Dual offline verification method and system based on non-interactive zero-knowledge proof algorithm
By adopting elliptic curve cryptography (ECC) and non-interactive verification methods in the zero-knowledge proof algorithm, the problems of computational complexity and performance bottlenecks in the prior art are solved, and an efficient and secure transaction verification process is achieved.
Patent Information
- Application Number
- CN202510077113.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-01-17
AI Technical Summary
Existing zero-knowledge proof algorithms have computational complexity, performance bottlenecks, trust setting issues, and challenges in transaction verification, especially in non-interactive scenarios.
A non-interactive zero-knowledge proof algorithm based on elliptic curve cryptography (ECC) is used to realize the dual offline verification process by generating transaction data public keys, building transaction vouchers and signatures. This algorithm uses point operations on the ECC curve to optimize the calculation process and improve efficiency.
A simple and efficient transaction verification mechanism is realized, which reduces computing complexity and performance bottlenecks, enhances transaction privacy and security, and improves the transparency and verifiability of the system.
Smart Images

Figure CN119515389B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and in particular to a method and system for realizing dual offline verification based on a non-interactive zero-knowledge proof algorithm. Background Art
[0002] With the rapid development of information technology, privacy protection and data security have become crucial in data transactions and transmission. People's demand for maintaining personal privacy and ensuring data security is becoming increasingly urgent.
[0003] Encryption technology based on Elliptic Curve Cryptography (ECC) has attracted much attention for its excellent security at a shorter key length. Compared with traditional RSA encryption technology, ECC not only performs well in protecting data security, but also reduces system resource usage and transmission delay, making it particularly suitable for resource-constrained environments such as mobile devices. At the same time, Zero-Knowledge Proofs (ZKP), as a core cryptographic technology, can complete verification while protecting personal privacy by only showing the knowledge mastered by the prover to the verifier without revealing any relevant proof content. Zero-knowledge proof technology has broad application potential in digital identity recognition, identity authentication, cryptographic protocols and other fields. It allows the prover to show the verifier the correctness of a statement without exposing any additional information. In transaction scenarios, the zero-knowledge proof algorithm can protect the privacy and security of both parties to the transaction, while verifying whether the payer has the willingness and ability to pay.
[0004] Current zero-knowledge proof algorithms are mainly divided into two categories to verify whether the transaction conditions are met by both parties: (1) interactive zero-knowledge proof; (2) non-interactive zero-knowledge proof. However, these methods have their limitations. For example, interactive zero-knowledge proof may require multiple rounds of communication during the interaction process, which not only increases the complexity of communication but also increases the time cost. In terms of security and privacy protection, interactive zero-knowledge proof may face security risks because there may be collusion between the verifier and the prover. As for application scenarios, non-interactive zero-knowledge proof has wider application potential in certain fields, especially suitable for protecting the anonymity and privacy of transactions. From the perspective of efficiency, the efficiency of interactive zero-knowledge proof is relatively low. Therefore, non-interactive zero-knowledge proof has more advantages due to its simple process. Nevertheless, the currently popular non-interactive zero-knowledge proof technologies such as zk-SNARKs and zk-STARKs, although providing strong privacy protection and transaction verification functions for both parties, also have some problems, including computational complexity, performance bottlenecks, trust setting problems, and challenges in transparency and verifiability. Summary of the invention
[0005] In view of the shortcomings of the prior art, the present invention provides a method and system for realizing dual offline verification based on a non-interactive zero-knowledge proof algorithm.
[0006] In order to solve the above technical problems, the present invention is solved by the following technical solutions:
[0007] A method for implementing dual offline verification based on a non-interactive zero-knowledge proof algorithm includes the following steps:
[0008] Obtain relevant information about the payer and payee in the transaction relationship, where the relevant information includes transaction data, private key, random number and specific point, and use the payee as the verification party;
[0009] Add hidden factors, use ECC curve and combine the private keys of the payer and the payee as well as the hidden factors to generate the transaction data public keys of the payer and the payee;
[0010] The transaction relationship is initially verified based on the transaction data public key. If the transaction data public key matches any point on the ECC curve, the initial verification is successful.
[0011] Based on the transaction data and hidden factors of the payer and the payee, the payer's transaction voucher, the transaction voucher source, the payer's change voucher and the payee's receipt voucher are obtained;
[0012] The payer's change voucher is updated, encrypted using the ECC curve to obtain an encryption result, and based on the encryption result, the payer's transaction voucher, the source of the transaction voucher, the payer's transaction change voucher and the payee's receipt voucher are verified to obtain a verification result;
[0013] Perform hash calculation on the random number and transaction data to obtain the hash value, and then obtain the payer's signature and the payee's signature; and obtain the transaction signature based on the payer's signature and the payee's signature, and obtain a zero-sum result based on the transaction signature. If the zero-sum result meets the preset conditions, the transaction relationship is valid.
[0014] As an implementable method, the public key of the transaction data is represented as follows:
[0015]
[0016] in, The public key representing the transaction data, Respectively represent the multiplication, addition and subtraction of specific points on the ECC curve, Respectively represent specific points on the ECC curve, Respectively represent the transaction data of the payer and the payee, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction.
[0017] As an implementable method, the payer transaction voucher is represented as:
[0018] The payer's transaction change voucher is expressed as:
[0019] The payee needs a receipt, which can be expressed as:
[0020] in, They represent the payee's transaction voucher, the source of the transaction voucher, and the payee's transaction change voucher. Respectively represent the transaction data of the payer and the payee, Respectively represent specific points on the ECC curve, They represent the multiplication and addition of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction.
[0021] As an implementable method, the update of the payer's change voucher, encryption using an ECC curve, and obtaining an encryption result include the following steps:
[0022] The payer's random point and the verifier's random point Make an association and get the random point of the payee , expressed as: , then the payer transaction change voucher is updated, expressed as:
[0023] The random point of the recipient Sent to the verifier, based on the random point of the payee at point Q on the ECC curve Encryption is performed to obtain the encryption result, and the encryption result is expressed as follows:
[0024]
[0025] in, They represent the payee's transaction voucher, the source of the transaction voucher, and the payee's transaction change voucher. Respectively represent the transaction data of the payer and the payee, Respectively represent specific points on the ECC curve, Respectively represent the multiplication, addition and subtraction of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction.
[0026] As an implementable method, the hash calculation is performed based on the random number and the transaction data to obtain the hash value, and then the payee signature and the payee signature are obtained, including the following steps:
[0027] The payer random number is expressed as: , the recipient's random number is expressed as: ;
[0028] The payer's random number and the payee's random number are hashed to obtain the hash value of the transaction information, which is expressed as follows:
[0029]
[0030] Based on the hash value, the payer's signature and the payee's signature are calculated, and the transaction signature is obtained based on the payer's signature and the payee's signature;
[0031] The payer's signature indicates the following:
[0032] The beneficiary's signature indicates the following:
[0033] The transaction signature is expressed as follows:
[0034] Among them, among them, They represent the payee's transaction voucher, the source of the transaction voucher, and the payee's transaction change voucher. Respectively represent specific points on the ECC curve, They represent the multiplication and addition of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction. Indicates the payer's random number. Indicates the random number of the payee.
[0035] As an implementable method, obtaining a zero-sum result based on the new voucher, if the zero-sum result meets a preset condition, the transaction relationship is valid, includes the following steps:
[0036] The zero-sum result is represented as follows:
[0037]
[0038] The preset condition is a preset proof condition, and the preset proof condition is expressed as follows:
[0039] ,
[0040] When the preset proof conditions are met, the transaction relationship is valid;
[0041] in, They represent the payee's transaction voucher, the source of the transaction voucher, and the payee's transaction change voucher. Respectively represent specific points on the ECC curve, They represent the multiplication and addition of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction. They represent the payee's signature and the payee's signature respectively.
[0042] As an implementation method, any two points Q and H are randomly selected on the ECC curve, and the multiplication operation of point Q and point H is expressed as follows:
[0043]
[0044] Wherein, point Q and point H are any two points on the ECC curve.
[0045] A dual offline verification system based on a non-interactive zero-knowledge proof algorithm, comprising a data acquisition module, a first generation module, a preliminary verification module, a first calculation module, an update calculation module and a transaction verification module;
[0046] The data acquisition module is used to obtain relevant information of the payer and the payee in the transaction relationship, wherein the relevant information includes transaction data, private key, random number and specific point, and the payee is used as the verification party;
[0047] The first generating module is used to increase the hidden factor, use the ECC curve and combine the private keys of the payer and the payee and the hidden factor to generate the transaction data public key of the payer and the payee;
[0048] The preliminary verification module performs preliminary verification on the transaction relationship based on the transaction data public key. If the transaction data public key matches any point on the ECC curve, the preliminary verification passes;
[0049] The first calculation module is used to obtain the payer's transaction voucher, the source of the transaction voucher, the payer's change voucher and the payee's receipt voucher based on the transaction data and hidden factors of the payer and the payee;
[0050] The update calculation module updates the payer's change voucher, encrypts it using the ECC curve to obtain an encryption result, and verifies the payer's transaction voucher, the source of the transaction voucher, the payer's transaction change voucher, and the payee's receipt voucher based on the encryption result to obtain a verification result;
[0051] The transaction verification module performs hash calculation on the random number and transaction data to obtain a hash value, and then obtains the payer's signature and the payee's signature; and obtains a transaction signature based on the payer's signature and the payee's signature, and obtains a zero-sum result based on the transaction signature. If the zero-sum result meets the preset conditions, the transaction relationship is valid.
[0052] A computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the method as described above:
[0053] Obtain relevant information about the payer and payee in the transaction relationship, where the relevant information includes transaction data, private key, random number and specific point, and use the payee as the verification party;
[0054] Add hidden factors, use ECC curve and combine the private keys of the payer and the payee as well as the hidden factors to generate the transaction data public keys of the payer and the payee;
[0055] The transaction relationship is initially verified based on the transaction data public key. If the transaction data public key matches any point on the ECC curve, the initial verification is passed;
[0056] Based on the transaction data and hidden factors of the payer and the payee, the payer's transaction voucher, the transaction voucher source, the payer's change voucher and the payee's receipt voucher are obtained;
[0057] The payer's change voucher is updated, encrypted using the ECC curve to obtain an encryption result, and based on the encryption result, the payer's transaction voucher, the source of the transaction voucher, the payer's transaction change voucher and the payee's receipt voucher are verified to obtain a verification result;
[0058] Perform hash calculation on the random number and transaction data to obtain the hash value, and then obtain the payer's signature and the payee's signature; and obtain the transaction signature based on the payer's signature and the payee's signature, and obtain a zero-sum result based on the transaction signature. If the zero-sum result meets the preset conditions, the transaction relationship is valid.
[0059] A dual offline verification device based on a non-interactive zero-knowledge proof algorithm includes a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the following method is implemented:
[0060] Obtain relevant information about the payer and payee in the transaction relationship, where the relevant information includes transaction data, private key, random number and specific point, and use the payee as the verification party;
[0061] Add hidden factors, use ECC curve and combine the private keys of the payer and the payee as well as the hidden factors to generate the transaction data public keys of the payer and the payee;
[0062] The transaction relationship is initially verified based on the transaction data public key. If the transaction data public key matches any point on the ECC curve, the initial verification is successful.
[0063] Based on the transaction data and hidden factors of the payer and the payee, the payer's transaction voucher, the transaction voucher source, the payer's change voucher and the payee's receipt voucher are obtained;
[0064] The payer's change voucher is updated, encrypted using the ECC curve to obtain an encryption result, and based on the encryption result, the payer's transaction voucher, the source of the transaction voucher, the payer's transaction change voucher and the payee's receipt voucher are verified to obtain a verification result;
[0065] Perform hash calculation on the random number and transaction data to obtain the hash value, and then obtain the payer's signature and the payee's signature; and obtain the transaction signature based on the payer's signature and the payee's signature, and obtain a zero-sum result based on the transaction signature. If the zero-sum result meets the preset conditions, the transaction relationship is valid.
[0066] The present invention has significant technical effects due to the adoption of the above technical solution:
[0067] The main application field of the present invention is to verify transaction data (such as amount) and realize the function of continuous proof of transaction through the designed "voucher". The non-interactive zero-knowledge proof algorithm realizes a concise and efficient proof mechanism by constructing a calculation formula that utilizes the commutative law of addition and multiplication of elliptic curve cryptography (ECC). In view of the simplicity of its calculation process, the algorithm can run on platforms with different performances. In addition, a method of using information digest as an encryption factor (similar to nonce) is proposed to combine transaction information with the proof calculation formula, so that the proof process can simultaneously complete the verification of the validity of the information. The concept of transaction voucher is introduced to prove the source of the provided data (amount), and can be further extended to the ability to generate new transactions for multiple received vouchers. In view of the ease of use of the ECC (elliptic curve cryptography) curve, the present invention converts the calculation process into point operations on the ECC curve and optimizes it. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0069] Figure 1 It is a schematic flow diagram of the method of the present invention;
[0070] Figure 2 It is a schematic diagram of the overall structure of the system of the present invention. DETAILED DESCRIPTION
[0071] The present invention is further described in detail below in conjunction with embodiments. The following embodiments are for explanation of the present invention but the present invention is not limited to the following embodiments.
[0072] Embodiment 1:
[0073] A dual offline verification method based on a non-interactive zero-knowledge proof algorithm, such as Figure 1 As shown, the following steps are included:
[0074] S100, obtaining relevant information of the payer and the payee in the transaction relationship, wherein the relevant information includes transaction data, private key, random number and specific point, and taking the payee as the verification party;
[0075] S200, adding a hidden factor, using the ECC curve and combining the private keys of the payer and the payee and the hidden factor to generate the transaction data public key of the payer and the payee;
[0076] S300, preliminarily verify the transaction relationship based on the transaction data public key. If the transaction data public key matches any point on the ECC curve, the preliminary verification is passed;
[0077] S400, based on the transaction data and hidden factors of the payer and the payee, obtain the payer's transaction voucher, the transaction voucher source, the payer's change voucher and the payee's receipt voucher;
[0078] S500, updating the payer's change voucher, encrypting it with an ECC curve, obtaining an encryption result, and verifying the payer's transaction voucher, the transaction voucher source, the payer's transaction change voucher, and the payee's receipt voucher based on the encryption result to obtain a verification result;
[0079] S600, perform hash calculation on the random number and transaction data to obtain a hash value, and then obtain the payer's signature and the payee's signature; and obtain a transaction signature based on the payer's signature and the payee's signature, and obtain a zero-sum result based on the transaction signature. If the zero-sum result meets the preset conditions, the transaction relationship is valid.
[0080] The credential in this application can be understood as an encrypted digital string.
[0081] In one embodiment, the public key of the transaction data is represented as follows:
[0082]
[0083] in, The public key representing the transaction data, Respectively represent the multiplication, addition and subtraction of specific points on the ECC curve, Respectively represent specific points on the ECC curve, Respectively represent the transaction data of the payer and the payee, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction.
[0084] The transaction voucher of the payer is expressed as:
[0085] The payer's transaction change voucher is expressed as:
[0086] The payee needs a receipt, which can be expressed as:
[0087] in, They represent the payee's transaction voucher, the source of the transaction voucher, and the payee's transaction change voucher. Respectively represent the transaction data of the payer and the payee, Respectively represent specific points on the ECC curve, They represent the multiplication and addition of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction.
[0088] In one embodiment, the updating of the payer's change voucher and the encryption using the ECC curve to obtain the encryption result include the following steps:
[0089] The payer's random point and the verifier's random point Make an association and get the random point of the payee , expressed as: , then the payer transaction change voucher is updated, expressed as:
[0090] The random point of the recipient Sent to the verifier, based on the random point of the payee at point Q on the ECC curve Encryption is performed to obtain the encryption result, and the encryption result is expressed as follows:
[0091]
[0092] in, They represent the payee's transaction voucher, the source of the transaction voucher, and the payee's transaction change voucher. Respectively represent the transaction data of the payer and the payee, Respectively represent specific points on the ECC curve, Respectively represent the multiplication, addition and subtraction of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction.
[0093] Wherein, point Q and point H are any two points on the ECC curve.
[0094] It can be understood that throughout the process, the symbols used in the calculation formula are " respectively represent the addition, multiplication and subtraction of points on the ECC curve, where subtraction is the operation of taking the inverse of a point and then adding it, and the other symbols used are the addition and subtraction operations of numbers in the usual sense. The calculation order of addition, multiplication and subtraction of points is the same as the calculation order of numbers in the usual sense. In particular, this document does not explain the calculation method of addition, multiplication and subtraction on the ECC curve (calculation on discrete groups), but only discusses the influence of its calculation results and characteristics on the algorithm.
[0095] Elliptic curve (ECC) encryption technology is often used in cryptography. Elliptic curves consist of a large set of points called C, which can be added, subtracted, or multiplied by integers (scalars). Given an integer k and using scalar multiplication, we can calculate , which is also a point on the curve C. Given another integer j, we can also calculate , which is equal to Addition and scalar multiplication operations on elliptic curves preserve the commutative and associative properties of addition and multiplication:
[0096]
[0097] In the formula, k and j are both private keys, demonstrating the addition of two private keys to obtain the public key , which is equivalent to the sum of the corresponding public keys of each private key In ECC, a very large number k is chosen as the private key, then is regarded as the corresponding public key. In other words, the multiplication of elliptic curve points is easy, but the "division" of curve points is extremely difficult.
[0098] Therefore, the proof principle adopted throughout the process is as follows;
[0099] By constructing a calculation formula that applies the characteristics of the ECC addition and multiplication commutative law, the information that needs to be verified is appropriately hidden in the number, realizing the zero-knowledge proof process based on ECC. The number that needs to be hidden is the number of transactions (amount). Zero-sum verification: The sum of the output minus the input is always equal to zero, proving that the transaction did not create new funds out of thin air and will not display the actual amount. Ownership of the transaction output: The ownership of the transaction output is guaranteed by owning the ECC private key, and proving that an owner owns these private keys is not achieved by directly signing the transaction.
[0100] It also involves the transaction algorithm, where Q and H are specific points on a known ECC encryption curve. This point will be pre-selected and will not change during subsequent transactions.
[0101] Taking SECD256K1 as an example, we take points Q and H on it as follows. In the following formula, the multiplication operation of points Q and H is similar to the process of calculating the public key. The addition of points Q and H can be understood as the addition of two points on the curve. The multiplication operation of points Q and H is expressed as follows:
[0102]
[0103]
[0104] In a specific transaction, the value of the input voucher should be equal to the sum of the change value and the payment value of the recipient. Based on this idea, it can be expressed as follows:
[0105]
[0106] The payer is the source of the currency value for this transaction: ; Change value of the payee transaction: ; The recipient needs to receive the currency value: , only when the payee enters a voucher with sufficient value ( ), and the change value of the transaction ( ) and the recipient's payment currency value ( ) and are the same, the above formula is valid, which can prove that the payer has sufficient amount of currency value and promised currency value.
[0107] The public key of the generated transaction data is expressed as follows:
[0108]
[0109] in, The public key representing the transaction data, Respectively represent the multiplication, addition and subtraction of specific points on the ECC curve, Respectively represent specific points on the ECC curve, Respectively represent the transaction data of the payer and the payee, The “×Q” operation in the formula can be understood as the process of generating a public key for the amount, corresponding to the Q point on the ECC curve. As can be seen from the above formula, the problem of proving the same is that the verification party (payee) can obtain the “ "value, or it can be proved that" " is a public key on curve Q to prove the transaction is established.
[0110] The payer enters the voucher, which is the source of the voucher for this transaction: ;Payer transaction change voucher: ; The payee needs a receipt: ; Based on the above information, we can get and summarize the general form of the voucher: .
[0111] Therefore, we need to prove whether the voucher is accurate, add another point Q on the curve, and the factors generated by both sides are unknown to each other, so some tricks are needed to enable the payee to verify the validity of this transaction. and The association is as follows:
[0112]
[0113] The payer's transaction change voucher is expanded to:
[0114] It can be seen that by distributing the factors into three variables, and It is already included in the certificate, just add Just send it to the party that can verify it. In order to save the information, curve Q is used for encryption. The encryption result is as follows:
[0115]
[0116] in, They represent the payee's transaction voucher, the source of the transaction voucher, and the payee's transaction change voucher. Respectively represent the transaction data of the payer and the payee, Respectively represent specific points on the ECC curve, Respectively represent the multiplication, addition and subtraction of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction. It can be seen that a "change" operation is required before the transaction. This operation process depends on the payer's mastery of the " "," "and" If you do not fully understand the above information, you will not be able to complete the "change" operation, and the recipient will need to " ", thus proving its ownership of the voucher. At the same time, the payee obtains a new " "," "and" ", to protect the voucher and make it impossible for the payee to obtain ownership of the "change" voucher.
[0117] The transaction signature will also be used for verification. After the transaction is initiated, two data exchanges are required. The data needs to be saved and not modified during this process to realize the identification of the transaction. Both parties need to generate their own Nonce for signature, which are and The HASH value of the transaction information is as follows:
[0118]
[0119] besides,
[0120] Signature of payer:
[0121] Signature of Payee:
[0122] Transaction signature:
[0123] Transaction signature:
[0124] From this we can see that:
[0125] The proof formula is as follows:
[0126]
[0127]
[0128] When the above formula is established, it can be proved that the transaction is valid.
[0129] Embodiment 2:
[0130] A dual offline verification system based on a non-interactive zero-knowledge proof algorithm, such as Figure 2 As shown, it includes a data acquisition module 100, a first generation module 200, a preliminary verification module 300, a first calculation module 400, an update calculation module 500 and a transaction verification module 600;
[0131] The data acquisition module 100 is used to acquire relevant information of the payer and the payee in the transaction relationship, wherein the relevant information includes transaction data, private key, random number and specific point, and the payee is used as the verification party;
[0132] The first generating module 200 is used to increase the hidden factor, use the ECC curve and combine the private keys of the payer and the payee and the hidden factor to generate the transaction data public key of the payer and the payee;
[0133] The preliminary verification module 300 performs preliminary verification on the transaction relationship based on the transaction data public key. If the transaction data public key matches any point on the ECC curve, the preliminary verification is passed;
[0134] The first calculation module 400 is used to obtain the payer's transaction voucher, the transaction voucher source, the payer's change voucher and the payee's receipt voucher based on the payer's and the payee's transaction data and hidden factors;
[0135] The update calculation module 500 updates the payer's change voucher, encrypts it using the ECC curve, obtains an encryption result, and verifies the payer's transaction voucher, the source of the transaction voucher, the payer's transaction change voucher, and the payee's receipt voucher based on the encryption result to obtain a verification result;
[0136] The transaction verification module 600 performs hash calculation on the random number and transaction data to obtain a hash value, and then obtains the payer's signature and the payee's signature; and obtains a transaction signature based on the payer's signature and the payee's signature, and obtains a zero-sum result based on the transaction signature. If the zero-sum result meets the preset conditions, the transaction relationship is valid.
[0137] In addition, it should be noted that the shapes and names of the parts and components of the specific embodiments described in this specification may be different. Any equivalent or simple changes made based on the structure, features and principles described in the patent concept of the present invention are included in the protection scope of the patent of the present invention. The technicians in the technical field of the present invention can make various modifications or supplements to the specific embodiments described or replace them in a similar manner, as long as they do not deviate from the structure of the present invention or exceed the scope defined by the claims, they should all fall within the protection scope of the present invention.
Claims
1. A method for implementing dual offline verification based on a non-interactive zero-knowledge proof algorithm, characterized in that: The following steps are involved: Obtain relevant information about the payer and payee in the transaction relationship, where the relevant information includes transaction data, private key, random number and specific point, and use the payee as the verification party; Add hidden factors, use ECC curve and combine the private keys of the payer and the payee as well as the hidden factors to generate the transaction data public keys of the payer and the payee; The transaction relationship is initially verified based on the transaction data public key. If the transaction data public key matches any point on the ECC curve, the initial verification is passed; Based on the transaction data and hidden factors of the payer and the payee, the payer's transaction voucher, the transaction voucher source, the payer's change voucher and the payee's receipt voucher are obtained; The payer's change voucher is updated, encrypted using the ECC curve to obtain an encryption result, and based on the encryption result, the payer's transaction voucher, the source of the transaction voucher, the payer's transaction change voucher and the payee's receipt voucher are verified to obtain a verification result; Perform hash calculation on the random number and transaction data to obtain the hash value, and then obtain the payer's signature and the payee's signature; and obtain the transaction signature based on the payer's signature and the payee's signature, and obtain the zero-sum result based on the transaction signature. If the zero-sum result meets the preset conditions, the transaction relationship is valid; The public key of the transaction data is represented as follows: The transaction voucher of the payer is expressed as: The payer's transaction change voucher is expressed as: The payee needs a receipt, which can be expressed as: in, The public key representing the transaction data, They represent the payer's transaction voucher, the payer's transaction change voucher, and the payee's receipt voucher. Respectively represent the transaction data of the payer and the payee, Respectively represent specific points on the ECC curve, Respectively represent the multiplication, addition and subtraction of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction.
2. According to claim 1, the method for realizing dual offline verification based on non-interactive zero-knowledge proof algorithm is characterized in that: The updating of the payer's change voucher and the encryption using the ECC curve to obtain the encryption result include the following steps: The payer's random point and the verifier's random point Make an association and get the random point of the payee , expressed as: , then the payer transaction change voucher is updated, expressed as: The random point of the recipient Sent to the verifier, based on the random point of the payee at point Q on the ECC curve Encryption is performed to obtain the encryption result, and the encryption result is expressed as follows: in, Indicates the updated payer transaction change voucher. Respectively represent the transaction data of the payer and the payee, Respectively represent specific points on the ECC curve, Respectively represent the multiplication, addition and subtraction of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction.
3. The method for realizing dual offline verification based on non-interactive zero-knowledge proof algorithm according to claim 1, characterized in that: The method of performing hash calculation based on the random number and the transaction data to obtain a hash value, and then obtaining the payer's signature and the payee's signature, includes the following steps: The payer random number is expressed as: , the recipient's random number is expressed as: ; The payer's random number and the payee's random number are hashed to obtain the hash value of the transaction information, which is expressed as follows: Based on the hash value, the payer's signature and the payee's signature are calculated, and the transaction signature is obtained based on the payer's signature and the payee's signature; The payer's signature indicates the following: The beneficiary's signature indicates the following: The transaction signature is expressed as follows: in, They represent the payee's transaction voucher and the payee's transaction change voucher respectively. Respectively represent specific points on the ECC curve, They represent the multiplication and addition of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction. Indicates the payer's random number. Indicates the random number of the payee.
4. The method for realizing dual offline verification based on non-interactive zero-knowledge proof algorithm according to claim 1, characterized in that: The zero-sum result is obtained based on the transaction signature. If the zero-sum result meets the preset conditions, the transaction relationship is valid, including the following steps: The zero-sum result is represented as follows: The preset condition is a preset proof condition, and the preset proof condition is expressed as follows: , When the preset proof conditions are met, the transaction relationship is valid; in, Respectively represent specific points on the ECC curve, They represent the multiplication and addition of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction. Respectively represent the signature of the payee and the signature of the payee, A hash value representing transaction information.
5. The method for realizing dual offline verification based on non-interactive zero-knowledge proof algorithm according to claim 1, characterized in that: Randomly select any two points on the ECC curve, namely point Q and point H, and the multiplication operation of point Q and point H is expressed as follows: Wherein, point Q and point H are any two points on the ECC curve.
6. A dual offline verification system based on a non-interactive zero-knowledge proof algorithm, characterized in that: It includes a data acquisition module, a first generation module, a preliminary verification module, a first calculation module, an update calculation module and a transaction verification module; The data acquisition module is used to obtain relevant information of the payer and the payee in the transaction relationship, wherein the relevant information includes transaction data, private key, random number and specific point, and the payee is used as the verification party; The first generating module is used to increase the hidden factor, use the ECC curve and combine the private keys of the payer and the payee and the hidden factor to generate the transaction data public key of the payer and the payee; The preliminary verification module performs preliminary verification on the transaction relationship based on the transaction data public key. If the transaction data public key matches any point on the ECC curve, the preliminary verification passes; The first calculation module is used to obtain the payer's transaction voucher, the source of the transaction voucher, the payer's change voucher and the payee's receipt voucher based on the transaction data and hidden factors of the payer and the payee; The update calculation module updates the payer's change voucher, encrypts it using the ECC curve to obtain an encryption result, and verifies the payer's transaction voucher, the source of the transaction voucher, the payer's transaction change voucher, and the payee's receipt voucher based on the encryption result to obtain a verification result; The transaction verification module performs hash calculation on the random number and the transaction data to obtain a hash value, and then obtains the payee's signature and the payee's signature; and obtains a transaction signature based on the payee's signature and the payee's signature, and obtains a zero-sum result based on the transaction signature. If the zero-sum result meets a preset condition, the transaction relationship is valid; The public key of the transaction data is represented as follows: The transaction voucher of the payer is expressed as: The payer's transaction change voucher is expressed as: The payee needs a receipt, which can be expressed as: in, The public key representing the transaction data, They represent the payer's transaction voucher, the payer's transaction change voucher, and the payee's receipt voucher. Respectively represent the transaction data of the payer and the payee, Respectively represent specific points on the ECC curve, Respectively represent the multiplication, addition and subtraction of specific points on the ECC curve, They represent the random numbers generated by the true random number generator for the payer and the payee during the transaction.
7. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.
8. A device for implementing dual offline verification based on a non-interactive zero-knowledge proof algorithm, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Transaction verification method and device, electronic equipment and computer readable storage medium
CN119313345A