Zero knowledge proof circuit solving method and computing device

By splitting the constraint group of a large zero-knowledge proof circuit into multiple sub-constraint groups and gradually solving it, the problem that the existing technology is difficult to review the correctness of large circuits is solved, and the correctness review of more circuits is achieved, and safety risks are reduced.

CN119945683APending Publication Date: 2025-05-06ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411969155.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing constraint solvers are difficult to directly solve the circuit constraint group of large zero-knowledge proof circuits, which leads to the inability to effectively review the correctness of the circuit and poses safety risks.

Method used

By splitting the large circuit constraint group into multiple smaller subconstraint groups, and using the constraint solver to solve each subconstraint group in sequence, the solution obtained from the previous solution is used as the circuit constraints of the subsequent subconstraint group, and the entire circuit constraint group is gradually solved.

Benefits of technology

This method expands the range of solveable circuit constraint groups, can review the accuracy of more zero-knowledge proof circuits, and reduces safety risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945683A_ABST
    Figure CN119945683A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a zero-knowledge proof circuit solving method and computing equipment, a zero-knowledge proof circuit comprises a first circuit constraint group, and variables in the circuit constraints correspond to parameters in a target model; the value of the specific variable in the first circuit constraint group is determined by the input data; the method comprises the following steps: firstly, splitting a first circuit constraint group into a plurality of sub-constraint groups which are arranged in sequence; in the multiple sub-constraint groups, the ith sub-constraint group comprises a first variable and a second variable, and the first i-1 sub-constraint groups comprise the first variable and do not comprise the second variable; then, sequentially solving each sub-constraint group according to the arrangement sequence of the plurality of sub-constraint groups by using a constraint solver so as to obtain a solution of the first circuit constraint group; wherein when the ith sub-constraint group is solved, the solution of the first (i-1) th sub-constraint group is taken as a circuit constraint and is added into the ith sub-constraint group; the solution of the first i-1 sub-constraint groups comprises the value of the first variable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this specification belong to the field of privacy computing technology, and in particular, to a zero-knowledge proof circuit solving method and computing device. Background Art

[0002] Zero-Knowledge Proof (ZKP) is a key cryptographic technology that has been widely used in blockchain, digital identity authentication, privacy computing and other fields. Its core feature is that it allows the prover to prove the correctness of a proposition to the verifier without revealing any additional information. This feature makes it an important pillar for building a trustworthy and privacy-preserving system.

[0003] For example, in the application scenario of machine learning, there are two parties involved: the data holder and the model holder. The data holder sends the data to be predicted to the model holder, who uses its private model to make predictions and returns the results to the data holder. However, since the model is usually the private asset of the model holder, the data holder cannot directly understand the specific details of the prediction process and therefore cannot confirm whether the prediction result is generated by the model.

[0004] At this point, the model holder can act as a prover and use zero-knowledge proof technology to prove to the data holder the correctness of the prediction process, including the use of the correct model to make the correct prediction, without disclosing the details of the model and the prediction process. The data holder, as a verifier, can verify the proof provided by the model holder to know the correctness of the prediction process.

[0005] The security of the zero-knowledge proof system depends largely on the correctness of its underlying zero-knowledge proof circuit (hereinafter referred to as the "circuit"). When the prover converts the proposition to be proved into a zero-knowledge proof circuit, the circuit may have vulnerabilities. As the core architecture of the system, once the circuit has vulnerabilities or defects, it will bring serious security risks. Malicious attackers may use these vulnerabilities to construct false proofs, thereby bypassing the verification system, and then interfering with or manipulating the system, causing serious consequences such as financial losses and data tampering. Therefore, before using the circuit to generate a zero-knowledge proof, it is necessary to first review the correctness of the circuit to see if there are circuit defects.

[0006] For circuits with circuit constraints, such as R1CS circuits (Rank-1 Constraint Systems), PLONK circuits, Halo2 circuits, etc., these circuits have a set of circuit constraints, each of which contains circuit variables. The prover will generate a zero-knowledge proof based on this set of circuit constraints. Circuit constraints can include equations and inequalities of circuit variables. By solving this set of circuit constraints and counting the number of feasible solutions, it can be determined whether this set of circuit constraints is correctly constrained as part of the correctness review of this type of circuit. When the number of feasible solutions is 0, the circuit is over constrained (Over Constrained); when the number of feasible solutions is one and only one set, the circuit is correctly constrained; when the number of feasible solutions is greater than one set, the circuit is under constrained (Under Constrained). Neither over-constraints nor under-constraints are correct constraints, and there are circuit defects.

[0007] The solution of the circuit constraint group can be completed using a constraint solver. However, for the circuit constraint group of some large circuits, the current constraint solver is often unable to directly solve because there are too many constraints and variables in the circuit. Therefore, a method is needed to solve the circuit constraint group of a large circuit to achieve the correctness review of the large circuit. Summary of the invention

[0008] The purpose of this specification is to provide a zero-knowledge proof circuit solving method and computing device, which is intended to solve a circuit constraint group to review the correctness of the zero-knowledge proof circuit.

[0009] In a first aspect, the present specification provides a method for solving a zero-knowledge proof circuit, wherein the zero-knowledge proof circuit includes a first circuit constraint group, wherein variables in the circuit constraint correspond to parameters in a target model; the target model is used to make predictions based on input data; and values ​​of specific variables in the first circuit constraint group are determined by the input data; the method includes:

[0010] Splitting the first circuit constraint group into a plurality of sub-constraint groups arranged in sequence; among the plurality of sub-constraint groups, the i-th sub-constraint group includes a first variable and a second variable, wherein the first i-1 sub-constraint groups include the first variable and do not include the second variable;

[0011] A constraint solver is used to solve each sub-constraint group in sequence according to the arrangement order of the multiple sub-constraint groups to obtain a solution to the first circuit constraint group; wherein, when solving the i-th sub-constraint group, the solutions of the first i-1 sub-constraint groups are added to the i-th sub-constraint group as circuit constraints; and the solutions of the first i-1 sub-constraint groups include the values ​​of the first variable.

[0012] In some possible implementations, the target model is a tree model, and each circuit constraint in the first circuit constraint group corresponds to a split node in the tree model.

[0013] In some possible implementations, the input data is text data.

[0014] In some possible implementations, the zero-knowledge proof circuit includes a plurality of circuit constraints; and the method further includes:

[0015] The multiple circuit constraints are divided into a plurality of circuit constraint groups, including the first circuit constraint group; each variable in any circuit constraint group does not belong to any other circuit constraint group.

[0016] In some possible implementations, the plurality of circuit constraints are divided into a plurality of circuit constraint groups, including:

[0017] For each variable in the plurality of circuit constraints, generating a corresponding graph node;

[0018] Traverse each circuit constraint, connect the graph nodes corresponding to each variable belonging to the same circuit constraint, and obtain several subgraphs;

[0019] According to the variables corresponding to the graph nodes in each subgraph, the corresponding circuit constraint groups are generated.

[0020] In some possible implementations, generating corresponding circuit constraint groups according to variables corresponding to graph nodes in each subgraph includes:

[0021] For any subgraph, a number of circuit constraints including variables corresponding to each graph node in the subgraph are determined, and the number of circuit constraints are added to a circuit constraint group corresponding to the subgraph.

[0022] In some possible implementations, solving the i-th sub-constraint group includes:

[0023] Determine whether the number of solutions reaches a preset second threshold; if not, add the solutions of the first i-1 sub-constraint groups as the second circuit constraint to the i-th sub-constraint group, and use the constraint solver to solve the i-th sub-constraint group; if there is a solution, increase the number of solutions by 1, and start solving the i+1-th sub-constraint group.

[0024] In some possible implementations, solving the i-th sub-constraint group further includes:

[0025] If the number of solutions reaches a second threshold, and i=1, then the first circuit constraint group has no solution;

[0026] If the number of solutions reaches the second threshold and i>1, the number of solutions is cleared, the solution of the i-1th sub-constraint group is set as infeasible, and the solution of the i-1th sub-constraint group is started.

[0027] In some possible implementations, setting the solution of the i-1th sub-constraint group as infeasible includes:

[0028] A third circuit constraint is added to the i-1th sub-constraint group, where the third circuit constraint is used to make each variable in the i-1th sub-constraint group not equal to a value in a solution of the i-1th sub-constraint group.

[0029] A second aspect of the present specification provides a method for solving a zero-knowledge proof circuit, wherein the zero-knowledge proof circuit includes a first circuit constraint group; the method includes:

[0030] Splitting the first circuit constraint group into a plurality of sub-constraint groups arranged in sequence; among the plurality of sub-constraint groups, the i-th sub-constraint group includes a first variable and a second variable, wherein the first i-1 sub-constraint groups include the first variable and do not include the second variable;

[0031] A constraint solver is used to solve each sub-constraint group in sequence according to the arrangement order of the multiple sub-constraint groups to obtain a solution to the first circuit constraint group; wherein, when solving the i-th sub-constraint group, the solutions of the first i-1 sub-constraint groups are added to the i-th sub-constraint group as circuit constraints; and the solutions of the first i-1 sub-constraint groups include the values ​​of the first variable.

[0032] In some possible implementations, the zero-knowledge proof circuit includes a plurality of circuit constraints; and the method further includes:

[0033] The multiple circuit constraints are divided into a plurality of circuit constraint groups, including the first circuit constraint group; each variable in any circuit constraint group does not belong to any other circuit constraint group.

[0034] In some possible implementations, the following further includes:

[0035] Summarize the solutions of each circuit constraint group to obtain the solution of the zero-knowledge proof circuit; wherein, when each circuit constraint group has a solution, the set of solutions of each circuit constraint group is used as the solution of the zero-knowledge proof circuit; when any circuit constraint group has no solution, the zero-knowledge proof circuit has no solution.

[0036] In some possible implementations, solving the i-th sub-constraint group includes:

[0037] Determine whether the number of solutions reaches a preset second threshold; if not, add the solutions of the first i-1 sub-constraint groups as the second circuit constraint to the i-th sub-constraint group, and use the constraint solver to solve the i-th sub-constraint group; if there is a solution, increase the number of solutions by 1, and start solving the i+1-th sub-constraint group.

[0038] In some possible implementations, solving the i-th sub-constraint group further includes:

[0039] If the i-th sub-constraint group has no solution, the number of solutions is set to the second threshold, and the i-th sub-constraint group is started to be solved.

[0040] In some possible implementations, solving the i-th sub-constraint group further includes:

[0041] If the number of solutions reaches a second threshold, and i=1, then the first circuit constraint group has no solution;

[0042] If the number of solutions reaches the second threshold and i>1, the number of solutions is cleared, the solution of the i-1th sub-constraint group is set as infeasible, and the solution of the i-1th sub-constraint group is started.

[0043] In some possible implementations, setting the solution of the i-1th sub-constraint group as infeasible includes:

[0044] A third circuit constraint is added to the i-1th sub-constraint group, where the third circuit constraint is used to make each variable in the i-1th sub-constraint group not equal to a value in a solution of the i-1th sub-constraint group.

[0045] In some possible implementations, the second circuit constraint is used to make each variable in the first i-1 sub-constraint groups equal to a value in a solution of the first i-1 sub-constraint groups.

[0046] A third aspect of the specification provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed in a computer, the computer is caused to execute the method described in the first aspect or the second aspect.

[0047] A fourth aspect of the specification provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method described in the first aspect or the second aspect is implemented.

[0048] A fifth aspect of the present specification provides a computer program product, comprising a computer program / instruction, which, when executed by a processor, implements the steps of the method described in the first aspect or the second aspect.

[0049] The zero-knowledge proof circuit solving method and computing device proposed in the embodiments of this specification, the method splits the circuit constraint group into multiple sub-constraint groups, and uses the constraint solver to solve each sub-constraint group in sequence according to a predetermined order, and substitutes the solution of the previously solved sub-constraint group as the circuit constraint into the solving process of the subsequent sub-constraint group. The embodiments of this specification expand the scope of the circuit constraint groups that can be solved by splitting a larger circuit constraint group into multiple smaller sub-constraint groups and solving them in sequence, so that the correctness of more zero-knowledge proof circuits can be reviewed. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the technical solutions of the embodiments of this specification, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0051] Figure 1 It is a flowchart of a method for solving a zero-knowledge proof circuit in an embodiment of this specification;

[0052] Figure 2 is a flow chart of a method for solving a zero-knowledge proof circuit in an embodiment of this specification;

[0053] Figure 3 is a flowchart of a method for solving a zero-knowledge proof circuit in an example of this specification;

[0054] Figure 4 is a flow chart for solving the i-th sub-constraint group in an embodiment of this specification;

[0055] Figure 5 is a schematic diagram of generating a subgraph in an example of this specification;

[0056] Figure 6 It is a schematic block diagram of a zero-knowledge proof circuit solving device in one embodiment of this specification. DETAILED DESCRIPTION

[0057] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this specification.

[0058] Figure 11 is a flow chart of a method for solving a zero-knowledge proof circuit in an embodiment of this specification. Figure 1 In the example, the circuit constraint group M to be solved contains several constraints, each of which includes one or more circuit constraint variables. First, the circuit constraint group M is split into n mutually exclusive sub-constraint groups, namely sub-constraint groups M1, M2, ..., M n , the union of each sub-constraint group is the circuit constraint group M. Then, starting from sub-constraint group M1, use the constraint solver to solve each sub-constraint group M in turn. i , and obtain the solution V of each sub-constraint group i Among them, when solving the i-th sub-constraint group M i When , the solutions of the first i-1 sub-constraint groups are added as circuit constraints to the i-th sub-constraint group M i Then, for the sub-constraint group M i Solve to obtain the i-th sub-constraint group M i Solution V i Then, the sub-constraint groups M are aggregated and merged. i Solution V i , and obtain the solution V of the circuit constraint group M.

[0059] The solutions of the first i-1 sub-constraint groups are added as circuit constraints to the i-th sub-constraint group M. i Specifically, it includes: taking the solutions of the first i-1 sub-constraint groups as circuit constraints, and putting the variables in each solution in the i-th sub-constraint group M i Set it as a constant in and then add it to the i-th child constraint group M i middle.

[0060] For example, the circuit constraint group M has three sub-constraint groups, namely M1, M2 and M3. M1 contains variables a1 and a2, M2 contains variables a2 and a3, and M3 contains variables a2, a3 and a4. First, use the constraint solver to solve M1 and obtain the corresponding solution V1, for example, a1=0, a2=1. Then, add the solution a1=0, a2=1 in V1 as constraints to M2, and set a1 and a2 as constants in M2 (at this time, only a3 is a variable in M2), and then use the constraint solver to solve M2 and obtain the corresponding solution V2, for example, a3=3. Next, add the solutions a1=0, a2=1, a3=3 in V1 and V2 as constraints to M3, and set a1, a2 and a3 as constants in M2 (at this time, only a4 is a variable in M3), and then use the constraint solver to solve M3 and obtain the corresponding solution V3, for example, a4=0. Finally, V1, V2 and V3 are summed up to obtain the solution V of the circuit constraint group M, that is, a1=0, a2=1, a3=3, a4=0.

[0061] It should be noted that when solving a certain sub-constraint group, there may be a situation where there is no solution. The specific method for handling the situation where there is no solution for the sub-constraint group will be described in detail in subsequent embodiments.

[0062] The specific implementation steps of the above zero-knowledge proof circuit solving method are described below in conjunction with specific embodiments.

[0063] Figure 2 1 is a flowchart of a method for solving a zero-knowledge proof circuit in an embodiment of this specification. The execution subject of the method can be any platform or server or device cluster with computing and processing capabilities. Figure 2 As shown, the zero-knowledge proof circuit includes a first circuit constraint group, and the variables in the circuit constraint correspond to the parameters in the target model; the target model is used to make predictions based on input data; the values ​​of specific variables in the first circuit constraint group are determined by the input data; the method includes: step 204, splitting the first circuit constraint group into a plurality of sub-constraint groups arranged in sequence; in the plurality of sub-constraint groups, the i-th sub-constraint group includes a first variable and a second variable, wherein the first i-1 sub-constraint groups include the first variable and do not include the second variable; step 206, using a constraint solver to solve each sub-constraint group in sequence according to the arrangement order of the plurality of sub-constraint groups to obtain a solution to the first circuit constraint group; wherein, when solving the i-th sub-constraint group, the solutions of the first i-1 sub-constraint groups are added to the i-th sub-constraint group as circuit constraints; the solutions of the first i-1 sub-constraint groups include the values ​​of the first variable.

[0064] The target model may be a prediction model, which performs prediction based on input data to obtain a prediction result. The circuit constraint group in the zero-knowledge proof circuit is used to generate a zero-knowledge proof that proves the correctness of the above prediction process.

[0065] The first circuit constraint group may be obtained by conversion according to the prediction process of the target model, wherein the variables in each circuit constraint correspond to the parameters in the target model. The specific variables in the first circuit constraint group may include relevant variables in the input circuit, which correspond to the input parameters of the target model, and the specific values ​​are determined by the input data.

[0066] In one embodiment, the target model is a tree model, the input data of the tree model may correspond to the input circuit of the zero-knowledge proof circuit, and the prediction result may correspond to the output circuit of the zero-knowledge proof circuit. Each circuit constraint in the first circuit constraint group corresponds to a split node (decision node) and a leaf node in the tree model.

[0067] Specifically, some constraints in the first circuit constraint group may be gate constraints, which are used to constrain the structure of the tree, including the hash value of the leaf node; another part of the constraints are table lookup constraints, which correspond to the threshold value on the split node.

[0068] The tree model can be a model for making predictions in a variety of scenarios. For example, in one embodiment, the tree model can be used in an anti-fraud scenario to predict whether a user and / or transaction is a risky user and / or a risky transaction. In this case, the input data can include at least one of user features and transaction information, and the prediction result can be the prediction result of the tree model on whether the input user / transaction is risky.

[0069] In another embodiment, the input data is text data, for example, information related to a user and / or a transaction in an anti-fraud scenario.

[0070] The specific execution process of each of the above steps is described below.

[0071] First, in step 204, the first circuit constraint group is split into a plurality of sub-constraint groups arranged in sequence; among the plurality of sub-constraint groups, the i-th sub-constraint group includes a first variable and a second variable, wherein the first i-1 sub-constraint groups include the first variable but do not include the second variable.

[0072] The first circuit constraint group can be denoted as M, and the total number of the plurality of sub-constraint groups can be n groups, and the splitting can be performed in any manner. Each sub-constraint group is mutually exclusive, and the union of all sub-constraint groups is the first circuit constraint group. That is, any circuit constraint in the first circuit constraint group is assigned to only one sub-constraint group. The plurality of sub-constraint groups can be denoted as M1, M2, ..., M n .

[0073] In one embodiment, the first circuit constraint group can be evenly divided into n groups, and the circuit constraints in the first circuit constraint group are arranged in order, and each circuit constraint is allocated to each sub-constraint group. Alternatively, in another embodiment, each circuit constraint in the first circuit constraint group can be randomly allocated to the n groups. This is not limited here.

[0074] The sequence arrangement in step 204 can be arranged in any order. Once the order is determined, it only needs to be kept unchanged in subsequent steps.

[0075] For example, for a first circuit constraint group with 10,000 circuit constraints, it can be divided into 10 sub-constraint groups, each of which has 1,000 circuit constraints. The first sub-constraint group contains the 1st to 1000th circuit constraints in the first circuit constraint group, the second sub-constraint group contains the 1001st to 2000th circuit constraints in the first circuit constraint group, and so on.

[0076] In one embodiment, the number of constraints in any one of the plurality of sub-constraint groups is less than or equal to a preset first threshold. The first threshold may be related to the maximum number of constraints that the constraint solver can solve. For example, the first threshold is the maximum number of constraints that the constraint solver can solve, or 0.8 times the maximum number of constraints that the constraint solver can solve, and so on.

[0077] After the first threshold is determined, the number of the plurality of sub-constraint groups is the total number of circuit constraints in the first circuit constraint group divided by the first threshold and rounded up.

[0078] Then, in step 206, a constraint solver is used to solve each sub-constraint group in sequence according to the arrangement order of the multiple sub-constraint groups to obtain a solution to the first circuit constraint group; wherein, when solving the i-th sub-constraint group, the solutions of the first i-1 sub-constraint groups are added to the i-th sub-constraint group as circuit constraints; and the solutions of the first i-1 sub-constraint groups include the value of the first variable.

[0079] Use the constraint solver to solve the sub-constraint groups M1, M2, ..., M in sequence. n , to obtain a solution to the first circuit constraint group M. Any constraint solver may be used for solving, such as a cvc5 constraint solver, a z3 constraint solver, etc., which is not limited here.

[0080] In one embodiment, the solutions of the first i-1 sub-constraint groups are added as circuit constraints to the i-th sub-constraint group, specifically including:

[0081] The solutions of the first i-1 sub-constraint groups are added as circuit constraints to the i-th sub-constraint group, and the variables in the first i-1 sub-constraint groups are declared as constants in the i-th sub-constraint group.

[0082] Since it is described in step 204 that the i-th sub-constraint group includes the first variable and the second variable, wherein the first i-1 sub-constraint groups include the first variable but do not include the second variable, therefore, in this embodiment, the i-th sub-constraint group includes the value of the first variable as a constraint, and the first variable is declared as a constant in the i-th sub-constraint group; in addition, the second variable is still declared as a variable in the i-th constraint group.

[0083] By solving each sub-constraint group M in turn i , and summarize the solutions V of each sub-constraint group i , we can get the solution V of the first circuit constraint group M. i Solution V i Including, the i-th sub-constraint group M i The values ​​of the variables that are still declared as variables.

[0084] In some possible implementations, since the first circuit constraint group M is split into multiple smaller sub-constraint groups and solved separately, the solutions of each sub-constraint group may not be unique due to the decrease in the number of constraints, and the number of feasible solutions may even be infinite. Among these feasible solutions, only a small number of solutions may be the real solutions of the first circuit constraint group. When using a constraint solver to solve a sub-constraint group, the constraint solver usually only outputs the first group of solutions that it finds that satisfy the sub-constraint group. This group of solutions may not be the solution of the first circuit constraint group. Specifically, when the solution of the sub-constraint group is added as a constraint to a subsequent sub-constraint group and solved, a subsequent sub-constraint group may have no solution, which makes it impossible to continue solving.

[0085] To address this problem, the embodiments of this specification use a method similar to depth-first search. After solving each sub-constraint group to obtain a set of solutions, the set of solutions is added as constraints to the subsequent sub-constraint group, and then the next sub-constraint group is solved. Until a sub-constraint group has no solution, it means that the solution of the previous sub-constraint group is not the correct solution to the first circuit constraint group. At this time, fall back to the previous sub-constraint group and set the solution of the sub-constraint group to be infeasible. The specific method is that in the sub-constraint group, each variable in the solution of the group is not equal to the value in the solution of the group, and the relationship between each unequal formula is "or". Then solve the sub-constraint group again. If a set of solutions can be found, continue to solve the next sub-constraint group; if there is no solution, continue to back up. And so on.

[0086] The following first uses a simple example to describe the above process, and then describes the specific implementation method of the depth-first search used to solve each sub-constraint group in step 206.

[0087] In an example, the first circuit constraint group M includes four circuit constraints, which are respectively as follows:

[0088] a0(a1-1)=0

[0089] a1(a1-1)=0

[0090] a2(a2-1)=0

[0091] a0+2a1+4a2-7=0

[0092] Among them, a0, a1, and a2 are variables. It is split into two sub-constraint groups. The first sub-constraint group M1 contains the first two circuit constraints, and the second sub-constraint group M2 contains the last two circuit constraints. The process of solving the sub-constraint groups in sequence can be as follows: Figure 3 shown. Figure 3 It is a flowchart of a method for solving a zero-knowledge proof circuit in an example of this specification.

[0093] First, use the constraint solver to solve the sub-constraint group M1 and get a set of solutions a0=0, a1=0, which are added as constraints to the sub-constraint group M2, and a0 and a1 are declared as constants in the sub-constraint group M2. At this time, only a2 is a variable in the sub-constraint group M2. Then solve the sub-constraint group M2 with constraints added. If no solution is found, return to the sub-constraint group M1 and add the constraint a0≠0or a1≠0 to it.

[0094] Then, the sub-constraint group M1 is solved again to obtain another set of solutions a0=0, a1=1, which are added as constraints to the sub-constraint group M2, and a0 and a1 are declared as constants in the sub-constraint group M2. Then, the sub-constraint group M2 with the added constraints is solved. If there is still no solution, return to the sub-constraint group M1 again and add the constraints a0≠0or a1≠1 therein.

[0095] Then, sub-constraint group M1 is solved again to obtain another set of solutions a0 = 1, a1 = 1, which are added as constraints to sub-constraint group M2, and a0 and a1 are declared as constants in sub-constraint group M2. Then, sub-constraint group M2 with added constraints is solved to obtain a set of solutions a2 = 1. The solutions of sub-constraint group M1 and sub-constraint group M2 are summarized to obtain the solutions of the first circuit constraint group M a0 = 1, a1 = 1, a2 = 1.

[0096] The above describes a specific example of solving each sub-constraint group based on the depth-first search. The following continues to describe the specific steps of the depth-first search in step 206.

[0097] In one embodiment, solving the i-th sub-constraint group in step 206 includes:

[0098] Determine whether the number of solutions reaches a preset second threshold; if not, add the solutions of the first i-1 sub-constraint groups as the second circuit constraint to the i-th sub-constraint group, and use the constraint solver to solve the i-th sub-constraint group; if there is a solution, increase the number of solutions by 1, and start solving the i+1-th sub-constraint group.

[0099] The i-th sub-constraint group M i The number of solutions can be c i, the second threshold can be max_iter. Since there may be multiple or even infinite feasible solutions to a sub-constraint group (for example, when a sub-constraint group is an indeterminate equation group), in order to avoid the solution process taking too long or failing to end, the second threshold is set to control the total number of solution attempts to avoid consuming too many computing resources.

[0100] When the i-th sub-constraint group M i The number of solutions c i The second threshold, c, is not reached i When < max_iter, it means that you can continue to solve M i At this time, firstly, the solutions V1 to V2 of the first i-1 sub-constraint groups are i-1 As the second circuit constraint, add it to the i-th sub-constraint group M i In the example, the second circuit constraint is used to make each variable in the first i-1 sub-constraint groups equal to the value in the solution of the first i-1 sub-constraint groups. Then, the constraint solver is used to solve the i-th sub-constraint group M. i If there is a solution, then c i Add 1 and start solving the subsequent i+1th sub-constraint group M i+1 It can be understood that solving the i+1th sub-constraint group M i+1 The process of step 206 will also follow the process of step 206, except that i is replaced by i+1.

[0101] If the i-th sub-constraint group M i If there is no solution, then solve it c times i Set as the second threshold max_iter, that is, let c i = max_iter, and start solving the i-th sub-constraint group M i That is, return to the aforementioned step of "determining whether the number of solutions reaches the preset second threshold value" and continue.

[0102] At this time, determine the number of solutions c again i Whether the preset second threshold value max_iter is reached, if it is found that the second threshold value max_iter is reached, it is further determined whether i is equal to 1, if i=1, it means that it is impossible to go back, and the first circuit constraint group M has no solution as a whole.

[0103] If the number of solutions c i When the second threshold max_iter is reached and i>1, the number of solutions is cleared, that is, c i = 0, and set the solution of the i-1th sub-constraint group as infeasible, and start solving the i-1th sub-constraint group M i-1 It can be understood that solving the i-1th sub-constraint group M i-1The process of step 206 will also follow the process of step 206, except that i is replaced by i-1.

[0104] Specifically, setting the solution of the i-1th sub-constraint group as infeasible includes: i-1 The third circuit constraint is added to the i-1 The variables in are not equal to the solution V of the i-1th sub-constraint group i-1 The value in .

[0105] Through the above steps, each sub-constraint group is solved in turn based on the depth-first search method, and the solutions of the previous sub-constraint groups are added as constraints to the subsequent sub-constraint groups for solution. When a sub-constraint group has no solution, it can fall back to solve the solutions of each sub-constraint group, or determine that the overall first circuit constraint group M has no solution. When the last group of sub-constraint groups M n If there is a solution, it means that the first circuit constraint group M has a solution. i Solution V i Summarize to obtain a solution V of the first circuit constraint group M. When the overall scale of the first circuit constraint group M exceeds the maximum scale that the constraint solver can support for solving, the method in the embodiment of this specification can also be used for solving.

[0106] The above steps can also be Figure 4 As shown, Figure 4 is a flowchart for solving the i-th sub-constraint group in an embodiment of this specification. It should be noted that: Figure 4 The steps in the middle box are to solve M i So, Figure 4 The solution M below i+1 ,as well as Figure 4 The solution M on the right side i-1 , which can also be expanded to Figure 4 The steps in the middle box are similar, except Figure 4 Not shown.

[0107] In some possible implementations, the zero-knowledge proof circuit includes a plurality of circuit constraints; and the method further includes:

[0108] Step 202: divide the plurality of circuit constraints into a plurality of circuit constraint groups, including the first circuit constraint group; each variable in any circuit constraint group does not belong to any other circuit constraint group.

[0109] When there are some circuit constraints that are unrelated to each other among the multiple circuit constraints included in the original zero-knowledge proof circuit, these circuit constraints can be divided into different circuit constraint groups first, so that each variable in any circuit constraint group does not belong to other circuit constraint groups, and then each circuit constraint group is solved separately using the method such as steps 204 to 206.

[0110] For example, multiple circuit constraints can look like this:

[0111] b0-b1=0

[0112] b1-1=0

[0113] b2×b3=0

[0114] b2+b4=0

[0115] It can be found that if it is divided into two circuit constraint groups, the first circuit constraint group includes the first two circuit constraints, and the second circuit constraint group includes the last two circuit constraints. In this way, the variables b0 and b1 in the first circuit constraint group do not belong to the second circuit constraint group, and the variables b2, b3 and b4 in the second circuit constraint group do not belong to the first circuit constraint group. Therefore, the values ​​of the variables in the two circuit constraint groups do not affect each other in the solution, and the two circuit constraint groups can be solved separately.

[0116] The constraint relationship between each variable in each circuit constraint can be recorded in the form of a graph. For any circuit constraint, the variables contained therein are constrained to each other, and there are connections between the corresponding nodes in the graph. Therefore, traverse each circuit constraint and connect the graph nodes corresponding to each variable belonging to the same circuit constraint. After the traversal is completed, check the connection results. The variables belonging to the same subgraph belong to the same circuit constraint group. Add all circuit constraints containing these variables to the same circuit constraint group, and multiple circuit constraints can be divided into several circuit constraint groups.

[0117] In one embodiment, step 202 specifically includes:

[0118] Step 2022: Generate a corresponding graph node for each variable in the plurality of circuit constraints.

[0119] Step 2024, traverse each circuit constraint, connect the graph nodes corresponding to each variable belonging to the same circuit constraint, and obtain a plurality of subgraphs.

[0120] Step 2026: Generate corresponding circuit constraint groups according to the variables corresponding to the graph nodes in each subgraph.

[0121] In a specific embodiment, step 2026 includes:

[0122] For any subgraph, a number of circuit constraints including variables corresponding to each graph node in the subgraph are determined, and the number of circuit constraints are added to a circuit constraint group corresponding to the subgraph.

[0123] According to the specific steps of step 202, each subgraph drawn according to the circuit constraint group in the above example can be as follows: Figure 5 shown. Figure 5 is a schematic diagram of generating a subgraph in an example of this specification. Figure 5 It can be seen that variables b0 and b1 belong to the same circuit constraint group, and the first two circuit constraints containing variables b0 and b1 are added to the first circuit constraint group. At the same time, variables b2, b3, and b4 belong to the same circuit constraint group, and the last two circuit constraints containing variables b2, b3, and b4 are added to the second circuit constraint group.

[0124] After the plurality of circuit constraints are divided into a plurality of circuit constraint groups in step 202, since the variables between the circuit constraint groups are not constrained to each other, the method of steps 204 to 206 can be used for each circuit constraint group to perform solutions in parallel, so as to improve the overall solution efficiency.

[0125] In some possible implementations, the method further includes:

[0126] Summarize the solutions of each circuit constraint group obtained in step 202 to obtain the solution of the zero-knowledge proof circuit; wherein, when each circuit constraint group has a solution, the set of solutions of each circuit constraint group is used as the solution of the zero-knowledge proof circuit; when any circuit constraint group has no solution, the zero-knowledge proof circuit has no solution.

[0127] According to the embodiments of this specification, the zero-knowledge proof circuit is divided into multiple circuit constraint groups that are not mutually constrained. The solutions of these circuit constraint groups do not interfere with each other, so they can be solved in parallel to improve the solution efficiency and shorten the solution time. At the same time, for a single circuit constraint group that cannot be directly solved by the constraint solver, according to the embodiments of this specification, it is split into multiple sub-constraint groups, and solved in sequence based on the idea of ​​depth-first search, which effectively broadens the scope of solvability.

[0128] Based on the same inventive concept, an embodiment of this specification further provides a method for solving a zero-knowledge proof circuit, wherein the zero-knowledge proof circuit includes a first circuit constraint group; the method includes:

[0129] Splitting the first circuit constraint group into a plurality of sub-constraint groups arranged in sequence; among the plurality of sub-constraint groups, the i-th sub-constraint group includes a first variable and a second variable, wherein the first i-1 sub-constraint groups include the first variable and do not include the second variable;

[0130] A constraint solver is used to solve each sub-constraint group in sequence according to the arrangement order of the multiple sub-constraint groups to obtain a solution to the first circuit constraint group; wherein, when solving the i-th sub-constraint group, the solutions of the first i-1 sub-constraint groups are added to the i-th sub-constraint group as circuit constraints; and the solutions of the first i-1 sub-constraint groups include the values ​​of the first variable.

[0131] In some possible implementations, the zero-knowledge proof circuit includes a plurality of circuit constraints; and the method further includes:

[0132] The multiple circuit constraints are divided into a plurality of circuit constraint groups, including the first circuit constraint group; each variable in any circuit constraint group does not belong to any other circuit constraint group.

[0133] In some possible implementations, the method further includes:

[0134] Summarize the solutions of each circuit constraint group to obtain the solution of the zero-knowledge proof circuit; wherein, when each circuit constraint group has a solution, the set of solutions of each circuit constraint group is used as the solution of the zero-knowledge proof circuit; when any circuit constraint group has no solution, the zero-knowledge proof circuit has no solution.

[0135] In one embodiment, solving the i-th sub-constraint group includes:

[0136] Determine whether the number of solutions reaches a preset second threshold; if not, add the solutions of the first i-1 sub-constraint groups as the second circuit constraint to the i-th sub-constraint group, and use the constraint solver to solve the i-th sub-constraint group; if there is a solution, increase the number of solutions by 1, and start solving the i+1-th sub-constraint group.

[0137] In one embodiment, solving the i-th sub-constraint group further includes:

[0138] If the i-th sub-constraint group has no solution, the number of solutions is set to the second threshold, and the i-th sub-constraint group is started to be solved.

[0139] In one embodiment, solving the i-th sub-constraint group further includes:

[0140] If the number of solutions reaches a second threshold, and i=1, then the first circuit constraint group has no solution;

[0141] If the number of solutions reaches the second threshold and i>1, the number of solutions is cleared, the solution of the i-1th sub-constraint group is set as infeasible, and the solution of the i-1th sub-constraint group is started.

[0142] In one embodiment, setting the solution of the i-1th sub-constraint group as infeasible includes:

[0143] A third circuit constraint is added to the i-1th sub-constraint group, where the third circuit constraint is used to make each variable in the i-1th sub-constraint group not equal to a value in a solution of the i-1th sub-constraint group.

[0144] In one embodiment, the second circuit constraint is used to make each variable in the first i-1 sub-constraint groups equal to a value in a solution of the first i-1 sub-constraint groups.

[0145] According to an embodiment of another aspect, a zero-knowledge proof circuit solving device is also provided. Figure 6 1 is a schematic block diagram of a zero-knowledge proof circuit solving device in an embodiment of this specification. The device can be deployed in any device, platform or device cluster with computing and processing capabilities. Figure 6 As shown, the zero-knowledge proof circuit includes a first circuit constraint group, the variables in the circuit constraint correspond to the parameters in the target model; the target model is used to make predictions based on input data; the values ​​of specific variables in the first circuit constraint group are determined by the input data; the device 600 includes:

[0146] The splitting unit 604 is configured to split the first circuit constraint group into a plurality of sub-constraint groups arranged in sequence; among the plurality of sub-constraint groups, the i-th sub-constraint group includes a first variable and a second variable, wherein the first i-1 sub-constraint groups include the first variable and do not include the second variable;

[0147] The solving unit 606 is configured to use a constraint solver to solve each sub-constraint group in sequence according to the arrangement order of the multiple sub-constraint groups to obtain a solution to the first circuit constraint group; wherein, when solving the i-th sub-constraint group, the solutions of the first i-1 sub-constraint groups are added to the i-th sub-constraint group as circuit constraints; and the solutions of the first i-1 sub-constraint groups include the values ​​of the first variable.

[0148] In some possible implementations, the zero-knowledge proof circuit includes a plurality of circuit constraints; the apparatus 600 further includes:

[0149] The division unit 602 is configured to divide the multiple circuit constraints into a plurality of circuit constraint groups, including the first circuit constraint group; each variable in any circuit constraint group does not belong to any other circuit constraint group.

[0150] In some possible implementations, the device 600 further includes:

[0151] The summarizing unit 608 is configured to summarize the solutions of each circuit constraint group to obtain the solution of the zero-knowledge proof circuit; wherein, when each circuit constraint group has a solution, the set of solutions of each circuit constraint group is used as the solution of the zero-knowledge proof circuit; when any circuit constraint group has no solution, the zero-knowledge proof circuit has no solution.

[0152] According to another aspect of the embodiment, a computer program product is also provided, including a computer program / instruction, which implements the steps of the method described in any of the above embodiments when executed by a processor.

[0153] According to yet another embodiment, a computing device is provided, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, the method described in any one of the above embodiments is implemented.

[0154] In the 1990s, improvements to a technology could be clearly distinguished as hardware improvements (for example, improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the method flow). However, with the development of technology, many improvements to the method flow today can be regarded as direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to ask a chip manufacturer to design and produce a dedicated integrated circuit chip. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages ​​and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.

[0155] The controller can be implemented in any appropriate manner, for example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (such as software or firmware) that can be executed by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in a purely computer-readable program code manner, the controller can be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, this controller can be considered as a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software modules for implementing the method and structures within the hardware component.

[0156] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a server system. Of course, the present application does not exclude that with the development of computer technology in the future, the computer that implements the functions of the above embodiments may be, for example, a personal computer, a laptop computer, a vehicle-mounted human-computer interaction device, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0157] Although one or more embodiments of the present specification provide method operation steps as described in the embodiments or flow charts, more or less operation steps may be included based on conventional or non-creative means. The order of steps listed in the embodiments is only one way of executing the order of many steps, and does not represent the only execution order. When the device or terminal product in practice is executed, it can be executed in sequence or in parallel according to the method shown in the embodiments or the drawings (for example, a parallel processor or a multi-threaded processing environment, or even a distributed data processing environment). The term "include", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, product or equipment including a series of elements includes not only those elements, but also includes other elements that are not explicitly listed, or also includes elements inherent to such a process, method, product or equipment. In the absence of more restrictions, it is not excluded that there are other identical or equivalent elements in the process, method, product or equipment including the elements. For example, if the words first, second, etc. are used to represent the name, they do not represent any specific order.

[0158] For the convenience of description, the above devices are described in various modules according to their functions. Of course, when implementing one or more of the present specification, the functions of each module can be implemented in the same or more software and / or hardware, or the module implementing the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0159] This specification is described with reference to the flowcharts and / or block diagrams of the methods, apparatus (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0160] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0161] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0162] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0163] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0164] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage, graphene storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0165] It should be understood by those skilled in the art that one or more embodiments of the present specification may be provided as a method, system or computer program product. Therefore, one or more embodiments of the present specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, one or more embodiments of the present specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0166] One or more embodiments of the present specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0167] Each embodiment in this specification is described in a progressive manner, and the same and similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. In the description of this specification, the description of the reference terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic representation of the above terms does not necessarily target the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples without contradiction.

[0168] The above description is only an example of one or more embodiments of the present specification and is not intended to limit one or more embodiments of the present specification. For those skilled in the art, one or more embodiments of the present specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification shall be included in the scope of the claims.

Claims

1. A method for solving a zero-knowledge proof circuit, wherein the zero-knowledge proof circuit comprises a first circuit constraint group, wherein variables in the circuit constraints correspond to parameters in a target model; The target model is used to make predictions based on input data; The value of a specific variable in the first circuit constraint group is determined by the input data; the method comprises: Splitting the first circuit constraint group into a plurality of sub-constraint groups arranged in sequence; among the plurality of sub-constraint groups, the i-th sub-constraint group includes a first variable and a second variable, wherein the first i-1 sub-constraint groups include the first variable and do not include the second variable; A constraint solver is used to solve each sub-constraint group in sequence according to the arrangement order of the multiple sub-constraint groups to obtain a solution to the first circuit constraint group; wherein, when solving the i-th sub-constraint group, the solutions of the first i-1 sub-constraint groups are added to the i-th sub-constraint group as circuit constraints; and the solutions of the first i-1 sub-constraint groups include the values ​​of the first variable.

2. The method according to claim 1, wherein: The zero-knowledge proof circuit includes a plurality of circuit constraints; the method further includes: The multiple circuit constraints are divided into a plurality of circuit constraint groups, including the first circuit constraint group; each variable in any circuit constraint group does not belong to any other circuit constraint group.

3. The method according to claim 2, wherein: Dividing the plurality of circuit constraints into a plurality of circuit constraint groups, including: For each variable in the plurality of circuit constraints, generating a corresponding graph node; Traverse each circuit constraint, connect the graph nodes corresponding to each variable belonging to the same circuit constraint, and obtain several subgraphs; According to the variables corresponding to the graph nodes in each subgraph, the corresponding circuit constraint groups are generated.

4. The method according to claim 2, further comprising: Summarize the solutions of each circuit constraint group to obtain the solution of the zero-knowledge proof circuit; wherein, when each circuit constraint group has a solution, the set of solutions of each circuit constraint group is used as the solution of the zero-knowledge proof circuit; when any circuit constraint group has no solution, the zero-knowledge proof circuit has no solution.

5. The method according to claim 1, wherein: Solve the i-th sub-constraint group, including: Determine whether the number of solutions reaches a preset second threshold; if not, add the solutions of the first i-1 sub-constraint groups as the second circuit constraint to the i-th sub-constraint group, and use the constraint solver to solve the i-th sub-constraint group; if there is a solution, increase the number of solutions by 1, and start solving the i+1-th sub-constraint group.

6. The method according to claim 5, wherein: Solving the ith sub-constraint group also includes: If the i-th sub-constraint group has no solution, the number of solutions is set to the second threshold, and the i-th sub-constraint group is started to be solved.

7. The method according to claim 5, wherein: Solving the ith sub-constraint group also includes: If the number of solutions reaches a second threshold, and i=1, then the first circuit constraint group has no solution; If the number of solutions reaches the second threshold and i>1, the number of solutions is cleared, the solution of the i-1th sub-constraint group is set as infeasible, and the solution of the i-1th sub-constraint group is started.

8. The method according to claim 5, wherein: The second circuit constraint is used to make each variable in the first i-1 sub-constraint groups equal to the value in the solution of the first i-1 sub-constraint groups.

9. A method for solving a zero-knowledge proof circuit, wherein the zero-knowledge proof circuit includes a first circuit constraint group; the method comprising: Splitting the first circuit constraint group into a plurality of sub-constraint groups arranged in sequence; Among the plurality of sub-constraint groups, the i-th sub-constraint group includes a first variable and a second variable, wherein the first i-1 sub-constraint groups include the first variable and do not include the second variable; A constraint solver is used to solve each sub-constraint group in sequence according to the arrangement order of the multiple sub-constraint groups to obtain a solution to the first circuit constraint group; wherein, when solving the i-th sub-constraint group, the solutions of the first i-1 sub-constraint groups are added to the i-th sub-constraint group as circuit constraints; and the solutions of the first i-1 sub-constraint groups include the values ​​of the first variable.

10. A computing device comprising a memory and a processor, wherein the memory stores executable codes, and when the processor executes the executable codes, the method according to any one of claims 1 to 9 is implemented.

Citation Information

Cited By

  • Zero-knowledge proof circuit solving method and computing device

    WO2026138157A1