A Blockchain Scaling Method Based on Multinomial Commitment Algorithm
By using a coding-based multinomial commitment method and constructing commitment values with Merkle trees and RS codes, the problems of trusted initialization and prover efficiency in blockchain scaling are solved, achieving efficient and secure blockchain scaling.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIHANG UNIV
- Filing Date
- 2024-12-09
- Publication Date
- 2026-08-04
AI Technical Summary
Existing multinomial commitment methods suffer from the problem of relying on trusted initialization in blockchain scaling, and the efficiency of provers and the size of proofs are difficult to balance, affecting the security and practicality of blockchain.
A coding-based polynomial commitment method is adopted. Common parameters are output through a parameter generation algorithm, commitment values are constructed using Merkle trees and RS codes, and the correctness of polynomial assignment is ensured through an interactive proof protocol, thereby reducing the computational overhead of the prover and improving efficiency.
This solution addresses the trusted initialization dependency problem of the multinomial commitment method, improves the security and versatility of the scheme, reduces the computational overhead of provers, and achieves efficient blockchain scaling.
Smart Images

Figure CN119788259B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of blockchain and information security technology, and in particular to a coding-based multinomial commitment method suitable for blockchain scaling. Background Technology
[0002] Blockchain is a distributed ledger technology that enables the sharing of a transparent and immutable ledger among nodes in a computer network, providing a trustless and decentralized platform for executing transactions and exchanging information. Due to its transparency and immutability, blockchain technology has attracted widespread attention in various applications. However, when implementing large-scale applications, blockchain still faces scalability issues due to limitations in transaction processing speed and network throughput. Layer-2 protocols can achieve scalability without altering the underlying blockchain by moving transaction or data processing off-chain. In recent years, zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK) has played a crucial role in the development of Layer-2 protocols.
[0003] zk-SNARKs are a cryptographic technique that allows a prover to generate a proof of the correctness of a complex computation, and this proof can be verified by any verifier. Although the original computation may be very complex, the generated proof is concise and can be efficiently transmitted and stored. Simultaneously, verifiers can quickly confirm the validity of the proof, requiring far fewer computational resources than repeating the original computation. zk-SNARKs allow provers to generate a concise and efficiently verifiable proof of the validity of blockchain transactions, playing a crucial role in Layer-2 solutions such as zk-Rollups. Typically, zk-SNARKs can be constructed using the Polynomial Commitment Scheme (PCS), and the efficiency of the PCS significantly impacts key performance indicators such as prover speed, proof size, and verifier speed.
[0004] Based on the above analysis, researching the multinomial commitment method and improving its performance plays an important role in enhancing the overall performance of blockchain scaling solutions.
[0005] To further promote the large-scale application of blockchain, scholars have been dedicated to researching highly efficient multinomial commitment methods in recent years and using them to achieve blockchain scaling. However, existing research schemes still face two problems: first, the reliance on trusted initialization; and second, the difficulty in balancing prover efficiency and proof size. Summary of the Invention
[0006] To overcome the aforementioned technical deficiencies, this application provides an encoding-based multinomial commitment method suitable for blockchain scaling, the specific scheme of which is as follows:
[0007] S1. Using a parameter generation algorithm, a set of common parameters are output for subsequent algorithm operations, with safety parameters and the number of polynomial variables as input.
[0008] S2. The prover performs a polynomial commitment algorithm to commit to the target polynomial. The input is the coefficients and common parameters of the target polynomial, and the output is the commitment value.
[0009] S3. The polynomial commitment opening algorithm is used to convince the verifier that the target polynomial is correctly assigned at a certain set of points. The polynomial commitment opening algorithm is an interactive proof protocol involving the prover and the verifier. The coefficients of the target polynomial are used as the prover's input, and the common parameters, commitment values, polynomial assignment points, and assignment results of the target polynomial are used as the common inputs of the prover and the verifier. The verifier outputs acceptance or rejection.
[0010] The technical solution of this application includes three algorithms, as follows:
[0011] 1) Parameter generation algorithm: This algorithm takes the safety parameter and the number of polynomial variables as input, and outputs a set of common parameters for subsequent algorithm calculations;
[0012] 2) Polynomial Commitment Algorithm: This algorithm, executed by the prover, is used to commit to a multilinear polynomial. Its input includes the coefficients and common parameters of the multilinear polynomial, and the output is the commitment value. The specific steps are as follows: First, the coefficients of the target polynomial are arranged into multiple vectors of equal length, and each vector is expanded using random values. Then, each expanded vector is treated as a new univariate polynomial, and each polynomial is encoded using a Reed-Solomon (RS) code, resulting in a matrix where each column is an RS codeword. Finally, a Merkle tree is used to commit to the matrix column by column, and the root node of the Merkle tree is output as the commitment value.
[0013] 3) Polynomial Commitment Opening Algorithm: This algorithm is an interactive proof protocol involving both the prover and the verifier, designed to convince the verifier that the target polynomial has been correctly assigned values at a certain set of points. The prover's input includes the coefficients of the target polynomial, while the shared input for both prover and verifier includes common parameters, commitment values, polynomial assignment points, and the assignment results of the target polynomial. After a series of interactions, the verifier outputs acceptance or rejection. Specifically, in this process, the prover and verifier first jointly invoke the Batch Fast RS Code Proxies Approach Interactive Apocalypse Proof to test whether each column in the matrix corresponding to the commitment value is an RS codeword. Subsequently, the prover and verifier perform multiple rounds of interactive operations. In each round, the prover decomposes the polynomial into lower-dimensional polynomials, then performs consistency tests on the polynomials before and after decomposition, as well as the polynomial assignment results, and commits to the decomposition results using a Merkle tree. Finally, the decomposition results in each round are verified using the Batch Fast RS Code Proxies Approach Interactive Apocalypse Proof to ensure that the decomposition results are correct RS codewords.
[0014] Furthermore, the above-mentioned coding-based multinomial commitment method also performs the following steps when used to achieve blockchain scaling:
[0015] S4. In zk-Rollup, the blockchain state is updated by aggregators calculating a large number of transaction results off-chain on the blockchain.
[0016] S5. Use the constructed SNARK to generate a short proof of the correctness of the updated state, and submit the generated proof to the smart contract on the blockchain.
[0017] S6. By verifying the proofs generated above in smart contracts, on-chain users can confirm the validity of a large number of transactions, thereby enabling blockchain scaling.
[0018] The technical effects achieved by using the above-described technical solution in the embodiments of this application are as follows:
[0019] First, this solution addresses the reliance on trusted initialization in existing polynomial commitment methods, improving the security and versatility of the scheme. Since the parameter generation algorithm in this scheme only requires public values as input, it does not rely on a trusted third party for parameter generation. Second, it addresses the difficulty in balancing prover efficiency and proof size in existing polynomial commitment methods. While maintaining an acceptable proof size, it reduces the prover computational overhead, improving the scheme's practicality. Firstly, due to the efficient proximity testing protocol of RS codes, PCS constructed based on RS codes has a smaller proof size. This scheme effectively solves the prover efficiency problem of RS code-based PCS. The main reason for the low prover efficiency of existing RS code-based PCS is the need to encode the entire polynomial coefficients, while RS codes typically have low encoding efficiency. To address this issue, this scheme arranges the polynomial coefficients into multiple shorter vectors and encodes these shorter vectors in parallel, significantly reducing encoding time and thus improving the prover efficiency of the PCS. Attached Figure Description
[0020] The accompanying drawings exemplify embodiments and form part of the specification, serving together with the textual description to explain exemplary implementations of the embodiments. The illustrated embodiments are for illustrative purposes only and do not limit the scope of the claims. Throughout the drawings, the same reference numerals refer to similar but not necessarily identical elements.
[0021] Figure 1 This is a flowchart illustrating the coding-based multinomial commitment method in this application;
[0022] Figure 2 A comparison chart showing the efficiency characteristics of the polynomial commitment method proposed in this application and existing coding-based polynomial commitment methods;
[0023] Figure 3 This is a comparison chart showing the efficiency of the polynomial commitment method proposed in this application and existing coding-based polynomial commitment methods. Detailed Implementation
[0024] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application. All other embodiments obtained by those skilled in the art based on the embodiments in this application without inventive effort are within the scope of protection of this application.
[0025] It should be noted that the descriptions involving "first," "second," etc., in the embodiments of this application are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined with "first" or "second" may explicitly or implicitly include at least one of that feature. Furthermore, the technical solutions of the various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. If the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed in this application.
[0026] In the description of this application, it should be understood that the numerical labels before the steps do not indicate the order of the steps, but are only used to facilitate the description of this application and to distinguish each step, and therefore should not be construed as a limitation of this application.
[0027] First, a definition of the terminology used in this application is provided:
[0028] Polynomials: A polynomial is an algebraic expression composed of the product of constants and powers of variables, obtained through addition and subtraction operations. Based on the number of variables, polynomials can be divided into single-variable polynomials and multi-variable polynomials. A single-variable polynomial contains only one variable and is in the form of a linear combination of a series of power terms, such as common quadratic and cubic equations. The main characteristic of this type of polynomial is that the powers of the variables can be any non-negative integers. Multilinear polynomials involve multiple variables, but the exponent of each variable in each term does not exceed 1, meaning each variable is linear. Multilinear polynomials are suitable for representing simple linear relationships between different variables and are widely used in fields such as multiple linear regression, linear algebra, and tensor operations in computer science.
[0029] Polynomial Commitment Scheme (PCS) is an important tool in cryptography used to prove the assignment of a committed polynomial at a certain point. For example, PCS is widely used to construct zero-knowledge proofs and verifiable secret sharing.
[0030] Merkle Tree: A Merkle tree is a tree-like data structure used to verify data integrity. It is constructed by first dividing the data into smaller blocks, calculating a hash value for each block, and designating each block as a leaf node. Then, it iterates upwards level by level, combining the hash values of adjacent leaf nodes to calculate their respective hash values, which become the parent nodes of these two leaf nodes. This process continues until only the top-level hash value remains, the root node. This structure efficiently verifies the integrity and consistency of data blocks because it only requires checking the associated path hash values.
[0031] Merkle Tree Commitment Protocol: The Merkle Tree Commitment Protocol includes the following three algorithms: MT.Com, MT.Open, and MT.Verify. MT.Com takes a set of vectors as input and outputs the root node of the Merkle tree constructed from those vectors. MT.Open takes the preimage of a leaf node of a Merkle tree as input and outputs the path from that leaf node to the root node. MT.Verify takes the root node of a Merkle tree, the preimage of a leaf node of a Merkle tree, and the path from that leaf node to the root node as input and determines the consistency of these input values; if they are consistent, it outputs 1; otherwise, it outputs 0.
[0032] zk-Rollup: zk-Rollup is a solution for Layer-2 scaling of blockchains, designed to reduce the on-chain data processing burden by packaging a large number of transactions off-chain into a single transaction and submitting it to the blockchain. It can significantly reduce the cost and confirmation time per transaction. Due to its efficiency and security, zk-Rollup is widely regarded as an important tool for solving the blockchain scaling problem.
[0033] zk-SNARKs are a cryptographic technique that allows provers to generate a proof of the correctness of a complex computation, and this proof can be verified by any verifier. Although the original computation may be very complex, the generated proof is concise and can be efficiently transmitted and stored. Simultaneously, verifiers can quickly confirm the validity of the proof, requiring far fewer computational resources than repeating the original computation. zk-SNARKs allow provers to generate a concise and efficiently verifiable proof of the validity of blockchain transactions, playing a crucial role in Layer-2 solutions such as zk-Rollup. In zk-Rollup, by batch verifying a large number of transactions off-chain and only providing proofs of transaction correctness generated by zk-SNARKs to the on-chain system, the on-chain transaction processing time can be significantly reduced, increasing transaction throughput. Improving the efficiency of zk-SNARKs directly reduces computational resource consumption and latency, thereby lowering operating costs, enabling more nodes to participate in the network, and increasing decentralization. A more efficient proof generation and verification process can not only speed up transaction processing and improve user experience, but also reduce the cost per transaction, thus promoting the large-scale application of blockchain technology. Improving the efficiency of zk-SNARKs will provide strong support for the further development of Layer-2 scaling technology, meeting the needs of a wider range of users and applications.
[0034] The three main efficiency metrics in zk-SNARKs are prover time, verifier time, and proof size. A typical construction of zk-SNARKs is a combination of Polynomial Interactive OracleProof (PIOP) and Polynomial Commitment Schemes (PCS). PIOP is a multi-round interactive proof where, in each round, the verifier sends a challenge to the prover to query the assignment of a polynomial at a certain point, and the prover responds in each round using a polynomial oracle. PCS allows the prover to commit to a polynomial and convince the verifier that the polynomial has a value at a set of common points. zk-SNARKs can be constructed by instantiating the polynomial oracle in PIOP using PCS. Generally speaking, the efficiency of PCS has a significant impact on the performance of zk-SNARKs.
[0035] Most existing high-performance zk-SNARKs are built upon PCS (Proof-of-Stake) systems that rely on trusted initialization. Directly applying these zk-SNARKs to Layer-2 blockchain extensions would compromise the decentralized nature of the blockchain. During trusted initialization, the system generates a set of public reference strings, which are used for subsequent proof and verification processes. Trusted initialization typically requires a trusted third party to generate these parameters and ensure the security and correctness of the generation process. The most significant problem here is the trust assumption: if the process of generating public parameters during initialization is maliciously manipulated, an attacker could generate false proofs undetected. This means that the security of the entire system depends on the absolute integrity and confidentiality of the initialization phase. Furthermore, trusted initialization is usually a one-time process, difficult to modify or update once completed, making the system inflexible in the face of potential security threats. To mitigate these problems, the community is exploring trustless solutions, such as using multi-party computation techniques to distribute trust, but these methods also introduce additional complexity and computational costs. Therefore, although trusted initialization provides a fundamental guarantee for the efficiency of zk-SNARKs, its inherent trust and security challenges remain an issue that needs to be continuously addressed, especially in decentralized applications such as blockchain Layer-2 extensions.
[0036] Furthermore, prover efficiency is a major performance bottleneck in current zk-SNARKs, especially in scenarios requiring large-scale computation, such as blockchain Layer-2 scaling. While PCS relying on trusted initialization has a smaller proof size, the numerous elliptic curve operations result in low prover efficiency. PCS based on encoding construction offers relatively fast proof generation without requiring trusted initialization, thus attracting widespread attention in academia. However, due to the difficulty in balancing prover time and proof size, zk-SNARKs constructed using these PCS still struggle to meet the efficiency requirements of current blockchain scaling. The main computational bottleneck of PCS based on RS codes lies in encoding time. For a polynomial of size , an RS code-based PCS has a verification time and proof size of order of magnitude, and its proof size is generally within acceptable limits, typically several hundred kilobytes. However, because the time spent encoding the polynomial coefficients during the commitment process is , its proof time remains at the order of magnitude. Linear-time coded error-correcting codes, such as Generalized Spielman (GS) codes or Expand Accumulate (EA) codes, can also be used to construct polynomial commitments, and the encoding and proof times are typically several times or even tens of times faster than those based on RS codes. However, unlike RS codes, GS and EA codes lack efficient proximity testing protocols, resulting in final verification times and proof sizes that remain at the level of megabytes, which is unacceptable for Layer-2 blockchain scaling.
[0037] To further promote the large-scale application of blockchain, scholars have been working in recent years to study highly efficient multinomial commitment methods and to implement blockchain scaling based on them. However, existing research methods still face two problems.
[0038] The first issue is the reliance on trusted initialization. Existing high-performance PCS systems rely on a common reference string to reduce proof size, but this inevitably introduces the challenge of trusted initialization: during initialization, a trusted third party or a secure multi-party computation protocol is needed to establish the common reference string. This means that the security of the entire system depends on the absolute integrity and confidentiality of the initialization phase. Furthermore, trusted initialization is usually a one-time process; once completed, it is difficult to change or update. How to securely and efficiently update and upgrade the common reference string remains a challenge.
[0039] The second challenge is balancing prover efficiency and proof size. While coding-based PCS does not rely on trusted initialization, it struggles to achieve this balance. Existing RS-code-based PCS can produce smaller proofs, but the long encoding time of RS codes results in lower prover efficiency. While PCS based on linear-time coded error-correcting codes offers faster provers, the generated proofs tend to be larger. Designing an efficient multinomial commitment method based on coding to balance, or even simultaneously balance, prover efficiency and proof size remains a significant challenge.
[0040] To address the aforementioned problems, this invention proposes a coding-based multinomial commitment method suitable for blockchain scaling. To facilitate understanding of the technical solutions provided in the embodiments of this application by those skilled in the art, the relevant technologies are described below:
[0041] See Figure 1 The coding-based multinomial commitment method applicable to blockchain scaling in this application embodiment includes:
[0042] S1. Using a parameter generation algorithm, a set of common parameters is output with safety parameters and the number of polynomial variables as input.
[0043] S2. The prover performs a polynomial commitment algorithm to commit to the target polynomial. The inputs are the coefficients and common parameters of the target polynomial, and the output is the commitment value.
[0044] S3. The polynomial commitment opening algorithm ensures that the verifier is convinced that the target polynomial is correctly assigned at a certain set of points. The polynomial commitment opening algorithm is an interactive proof protocol involving the prover and the verifier. The coefficients of the target polynomial are used as the prover's input, and the common parameters, commitment values, polynomial assignment points, and assignment results of the target polynomial are used as the common inputs of the prover and the verifier. The verifier outputs acceptance or rejection.
[0045] Furthermore, in S2, a multinomial commitment algorithm is executed to commit to the target polynomial, specifically including:
[0046] The coefficients of the target polynomial are decomposed into a matrix, which is then expanded with random values. Each row of the expanded matrix is then treated as a new polynomial, and the RS codes of these new polynomials are committed using a Merkle tree. Finally, the commitment value is output.
[0047] Furthermore, in S3, the polynomial commitment opening algorithm ensures that the verifier is convinced that the target polynomial is correctly assigned at a certain set of points, specifically including:
[0048] The prover and verifier first conduct an initial test using a batch fast RS code proximity cross-evangelism proof. Then, the prover performs calculations based on the verifier's challenge and iteratively decomposes and verifies the polynomial through multiple rounds. In each round of iteration, the calculation results are committed through a Merkle tree. Finally, further verification and testing are conducted using a batch fast RS code proximity cross-evangelism proof to ensure the correctness of the results.
[0049] Specifically, the steps in S1-S3 above can be as follows:
[0050] set up The witness It is the verifier. Given a finite field Let L represent The multiplicative coset on [a, b]. It has one variable of size μ, an upper bound of dimension d, and a size N = d. μ , defined in The polynomial on is represented as use Represent a multilinear polynomial, Represents its coefficient vector, Represents a single-variable polynomial with the same set of coefficients. express The set of all assignments on L. Given a code rate ρ∈(0,1), the RS code... Represents a set Furthermore, for multilinear polynomials with an arbitrary number of variables μ Assume N = 2 μ = mm′, where m and m′ are positive integers. And for any Make exist Make The Merkle tree commitment protocol MT = (MT.Com, MT.Open, MT.Verify) takes a set of vectors as output and outputs the root node of the Merkle tree constructed from the set of vectors. MT.Open takes the preimage corresponding to a leaf node of the Merkle tree as input and outputs the path from the leaf node to the root node. MT.Verify takes the root node of a Merkle tree, the preimage corresponding to a leaf node of the Merkle tree, and the path from the leaf node to the root node as input and judges the consistency of the above input values. If they are consistent, it outputs 1; otherwise, it outputs 0.
[0051] The parameter generation algorithm, polynomial commitment algorithm, and polynomial commitment opening algorithm included in the RS code-based multilinear polynomial commitment method are as follows:
[0052] Parameter generation algorithm: pp←Gen(1) λ ,μ): Input security parameter 1λ And the number of variables μ in the multilinear polynomial, output common parameters Where m′=O(logN) is a power of 2, m=N / m′ is an integer, and L0 is a multiplicative coset and |L0|=O(m).
[0053] Multinomial commitment algorithm: Given The coefficients (f1,...,f) N ), implement:
[0054] 1) The objective polynomial The coefficients are partitioned to obtain m′ vectors of size m. For j∈[m′], The coefficient is (f (j-1)·m+1 ,f (j-1)·m+2 ,…,f j·m Add m random entries to each vector to obtain m′ vectors of size 2m. Construct m′ single-variable polynomials of size 2m from each vector.
[0055] 2) Randomly select a multilinear polynomial of size 2m. calculate and set
[0056] Polynomial commitment opening algorithm: and implement:
[0057] 1) and right Invoke the batch fast RS code proximity interactive oracle proof. 2) in
[0058] 3) A random vector
[0059] 4) set up For i∈[μ+1], calculate Where x μ+1 =0, and and Through unique decomposition for Obtained. For i∈[μ], send Where L i ={x 2 |x∈Li-1}
[0060] 5) Consistency check: Repeat the following steps q = O(λ) times:
[0061] 5.1) β← $ L0.
[0062] 5.2) Open using MT.Open
[0063] 5.3) The validity of the Merkle tree commitment is checked using MT.Verify; for i∈[μ+1],
[0064] 6) Validity check: and Calling the bulk fast RS code proximity interactive oracle proof to prove in Depend on and The fast RS code proximity cross-evangelion proof. Batch fast RS code proximity cross-evangelion proof requires q′=O(λ) queries in L0, which may overlap with the consistency check.
[0065] 7) If all consistency and validity checks pass, Output 1.
[0066] The efficiency comparison between the PCS proposed in this application and existing coding-based multilinear PCS is as follows: Figure 2 and Figure 3 As shown in the figure, the commitment time is in milliseconds, the proof size is in kilobytes, "-parallel" indicates that multi-threaded parallel execution is used, and "-61" indicates that the finite field of the polynomial is 61. Where p is 2 61 -1, "-255" indicates that the finite field containing the polynomial is Where p is a 255-bit prime number.
[0067] In addition, the above-mentioned coding-based multinomial commitment method also performs the following steps when used to achieve blockchain scaling:
[0068] S4. In zk-Rollup, the blockchain state is updated by aggregators calculating a large number of transaction results off-chain on the blockchain.
[0069] S5. Then, use the constructed SNARK to generate a short proof of the correctness of the updated state and submit the generated proof to the smart contract on the blockchain.
[0070] S6. By verifying this proof in a smart contract, on-chain users can efficiently confirm the validity of a large number of transactions, achieving efficient scaling of the blockchain.
[0071] Optionally, the specific method for constructing a SNARK is as follows: by instantiating the polynomial oracle machine in SpartanPIOP using the PCS proposed in this application, and applying the Fiat-Shamir transformation to the obtained protocol, a highly efficient SNARK can be constructed.
[0072] First, we will introduce the symbols and preliminary knowledge. Let... The witness It is the validator. Let X be an instance of R1CS, and W be the witness, where Master (X,W), Only X is known. For any mapping f, use This indicates its multilinear extension. For a vector... use To represent the first element of a vector, use express The vector consisting of the remaining elements after removing the first element. For an R1CS instance Where A, B, and C are coefficient matrices, m represents the dimension of the R1CS coefficient matrix, and n represents the number of non-zero elements in the matrix. Let s = logm, and consider matrices A, B, and C as a matrix with a domain of {0, 1}. s ×{0,1} s The range is The mapping is as follows. Its input is the binary representation of the matrix element indices (i,j)∈{1,...,m}×{1,...,m}, and the corresponding output is the (i,j)th element of the matrix. For an R1CS instance, And a witness W, defined as Z = (W, 1, io). View Z as a mapping: Consider (1, io) as a mapping: Based on the arguments in Spartan, examine... This is equivalent to checking whether the following equation holds true:
[0073]
[0074] in It is a random vector. It is a multilinear extension of eq. Defined as:
[0075]
[0076] The steps for instantiating the polynomial oracle machine in Spartan PIOP are as follows:
[0077] 1) Run pp←Gen(1) λ ,s), the parameters pp of the generating polynomial commitment method.
[0078] 2) The elements in W are considered as a multilinear polynomial with s variables. The coefficient, the prover generates the pair promise And send C to the verifier.
[0079] 3) The verifier generates a random vector And send to
[0080] 4) and Running the sum-check protocol reduces the verification of equation ① to verifying whether the following conditions are true: in It is the validator in the sum-check protocol process from A vector randomly selected from [the data]. Specifically, examine The method is to target each Perform a calculation; check The method is through verification in The value is Towards Send, and by calling Let's verify.
[0081] Then, the interactive protocol is converted into a SNARK using the Fiat-Shamir transformation: As can be seen from the above process, only random vectors are sent during the interaction, so the Fiat-Shamir transformation can be used to convert the interactive protocol into a non-interactive protocol, thus obtaining the final constructed SNARK.
[0082] Obviously, those skilled in the art should understand that the modules or steps of the embodiments of this application described above can be implemented using general-purpose computer devices. They can be centralized on a single computer device or distributed across a network of multiple computer devices. Optionally, they can be implemented using computer-executable program code, thereby storing them in a storage device for execution by a computer device. In some cases, the steps shown or described can be performed in a different order than those presented here, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the embodiments of this application are not limited to any particular combination of hardware and software.
[0083] It should be noted that the above are merely preferred embodiments of this application and do not limit the scope of patent protection of this application. Any equivalent structural or procedural changes made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of this application.
Claims
1. A method for blockchain expansion based on a polynomial commitment algorithm, characterized in that, include: S1. Using a parameter generation algorithm, a set of common parameters are output with safety parameters and the number of polynomial variables as input. S2. The prover performs a polynomial commitment algorithm to commit to the target polynomial. The input is the coefficients and common parameters of the target polynomial, and the output is the commitment value. S3. The polynomial commitment opening algorithm is used to convince the verifier that the target polynomial is correctly assigned at a certain set of points. The polynomial commitment opening algorithm is an interactive proof protocol involving the prover and the verifier. The coefficients of the target polynomial are used as the prover's input, and the common parameters, commitment values, polynomial assignment points and the assignment results of the target polynomial are used as the common input of the prover and the verifier. The verifier outputs acceptance or rejection. The following steps are also performed when scaling up a blockchain: S4. In zk-Rollup, the blockchain state is updated by aggregators calculating a large number of transaction results off-chain on the blockchain. S5. Instantiate the polynomial prophecy machine in the polynomial interactive prophecy proof using the polynomial commitment algorithm to construct ZK-SNARKS, use the ZK-SNARKS to generate a short proof of the correctness of the updated state, and submit the generated proof to the smart contract on the blockchain. S6. By verifying the proofs generated above in smart contracts, on-chain users can confirm the validity of a large number of transactions, thereby achieving blockchain scaling. The specific steps in S2 where the prover performs the multinomial commitment algorithm to commit to the target polynomial are as follows: First, the coefficients of the objective polynomial are arranged into multiple vectors of equal length, and each vector is expanded using random values; Then, each expanded vector is treated as a new single-variable polynomial, and each polynomial is encoded as a Reed-Solomon code, thus obtaining a matrix in which each column is a Reed-Solomon codeword; Finally, the matrix is committed column by column using a Merkle tree, and the root node of the Merkle tree is output as the commitment value. The interactive argumentation process of S3 is as follows: First, the prover and the verifier jointly invoke the batch fast Reed-Solomon code proximity interactive oracle proof to test whether each column in the matrix corresponding to the commitment value is a Reed-Solomon codeword; Subsequently, the prover and the verifier engage in multiple rounds of interaction. In each round, the prover decomposes the polynomial into a polynomial of lower dimension, then performs consistency tests on the polynomial before and after decomposition and the polynomial assignment results, and makes a commitment to the decomposition results through a Merkle tree. Finally, the decomposition results in each round are verified by batch fast Reed-Solomon code proximity cross-evangelization to ensure that the decomposition results are correct Reed-Solomon code words.
2. A computer storage medium, characterized in that, The computer-readable storage medium stores computer instructions, which, when executed by a processor, implement a blockchain scaling method based on a multinomial commitment algorithm as claimed in claim 1.
3. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements a blockchain scaling method based on a polynomial commitment algorithm as claimed in claim 1.