Method and System for Generating Random Numbers through Multi-Party Collaboration

By performing K round operations between multiple nodes, generating and verifying ciphertext shards, the problem of difficulty in efficiently generating fair random numbers in distributed systems is solved, and the efficiency and fairness of random number generation is achieved.

CN114915410BActive Publication Date: 2025-05-30ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210277779.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-21
Publication Date
2025-05-30
Estimated Expiration
2042-03-21

AI Technical Summary

Technical Problem

It is difficult for prior art to efficiently generate fair random numbers by multiple nodes in collaboration, especially in distributed systems, such as blockchain systems, where fairness and unpredictability of random numbers are required.

Method used

By performing K rounds of operations between multiple nodes, each round of operations includes generating original shards, ciphertext shards, and promise values, and verifying the validity of ciphertext shards through aggregation, ultimately generating a random number.

Benefits of technology

The ciphertext verification efficiency in the random number generation process is improved, and the multiple parties can jointly generate common random numbers, making the random number generation more efficient and fair.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114915410B_ABST
    Figure CN114915410B_ABST
Patent Text Reader

Abstract

The embodiments of this specification provide a method and system for generating random numbers through multi-party collaboration. Among them, the multi-party includes N nodes, and the N nodes include a first node and a second node. The above method includes: The first node performs K rounds of first operations. Each single-round first operation includes generating N original shards corresponding to the N nodes according to the privacy values held by the first node, and generating corresponding N ciphertext shards and N commitment values; broadcasting the N ciphertext shards and the N commitment values. Then, the first node generates a first proof based on the N original shards, N ciphertext shards, and N commitment values of each of the K rounds, and broadcasts the first proof. The second node uses the first proof to verify the validity of all the ciphertext shards broadcast in the K rounds of first operations; in the case of successful verification, the second node generates K random numbers corresponding to the K rounds by using the N ciphertext shards of each of the K rounds.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this specification relate to the field of computers, and in particular, to a method and apparatus for generating random numbers through multi-party collaboration. Background Art

[0002] For a distributed system including multiple nodes, it may be necessary to generate the same random number based on the privacy values held by each of the multiple nodes. For example, in the process of generating a new block in a blockchain system, the transactions belonging to the new block may expect to use a random number to implement corresponding transactions; among them, in order to ensure the fairness of the random number, it may be necessary to generate the random number based on the privacy values held by each of the multiple blockchain nodes of the blockchain system.

[0003] There is a hope for a new solution to more efficiently achieve the generation of random numbers through the cooperation of multiple nodes. Summary of the Invention

[0004] One or more embodiments of this specification describe a method and system for generating random numbers through multi-party collaboration, which can more efficiently achieve the assistance of multiple nodes to fairly generate a common random number.

[0005] According to a first aspect, there is provided a method for generating random numbers through multi-party collaboration. The multi-party includes N nodes, and the N nodes include a first node and a second node. The method includes:

[0006] The first node performs K rounds of first operations. Wherein a single round of the first operation includes generating N original shards corresponding to the N nodes according to the privacy value held by the first node, and generating corresponding N ciphertext shards and N commitment values; broadcasting the N ciphertext shards and the N commitment values; where K is greater than 1;

[0007] The first node generates a first proof according to the N original shards, N ciphertext shards and N commitment values of each of the K rounds, and broadcasts the first proof;

[0008] The second node uses the first proof to verify the validity of all the ciphertext shards broadcast in the K rounds of first operations;

[0009] In the case where the validity verification passes, the second node generates K random numbers corresponding to the K rounds by using the N ciphertext shards of each of the K rounds.

[0010] In one embodiment, generating the corresponding N ciphertext shards and N commitment values specifically includes: respectively encrypting the N original shards by using the public keys of the N nodes to obtain the N ciphertext shards; performing a predetermined mapping operation based on the N original shards to obtain the corresponding N commitment values.

[0011] According to one embodiment, generating the first proof includes: generating corresponding N sets of verification values for N nodes according to a first random value; applying a target mapping function to the N sets of verification values, and K rounds of respective N ciphertext shards and N commitment values to obtain a first challenge value; for each node, aggregating the K original shards corresponding to the node in the K rounds of the first operation to obtain a plaintext aggregation shard of the node; generating a response value corresponding to the node according to the first random value, the plaintext aggregation shard, and the first challenge value; forming the first proof, which includes the first challenge value and N response values corresponding to the N nodes.

[0012] In an embodiment of the above embodiment, generating corresponding N sets of verification values for N nodes specifically includes: for each node, generating a first verification value and a second verification value based on the first random value and the public key of the node, and forming a set of verification values of the node.

[0013] Corresponding to the above embodiment, in an embodiment, verifying the validity of all ciphertext shards broadcast in K rounds of the first operation specifically includes: for each node, generating a set of check values corresponding to the node according to the K ciphertext shards corresponding to the node in K rounds of respective N ciphertext shards and the response value corresponding to the node in the N response values; performing the target mapping operation on the N sets of check values corresponding to the N nodes, and K rounds of respective N ciphertext shards and N commitment values to obtain a second challenge value; if the first challenge value is not equal to the second challenge value, the verification fails.

[0014] Further, in an example, generating a set of check values corresponding to the node specifically includes: aggregating the K ciphertext shards to obtain a ciphertext aggregation shard of the node; aggregating the K commitment values corresponding to the node in K rounds of respective N commitment values to obtain an aggregated commitment value of the node; generating a first check value according to the response value and the aggregated commitment value of the node; generating a second check value according to the public key of the node, the response value, and the ciphertext aggregation shard.

[0015] According to one embodiment, the N original shards are obtained by respectively substituting the node numbers of the N nodes into a first-order first polynomial constructed based on the privacy value; correspondingly, verifying the validity of all ciphertext shards broadcast in K rounds of the first operation specifically includes: for each node, generating a corresponding dual code of the node based on the node number of the node and a second-order second polynomial; where the second order and the first order satisfy a preset relationship; aggregating the combinations of the K-round commitment values of each node based on the dual codes of the N nodes to obtain an aggregated value; if the aggregated value is not equal to a predetermined target value, the verification fails.

[0016] Further, in a specific example, the first order is t - 1 order, and the second order is N - t - 1, where t is the number of allowed malicious nodes plus 1.

[0017] In one implementation, the second node uses the N ciphertext shards of each of the K rounds to generate K corresponding random numbers for the K rounds, including: for any target round among the K rounds, the second node decrypts the ciphertext shard corresponding to this node among the N ciphertext shards of the target round, and the decryption result is incorporated into the plaintext shard set of the second node; the second node decrypts the ciphertext shard corresponding to this node among the ciphertext shards from other nodes in the target round, and the decryption result is incorporated into the plaintext shard set of the second node, where the other nodes are the nodes that have passed the validity verification; the second node broadcasts the plaintext shard set of the second node and obtains the plaintext shard sets of other nodes broadcast by other nodes; based on the plaintext shard set of the second node and the plaintext shard sets of other nodes, the random number for the target round is generated.

[0018] In an embodiment of the above implementation, the second node also receives the second proof broadcast by other nodes; the second node uses the second proof to verify whether the plaintext shard set of the other nodes is obtained by the corresponding nodes decrypting the ciphertext shards corresponding to those nodes using their private keys; generating the random number for the target round includes: in the case where the above verification passes, based on the plaintext shard set of the second node and the plaintext shard sets of other nodes, generating the random number for the target round.

[0019] According to one implementation, the N nodes are N blockchain nodes of a blockchain system, a single round corresponds to a block in the blockchain system, and the generated random number is used for transactions in that block.

[0020] Further, in an embodiment, the first node executes different stages of the K rounds of the first operation in parallel, and / or, the second node executes different stages of generating the K corresponding random numbers for the K rounds in parallel, so that the K corresponding random numbers are generated at the block production times of the corresponding K blocks.

[0021] According to a second aspect, a method for multi - party collaborative generation of random numbers is provided. The multi - parties include N nodes, and the method is executed by any first node among the N nodes, including:

[0022] Execute K rounds of a first operation, where a single round of the first operation includes generating N original shards corresponding to the N nodes according to the private value held by the first node, and generating corresponding N ciphertext shards and N commitment values; broadcasting the N ciphertext shards and the N commitment values; where K is greater than 1;

[0023] Generate a first proof based on the N original shards, N ciphertext shards, and N commitment values for each of the K rounds.

[0024] Broadcast the first proof so that any second node among the N nodes uses the first proof to verify the validity of all the ciphertext shards broadcast in the first operation of the K rounds, and, when the validity verification passes, generate K random numbers corresponding to the K rounds using the N ciphertext shards for each of the K rounds.

[0025] According to a third aspect, there is provided a system for collaboratively generating random numbers, the system including N nodes, the N nodes including a first node and a second node, where:

[0026] The first node is configured to perform a first operation for K rounds, where a single-round first operation includes generating, according to the private value held by the first node, N original shards corresponding to the N nodes, and generating corresponding N ciphertext shards and N commitment values; broadcasting the N ciphertext shards and the N commitment values; where K is greater than 1.

[0027] The first node is further configured to generate a first proof based on the N original shards, N ciphertext shards, and N commitment values for each of the K rounds, and broadcast this first proof.

[0028] The second node is configured to use the first proof to verify the validity of all the ciphertext shards broadcast in the first operation of the K rounds.

[0029] The second node is further configured to, when the validity verification passes, generate K random numbers corresponding to the K rounds using the N ciphertext shards for each of the K rounds.

[0030] According to a fourth aspect, there is provided a device for multi-party collaborative random number generation, the multi-party including N nodes, the device being deployed in any first node among the N nodes, the device including:

[0031] A first operation unit configured to perform a first operation for K rounds, where a single-round first operation includes generating, according to the private value held by the first node, N original shards corresponding to the N nodes, and generating corresponding N ciphertext shards and N commitment values; broadcasting the N ciphertext shards and the N commitment values; where K is greater than 1.

[0032] A proof generation unit configured to generate a first proof based on the N original shards, N ciphertext shards, and N commitment values for each of the K rounds.

[0033] The broadcast unit is configured to broadcast the first proof, such that any second node among the N nodes uses the first proof to verify the validity of all ciphertext shards broadcast in the K rounds of the first operation, and in the case where the validity verification passes, uses the N ciphertext shards of each of the K rounds to generate K corresponding random numbers for the K rounds.

[0034] According to a fifth aspect, there is provided a computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method of the first aspect described above.

[0035] According to a sixth aspect, there is provided a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method of the first aspect described above is implemented.

[0036] In the solution for multi-party collaborative random number generation provided in the embodiments of this specification, by generating an aggregation proof for multi-round ciphertext shards generated in multiple rounds of operations, and performing batch verification on the multi-round ciphertext shards based on the aggregation proof, the efficiency of ciphertext verification in the random number generation process is improved, thereby more efficiently realizing multi-party collaborative generation of a common random number. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for description in the embodiments. Obviously, the following-described drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0038] Figure 1 It is a system framework diagram of the technical solution provided in the embodiments of this specification;

[0039] Figure 2 It is a flowchart of a method for multi-party collaborative random number generation provided in the embodiments of this specification;

[0040] Figure 3 It shows the step flow of generating the first proof in one embodiment;

[0041] Figure 4 It shows a schematic diagram of parallel execution of random number generation according to one embodiment;

[0042] Figure 5 It shows a schematic structural diagram of a device for multi-party collaborative random number generation deployed in a first node according to one embodiment. DETAILED DESCRIPTION

[0043] The following describes the solution provided in this specification with reference to the drawings.

[0044] As described above, for a distributed system including multiple nodes, multiple nodes may need to generate a common random number for business needs. For example, in the process of generating a new block in a blockchain system, transactions belonging to the new block may expect to use a random number to implement corresponding transactions. Therefore, it is necessary to collaboratively generate a common random number among multiple parties in the distributed system. Moreover, due to the business requirements of the distributed system, the generation of this random number should satisfy unpredictability and fairness, that is, the generation result of the random number cannot be unilaterally controlled by any node.

[0045] Figure 1 This is a system framework diagram of the technical solution provided in the embodiments of this specification. As Figure 1 shown, for a distributed system including N nodes such as node 1 to node N, in order to ensure the fairness of the random number collaboratively generated by multiple parties, it is usually necessary for node 1 to node N to pre-commit their respective private values, and then in the subsequent process, according to the actual requirements of the distributed system, based on the private values committed by each of the N nodes, perform several rounds of communication to complete the generation of a common random number for the distributed system or other computer programs by the cooperation of the N nodes.

[0046] In one implementation, a round of random number generation process can be divided into a commitment stage, a local calculation stage, and a recovery stage. In the commitment stage, each of the N nodes generates N ciphertext shards based on its respective private value, and sends the generated ciphertext shards and corresponding commitments to the remaining N - 1 nodes through the first communication; in the local calculation stage, each node verifies the validity of the ciphertext shards sent by other nodes based on the commitments received from other nodes. If it is verified to be valid, it decrypts the corresponding plaintext shard from it. Then, through the second communication, it broadcasts its own plaintext shard to other nodes. In the recovery stage, each node restores the private values of each node based on the valid plaintext shards, and thus obtains a common random number.

[0047] In the foregoing implementation, in the local calculation stage, since each node has to verify the validity of the ciphertext shards sent by all other nodes, the computational complexity is very high and it takes a long time.

[0048] In view of this, embodiments of this specification provide a method and apparatus for collaboratively generating a random number by multiple parties, generating an aggregation proof for multiple rounds of ciphertext shards, so that each node can batch verify the ciphertext shards of K rounds. Passing the batch verification means that the ciphertext shards of K rounds are all valid. In this way, the verification efficiency of the ciphertext shards is accelerated, and the generation of a common random number by the cooperation of N nodes can be completed more quickly and efficiently.

[0049] Figure 2This is a flowchart of a method for multi-party collaborative generation of random numbers provided in the embodiments of this specification. Among them, the above-mentioned multi-party includes N nodes, and these N nodes usually belong to the same distributed system. For example, these N nodes can be N blockchain nodes belonging to the same blockchain system. When the N nodes are N blockchain nodes belonging to the same blockchain system, a single random number to be generated can correspond to a single block in the blockchain. For example, it can be used for transactions in the corresponding block.

[0050] In addition, before executing the method for multi-party collaborative generation of random numbers provided in the embodiments of this specification, the N nodes can be initialized first. For example, the N nodes initialize a prime-order elliptic curve group, and initialize generators g and h based on this elliptic curve group and with unknown discrete logarithm relationships. The public keys and private keys corresponding to each of the N nodes can also be initialized. For example, the N nodes can be numbered in sequence first. Among them, the number of any i-th node among the N nodes can be denoted as i. Therefore, in the following text, the node numbered i will also be expressed as node i. Similarly, the node numbered j will also be expressed as the j-th node or node j. Then, for node i / node j, its corresponding private key sk i / private key sk j is initialized, and based on the generator h and the private key corresponding to node i / node j, the corresponding

[0051] After performing the above initialization, the N nodes can jointly execute the method flow as shown in Figure 2 In the following text, for the convenience of clearly and accurately describing the technical solution, any two nodes among the N nodes, called the first node and the second node, are specifically described.

[0052] As shown in Figure 2 , in step 21, the first node executes K rounds of first operations. Among them, a single round of the first operation includes generating N original shards corresponding to the N nodes according to the privacy value held by the first node, and generating corresponding N ciphertext shards and N commitment values; broadcasting the N ciphertext shards and the N commitment values.

[0053] It should be understood that in order to perform subsequent batch verification, K in the above K rounds is greater than 1. In Figure 2 and subsequent examples, the description is combined with K = 4. However, in other examples, K can also be selected as other values according to needs.

[0054] In Figure 2 , each round of the first operation is shown in a dashed box. In each round of the first operation, exemplarily, the first node, for example, denoted as node i, can obtain a random number and use it as the privacy value s of this round held by node i i . Then randomly select t - 1 random numbers c1 ,..., c t-1 to construct the following first polynomial of order t - 1:

[0055]

[0056] In the above formula (1), the value of c in the first polynomial 0 is equal to the privacy value s held by node i i ; the value of t can be determined based on a preset threshold. For example, when the N nodes are N blockchain nodes belonging to the same blockchain system, the preset threshold can be the number of malicious nodes allowed in the blockchain system, and the value of t can specifically be any integer greater than the preset threshold and not greater than N. For example, t can be the number of allowed malicious nodes plus 1.

[0057] Next, node i slices the privacy value s i based on the first polynomial and the respective numbers of the N nodes to generate N original shards corresponding to the N nodes. For example, the number j of any j-th node among the N nodes can be substituted into the variable x in the foregoing polynomial to calculate p(j), and the value of p(j) is the original shard generated by node i corresponding to node j, denoted as s ij .

[0058] In this way, the first node i can generate N original shards corresponding to the N nodes according to the privacy value of this round. Then, the first node i encrypts the N original shards corresponding to the N nodes according to the respective public keys of the N nodes to generate N ciphertext shards corresponding to the N nodes. For example, for the shard s ij corresponding to node j, the first node i can use the public key pk j of node j to encrypt the shard s ij to obtain the ciphertext shard corresponding to node j, that is where the public key pk j is also the one described above

[0059] For the verification of the validity of the ciphertext shards, in each round of the first operation, the first node i also generates a polynomial commitment composed of N commitment values to prove that the N shards can recover a unique privacy value. Exemplarily, node i can generate the polynomial commitment which includes N commitment values, and any j-th commitment value v j can be obtained based on a predetermined mapping operation on the j-th original shard s ij . For example, the predetermined mapping operation can be an exponential operation on the generator, and the obtained commitment value can be generated based on the generator g and the original shard s ij .

[0060] Thus, after the first node i generates N original shards corresponding to N nodes, it also generates N ciphertext shards corresponding to the N original shards and N commitment values. Then, the first node i can broadcast the N ciphertext shards and N commitment values to other nodes. Specifically, in different embodiments, the first node i can include the N ciphertext shards and N commitment values in a single broadcast message, or can include the N ciphertext shards and N commitment values in different broadcast messages respectively.

[0061] The process of the single-round first operation is described above. The first node i can perform K rounds of the first operation sequentially or in parallel. Each round of the first operation generates N original shards, and broadcasts the corresponding N ciphertext shards and N commitment values. Thus, after K rounds of the first operation, the first node i generates a total of K*N original shards, and the corresponding K*N ciphertext shards and commitment values.

[0062] Then, in step 22, the first node generates a first proof based on the N original shards, N ciphertext shards and N commitment values of each of the K rounds. This first proof is used to prove the validity of the ciphertext shards of the K rounds.

[0063] Figure 3 Shows the step flow of generating the first proof in one embodiment, that is Figure 2 The sub-steps of step 22.

[0064] As Figure 3 shown, in step 31, the first node generates corresponding N sets of verification values for N nodes according to the first random value.

[0065] Specifically, the first node i can randomly select a random number w as the above-mentioned first random value, and then based on the first random number w, the foregoing generator g and the public key pk of node j j , generate a set of verification values corresponding to node j. More specifically, the first node i can generate a first verification value based on the combination of the first random number w and the generator g, denoted as a 1j = g w ; generate a second verification value based on the combination of the first random number w and the public key pk of node j j , denoted as This first verification value and the second verification value constitute a set of verification values corresponding to node j.

[0066] It can be understood that the above verification value generation process is performed for each node, so that N sets of verification values corresponding to N nodes can be obtained. These N sets of verification values can be expressed as (a 11 , a 21 , …, a 1n , a2n ,).

[0067] Then, in step 32, for the above N sets of verification values, as well as the N ciphertext shards and N commitment values for each of the K rounds, apply the target mapping function to obtain the first challenge value. The above target mapping function can be a mapping function with an extremely low collision probability pre-agreed among the N nodes, preferably a function that is easy to calculate in one direction and difficult to solve in the reverse direction. For example, the target mapping function can be the hash function hash.

[0068] In one example, taking the target mapping function as the hash function and K = 4 as an example, the first challenge value c can be expressed as:

[0069]

[0070] where (v 11 ,...v 4n ) are the commitment values for each of the 4 rounds (N for each round), are the ciphertext shards for each of the 4 rounds (N for each round). It should be noted that here the first subscript in the subscript represents the round number, and the second subscript represents the node number targeted; (a 11 ,a 21 ,…,a 1n ,a 2n ,) are the N sets of verification values for the N nodes.

[0071] Next, in step 33, the first node aggregates the K original shards corresponding to each node j in the K rounds of the first operation to obtain the plaintext aggregation shard of the node. Preferably, in the aggregation process, the aforementioned first challenge number c can also be introduced as the aggregation coefficient.

[0072] In one example, taking K = 4 as an example, the plaintext aggregation shard of node j can be expressed as:

[0073]

[0074] Then, according to the first random value w, the above plaintext aggregation shard and the first challenge value c, generate the response value corresponding to the node. For example, for each node j, generate the response value corresponding to node j:

[0075] r j = w - s′ j * c (4)

[0076] Thus, in step 34, the first node can form the first proof proof 1 , which includes the first challenge value c, and the N response values corresponding to the N nodes. This can be expressed as where the response value vector is an N-dimensional vector, where the j-th element is the response value r corresponding to node j j .

[0077] Return to Figure 2 , after generating the first proof, at step 23, the first node can broadcast the first proof. Thus, all other nodes among the N nodes can receive the first proof, and any one of them, called the second node, can, at step 24, verify the validity of all ciphertext shards broadcast in the K rounds of the first operation according to the above first proof.

[0078] In one embodiment, the above validity verification includes verifying that the original shards corresponding to the ciphertext shards in each round can recover a unique privacy value. This can be achieved by verifying the validity of polynomials. Specifically, in one example, a polynomial f(x) of a target order (called the second order) is randomly selected, called the second polynomial. For each node j, based on the node number j of the node and the second polynomial, the dual code corresponding to the node j is generated. For example, the dual code of node j can be generated as follows:

[0079]

[0080] Among them, between the order of the second polynomial f(x) and the order of the aforementioned first polynomial p(x), a preset relationship corresponding to the dual property needs to be satisfied. For example, if the order of the first polynomial is t - 1, then the order of the second polynomial f(x) should be N - t - 1.

[0081] Thus, the dual codes of the N nodes can be obtained respectively. Then, based on the dual codes of each node, the combinations of the K-round commitment values of each node can be aggregated to obtain an aggregated value. Then, it is judged whether the aggregated value is the target value, and the target value is a preset value determined according to the dual code property and the above aggregation method.

[0082] For example, in one example, K is still set to 4, the combination of the K-round commitment values takes the product of the K-round commitment values, and the aggregation based on the dual code uses the product with the dual code as the exponential coefficient. In this case, the aggregated value e can be expressed as:

[0083]

[0084] The validity of the polynomial can be verified by judging whether e is equal to 1. If e is not equal to 1, the validity verification fails. At this time, it indicates that the ciphertext shards of the K rounds from the first node cannot be used in the subsequent random number generation process, and the ciphertext shards of the above K rounds broadcast by the first node can be discarded.

[0085] In one embodiment, the validity verification in step 24 includes verifying that the ciphertext shards and the corresponding commitment values in each round are obtained based on the same original shard. This can be achieved by using the first proof proof 1 to verify the validity of the discrete logarithm.

[0086] Specifically, in one example, for each node j, the second node generates a set of check values corresponding to the node based on the K ciphertext shards corresponding to the node j among the N ciphertext shards of each of the K rounds and the response value r corresponding to the node among the N response values j .

[0087] To generate the check values, the K ciphertext shards corresponding to the node j in the K rounds can be aggregated to obtain the ciphertext aggregated shard of the node j. For example, taking the first challenge number c as the aggregation coefficient, the K (=4) ciphertext shards can be aggregated to obtain the ciphertext aggregated shard shown in Equation (7):

[0088]

[0089] Similarly, the K commitment values corresponding to the node j among the N commitment values of each of the K rounds can be aggregated to obtain the aggregated commitment value of the node j. For example, taking the first challenge number c as the aggregation coefficient, the K (=4) commitment values can be aggregated to obtain the aggregated commitment value shown in Equation (8):

[0090]

[0091] According to the response value r of the node j j and the aggregated commitment value v' j , the first check value a' 1j is generated. For example, the first check value can be expressed as:

[0092]

[0093] In addition, according to the public key pk of the node j j , the corresponding response value r j and the ciphertext aggregated shard generate the second check value a' 2j . For example, the second check value can be expressed as:

[0094]

[0095] Above, the first check value a' of the node j 1j and the second check value a' 2j constitute a set of check values. Similarly, for the N nodes, the corresponding N sets of check values can be obtained, expressed as (a' 11 , a' 21,…,a′ 1n ,a′ 2n ,). Based on this, for the N groups of verification values, as well as the N ciphertext shards and N commitment values in each of the K rounds, the aforementioned target mapping operation is performed to obtain the second challenge value c'.

[0096] Continuing with the previous example, taking the target mapping function as the hash function and K = 4 as an example, the second challenge value c' can be expressed as:

[0097]

[0098] It should be understood that the ciphertext aggregation shard is the aggregation of ciphertext shards, and the aggregated commitment value is the aggregation of commitment values; if the ciphertext shards and commitment values are respectively based on the same original shards, then as shown in the last terms of formulas (7) and (8), their exponents for the generator g and the public key pk j are the same, and this exponent corresponds to the plaintext aggregation shard s' shown in formula (3) j . Combining with the relationship between the first random number w and s' in formula (4) j , and the definitions of the first verification value and the second verification: a 1j = g w , then there is: if the ciphertext shards and commitment values are respectively based on the same original shards, then the first / second verification values are respectively equal to the first / second verification values, that is: a 1j = a' 1j , a 2j = a' 2j ; furthermore, the first challenge value c calculated through the same mapping function should be equal to the second challenge value c'.

[0099] Conversely, if the ciphertext shards and commitment values in any one of the K rounds are not generated based on the same original shards, then the above-mentioned aggregated relationship no longer holds, resulting in the first adjustment value c and the second challenge value c' being unequal. Therefore, if the second node determines that the first challenge value is not equal to the second challenge value, the verification fails. At this time, it indicates that the ciphertext shards of the K rounds from the first node cannot be used in the subsequent random number generation process, and the ciphertext shards of the above K rounds broadcast by the first node can be discarded.

[0100] In the case where the above validity verification passes, next, in step 25, the second node uses the N ciphertext shards in each of the K rounds sent by the first node to generate K corresponding random numbers. In different embodiments, the second node can perform the subsequent random number generation process based on various existing methods. For clarity, for any one of the K rounds, called the target round, a description is given.

[0101] Assume that the second node is node j. Since each ciphertext shard is encrypted using the public key of the corresponding node, the second node j can use its own private key skj to decrypt the ciphertext shard corresponding to this node j among the N ciphertext shards sent by the first node i in the target round. The decryption result s obtained after decryption is ij classified into the plaintext shard set of the second node.

[0102] It should be understood that although Figure 2 for the sake of clarity, only the process of the first node performing the first operation for K rounds is shown, in fact, each of the N nodes will similarly perform the same process. Therefore, the second node will not only receive the ciphertext shards and the first proof for K rounds from the first node, but also receive the ciphertext shards and the corresponding first proof generated by the other nodes through the first operation for K rounds. As mentioned above, if the validity verification of the first proof from a certain node fails, the ciphertext shards of that node are discarded. For the other valid nodes that have passed the above-mentioned validity verification, the second node also uses the private key skj to decrypt the ciphertext shard corresponding to this node j among the ciphertext shards from the other valid nodes in the above-mentioned target round, and the decryption result is also classified into the plaintext shard set of the second node. In this way, the second node obtains the corresponding plaintexts of the ciphertext shards generated by the other valid nodes for this node j in the target round, which constitutes the plaintext shard set of the second node.

[0103] Then, the second node can broadcast the plaintext shard set of the second node. It can be understood that the other nodes in the system also perform similar decryption and broadcast operations. Therefore, the second node will also obtain the plaintext shard sets of the other nodes broadcast by the other nodes.

[0104] Thus, the plaintext shard set of this node and the plaintext shard sets of the other nodes can form a shard matrix, and by aggregating the elements in this shard matrix, a random number for the target round can be generated.

[0105] In one embodiment, after decrypting to obtain the plaintext shard set of the second node, the second node also generates a second proof proof 2 , which is used to prove that the plaintext shard set is correctly decrypted from each ciphertext shard using its own private key. Various methods in the prior art can be used to generate this second proof. The second node can broadcast this second proof.

[0106] Correspondingly, the second node will also receive the second proofs broadcast by other nodes. The second node uses the second proofs from other nodes to verify whether the plaintext shard set of that other node is obtained by decrypting the corresponding ciphertext shards of that node using its private key (second verification). If this second verification fails, the plaintext shard set of that other node is discarded and does not participate in the subsequent random number generation. Thus, the second node can use its own plaintext shard set and the plaintext shard sets of other nodes that pass the second verification to generate the random number for that target round.

[0107] It can be understood that during the entire random number generation process, through the first proof and possibly the second proof, some nodes that fail the verification may be filtered or excluded. Thus, the shard matrix composed of multiple plaintext shard sets may not be a complete N*N matrix. Based on the generation method of each shard, as long as the number of plaintext shards in the plaintext shard set is greater than or equal to t, the privacy value can be recovered by means of Lagrange interpolation, and then the final random number can be obtained.

[0108] Furthermore, when the N nodes are N blockchain nodes in the same blockchain system, any node among the N nodes can execute different stages of multiple random number generation rounds in parallel, so that multiple random number generation rounds generate corresponding multiple random numbers at the block time / block production time of the corresponding multiple blocks. More specifically, the entire random number generation process can be divided into multiple execution stages, such as including the original shard generation stage, the encryption stage, the commitment value generation stage, the decryption stage, etc., and the block time actually consumed by each execution stage is defined; by enabling the first node to execute different stages of the foregoing K rounds of first operations in parallel, and / or enabling the second node to execute different stages of generating K random numbers for K rounds in parallel, it is realized that a random number can be generated for the corresponding block within each block time for use in the transactions in the corresponding block.

[0109] In addition, it should be noted that for the sake of clarity and convenience of description above, the process of the first node generating the first proof, the second node verifying the first proof, and then generating the subsequent random number is introduced. However, it should be understood that in actual operation, each node will execute the entire random number generation process, that is, generate ciphertext shards and its own first proof, and verify the first proofs of other nodes, and generate random numbers based on the verification results. Therefore, each node will execute each stage of the entire random number generation process.

[0110] Figure 4A schematic diagram showing parallel execution of random number generation according to an embodiment. As described above, each node will execute each stage of the entire random number generation process. For the sake of clarity and simplicity, the entire random number generation process corresponding to a single random number is divided into: a secret value slicing encryption stage, which is included in the aforementioned first operation and is assumed to consume 2 block times; a first communication stage, corresponding to the broadcast of ciphertext shards and commitment values, also included in the aforementioned first operation and assumed to consume 1 block time; a decryption stage, assumed to consume 5 block times; a second communication and random number recovery stage, assumed to consume 1 block time. Referring to Figure 4 the example of Figure 4 it can be understood that a single random number generation round needs to consume 9 block times. Any node among the N nodes can substantially execute different stages of 9 random number generation rounds in parallel. Among them, the decryption stages of different random number rounds ( Figure 4 as shown in 3 rounds) have a time overlap, and the verification of the first proof can be performed during this overlapping time, so as to perform batch verification on these 3 rounds of random numbers. In this way, batch verification does not block the parallel execution of each round of random number generation stages, so that random numbers can be generated for the corresponding block within each block time. For example, as

[0111] it should be particularly noted that Figure 4 this is only used to assist in explaining the technical solutions in the embodiments of this specification. In actual scenarios, the multiple execution stages included in a single random number generation round may also be divided in other ways, and the block times consumed by each execution stage may also be defined in other ways. The embodiments of this specification do not make any limitations in this regard.

[0112] On the other hand, corresponding to the above process of multi-party collaborative random number generation, the embodiments of this specification also disclose a multi-party collaborative random number generation system, which includes N nodes. The N nodes at least include a first node and a second node, where:

[0113] The first node is used to execute K rounds of the first operation. Each round of the first operation includes generating N original shards corresponding to the N nodes according to the privacy value held by the first node, and generating corresponding N ciphertext shards and N commitment values; broadcasting the N ciphertext shards and the N commitment values; where K is greater than 1;

[0114] The first node is also used to generate a first proof according to the N original shards, N ciphertext shards and N commitment values of each of the K rounds, and broadcast the first proof;

[0115] The second node is used to verify the validity of all ciphertext shards broadcast in the K rounds of the first operation by using the first proof;

[0116] The second node is further used to generate K random numbers corresponding to the K rounds by using the N ciphertext shards of each of the K rounds when the validity verification passes.

[0117] In another aspect, corresponding to the steps executed by the first node in the process of multi-party collaborative random number generation, an embodiment of the present specification further discloses a device for multi-party collaborative random number generation, which is deployed in any first node among the N nodes, and the first node can be implemented as any computing unit, platform, server, device, etc. with computing and processing capabilities. Figure 5 The structural schematic diagram of the device for multi-party collaborative random number generation deployed in the first node according to an embodiment is shown in Figure 5 As shown, the device 500 includes:

[0118] A first operation unit 51, configured to execute the first operation in K rounds, where a single round of the first operation includes generating N original shards corresponding to the N nodes according to the privacy value held by the first node, and generating corresponding N ciphertext shards and N commitment values; broadcasting the N ciphertext shards and N commitment values; where K is greater than 1;

[0119] A proof generation unit 52, configured to generate a first proof according to the N original shards, N ciphertext shards and N commitment values of each of the K rounds;

[0120] A broadcasting unit 53, configured to broadcast the first proof, so that any second node among the N nodes uses the first proof to verify the validity of all ciphertext shards broadcast in the K rounds of the first operation, and generates K random numbers corresponding to the K rounds by using the N ciphertext shards of each of the K rounds when the validity verification passes.

[0121] In an embodiment, the above proof generation unit 52 further includes (not shown):

[0122] A verification value generation module, configured to generate corresponding N groups of verification values for the N nodes according to the first random value;

[0123] A challenge value generation module, configured to apply a target mapping function to the N groups of verification values, and the N ciphertext shards and N commitment values of each of the K rounds to obtain a first challenge value;

[0124] A response value generation module, configured to, for each node, aggregate the K original shards corresponding to the node in the K rounds of first operations to obtain a plaintext aggregated shard of the node; generate a response value corresponding to the node according to the first random value, the plaintext aggregated shard, and the first challenge value.

[0125] A proof formation module, configured to form the first proof, which includes the first challenge value and the N response values corresponding to the N nodes.

[0126] Through the above devices and systems, the verification efficiency can be improved during the process of multi-party collaborative random number generation, and thus the random number generation efficiency can be improved.

[0127] According to an embodiment of another aspect, there is also provided a computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the methods performed by each party during the above-mentioned multi-party collaborative random number generation process.

[0128] According to an embodiment of still another aspect, there is also provided a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the methods performed by each party during the above-mentioned multi-party collaborative random number generation process are implemented.

[0129] Those skilled in the art should be able to realize that in the above one or more examples, the functions described in the present invention can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.

[0130] The specific embodiments described above further elaborate the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above description is only the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of the present invention should be included in the protection scope of the present invention.

Claims

1. A method for generating random numbers through multi - party collaboration. The multi - parties include N nodes, and the N nodes include a first node and a second node. The method includes: The first node performs K rounds of first operations. Each round of the first operation includes generating N original shards corresponding to the N nodes according to the private value held by the first node, and generating corresponding N ciphertext shards and N commitment values; Broadcasting the N ciphertext shards and N commitment values; where K > 1; The first node generates a first proof based on the N original shards, N ciphertext shards and N commitment values of each of the K rounds, and broadcasts the first proof; The second node uses the first proof to verify the validity of all the ciphertext shards broadcast in the K rounds of the first operation; The validity verification includes: verifying through a verification polynomial that the original shards corresponding to the ciphertext shards in each round can recover a unique private value; In the case where the validity verification passes, the second node generates K random numbers corresponding to the K rounds using the N ciphertext shards of each of the K rounds; Generating the first proof includes: Generating corresponding N groups of verification values for the N nodes according to a first random value; Applying a target mapping function to the N groups of verification values, and the N ciphertext shards and N commitment values of each of the K rounds to obtain a first challenge value; For each node, aggregating the K original shards corresponding to the node in the K rounds of the first operation to obtain a plaintext aggregation shard of the node; generating a response value corresponding to the node according to the first random value, the plaintext aggregation shard and the first challenge value; Forming the first proof, which includes the first challenge value and the N response values corresponding to the N nodes.

2. The method according to claim 1, wherein, Generating the corresponding N ciphertext shards and N commitment values includes: Encrypting the N original shards respectively using the public keys of the N nodes to obtain the N ciphertext shards; Performing a predetermined mapping operation based on the N original shards to obtain the corresponding N commitment values.

3. The method according to claim 1, wherein, Generating corresponding N groups of verification values for the N nodes includes: For each node, generating a first verification value and a second verification value based on the first random value and the public key of the node, constituting a group of verification values of the node.

4. The method according to claim 1, wherein, Verifying the validity of all the ciphertext shards broadcast in the K rounds of the first operation specifically includes: For each node, generating a group of check values corresponding to the node according to the K ciphertext shards corresponding to the node in the N ciphertext shards of each of the K rounds and the response value corresponding to the node in the N response values; Performing a target mapping operation on the N groups of check values corresponding to the N nodes, and the N ciphertext shards and N commitment values of each of the K rounds to obtain a second challenge value; If the first challenge value is not equal to the second challenge value, the verification fails.

5. The method according to claim 4, wherein, Generating a group of check values corresponding to the node specifically includes: Aggregating the K ciphertext shards to obtain a ciphertext aggregation shard of the node; Aggregate the K commitment values corresponding to this node among the N commitment values of each of the K rounds to obtain the aggregated commitment value of this node; Generate a first verification value according to the response value and the aggregated commitment value of this node; Generate a second verification value according to the public key of this node, the response value and the ciphertext aggregated shards.

6. The method according to claim 1, wherein, The N original shards are obtained by substituting the node numbers of the N nodes into a first-degree first polynomial constructed based on the privacy value; Verify the validity of all ciphertext shards broadcast in the first operation of K rounds, including: For each node, generate the dual code corresponding to this node based on the node number of this node and a second-degree second polynomial; where the second degree and the first degree satisfy a preset relationship; Aggregate the combinations of the K-round commitment values of each node based on the dual codes of the N nodes to obtain an aggregated value; If the aggregated value is not equal to the predetermined target value, the verification fails.

7. The method according to claim 6, wherein, The first degree is t - 1, and the second degree is N - t - 1, where t is the number of allowed malicious nodes plus 1.

8. The method according to claim 1, wherein, The second node generates K random numbers corresponding to K rounds by using the N ciphertext shards of each of the K rounds, including: For any target round among the K rounds, the second node decrypts the ciphertext shard corresponding to this node in the N ciphertext shards of the target round, and incorporates the decryption result into the plaintext shard set of the second node; The second node decrypts the ciphertext shard corresponding to this node in the ciphertext shards from other nodes in the target round, and incorporates the decryption result into the plaintext shard set of the second node, where the other nodes are the nodes that have passed the validity verification; The second node broadcasts the plaintext shard set of the second node and obtains the plaintext shard sets of other nodes broadcast by other nodes; Generate the random number of the target round based on the plaintext shard set of the second node and the plaintext shard sets of other nodes.

9. The method according to claim 8, wherein, The second node generates K random numbers corresponding to K rounds by using the N ciphertext shards of each of the K rounds, and further includes: The second node receives the second proof broadcast by other nodes; The second node uses the second proof to verify whether the plaintext shard set of the other node is obtained by decrypting the ciphertext shard corresponding to this node by using its private key; Generating the random number of the target round includes: in the case where the above verification passes, generating the random number of the target round based on the plaintext shard set of the second node and the plaintext shard sets of other nodes.

10. The method according to any one of claims 1 - 9, wherein the N nodes are N blockchain nodes of a blockchain system, a single round corresponds to a block in the blockchain system, and the generated random number is used for transactions in this block.

11. The method according to claim 10, wherein, The first nodes execute different nodes of the K rounds of the first operation in parallel, and / or the second nodes execute different stages of generating K random numbers corresponding to the K rounds in parallel, so that K random numbers corresponding to the K rounds are generated at the block production times of the corresponding K blocks.

12. A method for multi-party collaborative generation of random numbers, where the multi-party includes N nodes, and the method is executed by any first node among the N nodes. It includes: Executing K rounds of the first operation, where a single round of the first operation includes generating N original shards corresponding to the N nodes according to the private value held by the first node, and generating corresponding N ciphertext shards and N commitment values; broadcasting the N ciphertext shards and the N commitment values; where K is greater than 1. Generating a first proof according to the N original shards, N ciphertext shards and N commitment values of each of the K rounds. Broadcasting the first proof, so that any second node among the N nodes uses the first proof to verify the validity of all the ciphertext shards broadcast in the K rounds of the first operation, and in the case where the validity verification passes, uses the N ciphertext shards of each of the K rounds to generate K random numbers corresponding to the K rounds; the validity verification includes: verifying through a verification polynomial that the original shards corresponding to the ciphertext shards in each round can recover a unique private value. Generating the first proof includes: Generating corresponding N groups of verification values for the N nodes according to a first random value. Applying a target mapping function to the N groups of verification values, and the N ciphertext shards and N commitment values of each of the K rounds to obtain a first challenge value. For each node, aggregating the K original shards corresponding to the node in the K rounds of the first operation to obtain a plaintext aggregation shard of the node; generating a response value corresponding to the node according to the first random value, the plaintext aggregation shard and the first challenge value. Forming the first proof, which includes the first challenge value and the N response values corresponding to the N nodes.

13. A system for collaborative generation of random numbers, the system includes N nodes, and the N nodes include a first node and a second node. Wherein: The first node is used to execute K rounds of the first operation, where a single round of the first operation includes generating N original shards corresponding to the N nodes according to the private value held by the first node, and generating corresponding N ciphertext shards and N commitment values; broadcasting the N ciphertext shards and the N commitment values; where K is greater than 1. The first node is further used to generate a first proof according to the N original shards, N ciphertext shards and N commitment values of each of the K rounds, and broadcast the first proof. The second node is used to use the first proof to verify the validity of all the ciphertext shards broadcast in the K rounds of the first operation. The validity verification includes: verifying through a verification polynomial that the original shards corresponding to the ciphertext shards in each round can recover a unique private value. The second node is further used to, in the case where the validity verification passes, use the N ciphertext shards of each of the K rounds to generate K random numbers corresponding to the K rounds. Generating the first proof includes: Generating corresponding N groups of verification values for the N nodes according to a first random value. Apply a target mapping function to the N sets of verification values, as well as the N ciphertext shards and N commitment values for each of the K rounds, to obtain a first challenge value; For each node, aggregate the K original shards corresponding to the node in the K rounds of the first operation to obtain a plaintext aggregation shard for the node; generate a response value corresponding to the node according to the first random value, the plaintext aggregation shard, and the first challenge value; Form the first proof, which includes the first challenge value and the N response values corresponding to the N nodes.

14. A device for multi-party collaborative random number generation, where the multi-party includes N nodes, and the device is deployed in any first node among the N nodes. The device comprises: A first operation unit configured to perform K rounds of a first operation, where a single round of the first operation includes generating, according to a privacy value held by the first node, N original shards corresponding to the N nodes, and generating corresponding N ciphertext shards and N commitment values; broadcasting the N ciphertext shards and the N commitment values; where K is greater than 1; A proof generation unit configured to generate a first proof according to the N original shards, N ciphertext shards, and N commitment values for each of the K rounds; A broadcasting unit configured to broadcast the first proof, such that any second node among the N nodes uses the first proof to verify the validity of all the ciphertext shards broadcast in the K rounds of the first operation, and, in the case where the validity verification passes, generate K corresponding random numbers for the K rounds using the N ciphertext shards for each of the K rounds; the validity verification includes: verifying, through a verification polynomial, that the original shards corresponding to the ciphertext shards in each round can recover a unique privacy value; The proof generation unit is specifically configured to generate corresponding N sets of verification values for the N nodes according to a first random value; apply a target mapping function to the N sets of verification values, as well as the N ciphertext shards and N commitment values for each of the K rounds, to obtain a first challenge value; for each node, aggregate the K original shards corresponding to the node in the K rounds of the first operation to obtain a plaintext aggregation shard for the node; generate a response value corresponding to the node according to the first random value, the plaintext aggregation shard, and the first challenge value; form the first proof, which includes the first challenge value and the N response values corresponding to the N nodes.

15. A computing device, comprising a memory and a processor, wherein, executable code is stored in the memory, and when the processor executes the executable code, the method described in any one of claims 1 - 11 is implemented.

Citation Information

Patent Citations

  • Random number generation method and device and storage medium

    CN110213059A

  • Random number generation method and system

    CN110737424A