Non-linkable and variable-limit cross-chain asset transfer method
By introducing electronic bulletin boards and advanced encryption technology in cross-chain asset transfers and building anonymous collections, the privacy, flexibility and security issues in cross-chain asset transfers are solved, and efficient and secure cross-chain asset transfers are achieved.
Patent Information
- Application Number
- CN202510770833.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-09-12
AI Technical Summary
Existing cross-chain asset transfer technologies face problems such as insufficient privacy, flexibility, and security, high transaction overhead, atomicity defects, and susceptibility to Griefing attacks, which lead to inconsistent asset status and system vulnerabilities.
It adopts an unlinkable and variable-amount cross-chain asset transfer method, builds an anonymous collection through an electronic bulletin board, utilizes randomizable commitments and non-interactive zero-knowledge proof technology to achieve secure transfer between asset senders, payment centers, and receivers, adopts exchange protocols and redemption protocols to ensure atomicity, and uses randomizable signatures and blind BLS signature technology to protect privacy and avoid duplicate transactions on the chain.
It achieves the atomicity, unlinkability, variability, de-collateralization and resistance to Griefing attacks of asset transfer, reduces the number of transactions and on-chain overhead, and improves the security and flexibility of cross-chain transactions.
Smart Images

Figure CN120634708A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of blockchain technology, and specifically relates to a cross-chain asset transfer method that is unlinkable and has variable amounts. Background Art
[0002] As a decentralized distributed ledger, blockchain offers transparency, immutability, and security, making it a fundamental component of digital asset management. Since the advent of Bitcoin in 2008, blockchain technology has been widely adopted in a variety of fields, including finance, asset management, and supply chains. With the continuous evolution of blockchain technology, it is estimated that by 2030, blockchain will account for approximately 10% of the global money supply. However, traditional blockchain systems are typically designed in isolation, with each blockchain network operating within its own boundaries. This makes it impossible to directly transfer assets between different blockchains. Cross-chain asset transfer has become a critical requirement, enabling users to flexibly transfer assets between different blockchains, significantly improving asset liquidity and expanding its application scenarios.
[0003] Existing cross-chain asset transfer technologies are categorized by technology type: third-party blockchains, proof relays, and notaries. Third-party blockchains utilize one or more third-party blockchains to achieve cross-chain asset transfers. Proof relay solutions involve transmitting proof-related information between chains. Notaries rely on one or more third parties to manage cross-chain asset transfers.
[0004] However, existing cross-chain asset transfer technologies face issues such as insufficient privacy, flexibility, and security, as well as high transaction costs. These issues can be embodied in the following six aspects:
[0005] 1. Atomicity Flaws: Existing cross-chain transfer solutions often rely on multi-party trust or complex protocol mechanisms, making some transactions successful while others fail, leading to inconsistent asset status and system vulnerabilities. This deficiency threatens the reliability and security of cross-chain transactions, especially in the event of unexpected interruptions or partial node failures in the cross-chain system. Atomicity flaws can lead to irreversible asset loss.
[0006] 2. Transaction parties are linkable: On-chain observers can track transactions and discover the payment relationship between senders and receivers, creating the risk of losing competitive advantage.
[0007] 3. Fixed transfer amount: Existing cross-chain asset transfer solutions that achieve unlinkability require the construction of a fixed-amount sender-receiver anonymous set, resulting in insufficient flexibility.
[0008] 4. Huge on-chain overhead: When processing cross-chain asset transfers from one sender to m receivers (abbreviated as 1-m transfers), the existing solution needs to repeat the 1-1 transfer m times. The number of transactions required is m times that of the 1-1 transfer, resulting in huge on-chain overhead.
[0009] 5. The sender needs to pledge assets: Existing solutions require the sender to lock additional assets on its chain as collateral to obtain the recipient's request qualification from an untrusted third party, which limits the participation of senders with insufficient funds.
[0010] 6. Griefing attack: The recipient initiates a lock transaction request to a third party, causing the third party to lock assets but not cooperate with the third party's subsequent operations. As a result, the third party locks too many assets and is unable to provide cross-chain transfer services to other users. Summary of the Invention
[0011] In order to solve at least one of the above problems existing in existing cross-chain asset transfer technologies, the present invention provides a cross-chain asset transfer method that is unlinkable and has variable quotas.
[0012] The technical problem to be solved by the present invention is achieved through the following technical solutions:
[0013] A non-linkable and variable-amount cross-chain asset transfer method, including:
[0014] Transfer and pledge phase: The asset sender queries the electronic bulletin board to identify an anonymous set of asset senders with the same asset transfer requirements. They then join the anonymous set by writing an asset transfer message to the electronic bulletin board. The asset transfer message includes the asset transfer amount and the number of payments (m). The asset senders in the anonymous set transfer their assets on the first blockchain to a first shared address with the payment center, and send a commitment and proof of asset transfer from the first blockchain to the payment center for verification of their validity. After verification, the payment center signs the commitment and sends the signature along with the asset address on the first blockchain to the asset sender. The asset sender then obtains a certificate of asset transfer from the payment center and forwards it to the m asset recipients on the second blockchain.
[0015] Transfer registration phase: The asset recipient verifies the received credential. Once the verification is successful, it generates a randomized commitment, a randomized signature, and an extended identification commitment and sends them to the payment center. The payment center verifies the received randomized commitment and randomized signature. Once the verification is successful, it locks its assets on the second blockchain to the second shared address with the asset recipient, records the asset address of the asset recipient on the second blockchain, and signs the received commitment to obtain an extended credential. The asset recipient verifies the extended credential and, once the verification is successful, sends the extended credential to the asset sender.
[0016] Transfer execution phase: The asset sender verifies the received extended credential. Once the verification is passed, the payment center deposits the assets locked in the first shared address into its asset address on the first blockchain.
[0017] Transfer completion stage: The asset recipient deposits the assets locked on the second shared address into its asset address on the second blockchain and informs the payment center of the successful withdrawal. After receiving the withdrawal success message from the asset recipient, the payment center removes the asset recipient's asset address from the record.
[0018] Preferably, the method further comprises:
[0019] System initialization phase: Generate public keys for the asset sender and the payment center, and generate their own private keys for the asset sender and the payment center for use in subsequent phases; the electronic bulletin board declares the message format and query conditions for write operations.
[0020] Preferably, the asset amount of V units on the first blockchain is not less than The amount of assets per unit;
[0021] Where V is the amount of assets locked by the asset sender on the first shared address, w i The amount of assets locked by the payment center at the second shared address to be transferred to the i-th asset recipient.
[0022] Preferably, the message format of the write operation is:
[0023] msg w :=((x V ,x m ),x meta :=(x txid ,x non_txid ));
[0024] Among them, the message content (x V ,x m ) means to divide x m Transfer x V Units of assets, message metadata x meta Plays a verification role, x txid Represents a unique transaction identifier, x non_txid Represents metadata other than the transaction identifier;
[0025] The query conditions are:
[0026] con r :=(x V ,x m ) or conr :=(x l ,"times_des");
[0027] Among them, con r :=(x V ,x m ) means to query all the items that match (x V ,x m ) news, con r :=(x l ,"times_des") means to find all messages with the same message content (x V ,x m ) messages into a set, sort by set size and return the first x l The message content of the largest set, "times_des" indicates descending order.
[0028] Preferably, the pledge transfer stage specifically includes:
[0029] The asset sender queries the electronic bulletin board to identify an anonymous set of asset senders with the same asset transfer requirements, locks their assets on the first blockchain to the first shared address, and joins the anonymous set of asset senders by writing an asset transfer message to the electronic bulletin board;
[0030] The asset sender generates a credential identifier, generates a first commitment for the credential identifier using the commitment algorithm in the randomizable signature technology for randomizable commitments, generates a first proof for the first commitment using the proof algorithm in the non-interactive zero-knowledge proof technology, generates a second commitment for the asset transfer amount using the commitment algorithm in the randomizable signature technology for randomizable commitments, and generates a second proof for the second commitment using the proof algorithm in the non-interactive zero-knowledge proof technology; and sends the first commitment, first proof, second commitment, and second proof to the payment center.
[0031] The payment center uses the verification algorithm in the non-interactive zero-knowledge proof technology to verify the first commitment, the first proof, the second commitment, and the second proof. After the verification is passed, the payment center uses the signature commitment algorithm in the randomizable signature technology of the randomizable commitment to generate a first signature for the first commitment and the second commitment, and sends the asset address and the first signature on the first blockchain to the asset sender;
[0032] The asset sender verifies the first signature using the verification algorithm in the randomizable signature technology of the randomizable commitment. After the verification is passed, the certificate identifier, asset transfer amount, first signature, first commitment and second commitment are sent as the certificate of transferred assets obtained from the payment center to the m asset recipients on the second blockchain.
[0033] Preferably, the method further comprises: starting to time the cross-chain asset transfer time during the system initialization phase;
[0034] The pledge transfer stage also includes:
[0035] When an asset sender in the anonymous set of asset senders transfers assets on the first blockchain to the first shared address, the asset sender sets a first clock cycle and records the current time;
[0036] After the asset sender sends the first commitment, the first proof, the second commitment, and the second proof to the payment center, and before the payment center verifies the first commitment, the first proof, the second commitment, and the second proof using the verification algorithm of the non-interactive zero-knowledge proof technology, the payment center determines whether the first clock cycle set by the asset sender is reasonable based on the recorded time. If it is unreasonable, the cross-chain asset transfer is terminated; if it is reasonable, the verification algorithm of the non-interactive zero-knowledge proof technology is continued to be used to verify the first commitment, the first proof, the second commitment, and the second proof.
[0037] Preferably, the transfer registration stage specifically includes:
[0038] The asset recipient uses the verification algorithm in the Pedersen commitment technology to verify the first commitment and the second commitment, and uses the verification algorithm in the randomizable signature technology of the randomizable commitment to verify the first signature. After verification, the randomized signature algorithm in the randomizable signature technology of the randomizable commitment is used to generate a first randomized commitment, a second randomized commitment, and a first randomized signature for the first and second commitments, and uses the commitment algorithm in the randomizable signature technology of the randomizable commitment to generate a third commitment for the extended credential identifier; a return message is generated based on the first randomized commitment, the second randomized commitment, the third commitment, the first randomized signature, and the asset address of the asset recipient on the second blockchain and sent to the payment center;
[0039] The payment center verifies the content of the returned message using the verification algorithm in the Pedersen commitment technology and the verification algorithm in the randomizable signature technology for randomizable commitments. After verification, the payment center records the asset address of the asset recipient on the second blockchain, locks the asset on the second blockchain to the second shared address, establishes a redemption transaction and redemption parameters for the asset recipient, generates certificate conditions using the commitment algorithm in the redemption technology, and uses the signature commitment algorithm in the randomizable signature technology for randomizable commitments to generate a second signature for the first randomized commitment, the second randomized commitment, and the third commitment, and sends the certificate conditions and the second signature to the asset recipient;
[0040] The asset recipient uses the verification algorithm in the redemption technology to verify the received certificate conditions, and uses the verification algorithm in the randomized signature technology of the randomized commitment to verify the second signature. After the verification is passed, the first randomized commitment, the second randomized commitment, the third commitment, and the second signature are sent to the asset sender as an extended credential; the extended credential also includes an extended credential identifier.
[0041] Preferably, the method further comprises: starting to time the cross-chain asset transfer time during the system initialization phase;
[0042] The transfer registration stage also includes:
[0043] After the payment center locks its assets on the second blockchain to the second shared address, the payment center sets a second clock cycle and records the current timing;
[0044] While the asset recipient uses the verification algorithm in the redemption technology to verify the received certificate conditions, and uses the verification algorithm in the randomized signature technology of the randomized commitment to verify the second signature, the asset recipient determines whether the second clock cycle set by the payment center is reasonable based on the recorded moment, and determines whether the expected assets to be received meet expectations; if it is unreasonable or does not meet expectations, the cross-chain asset transfer is terminated; if it is reasonable and meets expectations, after all relevant verifications are passed, the extended certificate identifier, the first randomized commitment, the second randomized commitment and the third commitment and the second signature are continued to be sent to the asset sender as an extended certificate.
[0045] Preferably, the transfer execution stage specifically includes:
[0046] Create m withdrawal transactions for the payment center;
[0047] The asset sender uses the verification algorithm in the Pedersen commitment technology and the verification algorithm in the randomizable signature technology of the randomizable commitment to verify the received extended credential. After the verification is passed, the asset sender uses the randomized signature algorithm in the randomizable signature technology of the randomizable commitment to make a third randomized commitment for the first randomized commitment, a fourth randomized commitment for the second randomized commitment, a fifth randomized commitment for the third commitment, and a second randomized signature for the second signature. The asset sender also uses the proof algorithm in the non-interactive zero-knowledge proof technology to produce a third proof for the fourth randomized commitment and sends the fourth randomized commitment, the fifth randomized commitment, the third randomized commitment, the second randomized signature, and the third proof to the payment center.
[0048] The payment center verifies the third proof using the verification algorithm in the non-interactive zero-knowledge proof technology, and verifies the fourth randomized commitment, the fifth randomized commitment, the third randomized commitment, and the second randomized signature using the verification algorithm in the randomized signature technology of the randomized commitment; if the verification is successful, the asset sender and the payment center set a public parameter, which contains m information about the credential identifier tid i The first blinded message bsm 1,i The payment center generates the first exchange message xm using the Setup algorithm of the exchange technology according to the public parameters 1,1 Sent to the asset sender; the asset sender according to xm 1,1 Generate the first second exchange message xm using the Buy algorithm of the exchange technology 2,1 Sent to the payment center, the payment center and the asset sender perform m-1 message interconnections;
[0049] Among them, in the i=[2,3,…,m]th message interconnection process, the payment center uses the verification algorithm in the digital signature technology to verify the i-1th second exchange message xm 2,i-1 After verification, the Setup algorithm of the exchange technology is used to generate the first exchange message xm i 1,i , using the signature algorithm in the blind BLS signature technology to perform the bsm in the public parameter 1,i Generate the i-th second blinded message bsm 2,i and bsm in the public parameters 1,i-1 Generate the i-1th second blinded message bsm 2,i-1 , using non-interactive zero-knowledge proof technology to establish the algorithm and prove the algorithm for BSM 2,i and bsm 2,i-1 Generate the i-th composite message And the corresponding proof, xm 1,i 、 The asset sender uses the verification algorithm in the non-interactive zero-knowledge proof technology to verify the composite message and the proof. If the verification is successful, the Buy algorithm of the exchange technology is used to generate the i-th second exchange message xm 2,i Sent to the payment center until the payment center receives the mth second exchange message xm 2,m ;
[0050] The payment center uses the Sell algorithm in the exchange technology to generate xm 2,m The signature of , deposits the assets locked in the first shared address into its asset address on the first blockchain;
[0051] The asset sender obtains the mth second blinded message based on the signature of the payment center on the mth second exchange message using the Get algorithm in the exchange technology. Based on the mth second blinded message, the remaining m-1 second blinded messages are deduced by reversing the group operation. The U2 algorithm in the blind BLS signature technology is used to sign the m second blinded messages respectively to obtain m credential identifiers tid. i The BLS signature will be about the credential identifier tid i The BLS signatures are sent to the corresponding asset recipients to notify the asset recipients of the payment.
[0052] Preferably, the non-linkable and variable-amount cross-chain asset transfer method further includes:
[0053] Transfer timeout phase: The asset sender and the payment center use on-chain time lock technology or verifiable timed discrete logarithm technology to retrieve their assets from the first shared address and the second shared address respectively.
[0054] The non-linkable and variable-amount cross-chain asset transfer method provided by the present invention has the following beneficial effects:
[0055] (1) During the asset transfer process, the present invention sequentially executes the protocols of the transfer pledge, transfer registration and transfer execution stages. When the asset recipient withdraws the assets locked in the second shared address, the payment center must withdraw the assets locked in the first shared address, thereby achieving atomicity.
[0056] (2) In the present invention, each successful 1-m transfer will generate an identical transfer record (V, m), where V is the amount of the asset transferred and m represents the number of payments. Assume that the on-chain observer has obtained the content of k groups of recipients (each group of recipients is to receive currency equivalent to V units of currency in the first blockchain), and these recipients are all different 1-m transfers. For a specific sender, the on-chain observer cannot determine which group of recipients received the currency, but must randomly select one from the k groups. Similarly, for a specific recipient, the on-chain observer can only randomly select one from the k senders to associate. Since the pairing of senders and receivers can only be randomly selected, the probability of a successful match is 1 / k, not 1. This means that the on-chain observer cannot definitely associate a specific sender with a receiver, thus achieving unlinkability.
[0057] (3) In the present invention, the asset sender can actively set the amount and number of transfers, which only requires the V unit currency on the first blockchain B1 to be The currencies on the second blockchain B2 are roughly equivalent, so there is no need to fix these amounts, so the amount variability is met, w iThe amount of assets locked by the payment center at the second shared address to be transferred to the i-th asset recipient, where m is the number of asset recipients.
[0058] (4) In the present invention, to complete 1-m transfers, the asset sender only needs to participate in two transactions, and the receiver only needs to participate in 2m transactions. The total number of transactions required is 2m+2, which is less than the number of transactions required to repeatedly perform 1-1 transfers m times, that is, 4m. Therefore, transaction aggregability is satisfied.
[0059] (5) In the present invention, all currencies on the first blockchain B1 locked by the asset sender are ultimately transferred to the asset receiver at roughly equivalent value. There is no need to lock additional currencies to participate in the cross-chain transfer process, thus satisfying the de-collateralization nature.
[0060] (6) In the present invention, each asset recipient must use the request qualification bound to the asset to make a request to the payment center, thereby ensuring resistance to Griefing attacks.
[0061] The present invention will be further described in detail below with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] Figure 1 This is a schematic diagram of the system architecture based on a non-linkable and variable-amount cross-chain asset transfer method provided by an embodiment of the present invention;
[0063] Figure 2 This is a flow chart of a non-linkable and variable-amount cross-chain asset transfer method provided by an embodiment of the present invention;
[0064] Figure 3 This is a flowchart of another non-linkable and variable-amount cross-chain asset transfer method provided by an embodiment of the present invention;
[0065] Figure 4 The code implementation of the transfer pledge stage in the present invention is shown as an example;
[0066] Figure 5 The code implementation of the transfer registration phase in the present invention is exemplarily shown;
[0067] Figure 6 The code implementation of the transfer execution phase in the present invention is exemplarily shown. DETAILED DESCRIPTION
[0068] The present invention will be further described in detail below with reference to specific examples, but the embodiments of the present invention are not limited thereto.
[0069] To address the technical issues faced by existing cross-chain asset transfer technologies, this invention provides a non-linkable and variable-amount cross-chain asset transfer method, which is applicable to the following scenarios:
[0070] See also Figure 1 , asset sender P on the first blockchain B1 s The recipient (P) wishes to transfer m assets (denoted as A) on the second blockchain B2 r,i ) i∈[m] A certain amount of assets on B2. However, P s There may be insufficient assets or even no asset address on B2. To this end, the present invention introduces two third parties, the payment center P h and electronic bulletin board EBB to assist in the transfer of assets. h There are asset addresses on both B1 and B2, and there are sufficient assets on B2. h You can use a composite address (i.e., a combination of multiple addresses) on B2 to meet the needs of the scenario. Assume P s Want to transfer to P across chains r,i w i Unit B2's assets, in this process, P s First, pay V units of assets to P on B1 h , then P h Will w i Unit assets paid to P r,i EBB provides P s The service of writing and reading transaction-related messages on B1 is to provide electronic bulletin board (EBB) service.
[0071] The present invention has the following premises or assumptions:
[0072] (1) The communication channel is secure and authentic. s and P r,j The communication channels between them are anonymous and cannot be identified by third parties.
[0073] (2) The underlying blockchain system supports deterministic payment transactions.
[0074] (3) The plan is executed in cycles, and the protocols or algorithms in the plan are executed in stages. The duration of each stage depends on factors such as transaction confirmation time and computing node performance. All participants can determine the cycle and stage they are in.
[0075] (4)P h Services are not disrupted by centralization risks, such as single points of failure.
[0076] (5) To motivate P h Provide services, the monetary value of V unit B1 is not less than The currency value on unit B2, that is, the asset amount of V units on the first blockchain is not less than the asset amount on the second blockchain. The asset amount in units, V is the asset amount of the sender locked in the payment center on the first shared address, w i The amount of assets locked by the payment center at the second shared address to be transferred to the i-th asset recipient.
[0077] (6) For convenience, the asset address on the blockchain is referred to by the corresponding signature public key.
[0078] In order to better understand the solution of the present invention, the definitions of symbols / formulas are shown in Table 1:
[0079] Table 1
[0080]
[0081]
[0082] The method of the present invention uses algorithms from eight technical aspects: digital signatures, Pedersen commitments, blind BLS signatures, randomizable signatures with randomizable commitments, non-interactive zero-knowledge proofs, Shamir key sharing, exchange protocols, redemption protocols, and electronic bulletin boards. The following describes each of them one by one:
[0083] 1. Digital Signature Technology S :
[0084] Π S :=(KeyGen,Sign,Verify), including the following three algorithms:
[0085] ①Key generation algorithm KeyGen, generates a public-private key pair, i.e. (pk, sk)←KeyGen(1 n ), is a security parameter, pk here represents the public key, and sk represents the private key.
[0086] ②Signature algorithm Sign, using the signer's signature private key sk for any message Generate signature σ, that is, σ←Sign(sk,m * ), Represents a message collection.
[0087] ③ Verify algorithm, verify signature σ, if b = 1, then the verification is successful, that is, b: = Verify(pk,m * ,σ).
[0088] In order to be secure against strong existential forgery (sEUF-CMA) under chosen message attack, the present invention requires that the public key entropy of the digital signature scheme is w(log(n)), where w is the original public key entropy.
[0089] 2. Pedersen Commitment Technique Π C
[0090] Π C :=(Commit,Verify), including the following two algorithms:
[0091] ① Commit algorithm Commit, generate a message m * Commitment cm, that is, (cm, decom) ← Commit (m * ), decom is the verification information.
[0092] ②Verify algorithm, verify the message m * Commitment cm, if b=1 verification is passed, that is, b:=
[0093] Verify(cm,decom,m * ).
[0094] The Pedersen commitment technology used in the present invention can satisfy the hiding and binding properties.
[0095] 3. Randomizable Signatures on Randomizable Commitments (RR) Technology RR :
[0096] Π RR It consists of 7 algorithms, 3 of which constitute a digital signature scheme π S , the other four algorithms are:
[0097] ① Commit algorithm Commit, generate a message m * Commitment cm, that is, (cm, decom) ← Commit (m * ).
[0098] ② Randomize the commitment algorithm RandCom and obtain the random commitment cm′ of the commitment cm, that is:
[0099] cm′←RandCom(cm,r);
[0100] in, is the set {0,1,2,…,p-1}, for The set of integers that are relatively prime to p, Represents a collection We uniformly sample x in Represents a collection A sample r is uniformly sampled from , and subsequent similar operations are not repeated here.
[0101] ③Signature commitment algorithm SignCom, using the signer's private key sk, we can get the commitment cm1,cm2,…,cm k The signature σ is:
[0102] σ←SignCom(cm1,cm2,…,cm k ,sk).
[0103] ④ Randomized signature algorithm RandSign, get the commitment cm1,cm2,…,cm k Randomized commitment cm′1,cm′2,…,cm′ k , and signature σ′, namely:
[0104] (σ′,cm′1,cm′2,…,cm′ k )←RandSign(cm1,cm2,…,cm k ,σ,pk,r).
[0105] The randomizable signature technology with random commitment used in the present invention can refer to the requirements of correctness, quasi-hiding, signature randomization and unforgeability. For the specific algorithm implementation, please refer to X. Qin, S. Pan, A. Mirzaei, Z. Sui, O. Ersoy, A. Sakzad, M. F. E. Esgin, J. K. Liu, J. Yu, and T. H. Yuen, “Blindhub: Bitcoin-compatible privacy-preserving payment channel hubs supporting variable amounts,” in 2023 IEEE Symposium on Security and Privacy (SP), IEEE. San Francisco, CA, USA: IEEE, 2023, pp. 2462-2480.
[0106] 4. Blind BLS Signatures Technology BBS :
[0107] Π BBs :=(KeyGen,U1,S,U2,Verify), including the following five algorithms:
[0108] ①The signer runs the key generation algorithm KeyGen to generate a public-private key pair, i.e. (pk, sk)←KeyGen(1 n ),in
[0109] ② User runs U1 to generate the blinded message bsm1 and private information α, that is, (bsm1,α)←U1(pk,m * ).
[0110] ③The signer runs the signature algorithm S to generate the transformable message bsm2, that is, bsm2←S(sk,bsm1).
[0111] ④The user runs U2 to obtain the signature σ, that is, σ←U2(α,bsm2).
[0112] ⑤ Verify algorithm, verify signature σ, if b = 1, verification is successful, that is, b: = Verify(pk,m * ,σ).
[0113] The blind BLS signature used in this work satisfies uniqueness, weak blinding, and many-to-one unforgeability. For the specific algorithm implementation, please refer to L. Hanzlik, JLSri, A. Thyagarajan, and B. Wagner, "Sweep-uc: Swapping coins privately," in 2024 IEEE Symposium on Security and Privacy (SP), IEEE. San Francisco, CA, USA: IEEE, 2024, pp. 3822-3839.
[0114] 5. Non-Interactive Zero-Knowledge Proof Technology NIZK :
[0115] Π NIZK :=(Setup, Prove, Verify), which consists of three algorithms:
[0116] ① Establish the algorithm Setup to generate a common reference string crs and a trapdoor td from the given relation R, that is, (crs, td)←Setup(R).
[0117] ② Prove algorithm generates a proof π for the statement x, where (x,w i )∈R, proving that π can be verified, that is, π←Prove(crs,x,w i ).
[0118] ③Verify algorithm, verify the proof π, if b = 1, the verification is successful, that is, b: = Verify(crs,π,x).
[0119] The non-interactive zero-knowledge proof scheme used in the present invention satisfies both reliability and zero-knowledge properties. For specific algorithm implementation, reference may be made to J. Groth, “On the size of pairing-based non-interactive arguments,” in Annual international conference on the theory and applications of cryptographic techniques, Springer. Cham: Springer International Publishing, 2016, pp. 305-326 and A.D. Santis, S. Micali, and G. Persiano, “Non-interactive zero knowledge proof systems,” in Conference on the Theory and Application of Cryptographic Techniques, Springer. Berlin, Heidelberg: Springer Berlin Heidelberg, 1987, pp. 52-72.
[0120] 6. Shamir Secret Sharing Technology
[0121] The Shamir key sharing technique can be used to divide a secret in an integer set or a cyclic group into multiple parts and recover the secret through a limited number of parts. and The secret in is divided into 2N parts, and N+1 parts are needed to recover the secret. When N+1 different points are provided or When , the Lagrange interpolation method is used to recover the secret, is the elliptic curve group of order p, and its generator is g1.
[0122] ①These points are The coordinates in (x i ,y i ) i∈[N+1] , then the recovered secret is:
[0123]
[0124] ②These points are The coordinates in (x i ,h i ) i∈[N+1], then the recovered secret is:
[0125]
[0126] Among them, l i (x) is calculated by the following formula:
[0127] l i (x):=∏ j∈[N+1],j≠i (xx j ) / (x i -x j ).
[0128] To simplify the representation, we use Reconst to represent the algorithm for recovering the secret by Lagrange interpolation from or Reconstruct a polynomial from N+1 points. This means that the reconstructed polynomial is evaluated at x0 to obtain the secret.
[0129] VII. Exchange Agreement and Redemption Agreement
[0130] i. About Π s and Π BBS The exchange protocol EXC: = (Setup, Buy, Sell, Get), two participants P s and P h This protocol is completed interactively and consists of 4 algorithms:
[0131] ①P h Execute the Setup algorithm to obtain the message xm1 and state st h , this state is used to indicate P h At what stage, sk BS and sk h1 Produced in Π S and Π BBS The key generation algorithm is xpar, which is a public parameter:
[0132] (xm1,st h )←Setup(xpar,sk BS ,sk h1 ).
[0133] ②P s Execute the Buy algorithm and obtain the message xm2, where sk s Is by Π S P generated by the key generation algorithm s Signature key, i.e. xm2←Buy(xpar,xm1,sk s ).
[0134] ③P h Execute the Sell algorithm to create a signature σ s , that is, σ s ←Sell(xm2,st h )
[0135] ④P s Execute the Get algorithm to obtain the message bsm2, that is, bsm2←Get(xpar,xm1,xm2,σ s ,σ h1 )
[0136] ii. About Π S and Π BBS The redemption protocol RP: = (Promise, VerPromise, Redeem), two participants P r,i and P h This protocol is completed non-interactively and consists of three algorithms:
[0137] ①P h Execute the Promise algorithm to generate a prom, where sk BS and sk h2 Produced in Π S and Π BBS The key generation algorithm, rpar is a public parameter, that is, promise←Promise(rpar,sk BS ,sk h2 ).
[0138] ②P r,i Execute the VerPromise algorithm to check prom. If b=1, the verification passes, that is:
[0139] b:=VerPromise(rpar,prom).
[0140] ③After verification, P r,i Execute the Redeem algorithm to obtain P h The signature σ h2 ,Right now:
[0141] σ h2 ←Redeem(rpar,prom,σ BS ).
[0142] The present invention utilizes the Shamir Secret Sharing technology mentioned above mainly in the Redeem algorithm.
[0143] The combination of the exchange protocol and the redemption protocol used in the present invention realizes cross-chain transfer, and regarding Pi S and ΠBBS All are safe. For specific algorithm implementation, please refer to the literature L.Hanzlik, JLSri, A.Thyagarajan, and B.Wagner,
[0144] "Sweep-uc: Swapping coins privately," in 2024 IEEE Symposium on Security and Privacy (SP), IEEE. San Francisco, CA, USA: IEEE, 2024, pp. 3822-3839.
[0145] 8. Electronic Bulletin Board Technology
[0146] An EBB involves three types of participants: a bulletin board (BB), readers, and writers. Messages written by writers are stored on the EBB and accessible to readers. The core security requirement is "immutable history," meaning that stored messages cannot be modified or deleted, regardless of collusion between the BB and writers. The EBB in this invention satisfies the following properties:
[0147] Liveness: Messages written by honest writers will eventually appear on the bulletin board. This means that all messages that meet the requirements will be published on the bulletin board in a timely manner, without missing any valid information.
[0148] Authorized Access: Only authorized writers can submit valid messages. This ensures the legitimacy of the message source and prevents unauthorized users from tampering with the content on the bulletin board.
[0149] Receipt Consistency: If a message is received from a bulletin board, it will eventually appear on the bulletin board. This feature ensures that messages submitted by writers are reliably recorded, preventing inconsistencies between receipts and messages.
[0150] The following is a detailed description of the process of the non-linkable and variable-amount cross-chain asset transfer method of the present invention.
[0151] The first is the system initialization phase, in which public keys need to be generated for the asset sender and the payment center, and private keys need to be generated for the asset sender and the payment center for use in subsequent phases. The public and private key pairs are connected through Π BBS and Π RRIn addition, the electronic bulletin board must also declare the message format and query conditions for write operations to ensure that it meets the above-mentioned liveness, authorized access, and receipt consistency.
[0152] For example, the message format of a write operation declared by an electronic bulletin board may be:
[0153] msg w :=((x V ,x m ),x meta :=(x txid ,x non_txid ));
[0154] Among them, the message content (x V ,x m ) means to divide x m Transfer x V Units of assets, message metadata x meta Plays a verification role, x txid Represents a unique transaction identifier, x non_txid Represents metadata other than the transaction identifier;
[0155] For example, the query conditions declared on the electronic bulletin board may be:
[0156] con r :=(x V ,x m ) or con r :=(x1,"times_des");
[0157] Among them, con r :=(x V ,x m ) means to query all the items that match (x V ,x m ) news, con r :=(x l "times_des") means to find all messages, sort them by message set size and return the first x l Details of the largest message collection.
[0158] See also Figure 2 As shown, after the system initialization stage, the non-linkable and variable-amount cross-chain asset transfer method provided by the present invention includes four stages: transfer pledge, transfer registration, transfer execution and transfer completion.
[0159] In the pledge transfer phase, four types of participants are involved: asset sender Ps , Payment Center P h 、Asset Receiver (P r,i ) i∈[m] and an electronic bulletin board. The asset sender queries the electronic bulletin board to identify an anonymous set of asset senders with the same asset transfer requirements. The asset sender then joins the anonymous set of asset senders by writing an asset transfer message to the electronic bulletin board; this asset transfer message includes the asset transfer amount V and the number of payments m. Each asset sender in the anonymous set transfers their assets on the first blockchain to a first shared address with the payment center, and sends the payment center a commitment and proof of asset transfer from the first blockchain for the payment center to verify its validity. After verification, the payment center signs the commitment and sends the signature, along with its asset address on the first blockchain, to the asset sender. The asset sender then obtains a certificate of asset transfer from the payment center and forwards it to the m asset recipients on the second blockchain.
[0160] Among them, the present invention helps senders to actively build an anonymous set, that is, a set of senders with the same transfer demand, by introducing an electronic bulletin board (EBB) service. The larger the set, the smaller the probability that any sender is associated with the corresponding receivers (the probability is the inverse of the number of elements in the set). The sender publishes their asset transfer demand to the EBB through a write operation, including the transfer currency amount V. When the sender reads the message, the EBB will summarize all the stored messages with the same transfer demand and sort them according to the demand. The sender can understand the needs of other senders based on these sorted messages, especially which ones have the largest number of demands, and then classify themselves into the set with the same demand by locking the assets, so EBB directly affects the unlinkability and directly realizes the variability of the amount.
[0161] See also Figure 4 , the pledge transfer stage, specifically including:
[0162] (1) The asset sender determines the anonymous set of asset senders with the same asset transfer requirements by querying (Reading) the electronic bulletin board, and locks its assets on the first blockchain to the first shared address, i.e. By writing asset transfer message msg to the electronic bulletin board w Join the anonymous set of asset senders. The algorithm implementation of this part of the operation can be found in Figure 4 The third line of code in .
[0163] In the algorithm implementation of this step, It is the base point. In turn, it represents the elliptic curve group of order p, and the generators are g1, g2, g t , pk RRπ RR The public key in sk RR π RR The private key in TPledge represents the transfer pledge protocol in this invention. s P s The public key (also known as the asset address), sk s P s The private key of the asset sender, T1 sets the first clock cycle, v i P s To be transferred to P r,i The amount of assets. s By calling the function Receiving parameters pk h Indicates the public key (asset address) of the payment center, sk h Indicates the private key of the payment center.
[0164] In the specification of the present invention, the numbers 1 and 2 in the superscripts / subscripts of the public and private key symbols correspond to the first blockchain B1 and the second blockchain B2, respectively. Indicates the shared address and on-chain time lock function. The "in" in the superscript / subscript of the public and private key symbols indicates that the address it identifies is the source address of the asset, and the "out" indicates that the address it identifies is the destination address of the asset.
[0165] (2) The asset sender generates a credential identifier (tid) i , using the commitment algorithm ∏ in the randomized signature technology of randomized commitment RR .Commit is the credential identifier tid i Generate first commitment ( To verify the information), we use the proof algorithm ∏ in the non-interactive zero-knowledge proof technology NIZK .Prove is the first commitment Generate the first proof Commitment algorithm π in randomizable signature technology using randomizable commitment RR .Commit is the asset transfer amount v i Generate second commitment ( To verify the information), we use the proof algorithm Π in the non-interactive zero-knowledge proof technology NIZK .Prove is the second commitment Generate the second proof π v ; Make the first commitment First proof Second Commitment and the second proof of π v Send to the payment center; the algorithm implementation of this part of the operation can be found in Figure 4 Lines 5-10 of the code.
[0166] (3) The payment center uses the verification algorithm Π in the non-interactive zero-knowledge proof technology NIZK .Verify the first commitment First proof Second Commitment and the second proof of π v Verify and use the signature commitment algorithm π in the randomized signature technology of randomized commitment after verification RR .SignCom's Commitment to First and the second commitment Make the first signature The asset address on the first blockchain and the first signature Sent to the asset sender; the algorithm implementation of this part of the operation can be found in Figure 4 Lines 12-17 of the code.
[0167] (4) The asset sender uses the verification algorithm Π in the randomizable signature technology of the randomizable commitment RR .Verify the first signature Verify and after verification, the credential identification tid i , asset transfer amount v i , first signature First Commitment and the second commitment As the certificate of transferred assets obtained from the payment center, it is sent to the m asset recipients on the second blockchain; the algorithm implementation of this part of the operation can be found in Figure 4 Lines 18-21 of the code.
[0168] Optionally, in one implementation, the method of the present invention may further include: starting to time the cross-chain asset transfer time during the system initialization phase. Accordingly, the transfer pledge phase also includes:
[0169] The asset sender in the asset sender anonymity set transfers the asset on the first blockchain to the first shared address When , the asset sender sets the first clock cycle T1 and records the current timing time t0;
[0170] The sender of the asset will first commit First proof Second Commitment and the second proof of π v After being sent to the payment center, the verification algorithm π in the payment center is used NIZK.Verify the first commitment First proof Second Commitment and the second proof of π v Before verification, the payment center determines whether T1 set by the asset sender is reasonable based on the recorded t0 ( Figure 4 If it is unreasonable, the cross-chain asset transfer is terminated; if it is reasonable, the verification algorithm of the non-interactive zero-knowledge proof technology is continued to verify the first commitment. First proof Second Commitment and the second proof of π v to verify.
[0171] Among them, the payment center determines whether T1 set by the asset sender is reasonable. Specifically, the payment center adds t0 to the clock cycle T1 set by the asset sender, and determines whether the obtained time point t1=t0+T1 satisfies t0+T1>Ta and t0+T1<Ta+△; where Ta is the starting time of the cross-chain asset transfer timeout phase, and △ is the duration of the cross-chain asset transfer timeout phase. The role of the cross-chain asset transfer timeout phase will be explained later. If it is not satisfied, it means that the asset sender may withdraw its assets before completing the normal cross-chain asset transfer cycle (system initialization phase + transfer pledge phase + transfer registration phase + transfer execution phase + transfer completion phase), which is not allowed, so T1 is judged to be unreasonable. Otherwise, T1 is judged to be reasonable.
[0172] During the transfer registration phase, the asset recipient verifies the received certificate. Once the verification is passed, a randomized commitment, a randomized signature, and an extended identification commitment are generated and sent to the payment center. The payment center verifies the received randomized commitment and randomized signature. Once the verification is passed, the payment center locks its assets on the second blockchain to the second shared address with the asset recipient, records the asset address of the asset recipient on the second blockchain, and signs the received commitment to obtain an extended certificate. The asset recipient verifies the extended certificate and sends it to the asset sender after the verification is passed.
[0173] Specifically, the transfer registration phase involves three types of participants: the payment center P h 、Asset Receiver (P r,i ) i∈[m] and asset sender P s The transfer registration phase specifically includes:
[0174] (a) The asset recipient uses the verification algorithm Π in the Pedersen commitment technique C .Verify the first commitment and the second commitment Verify using the verification algorithm π in the randomizable signature technology of randomizable commitment RR .Verify the first signature Verify, and after verification, use the randomized signature algorithm π in the randomized signature technology of randomized commitment RR .RandSign's First Commitment and the second commitment Generate the first randomized commitment Second randomization commitment and the first randomized signature Commitment algorithm π in randomizable signature technology using randomizable commitment RR .Commit is the extended credential identifier α i ·H p (tid i ) Generate the third commitment ( Verify the information for it); according to the first randomization commitment Second randomization commitment Third Commitment First randomized signature and the asset recipient's asset address on the second blockchain Generate a return message and send it to the payment center; the algorithm implementation of this part of the operation can be found in Figure 5 Lines 1-8 of the code, where H p It is a hash algorithm.
[0175] Figure 5 In the transfer registration phase, the protocol content is encapsulated as the TRegistratio protocol, and the public parameters involved include o r ,pk BS ,pk RR , where o r Indicates the exchange rate, pk BS and sk BS Represents a blind BLS signature public-private key pair.
[0176] (b) The payment center uses the verification algorithm Π in the Pedersen commitment technology C Verify and randomizable commitment verification algorithm π in randomizable signature technology RR .Verify verifies the content of the returned message. Once verified, it records the asset address of the asset recipient on the second blockchain. The payment center locks its sufficient assets on the second blockchain to the second shared address, i.e. Establishing a redemption transaction for the asset recipient and redemption parameter rpari , using the commitment algorithm RP.Promise in the redemption technology to generate the certificate condition prom i , and use the signature commitment algorithm Π in the randomized signature technology of randomized commitment RR .SignCom makes a second signature on the first randomized commitment, the second randomized commitment, and the third commitment Will the certificate condition prom i and the second signature Sent to the asset recipient; the algorithm implementation of this part of the operation can be found in Figure 5 In the 9th to 21st lines of code. In addition, the 10th line of code is used by the payment center to determine the voucher identifier tid i Whether it already exists in the list of credentials it maintains and determine the asset address of the asset recipient on the second blockchain Whether it already exists in the asset address list of the asset recipient it maintains If the answer is yes, it means the transaction already exists and the cross-chain asset transfer is aborted.
[0177] (c) The asset recipient verifies the received certificate conditions using the verification algorithm RP.VerPromise in the redemption technology and uses the verification algorithm π in the randomizable signature technology of the randomizable commitment. RR .Verify the second signature Verify and after verification, the credential identifier α will be extended i ·H p (tid i ), first randomization commitment Second randomization commitment Third Commitment Second signature Issued to the asset sender as an extended certificate. The algorithm implementation of this part of the operation can be found in Figure 5 Lines 24-26 of the code.
[0178] Optionally, in one implementation, the method of the present invention may further include: starting to time the cross-chain asset transfer time during the system initialization phase. Accordingly, the transfer registration phase may further include:
[0179] After the payment center locks its assets on the second blockchain to the second shared address, the payment center sets a second clock cycle T2 and records the current time t2;
[0180] The asset recipient uses the verification algorithm in the redemption technology to verify the received certificate condition prom iVerify and use the verification algorithm in the randomized signature technology of the randomized commitment to verify the second signature While verifying, the asset recipient determines whether the second clock cycle T2 set by the payment center is reasonable based on the recorded t2, and determines whether the assets expected to be received meet expectations (w i <v i / o r ), the algorithm implementation of this part of the operation can be found in Figure 5 Line 23 of the code; If T2 is unreasonable or the expected received assets do not meet expectations, the cross-chain asset transfer is terminated; If T2 is reasonable and meets expectations, after all relevant verifications ( Figure 5 After the 23rd-25th lines in the code are passed, continue to set the extended credential identifier α i ·H p (tid i ), the first randomized commitment, the second randomized commitment, the third commitment and the second signature are sent to the asset sender as an extended credential.
[0181] Among them, the asset recipient determines whether the second clock cycle T2 set by the payment center is reasonable based on t2. Specifically, after adding t2 to T2 set by the payment center, the asset recipient determines whether the obtained time point t3=t2+T2 satisfies t2+T2>Ta and t2+T2<Ta+△; if not, T2 is determined to be unreasonable, otherwise T2 is determined to be reasonable.
[0182] During the transfer execution phase, the asset sender verifies the received extended credential. Once the verification is passed, the payment center deposits the assets locked on the first shared address into its asset address on the first blockchain.
[0183] Specifically, the transfer execution phase includes:
[0184] (i) Create m withdrawal transactions for the payment center The withdrawal transaction is defined as:
[0185] Where V i :=i·V / m;
[0186] (ii) The asset sender uses the verification algorithm ∏ in the Pedersen commitment technique C Verify and randomizable commitment verification algorithm ∏ in randomizable signature technology RR .Verify verifies the received extended credentials, see Figure 6 Lines 1-6 in which H p is a hash algorithm. After verification, see Figure 6Line 8 of the randomized signature algorithm π is used to implement the randomized signature technology based on randomized commitment. RR .RandSign makes a third randomization commitment to the first randomization commitment Make a fourth randomization commitment to the second randomization commitment Make a fifth randomized commitment to the third commitment And the second signature Make a second randomized signature And use the proof algorithm in non-interactive zero-knowledge proof technology to make the fourth randomized commitment (commitment related to amount) gives third proof π ve (See Figure 6 Lines 9-10 in the , the fourth randomized commitment Fifth Randomization Commitment Third Randomization Commitment Second randomized signature And the third proof π ve Sent to the payment center (see Figure 6 11 in the ).
[0187] (iii) The payment center uses the verification algorithm Π in the non-interactive zero-knowledge proof technology NIZK .Verify the third proof π ve Verify ( Figure 6 Line 12), and use the verification algorithm Π in the randomizable signature technology of randomizable commitment RR .Verify the fourth randomized commitment Fifth Randomization Commitment Third Randomization Commitment and the second randomized signature Verify ( Figure 6 Lines 13-14), if the verification is successful, the asset sender and the payment center set the public parameter xpar i ( Figure 6 Line 15); The public parameter contains m credential identifiers tid i The first blinded message bsm a,i ; Payment center based on public parameter xpar i , using the setup algorithm EXC.Setup of the exchange technology to generate the first exchange message xm 1,1 Sent to asset sender ( Figure 6 Lines 16-17); the asset sender uses xm 1,1 Use the Buy algorithm EXC.Buy of the exchange technology to generate the first second exchange message xm 2,1 Sent to the payment center ( Figure 6Lines 18-19); the payment center and the asset sender perform m-1 message interconnections.
[0188] Among them, in the i=[2,3,…,m]th message interconnection process, the payment center uses the verification algorithm Π in the digital signature technology S .Verify the i-1th second exchange message xm 2,i-1 Verify ( Figure 6 Line 20.1), after verification, the setup algorithm EXC.Setup of the exchange technology is used to generate the i-th first exchange message xm 1,i ( Figure 6 Line 20.2) uses the signature algorithm in the blind BLS signature technology to sign the bsm in the public parameter 1,i Generate the i-th second blinded message bsm 2,i and bsm in the public parameters 1,i-1 Generate the i-1th second blinded message bsm 2,i-1 ( Figure 6 Line 20.3), using the non-interactive zero-knowledge proof technology to establish the algorithm and prove the algorithm for bsm 2,i and bsm 2,i-1 Generate the i-th composite message and corresponding proof ( Figure 6 Lines 20.4-20.7), change xm 1,i 、 and its proof Sent to asset sender ( Figure 6 Line 20.8); The asset sender verifies the composite message and proof using the verification algorithm in the non-interactive zero-knowledge proof technology ( Figure 6 Lines 20.9-20.11), if the verification is successful, the Buy algorithm EXC.Buy of the exchange technology is used to generate the i-th second exchange message xm 2,i Sent to the payment center ( Figure 6 Lines 20.12-20.13) until the payment center receives the mth second exchange message xm 2,m .
[0189] (iv) The payment center uses the Sell algorithm in the exchange technology to generate xm 2,m The signature σ s,m ( Figure 6 Line 22), by calling the function Deposit the assets locked on the first shared address into its asset address on the first blockchain, namely:
[0190]
[0191] (V) The asset sender’s signature σ on the mth second exchange message based on the payment center s,m , use the Get algorithm EXC.Get in the exchange technology to obtain the mth second blinded message bsm 2,m ( Figure 6 Lines 23-25); According to the mth second blinded message bsm 2,m , derive the remaining m-1 second blinded messages bsm by reversing the group operation 2,i , and uses the U2 algorithm π in the blind BLS signature technology BBS .U2 are m second blinded messages bsm 2,i sign( Figure 6 Lines 26-27) Get m credential identifiers tid i The BLS signature σ BS,i ; Set m credential identifiers tid i The BLS signature σ BS,i Sent to the corresponding asset recipients respectively Figure 6 Lines 28-29) to notify the recipient of the asset to receive payment.
[0192] Table 2 also lists Figure 6 Definitions of some unmentioned parameters:
[0193] Table 2
[0194]
[0195]
[0196] During the transfer completion phase, the asset recipient deposits the assets locked on the second shared address into its asset address on the second blockchain and informs the payment center of the successful withdrawal. After receiving the message of successful withdrawal from the asset recipient, the payment center removes the asset recipient's asset address from the record.
[0197] Specifically, the transfer completion stage includes:
[0198] The asset recipient obtains the payment center’s redemption transaction through the redemption algorithm Redeem of the redemption technology. The signature σ on h2,i , through the signature algorithm Π of digital signature technology S .Sign for redemption transactions To sign: Through two signatures, the asset recipient extracts the assets locked on the second shared address to its asset address on the second blockchain, namely P r,i Successfully received locked in (pk h2,i ,pk r,i ) in iUnit assets. Then, the asset recipient sends these two signatures to the payment center. After receiving them, the payment center removes the asset recipient’s asset address on the second blockchain. The asset transfer is complete.
[0199] In addition, the unlinkable and variable-amount cross-chain asset transfer method provided by the present invention may also include a transfer timeout phase.
[0200] Specifically, the transfer timeout phase involves two parties: the asset sender P s and payment center P h During the transfer timeout phase, the asset sender and the payment center use on-chain time lock technology or verifiable timed discrete logarithm technology to retrieve their assets from the first shared address and the second shared address respectively.
[0201] In the present invention, the system initialization, transfer pledge phase, transfer registration phase, transfer execution phase and transfer completion phase all have corresponding fixed periods. Assuming that their total period is recorded as T, starting from the system initialization phase, if the asset transfer is not completed after T, it can enter the transfer timeout phase, such as Figure 3 As shown in the figure, it can be understood that since the cross-chain asset transfer time is counted during the system initialization phase, the starting time Ta of the cross-chain asset transfer timeout phase is numerically equal to the total period T.
[0202] The following is an analysis of the threats faced by the present invention and the corresponding coping strategies of the present invention:
[0203] ①P h Is rational and curious, will try to steal P s Transfer of assets but not to P r,i Transfer assets and try to obtain P s and P r,i The relationship generated by cross-chain transactions.
[0204] To address this situation, the present invention ensures the atomicity of asset transfer during the transfer timeout phase and ensures unlinkability by adopting EBB (Electronic Bulletin Board) technology, reconstruction exchange technology, and redemption technology.
[0205] During the transfer pledge phase, the asset sender needs to lock its assets on the first blockchain to the first shared address with the payment center to obtain a certificate from the payment center. During the transfer registration phase, the payment center needs to lock its assets on the second blockchain to the second shared address with the asset recipient, and establish a redemption transaction. The asset recipient obtains an extended certificate from the payment center. During the transfer execution phase, the payment center generates m withdrawal information through exchange technology, performs group operations on the messages to create a composite message, and provides zero-knowledge proof to hide the composite message. Once the payment center deposits the assets locked in the first shared address into its asset address on the first blockchain, the sender can obtain the mth second blinded information and deduce the remaining m-1 second blinded information by reversing the group operation. During the transfer completion phase, the asset recipient obtains the payment center's response to the redemption transaction through redemption technology. The signature σ h2,i , obtain its signature σ for the redemption transaction through digital signature technology r,i , successfully depositing the assets locked in the second shared address into its asset address on the second blockchain. The withdrawal transaction corresponding to the mth transfer information must transfer all assets from the shared address to Ph to ensure fairness.
[0206] Electronic Bulletin Board (EBB) technology achieves the unlinkability of asset transfer by promoting the sender to actively build an anonymous set. Specifically, the sender publishes their asset transfer requirements on the electronic bulletin board. The message format is (x V ,x m ), where x V represents the total amount of money transferred, and x m Indicates how many transfers the transaction will be divided into. In this way, the set of sender-receiver pairs forms an anonymity set.
[0207] In this invention, senders publish their requests to an electronic bulletin board (EBB) via a write operation. The request includes the amount of assets to be transferred (V) and the number of transfers (m). Senders can then read other request messages on the EBB to learn about other senders' requests and sort them by quantity. Through this mechanism, senders can proactively choose to group their transferred assets into sets with similar transfer requirements. A key benefit of this is that the association between senders and receivers is reduced. The larger the set, the stronger the privacy between senders and receivers, because the larger the anonymous set, the lower the probability that any single sender and receiver can be associated.
[0208] In the transfer pledge phase, the sender transfers assets v in m times i Bind to its credential identity. This binding can be randomized, and a randomized signature is used on the randomized commitment to ensure unlinkability.
[0209] ②P r,i Will try to P h Launch a Griefing attack, that is, first initiate a lock transaction request, so that P h Lock assets but do not cooperate with P h The subsequent operation causes P h Unable to provide normal services to other users.
[0210] In view of this situation, the present invention, during the transfer registration phase: each recipient must use the certificate bound to the asset to register with P h Send a request. If the receiver launches a Griefing attack, it means that the corresponding sender must lock at least P h Locking assets of equal value, the sender's interest damaged is not less than the P damaged h Therefore, the recipient has no incentive to launch the attack.
[0211] ③P s and P r,i Will collude and try to steal P h Transferred assets.
[0212] In view of this situation, during the transfer execution phase, the present invention allows the asset sender to provide an extended certificate bound to the corresponding asset receiver, P h The extended credential is verified before continuing the cooperation. In addition, the combination of exchange technology and redemption technology ensures atomicity, avoiding the asset recipient from h Withdraw assets but P h Unable to withdraw assets from the sender.
[0213] The following compares the cross-chain asset transfer method of the present invention with some existing cross-chain asset transfer schemes, focusing on the atomicity, unlinkability, quota variability, transaction aggregability, decollateralization, and Griefing attack resistance of the schemes.
[0214] 1. Atomicity: Under normal circumstances, the sender relinquishes ownership of an asset on one blockchain, while the corresponding receiver obtains ownership of a roughly equivalent asset on another blockchain. If a problem occurs on one of the chains, the asset ownership of both parties remains unchanged.
[0215] 2. Unlinkability: The payment relationship between the sender and the receiver is kept secret from others.
[0216] 3. Amount variability: supports transfer of variable amounts.
[0217] 4. Transaction aggregability: Ensure that when executing 1~m (m≥2) transfers, the number of transactions required is less than m times the number of 1~1 transfers.
[0218] 5. Uncollateralized: No need for senders to lock up additional assets.
[0219] 6. Griefing attack resistance: Only recipients who meet the request qualifications can enable third parties to lock assets.
[0220] The comparison results are shown in Table 3, which proves the effectiveness of the present invention.
[0221] Table 3
[0222]
[0223] In Table 3, required transactions refer to the number of on-chain transactions required to complete 1 to m transfers. Existing cross-chain asset transfer schemes are cited from the following literature:
[0224] [4]H.Tian, K.Xue,
[0225] [6] A. Back, M. Corallo, L. Dashjr, M. Friedenbach, G. Maxwell, A. Miller, A. Poelstra, J. Timon, and P. Wuille, "Enabling'blockchain innovations with peggedsidechains," URL: http: / / www.opensciencereview.
[0226] com / papers / 123 / enablingblockchain-innovationswith-pegged-sidechains,vol.72,pp.201-224,2014.
[0227] [7]A.Kiayias and D.Zindros, "Proof-of-work sidechains," in FinancialCryptography and Data Security:FC 2019International Workshops,VOTING andWTSC,St.Kitts,St.Kitts and Nevis,February 18-22,2019,Revised Selected Papers23,Springer.Cham:Springer International Publishing,2020,pp.21-34.
[0228] [8] P. Gazi, A. Kiayias, and D. Zindros, “Proof-of-stake sidechains,” inˇ2019 IEEE Symposium on Security and Privacy (SP), IEEE. San Francisco, CA, USA: IEEE, 2019, pp. 139-156.
[0229] [9]T. Machinery, 2022, pp. 3003-3017.
[0230]
[10] Zhu Gengliang. Cross-chain asset transfer method, device, computer equipment and storage medium [P]. Guangdong Province: CN118921377A, 2024.11.08.
[0231]
[11] A.Zamyatin,D.Harz,J.Lind,P.Panayiotou,A.Gervais,andW.Knottenbelt,“Xclaim:Trustless,interoperable,cryptocurrencybacked assets,”in2019IEEE Symposium on Security and Privacy(SP),IEEE.San Francisco,CA,USA:IEEE,2019,pp.193-210。
[0232]
[12] Z.Yin,B.Zhang,J.Xu,K.Lu,and K.Ren,“Bool network:An open,distributed,secure cross-chain notary platform,”IEEE Transactions onInformation Forensics and Security,vol.17,pp.3465-3478,2022。
[0233]
[13] Chainlink,“Chainlink ccip,”2023.[Online].Available:https:
[0234] / / docs.chain.link / ccip
[0235]
[14] E.Tairi,P.Moreno-Sanchez,and M.Maffei,“A2l:Anonymous atomic locksfor scalability in payment channel hubs,”in 2021IEEE Symposium on Securityand Privacy(SP),IEEE.San Francisco,CA,USA:IEEE,2021,pp.1834-1851。
[0236]
[15] L. Hanzlik, JLSri, A. Thyagarajan, and B. Wagner, “Sweep-uc: Swappingcoins privately,” in 2024 IEEE Symposium on Security and Privacy (SP), IEEE. San Francisco, CA, USA: IEEE, 2024, pp. 3822-3839.
[0237]
[16] P.Han, Z.Yan, LTYang, and E.Bertino, “P2C2T: Preserving the privacy of
[0238] cross-chain transfer,” Cryptology ePrint Archive, Paper 2024 / 1467, 2024. [Online].
[0239] Available: https: / / eprint.iacr.org / 2024 / 1467.
[0240]
[17] Wang Zongyou, Zhu Gengliang. Cross-blockchain data processing method, device, computer equipment and storage medium[P].
[0241] Guangdong Province: CN118070339A, May 24, 2024.
[0242] The non-linkable and variable-amount cross-chain asset transfer method disclosed in the present invention has the following beneficial effects:
[0243] (1) In the process of asset transfer, the present invention sequentially executes the protocols of transfer pledge, transfer registration and transfer execution. When the asset recipient withdraws the assets locked in the second shared address, the payment center must withdraw the assets locked in the first shared address. If there is a problem with the asset transfer, P s and P h Assets locked in a shared address can be redeemed through the time lock function, achieving atomicity.
[0244] (2) In the present invention, each successful 1-m transfer will generate an identical transfer record (V, m), where V is the amount of the asset transferred and m represents the number of payments. Assume that the on-chain observer has obtained the content of k groups of recipients (each group of recipients is to receive currency equivalent to V units of currency in the first blockchain), and these recipients are all different 1-m transfers. For a specific sender, the on-chain observer cannot determine which group of recipients received the currency, but must randomly select one from the k groups. Similarly, for a specific recipient, the on-chain observer can only randomly select one from the k senders to associate. Since the pairing of senders and receivers can only be randomly selected, the probability of a successful match is 1 / k, not 1. This means that the on-chain observer cannot definitely associate a specific sender with a receiver, thus achieving unlinkability.
[0245] (3) In the present invention, the asset sender can actively set the amount and number of transfers, which only requires the V unit currency on the first blockchain B1 to be The currencies on the second blockchain B2 are roughly equivalent, so there is no need to fix these amounts, so the amount variability is met, w i The amount of assets locked by the payment center at the second shared address to be transferred to the i-th asset recipient, where m is the number of asset recipients.
[0246] (4) In the present invention, a novel message interconnection method is used to enable P s Only two transactions need to be participated in. If 1~m transfers are completed, the asset sender only needs to participate in two transactions, and the receiver only needs to participate in 2m transactions. The total number of transactions required is 2m+2, which is less than the number of transactions for m repeated 1~1 transfers, that is, 4m, so the transaction aggregability is met. Specifically, the asset sender transfers its assets on the first blockchain to the first shared address with the payment center (1 transaction), the payment center locks enough assets on the second blockchain to the second shared address with the asset receiver (m transactions), the payment center deposits the assets locked on the first shared address into its asset address on the first blockchain (1 transaction), and the asset receiver deposits the assets locked on the second shared address into its asset address on the second blockchain (m transactions). Therefore, when performing 1~m transfers, the asset transfer process of the present invention requires 2m+2 transactions, and the solution meets the transaction aggregability.
[0247] (5) In the present invention, all currencies on the first blockchain B1 locked by the asset sender are ultimately transferred to the asset receiver at roughly equivalent value. There is no need to lock additional currencies to participate in the cross-chain transfer process, thus satisfying the de-collateralization nature.
[0248] (6) In the present invention, each asset recipient must use the request qualification bound to the asset to make a request to the payment center, thereby ensuring resistance to Griefing attacks.
[0249] (7) Digital signature technology used in the present invention S The signature algorithm Sign in the adapter signature technology can adopt the signature algorithm and verification algorithm, so it can support adapter signatures. At the same time, the present invention also supports BLS signatures, which only requires on-chain signature verification and time lock functions, making it applicable to almost all blockchains.
[0250] (8) The present invention demonstrates security and privacy protection under static corruption in a Universal Composable (UC) framework. The adversary declares the parties it wants to corrupt at the outset. Since the present invention includes signature verification operations at each stage, no matter what message the adversary forges, the signature verification will fail, making the adversary unable to penetrate. This strong security and privacy protection ensures the robustness of the present invention in complex and unpredictable environments.
[0251] The present invention can be widely applied to cross-chain transfer scenarios. For example, one application scenario of the present invention can be:
[0252] Company labor remuneration payment: Company (as P s ) need to be provided to multiple employees (as P r,i ) payroll. Traditionally, companies and employees need to maintain accounts at the same bank, limiting flexibility in payroll. This invention addresses this limitation by leveraging cross-chain blockchain technology, allowing companies to pay on one blockchain while employees receive their wages on another. Furthermore, through an electronic bulletin board mechanism, direct transactions between companies and employees are concealed, achieving unlinkability and protecting privacy.
[0253] For example, another application scenario of the present invention may be:
[0254] Personal shopping payment: Consumer (as P s ) want to pay for goods using the currency on the blockchain they already hold, such as Bitcoin or Ethereum. But merchants (as P r,i ) only accepts currencies on another blockchain, such as USDT or a stablecoin. TransferHub facilitates these cross-chain payments without requiring consumers to hold currency on the same blockchain as the merchant. Furthermore, through an electronic bulletin board mechanism, the direct transaction relationship between consumers and merchants is concealed, achieving unlinkability and protecting privacy.
[0255] In summary, the unlinkable and scalable cross-chain asset transfer method provided by the present invention can simultaneously address the cross-chain asset transfer requirements of atomicity, unlinkability, scalability, transaction aggregability, decollateralization, and Griefing attack resistance. This method integrates an exchange protocol, a redemption protocol, and an electronic bulletin board mechanism to achieve atomicity, unlinkability, and scalability. This method introduces a message interconnection method to ensure transaction aggregability, achieves decollateralization by reusing locked assets on the blockchain, and achieves Griefing attack resistance by binding request qualifications to assets. The solution only requires on-chain signature verification and time lock functionality, supports adapter signatures and BLS signatures, and is applicable to cross-chain transfer scenarios across almost all blockchains.
[0256] It should be noted that the terms "first," "second," and the like are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present invention described herein can be implemented in sequences other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Instead, they are merely examples of devices and methods consistent with some aspects of the present invention.
[0257] Although the present invention is described herein in conjunction with various embodiments, in the process of implementing the claimed invention, those skilled in the art can understand and implement other variations of the disclosed embodiments by viewing the drawings and the disclosed content. In the description of the present invention, the word "comprising" does not exclude other components or steps, "one" or "a" does not exclude multiple situations, and "multiple" means two or more, unless otherwise clearly and specifically defined. In addition, certain measures are recorded in different embodiments, but this does not mean that these measures cannot be combined to produce good results.
[0258] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.
Claims
1. A non-linkable and variable-amount cross-chain asset transfer method, characterized by: include: Transfer and pledge phase: The asset sender queries the electronic bulletin board to identify an anonymous set of asset senders with the same asset transfer requirements. They then join the anonymous set by writing an asset transfer message to the electronic bulletin board. The asset transfer message includes the asset transfer amount and the number of payments m. The asset senders in the anonymous set transfer their assets on the first blockchain to the first shared address with the payment center, and send the payment center a commitment and proof of asset transfer from the first blockchain for the payment center to verify their validity. After verification, the payment center signs the commitment and sends the signature along with its asset address on the first blockchain to the asset sender. The asset sender obtains the asset transfer certificate from the payment center and forwards the certificate to the m asset recipients on the second blockchain. Transfer registration phase: The asset recipient verifies the received credential. Once the verification is successful, it generates a randomized commitment, a randomized signature, and an extended identification commitment and sends them to the payment center. The payment center verifies the received randomized commitment and randomized signature. Once the verification is successful, it locks its assets on the second blockchain to the second shared address with the asset recipient, records the asset address of the asset recipient on the second blockchain, and signs the received commitment to obtain an extended credential. The asset recipient verifies the extended credential and, once the verification is successful, sends the extended credential to the asset sender. Transfer execution phase: The asset sender verifies the received extended credential. Once the verification is passed, the payment center deposits the assets locked in the first shared address into its asset address on the first blockchain. Transfer completion stage: The asset recipient deposits the assets locked on the second shared address into its asset address on the second blockchain and informs the payment center of the successful withdrawal. After receiving the withdrawal success message from the asset recipient, the payment center removes the asset recipient's asset address from the record.
2. The unlinkable and variable-amount cross-chain asset transfer method according to claim 1, characterized in that: Before the pledge transfer stage, the method further includes: System initialization phase: Generate public keys for the asset sender and the payment center, and generate their own private keys for the asset sender and the payment center for use in subsequent phases; the electronic bulletin board declares the message format and query conditions for write operations.
3. The unlinkable and variable-amount cross-chain asset transfer method according to claim 1, characterized in that: The asset amount of V units on the first blockchain is not less than that on the second blockchain The amount of assets per unit; Where V is the amount of assets locked by the asset sender on the first shared address, w i The amount of assets locked by the payment center at the second shared address to be transferred to the i-th asset recipient.
4. The unlinkable and variable-amount cross-chain asset transfer method according to claim 2, characterized in that: The message format of the write operation is: msg w :=((x V ,x m ),x meta :=(x txid ,x non_txid )); Among them, the message content (x V ,x m ) means to divide x m Transfer x V Units of assets, message metadata x meta Plays a verification role, x txid Represents a unique transaction identifier, x non_txid Represents metadata other than the transaction identifier; The query conditions are: con r := (x V , x m ) or con r := (x l ,"times_des"); Among them, con r :=(x V ,x m ) means to query all the items that match (x V ,x m ) news, con r :=(x l ,"times_des") means to find all messages with the same message content (x V ,x m ) messages into a set, sort by set size and return the first x l The message content of the largest set, "times_des" indicates descending order.
5. The unlinkable and variable-amount cross-chain asset transfer method according to claim 2, characterized in that: The pledge transfer stage specifically includes: The asset sender queries the electronic bulletin board to identify an anonymous set of asset senders with the same asset transfer requirements, locks their assets on the first blockchain to the first shared address, and joins the anonymous set of asset senders by writing an asset transfer message to the electronic bulletin board; The asset sender generates a credential identifier, generates a first commitment for the credential identifier using the commitment algorithm in the randomizable signature technology for randomizable commitments, generates a first proof for the first commitment using the proof algorithm in the non-interactive zero-knowledge proof technology, generates a second commitment for the asset transfer amount using the commitment algorithm in the randomizable signature technology for randomizable commitments, and generates a second proof for the second commitment using the proof algorithm in the non-interactive zero-knowledge proof technology; and sends the first commitment, first proof, second commitment, and second proof to the payment center. The payment center uses the verification algorithm in the non-interactive zero-knowledge proof technology to verify the first commitment, the first proof, the second commitment, and the second proof. After the verification is passed, the payment center uses the signature commitment algorithm in the randomizable signature technology of the randomizable commitment to generate a first signature for the first commitment and the second commitment, and sends the asset address and the first signature on the first blockchain to the asset sender; The asset sender verifies the first signature using the verification algorithm in the randomizable signature technology of the randomizable commitment. After the verification is passed, the certificate identifier, asset transfer amount, first signature, first commitment and second commitment are sent as the certificate of transferred assets obtained from the payment center to the m asset recipients on the second blockchain.
6. The unlinkable and variable-amount cross-chain asset transfer method according to claim 5, characterized in that: The method further includes: starting to time the cross-chain asset transfer time during the system initialization phase; The pledge transfer stage also includes: When an asset sender in the anonymous set of asset senders transfers assets on the first blockchain to the first shared address, the asset sender sets a first clock cycle and records the current time; After the asset sender sends the first commitment, the first proof, the second commitment, and the second proof to the payment center, and before the payment center verifies the first commitment, the first proof, the second commitment, and the second proof using the verification algorithm of the non-interactive zero-knowledge proof technology, the payment center determines whether the first clock cycle set by the asset sender is reasonable based on the recorded time. If it is unreasonable, the cross-chain asset transfer is terminated; if it is reasonable, the verification algorithm of the non-interactive zero-knowledge proof technology is continued to be used to verify the first commitment, the first proof, the second commitment, and the second proof.
7. The unlinkable and variable-amount cross-chain asset transfer method according to claim 2, characterized in that: The transfer registration stage specifically includes: The asset recipient uses the verification algorithm in the Pedersen commitment technology to verify the first commitment and the second commitment, and uses the verification algorithm in the randomizable signature technology of the randomizable commitment to verify the first signature. After verification, the randomized signature algorithm in the randomizable signature technology of the randomizable commitment is used to generate a first randomized commitment, a second randomized commitment, and a first randomized signature for the first and second commitments, and uses the commitment algorithm in the randomizable signature technology of the randomizable commitment to generate a third commitment for the extended credential identifier; a return message is generated based on the first randomized commitment, the second randomized commitment, the third commitment, the first randomized signature, and the asset address of the asset recipient on the second blockchain and sent to the payment center; The payment center verifies the content of the returned message using the verification algorithm in the Pedersen commitment technology and the verification algorithm in the randomizable signature technology for randomizable commitments. After verification, the payment center records the asset address of the asset recipient on the second blockchain, locks the asset on the second blockchain to the second shared address, establishes a redemption transaction and redemption parameters for the asset recipient, generates certificate conditions using the commitment algorithm in the redemption technology, and uses the signature commitment algorithm in the randomizable signature technology for randomizable commitments to generate a second signature for the first randomized commitment, the second randomized commitment, and the third commitment, and sends the certificate conditions and the second signature to the asset recipient; The asset recipient uses the verification algorithm in the redemption technology to verify the received certificate conditions, and uses the verification algorithm in the randomized signature technology of the randomized commitment to verify the second signature. After the verification is passed, the first randomized commitment, the second randomized commitment, the third commitment, and the second signature are sent to the asset sender as an extended credential; the extended credential also includes an extended credential identifier.
8. The unlinkable and variable-amount cross-chain asset transfer method according to claim 7, characterized in that: The method further includes: starting to time the cross-chain asset transfer time during the system initialization phase; The transfer registration stage also includes: After the payment center locks its assets on the second blockchain to the second shared address, the payment center sets a second clock cycle and records the current timing; While the asset recipient uses the verification algorithm in the redemption technology to verify the received certificate conditions, and uses the verification algorithm in the randomized signature technology of the randomized commitment to verify the second signature, the asset recipient determines whether the second clock cycle set by the payment center is reasonable based on the recorded moment, and determines whether the expected assets to be received meet expectations; if it is unreasonable or does not meet expectations, the cross-chain asset transfer is terminated; if it is reasonable and meets expectations, after all relevant verifications are passed, the extended certificate identifier, the first randomized commitment, the second randomized commitment and the third commitment and the second signature are continued to be sent to the asset sender as an extended certificate.
9. The unlinkable and variable-amount cross-chain asset transfer method according to claim 1, characterized in that: The transfer execution phase specifically includes: Create m withdrawal transactions for the payment center; The asset sender uses the verification algorithm in the Pedersen commitment technology and the verification algorithm in the randomizable signature technology of the randomizable commitment to verify the received extended credential. After the verification is passed, the asset sender uses the randomized signature algorithm in the randomizable signature technology of the randomizable commitment to make a third randomized commitment for the first randomized commitment, a fourth randomized commitment for the second randomized commitment, a fifth randomized commitment for the third commitment, and a second randomized signature for the second signature. The asset sender also uses the proof algorithm in the non-interactive zero-knowledge proof technology to produce a third proof for the fourth randomized commitment and sends the fourth randomized commitment, the fifth randomized commitment, the third randomized commitment, the second randomized signature, and the third proof to the payment center. The payment center verifies the third proof using the verification algorithm in the non-interactive zero-knowledge proof technology, and verifies the fourth randomized commitment, the fifth randomized commitment, the third randomized commitment, and the second randomized signature using the verification algorithm in the randomized signature technology of the randomized commitment; if the verification is successful, the asset sender and the payment center set a public parameter, which contains m information about the credential identifier tid i The first blinded message bsm 1,i The payment center generates the first exchange message xm using the Setup algorithm of the exchange technology according to the public parameters 1,1 Sent to the asset sender; the asset sender according to xm 1,1 Generate the first second exchange message xm using the Buy algorithm of the exchange technology 2,1 Sent to the payment center, the payment center and the asset sender perform m-1 message interconnections; Among them, in the i=[2,3,…,m]th message interconnection process, the payment center uses the verification algorithm in the digital signature technology to verify the i-1th second exchange message xm 2,i-1 After verification, the Setup algorithm of the exchange technology is used to generate the first exchange message xm i 1,i , using the signature algorithm in the blind BLS signature technology to perform the bsm in the public parameter 1,i Generate the i-th second blinded message bsm 2,i and bsm in the public parameters 1,i-1 Generate the i-1th second blinded message bsm 2,i-1 , using non-interactive zero-knowledge proof technology to establish the algorithm and prove the algorithm for BSM 2,i and bsm 2,i-1 Generate the i-th composite message And the corresponding proof, xm 1,i 、 The asset sender uses the verification algorithm in the non-interactive zero-knowledge proof technology to verify the composite message and the proof. If the verification is successful, the Buy algorithm of the exchange technology is used to generate the i-th second exchange message xm 2,i Sent to the payment center until the payment center receives the mth second exchange message xm 2,m ; The payment center uses the Sell algorithm in the exchange technology to generate xm 2,m The signature of , deposits the assets locked in the first shared address into its asset address on the first blockchain; The asset sender obtains the mth second blinded message based on the signature of the payment center on the mth second exchange message using the Get algorithm in the exchange technology. Based on the mth second blinded message, the remaining m-1 second blinded messages are deduced by reversing the group operation. The U2 algorithm in the blind BLS signature technology is used to sign the m second blinded messages respectively to obtain m credential identifiers tid. i The BLS signature will be about the credential identifier tid i The BLS signatures are sent to the corresponding asset recipients to notify the asset recipients of the payment.
10. The unlinkable and variable-amount cross-chain asset transfer method according to claim 6 or 8, characterized in that: The unlinkable and variable-amount cross-chain asset transfer method also includes: Transfer timeout phase: The asset sender and the payment center use on-chain time lock technology or verifiable timed discrete logarithm technology to retrieve their assets from the first shared address and the second shared address respectively.
Citation Information
Patent Citations
Data processing method and device based on multi-block chain, equipment and medium
CN118921377A