Method for generating non-interactive zero-knowledge proof through efficient outsourcing

By segmenting and encrypting personal private inputs in efficient outsourcing generation of non-interactive zero-knowledge proofs, and generating proofs through the commitment and aggregation of computing clients, the problems of low computing efficiency, poor security and poor compatibility in the prior art are solved, and a more efficient, secure and compatible computing and verification process is achieved.

CN119995892APending Publication Date: 2025-05-13GUANGZHOU FANGHE DATA SERVICE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510064219.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art has problems of low computing efficiency, poor security and poor compatibility when efficiently outsourcing the generation of non-interactive zero-knowledge proofs (NIZK).

Method used

By generating public parameters and public-private keys used for encryption, the proofer divides the personal private input into several shares and encrypts it with the public key, calculates the client decrypts and randomly selects the private input vector and noise vector, performs commitment and broadcasts, aggregates and calculates challenges to generate proofs, and verifies the validity of the statement by the verifier.

Benefits of technology

It improves computing efficiency and security, reduces the computing and storage overhead of a single computing node, reduces the number of communications and data transmission, and enhances the ability to resist attacks and credibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995892A_ABST
    Figure CN119995892A_ABST
Patent Text Reader

Abstract

The invention discloses an efficient outsourcing generation non-interactive zero-knowledge proof method, which is characterized in that personal private input is segmented and encrypted into a plurality of shares, the security in transmission is ensured by using a public key encryption technology, even if a computing client is broken, complete private information cannot be directly acquired, and the security of the computing client is ensured. Each computing client only obtains part of shares after decryption, the data risk is dispersed, the data protection difficulty is improved, meanwhile, the clients can process respective shares in parallel, the computing efficiency is improved, the correctness and consistency of computing are ensured by aggregating commitments, computing challenges and processing and broadcasting private input shares, and the computing efficiency is improved. The finally generated proof can be sent to a verifier in a non-interactive manner, the statement validity can be verified without additional communication, the verification efficiency is improved, in addition, the calculation and storage overhead of a single calculation node is reduced through a segmentation and encryption method, the communication frequency and the data transmission amount are reduced through non-interactive verification, and the communication overhead is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of privacy computing application technology, and in particular to a method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs. Background Art

[0002] In the field of modern information technology, with the continuous increase in data volume and the improvement in the demand for privacy protection, the technology of efficiently outsourcing the generation of non-interactive zero-knowledge proof (NIZK) has received increasing attention. Non-interactive zero-knowledge proof is a technology that allows a prover to provide a one-time proof without multiple rounds of interaction with the verifier. The verifier only needs to use this proof to verify the authenticity of a statement without obtaining any secret information of the prover. This technology improves efficiency while ensuring data privacy. It is an indispensable security tool in current distributed computing and cloud computing.

[0003] With the widespread application of cloud computing, more and more companies and individuals outsource computing tasks to cloud service providers. Although this outsourcing model has brought great convenience, it has also caused concerns about the correctness of the computing results. Users hope to ensure the credibility of outsourced computing results without leaking input data. NIZK technology provides an effective solution for this. Through NIZK, users can generate a proof to prove the correctness of their computing results, and the cloud service provider does not need to know the specific content of the input data. This mechanism not only protects the user's privacy, but also ensures the credibility of the computing service.

[0004] Although NIZK technology brings many advantages, it still faces certain challenges in practical applications. The first is the problem of computational efficiency. As data complexity increases, how to design an efficient NIZK generation algorithm becomes a research focus. This requires striking a balance between ensuring the rapidity of proof generation and the efficiency of verification. The second is security assurance. In an outsourced computing environment, NIZK must guard against potential malicious attacks and ensure that proofs cannot be forged and information cannot be leaked. In addition, standardization and compatibility issues are also key to promoting NIZK technology. Summary of the invention

[0005] In view of this, the present invention proposes an efficient outsourcing method for generating non-interactive zero-knowledge proofs, which can solve the defects of low computational efficiency, poor security and poor compatibility in the prior art.

[0006] The technical solution of the present invention is achieved in this way:

[0007] A method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs, specifically comprising:

[0008] Generate public parameters and public and private keys used for encryption;

[0009] The prover splits the personal private input into several shares;

[0010] The prover encrypts several shares using the public key and sends the ciphertext to the corresponding computing client;

[0011] Each computing client decrypts the received ciphertext to obtain the corresponding private input share, and randomly selects the private input vector and noise vector;

[0012] Each computing client commits to and broadcasts the selected private input vector and noise vector;

[0013] Each computation client aggregates all commitments and computes the challenge, then computes and broadcasts the prover’s private input share;

[0014] Each computing client aggregates the received private shares and generates a proof to send to the verifier;

[0015] The verifier verifies the validity of the statement.

[0016] As a further optional solution of the method for efficiently outsourcing the generation of non-interactive zero-knowledge proof, the generation of public parameters specifically includes:

[0017] Trusted third party inputs security parameters;

[0018] Generate a public parameter matrix A, a hash function H, a group G, and a generator g according to the security parameters.

[0019] As a further optional solution of the method for efficiently outsourcing the generation of non-interactive zero-knowledge proof, the generation of public and private keys used for encryption specifically includes:

[0020] The trusted third party enters security parameters;

[0021] Generate a private key sk based on elliptic curve decryption according to the security parameters;

[0022] The public key pk used for elliptic curve encryption is calculated based on the private key sk.

[0023] As a further optional solution to the method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs, the prover divides the personal private input into several shares, specifically including:

[0024] The prover P analyzes the personal secret and obtains the data vector w and the noise vector e;

[0025] According to the data vector w and the noise vector e, the data is divided into several shares.

[0026] As a further optional solution of the efficient outsourcing method for generating non-interactive zero-knowledge proofs, the prover encrypts several shares using a public key and sends the ciphertext to the corresponding computing client, specifically including:

[0027] The prover uses the public key pk to perform EIGamal encryption on several shares dimension by dimension to obtain the encrypted ciphertext;

[0028] Send the encrypted ciphertext to the corresponding computing client.

[0029] As a further alternative to the method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs, each computing client aggregates all commitments and calculates challenges, and then calculates and broadcasts the prover's private input shares, specifically including:

[0030] Each computing client aggregates all commitments to get a complete commitment and calculates the challenge through the hash function H;

[0031] Respond to the calculated challenge, calculate the prover's private input share to obtain the private share, and broadcast the private share to other computing clients.

[0032] As a further alternative to the method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs, the verifier verifies the validity of the statement, specifically including:

[0033] The verifier receives the proof and divides it into corresponding tuples, then calculates the challenge through the hash function H, and checks the validity of the statement based on the challenge. If the statement is valid, it accepts the statement that there is a data vector w and a noise vector e.

[0034] An efficient outsourcing system for generating non-interactive zero-knowledge proofs, comprising:

[0035] A generation module, used to generate public parameters and public and private keys used for encryption;

[0036] The split module is used by the prover to split personal private input into several shares;

[0037] The encryption module is used by the prover to encrypt several shares using the public key and send the ciphertext to the corresponding computing client;

[0038] The selection module is used for each computing client to decrypt the received ciphertext to obtain the corresponding private input share, and randomly select the private input vector and the noise vector;

[0039] The commitment module is used for each computing client to commit to and broadcast the selected private input vector and noise vector;

[0040] Aggregation module, used by each computing client to aggregate all commitments and calculate challenges, and then calculate and broadcast the prover's private input share;

[0041] The proof module is used by each computing client to aggregate the received private shares and generate proofs to send to the verifier;

[0042] Verification module, used by verifiers to verify the validity of statements.

[0043] A computing device comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs are implemented.

[0044] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the above-mentioned method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs.

[0045] The beneficial effects of the present invention are as follows: by dividing personal private input into several shares and encrypting these shares with a public key, the security of private information during transmission is ensured. Even if a computing client is compromised, the complete private information cannot be directly obtained. Each computing client only obtains part of the private input share after decryption, which further disperses the data risk and increases the difficulty of data leakage. After decryption, the computing client can process the private input shares obtained by each client in parallel, thereby improving the computing efficiency. By aggregating all commitments and calculating challenges, and calculating and broadcasting the private input shares of the prover, the correctness and consistency of the calculation are ensured, and the proof finally generated can be verified. It is sent to the verifier non-interactively, and the verifier can verify the validity of the statement without additional communication with the prover or computing client, thereby improving the verification efficiency. Due to the segmentation and encryption methods, each computing client only needs to process part of the data, thereby reducing the computing and storage overhead of a single computing node. The non-interactive verification process reduces the number of communications and the amount of data transmission, further reducing the communication overhead. The use of zero-knowledge proof technology ensures that the prover can prove the authenticity of a statement to the verifier without leaking private information. By randomly selecting private input vectors and noise vectors, as well as making commitments and broadcasts, the anti-attack capability and credibility are increased. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0047] Figure 1 A schematic flow chart of the steps of a method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs provided by an embodiment of the present invention;

[0048] Figure 2 A schematic diagram of the composition of a system for efficiently outsourcing generation of non-interactive zero-knowledge proofs provided by an embodiment of the present invention;

[0049] Figure 3 A schematic diagram of the composition of a computing device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0050] The technical solutions in the embodiments of the present invention are described clearly and completely below. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0051] refer to Figures 1 to 3 , a method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs, specifically including:

[0052] Generate public parameters and public and private keys used for encryption;

[0053] The prover splits the personal private input into several shares;

[0054] The prover encrypts several shares using the public key and sends the ciphertext to the corresponding computing client;

[0055] Each computing client decrypts the received ciphertext to obtain the corresponding private input share, and randomly selects the private input vector and noise vector;

[0056] Each computing client commits to and broadcasts the selected private input vector and noise vector;

[0057] Each computation client aggregates all commitments and computes the challenge, then computes and broadcasts the prover’s private input share;

[0058] Each computing client aggregates the received private shares and generates a proof to send to the verifier;

[0059] The verifier verifies the validity of the statement.

[0060] In this embodiment, by dividing the personal private input into several shares and encrypting these shares with the public key, the security of private information during transmission is ensured. Even if a computing client is compromised, it cannot directly obtain the complete private information. Each computing client only obtains part of the private input share after decryption, which further disperses the data risk and increases the difficulty of data leakage. After decryption, the computing client can process the private input shares obtained by each client in parallel, thereby improving the computing efficiency. By aggregating all commitments and calculating challenges, and calculating and broadcasting the private input shares of the prover, the correctness and consistency of the calculation are ensured, and the proof finally generated can be very reliable. It is sent interactively to the verifier, and the verifier can verify the validity of the statement without additional communication with the prover or computing client, thereby improving the verification efficiency. Due to the segmentation and encryption methods, each computing client only needs to process part of the data, thereby reducing the computing and storage overhead of a single computing node. The non-interactive verification process reduces the number of communications and the amount of data transmission, further reducing the communication overhead. The use of zero-knowledge proof technology ensures that the prover can prove the authenticity of a statement to the verifier without leaking private information. By randomly selecting private input vectors and noise vectors, as well as making commitments and broadcasts, the anti-attack capability and credibility are increased.

[0061] It should be noted that the initialization phase parameters of the described method are defined as follows:

[0062] 1 λ : Security parameters;

[0063] m: the row of the selected cell;

[0064] n: the column of the selected cell;

[0065] q: modulus;

[0066] x: distribution mode;

[0067] k: the number of computing clients;

[0068] w: prover’s private input;

[0069] A: Matrix;

[0070] b: Public statement.

[0071] Preferably, the generating of the common parameters specifically includes:

[0072] Trusted third party inputs security parameters;

[0073] Generate a public parameter matrix A, a hash function H, a group G, and a generator g according to the security parameters.

[0074] In this embodiment, the trusted third party inputs security parameters 1 λ Generate common parameter matrix and a random hash function In this specific embodiment, we choose SHAKE256 for implementation. SHAKE256 is an extensible output function with one-way property: the original data cannot be reversely derived from the hash value, and anti-collision property: it is extremely difficult to find two different inputs that produce the same hash value. In practical applications, the security parameter A can be set to 1024 or higher to achieve a security strength that meets actual needs. The selected n is set based on the security parameter. In this embodiment, n is 1024 bits, so the output length of SHAKE256 needs to be set to 1024. In addition, q is set to 2. 30 .

[0075] Preferably, the generation of public and private keys for encryption specifically includes:

[0076] The trusted third party enters security parameters;

[0077] Generate a private key sk based on elliptic curve decryption according to the security parameters;

[0078] The public key pk used for elliptic curve encryption is calculated based on the private key sk.

[0079] In this embodiment, the trusted third party inputs security parameters 1 λ , randomly select the private key sk based on elliptic curve decryption, and calculate and generate the public key pk used for elliptic curve encryption based on the private key sk. In this embodiment, the elliptic curve public key EIGamal encryption and decryption algorithm is selected. First, the security parameter 1 λ Determine the group G and the generator g, and then randomly generate a private key Then calculate the public key pk: h = g x , EIGamal public key encryption is as follows: Randomly select And calculate En(pk, v) for the message v to be encrypted: c1 = g r , c2=h r ·g v And output the ciphertext pair (c1, c2), the private key decrypts the ciphertext pair (c1, c2),

[0080] Preferably, the prover divides the personal private input into several shares, specifically including:

[0081] The prover P analyzes the personal secret and obtains the data vector w and the noise vector e;

[0082] According to the data vector w and the noise vector e, the data is divided into several shares.

[0083] In this embodiment, the prover inputs the personal private data vector Noise Vector Segmentation is performed, wherein the noise distribution method selected in this embodiment is is a Gaussian distribution. The specific segmentation method is to split w and e into k parts and randomly select Random Selection

[0084] Preferably, the prover encrypts several shares using a public key and sends the ciphertext to the corresponding computing client, specifically including:

[0085] The prover uses the public key pk to perform EIGamal encryption on several shares dimension by dimension to obtain the encrypted ciphertext;

[0086] Send the encrypted ciphertext to the corresponding computing client.

[0087] In this embodiment, the prover converts multiple shares {w i , e i} i∈[k] Encrypt with public key pk to get ciphertext And the ciphertext Sent to the corresponding computing client, due to the share w i , e i It is a vector, so it is necessary to perform ElGamal encryption dimension by dimension. The details are as follows: For dimension w i,j Encryption En(pk i , w i,j ), randomly selected Get the ciphertext pair For sending the share of each computing client, encryption is performed k×n times in total.

[0088] It should be noted that each computing client decrypts the received ciphertext Get the corresponding private input share w i , e i , and randomly select a private input vector y i And according to the distribution Select the noise vector y i , the ciphertext pair received by the i-th computing client Decrypt using private key After n decryptions, the corresponding private input share vector w can be restored i , e i , randomly select a private input vector and the noise vector Distribution is a Gaussian distribution;

[0089] Each noise pair selects a private input vector y i and the noise vector f i Calculate C i =Ay i +f i , get the commitment C i And C i Broadcast to other computing clients.

[0090] Preferably, each computing client aggregates all commitments and calculates challenges, and then calculates and broadcasts the prover's private input share, specifically including:

[0091] Each computing client aggregates all commitments to get a complete commitment and calculates the challenge through the hash function H;

[0092] Respond to the calculated challenge, calculate the prover's private input share to obtain the private share, and broadcast the private share to other computing clients.

[0093] In this embodiment, each computing client aggregates all commitments {C i} i∈[k] ,calculate Get the complete commitment C, and calculate the challenge c through the hash algorithm H. Specifically, use the hash algorithm SHAKE256. First, serialize the matrix A to get a one-dimensional array, then string the one-dimensional array, and use the string with the statement b and the aggregated commitment C as the hash input to get the challenge c = SHAKE256 (A||b||C). Then respond to the generated challenge c and the prover's private input share w i , e i Calculate z i ,u i , where z i =y i +c·w i ,u i =f i +c·e i And z i ,u i Broadcast to other computing clients.

[0094] It should be noted that each client receives a private share {z i ,u i} i∈[k] Aggregation is performed to obtain z, u where And generate proof π=(C, z, u) and send it to the verifier.

[0095] Preferably, the verifier verifies the validity of the statement, specifically including:

[0096] The verifier receives the proof and divides it into corresponding tuples, then calculates the challenge through the hash function H, and checks the validity of the statement based on the challenge. If the statement is valid, it accepts the statement that there is a data vector w and a noise vector e.

[0097] In this embodiment, the verifier receives the proof π and divides it into corresponding tuples (C, z, u), then calculates the challenge c=SHAKE256(A||b||C) through the hash algorithm H, and checks whether the equation Az+u=C+c·b and ||u||≤B are true according to the challenge. If both are true, the verifier accepts the statement that there are w, e such that Aw+e=b, and ||u|| is selected using the L2 norm, that is, in k is the number of participants, σ ​​is the noise distribution parameter, i.e., the Gaussian distribution parameter, m is the dimension of the vector, and c is the size of the challenge.

[0098] An efficient outsourcing system for generating non-interactive zero-knowledge proofs, comprising:

[0099] A generation module, used to generate public parameters and public and private keys used for encryption;

[0100] The split module is used by the prover to split personal private input into several shares;

[0101] The encryption module is used by the prover to encrypt several shares using the public key and send the ciphertext to the corresponding computing client;

[0102] The selection module is used for each computing client to decrypt the received ciphertext to obtain the corresponding private input share, and randomly select the private input vector and the noise vector;

[0103] The commitment module is used by each computing client to commit to and broadcast the selected private input vector and noise vector:

[0104] Aggregation module, used by each computing client to aggregate all commitments and calculate challenges, and then calculate and broadcast the prover's private input share;

[0105] The proof module is used by each computing client to aggregate the received private shares and generate proofs to send to the verifier;

[0106] Verification module, used by verifiers to verify the validity of statements.

[0107] A computing device comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs are implemented.

[0108] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the above-mentioned method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs.

[0109] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. An efficient outsourcing method for generating non-interactive zero-knowledge proofs, characterized in that: Specifically include: Generate public parameters and public and private keys used for encryption; The prover splits the personal private input into several shares; The prover encrypts several shares using the public key and sends the ciphertext to the corresponding computing client; Each computing client decrypts the received ciphertext to obtain the corresponding private input share, and randomly selects the private input vector and noise vector; Each computing client commits to and broadcasts the selected private input vector and noise vector; Each computation client aggregates all commitments and computes the challenge, then computes and broadcasts the prover’s private input share; Each computing client aggregates the received private shares and generates a proof to send to the verifier; The verifier verifies the validity of the statement.

2. According to claim 1, a method for efficiently outsourcing generation of non-interactive zero-knowledge proofs is characterized in that: The generating of the public parameters specifically includes: Trusted third party inputs security parameters; Generate a public parameter matrix A, a hash function H, a group G, and a generator g according to the security parameters.

3. The method for efficiently outsourcing generation of non-interactive zero-knowledge proof according to claim 2, characterized in that: The generation of public and private keys used for encryption specifically includes: The trusted third party enters security parameters; Generate a private key sk based on elliptic curve decryption according to the security parameters; The public key pk used for elliptic curve encryption is calculated based on the private key sk.

4. The method for efficiently outsourcing generation of non-interactive zero-knowledge proof according to claim 3, characterized in that: The prover divides the personal private input into several shares, including: The prover P analyzes the personal secret and obtains the data vector w and the noise vector e; According to the data vector w and the noise vector e, the data is divided into several shares.

5. The method for efficiently outsourcing generation of non-interactive zero-knowledge proof according to claim 4, characterized in that: The prover encrypts several shares using the public key and sends the ciphertext to the corresponding computing client, specifically including: The prover uses the public key pk to perform EIGamal encryption on several shares dimension by dimension to obtain the encrypted ciphertext; Send the encrypted ciphertext to the corresponding computing client.

6. The method for efficiently outsourcing generation of non-interactive zero-knowledge proofs according to claim 5, characterized in that: Each computing client aggregates all commitments and calculates challenges, and then calculates and broadcasts the prover's private input share, specifically including: Each computing client aggregates all commitments to get a complete commitment and calculates the challenge through the hash function H; Respond to the calculated challenge, calculate the prover's private input share to obtain the private share, and broadcast the private share to other computing clients.

7. The method for efficiently outsourcing generation of non-interactive zero-knowledge proofs according to claim 6, characterized in that: The verifier verifies the validity of the statement, specifically including: The verifier receives the proof and divides it into corresponding tuples, then calculates the challenge through the hash function H, and checks the validity of the statement based on the challenge. If the statement is valid, it accepts the statement that there is a data vector w and a noise vector e.

8. An efficient outsourcing system for generating non-interactive zero-knowledge proofs, characterized in that: include: A generation module, used to generate public parameters and public and private keys used for encryption; The split module is used by the prover to split personal private input into several shares; The encryption module is used by the prover to encrypt several shares using the public key and send the ciphertext to the corresponding computing client; The selection module is used for each computing client to decrypt the received ciphertext to obtain the corresponding private input share, and randomly select the private input vector and the noise vector; The commitment module is used for each computing client to commit to and broadcast the selected private input vector and noise vector; Aggregation module, used by each computing client to aggregate all commitments and calculate challenges, and then calculate and broadcast the prover's private input share; The proof module is used by each computing client to aggregate the received private shares and generate proofs to send to the verifier; Verification module, used by verifiers to verify the validity of statements.

9. A computing device, characterized in that The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, which, when executed by a processor, implements the steps of the method for efficiently outsourcing the generation of non-interactive zero-knowledge proofs as described in any one of claims 1 to 7.

Citation Information

Cited By

  • Zero-knowledge proof compression method and system suitable for resource-constrained equipment

    CN120856346A