Extensible cross-chain transaction privacy protection method based on currency mixing mechanism

By adopting a method based on a currency mixing mechanism in cross-chain transactions, updating the cross-chain Merkel tree and generating a proof of deposit, the problem of low scalability of cross-chain transactions is solved, and a transaction process with efficient privacy protection is achieved.

CN120217426APending Publication Date: 2025-06-27SHENZHEN UNIV
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510225412.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The scalability of cross-chain transactions is limited by the computing overhead and storage requirements brought by encryption processing, resulting in inefficiency in transactions.

Method used

Using a method based on the currency mixing mechanism, the cross-chain Merkel tree is updated by generating random numbers and promised values, generating deposit certificates, and verifying deposit certificates when withdrawing, so as to achieve transaction privacy protection without encrypting data.

Benefits of technology

It reduces the computing overhead and storage requirements of cross-chain transactions, improves transaction scalability and efficiency, and at the same time realizes the protection of transaction privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217426A_ABST
    Figure CN120217426A_ABST
Patent Text Reader

Abstract

The invention discloses an expandability cross-chain transaction privacy protection method based on a mixed currency mechanism, and relates to the technical field of block chain transactions, and the method comprises the steps: responding to a deposit instruction, generating a first random number and a second random number after successful deposit through a mixed currency contract in a source chain, generating a commitment value based on the first random number and the second random number; determining a target cross-chain Merkel tree based on the source chain and a target chain in the deposit instruction, and updating the target cross-chain Merkel tree based on the commitment value; based on the first random number, the second random number and the updated target cross-chain Merkel tree, a deposit proof is obtained, and the deposit proof is used for constructing a withdrawal instruction during withdrawal; and in response to the withdrawal instruction, verifying the to-be-verified deposit proof in the withdrawal instruction through the target chain, and printing money to the withdrawal address in the withdrawal instruction after the verification is successful. The technical scheme of the invention aims to solve the technical problem of how to improve the expandability of cross-chain transactions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of blockchain transactions, and particularly to a scalable cross-chain transaction privacy protection method based on a coin mixing mechanism. Background Art

[0002] Cross-chain transactions refer to the transfer and interaction of assets or data between different blockchain networks, which can improve the liquidity of data and assets. However, since transaction information on the blockchain is usually publicly transparent, in order to protect transaction privacy, cross-chain transactions often need to be encrypted. However, the encryption process may bring relatively large computational overhead and storage requirements, thus imposing certain limitations on the scalability of cross-chain transactions.

[0003] Therefore, how to improve the scalability of cross-chain transactions is a technical problem that those skilled in the art still need to solve. Summary of the Invention

[0004] The main purpose of this application is to provide a scalable cross-chain transaction privacy protection method based on a coin mixing mechanism, aiming to solve the technical problem of how to improve the scalability of cross-chain transactions.

[0005] To achieve the above object, this application proposes a scalable cross-chain transaction privacy protection method based on a coin mixing mechanism, and the method includes:

[0006] In response to a deposit instruction, after successfully depositing through the coin mixing contract in the source chain, generate a first random number and a second random number, and generate a commitment value based on the first random number and the second random number;

[0007] Based on the source chain and the target chain in the deposit instruction, determine the target cross-chain Merkle tree, and update the target cross-chain Merkle tree based on the commitment value;

[0008] Based on the first random number, the second random number, and the updated target cross-chain Merkle tree, obtain a deposit proof, and the deposit proof is used to construct a withdrawal instruction when withdrawing;

[0009] In response to a withdrawal instruction, verify the deposit proof to be verified in the withdrawal instruction through the target chain, and transfer funds to the withdrawal address in the withdrawal instruction after successful verification.

[0010] In one embodiment, the step of generating a commitment value based on the first random number and the second random number includes:

[0011] Concatenate the first random number and the second random number, and use the resulting value as the target value;

[0012] Use the hash value of the target value as the commitment value.

[0013] In one embodiment, the step of generating a commitment value based on the first random number and the second random number includes:

[0014] Obtain the ID value of the target chain in the deposit instruction;

[0015] Concatenate the first random number, the second random number, and the ID value, and use the resulting value as the target value;

[0016] Use the hash value of the target value as the commitment value.

[0017] In one embodiment, the step of obtaining a deposit proof based on the first random number, the second random number, and the updated target cross-chain Merkle tree includes:

[0018] In the updated target cross-chain Merkle tree, determine the path of the leaf node corresponding to the commitment value, and determine the set of hash values corresponding to the path;

[0019] Input the first random number, the second random number, the path, and the set of hash values into a preset zero-knowledge proof circuit to obtain a deposit proof.

[0020] In one embodiment, the method further includes:

[0021] Detect whether the commitment value exists in the target cross-chain Merkle tree;

[0022] If it is detected that the commitment value exists in the target cross-chain Merkle tree, return to execute the steps of generating the first random number and the second random number, and generating the commitment value based on the first random number and the second random number, until the new commitment value does not exist in the target cross-chain Merkle tree;

[0023] If it is detected that the commitment value does not exist in the target cross-chain Merkle tree, update the target cross-chain Merkle tree based on the commitment value.

[0024] In one embodiment, the step of verifying the deposit proof to be verified in the withdrawal instruction by the target chain includes:

[0025] Determine whether the deposit proof to be verified in the withdrawal instruction is valid through the coin mixing contract in the target chain;

[0026] If it is determined that the deposit proof to be verified is valid, detect whether the parameter value of the preset attribute of the leaf node corresponding to the deposit proof to be verified in the target cross-chain Merkle tree is a preset value;

[0027] If it is detected that the parameter value of the preset attribute is not the preset value, it is determined that the verification of the deposit certificate to be verified is successful.

[0028] In one embodiment, before the step of generating the first random number and the second random number after successful deposit through the coin mixing contract in the source chain, the method further includes:

[0029] Determine the target account based on the deposit instruction, and obtain the account balance in the target account;

[0030] If it is detected that the account balance is greater than or equal to the deposit amount corresponding to the deposit instruction, deposit through the coin mixing contract of the source chain.

[0031] In addition, to achieve the above object, the present application also proposes a cross-chain transaction privacy protection system with scalability based on the coin mixing mechanism, and the cross-chain transaction privacy protection system with scalability based on the coin mixing mechanism includes:

[0032] A commitment value generation module, configured to, in response to a deposit instruction, generate a first random number and a second random number after successful deposit through the coin mixing contract in the source chain, and generate a commitment value based on the first random number and the second random number;

[0033] A Merkle tree update module, configured to determine a target cross-chain Merkle tree based on the source chain and the target chain in the deposit instruction, and update the target cross-chain Merkle tree based on the commitment value;

[0034] A deposit certificate generation module, configured to obtain a deposit certificate based on the first random number, the second random number, and the updated target cross-chain Merkle tree, and the deposit certificate is used to construct a withdrawal instruction when withdrawing money;

[0035] A withdrawal verification module, configured to, in response to a withdrawal instruction, verify the deposit certificate to be verified in the withdrawal instruction through the target chain, and transfer money to the withdrawal address in the withdrawal instruction after successful verification.

[0036] In addition, to achieve the above object, the present application also proposes an electronic device, and the electronic device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the cross-chain transaction privacy protection method with scalability based on the coin mixing mechanism as described above.

[0037] In addition, to achieve the above object, the present application also proposes a storage medium, the storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, the steps of the cross-chain transaction privacy protection method with scalability based on the coin mixing mechanism as described above are implemented.

[0038] In an embodiment of the present application, in response to a deposit instruction, after successfully depositing through a coin mixing contract in the source chain, a first random number and a second random number are generated, and a commitment value is generated based on the first random number and the second random number; then, based on the source chain and the target chain in the deposit instruction, a target cross-chain Merkle tree is determined, and the target cross-chain Merkle tree is updated based on the commitment value; then, based on the first random number, the second random number, and the updated target cross-chain Merkle tree, a deposit proof is obtained, and the deposit proof is used to construct a withdrawal instruction during withdrawal; then, in response to a withdrawal instruction, the target chain verifies the deposit proof to be verified in the withdrawal instruction, and transfers funds to the withdrawal address in the withdrawal instruction after successful verification.

[0039] Thus, the present application can protect transaction privacy through coin mixing contracts on the source chain and the target chain without encrypting data. Therefore, the present application can improve the scalability of cross-chain transaction technology by reducing the computational overhead and storage requirements in cross-chain transactions. In addition, the present application also jointly maintains a cross-chain Merkle tree by the source chain and the target chain, and realizes seamless transfer of cross-chain assets by obtaining a deposit proof through the cross-chain Merkle tree, thereby improving the efficiency of cross-chain transactions. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.

[0041] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.

[0042] Figure 1 It is a schematic flowchart provided for the first embodiment of a cross-chain transaction privacy protection method with scalability based on a coin mixing mechanism according to the present application;

[0043] Figure 2 It is a schematic architecture diagram of an embodiment of a cross-chain transaction privacy protection method with scalability based on a coin mixing mechanism according to the present application;

[0044] Figure 3 It is a schematic deposit flowchart provided for an embodiment of a cross-chain transaction privacy protection method with scalability based on a coin mixing mechanism according to the present application;

[0045] Figure 4Schematic diagram of the withdrawal process provided by an embodiment of the cross-chain transaction privacy protection method with scalability based on the coin mixing mechanism in this application;

[0046] Figure 5 Schematic diagram of the Merkle tree structure and update provided by an embodiment of the cross-chain transaction privacy protection method with scalability based on the coin mixing mechanism in this application;

[0047] Figure 6 Schematic diagram of the module structure of the cross-chain transaction privacy protection system with scalability based on the coin mixing mechanism in the embodiments of this application;

[0048] Figure 7 Schematic diagram of the device structure of the hardware operating environment involved in the cross-chain transaction privacy protection method with scalability based on the coin mixing mechanism in the embodiments of this application.

[0049] The realization of the purpose, functional features and advantages of this application will be further described with reference to the embodiments and the accompanying drawings. Detailed implementation manners

[0050] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of this application and are not used to limit this application.

[0051] In order to better understand the technical solutions of this application, the following will be described in detail with reference to the accompanying drawings of the specification and the specific implementation manners.

[0052] It can be understood that cross-chain transactions refer to the transfer and interaction of assets or data between different blockchain networks, which can improve the liquidity of data and assets. However, since the transaction information on the blockchain is usually publicly transparent, in order to protect transaction privacy, cross-chain transactions often need to be encrypted. However, the encryption process may bring relatively large computational overhead and storage requirements, thus imposing certain limitations on the scalability of cross-chain transactions.

[0053] Therefore, how to improve the scalability of cross-chain transactions is a technical problem that those skilled in the art still need to solve.

[0054] To solve the above problems, in response to a deposit instruction, after successfully depositing through the coin mixing contract in the source chain, this application generates a first random number and a second random number, and generates a commitment value based on the first random number and the second random number; then determines a target cross-chain Merkle tree based on the source chain and the target chain in the deposit instruction, and updates the target cross-chain Merkle tree based on the commitment value; then obtains a deposit proof based on the first random number, the second random number, and the updated target cross-chain Merkle tree, and the deposit proof is used to construct a withdrawal instruction during withdrawal; then, in response to a withdrawal instruction, verifies the deposit proof to be verified in the withdrawal instruction through the target chain, and transfers funds to the withdrawal address in the withdrawal instruction after successful verification.

[0055] Thus, this application can protect transaction privacy through the coin mixing contracts on the source chain and the target chain without encrypting the data. Therefore, this application can improve the scalability of cross-chain transaction technology by reducing the computational overhead and storage requirements in cross-chain transactions. In addition, this application also jointly maintains the cross-chain Merkle tree by the source chain and the target chain, and realizes seamless transfer of cross-chain assets by obtaining the deposit proof through the cross-chain Merkle tree, thereby improving the efficiency of cross-chain transactions.

[0056] Based on the above, the embodiments of this application provide a scalable cross-chain transaction privacy protection method based on a coin mixing mechanism. Refer to Figure 1 , Figure 1 which is a schematic flowchart of the first embodiment of the scalable cross-chain transaction privacy protection method based on the coin mixing mechanism of this application.

[0057] In this embodiment, the scalable cross-chain transaction privacy protection method based on the coin mixing mechanism includes steps S10 to S40:

[0058] Step S10, in response to a deposit instruction, after successfully depositing through the coin mixing contract in the source chain, generate a first random number and a second random number, and generate a commitment value based on the first random number and the second random number;

[0059] It should be noted that the source chain refers to the blockchain where the transaction is initiated. The coin mixing contract refers to a technology that enhances user privacy protection by mixing cryptocurrency transactions. The first random number and the second random number are data generated by the coin mixing contract after the deposit is successful. In this embodiment, the user needs to pre-set the blockchain information for withdrawal during the deposit process to avoid the problem of double spending. In this embodiment, the blockchain pre-set by the user for withdrawal is the target chain. To maintain the consistency between the source chain and the target chain, the source chain and the target chain need to jointly maintain a global Merkle tree in advance, that is, the cross-chain Merkle tree. In this application, based on the deposit instruction output by the user, the source chain needs to generate a commitment value based on the first random number and the second random number, so as to update the cross-chain Merkle tree based on the commitment value.

[0060] In a feasible implementation manner, the above step S10 includes:

[0061] Step S101, concatenate the first random number and the second random number, and use the value obtained after concatenation as the target value;

[0062] It can be understood that the first random number and the second random number refer to large random numbers, which are used to prevent the repeated use of the same input value, thereby protecting the privacy of users.

[0063] Step S102, use the hash value of the target value as the commitment value.

[0064] Exemplarily, the first random number nullifier can be:

[0065] 0x123456789abcdef0123456789abcdef0123456789abcdef0123456789abc def0, and the second random number secret can be:

[0066] 0xfedcba9876543210fedcba9876543210fedcba9876543210fedcba9876543210. Then concatenate nullifier and secret to obtain the target value combined:

[0067] combined = nullifier || secret =

[0068] 0x123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef0fedcba9876543210fedcba9876543210fedcba9876453210fedcba9876543210;

[0069] Then, the commitment value can be:

[0070] commitment = hash(combined).

[0071] Thus, a commitment value for characterizing the deposit record can be obtained to update the cross-chain Merkle tree.

[0072] In a feasible implementation manner, the above step S10 includes:

[0073] Step S103, obtaining the ID value of the target chain in the deposit instruction;

[0074] Step S104, concatenating the first random number, the second random number, and the ID value, and using the concatenated value as the target value;

[0075] Step S105, using the hash value of the target value as the commitment value.

[0076] It should be noted that the ID value refers to a specific value that uniquely identifies the blockchain identity.

[0077] It can be understood that even if two different blockchains use the same random number, due to the different blockchain ID values, the generated commitment values will be different. Therefore, by adding the blockchain ID value in this application, the commitment value generated by each blockchain can have stronger uniqueness, thereby reducing the probability of commitment value repetition.

[0078] Step S20, determining a target cross-chain Merkle tree based on the source chain and the target chain in the deposit instruction, and updating the target cross-chain Merkle tree based on the commitment value;

[0079] It can be understood that the target cross-chain Merkle tree refers to the Merkle tree jointly maintained by the above source chain and target chain.

[0080] In this embodiment, after obtaining the commitment value and the target cross-chain Merkle tree, the commitment value can be used as the leaf node of the target cross-chain Merkle tree, thereby updating the values of the nodes in the target cross-chain Merkle tree layer by layer from bottom to top until the root hash value in the updated target cross-chain Merkle tree is obtained.

[0081] It can be understood that after updating the target cross-chain Merkle tree based on the commitment value, the updated Merkle tree records the deposit operation corresponding to the deposit instruction, thereby converting the streaming data into the leaf nodes in the Merkle tree and reducing the complexity of cross-chain transactions.

[0082] Step S30: Obtain a deposit certificate based on the first random number, the second random number, and the updated target cross-chain Merkle tree, where the deposit certificate is used to construct a withdrawal instruction during withdrawal;

[0083] It should be noted that the deposit certificate in this application is a zero-knowledge proof generated through a zero-knowledge proof circuit. Thus, when a user needs to withdraw money, the zero-knowledge proof can be used as the basis for withdrawal. Therefore, the user can withdraw money on the target chain without exposing their privacy. In addition, this application generates the deposit certificate only based on the first random number, the second random number, and the updated target cross-chain Merkle tree, reducing the computational overhead when generating the zero-knowledge proof and achieving the purpose of efficiently protecting privacy.

[0084] In a feasible implementation manner, the above step S30 includes:

[0085] Step S301: In the updated target cross-chain Merkle tree, determine the path of the leaf node corresponding to the commitment value, and determine the set of hash values corresponding to the path;

[0086] It can be understood that the path refers to the path from the root node of the target cross-chain Merkle tree to the leaf node corresponding to the commitment value. The set of hash values refers to the set composed of the hash values of each node in the path.

[0087] Step S302: Input the first random number, the second random number, the path, and the set of hash values into a preset zero-knowledge proof circuit to obtain a deposit certificate.

[0088] It can be understood that if the first random number, the second random number, the path, and the set of hash values are directly output to the user as the withdrawal proof, then when the user withdraws money, the first random number, the second random number, the path, and the set of hash values will be directly exposed in the blockchain, resulting in privacy leakage.

[0089] Therefore, in this application, the first random number, the second random number, the path, and the set of hash values are converted into a zero-knowledge proof through a zero-knowledge proof circuit. Thus, the user can prove that they know the first random number, the second random number, the path, and the set of hash values through the zero-knowledge proof without exposing the values.

[0090] Step S40: In response to the withdrawal instruction, verify the deposit certificate to be verified in the withdrawal instruction through the target chain, and transfer funds to the withdrawal address in the withdrawal instruction after successful verification.

[0091] It can be understood that when a user withdraws money, a withdrawal request needs to be initiated on the target chain set during the deposit. The deposit proof to be verified refers to the deposit proof in the withdrawal instruction. In an actual scenario, during the period from giving the deposit proof after the deposit to initiating a withdrawal request based on the deposit proof, there are risks such as the deposit proof being tampered with or forged. Therefore, the deposit proof included in the withdrawal request can be referred to as the deposit proof to be verified.

[0092] In this embodiment, since the target chain and the source chain jointly maintain the target cross-chain Merkle tree, the coin mixing contract in the target chain can verify the deposit proof to be verified in the withdrawal instruction based on the target cross-chain Merkle tree, and transfer funds to the withdrawal address in the withdrawal instruction after successful verification.

[0093] In a feasible implementation manner, the above step S40 includes:

[0094] Step S401, determining whether the deposit proof to be verified in the withdrawal instruction is valid through the coin mixing contract in the target chain;

[0095] Step S402, if it is determined that the deposit proof to be verified is valid, detecting whether the parameter value of the preset attribute of the leaf node corresponding to the deposit proof to be verified in the target cross-chain Merkle tree is a preset value;

[0096] Step S403, if it is detected that the parameter value of the preset attribute is not the preset value, determining that the deposit proof to be verified is successfully verified.

[0097] It can be understood that the coin mixing contract in the target chain can determine whether the deposit proof to be verified is valid based on the target cross-chain Merkle tree. However, even if the deposit proof to be verified is valid, that is, there is a leaf node corresponding to the deposit proof to be verified in the target cross-chain Merkle tree, it is also necessary to determine whether the money has been withdrawn according to the parameter value of the preset attribute of the leaf node. Therefore, after determining that the deposit proof to be verified is valid, it is also necessary to determine whether the parameter value of the preset attribute of this leaf node is a preset value, so as to determine whether the deposit amount marked by this leaf node has been withdrawn.

[0098] It can be understood that the preset value is a value preset to indicate that the money has been withdrawn. Therefore, when it is detected that the parameter value of the preset attribute of this leaf node is not the same as the preset value, it can be determined that the deposit amount corresponding to this leaf node has not been withdrawn. Therefore, it can be determined that the deposit proof to be verified is successfully verified and meets the conditions for withdrawing money. Thus, the coin mixing contract on the target chain can transfer funds to the payment address in the withdrawal instruction.

[0099] In an embodiment of the present application, in response to a deposit instruction, after successfully depositing through a coin mixing contract in the source chain, a first random number and a second random number are generated, and a commitment value is generated based on the first random number and the second random number; then, based on the source chain and the target chain in the deposit instruction, a target cross-chain Merkle tree is determined, and the target cross-chain Merkle tree is updated based on the commitment value; then, based on the first random number, the second random number, and the updated target cross-chain Merkle tree, a deposit proof is obtained, and the deposit proof is used to construct a withdrawal instruction during withdrawal; then, in response to a withdrawal instruction, the target chain verifies the deposit proof to be verified in the withdrawal instruction, and transfers funds to the withdrawal address in the withdrawal instruction after successful verification.

[0100] Thus, the present application can protect transaction privacy through the coin mixing contracts on the source chain and the target chain without encrypting the data. Therefore, the present application can improve the scalability of cross-chain transaction technology by reducing the computational overhead and storage requirements in cross-chain transactions. In addition, the present application also jointly maintains the cross-chain Merkle tree by the source chain and the target chain, and realizes the seamless transfer of cross-chain assets by obtaining the deposit proof through the cross-chain Merkle tree, thereby improving the efficiency of cross-chain transactions.

[0101] Further, based on the first embodiment of the method for protecting cross-chain transaction privacy with scalability based on the coin mixing mechanism of the present application, a second embodiment of the method for protecting cross-chain transaction privacy with scalability based on the coin mixing mechanism of the present application is proposed.

[0102] In this embodiment, the method for protecting cross-chain transaction privacy with scalability based on the coin mixing mechanism further includes:

[0103] Step S100, detecting whether the commitment value exists in the target cross-chain Merkle tree;

[0104] Step S200, if it is detected that the commitment value exists in the target cross-chain Merkle tree, then return to execute the steps of generating the first random number and the second random number, and generating the commitment value based on the first random number and the second random number, until the new commitment value does not exist in the target cross-chain Merkle tree;

[0105] Step S300, if it is detected that the commitment value does not exist in the target cross-chain Merkle tree, then update the target cross-chain Merkle tree based on the commitment value.

[0106] It can be understood that the value of each leaf node in the target cross-chain Merkle tree is used to represent a transaction. To avoid different transactions being represented as the same leaf node in the target cross-chain Merkle tree, after obtaining the commitment value, it is also necessary to detect whether the currently obtained commitment value already exists in the target cross-chain Merkle tree. If the current commitment value already exists in the target cross-chain Merkle tree, it is necessary to regenerate the first random number and the second random number to generate a new commitment value. Of course, when the current commitment value does not exist in the target cross-chain Merkle tree, the current commitment value can be used as a leaf node and the target cross-chain Merkle tree can be updated.

[0107] In this embodiment, the present application can avoid the problem of different transactions being confused with each other by detecting whether the calculated commitment value exists in the target cross-chain Merkle tree, thereby improving the accuracy of cross-chain transactions.

[0108] Furthermore, based on the first embodiment and / or the second embodiment of the method for protecting the privacy of cross-chain transactions with scalability based on the coin mixing mechanism of the present application, a third embodiment of the method for protecting the privacy of cross-chain transactions with scalability based on the coin mixing mechanism of the present application is proposed.

[0109] In this embodiment, before the above step S10, the method further includes:

[0110] Step S400, determining a target account based on the deposit instruction and obtaining the account balance in the target account;

[0111] It can be understood that the target account refers to the account of the user who outputs the deposit instruction.

[0112] Step S500, if it is detected that the account balance is greater than or equal to the deposit amount corresponding to the deposit instruction, deposit through the coin mixing contract of the source chain.

[0113] It can be understood that if the account balance in the target account is less than the deposit amount corresponding to the deposit instruction, then there must be an error in the deposit instruction. Therefore, at this time, the user needs to re-determine the deposit amount. Of course, when it is detected that the account balance is greater than or equal to the deposit amount corresponding to the deposit instruction, the deposit can be made through the coin mixing contract of the source chain based on the deposit instruction.

[0114] In this embodiment, the present application can avoid errors in deposit instructions by comparing the account balance and the deposit amount, thereby improving the accuracy of cross-chain transactions.

[0115] Furthermore, based on the above various embodiments of the method for protecting the privacy of cross-chain transactions with scalability based on the coin mixing mechanism of the present application, a specific embodiment of the method for protecting the privacy of cross-chain transactions with scalability based on the coin mixing mechanism of the present application is proposed.

[0116] Please refer to Figure 2 , Figure 2 The architecture diagram shown shows the relationship between Chain A (source chain), Chain B (target chain), cross-chain communication module, coin mixer contract, and cross-chain Merkle tree (target cross-chain Merkle tree). Chain A and Chain B achieve key information interaction through the cross-chain communication module. The coin mixer contract is deployed on both Chain A and Chain B, responsible for handling user deposits and withdrawals. The cross-chain Merkle tree is jointly maintained by Chain A and Chain B and is the core structure to ensure cross-chain data consistency and verification.

[0117] Please refer to Figure 3 , Figure 3 This is the deposit flow chart of this application. In Figure 3 it shows the detailed process of depositing in the coin mixer contract on Chain A. Specifically, after the deposit is successful, a random number nullfier and a secret are generated, and the target chain is determined according to the deposit instruction to obtain the target chain ID (dstchainID). Then calculate the commitment value: commitment = Hash(nullfier || secret || dstchainID). Subsequently, the commitment is submitted to the smart contract, and the contract inserts the commitment into the Merkle tree as a leaf node, updates the commitment root hash and stores it in the contract. At the same time, a zero-knowledge proof is also generated on the source chain to prove that the user knows the nullfier and the secret without revealing the specific values. After the transaction is completed, the new root hash is synchronized to Chain B through the cross-chain communication module.

[0118] Please refer to Figure 4 , Figure 4 This is the withdrawal flow chart of this application. Figure 4 The withdrawal flow chart presents the steps of withdrawing in the coin mixer contract on Chain B. Specifically, when withdrawing, a deposit proof and a withdrawal address need to be given, and then the coin mixer contract verifies the validity of the deposit proof and checks whether the commitment has not been used by calculating whether nullfierhash (preset attribute) is true (preset value). If the verification passes, the smart contract transfers the funds to the user-specified withdrawal address and marks the commitment as used (that is, sets the parameter value of nullfierhash of this commitment node to true) to prevent double withdrawals.

[0119] Please refer to Figure 5 , Figure 5 This is the structure and update schematic diagram of the target cross-chain Merkle tree of this application. In Figure 5The initial structure of the cross-chain Merkle tree is shown, where each leaf node corresponds to a user's commitment. When a new deposit occurs, the new commitment is added as a leaf node to the Merkle tree, triggering the recalculation of the hash values of the relevant nodes and then updating the root hash. In the withdrawal operation, if the commitment is marked as used, the Merkle tree will also be adjusted accordingly to reflect the latest state, ensuring that the Merkle tree always accurately records the state of cross-chain transactions.

[0120] In this application, the Pedersen commitment scheme is used to generate the commitment, and combined with the randomly generated nullifier and secret, it can protect transaction privacy. Specifically, when multiple users deposit the same amount in the coin mixing contract, the way of generating the commitment value based on the nullifier and secret in this application can make it difficult for external observers to associate the transaction with the user address, effectively confusing the users' deposit behaviors and greatly ensuring user privacy. In addition, the zero-knowledge proof adopts the groth16 algorithm, which can efficiently prove that the user knows the nullifier and secret without revealing the specific values, further strengthening the effect of privacy protection.

[0121] In addition, in this application, the introduction of the cross-chain Merkle tree enables Chain A and Chain B to jointly maintain the global data state. By synchronizing the root hash, both parties can quickly verify whether the transaction data on the other chain has been tampered with, greatly improving the efficiency of cross-chain verification. The contract checks whether the commitment has been used by calculating the nullifier hash, ensuring the uniqueness and security of the transaction and avoiding the occurrence of duplicate withdrawals. The design of the cross-chain Merkle tree allows new leaf nodes, that is, new user commitments, to be easily added, enabling it to accommodate the joining of more users. At the same time, the design of the cross-chain communication module supports the access of more blockchains in the future and has good scalability. The operation processes in the deposit and withdrawal stages are simple and clear, and the smart contract automatically executes the verification and update operations, reducing manual intervention and greatly improving the transaction processing efficiency.

[0122] In addition, compared with the privacy protection scheme that encrypts the user account based on pure zero-knowledge proof, this application only performs zero-knowledge proof on the commitment, greatly reducing the computational overhead. In addition, this application also uses the Pedersen commitment to generate the commitment and combines the groth16 algorithm for zero-knowledge proof, so as to be able to improve the transaction processing efficiency while effectively protecting user privacy, and thus can achieve efficient privacy protection under limited resources.

[0123] In summary, the present application proposes an efficient and secure cross-chain transaction solution by introducing a cross-chain Merkle tree, zero-knowledge proof, and coin mixing contract. This solution not only enables seamless transfer of cross-chain assets but also enhances the security and user experience of the system through privacy protection and data consistency mechanisms.

[0124] In addition, it should be noted that in a feasible implementation, during the deposit stage, a homomorphic encryption algorithm can also be used to encrypt the deposit amount and the target chain, and then directly send the ciphertext to the cross-chain smart contract. Then, the cross-chain smart contract can perform operations on the ciphertext without decrypting it, such as verifying whether the deposit amount is sufficient. During the withdrawal stage, the cross-chain smart contract can transfer the corresponding encrypted funds based on the verification result, and finally, the recipient decrypts it. In this embodiment, the present application can also reduce the computational cost of the encryption steps by only encrypting the deposit amount and the target chain. Thus, the present application can balance low cost and the security of cross-chain transactions.

[0125] It should be noted that the above examples are only for understanding the present application and do not constitute a limitation on the scalable cross-chain transaction privacy protection method of the present application based on the coin mixing mechanism. More simple transformations in various forms based on this technical concept are within the protection scope of the present application.

[0126] The present application also provides a scalable cross-chain transaction privacy protection system based on the coin mixing mechanism. Please refer to Figure 6 , the scalable cross-chain transaction privacy protection system based on the coin mixing mechanism includes:

[0127] A commitment value generation module 10, configured to generate a first random number and a second random number in response to a deposit instruction after successful deposit through a coin mixing contract in the source chain, and generate a commitment value based on the first random number and the second random number;

[0128] A Merkle tree update module 20, configured to determine a target cross-chain Merkle tree based on the source chain and the target chain in the deposit instruction, and update the target cross-chain Merkle tree based on the commitment value;

[0129] A deposit proof generation module 30, configured to obtain a deposit proof based on the first random number, the second random number, and the updated target cross-chain Merkle tree, where the deposit proof is used to construct a withdrawal instruction during withdrawal;

[0130] A withdrawal verification module 40, configured to verify the deposit proof to be verified in the withdrawal instruction through the target chain in response to the withdrawal instruction, and transfer funds to the withdrawal address in the withdrawal instruction after successful verification.

[0131] In one embodiment, the commitment value generation module 10 is further configured to:

[0132] Concatenate the first random number and the second random number, and use the resulting value after concatenation as the target value;

[0133] Use the hash value of the target value as the commitment value.

[0134] In one embodiment, the commitment value generation module 10 is further configured to:

[0135] Obtain the ID value of the target chain in the deposit instruction;

[0136] Concatenate the first random number, the second random number, and the ID value, and use the resulting value after concatenation as the target value;

[0137] Use the hash value of the target value as the commitment value.

[0138] In one embodiment, the deposit certificate generation module 30 is further configured to:

[0139] In the updated target cross-chain Merkle tree, determine the path of the leaf node corresponding to the commitment value, and determine the set of hash values corresponding to the path;

[0140] Input the first random number, the second random number, the path, and the set of hash values into a preset zero-knowledge proof circuit to obtain a deposit certificate.

[0141] In one embodiment, the scalable cross-chain transaction privacy protection system based on the coin mixing mechanism further includes:

[0142] A numerical detection module, configured to detect whether the commitment value exists in the target cross-chain Merkle tree;

[0143] A loop module, configured to, if it is detected that the commitment value exists in the target cross-chain Merkle tree, return to execute the steps of generating the first random number and the second random number, and generating the commitment value based on the first random number and the second random number, until a new commitment value does not exist in the target cross-chain Merkle tree;

[0144] A transfer module, configured to, if it is detected that the commitment value does not exist in the target cross-chain Merkle tree, update the target cross-chain Merkle tree based on the commitment value.

[0145] In one embodiment, the withdrawal verification module 40 is further configured to:

[0146] Determine whether the deposit certificate to be verified in the withdrawal instruction is valid through the coin mixing contract in the target chain;

[0147] If it is determined that the deposit certificate to be verified is valid, then it is detected whether the parameter value of the preset attribute of the leaf node corresponding to the deposit certificate to be verified in the target cross-chain Merkle tree is a preset value;

[0148] If it is detected that the parameter value of the preset attribute is not the preset value, it is determined that the verification of the deposit certificate to be verified is successful.

[0149] In one embodiment, the scalable cross-chain transaction privacy protection system based on the coin mixing mechanism further includes:

[0150] An account information acquisition module, configured to determine a target account based on the deposit instruction and acquire the account balance in the target account;

[0151] A deposit module, configured to, if it is detected that the account balance is greater than or equal to the deposit amount corresponding to the deposit instruction, perform a deposit through the coin mixing contract of the source chain.

[0152] The scalable cross-chain transaction privacy protection system based on the coin mixing mechanism provided in this application adopts the scalable cross-chain transaction privacy protection method based on the coin mixing mechanism in the above embodiment, and can solve the technical problem of how to improve the scalability of cross-chain transactions. Compared with the prior art, the beneficial effects of the scalable cross-chain transaction privacy protection system based on the coin mixing mechanism provided in this application are the same as those of the scalable cross-chain transaction privacy protection method based on the coin mixing mechanism provided in the above embodiment, and other technical features in the scalable cross-chain transaction privacy protection system based on the coin mixing mechanism are the same as the features disclosed in the method of the above embodiment, and will not be elaborated here.

[0153] This application provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the scalable cross-chain transaction privacy protection method based on the coin mixing mechanism in the first embodiment above.

[0154] Next, refer to Figure 7 , which shows a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present application. Figure 7 The electronic device shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.

[0155] As Figure 7As shown, the electronic device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in the read-only memory 1002 or a program loaded from the storage device 1003 into the random access memory 1004. In the random access memory 1004, various programs and data required for the operation of the electronic device are also stored. The processing device 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other through a bus 1005. The input / output interface 1006 is also connected to the bus. Generally, the following systems may be connected to the input / output interface 1006: an input device 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the electronic device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows an electronic device with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems may be implemented or had alternatively.

[0156] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from the network through the communication device, or installed from the storage device 1003, or installed from the read-only memory 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are executed.

[0157] The electronic device provided by the present application adopts the scalable cross-chain transaction privacy protection method based on the coin mixing mechanism in the above embodiments, and can solve the technical problem of how to improve the scalability of cross-chain transactions. Compared with the prior art, the beneficial effects of the electronic device provided by the present application are the same as those of the scalable cross-chain transaction privacy protection method based on the coin mixing mechanism provided in the above embodiments, and other technical features in the electronic device are the same as the features disclosed in the method of the previous embodiment, and will not be elaborated here.

[0158] It should be understood that each part disclosed in this application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0159] As described above, the above are only specific embodiments of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0160] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the scalable cross-chain transaction privacy protection method based on the coin mixing mechanism in the above embodiments.

[0161] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.

[0162] The above computer-readable storage medium can be included in an electronic device; or it can exist separately without being assembled into the electronic device.

[0163] The above computer-readable storage medium carries one or more programs, which, when executed by an electronic device, cause the electronic device to: in response to a deposit instruction, after successfully depositing through a coin mixing contract in the source chain, generate a first random number and a second random number, and generate a commitment value based on the first random number and the second random number; determine a target cross-chain Merkle tree based on the source chain and the target chain in the deposit instruction, and update the target cross-chain Merkle tree based on the commitment value; obtain a deposit proof based on the first random number, the second random number, and the updated target cross-chain Merkle tree, where the deposit proof is used to construct a withdrawal instruction during withdrawal; in response to a withdrawal instruction, verify the deposit proof to be verified in the withdrawal instruction through the target chain, and transfer funds to the withdrawal address in the withdrawal instruction after successful verification.

[0164] Computer program code for performing the operations of this application may be written in one or more programming languages or combinations thereof. The above programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).

[0165] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0166] The modules involved in the embodiments of the present application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation on the unit itself in some cases.

[0167] The readable storage medium provided by the present application is a computer-readable storage medium, and the computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned scalable cross-chain transaction privacy protection method based on the coin mixing mechanism, which can solve the technical problem of how to improve the scalability of cross-chain transactions. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as those of the scalable cross-chain transaction privacy protection method based on the coin mixing mechanism provided by the above embodiments, and will not be elaborated here.

[0168] The above are only some embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structural transformation made by using the content of the specification and drawings of the present application under the technical concept of the present application, or direct / indirect application in other related technical fields, is included in the patent protection scope of the present application.

Claims

1. A scalable cross-chain transaction privacy protection method based on a coin mixing mechanism, characterized in that: The scalable cross-chain transaction privacy protection method based on the currency mixing mechanism includes: In response to the deposit instruction, after the deposit is successfully made through the coin-mixing contract in the source chain, a first random number and a second random number are generated, and a commitment value is generated based on the first random number and the second random number; Determine a target cross-chain Merkle tree based on the source chain and the target chain in the deposit instruction, and update the target cross-chain Merkle tree based on the commitment value; Based on the first random number, the second random number and the updated target cross-chain Merkle tree, a deposit certificate is obtained, where the deposit certificate is used to construct a withdrawal instruction when withdrawing money; In response to a withdrawal instruction, the deposit certificate to be verified in the withdrawal instruction is verified through the target chain, and after successful verification, the money is transferred to the withdrawal address in the withdrawal instruction.

2. The scalable cross-chain transaction privacy protection method based on the currency mixing mechanism as claimed in claim 1 is characterized in that: The step of generating a commitment value based on the first random number and the second random number comprises: Concatenate the first random number and the second random number, and use the concatenated value as the target value; The hash value of the target value is used as the commitment value.

3. The scalable cross-chain transaction privacy protection method based on the currency mixing mechanism as claimed in claim 1 is characterized in that: The step of generating a commitment value based on the first random number and the second random number comprises: Obtain the ID value of the target chain in the deposit instruction; Concatenate the first random number, the second random number, and the ID value, and use the concatenated value as the target value; The hash value of the target value is used as the commitment value.

4. The scalable cross-chain transaction privacy protection method based on the currency mixing mechanism as claimed in claim 1 is characterized in that: The step of obtaining a deposit certificate based on the first random number, the second random number and the updated target cross-chain Merkle tree includes: In the updated target cross-chain Merkle tree, determine the path of the leaf node corresponding to the commitment value, and determine the set of hash values ​​corresponding to the path; The first random number, the second random number, the path and the hash value set are input into a preset zero-knowledge proof circuit to obtain a deposit certificate.

5. The scalable cross-chain transaction privacy protection method based on the currency mixing mechanism as claimed in claim 1 is characterized in that: The method further comprises: Detecting whether the commitment value exists in the target cross-chain Merkle tree; If it is detected that the commitment value exists in the target cross-chain Merkle tree, returning to execute the steps of generating the first random number and the second random number, and the steps of generating the commitment value based on the first random number and the second random number, until the new commitment value does not exist in the target cross-chain Merkle tree; If it is detected that the commitment value does not exist in the target cross-chain Merkle tree, the target cross-chain Merkle tree is updated based on the commitment value.

6. The scalable cross-chain transaction privacy protection method based on the currency mixing mechanism as claimed in claim 1 is characterized in that: The step of verifying the deposit certificate to be verified in the withdrawal instruction through the target chain includes: Determine whether the deposit certificate to be verified in the withdrawal instruction is valid through the coin mixing contract in the target chain; If it is determined that the deposit certificate to be verified is valid, detecting whether the parameter value of the preset attribute of the leaf node corresponding to the deposit certificate to be verified in the target cross-chain Merkle tree is a preset value; If it is detected that the parameter value of the preset attribute is not the preset value, it is determined that the verification of the deposit certificate to be verified is successful.

7. The scalable cross-chain transaction privacy protection method based on the currency mixing mechanism as claimed in claim 1 is characterized in that: Before the step of generating the first random number and the second random number after the deposit is successfully made through the mixing contract in the source chain, the method further includes: Determine a target account based on the deposit instruction, and obtain an account balance in the target account; If it is detected that the account balance is greater than or equal to the deposit amount corresponding to the deposit instruction, the deposit is made through the mixing contract of the source chain.

8. A scalable cross-chain transaction privacy protection system based on a coin mixing mechanism, characterized in that: The scalable cross-chain transaction privacy protection system based on the currency mixing mechanism includes: A commitment value generation module, configured to generate a first random number and a second random number in response to a deposit instruction after a successful deposit through a mixing contract in a source chain, and to generate a commitment value based on the first random number and the second random number; A Merkle tree update module, configured to determine a target cross-chain Merkle tree based on the source chain and the target chain in the deposit instruction, and update the target cross-chain Merkle tree based on the commitment value; A deposit certificate generation module, used to obtain a deposit certificate based on the first random number, the second random number and the updated target cross-chain Merkle tree, wherein the deposit certificate is used to construct a withdrawal instruction when withdrawing money; The withdrawal verification module is used to respond to a withdrawal instruction, verify the deposit certificate to be verified in the withdrawal instruction through the target chain, and transfer funds to the withdrawal address in the withdrawal instruction after successful verification.

9. An electronic device, characterized in that: The electronic device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of a scalable cross-chain transaction privacy protection method based on a mixing coin mechanism as described in any one of claims 1 to 7.

10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the scalable cross-chain transaction privacy protection method based on a mixing currency mechanism as described in any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Dynamic updatable zero-knowledge proof commitment method and system supporting cross-chain transaction

    CN122155719A