein, The verification device is a node device in the blockchain, the computing device is an off-chain computing device, and the target computing task corresponds to the contract logic of a smart contract in the blockchain.

17. The method according to claim 1, wherein, The verification device is a participant in privacy-preserving federated learning; the target computation task corresponds to model computation.

18. A data verification apparatus, deployed in a computing device, comprising: The acquisition unit is configured to acquire function information of the target function group of the target arithmetic circuit, wherein the target arithmetic circuit is used to execute the target calculation task indicated by the verification device, and the target function group is used to describe the circuit structure of the target arithmetic circuit. The determining unit is configured to determine a first function based on the current round of calculation of the target calculation task, wherein the first function is used to describe the input and output values ​​of each gate in the target arithmetic circuit during the current round of calculation. The proof unit is configured to prove that the first function satisfies several preset constraints by executing an interactive proof protocol with the verification device, thereby proving the correctness of the current calculation process, wherein the several constraints include the constraint relationship between the function information of the first function and the target function group.

19. A computing device, comprising a memory and a processor, characterized in that, The memory stores executable code, and when the processor executes the executable code, it implements the method of any one of claims 1-17.