Privacy protection method and device based on batch zero-knowledge proof, equipment and medium

By combining the generation of multiple sets of commitment values and Galois autoisomorphic results, the construction of masking matrix hides private information, solving the problem of high communication complexity in batch zero-knowledge proofs, and achieving efficient privacy protection.

CN120378116APending Publication Date: 2025-07-25CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510535473.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the privacy protection based on batch zero-knowledge proof, the communication complexity is high, the probability of reasonable errors is high, and the completeness, rationality and zero-knowledge cannot be effectively guaranteed.

Method used

By generating multiple sets of commitment values, the masking matrix is constructed to hide private information, and the target response is determined using Galois autoisomorphic results, ensuring that the verification party cannot deduce private information, reducing the number of communication rounds and calculation complexity.

Benefits of technology

It realizes that while ensuring the completeness, rationality and zero knowledge of the proof, the communication complexity and calculation complexity are reduced, and the efficiency of the proof process is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378116A_ABST
    Figure CN120378116A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy protection method and device based on batch zero-knowledge proof, equipment and a medium, and relates to the technical field of information security, and the method comprises the steps: generating different multiple groups of commitment values based on different preset private information of private information owners, constructing a masking matrix for hiding the preset private information based on the multiple groups of commitment values, and hiding the preset private information based on the masking matrix; sending target information determined based on the masking matrix to a verification party, so that the verification party selects a target challenge from a preset challenge space and sends the target challenge to a privacy information holder; determining a target response corresponding to the target challenge by using the masking matrix, preset private information and the target isomorphic result; and if an output result determined based on the target response is a preset result, sending the target response to the verification party, so that the verification party checks the target response, and determining whether the proof, corresponding to the commitment value, of the privacy information holder is accepted by the verification party based on a check result. The communication complexity is reduced; and the completeness, rationality and zero knowledge of the certification are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly to a privacy protection method, device, equipment and medium based on batch zero-knowledge proof. Background Art

[0002] Zero-knowledge proof is a two-party interactive protocol that allows the holder of private information to prove to the verifier that a certain assertion is correct without disclosing any private information, and is widely used in advanced privacy protection protocols. The security requirements for zero-knowledge proof are completeness, soundness, and zero-knowledge. Completeness requires that any honest holder of private information can make the verifier accept their proof; soundness means that any cheating holder of private information can hardly deceive the verifier into accepting their proof. Further, the soundness error probability refers to the probability that a cheating holder of private information succeeds in deception; zero-knowledge means that after the interaction is completed, the verifier cannot obtain any additional information except for the correctness of the assertion.

[0003] When the prior art implements privacy protection based on batch zero-knowledge proof, in order to ensure the soundness of the proof, the challenge space is limited to a set that meets specific conditions, that is, the difference between any two challenge values must be reversible, and the coefficient of the inverse of the challenge difference cannot be too large, which results in a very small scale of the challenge space that meets the conditions. A too small challenge space scale will directly lead to a high soundness error probability of the scheme. To achieve the set security strength, the protocol will be executed multiple rounds repeatedly, resulting in too high communication complexity.

[0004] As can be seen from the above, how to reduce the communication complexity and ensure the completeness, soundness, and zero-knowledge of the proof is an urgent problem to be solved at present. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide a privacy protection method, device, equipment and medium based on batch zero-knowledge proof, which can reduce the communication complexity and ensure the completeness, soundness, and zero-knowledge of the proof. The specific scheme is as follows:

[0006] In a first aspect, the present application provides a privacy protection method based on batch zero-knowledge proof, which is applied to the holder of private information and includes:

[0007] Obtain multiple preset private information of the holder of private information, and generate different commitment values based on different said preset private information to obtain multiple groups of commitment values; the preset private information is parameter information existing in the form of a random vector;

[0008] Construct a masking matrix for hiding the preset private information based on the multiple groups of commitment values, and determine the target information to be sent to the verifier based on the masking matrix;

[0009] Send the target information to the verifier, so that after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the privacy information holder; the preset challenge space is a challenge space determined based on a preset polynomial ring;

[0010] Determine a target response corresponding to the target challenge by using the masking matrix, the preset private information, and the target isomorphism result; the target isomorphism result is the Galois automorphism result of the preset polynomial ring;

[0011] If the output result determined based on the target response is a preset result, send the target response to the verifier, so that the verifier checks the target response and determines whether the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier based on the check result.

[0012] Optionally, the obtaining multiple preset private information of the privacy information holder and generating different commitment values based on different preset private information to obtain multiple groups of commitment values includes:

[0013] Obtain the parameter information existing in the form of a random vector in the privacy information holder to obtain multiple preset private information;

[0014] Generate corresponding commitment values based on each preset private message, the corresponding polynomial vector parameter, and the first public parameter in the preset commitment strategy to obtain multiple groups of commitment values;

[0015] Wherein, the polynomial vector parameter is a vector parameter determined based on a preset noise distribution.

[0016] Optionally, the constructing a masking matrix for hiding the preset private information based on the multiple groups of commitment values and determining the target information to be sent to the verifier includes:

[0017] Determine a masking distribution for hiding the preset private information by using the preset private information, and determine a corresponding masking matrix from the masking distribution based on a preset selection method;

[0018] Determine the target information to be sent to the verifier by using the first public parameter and the masking matrix.

[0019] Optionally, sending the target information to the verifier so that, after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the privacy information holder, includes:

[0020] Sending the target information to the verifier so that, after receiving the target information, the verifier determines a corresponding polynomial set based on a preset polynomial and determines the polynomial set that meets the preset challenge condition as the preset challenge space;

[0021] Determining a target challenge corresponding to the commitment value based on the preset challenge space and sending the target challenge to the privacy information holder;

[0022] Wherein, the preset challenge condition is that the sum of the absolute values of all coefficients in the polynomial set does not exceed a preset absolute value threshold, and the maximum absolute value among the absolute values of all coefficients of the polynomial set is a first preset value.

[0023] Optionally, sending the target information to the verifier so that, after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the privacy information holder, includes:

[0024] Sending the target information to the verifier so that, after receiving the target information, the verifier selects a target challenge from a preset challenge space and performs a number-theoretic transform based on the target challenge and other challenges in the preset challenge space to obtain the number-theoretic transform coordinates of non-zero challenge differences;

[0025] Traversing the number-theoretic transform coordinates using a Galois automorphism and checking the number-theoretic transform coordinates during the traversal to obtain corresponding check results, and then piecing together the number-theoretic transform coordinates based on the check results to obtain a pieced-together result;

[0026] Correspondingly, after sending the target response to the verifier if the output result determined based on the target response is a preset result, further includes:

[0027] Verifying the target response using the pieced-together result, the masking matrix, the target challenge, the commitment value, and the target isomorphism result to determine whether the target response is correct based on the verification result;

[0028] If the target response is correct, trigger the step for the verifier to check the target response.

[0029] Optionally, if the output result determined based on the target response is a preset result, the target response is sent to the verifier so that the verifier can check the target response and determine whether the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier based on the check result, including:

[0030] Based on the target response, the target isomorphism result, and the preset private information, and using the rejection sampling algorithm to obtain corresponding output values, and determine whether the output values are the second preset values;

[0031] If the output values are the second preset values, the target response is sent to the verifier so that the verifier can check the elements in the target response and determine whether the check result meets the preset acceptance conditions;

[0032] If the check result meets the preset acceptance conditions, it is determined that the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier;

[0033] Wherein, the preset acceptance conditions are acceptance conditions determined based on the first public parameter and the second public parameter in the preset commitment strategy.

[0034] Optionally, if the output values are the second preset values, the target response is sent to the verifier so that the verifier can check the elements in the target response and determine whether the check result meets the preset acceptance conditions, including:

[0035] If the output values are the second preset values, the target response is sent to the verifier so that the verifier can determine the second norms corresponding to the elements in each column of the target response and determine whether each of the second norms does not exceed the target norm threshold;

[0036] If each of the second norms does not exceed the target norm threshold, a first parameter result is determined based on the target response and the first public parameter, and a second parameter result is determined using the target information, the second public parameter, and the target isomorphism result, and it is determined whether the first parameter result is equal to the second parameter result;

[0037] If the first parameter result is equal to the second parameter result, it indicates that the check result meets the preset acceptance conditions.

[0038] In a second aspect, the present application provides a privacy protection device based on batch zero-knowledge proof, which is applied to a privacy information holder, including:

[0039] A commitment value generation module, configured to obtain multiple preset private information of the privacy information holder, and generate different commitment values based on different said preset private information to obtain multiple sets of commitment values; the preset private information is parameter information existing in the form of a random vector;

[0040] A masking matrix construction module, configured to construct a masking matrix for hiding the preset private information based on the multiple sets of commitment values, and determine target information to be sent to the verifier based on the masking matrix;

[0041] A target challenge selection module, configured to send the target information to the verifier, so that after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the privacy information holder; the preset challenge space is a challenge space determined based on a preset polynomial ring;

[0042] A target response determination module, configured to determine a target response corresponding to the target challenge by using the masking matrix, the preset private information, and a target isomorphism result; the target isomorphism result is a Galois automorphism result of the preset polynomial ring;

[0043] A target response check module, configured to, if an output result determined based on the target response is a preset result, send the target response to the verifier, so that the verifier checks the target response and determines whether the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier based on the check result.

[0044] In a third aspect, the present application provides an electronic device, including:

[0045] A memory, configured to store a computer program;

[0046] A processor, configured to execute the computer program to implement the foregoing privacy protection method based on batch zero-knowledge proof.

[0047] In a fourth aspect, the present application provides a computer-readable storage medium, configured to store a computer program, wherein the computer program, when executed by a processor, implements the foregoing privacy protection method based on batch zero-knowledge proof.

[0048] This application obtains multiple preset private information of the privacy information holder, generates different commitment values based on different said preset private information to obtain multiple sets of commitment values; the preset private information is parameter information existing in the form of a random vector; constructs a masking matrix for hiding the preset private information based on the multiple sets of commitment values, and determines the target information to be sent to the verifier based on the masking matrix; sends the target information to the verifier, so that after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the privacy information holder; the preset challenge space is a challenge space determined based on a preset polynomial ring; determines a target response corresponding to the target challenge by using the masking matrix, the preset private information, and a target isomorphism result; the target isomorphism result is the Galois automorphism result of the preset polynomial ring; if the output result determined based on the target response is a preset result, sends the target response to the verifier, so that the verifier checks the target response and determines whether the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier based on the check result.

[0049] As can be seen from the above, this application generates different commitment values based on different preset private information of the privacy information holder, constructs a masking matrix using the commitment values to hide the preset private information, then constructs target information based on the masking matrix, then obtains the target challenge selected by the verifier from the preset challenge space, and determines the target response based on the masking matrix, the preset private information, and the Galois automorphism result of the preset polynomial ring, ensuring that the privacy information holder can generate a correct response based on the preset private information, while the verifier cannot deduce the private information from the response. Then, the target response is checked and judged, and it is determined whether the proof corresponding to the prover and the commitment value has been accepted based on the check result. In this way, the preset private information of the privacy information holder can be protected throughout the proof process. By batch-processing the preset private information, scenarios with a large amount of private information can be processed, reducing the number of communication rounds and computational complexity, making the proof process more efficient. Brief Description of the Drawings

[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on the provided drawings without creative efforts.

[0051] Figure 1 It is a flowchart of a privacy protection method based on batch zero-knowledge proof disclosed in this application;

[0052] Figure 2 A flowchart of a specific privacy protection method based on batch zero - knowledge proof disclosed in this application;

[0053] Figure 3 A schematic structural diagram of a privacy protection device based on batch zero - knowledge proof disclosed in this application;

[0054] Figure 4 A structural diagram of an electronic device disclosed in this application. Detailed implementation manners

[0055] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0056] Currently, when implementing privacy protection based on batch zero - knowledge proof, in order to ensure the rationality of the proof, it is required that the difference between any two challenge values must be reversible, and the coefficient of the inverse of the challenge difference cannot be too large. This results in a very small challenge space scale that meets the conditions. A too small challenge space scale will directly lead to a high probability of rationality error in the scheme. To achieve the set security strength, the protocol will be executed repeatedly for multiple rounds, resulting in too high communication complexity. For this reason, this application provides a privacy protection method based on batch zero - knowledge proof. The preset private information of the privacy information holder can be protected throughout the proof process. By batch - processing the preset private information, scenarios with a large amount of private information can be processed, reducing the number of communication rounds and computational complexity, making the proof process more efficient.

[0057] See Figure 1 As shown, the embodiments of the present invention disclose a privacy protection method based on batch zero - knowledge proof, which is applied to a privacy information holder and includes:

[0058] Step S11: Obtain multiple preset private information of the privacy information holder, and generate different commitment values based on different preset private information to obtain multiple groups of commitment values; the preset private information is parameter information existing in the form of a random vector.

[0059] In this embodiment, parameter information existing in the form of a random vector is obtained from the privacy information holder to obtain multiple preset private information. The preset private information may be account balances, transaction records, and asset certificates in the financial scenario. The privacy information holder wants to prove that it has sufficient assets for transactions without disclosing specific asset amounts or transaction histories. The preset private information may also be personal identity information, biometric data, and passwords in the identity authentication scenario. The privacy information holder wants to prove its identity to access certain services or resources without disclosing specific identity information or biometric data. The preset private information may further be medical records, diagnostic results, and genetic data in the medical scenario. The privacy information holder wants to prove that it meets certain medical conditions or has specific medical records without disclosing specific medical details.

[0060] It can be understood that after obtaining the multiple preset private information of the privacy information holder, the coefficients of the polynomial vector parameters corresponding to the preset private information are determined from the preset noise distribution to determine the corresponding polynomial vector parameters based on the coefficients. And the length of the polynomial vector parameters is within a preset range. Then, based on the preset private message, the polynomial vector parameters, and the first public parameter in the preset commitment strategy, the corresponding commitment values are generated to obtain multiple sets of commitment values. Specifically, obtaining multiple preset private information of the privacy information holder and generating different commitment values based on different preset private information to obtain multiple sets of commitment values includes: obtaining parameter information existing in the form of a random vector from the privacy information holder to obtain multiple preset private information; generating corresponding commitment values based on each preset private message, the corresponding polynomial vector parameters, and the first public parameter in the preset commitment strategy to obtain multiple sets of commitment values; where the polynomial vector parameters are vector parameters determined based on the preset noise distribution.

[0061] In a specific implementation manner, if there are sets of commitment values , where one set of commitment values is the commitment values generated based on the same random vector, and each set of commitment values contains messages to be committed, that is, . The specific form of the commitment values can be as follows:

[0062] ;

[0063] where is the polynomial vector parameter, is the first public parameter in the preset commitment strategy, and the preset commitment strategy may be a cryptographic commitment strategy. Integrate and into matrix forms respectively to obtain the preset private information and a second common parameter 。

[0064] Step S12: Construct a masking matrix for hiding the preset private information based on the multiple groups of commitment values, and determine the target information to be sent to the verifier based on the masking matrix.

[0065] In this embodiment, after obtaining the multiple groups of commitment values, use the preset private information to determine a masking distribution for hiding the preset private information. The masking distribution is a matrix distribution. Randomly select a target number of masking matrices from the masking distribution. The larger the target number, the higher the security. Therefore, the target number corresponding to the masking matrix can be determined based on specific requirements and characteristics. After obtaining the masking matrix, determine the target information based on the masking matrix and the first common parameter. The formula corresponding to the target information can be:

[0066] ;

[0067] wherein, is the target information; is the first common parameter; is the masking matrix.

[0068] Specifically, the step of constructing a masking matrix for hiding the preset private information based on the multiple groups of commitment values and determining the target information to be sent to the verifier based on the masking matrix includes: using the preset private information to determine a masking distribution for hiding the preset private information, and determining the corresponding masking matrix from the masking distribution based on a preset selection method; using the first common parameter and the masking matrix to determine the target information to be sent to the verifier.

[0069] Step S13: Send the target information to the verifier, so that after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the privacy information holder; the preset challenge space is a challenge space determined based on a preset polynomial ring.

[0070] In this embodiment, after obtaining the target information, the target information is sent to the verifier, so that after receiving the target information, the verifier determines a polynomial set based on a preset polynomial, and determines the polynomial set that meets the preset challenge condition as the preset challenge space, so as to determine a target challenge corresponding to the commitment value from the preset challenge space, and send the target challenge to the privacy information holder. Specifically, the step of sending the target information to the verifier so that the verifier selects a target challenge from the preset challenge space after receiving the target information and sends the target challenge to the privacy information holder includes: sending the target information to the verifier so that after receiving the target information, the verifier determines a corresponding polynomial set based on the preset polynomial, and determines the polynomial set that meets the preset challenge condition as the preset challenge space; determining a target challenge corresponding to the commitment value based on the preset challenge space, and sending the target challenge to the privacy information holder; where the preset challenge condition is that the sum of the absolute values of all coefficients in the polynomial set does not exceed a preset absolute value threshold, and the maximum absolute value among the absolute values of all coefficients of the polynomial set is a first preset value.

[0071] In a specific implementation, a polynomial set is first constructed based on a polynomial , and the polynomial can be as follows:

[0072] ;

[0073] where is a variable representing the unknown of the polynomial , represents that the degree of the polynomial is restricted within . The corresponding one-norm, two-norm, and infinity-norm of the polynomial are as follows:

[0074] ;

[0075] where is the one-norm corresponding to the polynomial , is the two-norm corresponding to the polynomial , is the infinity-norm corresponding to the polynomial . Correspondingly, for the k-dimensional polynomial vector , the corresponding one-norm, two-norm, and infinity-norm are as follows:

[0076] ;

[0077] where is a k-dimensional polynomial vector The corresponding one-norm is a k-dimensional polynomial vector The corresponding two-norm is a k-dimensional polynomial vector The corresponding infinity norm

[0078] Then, determine prime number q and positive integer d, where q satisfies , indicating that divided by has the same remainder as divided by , where is the modulo operation, and is a power of two that divides d. In other words is a factor of d and this factor is a power of two. Then, define polynomial , where the polynomial is in . Among them is the ring of integers modulo q is The polynomial ring over. And the polynomial can be factored into pieces of The irreducible polynomial in . Among them That is is the polynomial All of The primitive roots of unity of degree And they all fall in is Modulo The quotient ring of, that is The formula of can be shown as follows

[0079] ;

[0080] Among them is The polynomial ring over is the preset polynomial is the isomorphism symbol, indicating that there is an isomorphism relationship between two algebraic structures is the direct product symbol, indicating the Cartesian product of multiple polynomial rings is modulo The unit group of, that is, all integers relatively prime to Under the modulo The set under the operation.

[0081] Furthermore, denote as The Galois automorphism over, then The formula can be as follows:

[0082] ;

[0083] where k is a factor of the order of the Galois automorphism ; acts on the polynomial , indicating that the polynomial is subjected to the k - th Galois automorphism transformation. After obtaining (i.e., the polynomial set), taking the sum of the absolute values of all coefficients in the polynomial set not exceeding a preset absolute value threshold, and the maximum absolute value among the absolute values of all coefficients in the polynomial set being a first preset value as a preset challenge condition, and determining the polynomial set that meets the preset challenge condition as the preset challenge space, the formula corresponding to the preset challenge space is:

[0084] ;

[0085] where represents that the element in the preset challenge space comes from ; represents a conditional separator, is the 1 - norm of the coefficient in the polynomial set, represents that the sum of the absolute values of all coefficients in the polynomial set does not exceed the preset absolute value threshold , is the infinity - norm of the coefficient in the polynomial set, represents that the maximum absolute value among the absolute values of all coefficients in the polynomial set is 1. It is worth mentioning that the preset absolute value threshold can be adjusted according to the actual application scenario and is not specifically limited here.

[0086] In this embodiment, after the verifier receives the target information, a target challenge is selected from the preset challenge space, and number - theoretic transform (NTT) is performed based on the target challenge and other challenges in the preset challenge space to obtain the number - theoretic transform coordinates of non - zero challenge differences. Then, the Galois automorphism is used to traverse the number - theoretic transform coordinates, and the number - theoretic transform coordinates are extracted and checked during the traversal to ensure that the extracted number - theoretic transform coordinates are all invertible. Then, the Chinese Remainder Theorem is used to piece together the number - theoretic transform coordinates to obtain the pieced - together result. The pieced - together result not only represents a complete view of the preset private information but can also be used for further verification processes.​

[0087] Specifically, sending the target information to the verifier so that, after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the privacy information holder includes: sending the target information to the verifier so that, after receiving the target information, the verifier selects a target challenge from a preset challenge space and performs a number theory transformation based on the target challenge and other challenges in the preset challenge space to obtain the number theory transformation coordinates of non-zero challenge differences; traversing the number theory transformation coordinates using Galois automorphism and checking the number theory transformation coordinates during the traversal to obtain corresponding check results, and then piecing together the number theory transformation coordinates based on the check results to obtain the pieced-together result.

[0088] Step S14: Determine a target response corresponding to the target challenge by using the masking matrix, the preset private information, and the target isomorphism result; the target isomorphism result is the Galois automorphism result of the preset polynomial ring.

[0089] In this embodiment, after obtaining the target challenge, the Galois automorphism result of the preset polynomial ring is used to obtain the target isomorphism result, and a target response corresponding to the target challenge is determined based on the masking matrix, the preset private information, and the target isomorphism result. The formula for the target response is as follows:

[0090] ;

[0091] where is the Galois automorphism on the preset polynomial ring , represents performing the operation on each element in the challenge space; is the target information; is the masking matrix; is the preset private information.

[0092] Step S15: If the output result determined based on the target response is the preset result, send the target response to the verifier so that the verifier checks the target response and determines whether the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier based on the check result.

[0093] In this embodiment, after obtaining the pieced-together result, the target response is verified by using the pieced-together result, the masking matrix, the target challenge, the commitment value, and the target isomorphism result. Even when the underlying computing environment is split into factors with lower degrees, it can be verified whether the target response is correct. If the target response is correct, the step of triggering the verifier to check the target response is performed to further ensure the integrity of the target response. Specifically, after the target response is sent to the verifier if the output result determined based on the target response is a preset result, it further includes: verifying the target response by using the pieced-together result, the masking matrix, the target challenge, the commitment value, and the target isomorphism result to determine whether the target response is correct based on the verification result; if the target response is correct, triggering the verifier to check the target response.

[0094] It can be understood that after obtaining the target response, a corresponding output value is obtained based on the rejection sampling algorithm and the target response, and it is determined whether the output value is 0. If the output value is 0, the target response is sent to the verifier so that the verifier can check the elements in the target response and determine whether the check result meets the preset acceptance condition. If the check result meets the preset acceptance condition, it is determined that the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier, that is, the proof corresponding to the commitment value is a valid proof. Specifically, after the target response is sent to the verifier if the output result determined based on the target response is a preset result so that the verifier can check the target response and determine whether the proof corresponding to the commitment value of the privacy information holder has been accepted based on the check result, it includes: obtaining a corresponding output value based on the target response, the target isomorphism result, the preset private information, and using the rejection sampling algorithm, and determining whether the output value is a second preset value; if the output value is the second preset value, sending the target response to the verifier so that the verifier can check the elements in the target response and determine whether the check result meets the preset acceptance condition; if the check result meets the preset acceptance condition, it is determined that the proof corresponding to the commitment value of the privacy information holder has been accepted; where the preset acceptance condition is an acceptance condition determined based on the first public parameter and the second public parameter in the preset commitment strategy.

[0095] Further, if the output value is 0, the target response is sent to the verifier so that the verifier can determine the second norms corresponding to the elements of each column in the target response and determine whether each of the second norms does not exceed a target norm threshold; the target norm threshold is a threshold determined based on the statistical characteristics, distribution, and security requirements of the specific scenario of the target response; if each of the second norms does not exceed the target norm threshold, a first parameter result is determined based on the product of the target response and the first common parameter, and a second parameter result is determined using the target information, the second common parameter, and the target isomorphism result, and it is determined whether the first parameter result is equal to the second parameter result. The above process can be represented by the following formula:

[0096] ;

[0097] wherein, is the first common parameter, is the target response, is the target information, is the second common parameter, is the target isomorphism result. If the first parameter result is equal to the second parameter result, that is, the above equation holds, it indicates that the inspection result meets the preset acceptance condition, and it is determined that the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier, and 1 is output. If either each of the second norms does not exceed the target norm threshold or the inspection result meets the preset acceptance condition does not hold, it is determined that the proof corresponding to the commitment value of the privacy information holder is not accepted by the verifier, and 0 is output.

[0098] Specifically, if the output value is the second preset value, the target response is sent to the verifier so that the verifier can check the elements in the target response and determine whether the inspection result meets the preset acceptance condition, including: if the output value is the second preset value, the target response is sent to the verifier so that the verifier can determine the second norms corresponding to the elements of each column in the target response and determine whether each of the second norms does not exceed the target norm threshold; if each of the second norms does not exceed the target norm threshold, a first parameter result is determined based on the target response and the first common parameter, and a second parameter result is determined using the target information, the second common parameter, and the target isomorphism result, and it is determined whether the first parameter result is equal to the second parameter result; if the first parameter result is equal to the second parameter result, it indicates that the inspection result meets the preset acceptance condition.

[0099] As can be seen from the above, the present application generates different commitment values based on different preset private information of the privacy information holder, constructs a masking matrix using the commitment values to hide the preset private information, then constructs target information based on the masking matrix, then obtains the target challenge selected by the verifier from the preset challenge space, and determines the target response based on the masking matrix, the preset private information, and the Galois automorphism result of the preset polynomial ring, ensuring that the privacy information holder can generate a correct response based on the preset private information, while the verifier cannot deduce the private information from the response. Then, the target response is checked and judged, and based on the check result, it is determined whether the proof corresponding to the commitment value by the prover has been accepted. In this way, the preset private information of the privacy information holder can be protected throughout the proof process. By batch-processing the preset private information, scenarios with a large amount of private information can be processed, reducing the number of communication rounds and computational complexity, making the proof process more efficient.

[0100] As can be seen from the above embodiments, the present application performs a proof corresponding to the commitment value based on the preset challenge space and Galois automorphism to ensure the rationality and efficiency of the proof. Therefore, the process of performing a proof corresponding to the commitment value based on the preset challenge space and Galois automorphism is described.

[0101] See Figure 2 As shown, an embodiment of the present invention discloses a specific privacy protection method based on batch zero-knowledge proof, which is applied to a privacy information holder and includes:

[0102] In this embodiment, first, parameter information existing in the form of a random vector in the privacy information holder is obtained to obtain multiple preset private information. Based on each of the preset private messages, the corresponding polynomial vector parameter, and the first public parameter in the preset commitment strategy, corresponding commitment values are generated to obtain multiple groups of commitment values to be proved. Then, the preset private information is used to determine a masking distribution for hiding the preset private information, and a corresponding masking matrix is randomly selected from the masking distribution, so as to determine the target information to be sent to the verifier using the masking matrix and the first public parameter, and send the target information to the verifier. After the verifier receives the target information, a polynomial set is determined based on a preset polynomial, and the polynomial set that meets the preset challenge condition is determined as the preset challenge space. The target challenge corresponding to the commitment value is determined from the preset challenge space, and the target challenge is sent to the privacy information holder.

[0103] Next, after obtaining the target challenge, use the masking matrix, the preset private information, and the Galois automorphism result of the preset polynomial ring to determine the target response corresponding to the target challenge. Then, based on the rejection sampling algorithm and the target response, determine the output result, and judge whether the output value corresponding to the output result is 0. If the output value corresponding to the output result is not 0, jump to the step of randomly selecting the corresponding masking matrix from the masking distribution; if the output value corresponding to the output result is 0, send the target response to the verifier so that the verifier can judge whether the two-norms corresponding to the elements of each column in the target response do not exceed the target norm threshold; if the two-norms corresponding to the elements of each column in the target response do not all exceed the target norm threshold, it is judged that the proof corresponding to the commitment value is not accepted by the verifier, and 0 is output.

[0104] Further, if the two-norms corresponding to the elements of each column in the target response do not exceed the target norm threshold, determine the first parameter result based on the product of the target response and the first public parameter, and use the target information and the product result to determine the second parameter result; the product result is the result determined by the product of the second public parameter and the target isomorphism result; determine the target equation based on the first parameter result and the second parameter result; if the target equation holds, that is, the first parameter result is equal to the second parameter result, it is determined that the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier, and 1 is output; if the target equation does not hold, that is, the first parameter result is not equal to the second parameter result, it is determined that the proof corresponding to the commitment value of the privacy information holder is not accepted by the verifier, and 0 is output.

[0105] As can be seen from the above, in this application, multiple groups of commitment values for proof are generated from multiple preset private information in the privacy information holder, and a masking distribution for hiding the preset private information is determined based on the preset private information, so as to randomly select the corresponding masking matrix from the masking distribution, and use the masking matrix to determine the target information, so that after receiving the target information, the verifier can select the target challenge corresponding to the commitment value from the preset challenge space determined by the polynomial set of the preset challenge conditions, so that the privacy information holder can determine the target response based on the target challenge, and then check the target response to determine whether the proof corresponding to the commitment value has been accepted by the verifier based on the check result. In this way, using a larger preset challenge space can improve the communication efficiency. Even in a large number of proof verification scenarios, it can efficiently realize the proof of multiple groups of commitment values generated using different random vectors, and solve the problems of many communication rounds and high communication complexity in the proof process.

[0106] Correspondingly, seeFigure 3 As shown in the figure, the present application also provides a privacy protection device based on batch zero - knowledge proof, which is applied to the privacy information holder and includes:

[0107] A commitment value generation module 11, configured to obtain multiple preset private information of the privacy information holder, and generate different commitment values based on different preset private information to obtain multiple groups of commitment values; the preset private information is parameter information existing in the form of a random vector;

[0108] A masking matrix construction module 12, configured to construct a masking matrix for hiding the preset private information based on the multiple groups of commitment values, and determine target information to be sent to the verifier based on the masking matrix;

[0109] A target challenge selection module 13, configured to send the target information to the verifier, so that after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the privacy information holder; the preset challenge space is a challenge space determined based on a preset polynomial ring;

[0110] A target response determination module 14, configured to determine a target response corresponding to the target challenge by using the masking matrix, the preset private information, and a target isomorphism result; the target isomorphism result is a Galois automorphism result of the preset polynomial ring;

[0111] A target response check module 15, configured to, if the output result determined based on the target response is a preset result, send the target response to the verifier, so that the verifier checks the target response and determines whether the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier based on the check result.

[0112] As can be seen from the above, the present application generates different commitment values based on different preset private information of the privacy information holder, constructs a masking matrix by using the commitment values to hide the preset private information, then constructs target information based on the masking matrix, then obtains the target challenge selected by the verifier from the preset challenge space, and determines the target response based on the masking matrix, the preset private information, and the Galois automorphism result of the preset polynomial ring, ensuring that the privacy information holder can generate a correct response based on the preset private information, while the verifier cannot deduce the private information from the response. Then, the target response is checked and judged, and based on the check result, it is determined whether the proof corresponding to the prover and the commitment value has been accepted. In this way, the preset private information of the privacy information holder can be protected throughout the proof process. By batch - processing the preset private information, scenarios with a large number of private information can be processed, reducing the number of communication rounds and computational complexity, making the proof process more efficient.

[0113] In some specific embodiments, the commitment value generation module 11 may specifically include:

[0114] A private information acquisition unit, configured to acquire parameter information existing in the form of a random vector in the privacy information holder to obtain a plurality of preset private information;

[0115] A commitment value generation completion unit, configured to generate corresponding commitment values based on each of the preset private messages, the corresponding polynomial vector parameters, and the first public parameter in the preset commitment strategy, so as to obtain multiple groups of commitment values.

[0116] In some specific embodiments, the masking matrix construction module 12 may specifically include:

[0117] A masking distribution determination unit, configured to use the preset private information to determine a masking distribution for hiding the preset private information, and determine a corresponding masking matrix from the masking distribution based on a preset selection method;

[0118] A target information determination unit, configured to use the first public parameter and the masking matrix to determine target information to be sent to the verifier.

[0119] In some specific embodiments, the target challenge selection module 13 may specifically include:

[0120] A challenge space determination unit, configured to send the target information to the verifier, so that after receiving the target information, the verifier determines a corresponding polynomial set based on a preset polynomial, and determines a preset challenge space that satisfies the preset challenge condition;

[0121] A target challenge sending unit, configured to determine a target challenge corresponding to the commitment value based on the preset challenge space, and send the target challenge to the privacy information holder.

[0122] In some specific embodiments, the target challenge selection module 13 may specifically include:

[0123] A number theory transform coordinate determination unit, configured to send the target information to the verifier, so that after receiving the target information, the verifier selects a target challenge from the preset challenge space, and performs a number theory transform based on the target challenge and other challenges in the preset challenge space to obtain the number theory transform coordinates of the non-zero challenge difference;

[0124] A number theory transform coordinate checking unit is used to traverse the number theory transform coordinates by using Galois automorphism, and check the number theory transform coordinates during the traversal to obtain corresponding check results, and then piece together the number theory transform coordinates based on the check results to obtain a pieced-together result;

[0125] Correspondingly, the privacy protection device based on batch zero-knowledge proof may specifically further include:

[0126] A target response verification unit is used to verify the target response by using the pieced-together result, the masking matrix, the target challenge, the commitment value, and the target isomorphism result, so as to judge whether the target response is correct based on the verification result;

[0127] A target response judgment unit is used to, if the target response is correct, trigger the step of the verifier to check the target response.

[0128] In some specific embodiments, the target response checking module 15 may specifically include:

[0129] An output value judgment unit is used to obtain a corresponding output value based on the target response, the target isomorphism result, the preset private information and by using the rejection sampling algorithm, and judge whether the output value is a second preset value;

[0130] An element checking unit is used to, if the output value is the second preset value, send the target response to the verifier so that the verifier can check the elements in the target response and judge whether the check result meets a preset acceptance condition;

[0131] A check result judgment unit is used to, if the check result meets the preset acceptance condition, determine that the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier.

[0132] In some specific embodiments, the target response checking module 15 may specifically include:

[0133] A two-norm judgment unit is used to, if the output value is the second preset value, send the target response to the verifier so that the verifier can determine the two-norms corresponding to the elements in each column of the target response and judge whether each of the two-norms does not exceed a target norm threshold;

[0134] A parameter result judgment unit is used to, if each of the two-norms does not exceed the target norm threshold, determine a first parameter result based on the target response and the first public parameter, and determine a second parameter result by using the target information, the second public parameter, and the target isomorphism result, and judge whether the first parameter result is equal to the second parameter result;

[0135] An inspection result determination unit, configured to represent that the inspection result meets a preset acceptance condition if the first parameter result is equal to the second parameter result.

[0136] Furthermore, an embodiment of the present application also discloses an electronic device. Figure 4 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure cannot be considered as any limitation to the scope of use of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the privacy protection method based on batch zero-knowledge proof disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0137] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitation is made here.

[0138] In addition, the memory 22 as a carrier for resource storage may be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc., and the resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be short-term storage or permanent storage.

[0139] Among them, the operating system 221 is used to manage and control each hardware device on the electronic device 20 and the computer program 222, and it may be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the privacy protection method based on batch zero-knowledge proof executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs that can be used to complete other specific tasks.

[0140] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the privacy protection method based on batch zero-knowledge proof disclosed above. For the specific steps of this method, reference may be made to the corresponding content disclosed in the foregoing embodiments, and details are not described herein again.

[0141] In this specification, the various embodiments are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.

[0142] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0143] The steps of the methods or algorithms described in combination with the embodiments disclosed in this article can be directly implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0144] Finally, it should be noted that in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitations, the element defined by the statement "including an..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

[0145] The above has introduced the technical solution provided by this application in detail. Specific examples are used in this article to expound the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A privacy protection method based on batch zero-knowledge proof, characterized in that Applied to the privacy information holder, including: Obtain multiple preset private information of the privacy information holder, and generate different commitment values based on different said preset private information to obtain multiple sets of commitment values; the preset private information is parameter information existing in the form of a random vector; Construct a masking matrix for hiding the preset private information based on the multiple sets of commitment values, and determine the target information to be sent to the verifier based on the masking matrix; Send the target information to the verifier, so that after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the privacy information holder; the preset challenge space is a challenge space determined based on a preset polynomial ring; Determine a target response corresponding to the target challenge by using the masking matrix, the preset private information, and a target isomorphism result; the target isomorphism result is a Galois automorphism result of the preset polynomial ring; If the output result determined based on the target response is a preset result, send the target response to the verifier, so that the verifier checks the target response and determines whether the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier based on the check result.

2. The privacy protection method based on batch zero-knowledge proof according to claim 1, wherein, The obtaining multiple preset private information of the privacy information holder and generating different commitment values based on different said preset private information to obtain multiple sets of commitment values includes: Obtain parameter information existing in the form of a random vector in the privacy information holder to obtain multiple preset private information; Generate corresponding commitment values based on each said preset private message, the corresponding polynomial vector parameter, and the first public parameter in the preset commitment strategy to obtain multiple sets of commitment values; Wherein, the polynomial vector parameter is a vector parameter determined based on a preset noise distribution.

3. The privacy protection method based on batch zero-knowledge proof according to claim 2, wherein The constructing a masking matrix for hiding the preset private information based on the multiple sets of commitment values and determining the target information to be sent to the verifier based on the masking matrix includes: Determine a masking distribution for hiding the preset private information by using the preset private information, and determine a corresponding masking matrix from the masking distribution based on a preset selection method; Determine the target information to be sent to the verifier by using the first public parameter and the masking matrix.

4. The privacy protection method based on batch zero-knowledge proof according to claim 1, wherein The sending the target information to the verifier, so that after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the privacy information holder includes: Send the target information to the verifier, so that after receiving the target information, the verifier determines a corresponding polynomial set based on a preset polynomial and determines the polynomial set that meets the preset challenge condition as the preset challenge space; Determine a target challenge corresponding to the commitment value based on the preset challenge space and send the target challenge to the privacy information holder; Among them, the preset challenge condition is that the sum of the absolute values of all coefficients in the polynomial set does not exceed a preset absolute value threshold, and the maximum absolute value among the absolute values of all coefficients in the polynomial set is a first preset value.

5. The privacy protection method based on batch zero-knowledge proof according to any one of claims 1 to 4, characterized in that, The sending the target information to the verifier so that after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the private information holder includes: Sending the target information to the verifier so that after receiving the target information, the verifier selects a target challenge from a preset challenge space and performs a number-theoretic transform based on the target challenge and other challenges in the preset challenge space to obtain the number-theoretic transform coordinates of non-zero challenge differences; Traversing the number-theoretic transform coordinates using a Galois automorphism and checking the number-theoretic transform coordinates during the traversal to obtain corresponding check results, and then piecing together the number-theoretic transform coordinates based on the check results to obtain a pieced-together result; Correspondingly, after sending the target response to the verifier if the output result determined based on the target response is a preset result, it further includes: Verifying the target response using the pieced-together result, the masking matrix, the target challenge, the commitment value, and the target isomorphism result to determine whether the target response is correct based on the verification result; If the target response is correct, trigger the step of the verifier checking the target response.

6. The privacy protection method based on batch zero-knowledge proof according to claim 2, characterized in that, The sending the target response to the verifier if the output result determined based on the target response is a preset result so that the verifier checks the target response and determines whether the proof corresponding to the commitment value of the private information holder has been accepted by the verifier includes: Obtaining a corresponding output value based on the target response, the target isomorphism result, and the preset private information using a rejection sampling algorithm, and determining whether the output value is a second preset value; If the output value is the second preset value, send the target response to the verifier so that the verifier checks the elements in the target response and determines whether the check result meets a preset acceptance condition; If the check result meets the preset acceptance condition, determine that the proof corresponding to the commitment value of the private information holder has been accepted by the verifier; Among them, the preset acceptance condition is an acceptance condition determined based on the first public parameter and the second public parameter in the preset commitment strategy.

7. The privacy protection method based on batch zero-knowledge proof according to claim 6, characterized in that The sending the target response to the verifier if the output value is the second preset value so that the verifier checks the elements in the target response and determines whether the check result meets a preset acceptance condition includes: If the output value is the second preset value, send the target response to the verifier so that the verifier determines the second norms corresponding to the elements in each column of the target response and determines whether each of the second norms does not exceed a target norm threshold; If each of the second norms does not exceed the target norm threshold, determine a first parameter result based on the target response and the first common parameter, and determine a second parameter result by using the target information, the second common parameter, and the target isomorphism result, and determine whether the first parameter result is equal to the second parameter result; If the first parameter result is equal to the second parameter result, it indicates that the inspection result meets the preset acceptance condition.

8. A privacy protection device based on batch zero-knowledge proof, characterized in that, Applied to the privacy information holder, it includes: A commitment value generation module, configured to obtain a plurality of preset private information of the privacy information holder, and generate different commitment values based on different preset private information to obtain multiple groups of commitment values; the preset private information is parameter information existing in the form of a random vector; A masking matrix construction module, configured to construct a masking matrix for hiding the preset private information based on the multiple groups of commitment values, and determine target information to be sent to the verifier based on the masking matrix; A target challenge selection module, configured to send the target information to the verifier, so that after receiving the target information, the verifier selects a target challenge from a preset challenge space and sends the target challenge to the privacy information holder; the preset challenge space is a challenge space determined based on a preset polynomial ring; A target response determination module, configured to determine a target response corresponding to the target challenge by using the masking matrix, the preset private information, and the target isomorphism result; the target isomorphism result is the Galois automorphism result of the preset polynomial ring; A target response inspection module, configured to, if the output result determined based on the target response is a preset result, send the target response to the verifier, so that the verifier inspects the target response and determines whether the proof corresponding to the commitment value of the privacy information holder has been accepted by the verifier based on the inspection result.

9. An electronic device, characterized in that, It includes: A memory, configured to store a computer program; A processor, configured to execute the computer program to implement the privacy protection method based on batch zero-knowledge proof according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, For storing a computer program, wherein when the computer program is executed by the processor, it implements the privacy protection method based on batch zero-knowledge proof according to any one of claims 1 to 7.