Decentralized currency mixing method capable of aggregating partial blind signature and zero knowledge proof
By adopting a decentralized currency mixing method that can aggregate partial blind signatures and zero-knowledge proof in the Bitcoin currency mixing method, the problems of vulnerability and inflexibility in the existing technology are solved, and the effect of high privacy, anti-attack and flexible amount mixing is achieved.
Patent Information
- Application Number
- CN202510198301.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-22
- Publication Date
- 2025-05-30
AI Technical Summary
Existing Bitcoin mixing methods are susceptible to DoS attacks, conspiracy attacks and Sybil attacks, and cannot support flexible amount mixing.
A decentralized currency mixing method that can aggregate partial blind signatures and zero-knowledge proofs is adopted to achieve decentralization, anti-aggressive and flexible amount mixing through the advertising stage, trading stage and signature stage.
It realizes unlinkability and traceability, anti-DOS attacks, anti-Sybil attacks and conspiracy attacks, improves the privacy and flexibility of Bitcoin transactions, and reduces the occurrence of malicious behavior.
Smart Images

Figure CN120069957A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and more specifically, to a decentralized coin mixing method that combines partial blind signature and zero-knowledge proof. Background Art
[0002] The anonymity of Bitcoin mainly relies on pseudonyms, which theoretically severs the connection between transactions and the real identities of participants. Additionally, payers and payees can change their pseudonyms from time to time to conceal their identities. However, more and more research shows that the actual anonymity of Bitcoin is much weaker than we thought. Bitcoin's blockchain is a public ledger that stores all transactions indicating the flow of funds from payers to payees, which may expose the connections between their pseudonyms. Once a pseudonym is associated with a party's real identity, all related pseudonyms and transactions can be associated with that party, leading to the collapse of anonymity. To improve the anonymity of cryptocurrencies, several new anonymous cryptocurrencies (such as Zerocash and Monero) have been proposed and achieve complete unlinkability. However, they are not compatible with Bitcoin and there is a risk of tight liquidity. Alternatively, an anonymity-enhanced service mixer compatible with Bitcoin has emerged. Briefly, a mixer is a party in the Bitcoin network that is responsible for receiving Bitcoins (BTC) from a group of payers and then obscuring the relationship between the trading parties before re-sending the BTC to the final payee. In this way, Bitcoin analysts cannot infer the connection between the payee and the actual payer from a series of public Bitcoin transactions. Although the introduction of mixers into Bitcoin reveals solutions for anonymity and unlinkability, its practical application still faces some security and performance challenges that have not been well resolved; First, many existing coin mixing methods are vulnerable to DoS attacks. As we know, the process of recording transactions on the Bitcoin blockchain requires consuming transaction fees to reward miners. However, some existing schemes require the mixer to first hold Bitcoins on the blockchain for a specific period of time before mixing payments. Therefore, a powerful and well-funded attacker (i.e., the payer / payee) can repeatedly join and then deliberately abort the mixing protocol with a trivial transaction fee, which may lock up the mixer's limited amount of BTC for a long time and cause a specific DoS attack. Second, the collusion attack, that is, the situation where malicious parties (payers / payees) collude with the mixer to deceive their trading counterparts (payees / payers), has not been well resisted. When honest parties suffer from collusion attacks, it is difficult to ensure fair transactions. Third, the Sybil attack, where an attacker may conduct an attack by imitating multiple identities and registering multiple users simultaneously to achieve the result of manipulating transactions; In addition, existing coin mixing methods can basically only allow the mixing of the same share of amounts and cannot flexibly support multiple amounts; In response to the above several problems, we designed a decentralized coin mixing method (ZKBScoin) based on aggregatable partial blind signature and zero-knowledge proof. Summary of the Invention
[0003] The purpose of the present invention is to provide a decentralized coin mixing method with aggregatable partial blind signature and zero-knowledge proof, which has unlinkability, traceability, and is resistant to DOS attacks, Sybil attacks, and collusion attacks, and realizes complete decentralization, which is more in line with the essential characteristics of blockchain. Compared with ordinary blind signatures, it has the advantages of fewer verification times and stronger privacy. The signature combines the perdeson commitment and the BBS+ signature to generate relevant zero-knowledge proofs, realizing the function of supporting flexible variable amounts, and has obvious advantages in protecting transaction privacy in the Bitcoin scenario. At the same time, the number of times of generating zero-knowledge proofs is relatively low, improving the privacy and flexibility in Bitcoin transactions, effectively alleviating the risks of fixed amounts and distrust of third parties in coin mixing technology, and being easier to deploy and implement.
[0004] To achieve the above object, the present invention provides a decentralized coin mixing method with aggregatable partial blind signature and zero-knowledge proof, including the following steps: S1. Advertising stage: The advertiser publishes information on the blockchain and releases coin mixing information, combines coin mixing participants to form a coin mixing participation group, decomposes non-standard coin mixing amounts into several predefined standard amount units, and stores these units in different wallet addresses respectively; S2. Transaction stage: The coin mixing participants select an advertiser on the blockchain, broadcast the input address as the public key to form an input address list, generate an information including its output address and amount, and prove the validity of the information to the advertiser through zero-knowledge proof without disclosing the specific value. After verifying the zero-knowledge proof, the advertiser performs a partial blind signature operation on the information, allowing the participants to obtain a digital signature without exposing the original content; S3. Signature stage: The digital signatures of all participants are aggregated into a total signature as the aggregated signature, and the aggregated signature together with the relevant input addresses and amounts are publicly released on the blockchain for everyone to verify.
[0005] As a further improvement of this technical solution, the published information includes the contact address αA, the wallet input address αI, the standard amount M, the minimum number of addresses n and the maximum number of addresses m allowed for mixing, as well as the required mixing fee τ, the duration t, the timestamp, and the adopted hash function H.
[0006] As a further improvement of this technical solution, during the advertising stage, it also includes paying the advertising fee as collateral and miner rewards, and the mixed fee τ and the advertising fee γ satisfy the condition: nτ > γ > mτ / 2.
[0007] As a further improvement of this technical solution, the transaction stage includes a verification stage, enabling any coin mixing participant to withdraw from and join the group at any time. The specific steps are as follows: The middleman randomly selects an advertising fee , and the user generates a commitment for the subsequent partially blind signature process. The expression is: , where is the calculation result for the subsequent partially blind signature process, is the known generator; Select an input address and a random value for each advertising fee, generate the output address and the output amount , and then calculate the commitment , where , and are generators; Generate a zero-knowledge proof ; The advertiser uses to verify 's correctness. After the verification is okay, a random value randomly selected by the advertiser is used to extend the user's commitment . Then, another value e is randomly selected for calculating the exponential part of the partially blind signature, and the partially blind signature is calculated, where and are the base points on the elliptic curve, and the triple is returned to the user. The user who receives the triple replies a confirmation to the advertiser. When the advertiser receives at least the minimum mixing number n confirmations and at most the maximum mixing number m confirmations, the advertiser will announce on the blockchain that it will no longer accept new coin mixers and enter the mixing stage.
[0008] As a further improvement of this technical solution, the transaction stage also includes a mixing stage, which includes the following steps: Add the previously generated random value and in the partially blind signature received from the advertiser to obtain the total secret value ; Calculate and compare the bilinear pairing results on both sides to verify whether the partially blind signature A is valid. If the equation holds, it means the signature is correct; Construct a set of partial blind signatures, a set of total random values, and a set of randomly selected exponents for subsequent commitment and proof generation; The user combines the output amounts of their previous transactions at the same address to obtain the total output amount and calculates a new set of commitments; Generate a new zero-knowledge proof; The user submits the newly generated commitments and zero-knowledge proofs to the advertiser. The middleman forms a new temporary group based on the received information and prepares to enter the signing stage.
[0009] As a further improvement of this technical solution, the signing stage includes the following steps: Each participant uploads their multi-tuple to the group bulletin board, where is the new set of commitments generated by the user, and SPK is the zero-knowledge proof. All participants verify whether the SPK is correct. The advertiser uploads all the received input addresses and input amounts to the bulletin board and adds mτ / 2 bitcoins to their receiving address, where m is the total number of addresses participating in the coin mixing, to form the total transaction; Each participant checks the following for correctness: confirm whether the information on the bulletin board includes their input and output addresses, confirm that their input address has sufficient balance to support the transaction, confirm whether the input amount and output amount match, and ensure that the total input amount of all participants is equal to the total output amount; If all of the above are correct, all participants use the aggregate signature algorithm supported by the Bitcoin blockchain for aggregate signature; After everyone has signed, the final signed transaction is submitted to the blockchain.
[0010] As a further improvement of this technical solution, it also includes accountability in the verification stage, including the following postures: Posture 1: Delaying time: After perceiving that the coin mixer has paid the signature fee to the advertiser, it is regarded as a member finally participating in the coin mixing transaction; Posture 2: Insufficient account balance: The input address of each coin mixer is public, and the amount in the account is also public information. The advertiser monitors the balance in the account. If it is insufficient, the participation request of the coin mixer is rejected. Otherwise, it is regarded as a member finally participating in the coin mixing transaction; Posture 3: Delaying signing: When the coin mixer has paid the corresponding signature fee, if no signature is received or an incorrect signature is given within the specified time, the payment voucher of the coin mixer is posted to the group to indicate that this advertiser is malicious. If the advertiser cannot provide a correct signature, it is declared a malicious party, the group is dissolved, and since the advertiser's public key is public in the group, anyone can verify whether the advertiser has given a correct signature; Posture Four: The coin mixer and the advertiser are collusive malicious actors: It is perceived that the advertiser does not verify the coin mixer and directly signs. When the final transaction is formed, if the input and output amounts do not match and all information has been signed by the advertiser, then the advertiser must be a malicious actor and the transaction is invalid.
[0011] As a further improvement of this technical solution, it also includes accountability in the mixing stage, including the following postures: Posture One: Submitting false information: The correct output information is signed and confirmed by the advertiser during the verification stage. Any information without the corresponding signature is regarded as false and marked as invalid; Posture Two: The advertiser publicizes the duration during the advertising stage, and the information not submitted within the specified time becomes invalid.
[0012] Compared with the prior art, the beneficial effects of the present invention are: 1. Flexible exit mechanism, allowing participants to freely enter and exit during the advertising stage, avoiding unnecessary losses. Starting from the verification stage, it ensures the authenticity of all information, guarantees the security and fairness of the advertiser, the coin mixer, and the entire system. Through the accountability stage, multiple verification means and punishment measures are implemented to reduce the occurrence of malicious behaviors. All operations are carried out in an open and transparent environment, ensuring that the behavior of each party can be traced and verified, imposing severe punishments on malicious behaviors, such as being blacklisted, net loss, etc. At the same time, using the group bulletin board and public information, ensuring that all participants can understand the situation in a timely manner and make responses.
[0013] 2. Through n partial blind signatures and the requirement that each user needs several addresses with a certain entropy value, and at the same time different advertisers can set different acceptable mixing amounts and mixing fees to ensure that users can choose the advertiser that best matches their transaction amount. In addition, multiple standard amounts are supported simultaneously in one transaction, making the final mixing amount more flexible while reducing the splitting times to a certain extent, thereby reducing expenses. And using an anonymous bulletin board greatly reduces the communication overhead without reducing the security.
[0014] 3. Through random values, external observers cannot directly infer the output address and output amount from the commitment, thus achieving privacy protection. Moreover, the random value of each user is unique, so each address is also unique, ensuring the independence and non-linkability of each user during the coin mixing process. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 is the overall flow block diagram of the present invention; Figure 2 is the detailed principle block diagram of the overall accountability of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0016] Next, in combination with the accompanying drawings in the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention. Embodiment
[0017] Please refer to Figure 1 - Figure 2 As shown, this embodiment provides a decentralized coin mixing method that can aggregate partial blind signatures and zero-knowledge proofs, including the following steps: S1. Advertising stage: Advertisers publicly release information on the blockchain to attract users to participate in coin mixing, and release coin mixing information, combining coin mixing participants to form a coin mixing participation group. Decompose non-standard coin mixing amounts into several predefined standard amount units, and store these units using different wallet addresses respectively, so that any member who wants to participate in coin mixing can send their communication address and other personal information to the advertiser. Coin mixing participants with non-standard amounts need to decompose their coin mixing amounts into standard amounts and store them using different wallet addresses, and then send messages to the advertiser using different communication addresses. After receiving the messages, the advertiser will send confirmation messages to the users participating in coin mixing; Specifically, the released information includes the contact address αA, the wallet input address αI, the standard amount M (i.e., the amount for receiving the mixing transaction), the minimum number of addresses n and the maximum number of addresses m allowed for mixing, as well as the required mixing fee τ, the duration t, the timestamp, and the hash function H used.
[0018] Among them, in the advertising stage, it also includes paying the advertising fee as collateral and miner rewards. The mixing fee τ and the advertising fee γ satisfy the condition: nτ > γ > mτ / 2; The purpose of setting this amount is to ensure that the advertiser is in a loss state after collecting the signature fee, but can make a profit after completing the transaction, preventing malicious users from consuming the advertiser's resources by submitting a large number of small transactions, so as to achieve anti-DOS attacks.
[0019] S2. Transaction stage: Coin mixing participants select any advertiser listed on the blockchain, broadcast the input address as the public key to form an input address list {PK1, PK2,..., PKn}, generate an information containing its output address and amount, and prove the validity of the information to the advertiser through zero-knowledge proof without disclosing the specific values. After verifying the zero-knowledge proof, the advertiser performs a partial blind signature operation on the information, allowing the participant to obtain a digital signature without exposing the original content; Further, the transaction stage includes a verification stage, enabling any coin mixing participant to withdraw from and join the group at any time without affecting other ongoing users. The specific steps are as follows: The middleman randomly selects an advertising fee (from a finite field, this value is randomly generated by the advertiser when publishing an advertisement and is part of the collateral and miner rewards). The user generates a commitment for the subsequent partially blind signature process, with the expression: , where is the calculation result for the subsequent partially blind signature process, is a known generator (usually a point on an elliptic curve or an element in a finite field). Since is a random value private to the advertiser, the specific value of cannot be directly inferred externally. Even if and are known, the security of is ensured; Select an input address and a random value (a secret value randomly selected by the user to hide the specific output address) for each advertising fee, generate the output address and the output amount , and then calculate the commitment , where , and are generators (usually points on an elliptic curve or elements in a finite field) for generating the commitment. Since is random, an external observer cannot directly infer and from the commitment , thus achieving privacy protection. Moreover, each user's is unique, so each is also unique, ensuring the independence and unlinkability of each user during the coin mixing process; Generate a zero - knowledge proof . A zero - knowledge proof is a cryptographic technique that allows a prover to prove to a verifier that a certain statement is true without revealing any additional information. The user needs to prove that they know , , and that these values indeed satisfy , without disclosing the specific , and , Represents a specific construction method for public-key encryption or zero-knowledge proof. The specific implementation may rely on Schnorr proof, Fiat-Shamir transformation, or other zero-knowledge proof mechanisms; The advertiser uses to verify the correctness of , and when the verification is okay, a random value randomly selected by the advertiser, which is used to extend the user's commitment , where elliptic curve cryptography (ECC) is used and are the base points on the elliptic curve, and the triple is returned to the user. The user who receives the triple replies with a confirmation to the advertiser. When the advertiser receives at least the minimum mixing number n confirmations and at most the maximum mixing number m confirmations, the advertiser will announce on the blockchain that it will no longer accept new mixers and enter the mixing stage; Therefore, users can use the received partially blind signature A to verify whether the advertiser has correctly signed their commitments , improving verifiability. When returning the triple to the user, the user can use A, e, and to verify the correctness of the partially blind signature and confirm that the advertiser has indeed signed their commitments . The user replies with a confirmation message to the advertiser indicating that they have successfully received and verified the partially blind signature. When the advertiser receives a sufficient number of confirmations, it officially enters the next stage, ensuring the security and reliability of the entire coin mixing process. The partially blind signature mechanism not only enhances the security and privacy protection capabilities of the system but also ensures the fairness and trustless nature of the coin mixing process.
[0020] And, the transaction stage also includes a mixing stage, which includes the following steps: Add the previously generated random value and in the partially blind signature received from the advertiser to obtain the total secret value , which is used for subsequent verification steps to ensure the validity of the partially blind signature; Calculate and compare the results of the bilinear pairing on both sides to verify whether the partial blind signature A is valid. If the equation holds, it indicates that the signature is correct. Among them, the bilinear pairing is a commonly used tool in elliptic curve cryptography for verifying the validity of signatures and ensuring that the advertiser has correctly signed the user's commitment , thus ensuring the legality and security of the transaction; Construct a set of partial blind signatures, a set of total random values, and a set of randomly selected exponents for subsequent commitment and proof generation, ensuring that the output addresses and amounts of each user can be correctly processed and verified; The user combines the output amounts of their previous same address to obtain the total output amount , and calculates a new set of commitments. Among them, the new commitment is generated by introducing new random values and , generating new commitments and , further enhancing privacy protection. The commitments generated by each user are unique, preventing replay attacks; Generate a new zero-knowledge proof, ensuring the validity of all users' commitments and signatures, while hiding the specific output addresses and amounts. Advertisers and other participants can verify the new zero-knowledge proof to confirm the validity of the users' commitments and signatures without knowing the specific details; The user submits the newly generated commitments and zero-knowledge proofs to the advertiser. The middleman forms a new temporary group based on the received information and is ready to enter the signing stage. When the middleman receives information submitted by a sufficient number of users or exceeds the last message deadline, the middleman forms a new temporary group with the newly received communication addresses.
[0021] S3. Signing stage: The digital signatures of all participants are aggregated into a total signature as the aggregated signature, which helps to reduce the communication burden while maintaining anonymity. The aggregated signature, together with the relevant input addresses and amounts, is publicly released on the blockchain for everyone to verify.
[0022] Furthermore, the signing stage includes the following steps: Each participant uploads their multi-tuple to the group bulletin board, where It is a new set of commitments generated by users. The SPK is a zero-knowledge proof used to verify the validity of all users' commitments and signatures. All participants check whether the SPK is correct. The advertiser uploads all the received input addresses and input amounts to the bulletin board and adds mτ / 2 bitcoins to their own receiving address, where m is the total number of addresses participating in the coin mixing. The total transaction formed. The middleman aggregates the input addresses and amounts of all participants to ensure that all information is transparently visible. The middleman adds a mixing fee of τ / 2 to the input address of each participant to ensure the fairness of the transaction and the incentive mechanism; Each participant checks the following for correctness: confirm whether the information on the bulletin board includes their own input and output addresses, confirm that their input address has sufficient balance to support the transaction, confirm whether the input amount and output amount match, ensure that the total input amount of all participants is equal to the total output amount (including the mixing fee), ensure that the information of all participants is accurate and error-free, prevent any errors or malicious behaviors from affecting the transaction, and at the same time, ensure that the interests of all participants are protected and the transaction process is fair and transparent; If the above are all correct, all participants use the aggregate signature algorithm supported by the Bitcoin blockchain to perform aggregate signature. All participants use the aggregate signature algorithm (such as Schnorr signature) to sign the entire transaction. The aggregate signature can combine multiple signatures into one, improving efficiency and reducing the amount of data on the chain. It not only improves security but also reduces the size of the data on the chain, making the transaction more efficient; After everyone has signed, the final signed transaction is submitted to the blockchain. Once submitted to the blockchain, the transaction information cannot be tampered with, ensuring the security and reliability of the transaction. It fully relies on blockchain technology and smart contracts without the need for a third-party intermediary, achieving decentralization. Embodiment
[0023] The advertiser can decide whether to initiate the transaction after collecting a sufficient number of participation intentions. Any advertiser and participant can freely choose each other two-way. As long as no advertiser has publicly announced in the blockchain to enter the mixing stage, any member can withdraw and join the protocol at any time without causing any loss to either party, including time and money. However, when there are some coin mixing participants or advertisers with problems during the verification stage, it will affect the efficiency of coin mixing. Therefore, it also includes accountability during the verification stage, including the following postures: Posture 1: Delay time: After perceiving that the coin mixer delivers the signature fee to the advertiser, it is regarded as a member finally participating in the coin mixing transaction. As long as the advertiser receives enough paying coin mixers to participate, it can proceed to the next stage without being interfered by the procrastinator; Posture Two, Insufficient Account Balance: The input address of each mixer is public, and the amount in the account is also public information. The advertiser monitors the balance in the account. If it is insufficient, the participation request of the mixer is rejected. Otherwise, it is regarded as a member finally participating in the mixing transaction; Posture Three, Delaying Signing: After receiving the signature fee, the advertiser refuses to sign or delays signing. When the mixer pays the corresponding signature fee, if the unsigned signature is not received within the specified time or the wrong signature is given, the mixer's payment voucher is posted to the group to indicate that this advertiser is malicious. If the advertiser cannot provide evidence of correct signature or reasonable refusal, it is declared a malicious party and the group is dissolved. Due to the existence of the advertiser's collateral, there will be a net loss to ensure the safety of participants. And since the advertiser's public key is public in the group, anyone can verify whether the advertiser gives the correct signature; Posture Four, The Mixer and the Advertiser are Collusive Malicious Parties: It is perceived that the advertiser does not verify the mixer and directly signs. When the final transaction is formed, if the input and output amounts do not match and all information is signed by the advertiser, the advertiser must be a malicious party, the transaction is invalid, and the advertiser is output as a malicious party and the group is dissolved.
[0024] In addition, it also includes the accountability in the mixing stage, including the following postures: Posture One, Submitting False Information: The correct information output is signed and confirmed by the advertiser in the verification stage. Any information without the corresponding signature submitted is regarded as false and marked as invalid; Posture Two, The advertiser publicizes the duration in the advertising stage. The information not submitted within the specified time becomes invalid. The mixer may lose the signature fee or even the amount in the input address. The user who times out refuses to sign in the signing stage will be blacklisted and excluded from the subsequent process. The signed messages of honest mixers can be reused without paying multiple fees; And, it also includes the accountability in the signing stage. If this address is blacklisted by the advertiser, the malicious party needs to pay the signature fee again when signing again. The signature information of other honest users can be reused without paying again. Each input address has a corresponding signature. Any error in the signature corresponding to an address will blacklist that address. For the same input address and amount, no fee is charged when signing again to ensure that honest users are not affected; In summary, the core objectives of the accountability mechanism are as follows: a flexible exit mechanism that allows participants to freely enter and exit during the advertising phase, avoiding unnecessary losses. Starting from the verification phase, it ensures the authenticity of all information, guarantees the security and fairness of advertisers, mixers, and the entire system. Through various verification means and punishment measures, it reduces the occurrence of malicious behaviors. All operations are carried out in an open and transparent environment, ensuring that the actions of each party can be traced and verified. Severe punishments are imposed on malicious behaviors, such as being blacklisted, net losses, etc. At the same time, by using group bulletin boards and public information, it ensures that all participants can timely understand the situation and make responses.
[0025] The above has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification are only preferred examples of the present invention and are not used to limit the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A decentralized currency mixing method that can aggregate partial blind signatures and zero-knowledge proofs, characterized in that: The following steps are involved: S1, Advertising stage: Advertisers publish information publicly on the blockchain and publish coin mixing information, combine coin mixing participants to form a coin mixing participant group, decompose the non-standard coin mixing amount into several pre-defined standard amount units, and use different wallet addresses to store these units respectively; S2, Transaction phase: The coin mixing participants select advertisers on the blockchain, broadcast the input address as the public key, form an input address list, generate a message containing its output address and amount, and prove the validity of the information to the advertiser through zero-knowledge proof without revealing the specific value. After verifying the zero-knowledge proof, the advertiser performs a partial blind signature operation on the information, allowing participants to obtain a digital signature without exposing the original content; S3, Signature phase: The digital signatures of all participants are aggregated into a total signature as the aggregate signature, which is publicly published on the blockchain together with the relevant input addresses and amounts for everyone to verify.
2. The decentralized coin mixing method of aggregated partial blind signature and zero-knowledge proof according to claim 1, characterized in that: The published information includes the contact address αA, the wallet input address αI, the standard amount M, the minimum number of addresses n and the maximum number of addresses m allowed for mixing, as well as the required mixing fee τ, duration t, timestamp and the adopted hash function H.
3. The decentralized coin mixing method of aggregated partial blind signature and zero-knowledge proof according to claim 2, characterized in that: The advertising stage also includes paying advertising fees as collateral and miner rewards. The mixed fee τ and the advertising fee γ satisfy the condition: nτ>γ>mτ / 2.
4. The decentralized coin mixing method of aggregated partial blind signature and zero-knowledge proof according to claim 3, characterized in that: The transaction phase includes a verification phase, which allows any coin mixing participant to exit and join the group at any time. The specific steps are as follows: The middleman randomly selects an advertising fee , the user generates a commitment for the subsequent partial blind signature process, expressed as: ,in, is the calculation result, which is used in the subsequent partial blind signature process. is a known generator; Choose an input address and random value for each advertising fee , generate output address and output amount , then calculate the commitment ,in, , and is the generator; Generating a zero-knowledge proof ; Advertiser Use To verify The correctness of the advertiser is verified to be correct. Once the verification is successful, the advertiser randomly selects a random value. , used to extend the user's commitment , and then randomly select another value e to calculate the exponential part of the partial blind signature, and calculate the partial blind signature ,in, and is the base point on the elliptic curve, and the triple It is returned to the user. The user who receives the triplet replies with a confirmation to the advertiser. When the advertiser receives at least the minimum mixing number n confirmations and at most the maximum mixing number m confirmations, the advertiser will announce on the blockchain that it will no longer accept new mixers and enter the mixing stage.
5. The decentralized coin mixing method of aggregated partial blind signature and zero-knowledge proof according to claim 4, characterized in that: The transaction phase also includes a mixing phase, including the following steps: The previously generated random value and the partial blind signature received from the advertiser Add together to get the total secret value ; Calculate and compare the bilinear pairing results on both sides to verify whether the partial blind signature A is valid. If the equation holds, it means the signature is correct. Construct a set of partial blind signatures, a set of total random values, and a set of randomly selected exponents for subsequent commitment and proof generation; The user combines the output amounts of the same address to get the total output amount. , and compute a new set of commitments; Generate a new zero-knowledge proof; The user submits the generated new commitment and zero-knowledge proof to the advertiser, and the middleman forms a new temporary group based on the information received and prepares to enter the signing stage.
6. The decentralized coin mixing method of aggregated partial blind signature and zero-knowledge proof according to claim 5, characterized in that: The signing phase includes the following steps: Each participant will have his own multi-tuple Uploaded to the group bulletin board, where It is a new commitment set generated by the user. SPK is a zero-knowledge proof. All participants verify whether SPK is correct. The advertiser uploads all received input addresses and input amounts to the bulletin board and adds mτ / 2 bitcoins to his own receiving address, where m is the total number of addresses participating in the mixing of coins and the total transaction formed. Each participant checks whether the following is correct: confirm whether the information on the bulletin board contains their own input and output addresses, confirm that their own input address has enough balance to support the transaction, confirm whether the input amount and output amount match, and ensure that the total input amount of all participants is equal to the total output amount; If all of the above are correct, all participants use the aggregate signature algorithm supported by the Bitcoin blockchain to perform aggregate signatures; When everyone has signed, the final signed transaction is submitted to the blockchain.
7. The decentralized coin mixing method of aggregated partial blind signature and zero-knowledge proof according to claim 6, characterized in that: It also includes accountability during the verification phase, including the following gestures: Posture 1: Delaying time: After the perceived mixer pays the signature fee to the advertiser, he is regarded as the final member participating in the mixing transaction; Attitude 2: Insufficient account balance: The input address of each mixer is public, and the amount in the account is also public information. Advertisers monitor the balance in the account. If it is insufficient, the mixer’s participation request will be rejected. Otherwise, the mixer will be regarded as a member who finally participates in the mixing transaction. Posture 3: Delayed signing: After the mixer pays the corresponding signature fee, if the mixer does not receive an unexecuted signature or gives an incorrect signature within the specified time, the mixer’s payment voucher will be posted to the group to indicate that the advertiser is malicious. If the advertiser cannot provide the correct signature, it will be declared malicious and the group will be disbanded. In addition, since the advertiser publishes the public key in the group, anyone can verify whether the advertiser has given the correct signature. Posture 4: The coin mixer and the advertiser are malicious colluders: The advertiser does not verify the coin mixer and signs directly. When the final transaction is formed, if the input and output amounts do not match, and all information is signed by the advertiser, then the advertiser must be malicious and the transaction is invalid.
8. The decentralized coin mixing method of aggregated partial blind signature and zero-knowledge proof according to claim 7, characterized in that: It also includes accountability during the hybrid phase, including the following gestures: Posture 1: Submitting false information: The correct information output is signed and confirmed by the advertiser during the verification stage. Any information that does not submit the corresponding signature is considered false and marked as invalid; Posture 2: Advertisers shall publicize the duration of the advertising stage, and any information not submitted within the specified time shall be invalid.