A data processing method and device based on a blockchain network and a storage medium
By generating verification credentials in the blockchain network and combining Groth16 and Schnorr protocols, the zero-knowledge proof circuit is simplified, solving the problem of high complexity in zero-knowledge proof circuits and achieving efficient and accurate data verification.
Patent Information
- Application Number
- CN202210036407.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-13
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2042-01-13
AI Technical Summary
Existing zero-knowledge proof circuits constructed based on zk-SNARK technology have high complexity, resulting in long initialization time, long proof generation time, low data verification efficiency, and limited application scenarios.
By generating verification credentials in the blockchain network, including updated public data of the verifier, first proof data corresponding to K input data, and second proof data, data verification can be performed directly, avoiding hash value calculation logic in the zero-knowledge proof circuit. Combining the Groth16 scheme and the Schnorr protocol simplifies the proof process.
This effectively reduces the complexity of zero-knowledge proof circuits, enables efficient and accurate data verification, and improves verification efficiency.
Smart Images

Figure CN116488816B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a data processing method, apparatus and storage medium based on a blockchain network. Background Technology
[0002] Zero-knowledge proof (ZKP) refers to the ability of a prover to demonstrate the existence and correctness of a statement without providing the verifier with any valid information. Currently, ZK-SNARK technology is commonly used to implement zero-knowledge proofs, with Zcash being a specific application of this technology. However, current zero-knowledge proof circuits constructed using ZK-SNARK technology are typically quite complex. These circuits contain computational logic such as calculating the hash value of the input, resulting in long initialization and proof generation times. The constraints generated by this computational logic account for over 99% of the total constraints in the zero-knowledge proof, leading to complex and large-scale circuits. This results in low data verification efficiency and limited application scenarios. Summary of the Invention
[0003] This application provides a data processing method, apparatus, and storage medium based on a blockchain network, which can effectively reduce the complexity of zero-knowledge proof circuits and can efficiently and accurately verify data and corresponding processing logic.
[0004] In a first aspect, embodiments of this application provide a data processing method based on a blockchain network, the method comprising:
[0005] The first business node of the blockchain network obtains the target dataset, which includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node of the blockchain network based on the target processing logic.
[0006] The first business node generates a verification credential based on the target dataset. The verification credential includes updated public data of the verification party, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1.
[0007] The first service node sends a data verification instruction to the second service node, the data verification instruction being used to instruct the second service node to verify the K input data and the target processing logic according to the verification credentials.
[0008] Secondly, embodiments of this application provide another data processing method based on a blockchain network, the method comprising:
[0009] The second business node of the blockchain network sends a target dataset to the first business node. The target dataset includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node based on the target processing logic.
[0010] The second service node receives a data verification instruction sent by the first service node after generating a verification credential based on the target dataset. The verification credential includes updated public data of the verification party, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1.
[0011] The second service node responds to the data verification instruction and verifies the K input data and the target processing logic according to the verification credentials.
[0012] Thirdly, embodiments of this application provide a data processing apparatus, the apparatus comprising:
[0013] The acquisition module is used to acquire the target dataset, which includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node of the blockchain network based on the target processing logic.
[0014] The processing module is used to generate verification credentials based on the target dataset. The verification credentials include updated public data of the verifier, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1.
[0015] The sending module is used to send a data verification instruction to the second service node, wherein the data verification instruction is used to instruct the second service node to verify the K input data and the target processing logic according to the verification credentials.
[0016] Fourthly, embodiments of this application provide another data processing apparatus, the apparatus comprising:
[0017] The sending module is used to send a target dataset to the first business node of the blockchain network. The target dataset includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node of the blockchain network based on the target processing logic.
[0018] The receiving module is used to receive a data verification instruction sent by the first service node after generating a verification credential based on the target dataset. The verification credential includes updated public data of the verification party, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1.
[0019] The verification module is used to verify the K input data and the target processing logic according to the verification credentials in response to the data verification instruction.
[0020] Fifthly, embodiments of this application provide a computer device, the computer device including a processor, a network interface and a storage device, the processor, the network interface and the storage device being interconnected, wherein the network interface is controlled by the processor for sending and receiving data, the storage device is used to store a computer program, the computer program including program instructions, and the processor is configured to invoke the program instructions for executing the data processing method based on a blockchain network as described in the first or second aspect.
[0021] In a sixth aspect, embodiments of this application provide a computer-readable storage medium storing a computer program, the computer program including program instructions that are executed by a processor to perform the data processing method based on a blockchain network as described in the first or second aspect.
[0022] In a seventh aspect, embodiments of this application provide a computer program product, including a computer program, characterized in that, when the computer program is executed by a computer processor, it implements the data processing method based on a blockchain network as described in the first or second aspect.
[0023] In this embodiment, the first business node of the blockchain network obtains a target dataset, which includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node based on the target processing logic. The first business node generates a verification credential based on the target dataset. The verification credential includes updated verifier public data, first proof data corresponding to K input data, and second proof data. The first business node sends a data verification instruction to the second business node, instructing the second business node to verify the K input data and the target processing logic based on the verification credential. The zero-knowledge proof circuit generated in this embodiment does not need to include the calculation logic for calculating the hash value of the input data, which can effectively reduce the complexity of the zero-knowledge proof circuit. Furthermore, the verification of data and corresponding processing logic can be achieved efficiently and accurately through the first proof data and the second proof data. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. Other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1a This is a schematic diagram of the architecture of a data processing system provided in an embodiment of this application;
[0026] Figure 1b This is a schematic diagram of a blockchain structure provided in an embodiment of this application;
[0027] Figure 1c This is a schematic diagram illustrating a process for generating a new block, provided in an embodiment of this application.
[0028] Figure 2 This is a flowchart illustrating a data processing method based on a blockchain network provided in an embodiment of this application;
[0029] Figure 3 This is a flowchart illustrating another data processing method based on a blockchain network provided in an embodiment of this application;
[0030] Figure 4 This is a schematic diagram illustrating the overall implementation principle of a zero-knowledge proof provided in an embodiment of this application;
[0031] Figure 5 This is a flowchart illustrating another data processing method based on a blockchain network provided in the embodiments of this application;
[0032] Figure 6a This is a schematic diagram illustrating an application scenario of zero-knowledge proof provided in an embodiment of this application;
[0033] Figure 6b This is a schematic diagram illustrating another application scenario of zero-knowledge proof provided in the embodiments of this application;
[0034] Figure 7 This is a flowchart illustrating a data verification method provided in an embodiment of this application;
[0035] Figure 8 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application;
[0036] Figure 9 This is a schematic diagram of another data processing device provided in an embodiment of this application;
[0037] Figure 10 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0038] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. All other embodiments obtained based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0039] Zero-knowledge proof (ZKP): Through zero-knowledge proof, the prover can prove the existence and correctness of a statement to the verifier without providing any valid information. In a single zero-knowledge proof process, the prover and verifier need to exchange data multiple times (without providing valid information).
[0040] Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (zk-SNARK): zk-SNARK achieves non-interactive proof at the cost of some controversy. This is the difference between the argument in zk-SNARK and the proof in zkp. zk-SNARK is controversial when the prover possesses the computational power to break public-key encryption. Currently, this probability is extremely low. The advantage of zk-SNARK is that the generated proof is very small, and the verification cost is constant and independent of the computational cost of the content to be proven.
[0041] The Sigma protocol is essentially a zero-knowledge proof technique. The prover claims to know the value of a key x and proves their knowledge of x to the verifier without revealing x itself. The Sigma protocol is an interactive scheme, requiring multiple interactions between the prover and verifier. Because of these multiple interactions, verifiers who do not participate in the interactions cannot determine whether there was any cheating by either party. Therefore, the Sigma protocol cannot be publicly verified.
[0042] Schnorr Protocol: The Schnorr protocol is a type of Sigma protocol. However, the Schnorr protocol only requires one-way interaction. The Schnorr protocol can be used to generate Schnorr signatures and also for commitment schemes.
[0043] Merkle Tree, Merkle Root: A Merkle tree is a typical binary tree structure consisting of a root node (Merkle root), a set of intermediate nodes, and a set of leaf nodes. The leaf nodes at the bottom level store data or the hash value of the data, while the other nodes store the hash values of the contents of their corresponding two child nodes.
[0044] Please see Figure 1a This is a schematic diagram of the architecture of a data processing system provided in an embodiment of this application. The data processing system includes a service network 11, a core network 12, and terminal devices 13, wherein:
[0045] Business network 11 and core network 12 together constitute the blockchain network. A blockchain network is a network used for data sharing between node devices, and it can include multiple node devices. Each node device, in its normal operation, receives input information and maintains the shared data (i.e., the blockchain) within the network based on this received input information. To ensure information interoperability within the blockchain network, information connections can exist between each node device, enabling peer-to-peer (P2P) communication between any two node devices. This P2P communication can be conducted via wired or wireless communication links. For example, when any node device in the blockchain network receives input information, other node devices obtain this input information according to a consensus algorithm and store it as data in the shared data, ensuring consistency of data stored on all node devices in the blockchain network.
[0046] The core network 12 consists of multiple consensus nodes 102, and the business network 11 consists of multiple business nodes 101. Nodes in the business network 11 primarily execute business logic and do not perform accounting consensus. Instead, they obtain block header data and partially authorized block data from the core network 12 through identity authentication. Nodes in the core network 12 are primarily responsible for transaction data consensus, packaging transaction data into blocks for consensus accounting.
[0047] In some feasible implementations, a routing proxy layer can be set up between the service network 11 and the core network 12, wherein the routing proxy layer plays a role in isolating the service network 11 and the core network 12.
[0048] The terminal device 13 can access the blockchain network and communicate with node devices in the blockchain network (such as node 101 of business network 11). For example, it can submit transaction requests to the node devices, such as transfer requests, payment requests, and data query requests. The terminal device 13 can be a smartphone, tablet computer, laptop computer, desktop computer, in-vehicle smart terminal, etc., and this application embodiment does not limit it.
[0049] It should be noted that, Figure 1a The number of nodes 101 and 102 shown is merely illustrative; any number of nodes can be deployed as needed.
[0050] Each node in the blockchain network has a corresponding node identifier. Each node can also store the node identifiers of other nodes in the network, allowing the generated blocks to be broadcast to other nodes based on their identifiers. Each node maintains a node identifier list as shown in the table below, storing the node name and its corresponding identifier. The node identifier can be an Internet Protocol (IP) address or any other information that can be used to identify the node; the table only uses IP addresses as an example.
[0051] Node Name Node identifier Node 1 117.114.151.174 Node 2 117.116.189.145 … … Node N 119.123.789.258
[0052] In this blockchain network, each node device stores an identical copy of the blockchain. A blockchain consists of multiple blocks; see [link to blockchain documentation]. Figure 1b A blockchain consists of multiple blocks. The genesis block includes a block header and a block body. The block header stores input information feature values, version number, timestamp, and difficulty value, while the block body stores the input information. The next block after the genesis block takes the genesis block as its parent block. The next block also includes a block header and a block body. The block header stores the input information feature values of the current block, the block header feature values of the parent block, version number, timestamp, and difficulty value, and so on. This ensures that the block data stored in each block is related to the block data stored in the parent block, guaranteeing the security of the input information in the blocks.
[0053] When generating the various blocks in the blockchain, see [link / reference]. Figure 1c When a node device hosting the blockchain receives input information, it verifies the input information. After verification, it stores the input information in a memory pool and updates its hash tree used to record the input information. Then, it updates the timestamp to the time the input information was received and attempts to calculate the feature value multiple times using different random numbers, ensuring that the calculated feature value satisfies the following formula:
[0054] SHA256(SHA256(version+prev_hash+merkle_root+ntime+nbits+x)) <TARGET
[0055] Wherein, SHA256 is the feature value algorithm used to calculate the feature value; version (version number) is the version information of the relevant block protocol in the blockchain; prev_hash is the block header feature value of the parent block of the current block; merkle_root is the feature value of the input information; ntime is the update time of the update timestamp; nbits is the current difficulty, which is a fixed value for a period of time and is determined again after exceeding the fixed time period; x is a random number; TARGET is the feature value threshold, which can be determined based on nbits.
[0056] Thus, when a random number satisfying the above formula is calculated, the information can be stored accordingly, generating a block header and block body to obtain the current block. Subsequently, the node device where the blockchain resides sends the newly generated block to other node devices in its blockchain network based on the node identifiers of other node devices in the blockchain network. The other node devices verify the newly generated block and, after verification, add the newly generated block to their stored blockchain.
[0057] Among them, smart contracts can run on the node devices of the blockchain network. A smart contract is a code implementation that is executed when certain conditions are met. The contract logic can be defined by a programming language and published on the blockchain (smart contract registration). According to the logic of the contract terms, the execution is triggered by calling a key or other events to complete the contract logic. It also provides the functions of upgrading and canceling smart contracts.
[0058] In some feasible implementations, taking the example of a business node 101 (such as the first business node) in a blockchain network needing to prove to other business nodes 101 (such as the second business node) that K input data have undergone the processing logic specified by the second business node, the K input data specifically refers to data belonging to the first business node and not publicly disclosed. The K input data can be stored in the local storage space of the first business node, or it can be stored by a business node specified in the blockchain network. This application embodiment does not limit this. The processing logic specifically refers to the data operation rules. Specifically, the first business node can obtain the target dataset, which includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node based on the target processing logic. The first business node generates a verification credential based on the target dataset. The verification credential includes updated verifier public data, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1. The first business node sends a data verification instruction to the second business node, which instructs the second business node to verify the K input data and the target processing logic based on the verification credential. It can be seen that the embodiment of this application directly generates the zero-knowledge proof circuit based on the target processing logic, so that the zero-knowledge proof circuit does not need to perform hash calculations or other operations on the input data, but only needs to focus on the specific operation logic on the input data. Furthermore, by generating the first proof data and the second proof data, the verifier can verify whether the input data has been processed by the target processing logic and also verify the authenticity of the input data, thereby greatly reducing the design complexity of the zero-knowledge proof circuit and enabling efficient and accurate verification of data and corresponding processing logic.
[0059] As can be seen, the embodiments of this application enable business nodes to prove the existence of computational logic, the reliability of computational data sources, and the correctness of computational results to other nodes through zero-knowledge proofs without disclosing the input. This can significantly reduce the complexity of zero-knowledge proof circuits and efficiently generate zero-knowledge proofs while ensuring that the input is invisible and correct.
[0060] The implementation details of the technical solutions in the embodiments of this application are described in detail below:
[0061] Please see Figure 2 This application's embodiments are based on Figure 1a The illustrated data processing system provides a flowchart of a data processing method based on a blockchain network, which can be applied to... Figure 1a Business node 101, such as the first business node, can specifically include the following steps:
[0062] 201. The first business node obtains the target dataset, which includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node based on the target processing logic.
[0063] Specifically, the first business node can receive the target dataset sent by the second business node; or, after determining the target dataset, the second business node can write the target dataset into the blockchain, and the first business node can then obtain the target dataset from the blockchain; or, the second business node can write a portion of the data in the target dataset into the blockchain, for example, write the verifier's public data into the blockchain, and send the zero-knowledge proof circuit and the verifier's public data in the target dataset to the first business node, and the first business node can then obtain the verifier's public data in the target dataset from the blockchain.
[0064] The zero-knowledge proof circuit is generated by the second business node based on the target processing logic. The target processing logic can be provided by the second business node and can be made public. Specifically, the target processing logic refers to the logic of processing data according to certain calculation rules. For example, the target processing logic can be the logic of summing up the various input data. This makes the generated zero-knowledge proof circuit not need to perform hash calculation or commitment calculation on the input data. It only needs to focus on the specific calculation logic of the input data, which effectively reduces the complexity of the zero-knowledge proof circuit.
[0065] 202. The first business node generates a verification credential based on the target dataset. The verification credential includes updated public data of the verification party, first proof data corresponding to K input data, and second proof data.
[0066] Where K is an integer greater than or equal to 1. The K input data specifically refer to data belonging to the first business node that is not publicly disclosed, such as the asset amount of the first business node. These K input data need to be processed by the target processing logic.
[0067] Specifically, the first business node can generate two sets of proof data based on the target dataset, including the first proof data corresponding to K input data and the second proof data corresponding to each input data. The first proof data can be a zk-snark proof generated based on zk-snark, and the second proof data can be a schnorr proof generated based on the schnorr protocol. In addition, it also includes updated verifier public data, for example, the verifier public data can be updated based on the K input data.
[0068] 203. The first service node sends a data verification instruction to the second service node, the data verification instruction being used to instruct the second service node to verify the K input data and the target processing logic according to the verification credentials.
[0069] Specifically, after generating the verification credentials, the first business node sends a data verification instruction to the second business node. The second business node can then verify the K input data and the target processing logic based on the verification credentials. Thus, the second business node, acting as the verifier, can verify whether the input data has been processed by the target processing logic and verify the authenticity of the input data through the first and second sets of verification data. This allows for efficient and accurate verification of the data and the corresponding processing logic.
[0070] In this embodiment, a first business node acquires a target dataset, which includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by a second business node based on target processing logic. The first business node generates a verification credential based on the target dataset. The verification credential includes updated verifier public data, first proof data corresponding to K input data, and second proof data. The first business node sends a data verification instruction to the second business node, which instructs the second business node to verify the K input data and the target processing logic based on the verification credential. The generated zero-knowledge proof circuit does not need to include the calculation logic for hashing the input data, which can effectively reduce the complexity of the zero-knowledge proof circuit. Furthermore, the verification of data and corresponding processing logic can be achieved efficiently and accurately through the first and second proof data.
[0071] Please see Figure 3 This application's embodiments are based on Figure 1a The diagram illustrates another data processing method based on a blockchain network provided by the data processing system. This data processing method can be applied to... Figure 1a Business node 101, such as the first business node, can specifically include the following steps:
[0072] 301. The first business node obtains the target dataset, which includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node based on the target processing logic.
[0073] The verification public data includes the first base point corresponding to each of the K input data and the second base point corresponding to each of the N output data, where N is an integer greater than or equal to 1. The N output data refer to the data output after the K input data have been processed by the target processing logic.
[0074] 302. The first business node generates first proof data corresponding to K input data based on the zero-knowledge proof circuit and the public data of the prover. The first proof data includes N output data and K input data after hiding.
[0075] Specifically, the first business node can generate the third proof data corresponding to the K input data based on the zero-knowledge proof circuit and the public data of the prover. The third proof data includes plaintext data of N output data and plaintext data of K input data. Since the K input data belongs to the first business node and cannot be disclosed, the first business node needs to hide the K input data included in the third proof data to obtain the first proof data corresponding to the K input data. The hiding method can be to set all K input data to 1.
[0076] In some feasible implementations, the first business node can input the K input data into the zero-knowledge proof circuit, and obtain the corresponding N output data by running the zero-knowledge proof circuit. The first business node uses the zk-snark algorithm to process the K input data, the N output data, and the common data of the prover to generate the third proof data corresponding to the K input data. The third proof data is the zk-snark proof, and the first proof data can be regarded as the updated zk-snark proof.
[0077] In some feasible implementations, before generating the first proof data, the first business node needs to obtain the K input data. Specifically, it can check whether the K input data are stored in its local storage space. If not, the first business node sends an input data acquisition request to a third business node in the blockchain network. The first business node receives the K input data sent by the third business node in response to the input data acquisition request. The K input data can be stored in a designated business node (such as the third business node) in the blockchain network. It should be noted that there can be one or more third business nodes. If there are multiple third business nodes, each third business node can store a portion of the input data from the first business node.
[0078] 303. The first business node updates the first base point included in the verification party public data according to the K input data to obtain the updated verification party public data.
[0079] In this embodiment, N output data can be made public, while K input data cannot be made public. However, in this application embodiment, when the verifier (i.e. the second business node) generates the zero-knowledge proof circuit, it first considers all K input data and N output data as being public. Then, the generated verifier public data can include (K+N) base points. For example, the verifier public data can specifically include the first base point corresponding to each of the K input data and the second base point corresponding to each of the N output data.
[0080] Specifically, since the K input data in the generated first proof data are hidden, the base points corresponding to the K input data in the verifier's public data also need to be updated. For example, based on each of the K input data, the first base point corresponding to each input data in the verifier's public data can be updated to obtain the updated first base point corresponding to each input data. The updated first base point can be, for example, the power of the first base point's input data. The first business node determines the updated verifier's public data based on the second base point corresponding to each output data and the updated first base point corresponding to each input data.
[0081] 304. The first business node generates second proof data corresponding to each of the K input data.
[0082] Specifically, the first business node can use the Schnorr algorithm to generate second proof data corresponding to each input data. The second proof data includes a first base point, an updated first base point, commitment data, a third base point, a fourth base point, verification parameters, and a fifth base point corresponding to K input data for each input data. The fifth base point can be a base point negotiated and determined by the third business node that stores the K input data.
[0083] In some feasible implementations, the first business node can generate a third basis point for each input data based on a first basis point and a random number, wherein the random number is randomly generated and not publicly disclosed. The first business node can also generate a fourth basis point for each input data based on a fifth basis point and the random number. The first business node can then generate a target digest based on the first basis point, the updated first basis point, the committed data, the third basis point, the fourth basis point, and the fifth basis point. Finally, it can generate verification parameters for each input data based on each input data, the random number, and the target digest. The first business node can concatenate the first basis point, the updated first basis point, the committed data, the third basis point, the fourth basis point, and the fifth basis point to obtain a concatenated string, and then use the Sha256 algorithm to process the concatenated string to generate the target digest.
[0084] In some feasible implementations, when obtaining the commitment data corresponding to each input data, the first business node can send a commitment data acquisition request to the consensus node of the blockchain. The commitment data acquisition request is used to instruct the consensus node to obtain the commitment data corresponding to each of the K input data from the blockchain. The first business node receives the commitment data corresponding to each input data sent by the consensus node. The commitment data is generated by the third business node of the blockchain network based on the fifth basis point and each input data, and written into the blockchain. It can be seen that the embodiments of this application do not need to implement the calculation logic of hashing or making commitments on the input data in the zero-knowledge proof circuit. Instead, the process of calculating commitments is moved outside the zero-knowledge proof circuit, which greatly reduces the complexity of the zero-knowledge proof circuit.
[0085] 305. The first service node sends a data verification instruction to the second service node. The data verification instruction is used to instruct the second service node to verify the K input data and the target processing logic according to the verification credentials. The verification credentials include the updated verification party public data, the first proof data corresponding to the K input data, and the second proof data corresponding to each input data.
[0086] In some feasible implementations, the first business node receives a first smart contract sent by the consensus node of the blockchain network. The first smart contract is generated by the second business node according to the target processing logic and submitted to the consensus node. The first business node uses the first smart contract to process K input data to obtain the contract execution result. The contract execution result includes N output data corresponding to the K input data. The first business node writes the contract execution result and the verification certificate into the blockchain, which can serve as evidence that the first business node uses the K input data to execute the target processing logic.
[0087] In some feasible implementations, such as Figure 4 The diagram shown is a schematic representation of the overall implementation principle of a zero-knowledge proof provided in an embodiment of this application.
[0088] Specifically, this implementation combines the Groth16 zero-knowledge proof with the Schnorr protocol. x represents the K input data, y represents the N output data, f() represents the target processing logic, Com() represents the computational commitment, g2 represents the fifth base point, and the commitments corresponding to each input data form a Merkle tree, with each leaf node representing the commitment corresponding to each input data. g1 represents the first base point. Based on g1, g2, and other base points, zk-SNARK proofs and Schnorr proofs (i.e., the first and second proof data) are generated respectively. Based on the zk-SNARK and Schnorr proofs, x and f() can be accurately and efficiently verified, yielding the verification result. By combining the Groth16 zk-SNARK technology with the Schnorr protocol, the process of computational commitment is moved outside the zero-knowledge proof circuit. This simplifies the constructed zero-knowledge proof circuit, eliminating the need for hashing or commitment calculations within the circuit itself, significantly reducing its complexity.
[0089] In its implementation, the blockchain stores the commitment value of each input, as well as a base point G2. For each input a... i The commitment value is a is calculated from the commitment value and the base point G2. i It is a discrete logarithm problem, therefore we promise that a will not be made. i Exposure. Based on the Groth16 scheme, for each input a i have: Where G is the base point (a generator over a finite field), βu i (x)+αv i (x)+ω i (x) is the QAP polynomial corresponding to the i-th input, x is a random challenge, and γ is a random number.
[0090] When the verifier (such as the second business node mentioned above) initializes the zero-knowledge proof circuit, it will generate a verifier common string and a prover common string, both of which can be made public. For each input a i The verification public string contains a base point.
[0091] Suppose a computational logic has K inputs and N outputs, where all inputs need to be hidden, while all outputs can be made public. In this embodiment, when constructing the zero-knowledge proof circuit, the verifier first sets all K inputs and N outputs to be public. This results in (K+N) base points in the verifier's public string, each base point being determined by G. iThe calculation is as follows: The verifier sends the verifier's common string, the zero-knowledge proof circuit, and the prover's common string to the prover (as in the first business node mentioned above). The prover can generate a zk-SNARK proof using the circuit and the prover's common string. The proof contains plaintext with K inputs and N outputs.
[0092] For i∈[0,K], a i It needs to be hidden. The prover needs to update 'a' in the zk-SNARK proof. i i∈[0,K] and the verifier's common string i∈[0,K]. The update method is to update each i∈[0,K] is updated to Each a i , i∈[0,K] are updated to 1. From and G i Recover a i It is a discrete logarithm problem, therefore a i It will not be exposed. The proving party updates and generates a new validator public string and zk-SNARK proof through the above process.
[0093] The prover then needs to produce a Schnorr proof to demonstrate that they used the correct input. For each input a i For i∈[0,K], the Schnorr proof includes 1) base points. 2) Base point G2; 3) 4) 5) Where γ is a randomly generated, undisclosed random number; 6) 7) Z = γ + c*a i Where c = Sha256(G i |G2|C i ′|C2|A i |A2); where, for i∈[0,K], G i G2 corresponds to the first base point for each of the K input data mentioned above; C corresponds to the fifth base point mentioned above; i ′ corresponds to the updated first base point mentioned above; C2 corresponds to the commitment value (or commitment data) mentioned above; A i A1 corresponds to the third basis point mentioned above; A2 corresponds to the fourth basis point mentioned above; Z corresponds to the verification parameter mentioned above; c corresponds to the target summary mentioned above.
[0094] The verifier needs to verify: 1) whether the initial verifier common string matches the updated verifier common string; 2) whether the updated zk-SNARK proof passes verification; and 3) whether the Schnorr proof passes verification. The verification method for the third step, the Schnorr proof, is as follows: for each input a... i ,verify If both equations are true, then the Schnorr proof is verified, meaning the prover used the correct input.
[0095] This application embodiment uses the Sigma and Schnorr protocols to enable the zero-knowledge proof circuit to still prove the correctness of the input and whether the specified computational logic was used to process the input data, even though the zero-knowledge proof circuit does not contain computational logic that makes a commitment to the input value. This significantly reduces the complexity of the zero-knowledge proof circuit and greatly speeds up the initialization time of the zero-knowledge proof circuit and the time for the prover to generate the proof.
[0096] Please see Figure 5 This application's embodiments are based on Figure 1a The diagram shown illustrates another data processing method based on a blockchain network provided by the data processing system. This data processing method can be applied to... Figure 1a Business node 101, such as the second business node, can specifically include the following steps:
[0097] 501. The second business node sends a target dataset to the first business node. The target dataset includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node based on the target processing logic.
[0098] In some feasible implementations, before the second service node sends the target dataset to the first service node, it needs to determine the target dataset first. Specifically, this may include: the second service node generating a zero-knowledge proof circuit corresponding to the target processing logic; initializing the zero-knowledge proof circuit according to common parameters to obtain verifier common data and prover common data. The verifier common data includes a first base point corresponding to each of the K input data and a second base point corresponding to each of the N output data, where K is an integer greater than or equal to 1 and N is an integer greater than or equal to 1; and the second service node determining the target dataset based on the zero-knowledge proof circuit, the verifier common data, and the prover common data.
[0099] 502. The second service node receives a data verification instruction sent by the first service node after generating a verification credential based on the target dataset. The verification credential includes updated public data of the verification party, first proof data corresponding to K input data, and second proof data.
[0100] 503. The second business node responds to the data verification instruction and verifies the K input data and the target processing logic according to the verification credentials.
[0101] The data verification in this application embodiment includes two parts: one part is the verification of the target processing logic, and the other part is the verification of the input data. Only when both the target processing logic and the input data are verified can the final verification result be confirmed as verified; otherwise, the verification is deemed unsuccessful.
[0102] In some feasible implementations, the data verification instruction includes verification credentials. The second business node responds to the data verification instruction by verifying the target processing logic of the K input data based on the updated public data of the verification party and the first proof data. The second business node verifies the K input data based on the second proof data.
[0103] In some feasible implementations, the verification method for the target processing logic may specifically include: the second business node responding to the data verification instruction determines whether the verifier's public data matches the updated verifier's public data. For example, whether everything is completely consistent except for the first base point corresponding to each input data. If they match, the second business node verifies the first proof data according to the updated verifier's public data to obtain the verification result of the target processing logic. For example, the updated verifier's public data is input into the zk-SNARK proof algorithm, and the verification result of the target processing logic is determined according to the output result. If the output result is true, the verification passes; if the output result is false, the verification fails.
[0104] In some feasible implementations, the second proof data includes a first base point, an updated first base point, commitment data, a third base point, a fourth base point, verification parameters, and a fifth base point corresponding to K input data for each input data. The verification method for the input data may specifically include: for each input data corresponding to the second proof data, a second business node determines whether the first base point, verification parameters, updated first base point, third base point, and target digest satisfy a first preset relationship, obtaining a first verification result. The target digest is generated by the first business node based on the first base point, updated first base point, commitment data, third base point, fourth base point, and fifth base point. The second business node determines whether the fifth base point, verification parameters, commitment data, fourth base point, and target digest satisfy a second preset relationship, obtaining a second verification result. The verification result for each input data is determined based on the first and second verification results. For example, for each input a... i ,verify If both equations hold true, then the Schnorr proof is verified, meaning the prover used the correct input. Where, for i∈[0,K], G... i G2 corresponds to the first base point for each of the K input data mentioned above; C corresponds to the fifth base point mentioned above; i ′ corresponds to the updated first base point mentioned above; C2 corresponds to the commitment value (or commitment data) mentioned above; A i A1 corresponds to the third basis point mentioned above; A2 corresponds to the fourth basis point mentioned above; Z corresponds to the verification parameter mentioned above; c corresponds to the target summary mentioned above.
[0105] In this embodiment, the second business node, acting as the verifier, sends a target dataset to the first business node. The target dataset includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node based on the target processing logic. The second business node receives a data verification instruction sent by the first business node after generating a verification credential based on the target dataset. The verification credential includes updated verifier public data, first proof data corresponding to K input data, and second proof data. The second business node responds to the data verification instruction and verifies the K input data and the target processing logic based on the verification credential. The zero-knowledge proof circuit is directly generated based on the target processing logic, so that the zero-knowledge proof circuit does not need to perform hash calculations on the input data. It only needs to focus on the specific operation logic on the input data. Furthermore, the verifier can verify whether the input data has been processed by the target processing logic and verify the authenticity of the input data through the first and second proof data. This greatly reduces the design complexity of the zero-knowledge proof circuit and can efficiently and accurately realize the verification of data and corresponding processing logic.
[0106] In some feasible implementations, the blockchain network is divided into two layers: a witness network (i.e., the aforementioned business network) and a consensus network (i.e., the aforementioned core network). Consensus nodes execute consensus and produce blocks in the consensus network; business nodes execute business logic, submit business operations to the consensus network, and synchronize block data from consensus nodes in the witness network. This blockchain network supports running local contracts on business nodes; local contracts are a special type of contract whose execution result does not adhere to consensus. In some data-intensive computational scenarios, situations may arise such as... Figure 6a The scenario shown includes: 601. An object submits a transaction request to a business node; 602. The business node performs calculations on the input data using a local contract and obtains the result; 603. The business node appends the calculation result to the transaction and submits the transaction to the core chain; 604. The core chain distributes the transaction and calculation result to other business nodes after recording them on the chain. In this process, the business node executing step 602 needs to prove to other nodes that: 1) the calculation result was indeed calculated using the local contract's calculation logic; and 2) the correct input data was used in the calculation, not fabricated input data.
[0107] like Figure 6b The diagram illustrates another application scenario provided by an embodiment of this application. In this scenario, the core chain is located in the consensus network, and objects such as Object 0, Object 2, Object 1, Object 2, Object 3, and Object 4 are business nodes located in the witness network. In this scenario, Objects 1, 2, 3, and 4 are equivalent to the aforementioned third business nodes, Object 2 is equivalent to the aforementioned first business nodes, and Object 0 is equivalent to the aforementioned second business node. Objects 1, 2, 3, and 4 each possess a portion of the data of Object 2; specifically, Object 1 possesses data 1 of Object 2, Object 2 possesses data 2 of Object 2, Object 3 possesses data 3 of Object 2, and Object 4 possesses data 4 of Object 2. Object 0 possesses publicly available computational logic (i.e., the aforementioned target processing logic). Object 0 requires Object 2 to use data 1, 2, 3, and 4 as input to its computational logic to execute the computational logic and obtain the computational result. While executing computational logic, the second type of object needs to prove to the first type of object 0 through zero-knowledge proof and the Schnorr protocol that: 1) the computational logic has been executed; 2) the input of the computation is the input corresponding to the commitment value submitted by the first type of objects 1, 2, 3, and 4.
[0108] Specifically, a single calculation step for the data may include:
[0109] 611. In order not to disclose the data of the second type of objects, the first type of objects 1, 2, 3, and 4 only put the commitment value (Com1, Com2, Com3, Com4) of each data and the Merkle root of these commitment values on the chain;
[0110] 612. The first type of object 0 writes the computational logic into a local contract and deploys it to the core chain. The local contract will be cleared through the core chain to the business node where the second type of object resides;
[0111] 613. Object 0 of the first type is responsible for transforming computational logic into a zero-knowledge proof circuit and initializing the zero-knowledge proof circuit. The zero-knowledge proof circuit and its common string are obtained off-chain by objects of the second type.
[0112] The circuit common string includes the aforementioned verification public data and proof public data.
[0113] 614. The second type of object executes computation logic through a local contract at the business node, and uses data 1, 2, 3, and 4 as inputs to the local contract, and puts the computation results, circuit proof, and Schnorr protocol proof on the chain.
[0114] 615. Proof of the verification circuit for object 0 of the first type and proof of the Schnorr protocol.
[0115] The specific implementation methods of each step can be found in the relevant descriptions in the foregoing embodiments, and will not be repeated here.
[0116] Please see Figure 7 This application's embodiments are based on Figure 1a The diagram shown illustrates a data verification method provided by the data processing system, which may include the following steps:
[0117] 701. Each first-class object i negotiates a base point G2 and makes a commitment to the data of the second-class objects, and puts the base point and commitment on the chain.
[0118] Among them, base point G2 corresponds to the fifth base point mentioned above. The business nodes of each first type of object i correspond to the third business node mentioned above, the business nodes of the second type of object P correspond to the first business node mentioned above, and the business nodes of the first type of object 0 correspond to the second business node mentioned above.
[0119] 702. Each first-type object i sends the plaintext of the data to the queried second-type object P. If the data is already present on the business node of the second-type object P, then step 702 is skipped.
[0120] 703. The local contract that implements the computing logic is deployed on the business node of the first type of object 0. The local contract is cleared to the business node of the second type of object P through the consensus node.
[0121] The computational logic corresponds to the target processing logic mentioned above, and the local contract corresponds to the first smart contract mentioned above.
[0122] 704. Object 0 of the first type creates a zk-SNARK circuit C, sends the circuit and the prover public string to the business node of object P of the second type.
[0123] In this context, the zk-SNARK circuit C corresponds to the zero-knowledge proof circuit mentioned above, the verifier public string corresponds to the verifier public data mentioned above, and the prover public string corresponds to the prover public data mentioned above.
[0124] 705. The first type of object 0 puts the validator public string on the chain, and the consensus node distributes the validator public string to the business nodes of the second type of object P.
[0125] 706. The business node of the second type of object P runs the local contract corresponding to the calculation logic and obtains the calculation result.
[0126] 707. The business nodes of the second type of object P generate zk-SNARK proofs.
[0127] 708. The business node of the second type of object P updates the zk-snark proof, updates the verifier common string, and generates the Schnorr proof.
[0128] Among them, the zk-snark proof corresponds to the third proof data mentioned above, the updated zk-snark proof corresponds to the first proof data mentioned above, and the schnorr proof corresponds to the second proof data mentioned above.
[0129] 709. The business node of the second type of object P will put the updated zk-snark proof, the updated validator public string, and the generated schnorr proof on the chain.
[0130] 710. The business node of the first type of object 0 is verified by the smart contract: 1) The updated zk-snark proof can be verified by the updated validator common string; 2) The Schnorr proof is verified; 3) The validator common string before the update matches the validator common string after the update.
[0131] 711. The business node of the first type of object 0 will upload the verification result to the chain.
[0132] The specific implementation methods of each step can be found in the relevant descriptions in the foregoing embodiments, and will not be repeated here.
[0133] The above data verification method can simultaneously ensure that: 1) the data input by the computation executor (i.e., the second type of object P) is not exposed; 2) the computation executor correctly executes the computation logic; 3) the computation executor uses correct data (rather than forged input data) as the input for computation; and 4) the time for the computation logic provider (i.e., the first type of object 0) to initialize and the time for the proof generated by the computation executor are greatly reduced.
[0134] Please see Figure 8 This is a schematic diagram of the structure of a data processing device according to an embodiment of this application. The data processing device described in this embodiment can be applied to the aforementioned business nodes. The device includes:
[0135] The acquisition module 801 is used to acquire the target dataset, which includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node of the blockchain network based on the target processing logic.
[0136] Processing module 802 is used to generate verification credentials based on the target dataset. The verification credentials include updated public data of the verifier, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1.
[0137] The sending module 803 is used to send a data verification instruction to the second service node, the data verification instruction being used to instruct the second service node to verify the K input data and the target processing logic according to the verification credentials.
[0138] Optionally, the verification public data includes a first base point corresponding to each of the K input data and a second base point corresponding to each of the N output data, where N is an integer greater than or equal to 1; the processing module 802 is specifically used for:
[0139] The first proof data corresponding to the K input data is generated based on the zero-knowledge proof circuit and the proof party's public data. The first proof data includes the N output data and the K input data after hiding.
[0140] The first base point included in the verifier public data is updated based on the K input data to obtain the updated verifier public data.
[0141] Generate a second proof data corresponding to each of the K input data.
[0142] Optionally, the processing module 802 is specifically used for:
[0143] The third proof data corresponding to the K input data is generated based on the zero-knowledge proof circuit and the proof party's public data. The third proof data includes the N output data and the K input data.
[0144] The K input data included in the third proof data are hidden to obtain the first proof data corresponding to the K input data.
[0145] Optionally, the processing module 802 is specifically used for:
[0146] The K input data are input into the zero-knowledge proof circuit, and the corresponding N output data are obtained by running the zero-knowledge proof circuit.
[0147] The third proof data corresponding to the K input data is generated based on the K input data, the N output data, and the proof party's common data.
[0148] Optionally, the processing module 802 is specifically used for:
[0149] Based on each of the K input data, the first base point corresponding to each input data in the public data of the verification party is updated to obtain the updated first base point corresponding to each input data.
[0150] Based on the second base point corresponding to each output data and the updated first base point corresponding to each input data, the updated verification public data is determined.
[0151] Optionally, the second proof data includes a first basis point, an updated first basis point, commitment data, a third basis point, a fourth basis point, verification parameters, and a fifth basis point corresponding to each of the K input data; the processing module 802 is specifically used for:
[0152] Generate a third base point corresponding to each input data based on the first base point and the random number;
[0153] Generate a fourth base point corresponding to each input data based on the fifth base point and the random number;
[0154] A target summary is generated based on the first base point, the updated first base point, the commitment data, the third base point, the fourth base point, and the fifth base point;
[0155] The verification parameters corresponding to each input data are generated based on each input data, the random number, and the target digest.
[0156] Optionally, the device further includes a receiving module 804, wherein:
[0157] The sending module 803 is further configured to send a commitment data acquisition request to the consensus node of the blockchain, wherein the commitment data acquisition request is used to instruct the consensus node to acquire the commitment data corresponding to each of the K input data from the blockchain;
[0158] The receiving module 804 is used to receive the commitment data corresponding to each input data sent by the consensus node. The commitment data is generated by the third business node of the blockchain network based on the fifth basis point and each input data, and written into the blockchain.
[0159] Optionally, the receiving module 804 is further configured to receive a first smart contract sent by the consensus node of the blockchain network, wherein the first smart contract is generated by the second business node according to the target processing logic and submitted to the consensus node;
[0160] The processing module 802 is further configured to process the K input data using the first smart contract to obtain a contract execution result, wherein the contract execution result includes N output data corresponding to the K input data;
[0161] The processing module 802 is also used to write the contract execution result and the verification certificate into the blockchain.
[0162] Optionally, the processing module 802 is further configured to query whether the local storage space stores the K input data;
[0163] The sending module 803 is further configured to send an input data acquisition request to the third business node of the blockchain network if no.
[0164] The receiving module 804 is also used to receive the K input data sent by the third service node in response to the input data acquisition request.
[0165] It should be noted that the functions of each functional module of the data processing device in this application embodiment can be specifically implemented according to the methods in the above method embodiments. The specific implementation process can be referred to the relevant descriptions in the above method embodiments, which will not be repeated here.
[0166] Please see Figure 9 This is a schematic diagram of another data processing device according to an embodiment of this application. The data processing device described in this embodiment can be applied to the aforementioned consensus node. The device includes:
[0167] The sending module 901 is used to send a target dataset to the first business node of the blockchain network. The target dataset includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node of the blockchain network based on the target processing logic.
[0168] The receiving module 902 is used to receive a data verification instruction sent by the first service node after generating a verification credential based on the target dataset. The verification credential includes updated public data of the verification party, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1.
[0169] The verification module 903 is used to verify the K input data and the target processing logic according to the verification credentials in response to the data verification instruction.
[0170] Optionally, the device further includes a processing module 904, wherein:
[0171] The processing module 904 is used for:
[0172] Generate the zero-knowledge proof circuit corresponding to the target processing logic;
[0173] The zero-knowledge proof circuit is initialized according to the common parameters to obtain verifier common data and prover common data. The verifier common data includes the first base point corresponding to each of the K input data and the second base point corresponding to each of the N output data, where N is an integer greater than or equal to 1.
[0174] The target dataset is determined based on the zero-knowledge proof circuit, the verifier public data, and the prover public data.
[0175] Optionally, the data verification indication includes the verification credential, and the verification module 903 is specifically used for:
[0176] In response to the data verification instruction, the target processing logic of the K input data is verified based on the updated verification public data and the first proof data;
[0177] The K input data are verified based on the second proof data.
[0178] Optionally, the verification module 903 is specifically used for:
[0179] In response to the data verification instruction, determine whether the verifier's public data matches the updated verifier's public data;
[0180] If a match is found, the first proof data is verified based on the updated public data of the verification party to obtain the verification result of the target processing logic.
[0181] Optionally, the second proof data includes a first base point corresponding to each input data, an updated first base point, commitment data, a third base point, a fourth base point, verification parameters, and a fifth base point corresponding to the K input data; the verification module 903 is specifically used for:
[0182] For each input data corresponding to the second proof data, determine whether the first base point, the verification parameter, the updated first base point, the third base point, and the target digest satisfy a first preset relationship to obtain a first verification result. The target digest is generated by the first business node based on the first base point, the updated first base point, the commitment data, the third base point, the fourth base point, and the fifth base point.
[0183] Determine whether the fifth baseline, the verification parameters, the commitment data, the fourth baseline, and the target summary satisfy a second preset relationship to obtain a second verification result;
[0184] The verification result for each input data is determined based on the first verification result and the second verification result.
[0185] It should be noted that the functions of each functional module of the data processing device in this application embodiment can be specifically implemented according to the methods in the above method embodiments. The specific implementation process can be referred to the relevant descriptions in the above method embodiments, which will not be repeated here.
[0186] Please see Figure 10 This is a schematic diagram of the structure of a computer device according to an embodiment of this application. The computer device according to this embodiment includes a power supply module and other structures, and includes a processor 1001, a storage device 1002, and a network interface 1003. The processor 1001, the storage device 1002, and the network interface 1003 can exchange data.
[0187] The storage device 1002 may include volatile memory, such as random-access memory (RAM); the storage device 1002 may also include non-volatile memory, such as flash memory, solid-state drive (SSD), etc.; the storage device 1002 may also include a combination of the above types of memory.
[0188] The processor 1001 may be a central processing unit (CPU). In one embodiment, the processor 1001 may also be a graphics processing unit (GPU). The processor 1001 may also be a combination of a CPU and a GPU.
[0189] In one embodiment, the storage device 1002 is used to store program instructions, and the processor 1001 can invoke the program instructions to perform the following operations:
[0190] Obtain the target dataset, which includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node of the blockchain network based on the target processing logic.
[0191] A verification credential is generated based on the target dataset. The verification credential includes updated public data of the verifier, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1.
[0192] Send a data verification instruction to the second service node, the data verification instruction being used to instruct the second service node to verify the K input data and the target processing logic based on the verification credentials.
[0193] Optionally, the verification public data includes a first base point corresponding to each of the K input data and a second base point corresponding to each of the N output data, where N is an integer greater than or equal to 1; the processor 1001 is specifically used for:
[0194] The first proof data corresponding to the K input data is generated based on the zero-knowledge proof circuit and the proof party's public data. The first proof data includes the N output data and the K input data after hiding.
[0195] The first base point included in the verifier public data is updated based on the K input data to obtain the updated verifier public data.
[0196] Generate a second proof data corresponding to each of the K input data.
[0197] Optionally, the processor 1001 is specifically used for:
[0198] The third proof data corresponding to the K input data is generated based on the zero-knowledge proof circuit and the proof party's public data. The third proof data includes the N output data and the K input data.
[0199] The K input data included in the third proof data are hidden to obtain the first proof data corresponding to the K input data.
[0200] Optionally, the processor 1001 is specifically used for:
[0201] The K input data are input into the zero-knowledge proof circuit, and the corresponding N output data are obtained by running the zero-knowledge proof circuit.
[0202] The third proof data corresponding to the K input data is generated based on the K input data, the N output data, and the proof party's common data.
[0203] Optionally, the processor 1001 is specifically used for:
[0204] Based on each of the K input data, the first base point corresponding to each input data in the public data of the verification party is updated to obtain the updated first base point corresponding to each input data.
[0205] Based on the second base point corresponding to each output data and the updated first base point corresponding to each input data, the updated verification public data is determined.
[0206] Optionally, the second proof data includes a first base point corresponding to each input data, an updated first base point, commitment data, a third base point, a fourth base point, verification parameters, and a fifth base point corresponding to the K input data; the processor 1001 is specifically used for:
[0207] Generate a third base point corresponding to each input data based on the first base point and the random number;
[0208] Generate a fourth base point corresponding to each input data based on the fifth base point and the random number;
[0209] A target summary is generated based on the first base point, the updated first base point, the commitment data, the third base point, the fourth base point, and the fifth base point;
[0210] The verification parameters corresponding to each input data are generated based on each input data, the random number, and the target digest.
[0211] Optionally, the processor 1001 is further configured to:
[0212] Send a commitment data retrieval request to the consensus node of the blockchain, the commitment data retrieval request being used to instruct the consensus node to retrieve the commitment data corresponding to each of the K input data from the blockchain;
[0213] The consensus node sends commitment data corresponding to each input data. The commitment data is generated by the third business node of the blockchain network based on the fifth basis point and each input data, and written into the blockchain.
[0214] Optionally, the processor 1001 is further configured to:
[0215] The first smart contract is received from the consensus node of the blockchain network. The first smart contract is generated by the second business node according to the target processing logic and submitted to the consensus node.
[0216] The first smart contract is used to process the K input data to obtain the contract execution result, which includes N output data corresponding to the K input data.
[0217] The contract execution result and the verification certificate are written into the blockchain.
[0218] Optionally, the processor 1001 is further configured to:
[0219] Check if the K input data are stored in the local storage space;
[0220] If not, then send an input data acquisition request to the third business node of the blockchain network;
[0221] Receive the K input data sent by the third service node in response to the input data acquisition request.
[0222] In specific implementation, the processor 1001, storage device 1002, and network interface 1003 described in the embodiments of this application can execute the embodiments of this application. Figures 2-3 The implementation methods described in the relevant embodiments of the provided method can also be used to execute the embodiments of this application. Figure 8 The implementation methods described in the relevant embodiments of the provided device will not be repeated here.
[0223] In one embodiment, the storage device 1002 is used to store program instructions, and the processor 1001 can invoke the program instructions to perform the following operations:
[0224] A target dataset is sent to the first business node of the blockchain network. The target dataset includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node of the blockchain network based on the target processing logic.
[0225] After the first service node generates a verification credential based on the target dataset, it receives a data verification instruction. The verification credential includes updated public data of the verification party, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1.
[0226] In response to the data verification instruction, the K input data and the target processing logic are verified according to the verification credentials.
[0227] Optionally, the processor 1001 is further configured to:
[0228] Generate the zero-knowledge proof circuit corresponding to the target processing logic;
[0229] The zero-knowledge proof circuit is initialized according to the common parameters to obtain verifier common data and prover common data. The verifier common data includes the first base point corresponding to each of the K input data and the second base point corresponding to each of the N output data, where N is an integer greater than or equal to 1.
[0230] The target dataset is determined based on the zero-knowledge proof circuit, the verifier public data, and the prover public data.
[0231] Optionally, the data verification indication includes the verification credential, and the processor 1001 is specifically used for:
[0232] In response to the data verification instruction, the target processing logic of the K input data is verified based on the updated verification public data and the first proof data;
[0233] The K input data are verified based on the second proof data.
[0234] Optionally, the processor 1001 is specifically used for:
[0235] In response to the data verification instruction, determine whether the verifier's public data matches the updated verifier's public data;
[0236] If a match is found, the first proof data is verified based on the updated public data of the verification party to obtain the verification result of the target processing logic.
[0237] Optionally, the second proof data includes a first base point corresponding to each input data, an updated first base point, commitment data, a third base point, a fourth base point, verification parameters, and a fifth base point corresponding to the K input data; the processor 1001 is specifically used for:
[0238] For each input data corresponding to the second proof data, determine whether the first base point, the verification parameter, the updated first base point, the third base point, and the target digest satisfy a first preset relationship to obtain a first verification result. The target digest is generated by the first business node based on the first base point, the updated first base point, the commitment data, the third base point, the fourth base point, and the fifth base point.
[0239] Determine whether the fifth baseline, the verification parameters, the commitment data, the fourth baseline, and the target summary satisfy a second preset relationship to obtain a second verification result;
[0240] The verification result for each input data is determined based on the first verification result and the second verification result.
[0241] In specific implementation, the processor 1001, storage device 1002, and network interface 1003 described in the embodiments of this application can execute the embodiments of this application. Figure 5 The implementation methods described in the relevant embodiments of the provided method can also be used to execute the embodiments of this application. Figure 9 The implementation methods described in the relevant embodiments of the provided device will not be repeated here.
[0242] It is understood that in the specific embodiments of this application, data such as information about the object are involved. When the above embodiments of this application are applied to specific products or technologies, permission or consent from the object is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0243] In the above embodiments, the descriptions of each embodiment have their own emphasis. Parts not described in detail in a certain embodiment can be referred to in the relevant descriptions of other embodiments. The technical solutions of this application, in essence, or the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which can be a computer, server, or network device, specifically a processor in the computer device) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium may include: a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), and other media capable of storing program code.
[0244] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, it should be understood that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A data processing method based on a blockchain network, characterized in that, The method includes: The first business node of the blockchain network obtains the target dataset, which includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node of the blockchain network based on the target processing logic. The first business node generates a verification credential based on the target dataset. The verification credential includes updated public data of the verification party, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1. The first service node sends a data verification instruction to the second service node, the data verification instruction being used to instruct the second service node to verify the K input data and the target processing logic according to the verification credentials.
2. The method according to claim 1, characterized in that, The verification public data includes a first base point corresponding to each of the K input data and a second base point corresponding to each of the N output data, where N is an integer greater than or equal to 1; The first service node generates verification credentials based on the target dataset, including: The first business node generates first proof data corresponding to the K input data based on the zero-knowledge proof circuit and the proof party's public data. The first proof data includes the N output data and the K input data after hiding. The first business node updates the first base point included in the verifier public data according to the K input data to obtain the updated verifier public data. The first business node generates second proof data corresponding to each of the K input data.
3. The method according to claim 2, characterized in that, The first service node generates first proof data corresponding to the K input data based on the zero-knowledge proof circuit and the public data of the prover, including: The first service node generates third proof data corresponding to the K input data based on the zero-knowledge proof circuit and the public data of the prover. The third proof data includes the N output data and the K input data. The first business node performs a hiding process on the K input data included in the third proof data to obtain the first proof data corresponding to the K input data.
4. The method according to claim 3, characterized in that, The first service node generates third proof data corresponding to the K input data based on the zero-knowledge proof circuit and the public data of the prover, including: The first service node inputs the K input data into the zero-knowledge proof circuit, and obtains the corresponding N output data by running the zero-knowledge proof circuit; The first business node generates the third proof data corresponding to the K input data based on the K input data, the N output data, and the proof party common data.
5. The method according to any one of claims 2 to 4, characterized in that, The first service node updates the first base point included in the verifier public data based on the K input data to obtain the updated verifier public data, including: The first service node updates the first base point corresponding to each input data in the verification party public data according to each of the K input data, so as to obtain the updated first base point corresponding to each input data; The first business node determines the updated verification public data based on the second base point corresponding to each output data and the updated first base point corresponding to each input data.
6. The method according to any one of claims 2 to 4, characterized in that, The second proof data includes the first base point corresponding to each input data, the updated first base point, the commitment data, the third base point, the fourth base point, the verification parameters, and the fifth base point corresponding to the K input data; The first service node generates second proof data corresponding to each of the K input data based on each input data, including: The first service node generates a third base point corresponding to each input data based on the first base point and a random number; The first service node generates a fourth base point corresponding to each input data based on the fifth base point and the random number; The first business node generates a target summary based on the first base point, the updated first base point, the committed data, the third base point, the fourth base point, and the fifth base point; The first service node generates verification parameters corresponding to each input data based on each input data, the random number, and the target digest.
7. The method according to claim 6, characterized in that, The method further includes: The first business node sends a commitment data acquisition request to the consensus node of the blockchain. The commitment data acquisition request is used to instruct the consensus node to acquire the commitment data corresponding to each of the K input data from the blockchain. The first service node receives the commitment data corresponding to each input data sent by the consensus node. The commitment data is generated by the third service node of the blockchain network based on the fifth basis point and each input data, and written into the blockchain.
8. The method according to claim 1, characterized in that, The method further includes: The first business node receives a first smart contract sent by the consensus node of the blockchain network. The first smart contract is generated by the second business node according to the target processing logic and submitted to the consensus node. The first business node uses the first smart contract to process the K input data to obtain the contract execution result, which includes N output data corresponding to the K input data. The first business node writes the contract execution result and the verification certificate into the blockchain.
9. The method according to claim 1, characterized in that, Before the first business node generates verification credentials based on the target dataset, the method further includes: The first business node queries its local storage space to see if the K input data are stored; If not, the first business node sends an input data acquisition request to the third business node of the blockchain network; The first service node receives the K input data sent by the third service node in response to the input data acquisition request.
10. A data processing method based on a blockchain network, characterized in that, The method includes: The second business node of the blockchain network sends a target dataset to the first business node. The target dataset includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node based on the target processing logic. The second service node receives a data verification instruction sent by the first service node after generating a verification credential based on the target dataset. The verification credential includes updated public data of the verification party, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1. The second service node responds to the data verification instruction and verifies the K input data and the target processing logic according to the verification credentials.
11. The method according to claim 10, characterized in that, The method further includes: The second business node generates the zero-knowledge proof circuit corresponding to the target processing logic; The second business node initializes the zero-knowledge proof circuit according to the common parameters to obtain verifier common data and prover common data. The verifier common data includes the first base point corresponding to each of the K input data and the second base point corresponding to each of the N output data, where N is an integer greater than or equal to 1. The second business node determines the target dataset based on the zero-knowledge proof circuit, the verifier public data, and the prover public data.
12. The method according to claim 11, characterized in that, The data verification instruction includes the verification credentials. The second service node responds to the data verification instruction by verifying the K input data and the target processing logic based on the verification credentials, including: The second business node responds to the data verification instruction by verifying the target processing logic of the K input data based on the updated verification public data and the first proof data; The second business node verifies the K input data based on the second proof data.
13. The method according to claim 12, characterized in that, The second business node responds to the data verification instruction by verifying the target processing logic of the K input data based on the updated verification public data and the first proof data, including: The second service node responds to the data verification instruction to determine whether the verifier public data matches the updated verifier public data; If a match is found, the second business node verifies the first proof data based on the updated public data of the verification party, and obtains the verification result of the target processing logic.
14. The method according to claim 12, characterized in that, The second proof data includes the first base point corresponding to each input data, the updated first base point, the commitment data, the third base point, the fourth base point, the verification parameters, and the fifth base point corresponding to the K input data; The second service node verifies the K input data based on the second proof data, including: For each input data corresponding to the second proof data, the second business node determines whether the first base point, the verification parameters, the updated first base point, the third base point, and the target digest satisfy a first preset relationship, and obtains a first verification result. The target digest is generated by the first business node based on the first base point, the updated first base point, the commitment data, the third base point, the fourth base point, and the fifth base point. The second business node determines whether the fifth base point, the verification parameters, the commitment data, the fourth base point, and the target summary satisfy a second preset relationship, and obtains a second verification result; The second business node determines the verification result of each input data based on the first verification result and the second verification result.
15. A data processing apparatus, characterized in that, The device includes: The acquisition module is used to acquire the target dataset, which includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node of the blockchain network based on the target processing logic. The processing module is used to generate verification credentials based on the target dataset. The verification credentials include updated public data of the verifier, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1. The sending module is used to send a data verification instruction to the second service node, wherein the data verification instruction is used to instruct the second service node to verify the K input data and the target processing logic according to the verification credentials.
16. A data processing apparatus, characterized in that, The device includes: The sending module is used to send a target dataset to the first business node of the blockchain network. The target dataset includes a zero-knowledge proof circuit, verifier public data, and prover public data. The zero-knowledge proof circuit is generated by the second business node of the blockchain network based on the target processing logic. The receiving module is used to receive a data verification instruction sent by the first service node after generating a verification credential based on the target dataset. The verification credential includes updated public data of the verification party, first proof data corresponding to K input data, and second proof data, where K is an integer greater than or equal to 1. The verification module is used to verify the K input data and the target processing logic according to the verification credentials in response to the data verification instruction.
17. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program including program instructions, which are executed by a processor to perform the data processing method based on a blockchain network according to any one of claims 1 to 9, or the data processing method based on a blockchain network according to any one of claims 10 to 14.
Citation Information
Patent Citations
Zero knowledge proving method suitable for protecting privacy of block chain, and medium
CN108418689A
Computer-implemented system and method for trustless zero-knowledge contingent payment
CN111886829A