Requity proof consensus algorithm-oriented pledge hidden deterministic drawing method

By constructing Pedersen commitment and fully homomorphic encryption technology, the pledge distribution in the proof of stake consensus system is solved, and the security problems caused by public pledge distribution and the stability of probabilistic lottery elections are achieved, and the privacy protection of deterministic secret leader node lottery elections and pledge distributions is achieved.

CN120223302APending Publication Date: 2025-06-27BEIJING INST OF TECH +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510410658.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In the existing proof of stake consensus system, the public stake distribution exposes large pledge nodes and becomes the key target of the attack. At the same time, there is a risk of re-election and forking in the probabilistic lottery election.

Method used

A pledge hidden deterministic drawing method for proof of stake consensus algorithm is proposed. By constructing Pedersen's promise hidden pledge distribution, combining fully homomorphic encryption and secret sharing technology, the confidentiality and certainty of the election process are ensured.

Benefits of technology

Deterministic secret leader node lottery elections are implemented while hiding the staking distribution, avoiding the risks of re-election and forking, and protecting the privacy of the staking distribution, reducing the risk of large staking nodes being attacked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SMS_10
    Figure SMS_10
  • Figure SMS_11
    Figure SMS_11
  • Figure SMS_12
    Figure SMS_12
Patent Text Reader

Abstract

The pledge hiding deterministic drawing method for the equity proof consensus algorithm is combined with a commitment technology, a secret key homomorphic pseudo-random function technology, a secret sharing technology, a zero-knowledge proof technology and a threshold fully homomorphic encryption technology, pledge distribution is hidden, and meanwhile, the determinacy of leader node drawing election is ensured; and unpredictability and fairness are realized. Specifically, the method comprises the following steps: constructing Pedersen commitment to hide pledge distribution; confidentiality and certainty of the election process are guaranteed through fully homomorphic encryption calculation; a pseudo-random number generated in a distributed mode is constructed by combining a secret sharing technology and a secret key homomorphic pseudo-random function technology, so that unpredictability of lot drawing election is ensured; and a zero-knowledge proof scheme is constructed by combining a secret sharing technology on the basis of a cut and check strategy, so that the consistency of encrypted election ciphertext input and pledge commitment and the correctness of a distributed pseudo-random number are ensured, and the election fairness is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of blockchain consensus algorithms, and more particularly to the field of lottery algorithms applicable to proof-of-stake consensus algorithms, and specifically relates to a staking hidden deterministic lottery method for proof-of-stake consensus algorithms. Background Art

[0002] Blockchain technology has become the core foundation of decentralized systems and applications, and its consensus mechanism plays a crucial role in ensuring system security and consistency. Proof-of-Stake (PoS), as a widely adopted consensus mechanism, selects leader nodes by staking tokens in a lottery. However, the process of publicly selecting leader nodes in a proof-of-stake system may lead to serious security problems. During the period when the leader node is selected and packs blocks, the public identity of the leader node makes it vulnerable to malicious behaviors such as Denial-of-Service (DoS) attacks, thus affecting the normal operation of the system.

[0003] To address this challenge, some studies [1-4] have proposed Secret Leader Election schemes, where the identity of the leader node remains secret until the block is produced. For example, schemes such as Algoran [3] and Ouroboros [4] use probabilistic election mechanisms to conduct a lottery for the secret leader node. These schemes have, to some extent, solved the problem of leader node attacks in the proof-of-stake system. However, the probabilistic lottery election mechanism has also brought new problems. Due to the uncertainty of the lottery results, there may be a situation where no leader node is produced, leading to a re-election, or multiple leader nodes are produced, leading to a blockchain fork. These problems will seriously affect the stability and efficiency of the system. In response, Boneh et al. [5] proposed a deterministic secret leader node lottery election scheme called Single Secret Leader Election (SSLE) in 2020. SSLE ensures that a unique and deterministic leader node is produced in each round of lottery election, thus avoiding the zero-production and fork problems in probabilistic lottery elections. However, current deterministic secret leader node lottery election schemes [6-12] all rely on public stake distributions when applied to the proof-of-stake consensus system. The public stake distribution exposes large stake nodes, and these nodes have a higher probability of becoming leader nodes due to their large stake amounts, thus becoming the key targets of attacks. Although there are currently some secret leader node lottery election schemes [2][4] that hide the stake distribution, they achieve privacy protection by using zero-knowledge proofs to prove the relationship between the verifiable random function (VRF) values generated by users and their stake amounts. However, these schemes are only effective in probabilistic lottery elections and are not applicable to deterministic secret leader node lottery elections because deterministic secret leader node lottery elections do not rely on VRF. Therefore, there is an urgent need to design a deterministic secret leader node lottery election method that hides the stake distribution to address the deficiencies in existing schemes, enabling it to achieve both privacy protection for the stake distribution and deterministic secret leader node lottery elections, and promoting the development of proof-of-stake consensus. Summary of the Invention

[0004] The present invention aims to address the deficiencies of existing methods and proposes a stake-hiding deterministic lottery method for the proof-of-stake consensus algorithm, which protects the privacy of the stake distribution while avoiding the risks of re-election and fork faced by probabilistic lottery elections.

[0005] A stake-hiding deterministic lottery method for the proof-of-stake consensus algorithm is as follows:

[0006] Assume that there are T participants in the lottery election, namely P1, …, P T ;

[0007] Step 1: Generate public parameters and function definitions

[0008] Generate the common parameters Setup(1 λ ) -> pp(λ, p, q, G, g, h, N, σ, μ, ν), where λ is the set security parameter, and the common parameters are generated according to λ; P is a large prime number of λ bits; q is a large prime factor of -1; G is a cyclic subgroup with modulus p and order for Pedersen commitment; G' is another cyclic subgroup with modulus p and order q for discrete logarithm encryption; g is a generator in the cyclic group G; h is another generator in G, satisfying h = g x , where x is a secret value randomly selected in ; g' is a generator in the cyclic group G'; k is the length of the private key vector in the FHE algorithm based on the TRLWE problem; m is the number of rows of the random matrix in the key-homomorphic PRF based on LWE, m >> k; N is the order of the binary polynomial ring B[x] / (x N + 1) and the Torus polynomial ring T q [x] / (x N + 1) used in the FHE algorithm based on the TRLWE problem; σ is the standard deviation of the Gaussian distribution for noise sampling in the FHE algorithm based on the TRLWE problem; μ is the mean of the Gaussian distribution for noise sampling in the FHE algorithm based on the TRLWE problem; ν(μ, σ2) is the Gaussian distribution for noise sampling in the FHE algorithm based on the TRLWE problem;

[0009] The function definition includes the following:

[0010] ThFHE: A threshold fully homomorphic encryption scheme based on the TRLWE problem, consisting of 6 probabilistic polynomial-time algorithms, specifically as follows:

[0011] Th FHE

[0012] = (Th FHE.Setup, Th FHE.Enc, Th FHE.Eval, Th FHE.PartDec, Th FHE.FinDec)

[0013] Suppose there are N' participants: Pt = {Pt1,..., PtN'}, and the threshold is n', then there are:

[0014] Th FHE.Setup(λ, N′, n′) → (PK, sk1,...skN'), where λ in the input is the security parameter, and the output is a public key PK and N' partial private keys;

[0015] Th FHE.Enc(PK, x) → Cx, where x in the input is the secret value and PK is the public key, and the output is the fully homomorphically encrypted ciphertext value;

[0016] The FHE.Eval(PK, Circuit, Inputs) → Cy, where PK is the public key in the input, Circuit is the computing circuit, Inputs is the input of the computing circuit, and the output Cy is the computing result;

[0017] The FHE.PartDec(PK, Cts, SKi) → Dts piecei , with the input being the public key PK, the ciphertext Cts, and the partial secret key SKi, and the output Dts being the decryption shard of Dts piecei ;

[0018] The FHE.FinDec(PK, Cts, Dts pieces ) → ts: The input is the public key PK, the ciphertext Cts, and n' partial decryption shards Dts pieces , and the output is the decrypted result plaintext ts;

[0019] SecretSharing is a linear threshold secret sharing function. Given a secret value sv, N' participants, and a threshold of n', then: SecretSh aring(sv) = (sv piece1 ,..., sv pieceN′ );

[0020] Step 2: Each participant Pi generates and publishes a pledge commitment CM i , and the participant randomly selects a random number R q in Z i , and generates a Pedersen commitment of the pledge value according to its own pledge value STK i : The participant publicly publishes CM i ;

[0021] Step 3: The participants distributively generate the complete public key, the decryption key shards, calculate the shard public keys, and publish the shard public keys;

[0022] Step 4: Distributively generate a random seed sd1. Each participant Pi selects a random value Rnd q on Z i ; sd1 = Rnd1 xor Rnd2 xor... xor Rnd T ;

[0023] Step 5: Participant Pi generates a pseudo-random number shard PPRFi based on the random seed sd1;

[0024] Step 6: The participants encrypt the pseudo-random number shards using the complete public key and generate the corresponding T' zero-knowledge proof shards;

[0025] Step 7: The participant encrypts the staked value using the complete public key and generates the corresponding T' zero - knowledge proof shards;

[0026] Step 8: The participant generates a ticket stub, calculates the ticket stub hash value, and encrypts the second - half of the ticket stub hash value using the complete public key;

[0027] Step 9: The candidate generates a set of zero - knowledge proof shards for the encrypted ticket stub;

[0028] Step 10: The candidate publishes a candidacy message;

[0029] Step 11: A random seed sd2 is generated distributively in the same way as in Step 4;

[0030] Step 12: The participant reveals t' - 1 of the zero - knowledge proof shards according to the random seed sd2

[0031] Participant Pi generates t' - 1 different pseudo - random numbers within [1, T'] using a pseudo - random number generator according to the random seed sd2; that is, PRNG(sd2, T', t' - 1)->(Idx1…, Idx t-1 ); Participant Pi publishes the revelation values of the corresponding t' - 1 shards: The shard corresponding to Idx1 is: the ciphertext zero - knowledge proof shard of the staked value and the zero - knowledge proof shard of the staking commitment the ciphertext zero - knowledge proof shard of the pseudo - random number shard the zero - knowledge proof shard of the encrypted ticket stub

[0032] Step 13: Participant Pi verifies the revelation values of other participants (e.g., Pj);

[0033] Step 14: The participant performs a fully - homomorphic summation calculation using the ciphertext of the staked values in all the candidacy messages that pass the verification; If all T' candidacy messages pass the verification, then:

[0034] Step 15: The participant decrypts the staking sum ciphertext using the key shard and publishes the decryption shard. Participant Pi calculates and publishes: Dsum piecei = Th FHE.PartDec(PK, Csum, SKi);

[0035] Step 16: The participant collects a threshold number of decryption shards and decrypts to calculate the plaintext of the staking sum; Suppose the t' decryption shards collected by Participant Pi are then: Sum = ThFHE.FinDec(PK, Csum, (Dsum piece-i1 , …, Dsum piece-it ));

[0036] Step 17: The participant calculates the scaling ratio according to the plaintext of the pledge sum and the range of the pseudo-random number. The scaling ratio is calculated as:

[0037] Step 18: The participant homomorphically synthesizes the complete pseudo-random number ciphertext using the pseudo-random number shard ciphertexts in all the messages that pass the verification; if all T' candidate messages pass the verification, the complete pseudo-random number ciphertext is: CPRF = SecretRecover(CPPRF1,..., CPPRFT');

[0038] Step 19: The participant scales the complete pseudo-random number ciphertext, CPRF scaled = scale * CPRF;

[0039] Step 20: The participant calculates the election result, i.e., the encrypted ticket stub of the winner, using the pledge value ciphertext and the complete pseudo-random number ciphertext. The election calculation process is as follows:

[0040] (1) Calculate the cumulative value of the pledge ciphertexts in the order of the pledges (i.e., the serial numbers):

[0041]

[0042] (2) Use the scaled complete pseudo-random number ciphertext to perform a homomorphic comparison with the cumulative value ciphertext:

[0043] (C <1 , C <2 , …, C <3 )

[0044] = Th FHE.Eval(PK, Ccompare, (CPRF scaled , (C1, C2,..., C T′ )))

[0045] (3) Determine the position of the winner:

[0046] (CL1, CL2, …, CL T′ ) = Th FHE.Eval(PK, Clocate, (C <1 , C <2 , …, C <3 ))

[0047] (4) Calculate the winning information:

[0048] C leaderTicket =

[0049] Th FHE.Eval(PK, Cselect, ((Cticket i-piece1, …, Cticket i-pieceT′ ), (CL1, CL2, …, CL T′ )))

[0050] Step 21: The participant uses the key shard to decrypt the selected ticket stub ciphertext and publishes the decryption shard; Participant Pi calculates and publishes: DLeaderTicket piecei = Th FHE.PartDec(PK, C leaderTicket , SKi);

[0051] Step 22: The participant collects the threshold number of decryption shards and decrypts and calculates the hash value of the second half of the ticket stub of the selected winner; Suppose the t' decryption shards collected by Participant Pi are (DLeaderTicket piece-i1 , …, DLeaderTicket piece-it′ ), then:

[0052]

[0053] Step 23: The selected winner observes that they have won; Suppose Pi is the winner, Pi observes:

[0054] Step 24: When the selected winner wants to publicly announce their winning, they publish the ticket stub preimage; Suppose Pi is the winner, when revealing, Pi publicly announces Ticket i ;

[0055] Step 25: Other participants calculate and verify the correctness of the winning based on the ticket stub preimage revealed by the selected winner and their participation messages; Suppose Pi is the winner, verify the correctness of Pi's winning revelation:

[0056] Furthermore, the Circuit calculation circuit specifically includes:

[0057] Ccompare(C x , C y =(C y1 , …, C yN′ ))→(C x<y1 , …, C x<yN′ ), where C x is a ciphertext, and C y is a ciphertext vector containing N' ciphertexts; The output is a ciphertext vector, and the i-th element in the vector is the comparison result ciphertext of x < yi. The plaintext of the comparison result is 1 or 0. If x < yi, it is the ciphertext of 1, and if x >= yi, it is the ciphertext of 0;

[0058] Clocate(C r1 ,..., CrN′ ) → (CL1, CL2…, CL T′ ), the input is C r1 , …, C rN′ are N' ciphertexts, and the output is a ciphertext vector of length N' (CL1, CL2…, CL T′ ). The first element CL1 in the vector = C r1 . Except for the first element, the i-th element CL i = C ri - C ri-1 ;

[0059] Cselect((C1, C2…, C N′ ), (C x1 , …, C xN′ )) → Cti, the input is two ciphertext vectors of length N', and the output Cti is the dot product of the two ciphertext vectors.

[0060] Further, in the SecretSharing linear threshold secret sharing function, when using the shamir secret sharing scheme:

[0061] Select a polynomial of degree n' - 1 over Zq:

[0062]

[0063] where a0 = sv;

[0064] Select N' points on f(x), (1, f(1)), (2, f(2)), …, (N', f(N')), and the N' points are N' secret shards sv pieces ;

[0065] Gather any n' secret shards of sv (sv piece-r1 , …, sv piece-rn′ ), where (r1, …, rn') ∈ (1, …, N') then there is a secret recovery function:

[0066] SecretRecover(sv piece-r1 , …, sv piece-rn′ ) = sv

[0067] When using the shamir secret sharing scheme

[0068] When restoring on the exponent:

[0069] Further, the specific steps for the participants in step 2 to distributively generate the complete public key, decrypt the key shards, calculate the shard public keys, and publish the shard public keys are as follows:

[0070] The participants distributively generate the fully homomorphic encryption key DKG(pp, t, T) -> (PK, SK1,..., SK T ): pp is the common parameter generated in Setup, and t is the decryption threshold; the specific operations are as follows:

[0071] (1) : Randomly select k polynomials of degree N - 1 over B[x] / (x N +1) to generate the partial private key of FHE:

[0072]

[0073] (2) Pi: Randomly select k polynomials of degree N - 1 over T[x] / (x N +1) to obtain the k-dimensional vector for generating the public key, and publicly broadcast it:

[0074]

[0075] (3) Pi: Calculate:

[0076] (4) Pi: Take k minimal noise polynomials over T[x] / (x N +1), where the coefficients of the polynomials are sampled from the Gaussian distribution v(μ, σ 2 ), to generate the k-dimensional noise vector:

[0077]

[0078] (5) Pi: Generate and publicly disclose the FHE public key PPKi corresponding to the partial private key PSKi:

[0079] Bi j (x) = Asum j ·PSKi j (x) + ei j (x) j ∈ (1, 2,... k)

[0080] PPKi = ((Asum1(x), Bi1(x)),..., (Asum k (x), Bi k (x)))

[0081] (6) Pi: Calculate the complete public key:

[0082]

[0083] = ((PK1 A , PK1 B),...,(PKk A , PKk B )

[0084] (7) Pi: Use the secret sharing algorithm to generate T secret shards of PSKi:

[0085] SecretSharing(PSKi) = (PSKi sh are1 ,..., PSKi sh areT )

[0086] The j-th secret shard of PSKi:

[0087] PSKi sh arej = (PSKi 1-sh arej ,..., PSKi k-sh arej ) j ∈ (1, 2,..., T)

[0088] Gather any t PSKi share That is, PSKi can be restored;

[0089] (8) Pi: From the generated secret shards of T PSKi, select T - 1 PSKi by serial number share And distribute them to the corresponding remaining decryption participants (such as Pj); and calculate and publish the discrete logarithm public key of the T secret shards:

[0090]

[0091] (9) After all decryption participants have distributed the secret shards, the decryption key shards held by Pi are:

[0092]

[0093] The corresponding k-dimensional vector of the FHE key shards is:

[0094]

[0095] (10) Pi: Calculate and publish the shard public key of the decryption key shards:

[0096]

[0097] (11) Pi: Verify the shard public keys published by other participants according to other participants.

[0098] Furthermore, the specific steps for participant Pi to generate the pseudo-random number shard PPRFi according to the random seed sd1 in step 5 are: The participant uses the key-homomorphic pseudo-random function Flwe to generate PPRFi = Flwe(SKi, sd1); randomly generate two Ts qThe m×n matrices on it: A0, A1; Convert sd1 to binary: sd1 = x1x2x3…x u , u = 「log2(q)7 is the number of digits; where when x j = 0, Axj = A0; when x j = 1, Axj = A1.

[0099] Furthermore, the specific steps for the participants to encrypt the pseudo-random number shards using the complete public key and generate the corresponding T' zero-knowledge proof shards in step 6 are as follows:

[0100] (1) The participant uses the complete public key PK to encrypt PPRFi to obtain the ciphertext:

[0101]

[0102] (2) Participant Pi uses the secret sharing algorithm to generate T' shards of SKi, r prf-i , e prf-i :

[0103] SKi pieces = SecretSh aring(SKi) = (SKi piece1 , …, SKi pieceT′ )

[0104] where,

[0105]

[0106] Gather any t' SKipiece, that is, SKi can be restored,

[0107] (3) Participant Pi generates the discrete logarithm public key corresponding to SKi pieces :

[0108] PPK i ′ pieces = (PPK i ′ piece1 ,..., PPK i ′ pieceT′ )

[0109] where,

[0110] (4) The participant generates T' shards of the pseudo-random number shard CPPRFi:

[0111]

[0112] Among them, the L-th shard:

[0113]

[0114] Gather any t' That is, it can be restored

[0115]

[0116] Furthermore, the specific steps for the participant to encrypt the pledge value using the complete public key and generate the corresponding T' zero-knowledge proof shards in step 7 are as follows:

[0117] (1) Participant Pi encrypts the pledge value using the complete public key PK to generate a pledge ciphertext:

[0118]

[0119] Among them, STKi is the pledge value of Pi, is a random number, e stki is encryption noise;

[0120] (2) Participant Pi uses the secret sharing algorithm to cut STKi, and e stki , to generate T' shards:

[0121] STKi pieces = SecretSharing(STKi) = (STKi piece1 , …, STKi pieceT′ )

[0122]

[0123] (3) Participant Pi uses STKi pieces , and to generate T' shards of CSTKi:

[0124] CSTKi pieces = (CSTKi piece1 , …, CSTKi pieceT′ )

[0125] Gather any t' CSTKi piece , that is, CSTKi can be restored; among them,

[0126]

[0127] (4) Participant Pi uses the secret sharing algorithm to generate T' shards of the pledge commitment CMi:

[0128] ① Participant Pi uses the secret sharing algorithm to generate a random number R of the pledge commitment i into T' shards:

[0129]

[0130] ② Participant Pi generates T' shards of the pledge commitment CMi according to the STKi shards and the R i shards:

[0131]

[0132] Among them,

[0133] Furthermore, the specific steps for the participant to generate the ticket stub, calculate the ticket stub hash value, and encrypt the second half of the ticket stub hash value using the complete public key in step 8 are as follows:

[0134] (1) Participant Pi randomly selects a random number in Z q as the ticket stub, denoted as Ticket i ;

[0135] (2) Participant Pi calculates the ticket stub hash value: Hticket i = Hash(Ticket i );

[0136] (3) Participant Pi splits the ticket stub hash value Hticket i from the middle:

[0137] (4) Participant Pi encrypts the second half of the ticket stub hash value using the complete public key:

[0138]

[0139] Among them, the random number used for encryption, is the noise added for encryption.

[0140] Furthermore, the specific steps for the candidate to generate the zero-knowledge proof shard set of the encrypted ticket stub in step 9 are as follows:

[0141] (1) Participant Pi uses the secret sharing algorithm to cut respectively to generate T' shards;

[0142]

[0143] (2) Participant Pi generates T' shards of Cticket according to ; i For Cticket, any t' Ctickets can be used to restore Cticket; among them,

[0144] Cticket i-pieces =(Cticket i-piece1 ,…, Cticket i-pieceT′ )

[0145] Specifically, the candidate's message publishing in step 10 includes: i-piece ;

[0146] The candidate message RegisMsg of candidate Pi

[0147] ={ i

[0148] Pledge commitment: CM i ,

[0149] Pledge value ciphertext: CSTKi,

[0150] Pledge value ciphertext zero-knowledge proof shard set:

[0151] Pledge value ciphertext shard set: (CSTKi piece1 ,…, CSTKi pieceT′ )

[0152] Pledge commitment shard set:

[0153] Pseudo-random number shard ciphertext: CPPRFi

[0154] Pseudo-random number shard ciphertext zero-knowledge proof set: (CPPRFi piece1 ,…, CPPRFi pieceT′ )

[0155] Discrete logarithm public key set of shard key slices: (PPK i ′ piece1 ,..., PPK i ′ pieceT′ )

[0156] Encrypted ticket stub (encrypted hash value of the second half of the ticket stub): Cticket i ,

[0157] Encrypted ticket stub zero-knowledge proof shard set: (Cticket i-piece1 ,…, Cticket i-pieceT′ ) ​

[0158] Front - half ticket stub hash value:

[0159] Furthermore, in step 13, the specific process for participant Pi to verify the revealed value of other participants (such as Pj) is as follows:

[0160] When verifying the authenticity of the encrypted pledge value:

[0161] When verifying the authenticity of the pseudo - random number shard ciphertext CPPRFj of Pj:

[0162] (1) If the revealed value of the CPPRFj slice with serial number Idx1 is:

[0163]

[0164] (2) Verify whether the zero - knowledge proof of the pseudo - random number shard ciphertext can restore CPPRFj:

[0165] SecretRecover(CPPRFj piece1 ,..., CPPRFj pieceT′ )? = CPPRFj

[0166] (3) Verify whether the set of discrete logarithm public keys of the shard key slices corresponds to the discrete logarithm shard public keys published by Pj in steps 2 - 10:

[0167] SecretRecover(PPK j ′ piece1 ,..., PPK j ′ pieceT′ )? = PPK j ′;

[0168] (4) Use the set of discrete logarithm public keys of the verified shard key slices (PPK j ′ piece1 ,..., PPK j ′ pieceT′ ) to verify whether the key shards for generating the pseudo - random number shards are consistent with their discrete logarithm public keys in the revealed t' - 1 pseudo - random number shard ciphertext zero - knowledge proof shards. For example, when it is the slice with serial number Idx1,

[0169] (5) Verify whether the encryption is correct in the revealed t' - 1 pseudo - random number shard ciphertext zero - knowledge proof shards:

[0170]

[0171] Among them,, should be within the noise range;

[0172] When verifying the authenticity of the encrypted ticket stub:

[0173] (1) If the revealed value of the Cticket j slice with serial number Idx1 is:

[0174]

[0175] (2) Verify whether the zero - knowledge proof of the pseudorandom number shard ciphertext can restore Cticket j :

[0176] SecretRecover(Cticket j-piece1 , …, Cticket j-pieceT′ )? = Cticket j

[0177] (3) Verify whether the encryption of each shard in the revealed t’ - 1 encrypted ticket stub ciphertext zero - knowledge proof shards is correct:

[0178] When verifying the slice with serial number Idx1:

[0179]

[0180] Among them, should be within the noise range;

[0181] When verifying the correctness of the pledged value ciphertext:

[0182] (1) If the revealed value of the pledged ciphertext CSTKj slice CSTKj piece-idx1 with serial number Idx1 is:

[0183]

[0184] The revealed value of the pledged commitment CM j slice with serial number Idx1 is:

[0185]

[0186] Among them, STKj in the revealed values of the pledged ciphertexts with the same serial number piece should be consistent with STKj in the revealed values of the pledged commitments piece ;

[0187] (2) Verify whether the set of pledged ciphertext zero - knowledge proof shards can restore CSTKj:

[0188] SecretRecover(CSTKi piece1, …, CSTKi pieceT x)? = CSTKj

[0189] (3) Verify whether the shard set of the zero - knowledge proof of the pledge commitment can restore CM j :

[0190]

[0191] Among them, the SecretRecover here is the restoration scheme on the exponent;

[0192] (4) Verify whether the encryption of each shard in the t' - 1 revealed shards of the zero - knowledge proof of the pledge ciphertext is correct:

[0193] When verifying the slice with the serial number Idx1:

[0194]

[0195] Among them, It should be within the noise range;

[0196] (5) Verify whether the calculation of each shard in the t' - 1 revealed shards of the zero - knowledge proof of the pledge ciphertext is correct:

[0197] When verifying the slice with the serial number Idx1:

[0198]

[0199] The beneficial effects of the present invention are as follows: By constructing a Pedersen commitment to hide the pledge distribution, ensuring the confidentiality and determinacy of the election process through fully homomorphic encryption calculation, constructing a distributed - generated pseudo - random number by combining the secret sharing technology and the key - homomorphic pseudo - random function technology to ensure the unpredictability of the lottery election, and based on the cut and choose strategy, combining the secret sharing technology to construct a zero - knowledge proof scheme to ensure the consistency between the ciphertext input of the encrypted election and the pledge commitment, as well as the correctness of the distributed pseudo - random number, thus realizing the fairness of the election. Specific implementation manner

[0200] The present invention combines commitment technology, key - homomorphic pseudorandom function technology, secret sharing technology, zero - knowledge proof technology, and threshold fully homomorphic encryption technology to ensure the certainty, unpredictability, and fairness of the leader node lottery election while hiding the pledge distribution. Specifically, the method hides the pledge distribution by constructing a Pedersen commitment; ensures the confidentiality and certainty of the election process through fully homomorphic encryption calculation; constructs a distributed - generated pseudorandom number by combining secret sharing technology and key - homomorphic pseudorandom function technology to ensure the unpredictability of the lottery election; and constructs a zero - knowledge proof scheme based on the cut - and - choose strategy and combines secret sharing technology to ensure the consistency between the ciphertext input of the encrypted election and the pledge commitment, as well as the correctness of the distributed pseudorandom number, so as to guarantee the fairness of the election.

[0201] A pledge - hiding deterministic lottery method for the proof - of - stake consensus algorithm is as follows:

[0202] Suppose there are T participants in the lottery election, namely P1,…,P T ;

[0203] Step 1: Generate public parameters and function definitions

[0204] Generate public parameters Setup(1 λ )->pp(λ,p,q,G,g,h,N,σ,μ,ν), where λ is the set security parameter, and public parameters are generated according to λ; P is a large prime number of λ bits; q is a large prime factor of - 1; G is a cyclic subgroup with modulus p and order for Pedersen commitment; G’ is another cyclic subgroup with modulus p and order q for discrete logarithm encryption; g is a generator in the cyclic group G; h is another generator in G, satisfying h = g x , where x is a secret value randomly selected in ; g’ is a generator in the cyclic group G’; k is the length of the private key vector in the FHE algorithm based on the TRLWE (Learning with Errors over Torus Rings) problem; m is the number of rows of the random matrix in the LWE - based key - homomorphic PRF, m>>k; N is the order of the binary polynomial ring B[x] / (x N + 1) and the Torus polynomial ring T q [x] / (x N + 1) used in the FHE algorithm based on the TRLWE problem; σ is the standard deviation of the Gaussian distribution for noise sampling in the FHE algorithm based on the TRLWE problem. To ensure that the noise does not affect the final approximate value during decryption, an appropriate σ should be selected to ensure that the cumulative calculation of the noise is less than the discrete T qHalf of the upper quantization step; μ is the mean of the Gaussian distribution used for noise sampling in the FHE algorithm based on the TRLWE problem; ν(μ,σ2) is the Gaussian distribution used for noise sampling in the FHE algorithm based on the TRLWE problem;

[0205] The function definition is as follows:

[0206] ThFHE: A threshold fully homomorphic encryption scheme based on the TRLWE problem, consisting of 6 probabilistic polynomial-time (PPT) algorithms, specifically as follows:

[0207] Th FHE

[0208] =(Th FHE.Setup, Th FHE.Enc, Th FHE.Eval, Th FHE.PartDec, Th FHE.FinDec)

[0209] Suppose there are N' parties: Pt = {Pt1,..., PtN'}, and the threshold is n', then:

[0210] Th FHE.Setup(λ, N′, n′) → (PK, sk1,...skN'), where λ in the input is the security parameter, and the output is a public key PK and N' partial private keys;

[0211] Th FHE.Enc(PK, x) → Cx, where x in the input is the secret value, PK is the public key, and the output is the ciphertext value after full homomorphic encryption;

[0212] Th FHE.Eval(PK, Circuit, Inputs) → Cy, where PK in the input is the public key, Circuit is the computing circuit, Inputs is the input of the computing circuit, and the output Cy is the calculation result;

[0213] Th FHE.PartDec(PK, Cts, SKi) → Dts piecei , where the input is the public key PK, the ciphertext Cts, and the partial key SKi, and the output Dts is the decryption shard Dts of Dts piecei ;

[0214] Th FHE.FinDec(PK, Cts, Dts pieces ) → ts: The input is the public key PK, the ciphertext Cts, and n' partial decryption shards Dts pieces , and the output is the decrypted result plaintext ts;

[0215] SecretSharing is a linear threshold secret sharing function. Given a secret value sv, with N' participants and a threshold of n', then: SecretSharing(sv) = (sv piece1 ,..., sv pieceN′ );

[0216] Step 2: Each participant Pi generates and publishes a pledge commitment CM i . The participant randomly selects a random number R q in Z i , and generates a Pedersen commitment of the pledge value according to its own pledge value STK i : The participant publicly publishes CM i ;

[0217] Step 3: The participants distributively generate the complete public key, decrypt the key shards, calculate the shard public keys, and publish the shard public keys;

[0218] Step 4: Distributively generate a random seed sd1. Each participant Pi selects a random value Rnd q on Z i ; sd1 = Rnd1 xor Rnd2 xor... xor Rnd T ;

[0219] Step 5: Participant Pi generates a pseudo-random number shard PPRFi according to the random seed sd1;

[0220] Step 6: The participants encrypt the pseudo-random number shards using the complete public key and generate the corresponding T' zero-knowledge proof shards;

[0221] Step 7: The participants encrypt the pledge value using the complete public key and generate the corresponding T' zero-knowledge proof shards;

[0222] Step 8: The participants generate a ticket stub, calculate the ticket stub hash value, and encrypt the second half of the ticket stub hash value using the complete public key;

[0223] Step 9: The candidate generates a set of zero-knowledge proof shards for the encrypted ticket stub;

[0224] Step 10: The candidate publishes a candidacy message;

[0225] Step 11: Distributively generate a random seed sd2, generated in the same way as in Step 4;

[0226] Step 12: The participants reveal t'-1 of the zero-knowledge proof shards according to the random seed sd2

[0227] Participant Pi generates t'-1 different pseudo-random numbers within [1, T'] using a pseudo-random number generator based on the random seed sd2; that is, PRNG(sd2, T', t'-1)->(Idx1..., Idx t-1 ); Participant Pi publishes the disclosure values of the corresponding t'-1 shards: The shard corresponding to Idx1 is: the zero-knowledge proof shard of the staked value ciphertext and the zero-knowledge proof shard of the staking commitment the zero-knowledge proof shard of the pseudo-random number shard ciphertext the zero-knowledge proof shard of the encrypted ticket stub

[0228] Step 13: Participant Pi verifies the disclosure values of other participants (e.g., Pj);

[0229] Step 14: The participant performs a fully homomorphic summation calculation using the staked value ciphertexts in all the verified candidate messages; If all T' candidate messages pass the verification, then:

[0230] Step 15: The participant decrypts the staking sum ciphertext using the key shard and publishes the decryption shard. Participant Pi calculates and publishes: Dsum piecei = Th FHE.PartDec(PK, Csum, SKi);

[0231] Step 16: The participant collects a threshold number of decryption shards and decrypts to calculate the plaintext of the staking sum; Let the t' decryption shards collected by Participant Pi be (Dsum piece-i1 , …, Dsum piece-it ), then: Sum = Th FHE.FinDec(PK, Csum, (Dsum piece-i1 , …, Dsum piece-it ));

[0232] Step 17: The participant calculates the scaling ratio based on the plaintext of the staking sum and the pseudo-random number range. The scaling ratio is calculated as:

[0233] Step 18: The participant homomorphically synthesizes the complete pseudo-random number ciphertext using the pseudo-random number shard ciphertexts in all the verified messages; If all T' candidate messages pass the verification, the complete pseudo-random number ciphertext is: CPRF = SecretRecover(CPPRF1,... CPPRFT');

[0234] Step 19: The participant scales the complete pseudo-random number ciphertext using the scaling ratio, CPRF scaled = scale * CPRF;

[0235] Step 20: The participant uses the encrypted pledge value and the encrypted complete pseudo-random number to calculate the election result, i.e., the encrypted ticket stub of the winner; the election calculation process is as follows:

[0236] (1) Calculate the cumulative value of the encrypted pledges in the order of pledges (i.e., serial numbers):

[0237]

[0238] (2) Use the scaled encrypted complete pseudo-random number to perform a homomorphic comparison with the cumulative value ciphertext:

[0239] (C <1 ,C <2 ,…,C <3 )

[0240] =Th FHE.Eval(PK,Ccompare,(CPRF scaled ,(C1,C2,…,C T′ )))

[0241] (3) Determine the position of the winner:

[0242] (CL1,CL2,...,CL T′ )=Th FHE.Eval(PK,Clocate,(C <1 ,C <2 ,...,C <3 ))

[0243] (4) Calculate the winning information:

[0244] C leaderTicket =

[0245] Th FHE.Eval(PK,Cselect,((Cticket i-piece1 ,...,Cticket i-pieceT′ ),(CL1,CL2,...,CL T′ )));

[0246] Step 21: The participant uses the key shard to decrypt the encrypted ticket stub of the winner and publishes the decryption shard; the participant Pi calculates and publishes: DLeaderTicket piecei =Th FHE.PartDec(PK,C leaderTicket ,SKi);

[0247] Step 22: The participant collects the threshold number of decryption shards and decrypts and calculates the hash value of the second half of the ticket stub of the winner; assume that the t' decryption shards collected by the participant Pi are (DLeaderTicket piece-i1, …, DLeaderTicket piece-it′ ), then:

[0248]

[0249] Step 23: The selected winner observes that they have won; Assume Pi is the winner, and Pi observes:

[0250] Step 24: When the selected winner wants to announce their winning, they release the ticket stub preimage; Assume Pi is the winner, when revealing, Pi discloses Ticket i ;

[0251] Step 25: Other participants calculate and verify the correctness of the winning based on the ticket stub preimage revealed by the selected winner and their participation messages; Assume Pi is the winner, verify the correctness of Pi's winning revelation:

[0252] Furthermore, the Circuit computing circuit specifically includes:

[0253] Ccompare(C x , C y = (C y1 , …, C yN′ )) → (C x<y1 , …, C x<yN′ ), where C x in the input is a ciphertext, and C y is a ciphertext vector containing N' ciphertexts; The output is a ciphertext vector, and the i-th element in the vector is the comparison result ciphertext of x < yi, the plaintext of the comparison result is 1 or 0, the ciphertext is 1 for x < yi, and the ciphertext is 0 for x >= yi;

[0254] Clocate(C r1 ,..., C rN′ ) → (CL1, CL2 …, CL T′ ), where C r1 ,..., C rN′ in the input are N' ciphertexts, and the output is a ciphertext vector of length N' (CL1, CL2 …, CL T′ ), the first element CL1 in the vector = C r1 , and except for the first element, the i-th element CL i = C ri - C ri-1 ;

[0255] Cselect((C1, C2 …, C N′ ), (C x1 ,..., C xN′)) → Cti, with two ciphertext vectors of length N’ as input, and the output Cti is the dot product of the two ciphertext vectors.

[0256] Furthermore, in the SecretSharing linear threshold secret sharing function, when using the shamir secret sharing scheme:

[0257] Select a polynomial of degree n’ - 1 over Zq:

[0258]

[0259] where a0 = sv;

[0260] Select N’ points on f(x), (1, f(1)), (2, f(2)),..., (N’, f(N’)), and these N’ points are the N’ secret shares sv of sv pieces ;

[0261] Gather any n’ secret shares of sv (sv piece-r1 ,..., sv piece-rn′ ), where (r1,..., rn’) ∈ (1,..., N’), then there is a secret recovery function:

[0262] SecretRecover(sv piece-r1 ,…, sv piece-rn′ ) = sv

[0263] When using the shamir secret sharing scheme

[0264] When restoring on the exponent:

[0265] Furthermore, the specific steps for the participants in step 2 to distributively generate the complete public key, decrypt the key share, calculate the share public key, and publish the share public key are as follows:

[0266] The participants distributively generate the fully homomorphic encryption key DKG(pp, t, T) -> (PK, SK1,…, SK T ): pp is the common parameter generated in Setup, and t is the decryption threshold; the specific operations are as follows:

[0267] (1) : Randomly select k polynomials of degree N - 1 over B[x] / (x N + 1) to generate the partial private key of FHE:

[0268]

[0269] (2) Pi: Over T[x] / (x NRandomly select k N-1 degree polynomials on +1) to obtain a k-dimensional vector for generating the public key, and publicly broadcast it:

[0270]

[0271] (3) Pi: Calculate:

[0272] (4) Pi: Take k minimal noise polynomials on T[x] / (x N +1), where the coefficients of the polynomials are sampled from the Gaussian distribution v(μ, σ 2 ), and generate a k-dimensional noise vector:

[0273]

[0274] (5) Pi: Generate the FHE public key PPKi corresponding to the partial private key PSKi and make it public:

[0275] Bi j (x) = Asum j ·PSKi j (x) + ei j (x) j ∈ (1, 2,... k)

[0276] PPKi = ((Asum1(x), Bi1(x)), …, (Asum k (x), Bi k (x)))

[0277] (6) Pi: Calculate the complete public key:

[0278]

[0279] (7) Pi: Use the secret sharing algorithm to generate T secret shards of PSKi:

[0280] SecretSh aring(PSKi) = (PSKi sh are1 ,..., PSKi sh areT )

[0281] The j-th secret shard of PSKi:

[0282] PSKi sh arej = (PSKi 1-sh arej ,..., PSKi k-sh arej ) j ∈ (1, 2,.., T)

[0283] Gather any t PSKi share That is, PSKi can be restored;

[0284] (8) Pi: From the generated T secret shards of PSKi, select T - 1 PSKi by serial number share and distribute them to the corresponding remaining decryption participants (such as Pj); and calculate and publish the discrete logarithm public keys of the T secret shards:

[0285]

[0286] (9) After all decryption participants have distributed the secret shards, the decryption key shards held by Pi are:

[0287]

[0288] The corresponding k - dimensional vector of the FHE key shards is:

[0289]

[0290] (10) Pi: Calculate and publish the shard public keys of the decryption key shards:

[0291]

[0292] (11) Pi: Verify the shard public keys published by other participants according to other participants.

[0293] Furthermore, the specific steps for participant Pi to generate the pseudo - random number shard PPRFi according to the random seed sd1 in step 5 are: The participant uses the key - homomorphic pseudo - random function Flwe to generate PPRFi = Flwe(SKi, sd1); randomly generate two q m×n matrices over T: A0, A1; convert sd1 to binary: sd1 = x1x2x3…x u is the number of digits; where when x j = 0, Axj = A0; when x j = 1, Axj = A1.

[0294] Furthermore, the specific steps for the participant to encrypt the pseudo - random number shard using the complete public key and generate the corresponding T' zero - knowledge proof shards in step 6 are:

[0295] (1) The participant uses the complete public key PK to encrypt PPRFi to obtain the ciphertext:

[0296]

[0297] (2) Participant Pi uses the secret sharing algorithm to generate T' shards of SKi, r prf-i , e prf-i :

[0298] SKi​pieces = SecretSharing(SKi) = (SKi piece1 , …, SKi pieceT′ )

[0299] Among them,

[0300]

[0301] Gathering any t' SKipieces can restore SKi

[0302] (3) Participant Pi generates the discrete logarithm public keys corresponding to the SKipieces:

[0303] PPK i ′ pieces = (PPK i ′ piece1 ,..., PPK i ′ pieceT′ )

[0304] Among them,

[0305] (4) The participants generate T' shards of the pseudorandom number shard CPPRFi:

[0306]

[0307] Among them, the L-th shard:

[0308]

[0309] Gathering any t' can restore

[0310] Furthermore, the specific steps for the participants to encrypt the pledge value using the complete public key and generate the corresponding T' zero-knowledge proof shards in step 7 are as follows:

[0311] (1) Participant Pi encrypts the pledge value using the complete public key PK to generate a pledge ciphertext:

[0312]

[0313] Among them, STKi is Pi's pledge value, is a random number, e stki is the encryption noise;

[0314] (2) Participant Pi uses the secret sharing algorithm to split STKi, and e stki , generating T' shards:

[0315]

[0316] (3) Participant Pi uses STKi pieces 、 and to generate T' shards of CSTKi:

[0317] CSTKi Pieces =(CSTKi piece1 , …, CSTKi pieceT′ )

[0318] Collecting any t' CSTKi piece enables the restoration of CSTKi; where

[0319]

[0320] (4) Participant Pi uses the secret sharing algorithm to generate T' shards of the pledge commitment CMi:

[0321] ① Participant Pi uses the secret sharing algorithm to generate T' shards of the pledge commitment random number R i :

[0322]

[0323] ② Participant Pi generates T' shards of the pledge commitment CMi based on the STKi shards and the R i shards:

[0324]

[0325] where

[0326] Furthermore, the specific steps for the participant to generate the ticket stub, calculate the ticket stub hash value, and encrypt the second half of the ticket stub hash value using the complete public key in step 8 are as follows:

[0327] (1) Participant Pi randomly selects a random number in Z q as the ticket stub, denoted as Ticket i ;

[0328] (2) Participant Pi calculates the ticket stub hash value: Hticket i = Hash(Ticket i );

[0329] (3) Participant Pi splits the ticket stub hash value Hticket i from the middle:

[0330]

[0331] (4) Participant Pi encrypts the second half of the ticket stub hash value using the complete public key:

[0332]

[0333] where, the random number used for encryption, the noise added for encryption.

[0334] Furthermore, the specific steps for the candidate to generate the zero - knowledge proof shard set of the encrypted ticket stub in step 9 are as follows:

[0335] (1) Participant Pi uses the secret sharing algorithm to split and generates T' shards respectively;

[0336]

[0337]

[0338] (2) Participant Pi generates T' shards of Cticket according to i ;

[0339] Cticket i-pieces =(Cticket i-piece1 , …, Cticket i-pieceT′ )

[0340] Collecting any t' Cticket i-piece can restore Cticket; where,

[0341] Furthermore, the candidate's announcement of the candidacy message in step 10 specifically includes:

[0342] The candidacy message RegisMsg of candidate Pi i ={

[0343] Pledge commitment: CM i ,

[0344] Pledged value ciphertext: CSTKi,

[0345] Zero - knowledge proof shard set of the pledged value ciphertext:

[0346] Pledged value ciphertext shard set: (CSTKipiece1 , …, CSTKi pieceT′ )

[0347] Pledge commitment shard set:

[0348] Pseudo-random number shard ciphertext: CPPRFi

[0349] Pseudo-random number shard ciphertext zero-knowledge proof set: (CPPRFi piece1 , …, CPPRFi pieceT′ )

[0350] Discrete logarithm public key set of shard key slices: (PPK i ′ piece1 ,..., PPK i ′ pieceT′ )

[0351] Encrypted ticket stub (encrypted second half of ticket stub hash value): Cticket i ,

[0352] Encrypted ticket stub zero-knowledge proof shard set: (Cticket i-piece1 ,..., Cticket i-pieceT′ )

[0353] First half of ticket stub hash value:

[0354] Furthermore, the specific verification by participant Pi of the revelation values of other participants (such as Pj) in step 13 is as follows:

[0355] When verifying the authenticity of the pledged ciphertext value:

[0356] When verifying the authenticity of Pj's pseudo-random number shard ciphertext CPPRFj:

[0357] (1) If the revelation value of the CPPRFj slice with serial number Idx1 is:

[0358]

[0359] (2) Verify whether the pseudo-random number shard ciphertext zero-knowledge proof can restore CPPRFj:

[0360] SecretRecover(CPPRFj piece1 ,..., CPPRFj pieceT′ )? = CPPRFj

[0361] (3) Verify whether the discrete logarithm public key set of the shard key slices corresponds to the discrete logarithm shard public key published by Pj in steps 2 - 10:

[0362] SecretRecover(PPK j ′ piece1 ,..., PPK j ′ pieceT′ )? = PPK j ′; Note: The restoration scheme on the exponent during SecretRecover here;

[0363] (4) Use the set of discrete logarithm public keys (PPK j ′ piece1 ,..., PPK j ′ pieceT′ ) of the shard keys sliced by the verified shard keys to verify whether the key shards generating the pseudorandom number shards are consistent with their discrete logarithm public keys in the t'-1 revealed zero-knowledge proof shards of the pseudorandom number shard ciphertext: When slicing with the serial number Idx1,

[0364] (5) Verify whether the encryption is correct in the t'-1 revealed zero-knowledge proof shards of the pseudorandom number shard ciphertext:

[0365]

[0366] Among them,, should be within the noise range;

[0367] When verifying the authenticity of the encrypted ticket stub:

[0368] (1) If the revealed value of the slice of Cticket with the serial number Idx1 j is:

[0369]

[0370] (2) Verify whether the zero-knowledge proof of the pseudorandom number shard ciphertext can restore Cticket(2) Verify whether the zero-knowledge proof of the pseudorandom number shard ciphertext can restore Cticket j :

[0371] SecretRecover(Cticket j-piece1 , …, Cticket j-pieceT′ )? = Cticket j

[0372] (3) Verify whether the encryption of each shard is correct in the t'-1 revealed zero-knowledge proof shards of the encrypted ticket stub ciphertext:

[0373] When verifying the slice with the serial number Idx1:

[0374]

[0375] Among them, it should be within the noise range;

[0376] When verifying the correctness of the pledged value ciphertext:

[0377] (1) If the revealed value of the pledged ciphertext CSTKj slice CSTKj with serial number Idx1 piece-idx1 is:

[0378]

[0379] The revealed value of the pledged commitment CM with serial number Idx1 j slice is:

[0380]

[0381] Among them, STKj in the revealed values of the pledged ciphertexts with the same serial number piece should be consistent with STKj in the revealed value of the pledged commitment piece ;

[0382] (2) Verify whether the zero - knowledge proof shard set of the pledged ciphertext can restore CSTKj:

[0383] SecretRecover(CSTKi piece1 , …, CSTKi pieceT′ )? = CSTKj

[0384] (3) Verify whether the zero - knowledge proof shard set of the pledged commitment can restore CM j :

[0385]

[0386] Among them, SecretRecover here is the restoration scheme on the exponent;

[0387] (4) Verify whether the encryption of each shard in the revealed t’ - 1 pledged ciphertext zero - knowledge proof shards is correct:

[0388] When verifying the slice with serial number Idx1:

[0389]

[0390] Among them, it should be within the noise range;

[0391] (5) Verify whether the calculation of each shard in the revealed t’ - 1 pledged ciphertext zero - knowledge proof shards is correct:

[0392] When verifying the slice with serial number Idx1:

[0393]

[0394] The key technical points of the present invention are as follows: The present invention proposes a single secret leader node lottery election scheme for the proof-of-stake consensus algorithm that can hide the pledge distribution; it constructs a zero-knowledge proof scheme based on the Cut&Choose strategy, which can prove the consistency between the Pedersen commitment and the fully homomorphic ciphertext input; the present invention combines a key-homomorphic pseudorandom number generation function with secret sharing technology to construct a distributed pseudorandom number generation scheme, avoiding the multiplication depth required for generating pseudorandom functions in fully homomorphic ciphertext calculations.

[0395] The technical effects of the present invention are as follows: (1) The present invention can conduct deterministic secret leader node lottery elections while hiding the pledge distribution. Compared with the probabilistic secret leader node lottery election scheme, the scheme of the present invention avoids the risks of re-election and fork. (2) Compared with other deterministic lottery schemes, the present invention avoids the privacy leakage problem caused by the public pledge distribution and avoids large pledge nodes becoming the focus of attack targets. (3) Compared with other deterministic election schemes based on threshold fully homomorphic encryption, by designing and using a distributed pseudorandom number fully homomorphic ciphertext generation method, the present invention reduces the multiplication depth of generating pseudorandom numbers under fully homomorphic ciphertext and reduces the computational overhead.

[0396] The protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the said claims.

Claims

1. A pledge-hidden deterministic lottery method for a proof-of-stake consensus algorithm, characterized by: The pledge hidden deterministic lottery method is as follows: Assume that there are T participants in the lottery election, namely P1,…,P T ; Step 1: Generate common parameters and function definitions Generate common parameters Setup(1 λ )->pp(λ,p,q,G,g,h,N,σ,μ,ν), where λ is the security parameter set, and the public parameter is generated based on λ; P is a large prime number of λ bits; q is a large prime factor of -1; G is a cyclic subgroup with a modulus of p and an order of , used for Pedersen commitment; G' is another cyclic subgroup with a modulus of p and an order of q, used for discrete logarithm encryption; g is a generator in the cyclic group G; h is another generator in G, satisfying h=g x , where x is in A secret value randomly selected from the cyclic group G'; g' is a generator in the cyclic group G'; k is the length of the private key vector in the FHE algorithm based on the TRLWE problem; m is the number of rows of the random matrix in the key homomorphic PRF based on LWE, m>>k; N is the binary polynomial ring B[x] / (x N +1) and Torus polynomial ring T q [x] / (x N +1); σ is the standard deviation of the Gaussian distribution used for noise sampling in the FHE algorithm based on the TRLWE problem; μ is the mean of the Gaussian distribution used for noise sampling in the FHE algorithm based on the TRLWE problem; ν(μ,σ2) is the Gaussian distribution used for noise sampling in the FHE algorithm based on the TRLWE problem; The function definition includes the following: ThFHE: A threshold fully homomorphic encryption scheme based on the TRLWE problem, which consists of 6 probabilistic polynomial time algorithms, as follows: F =(Th FHE.Setup,Th FHE.Enc,Th FHE.Eval,Th FHE.PartDec,Th FHE.FinDec) Assume that there are N' participants: Pt = {Pt1, ..., PtN'}, and the threshold is n', then: Th FHE.Setup(λ,N',n')→(PK,sk1,…skN'), where λ in the input is a security parameter and the output is a public key PK and N' partial private keys; T h FHE.Enc(PK,x)→Cx, where x in the input is the secret value, PK is the public key, and the output is the ciphertext value after fully homomorphic encryption; T h FHE.Eval(PK,Circuit,Inputs)→Cy, where PK is the public key, Circuit is the computing circuit, Inputs is the input of the computing circuit, and the output Cy is the computing result; Th FHE.PartDec(PK,Cts,SKi)→Dts piecei , the input is the public key PK, the ciphertext Cts, and the partial key SKi, and the output is the decrypted fragment Dts of Dts piecei ; Th FHE.FinDec(PK,Cts,Dts pieces )→ts: Input is public key PK, ciphertext Cts, and n' partial decryption fragments Dts pieces , the output is the decryption result plaintext ts; SecretSharing is a linear threshold secret sharing function. Suppose there is a secret value sv, N' participants, and the threshold is n', then: SecretSharing(sv) = (sv piece1 ,…,sv pieceN' ); Step 2: Each participant Pi generates and publishes a pledge commitment CM i , participants in Z q Randomly select a random number R i , and according to their own pledge value STK i Generate Pedersen commitment of staked value: Participants publicly release CM i ; Step 3: Participants generate the complete public key in a distributed manner, decrypt the key shards, calculate the shard public key and publish the shard public key; Step 4: Distributed generation of random seeds sd1, each participant Pi in Z q Pick a random value Rnd i ;sd1=Rnd1xor Rnd2xor…xor Rnd T ; Step 5: Participant Pi generates a pseudo-random number shard PPRFi based on the random seed sd1; Step 6: The participant uses the full public key to encrypt the pseudo-random number shard and generate the corresponding T' zero-knowledge proof shards; Step 7: The participant uses the full public key to encrypt the pledge value and generate the corresponding T' zero-knowledge proof shards; Step 8: The participant generates a ticket stub, calculates the ticket stub hash value, and encrypts the second half of the ticket stub hash value using the full public key; Step 9: Candidates generate a zero-knowledge proof shard set of encrypted ticket stubs; Step 10: Candidates publish their candidacy information; Step 11: Generate random seed sd2 in a distributed manner in the same way as step 4; Step 12: Participants reveal t'-1 zero-knowledge proof shards based on the random seed sd2 Participant Pi uses a pseudo-random number generator to generate t'-1 different pseudo-random numbers in [1,T'] based on the random seed sd2; that is, PRNG(sd2,T',t'-1)->(Idx1…,Idxt -1 ); Participant Pi publishes the corresponding t'-1 shards' revealed value: The shard corresponding to Idx1 is: the pledge value ciphertext zero-knowledge proof shard Zero-knowledge proof sharding with pledge commitment Pseudo-random number sharding ciphertext zero-knowledge proof sharding Encrypted Ticket Zero-Knowledge Proof Sharding Step 13: Participant Pi verifies the revealed value of other participants (e.g., Pj); Step 14: The participants use the pledged value ciphertexts in all verified election messages to perform a fully homomorphic sum calculation; if all T' election messages are verified, then: Step 15: The participant uses the key shard to decrypt the pledge and ciphertext and publishes the decrypted shard. The participant Pi calculates and publishes: Dsum piecei =Th FHE.PartDec(PK,Csum,SKi); Step 16: The participants collect a threshold number of decrypted shards and decrypt and calculate the plaintext of the pledged sum; let the t' decrypted shards collected by participant Pi be (Dsum piece-i1 ,…,Dsum piece-it ), then: Sum=Th FHE.FinDec(PK,Csum,(Dsum piece-i1 ,…,Dsum piece-it )); Step 17: Participants calculate the scaling ratio based on the plaintext and pseudo-random number range of the staked sum. The scaling ratio is calculated as: Step 18: The participants use the pseudo-random number fragmented ciphertexts in all verified messages to homomorphically synthesize the complete pseudo-random number ciphertext; if all T' participating messages pass verification, the complete pseudo-random number ciphertext is: CPRF = SecretRecover (CPPRF1, ..., CPPRFT'); Step 19: Participants use the scaling ratio to scale the complete pseudo-random number ciphertext, CPRF scaled =scale*CPRF; Step 20: Participants use the pledge value ciphertext and the complete pseudo-random number ciphertext to calculate the election results, i.e. the encrypted ticket stubs of the winners; the election calculation process is as follows: (1) According to the order of pledge (i.e. serial number), calculate the cumulative value of pledged ciphertext: (2) Use the scaled complete pseudo-random number ciphertext to perform homomorphic comparison with the accumulated value ciphertext: (C <1 ,C <2 ,…,C <3 ) =Th FHE.Eval(PK,Ccompare,(CPRF scaled ,(C1,C2,…,C T' ))) (3) Determine the location of the winners: (CL1,CL2,…,CL T' )=Th FHE.Eval(PK,Clocate,(C <1 ,C <2 ,…,C <3 )) (4) Calculate the winning information: C leaderTicket = Th FHE.Eval(PK,Cselect,((Cticket i-piece1 ,…,Cticket i-pieceT' ),(CL1,CL2,…,CL T' ))); Step 21: The participant uses the key shard to decrypt the selected ticket ciphertext and publishes the decrypted shard; the participant Pi calculates and publishes: DLeaderTicket piecei =Th FHE.PartDec(PK,C leaderTicket ,SKi); Step 22: The participants collect a threshold number of decrypted shards, and decrypt and calculate the hash value of the second half of the ticket stub of the winner; let the t' decrypted shards collected by participant Pi be (DLeaderTicket piece-i1 ,…,DLeaderTicket piece-iy' ),but: Step 23: The winner observes that he has won the lottery; assuming Pi is the winner, Pi observes: Step 24: When the winner wants to make his / her selection public, he / she publishes the original image of the ticket. Assuming Pi is the winner, when revealing, Pi publishes the original image of the ticket. i ; Step 25: Other participants calculate and verify the correctness of the election based on the original ticket stub revealed by the winner and his / her election information; assuming Pi is the winner, verify the correctness of Pi's election disclosure:

2. A pledge-hidden deterministic lottery method for a proof-of-stake consensus algorithm as claimed in claim 1, characterized in that: The Circuit calculation circuit specifically includes: Ccompare(C x , C y = (C y1 , …, C yN' )) → (C x<y1 , …, C x<yN' ), where C x is a ciphertext, and C y is a ciphertext vector containing N' ciphertexts; the output is a ciphertext vector, and the i-th element in the vector is the ciphertext of the comparison result of x < yi. The plaintext of the comparison result is 1 or 0, the ciphertext is 1 when x < yi, and the ciphertext is 0 when x >= yi; Clocate(C r1 ,…,C rN' )→(CL1,CL2…,CL T' ), enter middle C r1 ,…,C rN' For N' ciphertexts, the output is a ciphertext vector (CL1, CL2..., CL T' ), the first element in the vector CL1 = C r1 , except for the first element, the i-th element CL i =C ri -C ri-1 ; Cselect((C1,C2…,C N' ),(C x1 ,…,C xN' ))→Cti, the input is two ciphertext vectors of length N', and the output Cti is the dot product of the two ciphertext vectors.

3. A pledge-hidden deterministic lottery method for a proof-of-stake consensus algorithm as claimed in claim 1, characterized in that: In the SecretSharing linear threshold secret sharing function, when using the Shamir secret sharing scheme: Choose an n'-1 degree polynomial on Zq: Where a0 = sv; Select N' points on f(x), (1,f(1)), (2,f(2)), ..., (N',f(N')), N' points are the N' secret shards sv of sv pieces ; Collect any n's sv's secret shards (sv piece-r1 ,…,sv piece-rn' ), where (r1,…,rn')∈(1,…,N') has a secret recovery function: SecretRecover(sv piece-r1 ,…,sv piece-rn' )=sv When using Shamir's secret sharing scheme When restoring on the index:

4. A pledge-hidden deterministic lottery method for a proof-of-stake consensus algorithm as claimed in claim 1, characterized in that: The specific steps for the participants in step 2 to generate the complete public key in a distributed manner, decrypt the key shards, calculate the shard public key and publish the shard public key are: Participants generate the fully homomorphic encryption key DKG(pp,t,T)->(PK,SK1,…,SK T ):pp is the public parameter generated in Setup, t is the decryption threshold; the specific operations are as follows: (1) In B[x] / (x N +1) randomly selects k N-1 order polynomials to generate the partial private key of FHE: (2)Pi: at T[x] / (x N +1) to obtain a k-dimensional vector for generating the public key and broadcast it publicly: (3) Pi: Calculation: (4)Pi: at T[x] / (x N +1) takes k extremely small noise polynomials, where the coefficients of the polynomials are in the Gaussian distribution ν(μ,σ 2 ) to generate a k-dimensional noise vector: (5) Pi: Generate the FHE public key PPKi corresponding to the partial private key PSKi and make it public: Be j (x)6Assume j ·PSKi j (x)+ei j (x)j∈(1,2,...,k) PPKi=((Assume1(x),Bi1(x)),...,(Assume k (x),By k (x))) (6) Pi: Calculate the complete public key: (7) Pi: Generate T secret fragments of PSKi using the secret sharing algorithm: SecretSh aring(PSKi)=(PSKi sh are1 ,...,PSKI sh areT ) The j-th secret shard of PSKi: PSKi sh arej =(PSKi 1-sh arej ,...,PSKi k-sh arej )j∈(1,2,..,T) Collect any t PSKi share That is, PSKi can be restored; (8) Pi: Select T-1 PSKi from the generated secret shards of T PSKi according to the sequence number. share Distribute to the corresponding other decryption participants (such as Pj); and calculate the discrete logarithm public key for publishing T secret shards: (9) After all decryption participants have distributed the secret shards, the decryption key shards held by Pi are: The corresponding FHE key shard k-dimensional vector is: (10) Pi: Calculate and publish the shard public key of the decryption key shard: (11) Pi: Verify the shard public keys issued by other participants based on other participants.

5. A pledge-hidden deterministic lottery method for a proof-of-stake consensus algorithm as claimed in claim 1, characterized in that: In step 5, the specific steps for the participant Pi to generate a pseudo-random number fragment PPRFi based on the random seed sd1 are as follows: the participant uses the key-homomorphic pseudo-random function Flwe to generate PPRFi = Flwe (SKi, sd1); randomly generate two T q m×n matrix on: A0, A1; convert sd1 into binary: sd1 = x1x2x3…x u , is the number of digits; When x j =0, Axj = A0; when x j When =1, Axj=A1.

6. A pledge-hidden deterministic lottery method for a proof-of-stake consensus algorithm as claimed in claim 1, characterized in that: The specific steps in step 6 where the participant uses the complete public key to encrypt the pseudo-random number shard and generate the corresponding T' zero-knowledge proof shards are: (1) The participant uses the complete public key PK to encrypt PPRFi and obtain the ciphertext: (2) Participant Pi uses the secret sharing algorithm to generate SKi,r prf-i ,e prf-i T' shards: SKi pieces =SecretSh aring(SKi)=(SKi piece1 ,...,SKi pieceT' ) in, Collect any t'SKi piece , That is, SKi can be restored. (3) Participant Pi generates SKi pieces The corresponding discrete logarithm public key: PPK i ' pieces =(PPK i ' piece1 ,...,PPK i ' pieceT' ) in, (4) The participant generates T' shards of the pseudo-random number shard CPPRFi: Among them, the Lth shard: Collect any t' That is, you can restore 7. A pledge-hidden deterministic lottery method for a proof-of-stake consensus algorithm as claimed in claim 1, characterized in that: The specific steps in step 7 where the participant uses the complete public key to encrypt the pledge value and generate the corresponding T' zero-knowledge proof shards are: (1) Participant Pi uses the complete public key PK to encrypt the pledge value and generate the pledge ciphertext: Among them, STKi is the pledge value of Pi, is a random number, e stki is the encryption noise; (2) Participant Pi uses the secret sharing algorithm to cut STKi, and e stki , generate T' shards: (3) Participant Pi uses STKi pieces , and Generate T' shards of CSTKi: CSTKi Pieces =(CSTKi piece1 ,...,SCTKi pieceT' ) Collect any t' CSTKi piece , that is, CSTKi can be restored; among them, (4) Participant Pi uses the secret sharing algorithm to generate T' shards of the pledge commitment CMi: ① Participant Pi uses the secret sharing algorithm to generate a pledge commitment random number R i T' shards: ② Participant Pi shares with R according to STKi sharding i Shards generate T' shards of pledge commitment CMi: in, 8. A pledge-hidden deterministic lottery method for a proof-of-stake consensus algorithm as claimed in claim 1, characterized in that: The specific steps in step 8 where the participant generates a ticket stub, calculates the ticket stub hash value, and encrypts the second half of the ticket stub hash value using the full public key are: (1) Participant Pi is in Z q A random number is randomly selected as the ticket stub, denoted as Ticket i ; (2) Participant Pi calculates the ticket stub hash value: Hticket i =Hash(Ticket i ); (3) Participant Pi sends the ticket stub hash value Hticket i Split from the middle: (4) Participant Pi uses the full public key to encrypt the second half of the ticket stub hash value: in, The random number used for encryption, Noise added for encryption.

9. A pledge-hidden deterministic lottery method for a proof-of-stake consensus algorithm as claimed in claim 1, characterized in that: The specific steps for the candidate to generate the zero-knowledge proof shard set of encrypted ticket stubs in step 9 are: (1) Participant Pi uses the secret sharing algorithm to cut Generate T' shards respectively; (2) Participant Pi according to Generate Cticket i T' shards; Collect any t' Ctickets i-piece , that is, Cticket can be restored; among them, 10. A pledge-hidden deterministic lottery method for a proof-of-stake consensus algorithm as claimed in claim 1, characterized in that: In step 10, the candidate publishes the election message specifically including: Candidate Pi's election message RegisMsg i ={ Pledge commitment: CM i , Pledge value ciphertext: CSTKi, Staking value ciphertext zero-knowledge proof shard set: Pledge value ciphertext shard set: (CSTKi piece1 ,...,CSTKi pieceT' ) Pledge commitment shard set: Pseudo-random number fragmentation ciphertext: CPPRFi Pseudo-random number sharded ciphertext zero-knowledge proof set: (CPPRFi piece1 ,...,CPPRFi pieceT' ), Discrete logarithmic public key set of shard key slice: (PPK i ' piece1 ,...,PPK i ' pieceT' ), Encrypted ticket stub (encrypted second half of the ticket stub hash value): Cticket i , Encrypted Ticket Zero-Knowledge Proof Shard Set: (CTicket i-piece1 ,…,Cticket i-pieceT' ), The first half of the ticket stub hash value: }.

11. A pledge-hidden deterministic lottery method for a proof-of-stake consensus algorithm as claimed in claim 1, characterized in that: In step 13, the revealed value of other participants verified by participant Pi is specifically: When verifying the authenticity of the ciphertext pledge value: When verifying the authenticity of Pj's pseudo-random number fragmentation ciphertext CPPRFj: (1) For example, the CPPRFj slice with serial number Idx1 The revealed value of is: (2) Verify whether the pseudo-random number sharding ciphertext zero-knowledge proof can restore CPPRFj: SecretRecover(CPPRFj piece1 ,...,CPPRFj pieceT' )?=CPPRFj (3) Verify that the set of discrete logarithmic public keys of the shard key slice corresponds to the discrete logarithmic shard public key published by Pj in step 2-10: SecretRecover(PPK j ' piece1 ,...,PPK j ' pieceT' )?=PPK j '; (4) Use the discrete logarithmic public key set (PPK) of the verified shard key slice j ' piece1 ,...,PPK j ' pieceT' ), verify whether the key shard for generating the pseudo-random number shard is consistent with its discrete logarithm public key among the revealed t'-1 pseudo-random number shard ciphertext zero-knowledge proof shards: for example, when the serial number is Idx1, (5) Verify whether the encryption is correct in the revealed t'-1 pseudo-random number shard ciphertext zero-knowledge proof shards: in,, Should be within the noise range; When verifying the authenticity of the encrypted ticket: (1) For example, Cticket with serial number Idx1 j slice The revealed value of is: (2) Verify whether the pseudo-random number sharding ciphertext zero-knowledge proof can restore Cticket j : SecretRecover(Cticket j-piece1 ,…,Cticket j-pieceT' )?=Cticket j (3) Verify whether the encryption of each of the revealed t'-1 encrypted ticket stub ciphertext zero-knowledge proof shards is correct: For example, when verifying the slice with serial number Idx1: in, Should be within the noise range; When verifying the correctness of the pledge value ciphertext: (1) For example, the pledge ciphertext CSTKj with serial number Idx1 is sliced ​​CSTKj piece-idx1 The revealed value of is: The pledge commitment CM with serial number Idx1 j slice The revealed value of is: Among them, STKj in the pledge ciphertext disclosure value with the same serial number piece Should be the same as STKj in the pledge commitment reveal value piece Consistency; (2) Verify whether the pledged ciphertext zero-knowledge proof shard set can restore CSTKj: SecretRecover(CSTKi piece1 ,...,CSTKi pieceT' )?=CSTKj (3) Verify whether the pledge commitment zero-knowledge proof shard set can restore CM j : Among them, SecretRecover here is a restoration scheme based on the index; (4) Verify whether the encryption of each shard among the revealed t'-1 pledged ciphertext zero-knowledge proof shards is correct: For example, when verifying the slice with serial number Idx1: in, Should be within the noise range; (5) Verify whether the calculation of each shard among the revealed t'-1 pledged ciphertext zero-knowledge proof shards is correct: For example, when verifying the slice with serial number Idx1: