A method for constructing a stateless blockchain system with high efficiency, polymerization and maintainability
Patent Information
- Application Number
- CN202211329672.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-27
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2042-10-27
AI Technical Summary
然而现存向量承诺方案都不能同时满足上述四个性质
[0028]本发明提供了一种高效可聚合和可维护的构造无状态区块链系统的方法(称之为“Matproofs”),所公开的向量承诺方案同时满足了简洁性、可聚合性、简易可更新性和可维护性,有重要的研究价值和应用前景。
Smart Images

Figure CN115907980B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method for constructing a stateless blockchain system. Background Technology
[0002] Blockchain systems are widely used in daily life due to their decentralized nature. To confirm the validity of transactions, most current blockchain systems require validating nodes to maintain a massive verification state. For example, Ethereum requires a verification state size exceeding 130GB, and this continues to expand with the hundreds of thousands of new accounts added daily. The large size and continuous expansion of the verification state lead to numerous negative impacts, such as slow processes for new nodes to join the system, long read / write times for the transaction verification process, and even denial-of-service attacks.
[0003] Vector commitment is an important cryptographic primitive that allows provers to compute a cryptographic commitment to the state vector of a blockchain system and prove the values of certain elements in the vector as needed. It allows verifiers to perform rapid public verification using commitments and proofs, thus providing a beneficial trade-off between storage and other computational resources, enhancing system scalability, and effectively mitigating the effects of state bloat. In a stateless blockchain system based on vector commitments, to initiate a new transaction, the transactor needs to provide the account balance and proof of that balance. Upon receiving the transaction, the miner needs to verify the account balance according to the commitment. If the verification passes and the transaction amount is not greater than the account balance, the miner considers the transaction valid and adds the transaction and related proof to a new block. When the new block is accepted by a majority of nodes, the transaction becomes effective, the vector of account balances changes accordingly, and the vector commitment and balance proof must be updated accordingly.
[0004] A vector commitment scheme is concise if the size of the commitment and the size of a single proof are independent of the size of the vector. Such a scheme can reduce the size of transactions and blocks in a stateless blockchain system. A scheme is aggregatable if multiple individual proofs can be aggregated into a single proof (called an aggregated proof). Such a scheme can further reduce the size of blocks in a stateless blockchain system. When the vector changes, if the commitment and proof of the new vector can be computed from the commitment and proof of the old vector, and only the change in the vector and common parameters are needed in the computation, then the scheme is simple and updatable. With such a scheme, transactors in a stateless blockchain system do not need to communicate with recipients before transacting. If the time complexity of updating all proofs is sublinear to the size of the vector, then the scheme is maintainable. With such a scheme, all proofs can be updated efficiently after a vector change. Therefore, concise, aggregatable, simple and updatable, and maintainable vector commitment schemes can be used to construct stateless blockchain systems with lower communication and computational complexity. However, existing vector commitment schemes do not simultaneously satisfy all four properties. Summary of the Invention
[0005] The objective of this invention is to design a concise, aggregateable, easy-to-update, and maintainable vector commitment scheme for constructing stateless blockchain systems.
[0006] To achieve the above objectives, one technical solution of the present invention provides a method for constructing a matrix commitment model, characterized by comprising the following steps:
[0007] Step 1: Generate a bilinear group based on the selected safety parameter λ. Where p represents a prime number, Describe a group of order p. Describe a group of order p. Let p denote a group of order p, and e denote the group... and The elements in the Cartesian product are mapped to the group Bilinear mapping of elements in a meta-element, g1 representation group generator, g2 represents group The generator; the group is obtained based on the prime number p. From the group Randomly select values α and β to form a vector. and Where n1 represents the pre-selected number of matrix rows and n2 represents the pre-selected number of matrix columns; by group middle Hequn g2, The common parameter pp is formed, where α[-1] represents the new vector obtained by removing the first element from the vector α;
[0008] Step 2: Based on the common parameter pp, for any matrix Computational matrix commitment
[0009] Step 3: Based on the common parameter pp, for any (i,j)∈[n1]×[n2], when the value M ij Updated to M ij +δ, matrix commitment by Updated to Among them, M ij δ represents the element located in the i-th row and j-th column of matrix M, and δ represents the group. Any element in;
[0010] Step 4: Based on the common parameter pp, for any value M in matrix M ij Calculate a single proof Where: c i Indicates a partial commitment. M i ω represents the i-th row vector in matrix M; i Represents a single global proof. β[-i] represents the new vector obtained by removing the i-th element from vector β, and (Mα)[-i] represents the new vector obtained by removing the i-th element from vector (Mα); Ω ij This represents a single local proof. M i [-j] represents vector M i The new vector obtained by removing the j-th element, α[-j] represents the new vector obtained by removing the j-th element from vector α;
[0011] Step 5: Based on the common parameter pp, for any (i,j)∈[n1]×[n2] and (k,l)∈[n1]×[n2], when the value M ij Updated to M ij +δ, update a single proof
[0012] When k ≠ i, the new single global proof is updated as follows: Single proof Updated to
[0013] When k = i and l ≠ j, the new local commitment is updated to The new single local proof is updated to Single proof Updated to
[0014] When k = i and l = j, the new local commitment is updated to Single proof Updated to
[0015] Step 6: For any set If |S|=1, then directly verify the correctness of the values in matrix M. The verification process includes the following steps:
[0016] There exist (i,j)∈[n1]×[n2] satisfying S={(i,j)} and Then check the equation during the verification process. and If all conditions are met, the validation passes; otherwise, it fails. Here, g... T e(g1,g2) represents a bilinear mapping; e(·) represents a bilinear mapping e.
[0017] If |S|>1, then first prove multiple individual proofs. After aggregation, verify the correctness of the values in matrix M.
[0018] Preferably, in step 6, multiple individual proofs are... Aggregation includes:
[0019] Multiple global proofs Aggregated into in: Let {i|(i,j)∈S} be the expression; for all Hash value Calculated by a collision-resistant hash function H;
[0020] Aggregating multiple local proofs {Ω ij} (i,j)∈S First, for each calculate in: It means {j|(i,j)∈S} i}, where for any For all (i,j)∈S, the hash value Calculated by a collision-resistant hash function H″. Representation vector M i Subscript in set A new vector composed of the elements in the vector; then, calculate... Where: for each Hash value Calculated by a collision-resistant hash function H′ It means {j|(i,j)∈S}k}, where for any Representation vector M k Subscript in set A new vector composed of the elements in the middle;
[0021] The final aggregated result is proven to be
[0022] Preferably, in step 6, when |S|>1, verifying the correctness of the values in matrix M includes:
[0023] Then check the equation during the verification process. and If all conditions are met, the verification passes; otherwise, the verification fails.
[0024] Another technical solution of the present invention provides a method for constructing a stateless blockchain system that is efficient, aggregateable, and maintainable, characterized by comprising the following steps:
[0025] The balances of all accounts are organized into a matrix M;
[0026] When initializing the blockchain system, matrix M is set as the zero matrix. The matrix commitment model construction method described above is used to generate matrix commitments and proofs for the zero matrix. The matrix commitments are included in the blocks.
[0027] In order to transfer funds to others: the transferor needs to include its account balance and proof of that balance in its proposed transaction; the block proposer needs to use the matrix commitment model construction method described above to verify the transaction, aggregate individual proofs, and update the matrix commitment; the block proposer needs to include the valid transaction, the aggregated proofs, and the new matrix commitment in the newly proposed block; each validator uses the matrix commitment model construction method described above to verify the validity of the new block, and after the new block is verified, all proofs are updated.
[0028] This invention provides a method for constructing a stateless blockchain system that is efficient, aggregatable, and maintainable (referred to as "Matproofs"). The disclosed vector commitment scheme simultaneously satisfies simplicity, aggregatability, easy updability, and maintainability, and has significant research value and application prospects. Attached Figure Description
[0029] Figure 1 This illustrates how Matproofs generates matrix commitments and proofs for a 2x3 matrix;
[0030] Figure 2This illustrates how Matproofs constructs a stateless blockchain system based on an account model. Detailed Implementation
[0031] The present invention will be further illustrated below with reference to specific embodiments. It should be understood that these embodiments are for illustrative purposes only and are not intended to limit the scope of the invention. Furthermore, it should be understood that after reading the teachings of this invention, those skilled in the art can make various alterations or modifications to the invention, and these equivalent forms also fall within the scope defined by the appended claims.
[0032] This invention first proposes a method for constructing a matrix commitment model. The matrix commitment model can be viewed as a special vector commitment model that organizes vectors into a matrix. This matrix commitment model is introduced to propose Matproofs that simultaneously satisfy simplicity, assemblability, ease of updating, and maintainability.
[0033] Specifically, the matrix commitment model construction method proposed in this invention includes the following steps:
[0034] Step 1: Select the security parameter λ, the number of matrix rows n1, and the number of matrix columns n2. Generate a bilinear group based on the security parameter λ. Where p represents a prime number, Describe a group of order p. Describe a group of order p. Let p denote a group of order p, and e denote the group... and The elements in the Cartesian product are mapped to the group Bilinear mapping of elements in a meta-element, g1 representation group generator, g2 represents group The generators. The group is obtained based on the prime number p. From the group Randomly select values α and β to form a vector. and By group middle Hequn g2, The common parameter pp is formed, where α[-1] represents the new vector obtained by removing the first element from the vector α.
[0035] Step 2: Based on the common parameter pp, for any matrix Computational matrix commitment
[0036] Step 3: Based on the common parameter pp, for any (i,j)∈[n1]×[n2], when the value M ij Updated to M ij+δ, matrix commitment by Updated to Among them, M ij δ represents the element located in the i-th row and j-th column of matrix M, and δ represents the group. Any element in.
[0037] Step 4: Based on the common parameter pp, for any value M in matrix M ij A single proof can be calculated. The proof By local commitment c i Single global proof ω i and a single local proof Ω ij Composition. Partial commitment Depends on M i , of which M i Let represent the i-th row vector in matrix M. Single global proof. Depends on M\M i It can be faced Prove c i The correctness of , where β[-i] represents the new vector obtained by removing the i-th element from vector β, and (Mα)[-i] represents the new vector obtained by removing the i-th element from vector (Mα). Single local proof Depends on M i [-j] can be directed to c i Prove M ij The correctness of M, where M i [-j] represents vector M i The new vector obtained by removing the j-th element, α[-j] represents the new vector obtained by removing the j-th element from vector α.
[0038] Step 5: Based on the common parameter pp, for any (i,j)∈[n1]×[n2] and (k,l)∈[n1]×[n2], when the value M ij Updated to M ij +δ, a single proof The update rules are as follows:
[0039] (1) When k≠i, M\M k It is a set {M k M\M k M k The only element that changes in [-l]}, therefore, ω k yes The only element that needs to be updated. Based on the computation process of a single proof, the new single global proof is updated as follows: In this case, a single proof Updated to
[0040] (2) When k = i and l ≠ j, the set {M} k M\M k M k element M in [-l]} k and M k [-l] has changed, therefore, c k and Ω kl It needs to be updated. Based on the computation process of a single proof, the new local commitment is updated to... The new single local proof is updated to In this case, a single proof Updated to
[0041] (3) When k = i and l = j, the set {M} k M\M k M k element M in [-l]} k Changes have occurred, therefore There is only c in the middle. k It needs to be updated. Based on the computation process of a single proof, the new local commitment is updated to... In this case, a single proof Updated to
[0042] Step 6: For any set Multiple individual proofs The polymerization process includes the following parts:
[0043] Multiple global proofs Aggregated into in: Let {i|(i,j)∈S} be the expression; for all Hash value Calculated by a collision-resistant hash function H.
[0044] In order to aggregate multiple local proofs {Ω ij} (i,j)∈S First, for each calculate in: It means {j|(i,j)∈S} i}, where for any For all (i,j)∈S, the hash value Calculated by a collision-resistant hash function H″. Representation vector M i Subscript in set A new vector composed of the elements in the vector; then, calculate... Where: for each Hash value Calculated by a collision-resistant hash function H′ It means {j|(i,j)∈S} k}, where for any Representation vector M k Subscript in set A new vector composed of the elements in the vector.
[0045] Therefore, the final result of the aggregation is proven to be
[0046] Step 7: Verify the correctness of the values in matrix M. The verification process involves two cases: |S| = 1 and |S| > 1.
[0047] When |S|=1, there exist (i,j)∈[n1]×[n2] satisfying S={(i,j)} and Then check the equation during the verification process. and Among them, g T Let e(g1, g2) represent the bilinear mapping e; e(·) represents the bilinear mapping e. If both equations are true, the verification passes; otherwise, the verification fails.
[0048] When |S|>1 Then check the equation during the verification process. and If both equations are true, the verification passes; otherwise, the verification fails.
[0049] Based on the above matrix commitment model construction method, combined with Figure 2 The present invention will be further illustrated by taking the stateless blockchain system under the account model as an example.
[0050] The balances of all accounts are organized into a matrix M. During blockchain system initialization, matrix M is set as a zero matrix. Matrix commitments and proofs are generated from the zero matrix using the matrix commitment model construction method described above. Matrix commitments are included in blocks. To transfer funds to others, the transferor needs to include their account balance and proof of that balance in their proposed transaction. The block proposer needs to verify the transaction using the matrix commitment model construction method described above, aggregate individual proofs, and update the matrix commitment. The block proposer needs to include the valid transaction, the aggregated proofs, and the new matrix commitment in the newly proposed block. Each validator uses the matrix commitment model construction method described above to verify the validity of the new block. After the new block is verified, all proofs are updated.
Claims
1. A method for constructing a stateless blockchain system that is efficient, aggregatable, and maintainable, characterized in that, Includes the following steps: The balances of all accounts are organized into a matrix. ; When initializing the blockchain system, the matrix The zero matrix is set, and matrix commitments and proofs are generated for the zero matrix using the matrix commitment model construction method. The matrix commitments are included in the block. In order to transfer money to someone else: the transferor needs to include its account balance and proof of that balance in the transaction it proposes; The block proposer needs to use the matrix commitment model construction method to verify transactions, aggregate individual proofs, and update the matrix commitments; the block proposer needs to include the valid transactions, the aggregated proofs, and the new matrix commitments into the newly proposed block; each validator uses the matrix commitment model construction method to verify the validity of the new block, and after the new block is verified, all proofs are updated. The matrix commitment model construction method includes the following steps: Step 1: Based on the selected safety parameters Generate bilinear group ,in, Represent a prime number, Describes an order of group Describes an order of group Describes an order of group Indicates the group and The elements in the Cartesian product are mapped to the group Bilinear mapping of elements in a given element group generator, group Generators; based on prime numbers Get Group From the group Randomly selected values and , forming vectors and ,in, Indicates the pre-selected number of matrix rows, Represents the pre-selected number of columns in a matrix; by group middle Hequn middle Composition of common parameters ,in, Representing vectors The new vector obtained by removing the first element; Step 2, based on common parameters For any matrix Calculate the matrix commitment ; Step 3, based on common parameters For any On duty Updated to Matrix commitment by Updated to ,in, Indicates that it is located in the matrix No. Line number Column elements, group Any element in; Step 4: Based on common parameters For the matrix any value Calculate a single proof ,in: Indicates a partial commitment. , Representation matrix The Middle Row vectors; Represents a single global proof. , Representing vectors Remove the first The new vector obtained from each element Representing vectors Remove the first The new vector obtained from each element; This represents a single local proof. , Representing vectors Remove the first The new vector obtained from each element Representing vectors Remove the first The new vector obtained from each element; Step 5: Based on common parameters For any and On duty Updated to Update a single proof : when At that time, the new single global proof is updated to Single proof Updated to ; when and At that time, the new local commitments were updated to The new single local proof is updated to Single proof Updated to ; when and At that time, the new local commitments were updated to Single proof Updated to ; Step 6: For any set ,like Then directly verify the matrix. The verification process for the correctness of the median includes the following steps: exist satisfy and Then, during the verification process, the equation is checked. and If all conditions are met, the validation passes; otherwise, it fails. express ; Represents a bilinear mapping ; like Then first, multiple individual proofs... After aggregation, verify the matrix. The accuracy of the median.
2. The method for constructing a stateless blockchain system that is efficient, aggregatable, and maintainable as described in claim 1, characterized in that, In step 6, multiple individual proofs are combined. Aggregation includes: Multiple global proofs Aggregated into ,in: express For all hash value Collision-resistant hash functions Calculated results; Aggregating multiple local proofs First, for each ,calculate ,in: express For any , For all hash value Collision-resistant hash functions Calculated, Representing vectors Subscript in set A new vector composed of the elements in the vector; then, calculate... , where: for each hash value Collision-resistant hash functions Calculated, express For any , , Representing vectors Subscript in set A new vector composed of the elements in the middle; The final aggregated proof is .
3. The method for constructing a stateless blockchain system that is efficient, aggregatable, and maintainable as described in claim 2, characterized in that, In step 6, when At that time, the verification matrix The correctness of the median includes: Then, during the verification process, the equation is checked. and If all conditions are met, the verification passes; otherwise, the verification fails.