Privacy protection asset allocation method and system based on zero knowledge proof
By employing a privacy-preserving asset allocation method based on zero-knowledge proofs, and utilizing deposit identifiers and tree-structured data, the impossible trinity problem in on-chain anonymous payment schemes is solved. This achieves strong double-spending protection and privacy protection for non-fixed denominations, supports anonymous transfers of any amount, and enhances the security and decentralization of asset allocation.
Patent Information
- Application Number
- CN202511117826.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-11
- Publication Date
- 2025-11-18
AI Technical Summary
Existing on-chain anonymous payment solutions suffer from the impossible triangle problem, lack flexibility, cannot achieve anonymous transfers of non-fixed denominations, and the traditional nullifier mechanism fails, failing to provide strong double-spending protection in a decentralized environment.
A privacy-preserving asset allocation method based on zero-knowledge proofs is adopted. By generating unique deposit identifiers and tree-structured data, and combining them with zero-knowledge proofs for verification, the uniqueness of deposit identifiers and the validity of commitments are ensured, thereby achieving strong double-spending protection against non-fixed denominations.
It achieves strong double-spending protection for non-fixed denominations in a fully decentralized environment, supports anonymous transfers of any deposit amount, enhances the security and privacy protection of asset allocation, and reduces gas costs.
Smart Images

Figure CN120975781A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the field of blockchain and cryptography technology, and particularly relates to a privacy protection asset allocation method and system based on zero-knowledge proof. BACKGROUND
[0002] With the rapid development of blockchain technology, public chains such as Ethereum provide transparent and tamper-proof transaction records, but also cause serious leakage of user privacy. All transaction amounts, sender and receiver addresses are publicly available, making the user's financial situation and transaction behavior completely exposed. In order to protect the privacy of users, on-chain anonymous payment technology is proposed, which aims to cut off the explicit association between transaction input and output without relying on a trusted third party, thereby realizing anonymous transfer of assets.
[0003] Existing on-chain anonymous payment schemes include: (1) Decentralized scheme based on fixed denomination: represented by TornadoCash, which realizes strong double-spend protection through nullifier hash, and is completely decentralized; its technical principle is that when depositing, the user generates a random number as a secret value and calculates the commitment and submits it; when withdrawing, the user needs to use zero-knowledge proof technology to prove to the chain that he indeed has an unused commitment corresponding to a certain fixed denomination, and provides a Nullifier (invalidation identifier), which can use the commitment hash as the only Nullifier; (2) Centralized scheme based on non-fixed denomination: usually coordinated by a centralized server or relay, the user sends assets of any amount to the centralized server, the server merges them into a fund pool, and according to the user's instructions, sends an equivalent asset from the bonus pool to the designated recipient; (3) Decentralized attempt based on non-fixed denomination: when depositing, use commitment to bind any amount and secret value to realize amount hiding, when withdrawing, use ZKP to prove to the chain contract that "I know the legal deposit corresponding to the amount and secret value, and the deposit has not been used, and my withdrawal amount is legal".
[0004] However, the existing on-chain anonymous payment scheme has corresponding deficiencies, including: (1) lack of flexibility: only supports fixed deposit denominations, and cannot support anonymous transfer of arbitrary amounts; (2) sacrificing the decentralized nature: relying on a centralized relay for double-spend detection, which has a single point of failure and the risk of malfeasance; (3) failure of the traditional Nullifier mechanism: different amounts of the same user will generate completely different commitments, and cannot establish a strong binding relationship between the commitment and the amount, so a Nullifier that can prove its validity and ensure its uniqueness cannot be generated for different amounts of deposits. At the same time, the existing on-chain anonymous payment scheme always has a fundamental "impossible triangle" problem, that is, the three core features of non-fixed denomination, strong double-spend protection, and decentralization cannot be achieved simultaneously in the same system, and existing technologies often have to sacrifice one or two features to achieve the remaining features.
[0005] Therefore, how to provide an effective technical solution to solve the "impossible triangle" problem, lack of flexibility, and failure of the traditional Nullifier mechanism in the prior art has become a difficult problem to be solved in the prior art. SUMMARY
[0006] The purpose of the present application is to provide a privacy-protected asset allocation method and system based on zero-knowledge proof, to solve the above problems existing in the prior art.
[0007] To achieve the above purpose, the present application adopts the following technical solutions: In a first aspect, the present application provides a privacy-protected asset allocation method based on zero-knowledge proof, comprising: Obtaining digital assets deposited by a payer, depositing the digital assets into a blockchain using a smart contract, and generating a unique deposit identifier; Obtaining an allocation array and a commitment submitted by the payer, a deposit identifier, a total allocation amount, and a first zero-knowledge proof, the first zero-knowledge proof proving that the digital assets corresponding to the deposit identifier exist and belong to the depositor, the total allocation amount is less than or equal to the digital assets, and the commitment calculation is correct; Using a preset smart contract on the blockchain to verify the first zero-knowledge proof, if the verification is correct, marking the deposit identifier as used, and inserting the commitment as a leaf node into a preset tree-shaped data structure to form a tree root of the tree-shaped data structure; Obtaining a withdrawal request of at least one recipient in the allocation array, the withdrawal request including a withdrawal amount, a tree root, and a second zero-knowledge proof, combining the data corresponding to each recipient in the allocation array with the commitment and the second zero-knowledge proof to obtain a receipt corresponding to each recipient; distributing the receipt corresponding to each receiver to the receiver, and the receiver verifying the validity of the commitment based on the receipt; if the verification is valid, obtaining a tree root of the tree-shaped data structure, and generating a third zero-knowledge proof based on the tree root, the third zero-knowledge proof being used to prove that the withdrawal amount belongs to the commitment and the commitment is contained in the tree root; verifying the validity of the third zero-knowledge proof, and repeatedly verifying the deposit identifier, the receipt and the commitment, if the verification is valid and not reused, paying the withdrawal amount to the receiver.
[0008] In a possible design, the commitment, the deposit identifier, the total allocation amount and the first zero-knowledge proof submitted by the payer are obtained, including: obtaining an allocation array containing at least one receiver off-chain; using a random number generator to obtain a random secret value; binding the allocation array, the deposit identifier and the random secret value based on a cryptographic commitment scheme to obtain the commitment; obtaining the total allocation amount of the depositor, and generating the first zero-knowledge proof based on the allocation array, the random secret value, the deposit identifier, the total allocation amount and the commitment.
[0009] In a possible design, the validity of the third zero-knowledge proof is verified, including: verifying the validity of the third zero-knowledge proof using a preset smart contract on the blockchain.
[0010] In a possible design, the first zero-knowledge proof, the second zero-knowledge proof and the third zero-knowledge proof can be generated in a smart contract, off-chain or in another blockchain.
[0011] In a possible design, the tree-shaped data structure is any tree-shaped data structure supporting a root node and supporting generation of a proof path from a leaf node to the root node.
[0012] In a possible design, the first zero-knowledge proof, the second zero-knowledge proof and the third zero-knowledge proof are used as a zero-knowledge proof system. The zero-knowledge proof system is any cryptographic proof system that can prove that private information satisfies a specific constraint condition without leaking the private information itself.
[0013] In a second aspect, the present application provides a privacy protection asset allocation system based on zero-knowledge proof, including: a storage generation module for obtaining digital assets deposited by a payer, depositing the digital assets into a blockchain using a smart contract, and generating a unique deposit identifier; The first acquisition module is used to acquire the allocation array, the commitment submitted by the payer, the deposit identifier, the total allocation amount, and the first zero-knowledge proof. The first zero-knowledge proof is used to prove that the digital asset corresponding to the deposit identifier exists and belongs to the depositor, that the total allocation amount is less than or equal to the digital asset, and that the commitment calculation is correct. The first verification module is used to verify the first zero-knowledge proof using a preset smart contract on the blockchain. If the verification is correct, the deposit identifier is marked as used, and the commitment is inserted as a leaf node into the preset tree data structure to form the root of the tree data structure. The second acquisition module is used to acquire the extraction request of at least one recipient in the allocation array. The extraction request includes the extraction amount, the root of the tree, and the second zero-knowledge proof. The data corresponding to each recipient in the allocation array is combined with the commitment and the second zero-knowledge proof to obtain a receipt that corresponds to at least one recipient. The second verification module is used to distribute a corresponding receipt to each recipient, and the recipient verifies the validity of the commitment based on the receipt. The third acquisition module is used to acquire the root of the tree data structure if the verification is valid, and generate a third zero-knowledge proof based on the root. The third zero-knowledge proof is used to prove that the extracted amount belongs to the commitment and that the commitment is contained in the root. The third verification module is used to verify the validity of the third zero-knowledge proof and to verify the repeatability of the deposit identifier, receipt, and commitment. If the verification is valid and the item is not reused, the recipient will be paid the withdrawal amount.
[0014] One possible design also includes: The storage management module is used to store information corresponding to digital assets and unique deposit identifiers; The asset transfer module is used to perform the allocation of funds after verification that the asset is valid and has not been reused.
[0015] Thirdly, the present invention provides a computer device comprising a memory, a processor, and a transceiver connected in sequence and communication, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the privacy-preserving asset allocation method based on zero-knowledge proof as described in the first aspect above.
[0016] Fourthly, the present invention provides a computer-readable storage medium storing instructions that, when executed on a computer, perform the privacy-preserving asset allocation method based on zero-knowledge proof as described in the first aspect above.
[0017] Fifthly, the present invention provides a computer program product containing instructions that, when executed on a computer, cause the computer to perform the privacy-preserving asset allocation method based on zero-knowledge proof as described in the first aspect above.
[0018] The beneficial effects of this invention are as follows: (1) This invention discloses a privacy-protected asset allocation method and system based on zero-knowledge proof. It verifies the validity of the third zero-knowledge proof and performs repeatability verification on deposit identifiers, receipts and commitments. It does not rely on centralized nodes and achieves strong double-spending protection for non-fixed denominations in a completely decentralized environment, solving the "impossible triangle" problem in the prior art. (2) This invention can support depositors to deposit any amount of money and can also support the unlimited splitting of deposits and distribution to multiple recipients, thus meeting diverse asset allocation scenarios. (3) This invention separates the deposit identifier from the allocation proof, establishes an effective unique constraint, solves the problem of the traditional nullifier mechanism failing under non-fixed denominations, and ensures that each deposit can only be used once, effectively preventing the reuse of funds, enhancing the security of asset allocation, and facilitating application and promotion. Attached Figure Description
[0019] Figure 1 A flowchart illustrating a privacy-preserving asset allocation method based on zero-knowledge proof, provided as a first aspect of an embodiment of the present invention; Figure 2 This is a block diagram of a privacy-preserving asset allocation system based on zero-knowledge proof, provided as a second aspect of the present invention. Detailed Implementation
[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below in conjunction with the accompanying drawings and descriptions of the embodiments or the prior art. Obviously, the following description of the structure of the accompanying drawings is only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. It should be noted that the description of these embodiments is for the purpose of helping to understand the present invention, but does not constitute a limitation of the present invention.
[0021] It should be understood that although the terms first, second, etc., may be used herein to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, a first unit may be referred to as a second unit, and similarly, a second unit may be referred to as a first unit, without departing from the scope of the exemplary embodiments of the invention.
[0022] It should be understood that the term "and / or" that may appear in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, B exists alone, and A and B exist simultaneously. The term " / and" that may appear in this document describes another relationship between related objects, indicating that two relationships can exist. For example, A / and B can mean: A exists alone, and A and B exist alone. In addition, the character " / " that may appear in this document generally indicates that the related objects before and after it are in an "or" relationship.
[0023] Example: like Figure 1 As shown, the first aspect of this embodiment provides a privacy-preserving asset allocation method based on zero-knowledge proof, which can be executed, but is not limited to, by a computer device or virtual machine with certain computing resources, such as a personal computer or smartphone, or by a virtual machine; the privacy-preserving asset allocation method includes, but is not limited to, the following steps: S1. Obtain the digital assets deposited by the payer, use a smart contract to store the digital assets into the blockchain, and generate a unique deposit identifier; S2. Obtain the allocation array and the commitment, deposit identifier, total allocation amount and first zero-knowledge proof submitted by the payer. The first zero-knowledge proof is used to prove that the digital asset corresponding to the deposit identifier exists and belongs to the depositor, the total allocation amount is less than or equal to the digital asset, and the commitment is calculated correctly. Specifically, in step S2, the allocation array, the payer's submitted commitment, deposit identifier, total allocation amount, and first zero-knowledge proof are obtained, including: S21. Obtain the allocation array that contains at least one receiver in the chain; S22. Use a random number generator to obtain a random secret value; S23. Based on a cryptographic commitment scheme, the allocation array, deposit identifier, and random secret value are bound together to obtain a commitment; S24. Obtain the total allocation amount for depositors and generate a first zero-knowledge proof based on the allocation array, random secret value, deposit identifier, total allocation amount, and commitment.
[0024] It should be noted that "off-chain" refers to the blockchain environment.
[0025] S3. Verify the first zero-knowledge proof using a pre-set smart contract on the blockchain. If the verification is successful, mark the deposit identifier as used and insert the commitment as a leaf node into the pre-set tree data structure to form the root of the tree data structure. In one possible design, the tree data structure is any tree data structure that supports a root node and supports generating a proof path from a leaf node to the root node.
[0026] It should be noted that the smart contract in this embodiment includes contract state variables and a DepositInfo structure. The contract state variables include deposits (digital assets), validCommitments (valid commitments), commitmentTreeRoot (current tree root), and validTreeRoots (historical set of valid tree roots). The DepositInfo structure includes amount (deposited digital assets), owner (depositor's address), and used (whether it has been used).
[0027] In one possible design, the deposit function is: function deposit() returns (DepositID): DepositID = generateUniqueID() deposits[DepositID] = {msg.value, msg.sender, false} return DepositID S4. Obtain the extraction request of at least one recipient in the allocation array, the extraction request including the extraction amount, the root of the tree and the second zero-knowledge proof, and combine the data corresponding to each recipient in the allocation array with the commitment and the second zero-knowledge proof to obtain a receipt corresponding to at least one recipient. Specifically, the second zero-knowledge proof is obtained by the depositor sending a commitment along with the corresponding receipt and allocation array to the recipient; the recipient then reconstructs the proof based on the receipt and allocation array.
[0028] S5. Distribute a receipt to each recipient, who then verifies the validity of the commitment based on the receipt; S6. If the verification is valid, obtain the root of the tree data structure, and generate a third zero-knowledge proof based on the root. The third zero-knowledge proof is used to prove that the extracted amount belongs to the commitment and that the commitment is contained within the root. S7. Verify the validity of the third zero-knowledge proof and perform repeatability verification on the deposit identifier, receipt, and commitment. If the verification is valid and the item is not reused, pay the recipient the withdrawal amount.
[0029] Specifically, in step S7, the validity of the third zero-knowledge proof is verified, including: S71. Use a pre-defined smart contract on the blockchain to verify the validity of the third zero-knowledge proof.
[0030] In this embodiment, a nullifier is used to perform duplicate verification on the deposit identifier, receipt, and commitment to ensure the global uniqueness of the deposit.
[0031] One possible design also includes contracts with transaction fee processing, comprising two methods. The first is that when a user deposits digital assets or withdraws them, the system automatically deducts a transaction fee, which can be allocated to a separate distribution contract for secondary distribution and rewards to participants to incentivize stakeholders. The second method involves including the prover's information when withdrawing using credentials. The distribution contract can then directly reward the prover. Since the prover provides GPU computing power, additional rewards can be generated. These rewards can be used to incentivize participating stakeholders and zero-knowledge provers to promote ecosystem prosperity.
[0032] One possible design also includes a time-lock mechanism, setting a lock-up period when depositors deposit digital assets. Withdrawals are prohibited during the lock-up period, but can be unlocked under certain conditions.
[0033] In one possible design, privacy allocation of multiple ERC20 tokens is also supported.
[0034] One possible design also includes KYC (Know Your Customer) and AML (Anti-Money Laundering) compliance checks.
[0035] One possible design also includes a fee collection and allocation mechanism. Fees for deposits, submissions, and withdrawals can be configured to be charged based on preset conditions, including calculations based on a fixed amount or percentage, while also supporting dynamic fee adjustment and allocation strategies.
[0036] In one possible design, the receiver can submit multiple extraction requests to optimize gas costs.
[0037] Furthermore, this embodiment supports asset allocation across blockchains.
[0038] It should be noted that, in this embodiment, the first zero-knowledge proof, the second zero-knowledge proof, and the third zero-knowledge proof can all be generated within a smart contract, off-chain, or in other blockchains; the first zero-knowledge proof, the second zero-knowledge proof, and the third zero-knowledge proof are regarded as a zero-knowledge proof system; the zero-knowledge proof system includes, but is not limited to, any cryptographic proof system that can prove that private information satisfies specific constraints without leaking the private information itself.
[0039] In one possible design, the process includes: an allocator generating an address commitment and a random salt value for each recipient; generating a first-level proof and outputting an address fingerprint array; an outsourced third-party prover generating a second-level proof based on the address fingerprint array; submitting the commitment and proof on the blockchain; distributing receipts containing salt values and path information to recipients; recipients generating their own first-level proof, which proves the address commitment and tree path; the outsourced third-party prover generating a second-level proof based on the address fingerprint array; recipients generating a third-level wrapper proof locally; and submitting the final proof on-chain for asset withdrawal. For the outsourced proof generation scenario, the system completely hides the user's address from the third-party prover, ensuring that the third-party prover cannot obtain the user's real address, while also preventing appropriation and duplication.
[0040] One possible design also includes degenerating the tree-like data structure into a queue or list structure. Specifically, commitments are inserted sequentially into the queue or list, the overall state of the queue or list is used as the basis for verification, and proofs of commitments to the current state are generated. Using a linear data structure instead of a tree structure reduces implementation complexity, supports asynchronous verification, and can be seamlessly integrated with existing architectures while maintaining the same security and functionality.
[0041] Based on the aforementioned public information, this embodiment uses a double-spending prevention mechanism to maintain a triple mapping of zero-knowledge proofs, commitments, and deposit identifiers through a pre-defined smart contract in the blockchain. The commitment and zero-knowledge proof can only be used once, with the commitment used to prove the validity of the payment voucher. Furthermore, the zero-knowledge proof is generated on the blockchain and only needs to be verified thereon, saving over 90% of gas costs compared to direct computation on the blockchain, significantly lowering the barrier to entry for users. This embodiment relies solely on the public blockchain and the zero-knowledge generator, requiring no centralized nodes. The recipient can independently check the validity of the commitment without trusting the depositor. Only the values of the allocation array and the root of the tree-like data structure are exposed on the blockchain, completely isolating the identities of the depositor and the recipient, providing a high level of privacy protection. This embodiment does not limit the deposit amount or withdrawal time, avoiding reverse engineering through amounts and time series.
[0042] like Figure 2 As shown, the second aspect of this embodiment provides a privacy-preserving asset allocation system based on zero-knowledge proof, including: The storage generation module is used to obtain the digital assets deposited by the payer, use smart contracts to store the digital assets into the blockchain, and generate a unique deposit identifier. The first acquisition module is used to acquire the allocation array, the commitment submitted by the payer, the deposit identifier, the total allocation amount, and the first zero-knowledge proof. The first zero-knowledge proof is used to prove that the digital asset corresponding to the deposit identifier exists and belongs to the depositor, that the total allocation amount is less than or equal to the digital asset, and that the commitment calculation is correct. The first verification module is used to verify the first zero-knowledge proof using a preset smart contract on the blockchain. If the verification is correct, the deposit identifier is marked as used, and the commitment is inserted as a leaf node into the preset tree data structure to form the root of the tree data structure. The second acquisition module is used to acquire the extraction request of at least one recipient in the allocation array. The extraction request includes the extraction amount, the root of the tree, and the second zero-knowledge proof. The data corresponding to each recipient in the allocation array is combined with the commitment and the second zero-knowledge proof to obtain a receipt that corresponds to at least one recipient. The second verification module is used to distribute a corresponding receipt to each recipient, and the recipient verifies the validity of the commitment based on the receipt. The third acquisition module is used to acquire the root of the tree data structure if the verification is valid, and generate a third zero-knowledge proof based on the root. The third zero-knowledge proof is used to prove that the extracted amount belongs to the commitment and that the commitment is contained in the root. The third verification module is used to verify the validity of the third zero-knowledge proof and to verify the repeatability of the deposit identifier, receipt, and commitment. If the verification is valid and the item is not reused, the recipient will be paid the withdrawal amount.
[0043] In one possible design, the system further includes: The storage management module is used to store information corresponding to digital assets and unique deposit identifiers; The asset transfer module is used to perform the allocation of funds after verification that the asset is valid and has not been reused.
[0044] The working process, working details and technical effects of the privacy-preserving asset allocation system based on zero-knowledge proof provided in the second aspect of this embodiment can be found in the privacy-preserving asset allocation method based on zero-knowledge proof described in the first aspect, and will not be repeated here.
[0045] This embodiment provides a computer device including a memory, a processor, and a transceiver connected in sequence. The memory stores a computer program, the transceiver sends and receives messages, and the processor reads the computer program and executes the privacy-preserving asset allocation method based on zero-knowledge proofs as described in the first aspect. Specifically, the memory may include, but is not limited to, random-access memory (RAM), read-only memory (ROM), flash memory, first-in-first-out (FIFO) memory, and / or first-in-last-out (FILO) memory, etc.; the processor may include, but is not limited to, a microprocessor of the STM32F105 series. Furthermore, the computer device may also include, but is not limited to, a power module, a display screen, and other necessary components.
[0046] The working process, working details and technical effects of the aforementioned computer device provided in the third aspect of this embodiment can be found in the privacy-protected asset allocation method based on zero-knowledge proof described in the first aspect, and will not be repeated here.
[0047] This fourth aspect of the embodiment provides a computer-readable storage medium storing instructions comprising the privacy-preserving asset allocation method based on zero-knowledge proof as described in the first aspect. Specifically, the computer-readable storage medium stores instructions that, when executed on a computer, perform the privacy-preserving asset allocation method based on zero-knowledge proof as described in the first aspect. The computer-readable storage medium refers to a data storage medium, which may include, but is not limited to, floppy disks, optical disks, hard disks, flash memory, USB flash drives, and / or Memory Sticks. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.
[0048] The working process, working details and technical effects of the aforementioned computer-readable storage medium provided in the fourth aspect of this embodiment can be found in the privacy-preserving asset allocation method based on zero-knowledge proof as described in the first aspect, and will not be repeated here.
[0049] The fourth aspect of this embodiment provides a computer program product, including a computer program or instructions, which, when executed by a computer, are used to implement the privacy-preserving asset allocation method based on zero-knowledge proof as described in the first aspect.
[0050] The working process, working details and technical effects of the aforementioned computer program product provided in this embodiment can be found in the privacy-preserving asset allocation method based on zero-knowledge proof as described in the first aspect, and will not be repeated here.
[0051] Finally, it should be noted that the above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A privacy-preserving asset allocation method based on zero-knowledge proof, characterized in that, include: The system retrieves the digital assets deposited by the payer, uses smart contracts to store the digital assets on the blockchain, and generates a unique deposit identifier. Obtain the allocation array, the commitment submitted by the payer, the deposit identifier, the total allocation amount, and the first zero-knowledge proof. The first zero-knowledge proof is used to prove that the digital asset corresponding to the deposit identifier exists and belongs to the depositor, that the total allocation amount is less than or equal to the digital asset, and that the commitment calculation is correct. The first zero-knowledge proof is verified using a pre-defined smart contract on the blockchain. If the verification is successful, the deposit identifier is marked as used, and the commitment is inserted as a leaf node into a pre-defined tree data structure to form the root of the tree data structure. Obtain the extraction request of at least one recipient in the allocation array, the extraction request including the extraction amount, the root of the tree and the second zero-knowledge proof, and combine the data corresponding to each recipient in the allocation array with the commitment and the second zero-knowledge proof to obtain a receipt corresponding to at least one recipient. Distribute a corresponding receipt to each recipient, who then uses the receipt to verify the validity of the commitment. If the verification is valid, the root of the tree data structure is obtained, and a third zero-knowledge proof is generated based on the root. The third zero-knowledge proof is used to prove that the extracted amount belongs to the commitment and that the commitment is contained within the root. The validity of the third zero-knowledge proof is verified, and the deposit identifier, receipt, and commitment are repeatedly verified. If the verification is valid and not reused, the withdrawal amount is paid to the recipient.
2. The privacy-preserving asset allocation method based on zero-knowledge proof according to claim 1, characterized in that, Retrieve the allocation array along with the payer's committed pledge, deposit identifier, total allocation amount, and first zero-knowledge proof, including: Get the allocation array that contains at least one receiver in the chain; Use a random number generator to obtain a random secret value; Based on a cryptographic commitment scheme, a commitment is obtained by binding an allocation array, a deposit identifier, and a random secret value. Obtain the total allocation amount for depositors and generate a first zero-knowledge proof based on the allocation array, random secret value, deposit identifier, total allocation amount, and commitment.
3. The privacy-preserving asset allocation method based on zero-knowledge proof according to claim 1, characterized in that, Validation of the third zero-knowledge proof includes: The validity of third-degree zero-knowledge proofs is verified using pre-defined smart contracts on the blockchain.
4. The privacy-preserving asset allocation method based on zero-knowledge proof according to claim 1, characterized in that, The first zero-knowledge proof, the second zero-knowledge proof, and the third zero-knowledge proof are generated within a smart contract, off-chain, or in another blockchain.
5. The privacy-preserving asset allocation method based on zero-knowledge proof according to claim 1, characterized in that, The tree data structure is any tree data structure that supports a root node and supports generating a proof path from a leaf node to the root node.
6. A privacy-preserving asset allocation system based on zero-knowledge proofs, used to implement the method of any one of claims 1 to 5, characterized in that, include: The storage generation module is used to obtain the digital assets deposited by the payer, use smart contracts to store the digital assets into the blockchain, and generate a unique deposit identifier. The first acquisition module is used to acquire the allocation array, the commitment submitted by the payer, the deposit identifier, the total allocation amount, and the first zero-knowledge proof. The first zero-knowledge proof is used to prove that the digital asset corresponding to the deposit identifier exists and belongs to the depositor, that the total allocation amount is less than or equal to the digital asset, and that the commitment calculation is correct. The first verification module is used to verify the first zero-knowledge proof using a preset smart contract on the blockchain. If the verification is correct, the deposit identifier is marked as used, and the commitment is inserted as a leaf node into the preset tree data structure to form the root of the tree data structure. The second acquisition module is used to acquire the extraction request of at least one recipient in the allocation array. The extraction request includes the extraction amount, the root of the tree, and the second zero-knowledge proof. The data corresponding to each recipient in the allocation array is combined with the commitment and the second zero-knowledge proof to obtain a receipt that corresponds to at least one recipient. The second verification module is used to distribute a corresponding receipt to each recipient, and the recipient verifies the validity of the commitment based on the receipt. The third acquisition module is used to acquire the root of the tree data structure if the verification is valid, and generate a third zero-knowledge proof based on the root. The third zero-knowledge proof is used to prove that the extracted amount belongs to the commitment and that the commitment is contained in the root. The third verification module is used to verify the validity of the third zero-knowledge proof and to verify the repeatability of the deposit identifier, receipt, and commitment. If the verification is valid and the item is not reused, the recipient will be paid the withdrawal amount.
7. The privacy-preserving asset allocation system based on zero-knowledge proof according to claim 6, characterized in that, Also includes: The storage management module is used to store information corresponding to digital assets and unique deposit identifiers; The asset transfer module is used to perform the allocation of funds after verification that the asset is valid and has not been reused.
8. A computer device, characterized in that, The device includes a memory, a processor, and a transceiver that are sequentially and communicatively connected. The memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the privacy-preserving asset allocation method based on zero-knowledge proof as described in any one of claims 1 to 5.
9. A computer-readable storage medium, characterized in that... The computer-readable storage medium stores instructions that, when executed on a computer, perform the privacy-preserving asset allocation method based on zero-knowledge proof as described in any one of claims 1 to 5.
10. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or the instructions are executed by the computer, they implement the privacy-preserving asset allocation method based on zero-knowledge proof as described in any one of claims 1 to 5.