Zero-knowledge proof generation method and device, equipment and storage medium
By implementing a method of sharing infrastructure with multiple proof protocols on the management platform, the problem of low resource utilization in different ZKP protocols and scenarios is solved, and efficient resource utilization is achieved.
Patent Information
- Application Number
- CN202410381649.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-17
- Filing Date
- 2024-03-29
- Publication Date
- 2025-05-20
AI Technical Summary
When generating zero-knowledge proof (ZKP), different ZKP protocol types and scenarios have different requirements for resources, resulting in low resource utilization.
By implementing a method of sharing infrastructure with multiple proof protocols on the management platform, the management platform allocates resources based on the proof generation request, determines the target computing resources from multiple computing resources, and generates the target ZKP, thereby improving the resource utilization rate.
It effectively improves the utilization rate of resources and ensures efficient use of resources under different ZKP protocols and scenarios.
Smart Images

Figure CN120021191A_ABST
Abstract
Description
[0001] This application claims the priority of the Chinese patent application with the application number 202311554136.2 and the invention title "Zero-Knowledge Proof Generation Method, Apparatus, Device and Storage Medium" filed on November 17, 2023, the entire content of which is incorporated herein by reference. Technical Field
[0002] This application relates to the field of data security, and particularly to a zero-knowledge proof (ZKP) generation method, apparatus, device and storage medium. Background Art
[0003] ZKP is a cryptographic protocol that allows a prover to prove to a verifier that a certain statement is correct without revealing any additional information to the verifier other than the statement itself. In various scenarios, it is necessary to generate ZKP, for example, in blockchain, distributed storage, and privacy protection, etc.
[0004] In the related art, ZKP can be generated through an online integrated development environment (IDE) or an online proof generation tool. This ZKP generation method includes: the user first selects the ZKP protocol type through the user interface of the IDE or the online proof generation tool, and then edits the circuit online or uploads the circuit file, and the IDE or the online proof generation tool generates ZKP according to the circuit or the circuit file.
[0005] However, different ZKP protocol types and different scenarios have different resource requirements. When the IDE or the online proof generation tool supports multiple ZKP protocols, the resources corresponding to different ZKP protocols are independent of each other, and there will be a situation where the resources are insufficient or a large amount of resources are idle, resulting in low resource utilization. Summary of the Invention
[0006] This application provides a ZKP generation method, apparatus, device and storage medium, in which multiple proof protocols share resources during the ZKP generation process, and the resource utilization rate can be improved.
[0007] In a first aspect, a ZKP generation method is provided. The method is applied to a management platform for managing infrastructure, where the infrastructure includes a plurality of computing resources, and each computing resource in the plurality of computing resources is used to generate zero-knowledge proofs corresponding to multiple proof protocols. The method includes: receiving a proof generation request, where the proof generation request includes proof protocol information and a circuit file. The proof protocol information is used to indicate a target proof protocol used to generate a target zero-knowledge proof, and the target proof protocol is one of the multiple protocol types. The circuit file is used to indicate a computing model for generating the target zero-knowledge proof; determining a target computing resource from the plurality of computing resources according to the proof generation request; and generating the target zero-knowledge proof through the target computing resource.
[0008] In this application, multiple proof protocols share the infrastructure. The management platform performs resource allocation according to the proof generation request, that is, determines a target computing resource from the multiple computing resources included in the infrastructure, and generates a target ZKP through the target computing resource, which can effectively improve the resource utilization rate.
[0009] Optionally, the proof generation request further includes configuration parameters. Determining a target computing resource from the plurality of computing resources according to the proof generation request includes: generating a constraint system corresponding to the target proof protocol according to the circuit file and the configuration parameters; and determining a target computing resource from the plurality of computing resources according to the target proof protocol and the characteristic information of the constraint system. The characteristic information of the constraint system includes at least one of the following information: the scale of the constraint system, the bit width of the elliptic curve, the type of the hash function, and the type of the polynomial commitment. Here, the characteristic information of the constraint system refers to the information that has a greater impact on the overall computational amount of the target computing task.
[0010] Different types of ZKP protocols may support different types of constraint systems, and different types of constraint systems require different amounts of computation in the process of generating ZKPs. Therefore, it is necessary to first generate a constraint system corresponding to the type indicated by the proof protocol information; then, according to the target proof protocol and the characteristic information of the constraint system, allocate computing resources for the target computing task from the computing resource pool.
[0011] Optionally, determining the target computing resource from the multiple computing resources according to the characteristic information of the target proof protocol and the constraint system includes: determining the task complexity according to the characteristic information of the target proof protocol and the constraint system; and determining the target computing resource from the multiple computing resources according to the task complexity. The task complexity is used to measure the complexity of the computing task in the process of generating the ZKP. Generally, the higher the task complexity, the more computing resources are required, and the lower the task complexity, the fewer computing resources are required. The characteristic information of the constraint system has a great influence on the overall amount of computation of the target computing task. Therefore, this information can be used to measure the task complexity of the target computing task.
[0012] Optionally, in addition to considering the characteristic information of the constraint system that has a great influence on the amount of computation, other reference information can also be combined to determine the task complexity of the target computing task. Correspondingly, the method further includes: obtaining the reference information. The reference information includes at least one of the user level, the number of concurrent processes, the size of the generated proof, and the expected response time for generating the proof. The user level is used to indicate the level of the initiator of the proof generation request, and the number of concurrent processes is used to indicate the number of other proof generation requests that coexist with the proof generation request. These reference information may also affect the amount of computation per unit time. Therefore, they can also be used to determine the task complexity.
[0013] Optionally, each computing resource includes a worker thread, and each worker thread is used to run an operator. The target proof protocol is associated with at least one operator. For the worker threads, the following method can be adopted for allocation: according to the task complexity, determine the target number of worker threads for each operator associated with the target proof protocol from the multiple computing resources, and the target number is positively correlated with the task complexity. The higher the task complexity, the more operator operations need to be performed. Therefore, the corresponding target number is also larger, so as to meet the requirements of the target computing task.
[0014] In some examples, each worker thread runs in a processor core, and each processor core runs only one worker thread, that is, each processor core is used to run an operator. In other examples, each processor core runs multiple worker threads, that is, each processor core is used to run one or more operators.
[0015] Optionally, the infrastructure further includes multiple storage resources, and the method further includes: determining the target storage resource from the multiple storage resources according to at least one of the scale of the constraint system, the size of the lookup table used in the polynomial commitment scheme, the bit width of the elliptic curve, and the algorithm of the computing operator.
[0016] During the execution of the target computing task, a large amount of data needs to be stored, and the above information is closely related to the amount of data to be stored during the execution of the computing task. Therefore, these information can be used to determine the target storage resources to store this data.
[0017] Optionally, the proof generation request further includes a first type of parameter, which is used to convert the circuit file into a quadratic arithmetic program QAP; the method further includes: verifying the circuit file and / or the first type of parameter according to the proof protocol information. After receiving the proof generation request, at least part of the content in the proof generation request is verified according to the proof protocol information to ensure the normal execution of the subsequent process of generating ZKP.
[0018] Optionally, the proof generation request further includes mode information, which is used to indicate that the mode of the target ZKP is a recursive mode; the generating of the ZKP by the target computing resource includes: obtaining a historical ZKP; generating a target ZKP based on the historical ZKP by the target computing resource. When the mode of the target ZKP is a recursive mode, it is necessary to first obtain the historical ZKP, and then generate the target ZKP based on the historical ZKP. That is, the present application can support both non-recursive mode ZKP and recursive mode ZKP.
[0019] Optionally, the proof generation request further includes proof index information of the historical ZKP; the obtaining of the historical ZKP includes: obtaining the historical ZKP from the cloud server according to the proof index information. The historical ZKP is stored in the cloud server, and when needed, the historical ZKP is obtained through the proof index information for recursive proof.
[0020] In a second aspect, a ZKP generation device is provided, and the ZKP generation device has the function of implementing the method described in the first aspect or any optional manner of the first aspect above. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0021] In a third aspect, a computing device cluster is provided, and the computing device cluster includes at least one computing device, and each computing device includes a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method in the first aspect above.
[0022] Optionally, the processor is one or more, and the processor is a multi-core processor, and the memory is one or more.
[0023] Optionally, the memory may be integrated with the processor, or the memory and the processor may be separately provided.
[0024] In a specific implementation process, the memory may be a non-transitory memory, such as a read only memory (ROM), which may be integrated with the processor on the same chip or may be separately provided on different chips. The present application does not limit the type of the memory and the setting manner of the memory and the processor.
[0025] In a fourth aspect, a computer-readable storage medium is provided. At least one instruction is stored in the storage medium and is loaded and executed by a computing device cluster so that the computing device cluster implements the method in the first aspect above.
[0026] In a fifth aspect, a computer program (product) is provided. The computer program (product) includes computer program code. When the computer program code is run by a computing device cluster, the computing device cluster executes the method in the first aspect above. Description of the Drawings
[0027] Figure 1 is a schematic diagram of an application scenario of an embodiment of the present application;
[0028] Figure 2 is a schematic flowchart of a ZKP generation method provided by an embodiment of the present application;
[0029] Figure 3 is a schematic diagram of a component architecture of a ZKP generation device provided by an embodiment of the present application;
[0030] Figure 4 is a schematic diagram of a detailed process of a ZKP generation method provided by an embodiment of the present application;
[0031] Figure 5 is a schematic diagram of a structure of a ZKP generation device provided by an embodiment of the present application;
[0032] Figure 6 is a schematic diagram of a structure of a computing device provided by an embodiment of the present application;
[0033] Figure 7 is a schematic diagram of a structure of a computing device cluster provided by an embodiment of the present application;
[0034] Figure 8 is a schematic diagram of a structure of a computing device cluster provided by an embodiment of the present application. Detailed Embodiments
[0035] To make the objectives, technical solutions, and advantages of this application clearer, the following will further describe the embodiments of this application in detail with reference to the accompanying drawings.
[0036] ZKP has three properties: Completeness, Soundness, and Zero-knowledge.
[0037] The applications of ZKP are very extensive, including but not limited to the following applications:
[0038] · Blockchain system: The rollup solution based on ZKP can effectively improve the throughput and performance of the entire Ethereum system while ensuring decentralization and security. Among them, Ethereum is the de facto standard for the underlying infrastructure of the decentralized Internet (web3) running on blockchain technology and is the public blockchain with the most users, developers, and projects. Ethereum faces the limitations of the blockchain system's impossible triangle (scalability, security, decentralization), resulting in extremely low throughput and performance.
[0039] · Distributed storage: ZKP can prove that a file is correctly stored without disclosing the file content.
[0040] · Privacy protection: ZKP can complete identity verification while protecting sensitive information.
[0041] · Security: ZKP can prove the possession of a certain secret (such as a key) without disclosing the secret itself.
[0042] · Artificial intelligence (AI): ZKP can keep the AI model training process confidential and at the same time prove that the model reaches a certain accuracy.
[0043] In related technologies, when generating ZKP, the resources that can be used by different ZKP protocol types are pre-allocated and independent of each other, which may lead to the problem of low resource utilization. For this reason, this application proposes a ZKP generation method that supports multiple protocols.
[0044] Figure 1 It is a schematic diagram of the application scenario of a ZKP generation method provided by an embodiment of this application. As Figure 1 shown, the management platform is used to manage the infrastructure.
[0045] The infrastructure includes multiple computing resources, which can form a computing resource pool. Each computing resource is used to generate ZKPs corresponding to multiple proof protocols, that is, it is shared by multiple proof protocols. Here, sharing means that there is no fixed binding relationship between the computing resources in the computing resource pool and the type of ZKP protocol. For example, a computing resource can be used to generate a ZKP corresponding to a first ZKP protocol in one time period, and to generate a ZKP corresponding to another ZKP protocol in another time period. The management platform can flexibly schedule computing resources to generate ZKPs for different proof protocols.
[0046] Optionally, the computing resources include one or more of a processor core, a thread running in a processor core, or a virtual machine.
[0047] Optionally, multiple proof protocols can be selected from the following protocol types: halo2, groth16, plonk, STARK, and supernova.
[0048] Optionally, the infrastructure also includes multiple storage resources, which can constitute a storage resource pool. Each storage resource is used to store various data generated during the calculation process in the process of generating ZKP. The storage resource can be a storage space of a memory such as a memory.
[0049] Figure 2 is a flow chart of a ZKP generation method provided in an embodiment of the present application. Figure 1 As shown in the figure, the ZKP generation method includes:
[0050] 11: Receive the certificate generation request.
[0051] The proof generation request includes proof protocol information, wherein the proof protocol information is used to indicate the target proof protocol used to generate the target ZKP, and the target proof protocol is one of the aforementioned multiple protocol types.
[0052] Optionally, the proof protocol information may be a number corresponding to the type of ZKP protocol. Different ZKP protocol types have different corresponding numbers. For example, the numbers corresponding to the four types of halo2, groth16, plonk, and supernova are 1, 2, 3, and 4, respectively. It should be noted that the number of protocol types and the relationship between protocol types and numbers are only examples and can be set according to actual needs. The proof protocol information may also be other identifiers as long as they can uniquely indicate the corresponding ZKP protocol.
[0053] The proof generation request also includes a circuit file. The circuit file is used to indicate the computational model for generating the target ZKP.
[0054] Among them, the circuit file is used to describe a circuit, and the circuit file contains a Turing-complete service description and can implement any service logic. In the embodiments of the present application, a circuit refers to a logical program composed of an input, circuit gates (also known as logic gates), and an output, and is used to describe and encode computing tasks. Optionally, the circuit file can be a JavaScript object notation (JSON) file, etc.
[0055] Optionally, the proof generation request further includes configuration parameters. The configuration parameters at least include a first type of parameter, and this first type of parameter is used to perform a quadratic arithmetic program (QAP) transformation on the constraint system. For example, this first type of parameter includes at least one of the type of elliptic curve, the type of hash function, and the type of polynomial commitment. Optionally, the type of elliptic curve includes, but is not limited to, BN (Barreto-Naehrig) 254 curve, BN-381 curve, BN-512 curve, BLS (Barreto-Lynn-Scott) 12-381 curve, etc., the type of hash function includes, but is not limited to, Poseidon, Minimal Multiplicative Complexity (MiMC), Neptune, secure hash algorithm (SHA) 384, and SHA256, etc., and the type of polynomial commitment includes, but is not limited to, IPA (based on discrete log group), FRI (based on hash function), KZG (based on pairing group), and DARKS (based on unknown order group), etc.
[0056] The content of this first type of parameter is related to the protocol type, and different protocol types require different types of first type of parameters to be set. For example, the type of polynomial commitment corresponding to the zksTARKs protocol is FRI, the type of polynomial commitment corresponding to the plonk protocol is KZG, the type of polynomial commitment corresponding to the halo2 protocol is IPA, and the type of polynomial commitment corresponding to the supersonic protocol is DARK.
[0057] Optionally, the configuration parameters further include a second type of parameter, and this second type of parameter includes mode information, and this mode information is used to indicate the ZKP mode. The ZKP mode includes a recursive mode and a non-recursive mode.
[0058] Optionally, the second type of parameter further includes proof index information of historical ZKPs, which is used to indicate the historical ZKPs required for recursive ZKPs. In some examples, when the mode information indicates that the ZKP mode is the recursive mode, the second type of parameter further includes proof index information of historical ZKPs; while when the mode information indicates that the ZKP mode is the non-recursive mode, the second type of parameter does not include proof index information of historical ZKPs. Exemplarily, the proof index information of historical ZKPs includes the identity (ID) of the historical ZKP. The proof index information of historical ZKPs is generated simultaneously with the generation of the historical ZKP and can uniquely indicate an existing ZKP.
[0059] Optionally, the second type of parameter further includes at least one of the following information: user level, size of the generated proof, and expected response time for generating the proof. The user level is used to indicate the level of the initiator of the proof generation request. The user level, size of the generated proof, and expected response time for generating the proof are related to user requirements.
[0060] Optionally, the proof protocol information, circuit file, and configuration parameters are sent by a user, and the user can be any component and / or role with computing requirements for ZKPs, including but not limited to a zero-knowledge virtual machine (ZK VM), ZK prover, etc.
[0061] Optionally, the user can send a proof generation request by calling a protocol request interface. Correspondingly, the cloud server receives the proof generation request through the protocol request interface. The protocol request interface is an application programming interface (API). It is convenient to send the proof protocol information and task information by calling the protocol request interface.
[0062] Exemplarily, the protocol request interface is as follows:
[0063]
[0064] Among them, "circuit" represents the circuit file, "params" represents the configuration parameter, and "protocol" represents the proof protocol information.
[0065] "circuit":"base64String" means that the circuit file is encoded into a base64 string; "protocol":"halo2 / groth16 / plonk / supernova" represents the protocol type, and multiple protocols such as halo2 / groth16 / plonk / supernova are supported.
[0066] In this example, the content of the proof generation request can be transmitted simultaneously through a single call to the protocol request interface. In other examples, the user can transmit the content of the proof generation request by making multiple calls to the protocol interface.
[0067] In one possible implementation, the user purchases a cloud server and deploys software on the cloud server to form a service. The user who purchases the cloud server can generate a ZKP by calling the service through the API.
[0068] In another possible implementation, the user generates a ZKP through the serverless API method. In the serverless method, the user can purchase the number of API interface calls on demand without purchasing a server.
[0069] 12: Generate a constraint system corresponding to the target proof protocol according to the circuit file and configuration parameters.
[0070] Optionally, the constraint system can be a rank-1 constraint system (R1CS) or a constraint system of the plonkish type, etc. By compiling the circuit file, the corresponding constraint system can be obtained.
[0071] For RICS, each variable is of rank 1. The variables of R1CS can be divided into two types. One is called a public input, and the other is called a non-public variable or an auxiliary variable (aux input). Therefore, the total number of variables in R1CS is the sum of the number of public variables and the number of non-public variables. Depending on the logic circuit, each variable can have different assignments, and these different assignments are called constraints. That is to say, variables and constraints (assignments) are the two determining factors for constructing RICS.
[0072] Each ZKP protocol can support one or more constraint systems. For example, the groth16 protocol supports R1CS. Another example is that the halo2 protocol can support plonkish or R1CS. Plonkish has a richer expression and higher constraint efficiency. Therefore, the halo2 protocol mainly supports plonkish in practice, but can be selected according to actual needs.
[0073] In a possible implementation, when the target proof protocol supports multiple constraint systems, determine the type of the constraint system corresponding to the target proof protocol according to the pre-configured correspondence between the ZKP type and the constraint system type. In this correspondence, each proof protocol corresponds to one type of constraint system; then generate a constraint system of the corresponding type. In another possible implementation, the type of the constraint system can be specified in the foregoing configuration parameters.
[0074] Optionally, before step 12, the method may further include: verifying at least one of the circuit file and the first type of parameters according to the target proof protocol, and after the verification is completed, generating a constraint system corresponding to the target proof protocol according to the circuit file and the first type of parameters.
[0075] In some examples, the correspondence between each protocol type and the circuit format verification rules can be stored in advance. Based on this correspondence, determine the corresponding target circuit format verification rules according to the target proof protocol, and then use the target circuit format verification rules to verify the circuit format. Each proof protocol supports one or more circuit formats. The circuit formats corresponding to different types of proof protocols may be completely different, partially the same, or completely the same. For example, proof protocol A corresponds to circuit format 1; proof protocol B corresponds to 2 circuit formats, namely circuit format 1 and circuit format 2; proof protocol C corresponds to circuit format 3; proof protocol D corresponds to 2 circuit formats, namely circuit format 1 and circuit format 2. It can be seen that the circuit formats corresponding to proof protocol A and proof protocol B are partially the same, the circuit formats corresponding to proof protocol A and proof protocol C are completely different, and the circuit formats corresponding to proof protocol B and proof protocol D are completely the same. The circuit format verification rules can be extracted based on the circuit formats supported by the ZKP protocol type, and the content of the verification rules is not limited in the embodiments of the present disclosure.
[0076] In other examples, the circuit file can be compiled by a compiler. If the compilation is successful, it means that the circuit format is correct; if the compilation fails, it means that the circuit format is incorrect.
[0077] The parameter formats of the first type of parameters corresponding to different types of proof protocols are different. Here, the parameter format includes the number of parameters, the types of parameters, etc. If the number of parameters or the types of parameters of proof protocol A and proof protocol B are different, it means that the parameter formats of the first type of parameters corresponding to proof protocol A and proof protocol B are different; if the number of parameters and the types of parameters of proof protocol A and proof protocol B are the same, it means that the parameter formats of the first type of parameters corresponding to proof protocol A and proof protocol B are the same. For example, the 2 types of the first type of parameters corresponding to proof protocol A are type 1 of elliptic curve and type 1 of polynomial commitment; the 3 types of the first type of parameters corresponding to proof protocol B are type 2 of elliptic curve, type 2 of hash function, and type 2 of polynomial commitment; the 3 types of the first type of parameters corresponding to proof protocol C are type 3 of elliptic curve, type 3 of hash function, and type 3 of polynomial commitment; the 3 types of the first type of parameters corresponding to proof protocol D are type 3 of elliptic curve, type 3 of hash function, and type 3 of polynomial commitment. The number of parameters corresponding to proof protocol A and proof protocol B is different, and the number of parameters corresponding to proof protocol B and proof protocol C is the same, but the parameter types are different; the number of parameters and the parameter types corresponding to proof protocol C and proof protocol D are both the same.
[0078] The corresponding relationship between various proof protocols and parameter formats can be pre-stored. Based on this corresponding relationship, the target parameter format can be determined according to the target proof protocol, and then the format of the first type of parameters can be verified using the target parameter format.
[0079] 13: Determine the target computing resource from multiple computing resources according to the target proof protocol and the characteristic information of the constraint system.
[0080] In some examples, the computing resource includes a processor core. Each processor core is respectively used to operate an operator, and each operator corresponds to multiple processor cores. In the following text, the processor core is taken as an example of a central processing unit (CPU) core for illustration.
[0081] Exemplarily, multiple CPU cores each run a worker thread, that is, each CPU core runs one worker thread, and each worker thread corresponds to an operator operation. These multiple worker threads form a worker pool. The worker threads in the worker pool are divided into at least two types of worker threads, and each type of worker thread includes multiple worker threads. Each type of worker thread corresponds to an operator operation, and the types of operator operations corresponding to different types of worker threads are different. For example, the worker pool includes two types of worker threads, namely multiple scalar multiplication (MSM) worker threads and number theoretic transform / inverse theoretic transform (NTT / INTT) worker threads. The MSM worker threads are used to perform MSM operations, and the NTT / INTT worker threads are used to perform NTT / INTT inverse transform operations. The embodiments of the present application support a worker pool for MSM and NTT operators, which can complete a specified-scale computing task independently of the ZKP algorithm.
[0082] It should be noted that the MSM and NTT operators are two operator operations required by the current ZKP protocol. Therefore, the embodiments of the present application are described by taking these two operators as examples. If the subsequent ZKP protocol involves other operator operations, the types of worker threads in the worker pool will also increase accordingly.
[0083] In this embodiment, each processor core runs one worker thread. Therefore, the computing resources can be allocated in units of processor cores or in units of worker threads, that is, the computing resources include processor cores and / or worker threads. In other embodiments, at least some processor cores can run multiple worker threads, and each worker thread runs one operator. In this case, the computing resources can be allocated in units of worker threads, that is, the computing resources include worker threads.
[0084] In the embodiments of the present application, in addition to the worker pool, a prover pool is also pre-configured in the management platform. Among them, the prover pool includes multiple prover threads, and each prover thread corresponds to a ZKP protocol. The ZKP protocol types corresponding to different prover threads are different. Each prover thread is used to schedule worker threads for one or more computing tasks related to the corresponding ZKP protocol. In this way, it is possible to support the parallel execution of prover threads corresponding to multiple protocols. For example, assume that two computing tasks are received simultaneously, and the ZKP protocol types corresponding to these two computing tasks are both Protocol A. Then the prover thread that supports Protocol A schedules worker threads for these two computing tasks, that is, allocates CPU cores.
[0085] The prover pool supports expansion and update, and can quickly release new algorithm libraries in the community, support new prover threads, and optimize and update the performance of existing prover threads, so as to adapt to the requirements of various application scenarios. Therefore, this method may further include: updating the Prover pool according to an operation instruction, and the update method includes deleting prover threads in the Prover pool; adding new prover threads to the prover pool, etc.
[0086] Next, the determination methods of the target computing resources and the target storage resources will be respectively described by way of example.
[0087] CPU core:
[0088] In some examples, the CPU cores can be allocated in the following two steps:
[0089] The first step is to determine the task complexity of the target computing task according to the characteristic information of the constraint system and the target proof protocol; the second step is to determine the number of CPU cores for generating the target ZKP according to the task complexity. Among them, the task complexity is used to measure the amount of computation of the target computing task. The higher the task complexity, the greater the amount of computation; the lower the task complexity, the smaller the amount of computation. The number of CPU cores allocated to the target computing task is positively correlated with the task complexity of the target computing task. That is, the higher the task complexity, the more CPU cores are allocated to the target computing task; conversely, the lower the task complexity, the fewer CPU cores are allocated to the target computing task.
[0090] Optionally, in the first step, the characteristic information of the constraint system includes at least one of the following information: the scale of the constraint system, the bit width of the elliptic curve, the type of hash function, and the type of polynomial commitment. These information have a greater impact on the overall amount of computation of the target computing task. Therefore, these information are used to measure the task complexity of the target computing task.
[0091] Among them, the scale of the constraint system can be represented by the number of circuit gates included in the constraint system. For example, a constraint system includes \(2^{23}\) circuit gates. The more the number of circuit gates, the larger the scale of the constraint system; the fewer the number of circuit gates, the smaller the scale of the constraint system. The scale of the constraint system is positively correlated with the task complexity, that is, the larger the scale of the constraint system, the higher the task complexity; and the smaller the scale of the constraint system, the lower the task complexity.
[0092] The bit width of the elliptic curve corresponds to the type of the elliptic curve, and the bit width corresponding to each type of elliptic curve is fixed. For example, the bit width of BN254 is 254 bits, and the bit width of BLS12-381 is 381 bits. The bit width of the elliptic curve is positively correlated with the task complexity, that is, the larger the bit width of the elliptic curve, the higher the task complexity; and the smaller the bit width of the elliptic curve, the lower the task complexity.
[0093] The scale of the gate circuit corresponding to each hash function after being converted into a circuit is different. For example, it may include different numbers of multiplication gates. The more multiplication gates, the higher the computational complexity, that is, the higher the task complexity. Exemplarily, taking the common Poseidon and SHA256 as an example, the computational complexity of Poseidon for zero-knowledge proof is lower than that of SHA256.
[0094] The types of polynomial commitments are different, and the computational complexity in the ZKP generation process is also different. The higher the computational complexity, the longer the time to generate the proof. Therefore, by testing the time to generate the proof corresponding to different polynomial commitments, the influence degree of different types of polynomial commitments on the computational complexity can be determined. For example, the time to generate the proof for KZG, IPA, and DARK is a constant, while the time to generate the proof for FRI increases exponentially with the degree of the polynomial. Therefore, the task complexity corresponding to KZG, IPA, and DARK is lower than that corresponding to FRI.
[0095] In addition to the characteristic information of the constraint system, the following reference information may affect the amount of computation per unit time of the target computing task. For example, user level, number of concurrent processes, size of the generated proof, expected response time for generating the proof, etc. Among them, the user level is used to indicate the level of the initiator of the proof generation request. The higher the user level, the more rights the user has to obtain computing resources preferentially to ensure the reliability and stability of the service, etc.; the number of concurrent processes is used to indicate the number of other proof generation requests that coexist with the proof generation request. If the number of concurrent processes is too large, it means that the amount of resources that can be allocated to each user may be limited; the larger the proof size, the higher the security level of the generated proof that the user desires; the shorter the expected response time for generating the proof, the faster the user hopes to obtain the ZKP proof. Therefore, these information can also be combined to determine the task complexity.
[0096] If the task complexity needs to be calculated based on the reference information, the method further includes obtaining the reference information. Among them, the user level, size of the generated proof, and expected response time for generating the proof can be carried in the proof generation request; the number of concurrent processes can be obtained by statistical analysis of the management platform.
[0097] In implementation, a task complexity calculation model can be established and stored in advance. The task complexity is calculated using this calculation model. The input of this calculation model is one or more of the aforementioned information, which can be selected as needed.
[0098] In some examples, the task complexity is calculated based on the following information:
[0099] Number of concurrent processes (or the number of concurrent requesting users): N
[0100] The parameters for each user are as follows:
[0101] Circuit scale constraint: C 0 , C 1 , …, C N-1
[0102] ZKP protocol type: P 0 , P 1 , …, P N-1
[0103] User level: R 0 , R 1 , …, R N-1
[0104] F i= f(C i , P i , R i ), o ∈ {0, N - 1}
[0105] Among them, f(C i , P i , R i ) is the aforementioned computing model.
[0106] In some other examples, the task complexity is calculated based on the following information:
[0107] Number of concurrent processes (or the number of concurrent requesting users): N;
[0108] The parameters for each user are as follows:
[0109] Circuit scale constraint: C 0 , C 1 , …, C N-1
[0110] ZKP protocol type: P 0 , P 1 , P 2 …
[0111] Hash function type: H 0 , H 1 , H 2 , …
[0112] Polynomial commitment type: PC 0 , PC 1 , PC 2 , …
[0113] Elliptic curve: EC 0 , EC 1 , EC 2 , …
[0114] Proof size: S 0 , S 1 , S 2 …
[0115] User level: R 0 , R 1 , …, R N-1
[0116] Expected response time range: T 0 , T 1 , …, T N-1
[0117] F i= f(C i , P i , H i , PC i , EC i , S i , R i , T i ), i ∈ {0, N - 1}
[0118] Among them, f(C i , P i , H i , PC i , EC i , S i , R i , T i ) is the aforementioned computing model.
[0119] Optionally, in this second step, according to the task complexity, for each operator associated with the target proof protocol, determine the target number of processor cores from multiple computing resources, and the target number is positively correlated with the task complexity.
[0120] In the embodiments of the present application, each ZKP protocol is associated with one or more operators, that is, in the process of generating a proof for each ZKP protocol, one or more operator operations need to be performed. The association relationship between various proof protocols and operator types can be preset. For example, halo2, groth 16, and plonk all correspond to two operator operations of MSM and NTT / INTT, while supernova corresponds to one operator operation of NTT / INTT. Since the number of processor cores corresponds to the number of worker threads, therefore, determining the target number of processor cores for each determined operator operation is equivalent to allocating the target number of worker threads to each operator. For ZKP protocols that require multiple operator operations, the total operator operation amount can be determined first according to the task complexity; then, combined with the proportion of the operation amount of each operator operation in the total operator operation amount, determine the number of CPU cores corresponding to each operator. For example, the plonk protocol corresponds to two operator operations of MSM and NTT / INTT, then first determine the total operator operation amount according to the task complexity, and then determine the number of CPU cores corresponding to each operator according to the proportion of the operation amount of each operator operation in the total operator operation amount. Here, for any protocol type, the proportion of the operation amount of each operator operation in the total operator operation amount is preset.
[0121] In one possible implementation, the concurrent computing tasks can be sorted according to F i , and then computing resources are allocated according to F i . For example, the computing resources are allocated to each computing task in descending order according to F i .
[0122] It should be noted that in addition to the task complexity, factors such as the number of idle resources in the computing resource pool can also be combined to allocate computing resources to the target computing tasks.
[0123] Storage resources:
[0124] Determine the target storage resource according to at least one of the number of circuit gates in the constraint system (i.e., the scale of the constraint system), the size of the Lookup Table used in the polynomial commitment scheme, the bit width of the elliptic curve, and the algorithm of the computing operator.
[0125] For example, first determine the amount of computed data according to at least one of the scale of the constraint system, the size of the Lookup Table used in the polynomial commitment scheme, the bit width of the elliptic curve, and the algorithm of the computing operator; then determine the storage resource of the target size, and the target size is positively correlated with the amount of computed data.
[0126] Among them, the number of circuit gates is positively correlated with the amount of allocated memory, that is, the more the number of circuit gates, the larger the size of the storage space to be used; while the fewer the number of circuit gates, the smaller the size of the storage space to be used.
[0127] A Lookup Table is a data structure that stores the mapping relationship between inputs and outputs. In the Lookup Table, the inputs and outputs respectively correspond to the secret inputs to be hidden and the public inputs to be proved in the zero-knowledge proof. The inputs and outputs can be of any data type, such as numbers, strings, or other complex objects, etc. In the Lookup Table, each input corresponds to one output, so that the corresponding output value can be quickly found according to the given input value. The mapping relationship between the input and the output can come from pre-computation or complex functions, etc. By pre-computing and storing the complex calculation or function mapping in the Lookup Table as the proof of the validity of the statement in the proof, the efficiency of proof generation can be improved. The larger the size of the Lookup Table, the larger the amount of data to be stored, and correspondingly, the larger the storage space to be used; while the smaller the size of the Lookup Table, the smaller the amount of data to be stored, and correspondingly, the smaller the storage space to be used.
[0128] The larger the bit width of the elliptic curve, the larger the amount of data to be stored, and correspondingly, the larger the storage space to be used; while the smaller the bit width of the elliptic curve, the smaller the amount of data to be stored, and correspondingly, the smaller the storage space to be used.
[0129] Each operator operation can use different algorithms (i.e., calculation methods) to calculate the operator. For the same operator, different algorithms are used, and the amount of intermediate data generated may be different. Therefore, the size of the storage resource can be determined according to the algorithm of the computing operator.
[0130] During the process of generating ZKP, a large amount of data needs to be stored, and the above information is closely related to the amount of data to be stored during the process of generating ZKP. Therefore, the target storage resource can be determined according to this information.
[0131] Optionally, if the configuration parameters further include second - type parameters, and the second - type parameters further include proof index information, before step 13, the method further includes: obtaining a historical ZKP according to the proof index information. Exemplarily, the proof index information is used to indicate the generated historical ZKP, for example, it can be the ID of the historical ZKP.
[0132] In some examples, the historical ZKP and the corresponding proof index information can be stored in the cloud (such as in a cloud server). Then obtaining the historical ZKP according to the proof index information includes: obtaining the historical ZKP from the cloud.
[0133] It can be seen that the method provided by the embodiments of the present application supports users to use cloud - stored data (such as historical proof files and other data files, etc.) as input to generate zero - knowledge proofs, and cost - effectively adapts to business scenarios of web3 distributed storage such as the interplanetary file system (IPFS).
[0134] 14: Generate a target ZKP through the target computing resource.
[0135] If the historical ZKP has been obtained according to the proof index information, in step 14, it is necessary to generate the target ZKP based on the historical ZKP through the target computing resource. It can be seen that in the embodiments of the present application, the prover thread supports first - level or multi - level recursive zero - knowledge proof generation, and can store the intermediate proof (i.e., the aforementioned historical ZKP) in cloud storage and use it through the proof index information.
[0136] After generating the target ZKP, the target ZKP can be returned to the user. When returning the target ZKP to the user, the proof index information corresponding to the target ZKP can also be returned.
[0137] Optionally, if the mode information in the aforementioned second - type parameters indicates that the ZKP mode is a recursive mode, the method further includes: storing the generated target ZKP and the corresponding index information, for example, storing the generated target ZKP and the corresponding index information in the cloud for being called in the subsequent process of generating ZKPs, that is, for recursive proof.
[0138] In the embodiments of the present application, both the generated target ZKP and the historical ZKP can refer to proof information, and the proof information can be in any form, such as numbers, etc.
[0139] Figure 3 It is the component architecture diagram of a proof generation device provided by the embodiments of the present application. As Figure 3 shown, the device includes a verifier, an adapter, a scheduler, a prover pool, and a worker pool (i.e., a multi - core CPU pool). Figure 4It is a detailed process diagram of a proof generation method provided by an embodiment of the present application. In combination with Figure 3 and Figure 4 , the verifier is used to implement the verification of at least one of the circuit file and the first type of parameters according to the proof protocol information. The adapter is used to generate a constraint system corresponding to the target proof protocol, that is, to execute step 12. That is to say, through the pre-verifier and the adapter, parameter verification, circuit and backend protocol matching verification, and corresponding adaptation work are completed. The adapter will perform different arithmetizations and constraint generations on the input circuit according to the protocol type. The scheduler is used to execute step 13.
[0140] It can be seen that the embodiment of the present application implements zero-knowledge proofs supporting multiple protocols and multiple modes based on the API method, and the service does not need to worry about computing resources. In addition, based on multi-core CPUs (even many-core CPUs), an NTT and MSM operator worker pool is implemented to shield protocol changes and support the generation of multiple protocol proofs in parallel. Moreover, the embodiment of the present application can also be equipped with a cloud storage module to support the query, download, and recursive proof generation of proofs, support an unlimited recursive proof mode, and generate zero-knowledge proofs based on multiple stored proofs to further compress the proof size.
[0141] The embodiment of the present application is particularly applicable to the following two scenarios:
[0142] 1. It can be widely applied in the Web3 layer2 zkrollup scenario, and is provided to components and roles with computing requirements for zero-knowledge proofs, such as zero-knowledge virtual machines (zkVMs) and zk provers, in the form of an interface through cloud services to complete fast proof generation adapting to multiple protocols.
[0143] 2. It can be applicable to the web3 distributed storage scenario to help project parties complete the relocation of the Internet data center (IDC) to the cloud, and deploy encapsulation, proof generation, and storage on the cloud. The generation of storage proofs is completed based on the method of interface call.
[0144] Of course, in addition to these two scenarios, it can also be applicable to any scenario with computing and accelerated computing requirements for zero-knowledge proofs.
[0145] In summary, the embodiment of the present application proposes a proof generation method supporting multiple protocols. Users can focus only on the business without paying attention to the zero-knowledge protocol itself, and can complete adaptation and switching relatively quickly when the protocol changes or when they hope to use a more advanced or more efficient protocol. Moreover, users do not need to worry about the large consumption of resources by ZKP computing and performance problems such as slow computing.
[0146] The embodiment of the present application also provides a ZKP generation device, Figure 5It is a schematic structural diagram of a ZKP generation device provided by an embodiment of the present application. This device is applied to the aforementioned management platform. As Figure 5 shown, the device 400 includes: a receiving module 401, a determining module 402, and a generating module 403. The receiving module 401 is configured to receive a proof generation request, where the proof generation request includes proof protocol information and a circuit file. Among them, the proof protocol information is used to indicate the target proof protocol used to generate the target zero-knowledge proof, and the target proof protocol is one of the multiple protocol types. The circuit file is used to indicate the calculation model for generating the target zero-knowledge proof; the determining module 402 is configured to determine a target computing resource from the multiple computing resources according to the proof generation request; the generating module 403 is configured to generate a target ZKP through the target computing resource.
[0147] Optionally, the determining module 402 includes: a system generation sub-module and a determining sub-module. The system generation sub-module is configured to generate a constraint system corresponding to the target proof protocol based on the circuit file and the configuration parameters; the determining sub-module is configured to determine a target computing resource from the multiple computing resources according to the target proof protocol and the characteristic information of the constraint system. The characteristic information of the constraint system includes at least one of the following information: the scale of the constraint system, the bit width of the elliptic curve, the type of the hash function, and the type of the polynomial commitment.
[0148] Optionally, the determining sub-module is configured to determine the task complexity according to the target proof protocol and the characteristic information of the constraint system; and determine the target computing resource from the multiple computing resources according to the task complexity.
[0149] Optionally, the device further includes: an obtaining module, configured to obtain reference information, where the reference information includes at least one of a user level, the number of concurrent processes, the size of the generated proof, and the expected response time for generating the proof. The user level is used to indicate the level of the initiator of the proof generation request, and the number of concurrent processes is used to indicate the number of other proof generation requests that coexist with the proof generation request; the determining sub-module is configured to determine the task complexity according to the target proof protocol, the characteristic information of the constraint system, and the reference information.
[0150] Optionally, each computing resource includes a worker thread, and the worker thread is configured to run an operator. The target proof protocol is associated with at least one operator. The determining sub-module is configured to determine a target number of worker threads for each operator associated with the target proof protocol from the multiple computing resources according to the task complexity, and the target number is positively correlated with the task complexity.
[0151] Optionally, the infrastructure further includes a plurality of storage resources, and the apparatus further includes: a second determination module, configured to determine a target storage resource from the plurality of storage resources according to at least one of the scale of the constraint system, the size of the lookup table used in the polynomial commitment scheme, the bit width of the elliptic curve, and the algorithm of the computing operator.
[0152] Optionally, the proof generation request further includes a first type of parameter for converting the circuit file into a quadratic arithmetic program (QAP); the apparatus further includes: a verification module 404, configured to verify the circuit file and / or the first type of parameter according to the proof protocol information after receiving the proof generation request.
[0153] Optionally, the task information further includes mode information for indicating that the mode of the target ZKP is a recursive mode. The generation module 403 includes: an acquisition sub-module, configured to acquire a historical zero-knowledge proof; and a proof generation sub-module, configured to generate the target zero-knowledge proof based on the historical zero-knowledge proof by using the computing resources.
[0154] The system generation sub-module is used to implement Figure 3 and Figure 4 the functions of the adapter in Figure 3 and Figure 4 the functions of the scheduler in Figure 3 and Figure 4 the functions of the verifier in
[0155] Among them, the acquisition module, the determination module, and the generation module can all be implemented by software or can be implemented by hardware. Exemplarily, next, taking the acquisition module as an example, the implementation manner of the acquisition module is introduced. Similarly, the implementation manners of the determination module and the generation module can refer to the implementation manner of the acquisition module.
[0156] As an example of a software functional unit, the acquisition module may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance may be one or more. For example, the acquisition module may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running the code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers for running the code may be distributed in the same availability zone (AZ) or in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Usually, one region may include multiple AZs.
[0157] Similarly, the multiple hosts / virtual machines / containers for running the code may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is achieved through the communication gateway.
[0158] As an example of a hardware functional unit, the acquisition module may include at least one computing device, such as a server. Alternatively, the acquisition module may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0159] The multiple computing devices included in the acquisition module may be distributed in the same region or in different regions. The multiple computing devices included in the acquisition module may be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the acquisition module may be distributed in the same VPC or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0160] It should be noted that in other embodiments, the acquisition module may be used to execute any step in the ZKP generation method, the determination module may be used to execute any step in the ZKP generation method, and the generation module may be used to execute any step in the ZKP generation method. The steps implemented by the acquisition module, the determination module, and the generation module can be specified as needed. The entire function of the ZKP generation device is realized by respectively implementing different steps in the ZKP generation method through the acquisition module, the determination module, and the generation module.
[0161] The descriptions of the processes corresponding to the above respective drawings have their own emphases. For parts not detailed in a certain process, reference can be made to the relevant descriptions of other processes.
[0162] This application also provides a computing device 100. As Figure 6 shown, the computing device 100 includes: a bus 102, a processor 104, a memory 106, and a communication interface 108. The processor 104, the memory 106, and the communication interface 108 communicate with each other through the bus 102. The computing device 100 may be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 100.
[0163] The bus 102 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 5 only one line is shown herein, but it does not mean that there is only one bus or one type of bus. The bus 104 may include a path for transmitting information between various components (such as the memory 106, the processor 104, and the communication interface 108) of the computing device 100.
[0164] The processor 104 may include any one or more of processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0165] The memory 106 may include a volatile memory, such as a random access memory (RAM). The processor 104 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0166] The memory 106 stores executable program codes, and the processor 104 executes the executable program codes to respectively implement the functions of the foregoing obtaining module, determining module, and generating module, thereby implementing the ZKP generation method. That is to say, the memory 106 stores instructions for executing the ZKP generation method.
[0167] The communication interface 103 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 100 and other devices or communication networks.
[0168] The embodiment of the present application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device may be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device may also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.
[0169] As Figure 7 shown, the computing device cluster includes at least one computing device 100. The memory 106 in one or more computing devices 100 in the computing device cluster may store the same instructions for executing the ZKP generation method.
[0170] In some possible implementation manners, the memory 106 of one or more computing devices 100 in the computing device cluster may also respectively store partial instructions for executing the ZKP generation method. In other words, a combination of one or more computing devices 100 may jointly execute the instructions for executing the ZKP generation method.
[0171] It should be noted that the memories 106 in different computing devices 100 in the computing device cluster can store different instructions, which are respectively used to execute some functions of the ZKP generation device. That is, the instructions stored in the memories 106 in different computing devices 100 can implement the functions of one or more of the acquisition module, the determination module, and the generation module.
[0172] In some possible implementation manners, one or more computing devices in the computing device cluster can be connected through a network. Among them, the network can be a wide area network or a local area network, etc. Figure 8 A possible implementation manner is shown. As Figure 8 shown, two computing devices 100A and 100B are connected through a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this type of possible implementation manner, the memory 106 in the computing device 100A stores instructions for executing the function of the acquisition module. At the same time, the memory 106 in the computing device 100B stores instructions for executing the functions of the determination module and the generation module.
[0173] Figure 8 The connection manner between the computing device clusters shown can be considered that since the ZKP generation method provided in this application needs to uniformly manage computing resources, it is considered to hand over the functions implemented by the determination module and the generation module to the computing device 100B for execution.
[0174] It should be understood that Figure 8 the functions of the computing device 100A shown in
[0175] can also be completed by multiple computing devices 100. Similarly, the functions of the computing device 100B can also be completed by multiple computing devices 100.
[0176] An embodiment of this application also provides a computer program product containing instructions. The computer program product can be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute the foregoing ZKP generation method.
[0177] In the embodiments of the present application, A and / or B represent three cases: A, B, and A and B.
[0178] The above description is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should be covered within the protection scope of the present application.
Claims
1. A method for generating a zero-knowledge proof, characterized in that: The method is applied to a management platform, the management platform is used to manage infrastructure, the infrastructure includes multiple computing resources, each of the multiple computing resources is used to generate zero-knowledge proofs corresponding to multiple proof protocols, and the method includes: Receive a proof generation request, the proof generation request including proof protocol information and a circuit file, wherein the proof protocol information is used to indicate a target proof protocol used to generate a target zero-knowledge proof, the target proof protocol is one of the multiple proof protocols, and the circuit file is used to indicate a computational model for generating a target zero-knowledge proof; Determining a target computing resource from the plurality of computing resources according to the proof generation request; The target zero-knowledge proof is generated through the target computing resources.
2. The method according to claim 1, characterized in that The proof generation request further includes configuration parameters, and determining the target computing resource from the plurality of computing resources according to the proof generation request includes: generating a constraint system corresponding to the target certification protocol according to the circuit file and the configuration parameters; A target computing resource is determined from the multiple computing resources according to the target proof protocol and characteristic information of the constraint system, wherein the characteristic information of the constraint system includes at least one of the following information: the scale of the constraint system, the bit width of the elliptic curve, the type of hash function, and the type of polynomial commitment.
3. The method according to claim 2, characterized in that The step of determining a target computing resource from the plurality of computing resources according to the target certification protocol and the characteristic information of the constraint system includes: Determining task complexity according to the target certification protocol and characteristic information of the constraint system; The target computing resource is determined from the multiple computing resources according to the task complexity.
4. The method according to claim 3, characterized in that: The method further includes: acquiring reference information, the reference information including at least one of a user level, a concurrent processing number, a size of a generated certificate, and an expected response time for generating a certificate, the user level being used to indicate a level of an initiator of the certificate generation request, and the concurrent processing number being used to indicate a number of other certificate generation requests existing simultaneously with the certificate generation request; The determining the task complexity according to the target certification protocol and the characteristic information of the constraint system includes: The task complexity is determined according to the target certification protocol, the characteristic information of the constraint system and the reference information.
5. The method according to claim 3 or 4, characterized in that: Each computing resource includes a worker thread, the worker thread is used to run an operator, the target certification protocol is associated with at least one operator, The step of determining the target computing resource from the plurality of computing resources according to the task complexity includes: According to the task complexity, a target number of worker threads is determined for each operator associated with the target proof protocol from the multiple computing resources, and the target number is positively correlated with the task complexity.
6. The method according to any one of claims 2 to 5, characterized in that: The infrastructure also includes a plurality of storage resources, The method further comprises: A target storage resource is determined from the plurality of storage resources based on at least one of a scale of the constraint system, a size of a lookup table used in a polynomial commitment scheme, a bit width of an elliptic curve, and an algorithm of a computation operator.
7. The method according to any one of claims 1 to 6, characterized in that: The proof generation request further includes first type parameters, wherein the first type parameters are used to convert the circuit file into a quadratic arithmetic program QAP; After receiving the certificate generation request, the method further includes: The circuit file and / or the first type of parameters are verified according to the certification protocol information.
8. The method according to any one of claims 1 to 7, characterized in that: The proof generation request further includes mode information, where the mode information is used to indicate that the mode of the target zero-knowledge proof is a recursive mode; The generating the target zero-knowledge proof by using the target computing resource includes: Obtain historical zero-knowledge proof; The target zero-knowledge proof is generated through the target computing resources based on the historical zero-knowledge proof.
9. A zero-knowledge proof generating device, characterized in that: The device is applied to a management platform, the management platform is used to manage infrastructure, the infrastructure includes multiple computing resources, each of the multiple computing resources is used to generate zero-knowledge proofs corresponding to multiple proof protocols, and the device includes: A receiving module, configured to receive a proof generation request, wherein the proof generation request includes proof protocol information and a circuit file, wherein the proof protocol information is used to indicate a target proof protocol used to generate a target zero-knowledge proof, the target proof protocol being one of the multiple proof protocols, and the circuit file is used to indicate a computational model for generating a target zero-knowledge proof; a determination module, configured to determine a target computing resource from the plurality of computing resources according to the proof generation request; A generation module is used to generate the target zero-knowledge proof through the target computing resources.
10. The device according to claim 9, characterized in that The certificate generation request also includes configuration parameters, and the determination module includes: A system generation submodule, used for the circuit file and the configuration parameters to generate a constraint system corresponding to the target certification protocol; A determination submodule is used to determine a target computing resource from the multiple computing resources based on the target proof protocol and characteristic information of the constraint system, wherein the characteristic information of the constraint system includes at least one of the following information: the scale of the constraint system, the bit width of the elliptic curve, the type of hash function, and the type of polynomial commitment.
11. The device according to claim 10, characterized in that The determination submodule is used to determine the task complexity according to the target certification protocol and the characteristic information of the constraint system; and determine the target computing resource from the multiple computing resources according to the task complexity.
12. The device according to claim 11, characterized in that The device also includes: an acquisition module, configured to acquire reference information, the reference information including at least one of a user level, a concurrent processing number, a size of a generated certificate, and an expected response time for generating a certificate, the user level being used to indicate a level of an initiator of the certificate generation request, and the concurrent processing number being used to indicate a number of other certificate generation requests existing simultaneously with the certificate generation request; The determination submodule is used to determine the task complexity according to the target certification protocol, the characteristic information of the constraint system, and the reference information.
13. The device according to claim 11 or 12, characterized in that Each computing resource includes a worker thread, the worker thread is used to run an operator, the target certification protocol is associated with at least one operator, The determination submodule is used to determine a target number of worker threads for each operator associated with the target proof protocol from the multiple computing resources according to the task complexity, and the target number is positively correlated with the task complexity.
14. The device according to any one of claims 10 to 13, characterized in that The infrastructure also includes multiple storage resources, and the device also includes: a second determination module, used to determine the target storage resource from the multiple storage resources based on at least one of the scale of the constraint system, the size of the lookup table used in the polynomial commitment scheme, the bit width of the elliptic curve, and the algorithm of the calculation operator.
15. The device according to any one of claims 9 to 14, characterized in that The proof generation request further includes first type parameters, wherein the first type parameters are used to convert the circuit file into a quadratic arithmetic program QAP; The device further includes: a verification module, configured to verify the circuit file and / or the first type of parameters according to the certification protocol information after receiving the certification generation request.
16. The device according to any one of claims 9 to 15, characterized in that The proof generation request further includes mode information, where the mode information is used to indicate that the mode of the target zero-knowledge proof is a recursive mode; The generating module comprises: Get submodule, used to get historical zero-knowledge proof; The proof generation submodule is used to use the computing resources to generate the target zero-knowledge proof based on the historical zero-knowledge proof.
17. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the zero-knowledge proof generation method as described in any one of claims 1 to 8.
18. A computer-readable storage medium, characterized in that: The computer storage medium stores at least one instruction, and the at least one instruction is loaded and executed by a computing device cluster so that the computing device cluster implements the zero-knowledge proof generation method as described in any one of claims 1 to 8.
19. A computer program product, characterized in that The computer program product includes: a computer program code, which is loaded and executed by a computing device cluster so that the computing device cluster implements the zero-knowledge proof generation method according to any one of claims 1 to 8.
Citation Information
Cited By
Multi-node multi-factor security authentication method and system
CN120415752A
Zero-knowledge proof generation method and apparatus, and device and storage medium
EP4797611A1
Zero-knowledge proof generation method and apparatus, and device and storage medium
WO2025102696A1