Decentralized zero-knowledge educational background authentication method and readable medium
Through the decentralized zero-knowledge academic qualification certification method, blockchain and zero-knowledge proof technology, the problems of insufficient privacy protection, poor scalability and complex operations in the existing technology are solved, and efficient, safe and transparent certificate authentication and management are achieved.
Patent Information
- Application Number
- CN202510111345.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-23
AI Technical Summary
The existing technology has problems such as insufficient privacy protection, poor scalability and complex operation in academic qualification certification, resulting in low certification efficiency, high cost, high privacy leakage risks, lack of transparency and decentralized management problems.
The decentralized zero-knowledge academic qualification certification method is adopted. By determining the security parameters and disclosure parameters selected by the system builder, the certificate issuing authority processes and stores the certificate information of the target group, and distributes the certificate to users, supporting the revocation and batch verification of certificates, and using blockchain and zero-knowledge proof technology to ensure privacy protection and data transparency.
It greatly reduces the cost of document management, eliminates false certificates, supports the authorization open revocation mechanism, realizes the efficiency of batch verification and the simplicity of operation, and has good privacy protection and scalability.
Smart Images

Figure CN120030055A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computers, and in particular to a method and readable medium for decentralized zero-knowledge academic certification. Background Art
[0002] The current academic qualifications and degree certification mainly rely on traditional centralized institutions, such as universities, the Ministry of Education, and certification service providers. These institutions are responsible for storing and verifying academic qualifications information. However, these methods have the following problems and defects: 1) Inefficiency: The traditional certification process is cumbersome, requires cooperation from multiple parties, and takes a lot of time; 2) High cost: Certification requires manual review, document processing, and mailing, which increases costs; 3) Privacy leakage risk: Centralized storage is easy to become a target of attack, and users' sensitive information (such as transcripts, degree certificates) may be leaked; 4) Lack of transparency: Applicants cannot obtain verification status immediately, and the opacity of storage institutions may cause trust issues; 5) Decentralized management: The management and verification of various certificates usually requires relying on independent institutions for filing and storage.
[0003] In recent years, blockchain technology has been proposed to store and verify academic data, but most of them have problems such as insufficient privacy protection, poor scalability, and complex operation. For example, storing data directly on the chain is prone to exposing personal information, and using complex smart contracts may increase processing costs. Existing blockchain solutions lack efficient privacy protection mechanisms, which limits their application in the field of academic certification.
[0004] Blockcerts is an open source standard that records and verifies academic certificates through blockchain. It has the advantages of being tamper-proof and easy to share. However, Blockcerts does not provide sufficient privacy protection mechanisms, for example, sensitive information (such as grades) may be made public. In addition, the system requires high technical capabilities, which is difficult for small institutions to implement, and its scalability has not been fully verified for cross-border certification scenarios.
[0005] IEEE's academic verification system enhances the security and transparency of the traditional centralized certification system by decentralizing the recording of certification information through blockchain. This approach avoids single point failure problems and improves verification efficiency. However, the system is not good at dynamic management of certificates, such as lack of flexibility when certificates need to be updated or revoked. In addition, its privacy protection capabilities are weak, it fails to meet the requirements of international privacy laws (such as GDPR), and has limitations in supporting complex transcripts and multidisciplinary data.
[0006] IBM's blockchain credential management system provides an enterprise-level solution with a focus on scalability and privacy protection, suitable for large-scale education and professional certification scenarios. The system supports cooperation and integration between institutions and demonstrates strong industrial application value. However, due to its reliance on IBM's technology stack, its flexibility is limited, and its high cost may pose an obstacle to small and medium-sized educational institutions. In addition, the trade-off between privacy protection and user experience still needs further improvement.
[0007] These existing technologies are groundbreaking in improving the efficiency and security of academic certification, but they are insufficient in key aspects such as privacy protection, dynamic management, scalability and cost. These issues provide clear directions for further innovation, such as introducing zero-knowledge proof technology to enhance privacy protection, designing dynamic management functions that support certificate renewal and revocation, and developing a low-cost and easy-to-deploy system architecture. Summary of the invention
[0008] One purpose of this application is to provide a decentralized zero-knowledge academic qualification authentication method and a readable medium to solve the problems of insufficient privacy protection, poor scalability and complex operation in the authentication method of the prior art.
[0009] According to one aspect of the present application, a method for decentralized zero-knowledge academic certification is provided, the method comprising:
[0010] Determine the security parameters selected by the system builder and determine all used fields and target groups selected to meet the specified requirements to construct public parameters;
[0011] Determine the target group through the certificate issuing authority, process and store the certificate information of the target group according to the public parameters, and distribute the certificate to each user in the target group;
[0012] According to the request for revocation submitted by the certificate issuing authority, a message is posted on the chain to generate a certificate revocation form;
[0013] Merge and generate proof for each user's experience based on the document verification requirements;
[0014] When the user's certificate information is received, the combined proof is authenticated through the authentication contract, and the authenticity of the certificate information is returned.
[0015] Optionally, construct public parameters, including:
[0016] All used fields that meet the specified requirements are input into the program to execute the zero-knowledge proof system parameter generation algorithm, and the generated parameters are made public to obtain public parameters, wherein the public parameters include prime order fields, groups, proof parameters, verification keys, hash functions and generators.
[0017] Optionally, the document information of the target group is processed and stored according to the public parameters, including:
[0018] Classify the graduation information of all users in the target group according to the information category to obtain m data sets, wherein the certificate information is determined by the user's graduation information;
[0019] Select a target random number that is common to all data sets, process each user's data set separately, and use a polynomial to compress each user's graduation information on the target random number to obtain a compressed data set;
[0020] Determine a target polynomial through an interpolation operation, and generate a corresponding commitment according to the target polynomial, wherein each term in the target polynomial is determined by the compressed data set;
[0021] The commitments corresponding to the m data sets are written into the blocks in the blockchain for storage, where the commitments contain all the user's information.
[0022] Optionally, distribute the certificate to each user in the target group, including:
[0023] Calling the opening algorithm of the target polynomial commitment, and sequentially calculating the proof and evaluation values of all certificates related to the applicant user to be applied for the certificate;
[0024] Package all certificate proofs and send the certificate information and application user number to the applicant.
[0025] Optionally, a message is posted on the chain based on the request for revocation submitted by the certificate issuing authority, and a certificate revocation form is generated, including:
[0026] Determine the certificate to be revoked according to the request for revocation submitted by the certificate issuing authority, sign it and publish a message on the chain, where the request for revocation includes the ID of the user to be revoked;
[0027] The superior authority of the certificate issuing authority will review it and send a signed consent message to the chain;
[0028] Add the ID and commitment of the user to be revoked corresponding to the certificate to be revoked to the certificate revocation form.
[0029] Optionally, generate a certificate for each user's experience based on the certificate verification requirements, including:
[0030] When the certificate verification requirement is the trust of the user in the verification party, each graduation information of each experience of the user is compressed to obtain a compressed information value, and the compressed information values corresponding to each experience are merged to obtain a merged compressed information value;
[0031] Generate a combined certificate based on the combined compressed information value and calculate the challenge value;
[0032] The graduation information of the target segment of experience that the user needs to disclose, the corresponding user number in each experience, and the combined certificate are provided to the verification party trusted by the user for verification.
[0033] Optionally, generate a certificate for each user's experience based on the certificate verification requirements, including:
[0034] When the certificate verification requirement is that the user does not trust the verification party, each graduation information of each experience of the user is compressed to obtain a compressed information value, and the compressed information values corresponding to each experience are merged to obtain a merged compressed information value;
[0035] Assign the certificate and information corresponding to the undisclosed graduation information in each experience a value of 0, calculate the challenge value based on the combined compressed information value and the certificate and information corresponding to the undisclosed graduation information, and generate a combined certificate based on the challenge value and the compressed information value;
[0036] A certificate is generated based on public information and private information, wherein the public information includes the public part of the graduation information, the challenge value and the combined compressed information value of each experience, and the private information includes the undisclosed information in the graduation information and the information compression value of all information.
[0037] Optionally, when receiving the user's certificate information, the combined proof is authenticated through the authentication contract, and the authenticity result of the certificate information is returned, including:
[0038] When the verifier is trusted by the user, it receives the graduation information of each experience disclosed by the user, the user number corresponding to each experience, the challenge value and the certificate;
[0039] The verifier checks whether the user number corresponding to each experience and the commitment corresponding to the public graduation information are in the certificate revocation form. If not, the verifier calculates the compressed information of each graduation information of each experience respectively, merges the compressed information, and obtains the merged compressed information value;
[0040] The challenge value is recalculated based on the combined compressed information value, and the promised batch verification scheme is called to verify the combined compressed information value and the recalculated challenge value.
[0041] Optionally, when receiving the user's certificate information, the combined proof is authenticated through the authentication contract, and the authenticity result of the certificate information is returned, including:
[0042] When the verifier is not trusted by the user, it receives the public information part of each experience disclosed by the user, the user number corresponding to each experience, the challenge value, the compressed information value of each experience, and the certificate;
[0043] The verifier checks whether the user number corresponding to each experience and the commitment corresponding to the public graduation information are in the certificate revocation form. If not, the verifier verifies the challenge value and the compressed information value of each experience;
[0044] Read the commitment of all graduation information related to the user from the blockchain block and calculate the combined commitment of each experience;
[0045] The challenge value is recalculated based on the combined compressed information value of each experience, and the promised batch verification scheme is called to verify the combined compressed information value and the recalculated challenge value.
[0046] According to another aspect of the present application, a computer-readable medium is provided, on which computer-readable instructions are stored. The computer-readable instructions can be executed by a processor to implement the method described above.
[0047] Compared with the prior art, this application determines the security parameters selected by the system builder, and determines all the fields selected to meet the specified requirements to construct public parameters; determines the target group through the certificate issuing authority, processes and stores the certificate information of the target group according to the public parameters, and distributes the certificate to each user in the target group; publishes a message on the chain according to the request for revocation submitted by the certificate issuing authority, and generates a certificate revocation form; merges and generates a certificate for each experience of the user according to the certificate verification requirements; when the user's certificate information is received, the merged certificate is authenticated through the authentication contract, and the authenticity result of the certificate information is returned. This can greatly reduce the cost of related certificate management, eliminate false certificates, support the authorized public revocation mechanism, and can perform batch verification, and is simple to operate and easy to expand. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Other features, objects and advantages of the present application will become more apparent by reading the detailed description of non-limiting embodiments made with reference to the following drawings:
[0049] Figure 1 A flowchart of a method for decentralized zero-knowledge academic qualification certification provided according to one aspect of the present application is shown.
[0050] The same or similar reference numerals in the drawings represent the same or similar components. DETAILED DESCRIPTION
[0051] The present application is described in further detail below in conjunction with the accompanying drawings.
[0052] In a typical configuration of the present application, the terminal, the device of the service network and the trusted party all include one or more processors (eg, a central processing unit (CPU)), an input / output interface, a network interface and a memory.
[0053] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0054] Computer readable media include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, Phase-Change RAM (PRAM), Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), other types of random access memory (RAM), Read-Only Memory (ROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Flash memory or other memory technology, Compact Disc Read-Only Memory (CD-ROM), Digital Versatile Disk (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. According to the definition in this article, computer-readable media does not include non-transitory media such as modulated data signals and carrier waves.
[0055] Figure 1 A schematic diagram of a method flow of decentralized zero-knowledge academic qualification certification provided according to one aspect of the present application is shown, the method comprising: steps S11 to S15, wherein:
[0056] Step S11, determine the security parameters selected by the system builder, and determine all the used fields that meet the specified requirements to construct the public parameters; here, the system builder is a trusted participant, and its main responsibility is to run a one-time initialization module to generate the public parameters of the system, such as field parameters, public hash functions, commitment scheme parameters, and ZK-SNARK algorithm parameters; the credibility of the system builder ensures the correctness and security of the public parameters, ensuring that all subsequent operations are based on the same trusted basis. In the initialization module, the system builder selects a security parameter \lambda, selects all the used fields that meet the specified requirements, and then constructs the public parameters for subsequent use.
[0057] Step S12, the target group is determined by the certificate issuing authority, the certificate information of the target group is processed and stored according to the public parameters, and the certificate is distributed to each user in the target group; here, the target group is the graduate student group, including each graduate student, and the certificate issuing authority determines the graduate student group; the certificate issuing authority is a fully trusted participant, responsible for processing graduation information for each student and generating a related academic certificate. Specifically, the certificate issuing authority calculates the academic certificate based on the student's graduation information content, and further generates a polynomial commitment of the certificate to ensure its integrity and immutability. The credibility of the certificate issuing authority makes it a key bridge between students and verifiers. The certificate issuing authority uploads the commitment information of the student's certificate to the blockchain and issues relevant certificate information to the student. Assume that the graduation information of n students needs to be processed. Each student contains m pieces of graduation-related information, such as academic information, degree information, and grade information. The certificate issuing authority needs to generate a certificate with corresponding information for each student. The certificate issuing authority uses the public parameters in step S11 to process the graduation information of each student. The certificate information is obtained based on the certificate determined by the graduation information. All students' information is compressed into a value for storage. It is not necessary to store each student's certificate information. For example, it is necessary to process the graduation information of n students. Each student contains m pieces of graduation-related information. Finally, only m pieces of information are stored. According to the m pieces of information, corresponding certificates are generated. For example, if a student has 3 pieces of graduation information, 3 corresponding graduation certificates are generated. And these stored information are distributed to the corresponding students, that is, the students are given their own graduation certificates.
[0058] Step S13, according to the request for revocation submitted by the certificate issuing authority, a message is published on the chain to generate a certificate revocation form; here, the certificate revocation procedure denies some information, which is used by the authority to withdraw the issuance of a certificate that is indeed erroneous; in the embodiment of the present application, a mechanism is provided to query invalid certificates; the revocation of certificates can also be declared invalid by an authority. In the embodiment of the present application, the declaration of a certificate as invalid requires the joint signature of the certificate issuing authority and its superior authority to constitute a revocation record and upload it to the chain. Considering that certificate revocation is a low-probability event, a unified certificate revocation form can be used for query.
[0059] Step S14, based on the certificate verification requirements, each experience of the user is combined to generate a certificate; here, the user is a student, and each experience refers to each student's school experience; the certificate owner can generate a certificate through the certificate generation program based on the information and certificate he has, and this certificate can be verified through the authentication contract. The certificate verification requirements include the requirements for the verifier to be trustworthy and the requirements for the verifier to be untrustworthy; different methods are used to combine and generate certificates for each student's school experience according to different requirements. In this way, the size of the certificate is fixed, and no matter how many graduation information needs to be verified, the student only sends one certificate.
[0060] Step S15, when the user's certificate information is received, the combined proof is authenticated through the authentication contract, and the authenticity result of the certificate information is returned. Here, the authentication contract is a smart contract running on the blockchain for verifying certificate information. The code is open source and cannot be changed. The authentication contract verifies the certificate-related information input by the user and returns the authenticity result of the certificate information. Batch verification can be achieved, and the verifier can quickly verify the authenticity of multiple certificates, improve verification efficiency, and reduce the cost of redundant verification.
[0061] In some embodiments of the present application, in step S11, all used fields that meet the specified requirements are input into the program to execute the zero-knowledge proof system parameter generation algorithm, and the generated parameters are made public to obtain public parameters, wherein the public parameters include prime order fields, target groups, proof parameters, verification keys, hash functions and generators. Here, the system builder selects a security parameter \lambda, and selects all used fields and groups (F, G_1, G_2, G_t, e, g_1, g_2, g_t) that meet the following requirements, wherein: F is a prime order field, the size of which is a superpolynomial r = \lambda^{ω(1)}; G_1, G_2, G_t is a group of size r, and e is an efficient non-degenerate pairing function e: G_1×G_2→G_t. g_1, g_2 are uniformly selected generators that satisfy e(g_1, g_2) = g_t. Then the system builder selects a random number r and calculates the parameter srs of the KZG polynomial commitment scheme = \{[1]_1,[r]_1,...,[r^n]_1,[1]_2,[r]_2...,[r^n]_2\}. Then the hash function H used in the system is selected. Subsequently, the system builder inputs the program to execute the zero-knowledge proof (ZK-SNARK) system parameter generation algorithm to generate the proof parameter pk and the verification key vk, where pk and vk are the public parameters generated by ZK-SNARK; finally, the system constructs the public parameters ((F, G_1, G_2, G_t, e, g_1, g_2, g_t), H, srs, pk, vk) for subsequent use.
[0062] It should be noted that the KZG polynomial commitment scheme refers to a polynomial commitment scheme that allows a participant (committer) to generate a commitment value C about a polynomial f(x), and allows others to verify the value of the polynomial at a specific point without revealing the content of the polynomial. Specifically, the commitment value of the KZG scheme is represented by the elements of the elliptic curve group, and the process of commitment generation and verification can be completed through the following steps: The KZG polynomial commitment scheme consists of the following four main algorithms: parameter generation, commitment generation, commitment opening, and verification.
[0063] This scheme is based on elliptic curves that satisfy bilinear pairing. Specifically, in the scheme, a prime order field F and a set of elliptic curve groups G_1, G_2, G_t are used, where G_1, G_2 and G_t are groups of size r = \lambda^{ω(1)}, and G_t is the target group, which satisfies the non-degenerate pairing function e:G_1×G_2→G_t, and is implemented by pairing operations. In this application, addition is used to represent group operations on G_1 and G_2, and the symbols [x]_1: = x·g_1 and [x]_2: = x·g_2 are defined.
[0064] Parameter generation (gen): The input is the polynomial order d, and the output is the public parameters of the commitment scheme srs = \{[1]_1, [r]_1, ..., [r^n]_1, [1]_2, [r]_2\}. Select a random number r, calculate and output srs = \{[1]_1, [r]_1, ..., [r^n]_1, [1]_2, [r]_2\}.
[0065] Commitment generation (commit): The input is the polynomial f(x) = a_0 + a_1x,…, a_nx^n and the public parameter srs, and the output is commitment C. It calculates and returns the commitment C = a_0[1]_1 + a_1[r]_1 +…+a_n[r^n]_1 corresponding to the polynomial f(x).
[0066] Commitment open: The input is the public parameter srs, the evaluation point z, and the polynomial f(x); the output is the evaluation f(z) and the open proof proof; first, the committer calculates the value f(z) of the polynomial at the evaluation point z, and then performs the following calculation h(x) = \frac{f(x)-f(z)}{xz}, and then calculates the commitment of h(x) as proof proof = commit(h(x), srs).
[0067] Commitment verification (Verify): The input is the public parameter srs, the polynomial commitment C, the open proof proof, the evaluation point z and the evaluation value f(z). The output is 0 or 1.
[0068] The verifier checks the equation e(C-[f(z)]_1,[1]_2)=e(proof,[r]_2-[z]_2). If the equation holds, it outputs 1; otherwise, it outputs 0.
[0069] In the above algorithm, the commitment, evaluation and opening proof generated by opening the unified evaluation point of multiple polynomials all satisfy additive homomorphism, that is, given polynomials f_1(x), f_2(x), the following equations are satisfied: when C_1=commit(f_1(x),srs),C_2=commit(f_2(x),srs), the following equation holds: C_1+C_2=commit(f_1(x)+f_2(x),srs); when (proof_1,f_1(z)\leftarrow open(f_1(x),z,srs),(proof_2,f_2(z)\leftarrow open(f_2(x),z,srs), the following equation holds: (proof_1+proof_2,f_1(z)+f_2(z))\leftarrow open(f_1(x)+f_2(x),z,srs); verify(C_1+C_2,proof_1+proof_2,z,f_1(z)+f_2(z),srs) holds if and only if verify(C_1,proof_1,z,f_1(z),srs) and verify(C_2,proof_2,z,f_2(z),srs) both hold.
[0070] In many application scenarios, it is necessary to verify the values y_1=f_1(β),y_2=f_2(β),…,y_k=f_k(β) of multiple polynomials f_1(x),f_2(x),…,f_k(x) at the same point β. The traditional method verifies the commitment of each polynomial and its opening proof one by one, resulting in high computational cost. This application adopts the KZG polynomial commitment scheme with additive homomorphic properties when opening the same evaluation point, introduces random linear combinations to implement batch verification technology, and optimizes the verification process.
[0071] In addition, the opening proofs generated by multiple polynomials at multiple different evaluation points can also have additive homomorphic properties by modifying the verification algorithm and parameter generation algorithm. That is, given polynomials f_1(x), f_2(x), f_1(x) is opened at z_1, the opening proof is proof_1, f_2(x) is opened at z_2, the opening proof is proof_2, and the random value \xi can be combined to perform the following verification:
[0072] e([C_{f_1}-f_1(z_1)]_1,[r-z_1]_2)\cdot e(\xi[C_{f_2}-f_2(z_2)]_1,[r-z_2]_2)\\
[0073] =e([proof_1+\xi proof_2]_1,[Z_T(r)]_2);
[0074] Where Z_T(r)=(r-z_1)(r-z_2). Therefore, at this time, the parameter generation algorithm calculates and outputs srs=\{[1]_1,[r]_1,...,[r^n]_1,[1]_2,[r]_2,...,[r^n]_2\}.
[0075] ZK-SNARK (Zero-Knowledge Succinct Non-Interactive Argument of Knowledge) is a zero-knowledge proof protocol that can prove the correctness of a calculation without disclosing private data, while ensuring the simplicity and non-interactive nature of the argument. The ZK-SNARK used in this application includes the following three algorithms: 1) System parameter generation: input security parameter λ and program C, output proof parameter pk and verification key vk; 2) Proof generation: the prover holds the proof parameter pk, public input x and private witness w, and outputs proof \pi when the relationship R(x,w)=1 is satisfied. 3) Proof verification: the verifier inputs the verification key vk, public input x and proof \pi. If the verification passes, output 1, and vice versa.
[0076] In some embodiments of the present application, in step S12, the graduation information of all users in the target group is classified according to the information category to obtain m data sets, wherein the certificate information is determined by the graduation information of the user; a target random number common to all data sets is selected, and the data set of each user is processed separately, and the graduation information of each user is compressed on the target random number using a polynomial to obtain a compressed data set; the target polynomial is determined by an interpolation operation, and a corresponding commitment is generated according to the target polynomial, wherein each term in the target polynomial is determined by the compressed data set; the commitment corresponding to the m data sets is written into a block in the blockchain for storage, wherein the commitment contains all the information of the user. Here, it is assumed that the graduation information of n students needs to be processed. Each student contains m pieces of graduation-related information, such as academic information, degree information, and grade information. The certificate authority needs to generate a certificate for each student with the corresponding information. In order to simplify the data management and certificate generation process, the certificate authority classifies the graduation information of all students according to the information category to form m data sets, which are respectively recorded as \bm{M_1M_2,...,M_m}. When processing certificate information, the following steps are performed: Step 1. The certificate issuing authority selects and publishes a random number \alpha that is common to all data sets. This random number \alpha is used as a public parameter for subsequent processing and calculation, and is shared by all data sets during the entire certificate generation process. Step 2. The certificate issuing authority processes each graduation information data set \bm{M_i=\{m_{i1},...,m_{in}\}} separately, and uses a polynomial to compress a vector into a value. Specifically, each item of the data \bm{m_{ij}} is used as a polynomial coefficient to construct a corresponding polynomial, and the polynomial value g_{ij}(\alpha) is calculated, where \alpha is a public random number. Note that if \bm{m_{ij}} contains at least two data items, the certificate issuing authority obtains the compressed data set \bm{M_i'}=\{g_{i1}(\alpha),......,g_{in}(\alpha)\} of the data set \bm{M_i}, that is, the information of each student is compressed into a value at point \alpha.Step 3. The certificate issuing authority determines a unique polynomial f_i(x) less than order n through interpolation operation. The polynomial is generated through the following interpolation points: f_i(x) = Interpolate((1,g_{i1}(\alpha)),......,(n,g_{in}(\alpha))); The certificate issuing authority interpolates \{(1,g_{i1}(\alpha)),......,(n,g_{in}(\alpha))\} to determine a unique polynomial f_i(x) less than order n, and calls KZG.commit(f_i(x),srs) to generate the corresponding commitment C_{f_i}. To facilitate subsequent verification, all information of any student j is at the same point of the polynomial, i.e., f_1(j),...,f_m(j), and j is called the student number. Subsequently, the certificate is stored, and the certificate issuing authority writes the corresponding commitments (C_{f_1}, C_{f_2}....., C_{f_m}) of the m graduation information data sets into the block of the blockchain for storage. These m commitments contain all the information of all students. The cost of related certificate management is greatly reduced, and the certificate commitment information is stored in the public blockchain network, avoiding dependence on multiple traditional institutions. The certificate information is stored for a long time at almost zero cost. The anti-tampering characteristics of the blockchain can effectively prevent the forgery and tampering of fake certificates.
[0077] In some embodiments of the present application, in step S12, the target polynomial commitment opening algorithm is called to sequentially calculate the proofs and evaluation values of all certificates related to the applicant user to be applied for the certificate; the proofs of all certificates are packaged, and the certificate information and the applicant user number are sent to the applicant user. Here, the certificate issuing authority is responsible for generating corresponding certificates for all students and distributing the generated certificates to each student. The specific steps for the certificate generation and distribution process for the jth student are as follows:
[0078] Step 1: The certificate issuing authority calls the polynomial commitment opening algorithm to calculate the proof and evaluation values of all certificates related to the student in turn. Assuming that there are m types of certificates in the system, the polynomial commitment opening calculation process is as follows:
[0079] (proof_1^j,f_1(j))\leftarrow open(f_1(x),j,srs)\\
[0080] (proof_2^j,f_2(j))\leftarrow open(f_2(x),j,srs)\\
[0081] ......\\
[0082] (proof_m^j,f_m(j))\leftarrow open(f_m(x),j,srs)\\
[0083] Among them, f_i(x) is the polynomial corresponding to the i-th type certificate, j is the student number, srs is the public parameter, f_i(j) is the evaluation value of the polynomial f_i(x) at point j, and proof_i^j is the corresponding opening proof.
[0084] Step 2: The certificate issuing authority packages the above generated proofs (proof_1^j, proof_2^j, ..., proof_m^j) and sends the complete certificate information and student number j to the student.
[0085] Through the above method, the certificate issuing authority provides each student with all the corresponding certificates and proofs.
[0086] In some embodiments of the present application, in step S13, the certificate to be revoked is determined according to the request for revocation submitted by the certificate issuing authority, and a signature is made and a message is published on the chain, wherein the request for revocation includes the number of the user to be revoked; the superior authority of the certificate issuing authority reviews it and sends a signature consent message on the chain; the number and commitment of the user to be revoked corresponding to the certificate to be revoked are added to the certificate revocation form. Here, the original certificate issuing authority applies to revoke a certificate proof^j_i of a student numbered j, and signs and publishes a message on the chain; the superior authority of the original certificate issuing authority reviews it and sends a signature consent message on the chain; the contract verifies that multiple signatures are established; the student number and commitment j, C_{f_i} corresponding to the certificate proof^j_i are added to the certificate revocation form. The same process can be used to cancel the revocation and change the revoked certificate to be valid. At this time, the process is the same, except that the application is changed to cancel the revoked certificate. The scheme described in this application supports the authorized public revocation mechanism, ensuring that the certificate information can be updated and revoked in a timely manner when errors or changes occur, and ensuring the validity and accuracy of the certificate.
[0087] In order to meet the needs of privacy protection in different scenarios, the embodiments of the present application provide two different proof generation modes: a proof generation mode where the verifier is trusted and a proof generation mode where the verifier is not trusted. These two modes provide flexible options for different document verification requirements. The implementation methods and processes of these two modes are described in detail below:
[0088] In some embodiments of the present application, in step S14, when the certificate verification requirement is the user's trust in the verifier, each graduation information of each experience of the user is compressed to obtain a compressed information value, and the compressed information value corresponding to each experience is merged to obtain a merged compressed information value; a merged certificate is generated based on the merged compressed information value, and a challenge value is calculated; the graduation information of the target experience that the user needs to disclose, the corresponding user number in each experience, and the merged certificate are provided to the verifier trusted by the user for verification. Here, the verification party's trusted proof generation mode is as follows: In actual application scenarios, students may trust the verifier and choose to provide graduation data containing private information to the verifier, such as when enrolling in a new school or joining a company. Assume that a student has t periods of study experience, and the student numbers corresponding to each experience are j_1, j_2,..., j_t, and k_i items of graduation information are selectively disclosed for each experience\bm{m_1,m_2,...,m_{k_i}}. For this information, the following steps are used to generate a merged proof of multiple experiences:
[0089] Step 1: Calculate the compression information for each graduation information of each experience, that is, treat each item of the data \bm{m_k} as a polynomial coefficient to construct the corresponding polynomial and calculate the corresponding compression value g_{k}(\alpha).
[0090] Step 2: Enter all the compression information experienced to calculate the challenge value:
[0091] ξ=H(g_{11}(\alpha),g_{12}(\alpha),...,g_{tm}(\alpha)), use the random linearization method to merge the proofs, generate the merged certificate Proof_i of each learning experience and the merged compressed information value of each learning experience (g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}), where the certificate and information corresponding to the graduation information that is not disclosed in each experience are 0:
[0092] Proof_i=proof_{i1}+ξproof_{i2}+...+ξ^{m-1}proof_{im}\\
[0093] g_i(\alpha)^{\prime}=g_{i1}(\alpha)+ξg_{i2}(\alpha)+...+ξ^{m-1}g_{im}(\alpha).
[0094] Step 3: Based on the compressed information value of each learning experience (g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}), compress the information of a three-dimensional array into a one-dimensional vector for subsequent verification; transform the three-dimensional array into a two-dimensional array through the polynomial value, and transform the two-dimensional array into one-dimensional array through random linearization. Further calculate the challenge value: \theta=H(g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}), randomly linearize the combined proof of all experiences, and generate the final combined certificate Proof:
[0095] Proof=Proof_1+\theta Proof_2+...+\theta^{t-1}Proof_{t}.
[0096] Step 4: Finally, the student discloses the graduation information of t study experiences, the corresponding student numbers j_1, j_2, ..., j_t in each experience, and the final certificate Proof to the trusted verifier for verification.
[0097] Continuing with the above embodiment, when the certificate verification requirement is that the user's trust in the verifier is a distrust requirement, each graduation information of each experience of the user is compressed to obtain a compressed information value, and the compressed information values corresponding to each experience are merged to obtain a merged compressed information value; the certificate and information corresponding to the undisclosed graduation information in each experience are assigned a value of 0, and the challenge value is calculated according to the merged compressed information value and the certificate and information corresponding to the undisclosed graduation information, and a merged certificate is generated according to the challenge value and the compressed information value; a certificate is generated according to the public information and the private information, wherein the public information includes the public part of the graduation information, the challenge value and the merged compressed information value of each experience, and the private information includes the undisclosed information in the graduation information and the information compression value of all information. Here, the untrustworthy proof generation mode of the verifier is as follows: In actual application scenarios, students may not trust the verifier and provide the verifier with graduation data that does not contain private information, such as personal homepages. Students can decide whether to make sensitive data public according to actual needs, while protecting personal privacy and still ensuring the authenticity of graduation information. Assume that a student has t periods of study experience, and the student numbers corresponding to each period are j_1, j_2, ..., j_t, and for each period, k_i graduation information items are selectively disclosed\bm{m_1,m_2,...,m_{k_i}}. Each graduation information\bm{m_i}=(x,w), where x refers to the public information part of this graduation information, and w refers to the private information part. For this information, the following steps are used to generate the combined proof of multiple experiences:
[0098] Step 1: Calculate the compressed information for each graduation information of each experience, that is, take each item of the data \bm{m_k} as a polynomial coefficient to construct the corresponding polynomial, and calculate the polynomial value g_{k}(\alpha), where \alpha is a public random number.
[0099] Step 2: Input the compressed information of all graduation information to calculate the challenge value: ξ=H(g_{11}(\alpha),g_{12}(\alpha),...,g_{tm}(\alpha)), use the random linearization method to merge the proof and the compressed information value, and generate the combined certificate (Proof_1,Proof_2,...,Proof_{t}) and the combined compressed information value (g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}) of each study experience. Among them, the certificate and information corresponding to the graduation information that is not disclosed in each experience are 0:
[0100] Proof_i=proof_{i1}+ξproof_{i2}+...+ξ^{m-1}proof_{im}\\
[0101] g_i(\alpha)^{\prime}=g_{i1}(\alpha)+ξg_{i2}(\alpha)+...+ξ^{m-1}g_{im}(\alpha).
[0102] Step 3: Based on the combined compressed information value of each study experience (g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}), further calculate the challenge value: \theta=H(g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}), randomly linearize the combined proof of all experiences, and generate the final combined certificate Proof:
[0103] Proof=Proof_1+\theta Proof_2+...+\theta^{t-1}Proof_{k_i}.
[0104] Step 4: Generate a proof for the information compression value. Use the ZK-SNARK proof algorithm to generate a proof, where the input public information x^{\prime} is the public part of the graduation information x, the challenge value ξ, and the combined compressed information value of each study experience; the input private message w^{\prime} is the private information w in the graduation information and all the information compression values.
[0105] Step 5. Finally, the student publicly discloses the public information part of the graduation information of t stages of study experience, the corresponding student number j_1, j_2, ..., j_t in each stage of study, the challenge value ξ, the compressed information value of each stage of study experience (g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}) and the final certificate Proof to the untrusted verifier for verification.
[0106] In some embodiments of the present application, in step S15, when the verifier is trusted by the user, the graduation information of each experience disclosed by the user, the user number corresponding to each experience, the challenge value and the certificate are received; the verifier queries whether the user number corresponding to each experience and the commitment corresponding to the disclosed graduation information are in the certificate revocation form, if not, the verifier calculates the compressed information of each graduation information of each experience respectively, merges the compressed information, and obtains the combined compressed information value; recalculates the challenge value according to the combined compressed information value, and calls the batch verification scheme of the commitment to verify the combined compressed information value and the recalculated challenge value. Here, the verification contract verification process of the verifier is trusted: when the verifier is trusted by the prover, the graduation information of the public t-stage study experience sent by the student, the student number corresponding to each experience is j_1, j_2, ..., j_t and the final certificate Proof. The verifier performs the following operations for verification: Step 1, the verifier queries whether the student number is j_1, j_2, ..., j_t and the commitment corresponding to the public graduation information are in the certificate revocation form, if so, the verification is terminated and the output is 0. Step 2: The verifier calculates the compressed information of each graduation information of each experience, that is, each item of the data \bm{m_k} is regarded as a polynomial coefficient to construct the corresponding polynomial, and calculates the polynomial value g_{k}(\alpha). Step 3: Input the compressed information of all graduation information to calculate the challenge value: ξ=H(g_{11}(\alpha),g_{12}(\alpha),...,g_{tm}(\alpha)), read the commitment of all graduation information involved from the blockchain block, and use the random linearization method to calculate the combined compressed information value of each study experience (g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}) and commitment: g_i(\alpha)^{\prime}=g_{1}(\alpha)+ξg_{2}(\alpha)+...+ξ^{k_i-1}g_{k_i}(\alpha)\\
[0107] C_i^{\prime}=C_{1}+ξC_{2}+...+ξ^{k_i-1}C_{k_i}.
[0108] Step 4. Based on the combined compressed information value of each learning experience (g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}), further calculate the challenge value: \theta=H(g_1^{\prime}(\alpha),g_2^{\prime}(\alpha),...,g_t^{\prime}(\alpha)).
[0109] Step 5: First calculate the polynomial Z_T(r)=(x-j_1)(x-j_2),...,(x-j_t) and the polynomial Z_1(x),...,Z_t(x), where Z_i(x)=\frac{Z_T(x)}{x-j_i}. Then calculate their encrypted values [Z_T(r)]_2,[Z_1(r)]_2,...,[Z_t(r)]_2.
[0110] Step 6: The verifier calls the promised batch verification scheme and outputs 1 if it is established, otherwise it outputs 0.
[0111] In some embodiments of the present application, in step S15, when the verifier is not trusted by the user, it receives the public information portion of each experience disclosed by the user, the user number corresponding to each experience, the challenge value, the compressed information value of each experience, and the certificate; the verifier inquires whether the user number corresponding to each experience and the commitment corresponding to the public graduation information are in the certificate revocation form, if not, the verifier verifies the challenge value and the compressed information value of each experience; reads the commitment of all graduation information related to the user from the blockchain block, and calculates the combined commitment of each experience; recalculates the challenge value according to the combined compressed information value of each experience, and calls the promised batch verification scheme to verify the combined compressed information value and the recalculated challenge value. Here, the verification process of the authentication contract where the verifier is untrusted:
[0112] When the verifier is trusted by the prover, it receives the public information part of the graduation information of t learning experiences sent by the student, the corresponding student numbers j_1, j_2, ..., j_t in each experience, the challenge value ξ, the compressed information value of each learning experience (g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}), the proof \pi and the final certificate Proof. The verifier performs the following operations for verification:
[0113] Step 1: The verifier checks whether the commitment corresponding to the student number j_1, j_2, ..., j_t and the public graduation information is in the certificate revocation form. If so, the verification is terminated and the output is 0. Step 2: Use the ZK-SNARK verification algorithm to verify the correctness of the challenge value ξ and the compressed information value of each learning experience (g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}), that is, ZK-SNARK.Verify(vk,x^{\prime},\pi), where the public input x^{\prime} is the public information part of the graduation information of t learning experiences, the challenge value ξ and the compressed information value of each learning experience (g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}). If it is established, continue with the subsequent steps, and output 0 anyway.
[0114] Step 3. Read the commitments of all graduation information involved from the blockchain block, and use the random linearization method to calculate the combined commitment C_i^{\prime}=C_{1}+ξC_{2}+...+ξ^{m-1}C_{m-1} for each study experience. Note that the commitment for undisclosed graduation information is 0.
[0115] Step 4. Based on the combined compressed information value of each learning experience (g_1(\alpha)^{\prime},g_2(\alpha)^{\prime},...,g_t(\alpha)^{\prime}), further calculate the challenge value: \theta=H(g_1^{\prime}(\alpha),g_2^{\prime}(\alpha),...,g_t^{\prime}(\alpha)).
[0116] Step 5: First calculate the polynomial Z_T(r)=(x-j_1)(x-j_2),...,(x-j_t) and the polynomial Z_1(x),...,Z_t(x), where Z_i(x)=\frac{Z_T(x)}{x-j_i}. Then calculate their encrypted values [Z_T(r)]_2,[Z_1(r)]_2,...,[Z_t(r)]_2.
[0117] Step 6: The verifier calls the promised batch verification scheme and outputs 1 if it is established, otherwise it outputs 0.
[0118] This application uses blockchain technology to manage important certificates such as academic qualifications, degrees, and transcripts, and uses the KZG commitment scheme and zero-knowledge proof technology to achieve privacy protection and related authentication. The scheme described in this application allows students' different school experiences to be processed uniformly by the same authentication mechanism without the need for multi-party cooperation. The scheme uses the immutability of blockchain, the automated verification function of smart contracts, and zero-knowledge proof technologies to provide an efficient, secure, and transparent certificate authentication mechanism. At the same time, based on actual conditions, students can choose whether to disclose their privacy.
[0119] In addition, an embodiment of the present application also provides a computer-readable medium on which computer-readable instructions are stored, and the computer-readable instructions can be executed by a processor to implement the aforementioned method of decentralized zero-knowledge academic qualification certification.
[0120] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
[0121] It should be noted that the present application can be implemented in software and / or a combination of software and hardware, for example, can be implemented using an application specific integrated circuit (ASIC), a general purpose computer or any other similar hardware device. In one embodiment, the software program of the present application can be executed by a processor to implement the steps or functions described above. Similarly, the software program of the present application (including relevant data structures) can be stored in a computer-readable recording medium, for example, a RAM memory, a magnetic or optical drive or a floppy disk and similar devices. In addition, some steps or functions of the present application can be implemented using hardware, for example, as a circuit that cooperates with a processor to perform each step or function.
[0122] In addition, a part of the present application may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present application through the operation of the computer. The program instruction for calling the method of the present application may be stored in a fixed or removable recording medium, and / or transmitted through a data stream in a broadcast or other signal-bearing medium, and / or stored in a working memory of a computer device that runs according to the program instruction. Here, according to an embodiment of the present application, a device is included, the device including a memory for storing computer program instructions and a processor for executing program instructions, wherein, when the computer program instruction is executed by the processor, the device is triggered to run the method and / or technical solution based on the aforementioned multiple embodiments according to the present application.
[0123] It is obvious to those skilled in the art that the present application is not limited to the details of the above exemplary embodiments, and that the present application can be implemented in other specific forms without departing from the spirit or basic features of the present application. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-restrictive, and the scope of the present application is defined by the appended claims rather than the above description, and it is intended that all changes falling within the meaning and scope of the equivalent elements of the claims are included in the present application. Any figure mark in the claims should not be regarded as limiting the claims involved. In addition, it is obvious that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. The words first, second, etc. are used to indicate names, and do not indicate any particular order.
Claims
1. A decentralized zero-knowledge academic certification method, characterized in that: The method comprises: Determine the security parameters selected by the system builder and determine all used fields selected to meet the specified requirements to construct public parameters; Determine the target group through the certificate issuing authority, process and store the certificate information of the target group according to the public parameters, and distribute the certificate to each user in the target group; According to the request for revocation submitted by the certificate issuing authority, a message is posted on the chain to generate a certificate revocation form; Merge and generate proof for each user's experience based on the document verification requirements; When the user's certificate information is received, the combined proof is authenticated through the authentication contract, and the authenticity of the certificate information is returned.
2. The method according to claim 1, characterized in that Construct public parameters, including: All used fields that meet the specified requirements are input into the program to execute the zero-knowledge proof system parameter generation algorithm, and the generated parameters are made public to obtain public parameters, wherein the public parameters include prime order fields, groups, proof parameters, verification keys, hash functions and generators.
3. The method according to claim 1, characterized in that Process and store the target group’s document information based on public parameters, including: Classify the graduation information of all users in the target group according to the information category to obtain m data sets, wherein the certificate information is determined by the user's graduation information; Select a target random number that is common to all data sets, process each user's data set separately, and use a polynomial to compress each user's graduation information on the target random number to obtain a compressed data set; Determine a target polynomial through an interpolation operation, and generate a corresponding commitment according to the target polynomial, wherein each term in the target polynomial is determined by the compressed data set; The commitments corresponding to the m data sets are written into the blocks in the blockchain for storage, where the commitments contain all the user's information.
4. The method according to claim 3, characterized in that Distribute the certificate to each user in the target group, including: Calling the opening algorithm of the target polynomial commitment, and sequentially calculating the proof and evaluation values of all certificates related to the applicant user to be applied for the certificate; Package all certificate proofs and send the certificate information and application user number to the applicant.
5. The method according to claim 3, characterized in that: According to the request for revocation submitted by the certificate issuing authority, a message is published on the chain to generate a certificate revocation form, including: Determine the certificate to be revoked according to the request for revocation submitted by the certificate issuing authority, sign it and publish a message on the chain, where the request for revocation includes the ID of the user to be revoked; The superior authority of the certificate issuing authority will review it and send a signed consent message to the chain; Add the ID and commitment of the user to be revoked corresponding to the certificate to be revoked to the certificate revocation form.
6. The method according to claim 1, characterized in that Based on the certificate verification requirements, generate a certificate for each user's experience, including: When the certificate verification requirement is the trust of the user in the verification party, each graduation information of each experience of the user is compressed to obtain a compressed information value, and the compressed information values corresponding to each experience are merged to obtain a merged compressed information value; Generate a combined certificate based on the combined compressed information value and calculate the challenge value; The graduation information of the target segment of experience that the user needs to disclose, the corresponding user number in each experience, and the combined certificate are provided to the verification party trusted by the user for verification.
7. The method according to claim 1, characterized in that Based on the certificate verification requirements, generate a certificate for each user's experience, including: When the certificate verification requirement is that the user does not trust the verification party, each graduation information of each experience of the user is compressed to obtain a compressed information value, and the compressed information values corresponding to each experience are merged to obtain a merged compressed information value; Assign the certificate and information corresponding to the undisclosed graduation information in each experience a value of 0, calculate the challenge value based on the combined compressed information value and the certificate and information corresponding to the undisclosed graduation information, and generate a combined certificate based on the challenge value and the compressed information value; A certificate is generated based on public information and private information, wherein the public information includes the public part of the graduation information, the challenge value and the combined compressed information value of each experience, and the private information includes the undisclosed information in the graduation information and the information compression value of all information.
8. The method according to claim 6, characterized in that When the user's certificate information is received, the combined proof is authenticated through the authentication contract, and the authenticity result of the certificate information is returned, including: When the verifier is trusted by the user, it receives the graduation information of each experience disclosed by the user, the user number corresponding to each experience, the challenge value and the certificate; The verifier checks whether the user number corresponding to each experience and the commitment corresponding to the public graduation information are in the certificate revocation form. If not, the verifier calculates the compressed information of each graduation information of each experience respectively, merges the compressed information, and obtains the merged compressed information value; The challenge value is recalculated based on the combined compressed information value, and the promised batch verification scheme is called to verify the combined compressed information value and the recalculated challenge value.
9. The method according to claim 7, characterized in that: When the user's certificate information is received, the combined proof is authenticated through the authentication contract, and the authenticity result of the certificate information is returned, including: When the verifier is not trusted by the user, it receives the public information part of each experience disclosed by the user, the user number corresponding to each experience, the challenge value, the compressed information value of each experience, and the certificate; The verifier checks whether the user number corresponding to each experience and the commitment corresponding to the public graduation information are in the certificate revocation form. If not, the verifier verifies the challenge value and the compressed information value of each experience; Read the commitment of all graduation information related to the user from the blockchain block and calculate the combined commitment of each experience; The challenge value is recalculated based on the combined compressed information value of each experience, and the promised batch verification scheme is called to verify the combined compressed information value and the recalculated challenge value.
10. A computer-readable medium having computer-readable instructions stored thereon, wherein the computer-readable instructions can be executed by a processor to implement the method according to any one of claims 1 to 9.