Non-interactive zero-knowledge proving method for universal mixed relationship

By introducing an internal product transformation method in zero-knowledge proof, the non-interactive zero-knowledge proof method for general mixed relationships solves the problem that only specific mixed relationships can be proved in the prior art, achieving a wider application scenario and better proof performance.

CN120200756APending Publication Date: 2025-06-24SHANGHAI JIAOTONG UNIV
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510345825.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

Existing zero-knowledge proof technology can only prove a specific mixed relationship, cannot adapt to a general mixed relationship, and it is difficult to achieve practical proof length and proof time at the same time.

Method used

A non-interactive zero-knowledge proof method for general mixed relationships is proposed, and the RLWE ciphertext and Pedersen commitment to encrypt message m are generated through RLWE encryption and Pedersen commitment algorithms, and the proof for general mixed relationships is generated and verified using the inner product transformation method.

Benefits of technology

The proof of correctness of RLWE encryption and Pedersen commitments is realized, supporting a wider range of application scenarios, and the proof length and proof time are currently optimal.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200756A_ABST
    Figure CN120200756A_ABST
Patent Text Reader

Abstract

The invention discloses a non-interactive zero-knowledge certification implementation method for a universal mixed relationship. The method comprises the following steps: integrating the requirements of an actual application scene into a certification framework; public parameters are initialized through zero-knowledge proof; generating a non-interactive zero-knowledge proof for the general mixed relationship; non-interactive zero-knowledge proof for the generic hybrid relationship is validated. According to the method, perfect completeness, reliability based on a discrete logarithm difficulty problem and zero knowledge based on a lattice difficulty problem can be realized when a value which is committed to be hidden by Pedersen and a plaintext value encrypted by RLWE are in any linear relation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a technology in the field of information security, specifically a non-interactive zero-knowledge proof method for RLWE encryption and Pedersen commitment correctness of proof-sharing evidence for general mixed relationships, which is used in privacy outsourcing scenarios. Background Art

[0002] In privacy outsourcing computing, multiple users upload encrypted data to a server. The server performs intensive homomorphic or fully homomorphic operations without knowing the plaintext information and then returns the ciphertext result to multiple users. Multiple users jointly decrypt to obtain the plaintext calculation result. To prevent a user from providing invalid ciphertext to the server and causing the outsourcing calculation to fail, it is necessary for each user to provide a zero-knowledge proof of ciphertext validity. In addition, it may also be necessary to prove through Pedersen commitment that the encrypted message satisfies certain additional attributes specified by the protocol. Efficient fully homomorphic encryption is often constructed by RLWE encryption schemes. However, the existing zero-knowledge proof techniques can only prove specific and particular mixed relationships, that is, the relationship between the value hidden by the Pedersen commitment and the plaintext value encrypted by RLWE is fixed, thus limiting the application scenarios of this zero-knowledge proof. In addition, the existing work cannot achieve both practical proof length and proof time simultaneously. Summary of the Invention

[0003] In view of the deficiency that the existing technology can only prove specific and particular mixed relationships, the present invention proposes a non-interactive zero-knowledge proof method for general mixed relationships, which can achieve perfect completeness, reliability based on the difficulty of discrete logarithm problems, and zero-knowledge based on the difficulty of lattice problems when the value hidden by the Pedersen commitment and the plaintext value encrypted by RLWE are in an arbitrary linear relationship.

[0004] The present invention is realized by the following technical solutions:

[0005] The present invention relates to a non-interactive zero-knowledge proof method for general mixed relationships, including:

[0006] Step 1: Integrate the requirements of the actual application scenario into a proof framework including a proof integration unit for the actual application scenario, an initialization unit for public parameters, a proof generation unit for zero-knowledge proof, and a proof verification unit for zero-knowledge proof;

[0007] In the actual application scenario unit, the participating parties execute the RLWE encryption algorithm and the Pedersen commitment algorithm to generate an RLWE ciphertext for encrypting the message m and a Pedersen commitment for committing to the message where: m and There is a linear relationship. To prevent malicious behavior of protocol participants, a participant proves to other users that it has correctly executed the RLWE encryption algorithm and the Pedersen commitment algorithm. In the actual application scenario, the unit of relationship to be proven abstracts the linear relationship between the RLWE ciphertext, the Pedersen commitment, and the hidden evidence from the scenario to obtain a specific mixed relationship. The unit of initializing common parameters obtains the parameters for zero-knowledge proof initialization according to the specific mixed relationship. The proof generation unit of zero-knowledge proof converts the mixed relationship into an inner product relationship according to the initialized parameters and calls the existing inner product proof component to generate a proof for the mixed relationship and returns it to the corresponding application scenario. The proof verification unit of zero-knowledge proof performs inner product conversion according to the initialized parameters and the existing proof and calls the existing inner product verification component to return the acceptance / rejection result to the corresponding scenario.

[0008] Step 2: Initialize the common parameters of zero-knowledge proof;

[0009] Step 3: Generate a non-interactive zero-knowledge proof for the general mixed relationship;

[0010] Step 4: Verify the non-interactive zero-knowledge proof for the general mixed relationship. Technical effects

[0011] The present invention optimizes the definition framework of the mixed relationship, introduces a more efficient inner product conversion method for proving the correctness of RLWE encryption, and first proposes an inner product conversion method for proving the correctness of Pedersen commitment and the linear relationship between the hidden message and the plaintext of RLWE encryption. Compared with the prior art, the present invention supports a wider range of application scenarios, and the proof length and proof time reach the current optimum. Description of the drawings

[0012] Figure 1 It is a flowchart of the present invention;

[0013] Figure 2 Schematic diagram of the embodiment. Detailed implementation manners

[0014] As Figure 1 shown, this embodiment relates to a non-interactive zero-knowledge proof method for a general mixed relationship, including:

[0015] Step 1: Integrate the requirements of the actual application scenario into the proof framework, specifically including:

[0016] 1.1 Select a specific example of privacy outsourcing computing, namely privacy financial situation analysis. In this scenario, a third-party institution decides whether to form a new company based on the financial situation of the users supporting the project. Existing users P1,…,P nWant to use assets u1, …, u on a confidential blockchain n to support their proposals, where the assets of these users are kept private using Pedersen commitments. The protocol aims to calculate the mean and variance without a third party knowing each user's assets to assist in decision-making: the mean must be close enough to a specified target value, and individual funds should not deviate far from the mean. Specifically, the participating parties execute the RLWE encryption algorithm to encrypt the message m: input the encryption public key and the message m ∈ S B , randomly select u, e1, e2 ∈ S B , define Calculate the ciphertext where: R q is the integer polynomial ring Z q [x] / (x d +1) and Z q = {-(q - 1) / 2, …, (q - 1) / 2}, is a 2-dimensional vector with elements in R q , S B is a subset of the integer polynomial ring R q whose maximum absolute value of the coefficients is B. For randomly selected dk, e ∈ S B , a ∈ R q , calculate ek = (ek0, ek1) = (-(a·dk + e), a).

[0017] Execute the Pedersen commitment algorithm to commit to k messages where Ξ ∈ Z k×4d represents any linear mapping, is the vector composed of the coefficients of the polynomial vector : input the generators f, u ∈ G, k messages randomly select calculate a set of commitment values where G is a cyclic group of prime order p, G k is a k-dimensional vector with elements in G, Z p represents a set {0, 1, …, p - 1}, is a k-dimensional vector with elements in z p , represents the vector obtained by taking the power of each component of f and the vector , operation represents the vector obtained by taking the power of each component of u and the vector , and the operator is the Kronecker product.

[0018] 1.2 To ensure that the participating parties honestly execute the RLWE encryption algorithm and the Pedersen commitment algorithm, in addition to providing other users with the ciphertext ct and a set of commitment values C, the participating parties also need to prove that the ciphertext is indeed computed from and is a set of short vectors, and the commitment values are indeed commitments to linear mappings. Integrating them into the proof framework gives The generality of this hybrid relationship lies in supporting any linear relationship between the plaintext encrypted by RLWE and the plaintext hidden by Pedersen commitments, as opposed to only supporting a certain fixed linear relationship in existing work.

[0019] Step 2, Initialize the common parameters for zero - knowledge proof. In addition to the statement of the zero - knowledge proof the common parameters that need to be initialized include: l = 4db+2db′∈Z, where: G l is an l - dimensional vector of elements in G, is the ceiling operation. Both the prover and the verifier need to execute this initialization algorithm.

[0020] Step 3, Generate a non - interactive zero - knowledge proof for the general hybrid relationship. Each user needs to prove to a third - party institution that the assets hidden by Pedersen commitments and the assets encrypted by RLWE are consistent, where the RLWE ciphertext will be used by the third - party institution for mean and variance calculations. According to the input perform the following proof: Calculate where rot(f)∈Z d×d is for a polynomial f = f0 + f1X+…+f d-1 X d-1 defines the matrix and the rot(·) operation can be extended to an input of a polynomial matrix; Integrate the evidence vector where: Bin(z)=(z0,…,z b-1 )∈{0,1} b is the binary representation of any integer z such that z = z0+z12+…+z b-2 2 b-2 -z b-1 2 b-1 , and the Bin(·) operation can be extended to an input of an integer vector; Calculate the complementary vector Calculate and record the partial proof and where This operation also applies to vectors composed of other elements in G and Zp The elements on it constitute the power operation of vectors; taking the public input and the already generated proofs w1, w2 as the input of the hash function, the following random number stream is output: Where: Calculate Where: is to invert each element in the vector and Calculate Where: (·) T is the transpose operation, is the tensor product operation, || represents the concatenation of vectors, Calculate Where O (l-n2db)×1 is a zero matrix of (l - 4db)×1 dimension; calculate and Calculate Calculate Calculate Execute the proof algorithms of sub - protocols IPSS and IPSP. The relation proved by the IPSS protocol is The relation proved is

[0021] Step 4, Verify the non - interactive zero - knowledge proof for the general mixed relation. After receiving the Pedersen commitments and RLWE encryptions of the assets from each user, the third - party institution first verifies the validity of the message by verifying the non - interactive zero - knowledge proof for the general mixed relation, secondly performs mean and variance operations on the RLWE ciphertexts of n users, and finally returns the encrypted operation results to each user. According to the complete proof obtained in Step 3 and perform the following verification calculations; taking the public input and the proofs w1, w2 as the input of the hash function, the following random number stream is output: Calculate Calculate Calculate Calculate and Calculate Execute the verification algorithms of sub - protocols IPSS and IPSP.

[0022] The described IPSS sub - protocol is implemented by, but not limited to, the technology described by del Pino et al. in "Short discrete log proofs for fhe and ring - lwe ciphertexts" ([C] / / 22nd edition of the International Conference on Practice and Theory of Public Key Cryptography. Springer International Publishing, 2019:344 - 373.).

[0023] The described IPSP sub - protocol is implemented by, but not limited to et al. in "PriBank: Confidential Blockchain Scaling Using Short Commit - and - Proof NIZK Argument" ([C] / / Cryptographers’ Track at the RSA Conference. Cham: Springer International Publishing, 2022:589 - 619.).

[0024] To ensure the security of the RLWE encryption scheme, in a specific instance, the 128 - bit quantum - resistant security parameters {d, q, B} = {1024, 2 16 , 1} are selected to generate ct; to ensure the security of the Pedersen commitment scheme, the group G is selected as the 256 - bit secure elliptic curve Secp256k1 in the instance. In this scenario, a set of messages hidden by the Pedersen commitment is the bit - by - bit concatenation of the plaintext messages hidden by the RLWE encryption scheme. Specifically, taking k = 1, the user's asset is a Pedersen commitment To perform privacy - asset analysis, the user additionally generates an RLWE ciphertext ct to encrypt the plaintext m = m0 + m1X+…+m 1023 X 1023 , m i ∈{0, 1}. The plaintext hidden by the Pedersen commitment is equal to m_0||…||m 255 ||0 1×768 . To prove the correctness of the RLWE ciphertext ct and the Pedersen commitment C0 generated in this scenario, it is integrated into the described proof framework to obtain where the linear mapping Ξ=(0 1×3d , 1, 2,..., 2255 , 0, ..., 0). After specific actual experiments, on a MacbookPro (Intel i7@2.3GHz , 16GB RAM), the above proof and verification steps were implemented, and the following experimental results were obtained. The length of the generated proof is 2074 bytes, and the execution times of each algorithm are shown in Table 1.

[0025] Table 1 Execution Time Test of Zero-Knowledge Proof Algorithm for General Hybrid Relations Name of cryptographic algorithm Time overhead (s) Initialization 2.95 Proof generation 2.98 Proof verification 0.89

[0026] In summary, compared with the prior art, the present method supports any linear mapping in the hybrid relation, and at the same time, the execution time of the proof generation algorithm and the length of the generated proof both reach the optimal level in the current zero-knowledge proof scheme for hybrid relations.

[0027] Those skilled in the art can make local adjustments to the above specific implementation in different ways without departing from the principles and purposes of the present invention. The protection scope of the present invention is subject to the claims and is not limited by the above specific implementation, and all implementation solutions within its scope are subject to the present invention.

Claims

1. A non-interactive zero-knowledge proof method for a universal mixing relation, characterized in that: include: Step 1: Integrate the requirements of the actual application scenario into a proof framework including an actual application scenario proof integration unit, a public parameter initialization unit, a zero-knowledge proof proof generation unit, and a zero-knowledge proof proof verification unit; Step 2: Zero-knowledge proof to initialize public parameters; Step 3: Generate a non-interactive zero-knowledge proof for the universal mixing relation; Step 4: Verify the non-interactive zero-knowledge proof for the universal mixing relation.

2. The non-interactive zero-knowledge proof method for a universal hybrid relation according to claim 1, characterized in that: In the actual application scenario unit, the participants execute the RLWE encryption algorithm and the Pedersen commitment algorithm to generate the RLWE ciphertext encrypted for the message m and the RLWE ciphertext encrypted for the message m. The Pedersen commitment of a commitment, where: m and In order to prevent malicious behavior of the protocol participants, the participants shall prove to other users that they have correctly executed the RLWE encryption algorithm and the Pedersen commitment algorithm. The actual application scenario abstracts the relationship to be proved unit, extracts the linear relationship between the RLWE ciphertext and the Pedersen commitment and the hidden evidence from the scenario, and obtains a specific mixed relationship. The public parameter initialization unit obtains the parameters for zero-knowledge proof initialization according to the specific mixed relationship. The proof generation unit of the zero-knowledge proof converts the mixed relationship into an inner product relationship according to the initialized parameters and calls the existing inner product proof component to generate a proof of the mixed relationship and returns it to the corresponding application scenario. The proof verification unit of the zero-knowledge proof performs inner product conversion and calls the existing inner product verification component according to the initialization parameters and the existing proof, thereby returning the acceptance / rejection result to the corresponding scenario.

3. The non-interactive zero-knowledge proof method for a universal hybrid relation according to claim 1 or 2, characterized in that: The step 1 specifically includes: 1.1 In the multi-party secure computation scenario, the participants execute the RLWE encryption algorithm to encrypt the message m: Input the encryption public key and message m∈S B , randomly select u,e1,e2∈S B ,definition Calculate ciphertext Where: R q is the ring of integer polynomials Z q [X] / (X d +1) and Z q ={-(q-1) / 2,…,(q-1) / 2}, For elements in R q The 2D vector on S B is the integer polynomial ring R q The subset whose coefficient has the maximum absolute value of B, for a randomly selected dk,e∈S B , a∈R q , calculate ek = (ek0, ek1) = (-(a·dk+e), a); execute the Pedersen commitment algorithm to commit k messages Ξ∈Z k×4d represents any linear mapping, is a polynomial vector The vector of coefficients: input generator f,u∈G, k messages Random Selection Calculate a set of commitment values G is a cyclic group of prime order p, G k is the k-dimensional vector of the element on G, Z p represents a set {0,1,…,p-1}, For elements in Z p k-dimensional vector on , represents f and vector The vector obtained by exponentially operating each component of Operations represent u and vectors The vector obtained by raising each component of is the Kronecker product; 1.2 In order to ensure that the participants honestly execute the RLWE encryption algorithm and the Pedersen commitment algorithm, in addition to providing the ciphertext ct and a set of commitment values ​​C to other users, the participants also need to prove that the ciphertext is indeed Calculated, and is a set of short vectors, the commitment value is indeed The promise of linear mapping, which is integrated into the proof framework, is The universality of this hybrid relationship lies in that it supports any linear relationship between the plaintext encrypted by RLWE and the plaintext hidden by Pedersen commitment, in contrast to existing work that only supports a fixed linear relationship.

4. The non-interactive zero-knowledge proof method for a universal hybrid relation according to claim 1 or 2, characterized in that: The zero-knowledge proof initialization public parameters are: Ξ∈Z k×4d ,C∈G k In addition to ,f,u∈G, the common parameters that need to be initialized include: l=4db+2db′∈Z, where: G l is the l-dimensional vector of the element on G, To perform the rounding operation, both the prover and the verifier need to execute the initialization algorithm.

5. The non-interactive zero-knowledge proof method for a universal hybrid relation according to claim 1 or 2, characterized in that: The generation of a non-interactive zero-knowledge proof for a universal mixing relation means: Ξ∈Z k×4d ,C∈G k ,f,u∈G, b,b′,l∈Z, Prove the following: Calculate A = rot(A)∈Z 2d×4d , Where: rot(f)∈Z d×d For a polynomial f = f0 + f1X + ... + f d-1 X d-1 The matrix defined And the rot(·) operation is extended to input a polynomial matrix; integrating the evidence vector Bin(z)=(z0,…,z b-1 )∈{0,1} b is the binary representation of any integer z. The Bin(·) operation is extended to integer vectors; the complement vector is calculated. Calculate and record partial proofs and in The same operation is applicable to other elements of G to form vectors and Z p The elements on the vector form a power operation; the public input and the currently generated proof w1, w2 are used as inputs to the hash function, and the following random number stream is output: calculate f′=f θ , is the vector Invert each element in calculate (·) T is the transpose operation, is the tensor product operation, || represents the concatenation of vectors, calculate in is a zero matrix of dimension (l-4db)×1; calculate and calculate Calculate o = o1η + o2, calculate Execute the proof algorithm of the sub-protocols IPSS and IPSP. The relationship proved by the IPSS protocol is The relationship proved by IPSP is 6. The non-interactive zero-knowledge proof method for a universal hybrid relation according to claim 1 or 2, characterized in that: The verification of the non-interactive zero-knowledge proof for the universal mixing relation refers to: the complete proof obtained in step 3 and Ξ∈Z k×4d ,C∈G k ,f,u∈G, b,b′,l∈Z, perform the following verification calculation; take the public input and proof w1,w2 as the input of the hash function, and output the following random number stream: calculate f′=f θ ;calculate calculate calculate and calculate Executes the verification algorithm of sub-protocols IPSS and IPSP.

Citation Information

Cited By

  • Privacy protection method and system for hybrid encryption strategy

    CN121000522A