Data security verification method, verification device, electronic device and storage medium
Through multi-party security computing and recursive zero-knowledge proof technology, complex computing circuits are split and verified, and the problems of high computational complexity and low efficiency in the existing technology are solved, achieving efficient data security verification.
Patent Information
- Application Number
- CN202510163948.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-02-14
AI Technical Summary
When existing zero-knowledge proof technology deals with complex computing or large-scale circuits, the computational complexity of the verification process has increased sharply, resulting in excessive resource consumption and low verification efficiency, making it difficult to meet the needs of efficient data security verification.
Through the multi-party safety computing protocol, the common parameters of the target computing circuit are calculated, the target computing circuit is split into multiple sub-circuits, the original constraints of each sub-circuit are constructed based on the common parameters, constraint aggregation is performed, the target constraint set is generated, the sub-proof of each sub-circuit is generated, and the sub-proof is verified through recursive means to obtain a global proof to determine the data security verification result.
The number of constraints is reduced, the computational complexity is reduced, the computing efficiency is improved, the efficiency of data security verification is significantly improved, single point of failure and security risks are avoided, and the ability to resist malicious behavior is enhanced.
Smart Images

Figure CN119622751B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of information security technology, and in particular, relates to a data security verification method, a verification device, an electronic device and a storage medium. Background Art
[0002] With the rapid development of distributed technologies such as blockchain, Internet of Things, cloud computing, and federated learning, the demand for data privacy protection has increased dramatically, and how to verify data security has become an important issue.
[0003] At present, the existing zero-knowledge proof technology performs well in relatively simple computing scenarios and can provide effective privacy protection and data security verification. However, when dealing with complex calculations or large-scale circuits, the computational complexity of the verification process increases sharply with the growth of the circuit scale, resulting in excessive resource consumption and low verification efficiency. Moreover, as the complexity of the application increases, the number of constraints in the proof circuit expands rapidly, leading to performance bottlenecks, making it difficult to meet the needs of efficient data security verification in scenarios that require processing complex models or algorithms, or when computing resources are limited.
[0004] Therefore, how to improve the efficiency of data security verification has become an urgent problem to be solved. Summary of the invention
[0005] The embodiments of the present application provide a data security verification method, a verification device, an electronic device and a storage medium, aiming to improve the efficiency of data security verification.
[0006] In a first aspect, an embodiment of the present application provides a data security verification method, the method comprising: based on a multi-party secure computing protocol, calculating the common parameters of a target computing circuit by multiple participants; splitting the target computing circuit to obtain multiple sub-circuits; constructing original constraints corresponding to each of the sub-circuits based on the common parameters to generate an original constraint set; performing constraint aggregation based on the original constraint set to obtain a target constraint set, the target constraint set including target constraints corresponding to each of the sub-circuits; generating sub-proofs corresponding to each of the sub-circuits based on the target constraint set and the common parameters; recursively verifying each of the sub-proofs to obtain a global proof; and determining a data security verification result based on the global proof.
[0007] In a possible implementation, the constraint aggregation is performed based on the original constraint set to obtain a target constraint set, including: dividing the original constraint set into multiple original constraint subsets, each of the original constraint subsets including at least two of the original constraints; assigning a weight to each of the original constraints in each of the original constraint subsets; based on the weights corresponding to each of the original constraints, aggregating multiple original constraints in each of the original constraint subsets into a target constraint to obtain target constraints corresponding to each of the original constraint subsets; and constructing the target constraint set based on the target constraints corresponding to each of the original constraint subsets.
[0008] In a possible implementation, the target constraint includes a target polynomial constraint, and generating a sub-proof corresponding to each of the sub-circuits based on the target constraint set and the public parameters includes: generating a polynomial commitment corresponding to each of the sub-circuits based on the target constraint set and the public parameters; determining an expected value corresponding to each of the sub-circuits based on random points in each of the sub-circuits and the target polynomial constraints corresponding to each of the sub-circuits; and determining a sub-proof corresponding to each of the sub-circuits based on the polynomial commitment, random points and expected values corresponding to each of the sub-circuits.
[0009] In a possible implementation, recursively verifying each of the sub-proofs to obtain a global proof includes: verifying the sub-proof corresponding to the first sub-circuit based on the public parameters and the polynomial commitment of the first sub-circuit to obtain a first verification result, where the first sub-circuit is any of the sub-circuit; verifying the sub-proof corresponding to the second sub-circuit based on the public parameters, the first verification result and the polynomial commitment of the second sub-circuit to obtain a second verification result, where the second sub-circuit is any of the multiple sub-circuits except the first sub-circuit; and repeating the above verification steps until all of the multiple sub-circuits are verified to obtain the global proof.
[0010] In a possible implementation, the multi-party secure computing protocol is based on which multiple parties calculate the common parameters of the target computing circuit, including: based on the target computing circuit, determining the input data of each of the participants; dividing the input data of each of the participants into multiple sub-input data, and sending each of the sub-data to other participants respectively; each of the participants performs local calculations based on the input data and the received sub-input data to obtain an intermediate result; each of the participants performs intermediate result exchange and local calculations based on the intermediate result to obtain calculation results corresponding to each of the participants respectively; each of the participants performs result aggregation based on each of the calculation results to obtain the common parameters.
[0011] In a possible implementation, each of the participants aggregates results based on each of the calculation results to obtain the common parameter, including: selecting a preset number of aggregators from the multiple participants; the preset number of aggregators aggregates results based on each of the calculation results to obtain the common parameter.
[0012] In a possible implementation, splitting the target computing circuit to obtain a plurality of sub-circuits includes: splitting the target computing circuit based on the number of gates in the target computing circuit to obtain the plurality of sub-circuits.
[0013] In the second aspect, an embodiment of the present application provides a data security verification device, which includes: a parameter calculation module, which is used to calculate the common parameters of the target computing circuit through multiple participants based on a multi-party secure computing protocol; a circuit splitting module, which is used to split the target computing circuit to obtain multiple sub-circuits; a constraint construction module, which is used to construct the original constraints corresponding to each of the sub-circuits based on the common parameters to generate an original constraint set; a constraint aggregation module, which is used to perform constraint aggregation based on the original constraint set to obtain a target constraint set, and the target constraint set includes the target constraints corresponding to each of the sub-circuits; a sub-proof generation module, which is used to generate sub-proofs corresponding to each of the sub-circuits based on the target constraint set and the common parameters; a global proof generation module, which is used to verify each of the sub-proofs in a recursive manner to obtain a global proof; a data security verification module, which is used to determine the data security verification result based on the global proof.
[0014] In a third aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method described in the first aspect or any one of the implementation methods thereof is implemented.
[0015] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in the first aspect or any one of the implementation methods thereof is implemented.
[0016] In a fifth aspect, an embodiment of the present application provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of the method described in the first aspect or any one of the implementation methods thereof.
[0017] Compared with the prior art, the embodiments of the present application have the following beneficial effects: based on a multi-party secure computing protocol, the public parameters of the target computing circuit are calculated by multiple participants, and no longer rely on a single trusted party, thus avoiding potential single point failures and security risks, and enhancing the ability to resist malicious behavior; the target computing circuit is split to obtain multiple sub-circuits; based on the public parameters, the original constraints corresponding to each sub-circuit are constructed to generate an original constraint set; based on the original constraint set, constraints are aggregated to obtain a target constraint set, which reduces the number of constraints, reduces the computational complexity, and improves the computational efficiency; based on the target constraint set and the public parameters, sub-proofs corresponding to each sub-circuit are generated; each sub-proof is recursively verified to obtain a global proof; based on the global proof, the data security verification result is determined, and data security verification can be achieved by only verifying the recursively generated global proof, which reduces the computational complexity of the verification process, reduces the consumption of computing resources caused by verifying each sub-proof one by one, and significantly improves the efficiency of data security verification.
[0018] It can be understood that the data security verification device, electronic device, computer-readable storage medium and computer program product provided in the embodiments of the present application have the same beneficial effects as the above-mentioned data security verification method, which will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0020] Figure 1 A flowchart of a data security verification method provided in one embodiment of the present application;
[0021] Figure 2 A schematic diagram of a data security verification method provided by an embodiment of the present application;
[0022] Figure 3 A structural block diagram of a data security verification device provided in one embodiment of the present application;
[0023] Figure 4 A schematic diagram of the structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0024] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0025] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0026] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0027] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.
[0028] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0029] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0030] To facilitate understanding, some concepts involved in the embodiments of the present application are first explained.
[0031] Recursive zero-knowledge proof: By dividing a large proof process into multiple sub-proofs, and then recursively verifying these sub-proofs, the entire system is finally verified.
[0032] Halo 2 protocol: An advanced recursive zero-knowledge proof protocol, it is one of the important technical solutions to improve the efficiency of data security verification. Based on the polynomial commitment scheme, efficient verification of complex computing tasks is achieved recursively. The Halo 2 protocol allows large-scale computing processes to be decomposed into multiple sub-processes, and the final recursive proof is generated by aggregating the proofs of the sub-processes, thereby reducing the overall verification complexity. Among them, polynomial commitment is one of the core mechanisms of Halo 2, which means that by committing to the coefficients of the polynomial, the verifier can verify the correctness of the polynomial without viewing the specific data. Compared with traditional zero-knowledge proofs, the Halo 2 protocol significantly reduces the proof size and verification time by optimizing polynomial commitments and recursive verification while ensuring data security.
[0033] Low trust assumption: refers to the assumption that most participants in the system may be dishonest or have malicious behavior.
[0034] Multi-Party Computation (MPC): is a cryptographic technology that allows multiple participants to jointly calculate the result of a function without revealing their own data, ensuring the privacy and security of the input of each party.
[0035] Byzantine Assumption: A fault-tolerant model that assumes that some participants in the system may behave maliciously (such as providing false information or not cooperating), while the system can still operate normally.
[0036] With the increasing demand for data privacy protection, zero-knowledge proof technology has been widely used in blockchain, distributed systems, machine learning and other fields. Existing zero-knowledge proof protocols can effectively protect data security and privacy in some scenarios, but they still face problems such as insufficient applicability in low-trust environments, low verification efficiency and difficulty in handling large-scale calculations.
[0037] In order to solve the problems existing in the prior art, the present application provides a data security verification method, which is based on a multi-party secure computing protocol, and calculates the public parameters of a target computing circuit by multiple participants; the target computing circuit is split into multiple sub-circuits; the original constraints corresponding to each sub-circuit are constructed based on the public parameters to generate an original constraint set; constraints are aggregated based on the original constraint set to obtain a target constraint set, and the target constraint set includes the target constraints corresponding to each sub-circuit; based on the target constraint set and the public parameters, sub-proofs corresponding to each sub-circuit are generated; each sub-proof is verified recursively to obtain a global proof; based on the global proof, a data security verification result is determined.
[0038] The technical solution of the present application will be described in detail below with reference to the accompanying drawings.
[0039] Figure 1 A flowchart of a data security verification method provided in an embodiment of the present application is shown in FIG. Figure 2 This is a schematic diagram of a data security verification method provided by an embodiment of the present application. For the sake of convenience, only the part related to the present embodiment is shown. The method provided by the present embodiment specifically includes the following steps:
[0040] S110, based on a multi-party secure computing protocol, public parameters of a target computing circuit are calculated by multiple participants.
[0041] Specifically, public parameters usually include the mathematical structure used to define zero-knowledge proofs (ZKP) (such as group generators, moduli, etc.) or the necessary parameters of the specific algorithm supporting ZKP (such as random numbers, polynomial coefficients, verification keys, etc.).
[0042] In one possible implementation, based on the target computing circuit, the input data of each participant is determined; the input data of each participant is divided into multiple sub-input data, and each sub-input data is sent to other participants respectively; each participant performs local calculation based on the input data and the received sub-input data to obtain an intermediate result; each participant performs intermediate result exchange and local calculation based on the intermediate result to obtain a calculation result corresponding to each participant; each participant aggregates the results based on the calculation results to obtain a common parameter.
[0043] Among them, the input data of each participant refers to sensitive information that needs to be protected and distributed; each participant aggregates the results based on each calculation result to obtain a public parameter, including: selecting a preset number of aggregators from multiple participants; a preset number of aggregators aggregate the results based on each calculation result to obtain a public parameter.
[0044] As an example, Figure 2As shown, multi-party secure computing is used in the trust startup phase to divide the target computing circuit or target computing task into multiple secret fragments, each secret fragment contains a proof key, a verification key, and toxic waste, etc. The toxic waste is destroyed, and the system is established and public parameter calculations are performed based on the proof key and verification key contained in each secret fragment.
[0045] In a specific implementation, generating public parameters includes the following steps:
[0046] Step 1: Initialization and secret sharing
[0047] Each participant generates its own random input (such as random numbers, random polynomial coefficients, etc.), and divides the input of each participant into multiple shares through a secret sharing protocol (such as Shamir secret sharing) and distributes it to other participants. Each participant only receives a part of the data, ensuring that a single participant cannot know the input of other participants.
[0048] As an example, the execution steps of the Shamir secret sharing algorithm include:
[0049] 1) Choose a large prime number and an integer ,in Must be greater than , It is the minimum number of parties required to recover the secret. These two parameters will be used to confirm the sharing method and the security of the information.
[0050] 2) Choose a randomly generated polynomial , Among them, the secret This is the secret information we want to share. are randomly generated coefficients. To make the polynomial unique, in addition to the secret The outer coefficients should be generated randomly.
[0051] 3) Calculate the polynomial based on the selected prime number p A value in the integer range. That is, calculate These values are the shared secrets that are distributed to the participants.
[0052] 4) Distribute the calculated shared secret to other participants. Each participant will receive a pair of values ,in Indicates the sharing number. A shared value representing a secret.
[0053] 5) To recover the original secret information, at least This The parties combine the shared values and reconstruct the polynomial using the Lagrangian method. And calculate the secret .
[0054] For example, assuming there are 5 participants, each participant can divide its input data into 5 sub-input data, and each participant receives any one of the sub-input data; it can also divide its input data into 3 sub-input data and randomly distribute them to any 3 of the participants.
[0055] Step 2: Local Calculation
[0056] Each participant performs local computation based on the received shares, such as calculating partial polynomial values or random combinations. The computation process is performed on secret shared or encrypted data to ensure privacy.
[0057] Specifically, after receiving the sharing from other participants, each participant uses its own input data and the received shared data to perform local calculations according to the predetermined calculation rules, such as addition or multiplication. This step does not involve disclosing any input, and all calculations are performed on encrypted or secret shared data.
[0058] Step 3: Intermediate result exchange
[0059] Each participant encrypts or splits the intermediate results of the local calculation and sends them to other participants. Each participant uses the received intermediate results to continue the next round of local calculation.
[0060] Step 4: Result aggregation
[0061] All participants reconstruct or encrypt and decrypt through secret sharing and combine to obtain the calculation results. The final public parameters are shared by all participants, and no single participant can reconstruct the generation process alone.
[0062] Specifically, after completing the intermediate calculations, all participants will merge the local calculation results through secret sharing or encryption algorithms, and gradually restore the calculation results. Participants can only reconstruct the calculation results when they receive enough shares.
[0063] As an example, each participant passes the result fragment it holds to the predetermined aggregator, and the aggregator restores the complete calculation result based on the shared information. During the recovery process, the input of any participant is not leaked, and the result can be securely shared among all participants.
[0064] It should be noted that the number of aggregators is customized according to actual conditions and this application does not limit this.
[0065] S120, splitting the target computing circuit into multiple sub-circuits.
[0066] As an example, the target computing circuit is split based on the circuit scale (eg, the number of gates) of the target computing circuit to obtain multiple sub-circuits.
[0067] As another example, the target computing circuit is split based on the circuit depth (eg, the number of computing layers) of the target computing circuit to obtain multiple sub-circuits.
[0068] S130, constructing original constraints corresponding to each sub-circuit based on the common parameters to generate an original constraint set.
[0069] In a specific implementation, each subcircuit is converted into a set of constraints, namely primitive constraints, based on common parameters to describe the relationship between the input and output of each subcircuit. Primitive constraints include addition constraints, multiplication constraints, and logical relationship constraints (such as Boolean relations).
[0070] As an example, based on the Halo 2 protocol, the original constraints of each subcircuit are encoded as polynomials, each constraint corresponds to a polynomial equation, and the polynomial constraints corresponding to each subcircuit are obtained. These polynomial constraints check the correctness of each subcircuit by verifying the zero point.
[0071] S140, performing constraint aggregation based on the original constraint set to obtain a target constraint set, where the target constraint set includes target constraints corresponding to each sub-circuit.
[0072] In a possible implementation, the original constraint set is divided into multiple original constraint subsets, each original constraint subset includes at least two original constraints; a weight is assigned to each original constraint in each original constraint subset; based on the weights corresponding to each original constraint, multiple original constraints in each original constraint subset are aggregated into a target constraint to obtain target constraints corresponding to each original constraint subset; based on the target constraints corresponding to each original constraint subset, a target constraint set is constructed.
[0073] In a specific implementation, multiple original constraints in the original constraint set that are logically similar, computationally repeated, or structurally related are taken as an original constraint subset, and the original constraint set is divided into multiple original constraint subsets. In each original constraint subset, a suitable weight is assigned to each original constraint, and based on the weight of each original constraint, each original constraint subset is replaced with a target constraint, and the target constraint corresponding to each original constraint subset is constructed as a target constraint set.
[0074] As an example, suppose the original constraint set is a set of arithmetic constraints:
[0075] ;
[0076] By adding the original constraint subset The original constraints in Merge into a new target constraint , thus reducing the number of constraints:
[0077] ;
[0078] in, It is defined as The polynomial of the original constraints, is the common input, is the prover's private witness, is the weight, ensuring the contribution ratio of different original constraints and the merged target constraint Should be mathematically equivalent to the original set of constraints.
[0079] In order to improve the adaptability of the solution and achieve more efficient allocation, the weights in this embodiment are Perform dynamic adjustments based on the priority or importance of the original constraints, for example:
[0080]
[0081] in, and Dynamically set based on constraint verification complexity.
[0082] S150, generating sub-proofs corresponding to each sub-circuit based on the target constraint set and the common parameters.
[0083] In one possible implementation, based on the target constraint set and the common parameters, a polynomial commitment corresponding to each subcircuit is generated; based on the random points in each subcircuit and the target polynomial constraints corresponding to each subcircuit, the expected value corresponding to each subcircuit is determined; based on the polynomial commitment, random points and expected value corresponding to each subcircuit, the sub-proof corresponding to each subcircuit is determined.
[0084] In the specific implementation, the generation process of the sub-proof corresponding to each sub-circuit is as follows:
[0085] 1) Generate polynomial commitment: For each subcircuit, first convert the computation of the subcircuit into a polynomial constraint. Then, use the polynomial commitment structure in the Halo 2 algorithm to encrypt the polynomial constraint. The commitment value will contain enough information to prove that the computation of the subcircuit is correct.
[0086] 2) Proof generation: By decomposing the target computational circuit into multiple subcircuits, the prover constructs a polynomial representation and generates a corresponding polynomial commitment. Using the compactness and random verification of polynomial commitments, the prover selects random points and only verifies the consistency of the input and intermediate results at these points, without having to process the global input one by one. Furthermore, through a recursive construction mechanism, the sub-proofs of each subcircuit are gradually merged to generate a small zero-knowledge proof, which not only verifies the consistency of the commitment and the computational process, but also protects the privacy of the input data.
[0087] Exemplarily, it is assumed that the polynomial constraint corresponding to any subcircuit is:
[0088]
[0089] We need to prove that for a random point , the calculation results is correct, i.e. , without directly revealing the entire polynomial.
[0090] Step 1: Calculate the polynomial value
[0091] First, based on random points Compute the expected value corresponding to the polynomial constraint:
[0092] .
[0093] Step 2: Generate polynomial commitment
[0094] This commitment is usually generated using a commitment scheme such as the KZG commitment. The commitment is generated using a cryptographic algorithm that contains some information about the polynomial constraint but does not reveal all the details of the polynomial constraint.
[0095] Pick a random value , used to encrypt polynomial constraints.
[0096] Use the KZG commitment scheme to calculate the polynomial commitment value. The polynomial commitment value Representing polynomials An encrypted version of .
[0097] The simplified representation is as follows:
[0098] ;
[0099] At this time, the polynomial commitment value is an encrypted value that contains some information about the polynomial constraints but does not reveal the actual coefficients of the polynomial.
[0100] Step 3: Generate zero-knowledge proof
[0101] The prover uses the Halo 2 algorithm to generate a zero-knowledge proof that Be correct without leaking The core of zero-knowledge proof is to generate a proof. The prover will use polynomial commitment and some encryption technology to ensure that the verifier can verify correctness.
[0102] Step 4: Verification Process
[0103] The validator receives the proof and the commitment value , and then use the Halo 2 protocol's verification algorithm to check whether the proof is valid. The verifier only needs to confirm Is it correct and verify whether the proof meets the promised value and the given input .
[0104] S160, recursively verify each sub-proof to obtain a global proof.
[0105] In one possible implementation, a sub-proof corresponding to a first subcircuit is verified based on a public parameter and a polynomial commitment of the first subcircuit to obtain a first verification result, where the first subcircuit is any subcircuit; a sub-proof corresponding to a second subcircuit is verified based on the public parameter, the first verification result, and the polynomial commitment of the second subcircuit to obtain a second verification result, where the second subcircuit is any subcircuit among the multiple subcircuits except the first subcircuit; the above verification steps are repeated until all subcircuits among the multiple subcircuits are verified to obtain a global proof.
[0106] In the specific implementation, a recursive proof framework is constructed, and the proof result of the previous layer of sub-circuit is used as the input of the proof of the next layer of sub-circuit, and a new proof is recursively generated. At the recursive level, not only the proof of the current layer needs to be verified, but also the sub-proof corresponding to the sub-circuit of the previous layer needs to be verified in a nested manner, until the global proof of the entire target computing circuit is finally obtained.
[0107] As an example, Figure 2 As shown, the original proof object (target computing circuit or target computing task) is split into circuits and a zero-knowledge proof for each sub-circuit is generated. The zero-knowledge proofs of the sub-circuits are combined into a zero-knowledge proof for the complete circuit. A recursive proof is performed based on the zero-knowledge proof for the complete circuit, and data security verification is performed on the original proof object.
[0108] S170, determining the data security verification result based on the global proof.
[0109] In a specific implementation, each sub-proof is verified recursively. The recursive proof process allows for nested verification of each sub-proof, forming a unified global proof. This global proof simultaneously includes the correctness verification of all sub-circuits and essentially compresses the sub-proofs corresponding to all sub-circuits, enabling the verifier to determine the data security verification result by only verifying the finally generated global proof instead of verifying all sub-proofs one by one. The verification time is independent of the number of sub-proofs, significantly improving the verification efficiency, especially suitable for blockchain environments with limited resources.
[0110] The technical solution provided in this embodiment is based on a multi-party secure computing protocol. Multiple participating parties calculate the common parameters of the target computing circuit, no longer relying on a single trusted party, avoiding potential single-point failures and security risks, and enhancing the ability to resist malicious behaviors. The target computing circuit is split into multiple sub-circuits; based on the common parameters, the original constraints corresponding to each sub-circuit are constructed to generate an original constraint set; based on the original constraint set, constraint aggregation is performed to obtain a target constraint set, reducing the number of constraints, lowering the computational complexity, and improving the computational efficiency; based on the target constraint set and the common parameters, the sub-proofs corresponding to each sub-circuit are generated; each sub-proof is verified recursively to obtain a global proof; based on the global proof, the data security verification result is determined. Data security verification can be achieved by only verifying the globally generated proof recursively, reducing the computational complexity of the verification process and the consumption of computing resources caused by verifying each sub-proof one by one, and significantly improving the efficiency of data security verification.
[0111] In summary, the technical solution proposed in this application mainly includes the following key innovation points:
[0112] (1) Design of a zero-knowledge proof protocol under low trust assumptions
[0113] When designing the zero-knowledge proof protocol in this application, multi-party secure computing (MPC) is used to replace the traditional trusted startup phase, solving the problem in the prior art that high trust assumptions rely on a trusted third party. On this basis, the protocol transforms the dependent security assumptions into Byzantine fault tolerance or honest majority assumptions to ensure secure execution in a distributed environment. By weakening or removing the role of the trusted third party, the system can jointly generate zero-knowledge proofs among multiple participating parties without relying on a single trust source. This design is applicable to large-scale distributed networks and blockchain applications, reducing the risk of security vulnerabilities and enhancing the decentralized characteristics of the protocol.
[0114] (2) Optimization of the generation and verification of recursive zero-knowledge proofs based on improved Halo 2
[0115] In order to solve the computational complexity problem of traditional zero-knowledge proofs in large-scale computing tasks, this application introduces the recursive zero-knowledge proof (Recursive ZKP) technology based on the improved Halo 2, which decomposes the complete computing task into multiple sub-circuits, generates independent zero-knowledge proofs for each sub-circuit, and then nests and combines the sub-proofs in a recursive manner to finally generate a global proof. This recursive process can significantly reduce the circuit expansion coefficient of the zero-knowledge proof, while reducing the computational burden of the verifier, so that the verification process can be carried out quickly under limited resources. This optimized design is particularly suitable for resource-constrained blockchain environments, ensuring efficient verification when executed on the chain.
[0116] (3) Implementation of lightweight verification mechanism
[0117] In order to achieve efficient zero-knowledge proof verification in a blockchain environment, this application designs a lightweight verification mechanism that avoids the high cost of verifying each sub-proof one by one on the chain by only verifying the recursively generated global proof. This not only greatly improves the verification efficiency, but also reduces the consumption of computing resources. It is particularly suitable for complex task verification in smart contracts. The verifier only needs to verify one global proof on the chain, and this global proof has recursively verified the correctness of all sub-proofs. In this way, the system can achieve rapid verification of distributed computing tasks without sacrificing security, thereby improving the scalability of blockchain applications.
[0118] Based on the above key innovations, the technical solution provided by this application has the following beneficial effects:
[0119] (1) Integration of trust management and technical security
[0120] Removing reliance on trusted third parties helps improve the autonomy and flexibility of the system and reduces the trust requirements for centralized institutions. This application uses multi-party secure computing to disperse trust to all participants, so that each node can ensure data security when collaboratively generating zero-knowledge proofs, effectively simplifying the trust management process, enabling the system to maintain security without relying on a single trusted entity, reducing reliance on external management, and improving the robustness and credibility of the system.
[0121] (2) Optimization of computing resource management and zero-knowledge proof generation efficiency
[0122] By introducing recursive zero-knowledge proofs, this application significantly reduces the computing resource consumption required for proof generation and verification. In resource-limited environments, such as blockchain or distributed computing systems, recursive proof technology enables the system to complete complex task verification at a lower computing cost, reducing system load, effectively improving overall resource utilization and management efficiency, and making resource allocation more flexible and efficient.
[0123] (3) Combination of blockchain smart contract verification management and lightweight verification mechanism
[0124] The lightweight verification mechanism proposed in this application not only improves the verification efficiency of zero-knowledge proofs, but also optimizes the verification process of blockchain. Only the recursively generated global proof needs to be verified on the chain. This design reduces the resource and time consumption during the execution of smart contracts, and helps managers better allocate computing tasks and bandwidth resources of blockchain nodes. Through this mechanism, the scalability of the system is significantly enhanced, and the management of the verification process is also simplified, making the execution of tasks in large-scale application scenarios smoother and more efficient.
[0125] Figure 3 This is a structural block diagram of a data security verification device provided by an embodiment of the present application. For the sake of convenience, only the part related to the embodiment of the present application is shown. Figure 3 The data security verification device 300 may include a parameter calculation module 301, a circuit splitting module 302, a constraint construction module 303, a constraint aggregation module 304, a sub-proof generation module 305, a global proof generation module 306 and a data security verification module 307.
[0126] The parameter calculation module 301 is used to calculate the common parameters of the target computing circuit through multiple participants based on the multi-party secure computing protocol.
[0127] The circuit splitting module 302 is used to split the target computing circuit into multiple sub-circuits.
[0128] The constraint construction module 303 is used to construct original constraints corresponding to each sub-circuit based on the common parameters to generate an original constraint set.
[0129] The constraint aggregation module 304 is used to perform constraint aggregation based on the original constraint set to obtain a target constraint set, where the target constraint set includes target constraints corresponding to each sub-circuit.
[0130] The sub-proof generation module 305 is used to generate sub-proofs corresponding to each sub-circuit based on the target constraint set and the public parameters.
[0131] The global proof generation module 306 is used to recursively verify each sub-proof to obtain a global proof.
[0132] The data security verification module 307 is used to determine the data security verification result based on the global proof.
[0133] A data security verification device provided in an embodiment of the present application has the same beneficial effects as the above-mentioned data security verification method.
[0134] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0135] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0136] Figure 4 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Figure 4 As shown, the electronic device 4 of this embodiment includes: at least one processor 40 ( Figure 4 Only one is shown in the figure), a memory 41, and a computer program 42 stored in the memory 41 and executable on at least one processor 40, the processor 40 executes the computer program 42 to implement the above Figure 1 or Figure 2 The steps in the method embodiment, or the implementation of the above Figure 3 Functions of each module / unit in the device embodiment.
[0137] The electronic device 4 may be a computing device such as a desktop computer, a notebook, a PDA, or a cloud server. The electronic device 4 may include but is not limited to a processor 40 and a memory 41. Those skilled in the art will appreciate that Figure 4 It is only an example of the electronic device 4 and does not constitute a limitation on the electronic device 4. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, it may also include input and output devices, network access devices, etc.
[0138] The processor 40 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0139] In some embodiments, the memory 41 may be an internal storage unit of the electronic device 4, such as a hard disk or memory of the electronic device 4. In other embodiments, the memory 41 may also be an external storage device of the electronic device 4, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device 4. Further, the memory 41 may also include both an internal storage unit and an external storage device of the electronic device 4. The memory 41 is used to store an operating system, an application program, a boot loader (BootLoader), data, and other programs, such as program codes of a computer program. The memory 41 may also be used to temporarily store data that has been output or is to be output.
[0140] The embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.
[0141] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to an electronic device, a recording medium, a computer memory, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), an electrical carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a disk or an optical disk.
[0142] A computer-readable storage medium provided in an embodiment of the present application has the same beneficial effects as the above-mentioned data security verification method.
[0143] An embodiment of the present application provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.
[0144] A computer program product provided in an embodiment of the present application has the same beneficial effects as the above-mentioned data security verification method.
[0145] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0146] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0147] In the embodiments provided in the present application, it should be understood that the disclosed devices / equipment and methods can be implemented in other ways. For example, the device / equipment embodiments described above are merely schematic, for example, the division of the modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0148] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0149] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A data security verification method, characterized in that: The method comprises: Based on the multi-party secure computing protocol, multiple parties calculate the public parameters of the target computing circuit; Splitting the target computing circuit to obtain multiple sub-circuits; Constructing original constraints corresponding to each of the sub-circuits based on the common parameters to generate an original constraint set; Perform constraint aggregation based on the original constraint set to obtain a target constraint set, wherein the target constraint set includes target constraints corresponding to each of the sub-circuits; Based on the target constraint set and the common parameters, generate sub-proofs corresponding to the sub-circuits respectively; Verify each of the sub-proofs recursively to obtain a global proof; Based on the global proof, determine a data security verification result; Among them, the constraint aggregation is performed based on the original constraint set to obtain the target constraint set, including: dividing the original constraint set into multiple original constraint subsets, each of the original constraint subsets includes at least two of the original constraints; assigning weights to each of the original constraints in each of the original constraint subsets; based on the weights corresponding to each of the original constraints, aggregating multiple original constraints in each of the original constraint subsets into a target constraint to obtain the target constraints corresponding to each of the original constraint subsets; and constructing the target constraint set based on the target constraints corresponding to each of the original constraint subsets.
2. The method according to claim 1, characterized in that The target constraint includes a target polynomial constraint, and generating sub-proofs corresponding to each of the sub-circuits based on the target constraint set and the common parameters includes: Based on the target constraint set and the common parameters, generating polynomial commitments corresponding to each of the sub-circuits; Determine the expected value corresponding to each of the subcircuits based on the random points in each of the subcircuits and the target polynomial constraints corresponding to each of the subcircuits; Based on the polynomial commitment, random point and expected value respectively corresponding to each of the sub-circuits, the sub-proofs respectively corresponding to each of the sub-circuits are determined.
3. The method according to claim 2, characterized in that The recursive verification of each of the sub-proofs to obtain a global proof includes: Verify the sub-proof corresponding to the first sub-circuit based on the public parameter and the polynomial commitment of the first sub-circuit to obtain a first verification result, where the first sub-circuit is any of the sub-circuits; Verifying the sub-proof corresponding to the second sub-circuit based on the public parameter, the first verification result and the polynomial commitment of the second sub-circuit to obtain a second verification result, where the second sub-circuit is any sub-circuit among the multiple sub-circuits except the first sub-circuit; The above verification steps are repeatedly performed until all sub-circuits in the multiple sub-circuits have completed verification, thereby obtaining the global proof.
4. The method according to claim 1, characterized in that: The method of calculating the public parameters of the target computing circuit by multiple participants based on the multi-party secure computing protocol includes: Determining input data of each of the participants based on the target computing circuit; Splitting the input data of each participant into a plurality of sub-input data, and sending each sub-input data to other participants respectively; Each of the participants performs local calculation based on the input data and the received sub-input data to obtain an intermediate result; Each of the participants performs intermediate result exchange and local calculation based on the intermediate result to obtain calculation results corresponding to each of the participants; Each of the participants aggregates the results based on the calculation results to obtain the common parameters.
5. The method according to claim 4, characterized in that The participants aggregate the results based on the calculation results to obtain the common parameters, including: selecting a preset number of aggregators from the plurality of participants; The preset number of aggregators aggregate the results based on the calculation results to obtain the common parameters.
6. The method according to claim 1, characterized in that: The target computing circuit is split into multiple sub-circuits, including: The target computing circuit is split based on the number of gates in the target computing circuit to obtain the multiple sub-circuits.
7. A data security verification device, characterized in that: The device comprises: A parameter calculation module, used to calculate the public parameters of the target computing circuit through multiple participants based on a multi-party secure computing protocol; A circuit splitting module, used for splitting the target computing circuit into multiple sub-circuits; A constraint construction module, used for constructing original constraints corresponding to each of the sub-circuits based on the common parameters to generate an original constraint set; A constraint aggregation module, configured to perform constraint aggregation based on the original constraint set to obtain a target constraint set, wherein the target constraint set includes target constraints corresponding to each of the sub-circuits; A sub-proof generation module, used for generating sub-proofs corresponding to each of the sub-circuits based on the target constraint set and the common parameters; A global proof generation module, used to recursively verify each of the sub-proofs to obtain a global proof; A data security verification module, used to determine a data security verification result based on the global proof; The constraint aggregation module is specifically used to divide the original constraint set into multiple original constraint subsets, each of which includes at least two of the original constraints; assign a weight to each of the original constraints in each of the original constraint subsets; based on the weights corresponding to each of the original constraints, aggregate the multiple original constraints in each of the original constraint subsets into a target constraint to obtain the target constraints corresponding to each of the original constraint subsets; and construct the target constraint set based on the target constraints corresponding to each of the original constraint subsets.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Intelligent contract authentication data privacy protection method and system based on zero knowledge proof
CN110781521A
Cipher state prediction verification method and device, equipment and storage medium
CN113965331A
Blockchain oracle methods and systems based on zero-knowledge proof with recursive prover
US20240421998A1