Method for privacy transaction record in environmental protection and logistics scenarios

By combining blockchain technology and cryptography, a tabular ledger structure and range proof algorithm were designed to solve the problems of transaction amount privacy protection and verification efficiency. This enabled the anonymization and legality verification of transaction amounts in environmental protection and logistics scenarios, thereby improving transaction processing efficiency.

CN115204877BActive Publication Date: 2026-01-27NANKAI UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210881915.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-26
Publication Date
2026-01-27
Estimated Expiration
2042-07-26

AI Technical Summary

Technical Problem

Existing transaction recording schemes cannot effectively hide transaction amounts, making it impossible for transaction verifiers to directly verify the validity of transactions and failing to guarantee the balance of transaction amounts. This is especially problematic in environmental protection and logistics scenarios where privacy protection is required.

Method used

By combining blockchain technology with commitment and range proof techniques in cryptography, a tabular ledger structure is designed. The range proof algorithm using Bulletproof and Borromean ring signatures is used to anonymize and hide transaction amounts, and the verification efficiency is improved by aggregating range proofs.

Benefits of technology

It achieves anonymization and privacy protection of transaction amounts in environmental protection and logistics scenarios, while also enabling online verification of the legality of transaction amounts, ensuring that transaction amounts are within the specified range, and improving the efficiency of transaction verification and the system's transaction processing capacity per second.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115204877B_ABST
    Figure CN115204877B_ABST
Patent Text Reader

Abstract

A privacy transaction record method in an environmental protection and logistics scene; based on blockchain technology, each participating entity is regarded as a node in the blockchain network, and different nodes are divided into three types according to the environmental protection and logistics scene: management node, agent node and user node, each node independently maintains a local account book, and the account book contains all transaction records; design a ledger structure and transaction content that hides the entity identity and transaction amount, and design a corresponding transaction verification and auditing method to ensure that the total amount of outgoing transactions of the agent node and the user node is controllable, and the transaction income and expenditure are balanced; design a range proof aggregation method based on dynamic programming algorithm, and further use the greedy strategy for optimization according to the characteristics of Bulletproof aggregation proof, fully utilize the characteristics of different range proof algorithms, and obtain the lowest average single range proof verification time by properly selecting the combination scheme of aggregation proof, realize efficient transaction verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of transaction record processing technology in the Internet context, specifically to a transaction record method with anonymity and transaction amount concealment functions. Background Technology

[0002] With the development of internet technology, the trend of digitizing transaction records has become apparent. Digital transaction records offer strong anti-counterfeiting capabilities and high convenience, showing promising application prospects in scenarios such as logistics, power resource procurement, and carbon emissions. Unlike current centralized forms of digital transaction records, decentralized transaction records based on blockchain technology do not rely on any authoritative institution to complete the flow of transactions. The transactions proceed according to predetermined logic within the system and cannot be controlled by any centralized institution.

[0003] However, in real-world scenarios, the flow of transaction records is often dominated by centralized nodes or institutions, resulting in different types of institutions with corresponding functions. In the scenario of carbon emission quota allocation, the environmental management department determines the total emission quota for each environmental department under its jurisdiction, meaning it can "create transferable transaction records out of thin air." Each environmental department receives its quota from the environmental management department and allocates it to its subordinate key enterprises. Similarly, similar node classifications exist in logistics and transportation scenarios. Specifically, a goods factory manufactures materials, meaning it can "create transferable transaction records out of thin air." The factory transports its produced materials to logistics operation centers, and the materials can also circulate between these centers. The recipient can receive materials from various logistics operation centers. Most existing transaction record schemes do not clearly classify system participants based on these characteristics, nor define the functional responsibilities of each participant. Referring to most current systems that require recording transaction flows, participant roles can be divided into three types: management nodes, agent nodes, and other participants, referred to as user nodes. As the original trusted entity, the management node can generate transaction records out of thin air. The proxy node accepts the transaction quota allocated to it by the management node, and then breaks down these large transaction records and transfers them to other user nodes, realizing the transfer of transaction quotas between different levels.

[0004] In real-world scenarios, transaction records often require privacy protection. A method needs to be designed to ensure the privacy of specific amounts, flow directions, and the identities of participating nodes, especially the concealment of transaction amounts. Concealing transaction amounts introduces several problems, the most significant being that transaction verifiers cannot directly verify transaction validity using plaintext transaction amounts. Therefore, it is necessary to prove the conservation of transaction amounts in each transaction record and that the total outflow of transaction amounts for each participating entity is controlled. Existing transaction amount concealment schemes typically use commitments, while range proof algorithms are used to generate proofs that transaction amounts are within a certain specified limit. Summary of the Invention

[0005] The purpose of this invention is to design a transaction recording method with anonymity and transaction amount concealment, suitable for environmental protection and logistics scenarios. It can control the total transaction amount flowing out of the agent node while hiding the entity's identity and transaction amount, and can verify in a short time whether the transaction amount in a transaction is within the remaining transaction amount of the transaction initiator.

[0006] Technical solution of the present invention

[0007] To achieve the above objectives, this invention provides a privacy-preserving transaction recording method for environmental protection and logistics scenarios, concealing the identities of participating entities and transaction amounts. This method utilizes the transaction initiation, verification, and consensus processes of blockchain technology to realize the flow of transaction records. It uses a tabular ledger to anonymize the identities of participating entities and employs cryptographic techniques such as commitment and range proof to hide the transaction amounts within the records. This encrypted transaction flow record is then stored on the blockchain. This invention designs transaction content that hides transaction amounts and a ledger structure for recording transaction flow. Based on the ledger structure and transaction content, it designs transaction initiation and verification methods. Using existing consensus processes, such as PBFT, it achieves a transaction recording method with anonymity and transaction amount concealment. Furthermore, based on the ledger structure and transaction content, this invention also designs a transaction auditing method, allowing any entity to publicly verify that the total output transaction amount of the proxy node and user node does not exceed their total input transaction amount.

[0008] The present invention provides a method for recording privacy transactions in environmental protection and logistics scenarios. This method is applied to the carbon neutrality authorization trading scenario in the environmental protection field, for recording the authorization and trading of carbon emissions between various entities, or to the parcel transfer scenario in the logistics field, for recording the transfer information of each parcel, while maintaining the anonymity of participating entities and the concealment of carbon emission authorization trading or parcel transfer records, while allowing public verification of the conservation of the confidential transaction amount in each transaction record and ensuring that the confidential transaction amount is within a limited range.

[0009] The method employs a three-layer blockchain-based architecture, mapping each participating entity to a node in the blockchain network. Each participating entity independently maintains a tabular local ledger, where each row represents a transaction record and each column represents a participating entity or other transaction information. A local ledger contains multiple transactions, and each transaction flow record constitutes a transaction in the local ledger. This invention categorizes all nodes into three types: management nodes, agent nodes, and user nodes. The management node corresponds to the ecological environment management department in an environmental protection scenario or a goods factory in a logistics scenario. The management node initiates transactions with agent nodes as recipients and can allocate transaction quotas to each agent node. The total transaction quota received by the management node (i.e., its total input transaction quota) can be less than the total transaction quota sent by the management node (i.e., its total output transaction quota). The management node can create transaction quotas. Agent nodes correspond to various ecological environment management departments in environmental protection scenarios or logistics transfer centers in logistics scenarios. User nodes correspond to key enterprises in environmental protection scenarios or recipients in logistics scenarios. Within their allocated transaction quotas, agent nodes and user nodes transfer a portion of their allocated quotas to other nodes. Of the three node types, the management node is the original trusted entity in the system. Transactions initiated by it are treated specially. Provided valid identity verification is provided, the output amount of a transaction initiated by the management node is allowed to exceed the input amount in that transaction; that is, the management node can create transaction flow quotas. The management node allocates transaction quotas to proxy nodes by initiating a transaction with the proxy node as the recipient. Proxy nodes with remaining transaction quotas can initiate transactions, and identity verification is also required when initiating a transaction. Similarly, user nodes with remaining transaction quotas can also initiate transactions, but identity verification is not required. In summary, the flow of transaction quotas can be represented by a flow network. Each node in this flow network is allowed to have input and output streams, and only the sum of all output streams of the management node is allowed to exceed the sum of all its input streams to complete the process of generating transaction quotas.

[0010] The following sections will first describe the ledger structure and transaction details, followed by a description of the specific methods for recording and auditing transactions.

[0011] The ledger structure is tabular, with each row representing a transaction record and each column representing the transaction content or other transaction-related information for a participating entity, such as a transaction timestamp and transaction number. Within each transaction record, the transaction content for each participating entity includes a confidential transaction amount and a series of proofs. Under this ledger structure, although the system participating entity corresponding to each column is definite, the specific correspondence between each column and the system participating entity is obfuscated. The identity of a participant cannot be determined by analyzing the relationships between transaction records, thus achieving entity anonymity.

[0012] Each participating entity's transaction content includes a secret transaction amount and a series of proofs. These proofs verify that a transaction's income and expenditure are balanced and that the transaction amount does not exceed the transaction initiator's remaining total transaction limit, thus achieving the characteristic of transaction amount concealment. For each transaction i, system participant P... j The transaction content corresponding to column j (j = 0, 1…n, where n is the number of system participants) includes:

[0013] (1) Regarding the transaction amount v i,j promise Where r i,j is a random value, and g and h are elements in the elliptic curve additive group;

[0014] (2)Π i,j A set of proofs that can be used to prove that the current transaction amount of the proxy node is within the limit of node P. j Within the remaining transaction limit and the transaction is not forged. When the initiator of transaction i is the management node, if the management node is P j Other nodes are P j' ,∏ i,j Includes an identity verification code (IdentityProof) i,j , Π i,j' Includes a new commitment value, BalanceComm i,j' A range proof RangeProof i,j' When the initiator of transaction i is a proxy node, for any node P j , Π i,j Includes a new commitment value, BalanceComm i,j A range proof RangeProof i,j and the IdentityProof provided by the proxy node i,j When the initiator of transaction i is a user node, for any node P j Π i,j It is a new commitment value, BalanceComm. i,j A range proof RangeProof i,j Among them, IdentityProof i,j Use entity P j Private key generation using P j Public key verification for BalanceComm. i,j and RangeProof i,j When Comm i,j (v i,j ,r i,j v in ) i,jWhen it is greater than 0, BalanceComm i,j Use a new random value for v i,j Make another commitment, that is, BalanceComm i,j : = Comm i,j (v′ i,j , r' i,j ), v′ i,j = v i,j , range proof RangeProof i,j Prove that v′ i,j belongs to [c, d), where both c and d are positive integers and c < d; when Comm i,j (v i,j , r i,j ), v i,j is less than 0, BalanceComm i,j Calculate the commitment of the sum of the j - th column, BalanceComm i,j : = Comm i,j (v' i,j , r' i,j ), v′ i,j = ∑ j v i,j , range proof RangeProof i,j Prove that v′ i,j belongs to [c, d). v' i,j belongs to [c, d), that is, v i,j ' belongs to [c, c + 2 s ) and does not belong to [d, d + 2 k ), where c, d, s are all positive integers and c < d, c + 2 s < d + 2 s . Therefore, to prove that the transaction amount v′ i,j belongs to [c, d) using the Bulletproof range proof algorithm, two proofs are needed: prove that v' i,j belongs to the interval [c, c + 2 s ), and prove that v′ i,j does not belong to the interval [d, d + 2 k ).

[0015] The commitments in a transaction record i form a proof that ∑ i v i,j = 0 in the current transaction i, that is, the sum of the transaction amounts hidden by all commitments in the i - th row is 0. This proof does not require additional data filling and calculation, but only depends on the selection of the random number r i,j . The verifier calculates the sum of the commitments in transaction i, CommSum i=Comm(∑ i v i,j ,∑ i r i,j ), by CommSum i The value is compared with the expected value, that is, the ∑ is verified. i v i,j =0.

[0016] To achieve transaction limit concealment and efficient transaction verification, this invention combines a Borromean ring signature-based range proof algorithm and a Bulletproof range proof algorithm. All range proofs in each transaction i are aggregated into one or more aggregated range proofs, and the verification of these aggregated range proofs replaces the verification of individual range proofs. For example... Figure 10 As shown, when the number of aggregations exceeds four, the average verification time of a single proof using Bulletproof is superior to that of a range proof scheme based on Borromean ring signatures. Since the number of aggregations that makes Bulletproof's single proof verification time less than that of a range proof based on Borromean ring signatures (or a zk-SNARK-based proof) varies with the device, more generally, let's assume that the number of aggregations that makes Bulletproof's single proof verification time less than that of a single range proof based on Borromean ring signatures is two. b , where b is an integer and b≥0. Therefore, when the number of system participants is at least 2 b At this time, both the Bulletproof range proof algorithm and the Borromean ring signature-based range proof algorithm will be used simultaneously to prove the range proof for each entity in each transaction i. i,j (j = 0, 1, ..., n), carefully select the number of range proofs to be aggregated, obtain one or more aggregated range proofs and one or more Borromean-based range proofs, and obtain a range proof set RangeProof. i When the number of system participants is less than 2 b When using only the Borromean-based range proof algorithm, the range proof RangeProof for each entity in transaction i is calculated. i,j The range of proof set (j = 0, 1, ..., n) is composed of the rangeProof set. i .

[0017] Aggregation is performed using the Bulletproof range proof algorithm, and the number of aggregated proofs must be a power of two. Therefore, an allocation scheme is used to aggregate range proofs in a larger system. For a system with n participants, the aggregation method is described as follows: It is easy to see that the integer n can be represented in binary form: n = a0 + a1*2 + a2*2 2 +...+a l *2 l (a0, a1, ..., a l ∈Z and 0 < n < 2 l+1 It is obvious that in order to use the aggregation function of the Bulletproof range proof algorithm, a total of n = a0 + a1 + ... + a l An aggregate proof, where a l The corresponding aggregation proof is 2. l An aggregation of the original proofs. Therefore, for a given number of participants, n = a0 + a1*2 + a2*2 2 +...a l *2 l The system uses a b +a b+1 +...+a l A series of aggregated Bulletproof range proofs, and a0+…+a b-1 t*2 b-1 A range proof based on Borromean ring signatures. The number of original proofs in the Bulletproof proof aggregation varies, and the average verification time of a single proof also varies. For an aggregation of 2... k An aggregated proof of a number of original Bulletproof range proofs, assuming the average verification time of a single proof is t. k (k = 1, 2, ..., l, t) k The value ranges from approximately 0.1ms to 50ms. The range proof verification time for a single Borromean ring signature is t (t is approximately 20ms). Therefore, under this aggregation scheme, a total of n = a0 + ... + a b-1 *2 b-1 +a b *2 b +...+a l *a l For a system that provides a primitive range proof, only a0t+...+a b-1 t*2 b-1 +a b t b 2 b +...a l t l 2 lThe total verification time.

[0018] Using a range proof aggregation method based on the dynamic programming algorithm, solve for a0, a1, a2, ..., a l Aggregate multiple original range proofs to achieve the purpose of efficient transaction verification. Solve for a0, a1, a2, ..., a under the following constraints and solution objectives l

[0019] Constraint: n = a0 + a1 * 2 + a2 * 2 2 +... + a l * 2 l

[0020] a0, a1, ..., a l ∈Z.

[0021] Optimization objective: minimize a0 +... + a b-1 t * 2 b-1 + a b t b 2 b +... + a l t l 2 l

[0022] This problem can be regarded as a variant of the complete knapsack problem, and this problem can be transformed into: There is now a knapsack that can hold a weight of n, and there are l different items. For each item k, its weight is 2 k , when k < b, the value of the item is t2 k , when k ≥ b, the value of item k is t k 2 k , each item has an infinite number of pieces, and the goal is to obtain the minimum total value of items when the knapsack is exactly full. Solve this problem, use V(w) to represent the minimum transaction verification time obtained after aggregating w range proofs. The recurrence formula is:

[0023] V(w) = min{v(w - 1) + t,..., V(w - 2 b-1 ) + 2 b-1 t, V(w - 2 b ) + t b 2 b ,..., V(w - 2 l ) + t l 2 l};

[0024] V(0) = 0.

[0025] Using the above recursive formula, we can calculate the value of V(w) when w = n, and record the values ​​a0, a1, a2, ..., a l The values ​​of a0, a1, a2, ..., a can be obtained in polynomial time. l This minimizes the verification time of a transaction while obtaining a set of aggregated range proofs. The set of aggregated range proofs for transaction i is denoted as RangeProof. i , stored in the transaction does not correspond to any participating entity in a column.

[0026] like Figure 10 As shown, in Bulletproof range proofs, when the number of aggregate proofs is within 64, the more aggregate proofs there are, the shorter the average verification time required per proof. Furthermore, when the number of aggregate proofs is less than 2... b ( Figure 10 When testing on the demonstrated device yielded b=2 results, the average verification time per proof for range proofs based on Borromean ring signatures was lower than that for Bulletproof. If a pattern exists where, in Bulletproof range proofs, the average verification time per proof gradually decreases as the number of aggregated proofs increases, then the knapsack problem can be further simplified, and a greedy strategy can be used to solve the problem for a0, a1, a2, ..., a l Solve for it.

[0027] In the solution based on a greedy strategy, the recurrence relation is as follows:

[0028]

[0029] V(0)=0.

[0030] Using the above recurrence relation, compared to solving the complete knapsack problem, it is possible to solve for a0, a1, a2, ..., a... more efficiently. l .

[0031] Each node can participate in transaction initiation, transaction verification, and consensus processes to record transactions. After the transaction record is completed, any entity can participate in the transaction audit process to audit the transaction records of proxy nodes and user nodes.

[0032] The transaction recording steps of the method include:

[0033] (1) Transaction Initiation: The transaction initiation process is completed by the node that initiates the transaction. Specifically, during the transaction initiation process, the node fills in the transaction content according to its own node type and transaction amount. After the content is filled in, the transaction is broadcast to the blockchain network. For the content to be filled in for each transaction, please refer to the introduction of the above transaction content. Figure 3It demonstrates the process of filling in a transaction;

[0034] (2) Transaction Verification: The transaction verification process is completed by each node. Specifically, they verify the validity of each received transaction. Valid transactions enter the consensus process, while invalid transactions are discarded. During transaction verification, when verifying transactions initiated by the management node, it is only necessary to verify each π. i,j Effective. When verifying transactions initiated by proxy nodes and user nodes, it is necessary to verify and prove each Π. i,j With proof Valid. Specifically, using aggregated range proofs, the verification of transaction i can utilize the aggregated range proof set RangeProof for the transaction. i Verification, instead of verifying each participating entity P j The corresponding proof ∏ i,j Therefore, there are two methods to verify each Π, which is a range proof. i,j Valid: (1) For each participating entity P in transaction i j Verify the Π in its cell. i,j Effective for every Π i,j RangeProof included i,j Verification alone is inefficient; (2) First verify the aggregate range proof set RangeProof in transaction i. i Valid, then for each participating entity P j Verify the Π in its corresponding cell. i,j This method is highly efficient in proving the validity of all proofs except for the range proof. Figure 4 It demonstrates the verification process of a transaction;

[0035] (3) Consensus process: The consensus process is completed by the management node and the proxy node. The present invention does not limit the specific consensus method. Optionally, different consensus algorithms such as PBFT can be used to complete the consensus process. After the consensus process, a transaction is finally added to the local ledger by each node and the transaction record is successfully completed.

[0036] The transaction audit process is as follows:

[0037] In transaction auditing, audit agent node P j At that time, based on P in each transaction i preceding transaction k j Column commitment Comm k,j (v k,j ,r k,j Proof of transaction i i,j Verify the transaction amount v in the historical commitment. k,j The promise of summation equals Πi,j New commitments in the middle, and Π i,j The range proof in the proof is valid, and this operation can be completed without opening the commitment.

[0038] To provide sufficient privacy guarantees, the tabular distributed ledger proposed in this invention will consume a large amount of storage space. To reduce space consumption, the cells occupied by entities that did not participate in the transaction can be compressed and omitted, thus transforming the tabular ledger into a linked list-based ledger. Conversely, in each cell, a record of the entity number corresponding to that cell is added.

[0039] Advantages and beneficial effects of the present invention:

[0040] The tabular ledger designed in this invention can anonymize the identities of each participating entity, hide the amount in the transaction record, and ensure the correct flow of transaction records in a confidential state. It also allows each node to publicly and online audit the transaction flow process between agent nodes and user nodes. For environmental protection and logistics scenarios, this invention divides different participating entity types. Compared with the design where all entities have the same function, this invention can be better applied to carbon emission quota allocation and transaction record scenarios in the environmental protection field, as well as material flow record scenarios in the logistics field.

[0041] This invention integrates the range proof scheme based on ring signatures and the Bulletproof range proof scheme, and provides an aggregation method for range proofs, which can achieve a lower average time required for verifying a single proof, improve the verification efficiency of a single transaction, and increase the number of transactions processed per second of the system. Attached Figure Description

[0042] Figure 1 The present invention provides ledger design and transaction content design diagrams, demonstrating the ledger design style and different contents in different transactions, as well as the transaction data required for transaction verification and transaction auditing.

[0043] Figure 2 Commonly used symbols and descriptions in this invention are given.

[0044] Figure 3 A flowchart of a transaction filling in an environmental protection or logistics scenario is provided.

[0045] Figure 4 A flowchart of a transaction verification under an environmental or logistics scenario is provided.

[0046] Figure 5 A diagram showing the correspondence between the various node types in this invention and the nodes in the environmental protection scenario is provided.

[0047] Figure 6 A transaction flow example diagram of the present invention in an environmental protection scenario is provided.

[0048] Figure 7 A diagram showing the correspondence between the various node types in this invention and the nodes in the logistics scenario is provided.

[0049] Figure 8 A transaction flow example diagram of the present invention in a logistics scenario is provided.

[0050] Figure 9 The computation time test results of the range proof algorithm based on Borromean ring signature used in this invention are presented.

[0051] Figure 10 The paper presents a comparison between the verification time of a single proof obtained by the SM2-based Bulletproof range proof algorithm used in this invention and the verification time of a single proof by the Borromean ring signature-based range proof algorithm. Detailed Implementation

[0052] Example 1:

[0053] The specific embodiments of the present invention will now be described in conjunction with the accompanying drawings.

[0054] like Figure 1 The diagram illustrates the main aspects of the transaction recording method in this invention, including the design of the ledger structure and transaction content, as well as examples of transaction content required for transaction verification and auditing. Each transaction record on the ledger is written into the ledger after the transaction initiation and verification process, becoming a valid transaction record. The auditing process can occur at any time after a transaction is written into the ledger and can be publicly verified by any node.

[0055] like Figure 2 The following describes the symbols commonly used in this invention.

[0056] like Figure 6 The image shows an embodiment of the present invention in an environmental protection scenario, as follows: Figure 8 The illustration shows an embodiment of the present invention in a logistics scenario. In this embodiment, the maximum allowed transaction amount is limited to 2. 32 Among them, the proof of Π i,j It is a set of multiple other proofs, such as Figure 6 and Figure 8 In the embodiments, it is not indicated separately, except for the commitment Comm i,j (v i,j ,r i,j All data other than ) belongs to the proof of Π i,j ;prove By the commitment Commi,j Homomorphic summation is completed without requiring additional data, such as... Figure 6 and Figure 8 The embodiments are not specifically mentioned here. The following will first describe... Figure 6 The illustrated embodiments will be described in detail, followed by... Figure 8 The embodiments are described in detail below. Optionally, in the embodiment description, the consensus process in the transaction record uses the longest chain principle.

[0057] like Figure 5 The diagram illustrates the relationship between the various node types in this invention and the various entity types in an environmental protection scenario. It shows the correspondence between the node types proposed in this invention and the various institutions involved in the carbon emission trading scenario when applied to the carbon emission trading scenario. Specifically, the management node corresponds to the ecological and environmental management department, responsible for formulating carbon emission quota allocation methods and setting approximate carbon emission amounts for each ecological and environmental department. The agent node corresponds to each ecological and environmental department, responsible for allocating and adjusting carbon emission quotas for its key subordinate enterprises. The user node corresponds to each key enterprise, accepting the carbon emission quotas assigned to it by the ecological and environmental department and able to trade carbon emission amounts with each other. The carbon emission quota and trading volume are collectively referred to as carbon trading quota, which corresponds to the trading quota in this invention. Using the auditing method of this invention, ecological and environmental management departments are allowed to conduct carbon emission quota audits on various ecological and environmental departments, ensuring that the carbon emission quotas allocated by each ecological and environmental department to its key enterprises are less than or equal to the permitted allocation quotas, thus avoiding excessive carbon emission allocation. The method also allows for auditing of the carbon emission trading volume of each key enterprise, ensuring that its carbon emission trading volume is within its total carbon emission volume and that there is no carbon emission exceeding the standard.

[0058] like Figure 6 In the illustrated embodiment, three transaction records were completed in the environmental protection scenario: Transaction 0 (Txid=0), Transaction 1 (Txid=1), and Transaction 2 (Txid=2). The initiators of these transactions were the ecological and environmental management department, the ecological and environmental department in charge, and a key enterprise, respectively. The transaction recording process for each transaction is described below, followed by an example of the audit process for the ecological and environmental department in charge (P1).

[0059] like Figure 6 As shown, in transaction 0, the ecological and environmental management department P0 allocates 1P1400 units of carbon emission credit to the ecological and environmental sub-department, and 2P2600 units of carbon emission credit to the ecological and environmental sub-department. The transaction recording process for transaction 0 is as follows:

[0060] (1) Initiation of Transaction 0: The initiator of Transaction 0, the ecological environment management department P0, first calculates the transaction amount protected in each commitment based on the transaction amount of this transaction, i.e., v. 0,0 =-1000,v 0,1 =400,v 0,2 =600,v 0,3 =v 0,4 =0, then generate a random number r 0,0 ,r 0,1 ,r 0,2 ,r 0,3 ,r 0,4 , making r 0,0 +r 0,1 +r 0,2 +r 0,3 +r 0,4 =0, then use Pedersen commitments to encrypt each transaction amount value, representing the commitment as Comm(-1000,r) 0,0 Comm(400,r) 0,1 Comm(600,r) 0,2 Comm(0,r) 0,3 Comm(0,r) 0,4 After the calculation is complete, fill the five data points into the corresponding cells; then, P0 generates an IdentityProof for itself. 0,0 Then, P0 calculates v' and fills it into its own column; subsequently, P0 calculates v' respectively. 0,1 ,v' 0,2 ,v' 0,3 With v' 0,4 , respectively v' 0,1 =v' 0,2 =400, v' 0,3 =600, v' 0,4 =0, and also encrypt them using Pedersen commitments to obtain BalanceComm(v' 0,1 ,r' 0,1 BalanceComm(v' 0,2 ,r' 0,2 BalanceComm(v' 0,3 ,r' 0,3 ) and BalanceComm(v' 0,4 ,r' 0,4 The values ​​are filled into the corresponding transaction cells P1, P2, P3, and P4 respectively. Finally, P0 generates a range proof RangeProof(v') using a range proof algorithm based on Bulletproof ring signatures. 0,1 RangeProof(v'0,2 RangeProof(v' 0,3 ) and RangeProof(v' 0,4 Prove v' 0,1 ,v' 0,2 ,v' 0,3 With v' 0,4 Within the range [0,2 32 In this process, the four range proofs are aggregated to obtain RangeProof0, which is then filled into transaction 0. At this point, as shown... Figure 3 As shown, the transaction filling process is complete, and all cells in transaction 0 except for the transaction ID and timestamp have been filled. Note that the proof of π... B The calculation can be performed using the commitment value, without storing any additional data. P0 then broadcasts transaction 0 to the other nodes.

[0061] (2) Verification of Transaction 0: After receiving Transaction 0 broadcast by P0, P1, P2, P3, and P4 only need to verify P0's IdentityProof. 0,0 Whether it is valid or not is sufficient. In this embodiment, each entity verifies that transaction 0 is valid.

[0062] (3) Consensus process for transaction 0: After P1, P2, P3, and P4 verify the validity of transaction 0, they add transaction 0 to their local ledgers. P0 directly adds transaction 0 to its local ledger.

[0063] like Figure 6 As shown, in Transaction 1, the ecological and environmental protection department 1P1 subsequently allocated a carbon emission quota of 200 to its key subordinate enterprise 1P3. The transaction record process for Transaction 1 is as follows:

[0064] (1) Initiation of Transaction 1: When P1 initiates this transaction, it is the same as Transaction 0, first calculates v 1,0 ,v 1,1 ,v 1,2 ,v 1,3 ,v 1,4 The value of is then used to generate a random number r. 1,0 ,r 1,1 ,r 1,2 ,r 1,3 ,r 1,4 Similarly, sum them up to 0, and use the Pedersen commitment scheme to calculate the commitment value Comm(0,r) for each entity. 1,0 ),Comm(-200,r 1,1 Comm(0,r) 1,2 Comm(200,r) 1,3 ) and Comm(0,r 1,4After the calculations are complete, the results are filled into the corresponding cells; subsequently, P1 generates an IdentityProof for itself. 1,1 Then, P1 calculates v' for each participant and fills it into its own column. 1,0 ,v' 1,1 ,v' 1,2 ,v' 1,3 With v' 1,4 , respectively v' 1,0 =0, v' 1,1 =200, v' 1,3 =200, v' 1,2 =v 1,4 =0. Use them to calculate new commitment values ​​and populate them separately for each entity; finally, P1 generates range proofs for all entities and aggregates them into RangeProof1, which is then populated into Transaction 1, and the populated Transaction 1 is broadcast to other nodes.

[0065] (2) Verification of Transaction 1: After receiving Transaction 1 broadcast by P1, P0, P2, P3, and P4 first verify the validity of the aggregate proof RangeProof1; then prove... It works. The proof is that each Comm(v) in a row... 1,j ,r 1,j Summing these values, we get Comm(0+(-200)+0+(200)+0,r) 1,0 The process involves verifying whether the value is 1. If it is 1, the verification passes; otherwise, the verification fails, and the transaction is invalid. Since the initiator of transaction 1 is P1, the initiator needs to prove the identity of its proxy node, thus requiring the verification of the IdentityProof function. 1,1 The validity of the identity document is checked. If the identity document is valid, the transaction is valid; otherwise, the transaction is invalid.

[0066] (3) Consensus process of transaction 1: After P0, P2, P3 and P4 verify the validity of transaction 1, they add transaction 1 to their local ledger. P1 directly adds transaction 1 to its local ledger.

[0067] like Figure 6 Transaction 2 is a transaction between key enterprise 1 under ecological and environmental protection department 1 and key enterprise 1 under ecological and environmental protection department 2 (a transaction between entities P3 and P4). The transaction recording process for Transaction 2 is as follows:

[0068] (1) Initiation of Transaction 2: P3 first calculates the commitment to the transaction amount for each transaction participant and fills it into the corresponding cell; then calculates the new commitment value and fills it; then P3 broadcasts the filled Transaction 2 to other nodes.

[0069] (2) Verification of Transaction 2: After P0, P1, P2, and P4 receive Transaction 2 broadcast by P3, as follows: Figure 4 In the transaction verification shown, in order to verify Figure 6 The verification method for Transaction 3 shown is similar to that of Transaction 1. First, it verifies the validity of the aggregation range proof, and then it proves... As long as it works.

[0070] (3) Consensus process of transaction 2: After P0, P1, P2 and P4 verify the validity of transaction 2, they add transaction 2 to their local ledger. P3 directly adds transaction 2 to its local ledger.

[0071] for Figure 6 Except for transaction 0, all other transactions can have their output transaction amounts audited. Taking transaction 1 as an example, to ensure that the calculated v' in transaction 1... 1,1 It is legal. The method for transaction auditing is: extract all Comm(v) values ​​from the cells corresponding to all entities P1 before transaction 1. i,1 ,r i,1 Summing again, and then combining the sum with BalanceComm(v') from transaction 1. 1,1 ,r' 1,1 The values ​​of ) are compared. If they are the same, the audit passes, indicating that the outflow transaction amount of entity P1 is less than the remaining transaction amount. In this embodiment, the commitments of all historical transactions of entity P1 are summed, that is, Comm(400, r) is calculated. 0,1 )+Comm(-200,r 1,1 =BalanceComm(v′) 1,1 ,r′ 1,1 =BalanceComm(200,r′) 1,1 ).

[0072] like Figure 7 The diagram shown illustrates the correspondence between the various node types proposed in this invention and the various institutions involved in logistics transportation when applied to a logistics transportation scenario. The management node corresponds to the goods production factory, which can create transaction quotas, i.e., create goods. The agent node corresponds to logistics transportation centers at various levels. These centers receive goods from the goods production factory and send them to other logistics transportation centers. One goods transfer corresponds to one transaction in this invention, and the number of transferred goods corresponds to the transaction quota. The user node corresponds to the recipient, who can accept goods from various logistics transportation centers, corresponding to the transaction from the agent node to the user node in this invention.

[0073] like Figure 8In the illustrated embodiment, three transaction records were completed in the logistics scenario: Transaction 0 (Txid=0), Transaction 1 (Txid=1), and Transaction 2 (Txid=2). Their initiators are the goods factory, logistics transfer center 1, and logistics transfer center 2, respectively, representing the production and transfer process from the factory to the logistics transfer center, the transfer process between logistics transfer centers, and the transfer process from the logistics transfer center to the recipient. The transaction record process for each transaction is described below.

[0074] like Figure 8 As shown, in transaction 0, the goods factory P0 first initiates a transaction 0 (Txid=0) to transfer 300 units of materials to logistics transfer center 1, i.e., P1. The transaction initiation process of transaction 0 is as follows:

[0075] (1) Initiation of Transaction 0: Similar to Figure 6 In the transaction filling process shown, P0 first calculates v 0,0 ,v 0,1 ,v 0,2 ,v 0,3 The value of is then used to generate a random number r. 0,0 ,r 0,1 ,r 0,2 ,r 0,3 And make r 0,0 +r 0,1 +r 0,2 +r 0,3 =0, calculate and populate the Pedersen commitment value for each of the four entities; subsequently, P0 generates an IdentityProof for itself. 0,0 Then P0 calculates v' for the other four entities respectively. 0,1 ,v' 0,2 ,v' 0,3 They then use these values ​​to calculate new commitment values ​​and fill them into the corresponding transaction cells of P1, P2, and P3 respectively. Finally, P0 generates range proofs for entities P1, P2, and P3 using a range proof algorithm based on Bulletproof ring signatures and aggregates them to obtain RangeProof0. Subsequently, P0 broadcasts the filled transaction 0 to other nodes.

[0076] (2) Verification of Transaction 0: After receiving Transaction 0 broadcast by P0, P1, P2, and P3 only need to verify P0's IdentityProof. 0,0 Whether it works or not is the only question.

[0077] (3) Consensus process of transaction 0: After P1, P2, and P3 verify the validity of transaction 1, they add transaction 1 to their local ledgers. P0 directly adds transaction 1 to its local ledger.

[0078] like Figure 8 As shown, in transaction 1, logistics transfer center 1, i.e., P1, subsequently transfers 300 units of goods to logistics transfer center 2, i.e., P2. The transaction record process of transaction 1 is as follows:

[0079] (1) Initiation of transaction 1: P1 calculates v 1,0 ,v 1,1 ,v 1,2 ,v 1,3 The value of is then used to generate a random number r that adds up to 0. 1,0 ,r 1,1 ,r 1,2 ,r 1,3 The Pedersen commitment scheme is used to calculate commitment values ​​for the four entities and fill them into the corresponding cells; then P1 generates an IdentityProof for itself. 1,1 Then, P1 calculates v' for each participant and fills it into its own column; subsequently, P1 calculates v' for each participant. 1,0 ,v' 1,1 ,v' 1,2 ,v' 1,3 They use these to calculate new commitment values ​​and populate them separately for each entity. Finally, P1 generates range proofs for all entities and aggregates them; then P1 broadcasts transaction 1 to the other nodes.

[0080] (2) Verification of Transaction 1: After receiving Transaction 1 broadcast by P1, P0, P2, and P3 first verify the validity of the aggregated proof IdentityProof1; then prove... Valid; finally, IdentityProof is proven. 1,1 The effectiveness.

[0081] (3) Consensus process of transaction 1: After P0, P2 and P3 verify the validity of transaction 1, they add transaction 1 to their local ledger. P1 directly adds transaction 1 to its local ledger.

[0082] like Figure 8 As shown, in transaction 2, P2 subsequently delivers 300 units of goods to recipient P3. The transaction record process for transaction 2 is as follows:

[0083] (1) Initiation of Transaction 2: When P2 initiates a transaction, it first calculates the commitment to the transaction amount for each participant and fills the corresponding cell. Then, it calculates and fills the new commitment value, and generates an identity verification. The verification method for this transaction is the same as that for Transaction 2: first, it verifies the validity of the aggregated range proof, and then it proves... Effective and IdentityProof 2,2 As long as it works.

[0084] (2) Verification of transaction 2: After P0, P1, and P3 verify that the transaction is valid, they add transaction 1 to their local ledger. P1 directly adds transaction 1 to its local ledger.

[0085] (3) Consensus process of transaction 2: After P0, P1 and P3 verify the validity of transaction 2, they add transaction 2 to their local ledgers. P2 directly adds transaction 2 to its local ledger.

[0086] Figure 8 Auditing methods for transactions in China and Figure 6 The audit process shown is the same.

[0087] Figure 9 This describes the proof generation and verification time using the SM3 hash algorithm and the Borromean ring signature-based range proof algorithm with the secp256k1 curve, under an Intel i7-8556U 1.80GHz processor, 8GB of memory, and a 64-bit Windows 10 operating system. The transaction amount is set to v∈[0,m]. U Let m = 2, and we select U = 16, 32, 48, and 64 respectively. It can be seen that the range proof algorithm implemented in this invention achieves a runtime in milliseconds. In this method, the range proof algorithm accounts for a very high percentage of the time consumption. Optimizing the range proof algorithm helps improve the throughput of the digital currency system and achieve a higher transaction throughput per second.

[0088] Figure 10 This invention compares the time cost of verifying a single proof using the SM2 public-key cryptography Bulletproof algorithm with the time cost of verifying a single range proof using the Borromean ring signature-based range proof algorithm. The test was conducted on an Intel i7-8556U 1.80GHz processor, 8GB of RAM, and a 64-bit Windows 10 operating system, requiring proof of a transaction amount v ∈ [0, 2]. 32 As can be seen, when the number of aggregates is small, the range proof algorithm based on Borromean ring signatures has an advantage in average verification time, while the advantage of the Bulletproof range proof algorithm becomes more prominent when the number of aggregate proofs increases.

[0089] References

[0090] [1] Bünz B, Bootle J, Boneh D, et al. Bulletproofs: Short proofs for confidential transactions and more[C] / / 2018 IEEE Symposium on Security and Privacy(SP). IEEE, 2018: 315 - 334.

[0091] [2] Sasson E B, Chiesa A, Garman C, et al. Zerocash: Decentralized anonymous payments from bitcoin[C] / / 2014 IEEE Symposium on Security and Privacy. IEEE, 2014: 459 - 474.

[0092] [3] Noether S, Mackenzie A. Ring confidential transactions[J]. Ledger, 2016, 1: 1 - 18.

[0093] [4] Camenisch J, Chaabouni R. Efficient protocols for set membership and range proofs[C] / / International Conference on the Theory and Application of Cryptology and Information Security. Springer, Berlin, Heidelberg, 2008: 234 - 252.

Claims

1. A method for recording privacy-preserving transactions in an environmental protection and logistics scenario, characterized in that, This method is applied to carbon neutrality authorization trading scenarios in the environmental protection field, to record the authorization and trading of carbon emissions between various entities, or to parcel transfer scenarios in the logistics field, to record the transfer information of each parcel, while maintaining the anonymity of participating entities and the concealment of carbon emission authorization trading or parcel transfer records, while allowing public verification that the confidential transaction amount in each transaction record is conserved and that the confidential transaction amount is within a limited range. The transaction recording steps of the method include: (1) Transaction Initiation: When any participating entity conducts a transaction, a new transaction is first constructed based on the node type of the transaction initiator and the transaction amount, which is the transaction initiation process; (2) Transaction verification: The new transaction is then broadcast to other nodes, and each node verifies the transaction. (3) Consensus process: If the transaction is verified to be valid, it enters the consensus process and is eventually added to the local ledger by each node, thus successfully completing the transaction record. The method employs a three-layer blockchain-based architecture, assigning each participating entity a node and categorizing all nodes into three types: management nodes, proxy nodes, and user nodes. Management nodes correspond to ecological and environmental management departments in environmental protection scenarios or goods factories in logistics scenarios. These management nodes allocate transaction quotas to each proxy node by initiating transactions with proxy nodes as recipients. The total transaction quota received by the management node (i.e., the total input transaction quota) can be less than the total transaction quota sent by the management node (i.e., the total output transaction quota). Management nodes can also generate transaction quotas. Proxy nodes correspond to various ecological and environmental management departments in environmental protection scenarios or logistics transfer centers in logistics scenarios. User nodes correspond to key enterprises in environmental protection scenarios or recipients in logistics scenarios. Proxy nodes and user nodes can transfer a portion of their allocated quota to other nodes within their total allocated transaction quota. Each node can participate in transaction initiation, verification, and consensus processes, and also audits transactions. Each participating entity maintains a separate tabular local ledger, with each row representing a transaction record and each column representing a participating entity or other transaction information.

2. The method for recording privacy-preserving transactions in environmental protection and logistics scenarios according to claim 1, characterized in that, The method for initiating transactions involves combining a ring signature-based range proof algorithm with a Bulletproof range proof algorithm to protect the privacy of transaction amounts during transaction filling. A dynamic programming-based combined method is proposed and implemented. This method leverages the advantages of Bulletproof aggregation proofs, creating one or more aggregation range proofs and one or more ring signature-based range proofs for each transaction. This minimizes the verification time for a single transaction, achieving an efficient transaction verification process. The range proof algorithm supports arbitrary ranges. The proof, in which .

3. The method for recording privacy-preserving transactions in environmental protection and logistics scenarios according to claim 2, characterized in that, The aforementioned transaction initiation steps include transaction information related to an entity or transaction information related to a transaction in each transaction; if only entity-related transaction information is considered, for each transaction... For a containing A system of entities, with entities participating in the system. The transaction details were filled into the column. In the middle, the transaction details include a transaction amount promise A proof of transaction balance and a set of proofs , This is used to prove that: the transaction has not been forged, and the total transaction amount flowing out of the node does not exceed the total transaction amount currently held by that node, or that the initiator of the transaction is a managing node; among different transaction types, The content is different.

4. The method for recording privacy transactions in environmental protection and logistics scenarios according to claim 3, characterized in that, The transaction verification method described above verifies the validity of a transaction initiated by the management node by verifying the aforementioned set of proofs. To verify the validity of transactions initiated by other nodes, it is necessary to verify the aforementioned transaction balance proof. With proof set Is it effective? 5. The method for recording privacy transactions in environmental protection and logistics scenarios according to claim 3, characterized in that, The aforementioned transaction auditing includes transaction auditing of proxy nodes and transaction auditing of user nodes. The method of transaction auditing is to audit transactions generated by a specific proxy node or user node. A transaction that initiates a transaction applies to any transaction that occurred before or included that transaction at that node. ,verify Commitments in the corresponding column homomorphism and With the transaction Committed value of remaining transaction amount The values ​​are the same, and the range proof is valid; therefore, we commit. Included in the proof set In the middle, it refers to the current account balance or the current transaction. The commitment to the inflow of transaction volume.