Penetration-type supervision privacy protection distributed transaction method and system

By using homomorphic public-key encryption and non-interactive zero-knowledge proof technology, the contradiction between privacy protection and regulatory auditing in cryptocurrency systems is resolved, achieving privacy protection and transparent supervision under the account model, and ensuring the confidentiality, anonymity and regulatory oversight of transactions.

CN120996799APending Publication Date: 2025-11-21SHANDONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511125048.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-12
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

While existing cryptocurrency systems protect transaction privacy, they struggle to achieve effective auditing by regulatory authorities. In particular, under the account model, a system that satisfies both confidentiality and anonymity while supporting transparent oversight has yet to be realized.

Method used

It employs homomorphic public-key encryption and non-interactive zero-knowledge proof technology to encrypt transaction amounts by randomly selecting anonymity sets and generating transaction validity proofs, ensuring the confidentiality and anonymity of transaction information while meeting the regulatory authorities' need for transparent oversight.

Benefits of technology

It enables effective monitoring of transaction activities while protecting transaction privacy, meeting the needs for confidentiality and anonymity, and ensuring the verifiability and regulatory oversight of transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120996799A_ABST
    Figure CN120996799A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy protection distributed transaction method and system for penetration type supervision, and relates to the technical field of cryptocurrency systems, and the method comprises the steps: enabling an initiator account and a receiver account to correspond to an anonymous set; the transaction amount is encrypted based on the anonymous set public key to obtain a secret transaction amount, and the transaction amount, the index corresponding to the sender account and the index corresponding to the receiver account are encrypted based on the supervisor public key to obtain a secret transaction copy; generating a transaction validity proof by using a non-interactive zero-knowledge proof, generating a transaction in combination with the anonymous set, the secret-state transaction amount and the secret-state transaction copy, and verifying by using the non-interactive zero-knowledge proof; and for the verified transaction, the secret balance of each account in the anonymous set is updated according to the secret transaction amount, and transaction information is obtained according to the set secret parameter and the secret transaction copy. Strong privacy protection is met, namely confidentiality and anonymity are met at the same time, and penetrating supervision is supported.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cryptocurrency system technology, and in particular to a privacy-preserving distributed transaction method and system with transparent supervision. Background Technology

[0002] The statements in this section are merely background information related to the present invention and do not necessarily constitute prior art.

[0003] Blockchain-based distributed transaction systems are also known as cryptocurrency systems. Cryptocurrencies are currently a cutting-edge hot topic in financial technology. Privacy in cryptocurrencies encompasses two aspects: confidentiality, meaning that no third party other than the transacting parties can know the transaction amount; and anonymity, meaning that no third party other than the transacting parties can know the identity information of the transacting parties.

[0004] However, while cryptographic technology protects transaction privacy, it also presents significant challenges to regulatory auditing. Confidentiality makes it difficult for regulators to accurately identify illegal activities such as money laundering and fraud, while anonymity allows users to deny their participation in a transaction, further complicating the tracking of fund flows. Therefore, resolving the conflict between privacy protection and regulatory auditing is a pressing technical challenge in cryptocurrency design.

[0005] According to the inventor, there is currently no cryptocurrency system under the account model that satisfies both strong privacy protection (i.e., both confidentiality and anonymity) and supports transparent supervision. Summary of the Invention

[0006] To address the aforementioned issues, this invention proposes a privacy-preserving distributed transaction method and system with penetrating oversight, achieving strong privacy protection while also being subject to penetrating oversight by regulators, thus satisfying both confidentiality and anonymity.

[0007] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a privacy-preserving distributed transaction method with transparent oversight, comprising: Randomly select an anonymous set and associate the initiator's account and the receiver's account with the anonymous set; The transaction amount is encrypted using a homomorphic public-key encryption algorithm based on the anonymous set public key to obtain the encrypted transaction amount. The transaction amount is then encrypted using the regulator's public key to obtain an encrypted transaction copy. A transaction validity proof is generated using non-interactive zero-knowledge proofs. Based on the transaction validity proof, the anonymous set, the encrypted transaction amount, and the encrypted transaction copy, a transaction is generated. Non-interactive zero-knowledge proofs are then used to verify that the encrypted values ​​of the encrypted transaction amount and the encrypted transaction copy are the same. For verified transactions, update the encrypted balance of each account in the anonymous set according to the encrypted transaction amount, and obtain transaction information based on the set secret parameters and the encrypted transaction copy.

[0008] As an alternative implementation method, the verification process includes: for all All of them have secret transaction amounts And ciphertext Established; Indicates whether the sender is transferring out or transferring in the first... The amount in each account, For the anonymous set public key; , It is a random number; This is the public key for the regulator.

[0009] As an alternative implementation, input secret parameters and transactions Analysis For all ,run Obtain the vector of transfer amount Output transaction information ,in They are respectively The index corresponding to the only negative or positive value in the table; Proof of the validity of the transaction; An anonymous set, Let be the dense transaction amount vector. For a copy of a confidential transaction, for The ciphertext in Indicates whether the sender is transferring out or transferring in the first... The amount in each account, For the sender's public key, For the recipient's public key, This indicates that the initiator's public key and the receiver's public key are related to the first one in the anonymous set. Position and The public key corresponding to the bit.

[0010] Secondly, this invention provides a privacy-preserving distributed transaction method with transparent oversight, comprising: Randomly select an anonymous set and associate the initiator's account and the receiver's account with the anonymous set; The transaction amount is encrypted using a homomorphic public-key encryption algorithm based on the anonymous set public key to obtain the encrypted transaction amount. The encrypted transaction copy is then obtained by encrypting the sender's account index, the receiver's account index, and the transaction amount based on the regulator's public key. A non-interactive zero-knowledge proof is used to generate a proof of transaction validity. Based on the proof of transaction validity, the anonymous set, the encrypted transaction amount, and the encrypted transaction copy, a transaction is generated. The non-interactive zero-knowledge proof is then used to verify that the information encrypted by the three ciphertexts in the encrypted transaction copy is consistent with the transaction information in the encrypted transaction amount vector. For verified transactions, update the encrypted balance of each account in the anonymous set according to the encrypted transaction amount, and obtain transaction information based on the set secret parameters and the encrypted transaction copy.

[0011] As an alternative implementation method, the verification process includes: three ciphertexts being correct, namely, the sender's account corresponding index. ciphertext Index corresponding to the recipient's account ciphertext Transaction amount ciphertext In addition, to ensure that regulatory information is consistent with actual transaction information, the transfer amount is required to be... ; For the regulator's public key; These are vectors of transfer amounts. The index corresponding to the only negative or positive value in the table; , , It is a random number.

[0012] As an alternative implementation, input secret parameters and transactions Analysis Calculate the index corresponding to the sender's account. Index corresponding to the recipient's account and transaction amount Output transaction information ; Proof of the validity of the transaction; An anonymous set, Let be the dense transaction amount vector. The index corresponding to the sender's account Ciphertext, recipient account corresponding index ciphertext and transaction amount The ciphertext, For the sender's public key, For the recipient's public key, This indicates that the initiator's public key and the receiver's public key are related to the first one in the anonymous set. Position and The public key corresponding to the bit.

[0013] As an alternative implementation method, the verification process also includes: Transfer amount conservation: for all All of them have secret transaction amounts Established, and ; Interference with account integrity: Exists Set of sizes ,have For all All are true; Receiver valid: Index exists There is a transfer amount ; Sender is reimbursable: Index exists There is a transfer amount and ; in, These are vectors of transfer amounts. The index corresponding to the only negative or positive value in the table; Indicates whether the sender is transferring out or transferring in the first... The amount in each account, For the anonymous set public key; It is a random number; The sender's private key; For anonymous centralized indexing The encrypted balance of the account; For anonymous centralized indexing The amount of secret transactions.

[0014] As an alternative implementation method, input security parameters ,run , , , Output public parameters and secret parameters ; Enter the initial account balance ,run Output public key and private key According to the public key Initial account balance and random numbers ,calculate As the initial dense state balance; Based on the private key and initial dense state balance ,run The balance is calculated. .

[0015] Thirdly, the present invention provides a privacy-preserving distributed trading system with transparent oversight, comprising: The hidden module is configured to randomly select an anonymous set and map the initiator's account and the receiver's account to the anonymous set; The encryption module is configured to use a homomorphic public-key encryption algorithm to encrypt the transaction amount based on the anonymous set public key to obtain the encrypted transaction amount, and to encrypt the transaction amount based on the regulator's public key to obtain an encrypted transaction copy; The verification module is configured to generate a transaction validity proof using non-interactive zero-knowledge proofs, generate a transaction based on the transaction validity proof, the anonymous set, the encrypted transaction amount, and the encrypted transaction copy, and verify that the encrypted transaction amount and the encrypted transaction copy are the same using non-interactive zero-knowledge proofs. The transaction opening module is configured to update the encrypted balance of each account in the anonymous set based on the encrypted transaction amount for verified transactions, and obtain transaction information based on the set secret parameters and the encrypted transaction copy.

[0016] Fourthly, the present invention provides a privacy-preserving distributed trading system with transparent oversight, comprising: The hidden module is configured to randomly select an anonymous set and map the initiator's account and the receiver's account to the anonymous set; The encryption module is configured to use a homomorphic public key encryption algorithm to encrypt the transaction amount based on the anonymous set public key to obtain the encrypted transaction amount. The encrypted transaction copy is obtained by encrypting the sender's account index, the receiver's account index, and the transaction amount based on the regulator's public key. The verification module is configured to generate a transaction validity proof using non-interactive zero-knowledge proofs. Based on the transaction validity proof, the anonymous set, the encrypted transaction amount, and the encrypted transaction copy, a transaction is generated. The non-interactive zero-knowledge proof is then used to verify that the information encrypted by the three ciphertexts in the encrypted transaction copy is consistent with the transaction information in the encrypted transaction amount vector. The transaction opening module is configured to update the encrypted balance of each account in the anonymous set based on the encrypted transaction amount for verified transactions, and obtain transaction information based on the set secret parameters and the encrypted transaction copy.

[0017] Fifthly, the present invention provides an electronic device including a memory and a processor, and computer instructions stored in the memory and running on the processor, wherein the computer instructions, when executed by the processor, perform the method described in the first aspect.

[0018] In a sixth aspect, the present invention provides a computer-readable storage medium for storing computer instructions, which, when executed by a processor, perform the method described in the first aspect.

[0019] In a seventh aspect, the present invention provides a computer program product, including a computer program that, when executed by a processor, implements the method described in the first aspect.

[0020] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention targets account-based cryptocurrency systems. Based on homomorphic public-key encryption and non-interactive zero-knowledge proofs, it designs a privacy-preserving account-based cryptocurrency system that supports transparent oversight. Two privacy-preserving distributed transaction methods for transparent oversight are proposed. First, the initiator's and receiver's accounts are mapped to an anonymous set to hide the information of both parties. The transaction amount is encrypted using a homomorphic public-key encryption algorithm based on the anonymous set's public key, resulting in a encrypted transaction amount. Then, based on the regulator's public key, the corresponding indices of the sender's and receiver's accounts, as well as the transaction amount, are encrypted to obtain a encrypted transaction copy. Finally, a non-interactive zero-knowledge proof is used to generate a proof of transaction validity. The transaction is then generated by combining the anonymous set, the encrypted transaction amount, and the encrypted transaction copy, and verified using non-interactive zero-knowledge proofs. This ensures the transaction's authenticability, regulatory oversight, and validity, achieving strong privacy protection while also being subject to transparent oversight by regulators, simultaneously satisfying confidentiality and anonymity.

[0021] Advantages of additional aspects of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0023] Figure 1 This is a flowchart of a privacy-preserving distributed transaction method with transparent supervision provided in Embodiment 1 of the present invention; Figure 2 This is a schematic diagram of the transaction data structure provided in Embodiment 1 of the present invention; Figure 3 This is a flowchart of a privacy-preserving distributed transaction method with transparent supervision provided in Embodiment 2 of the present invention; Figure 4 This is a schematic diagram of the transaction data structure provided in Embodiment 2 of the present invention. Detailed Implementation

[0024] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0025] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0026] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of exemplary embodiments of the invention. As used herein, unless the context clearly indicates otherwise, the singular form is intended to include the plural form as well. Furthermore, it should be understood that the terms “comprising” and “including”, and any variations thereof, are intended to cover non-exclusive inclusion, for example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0027] Where there is no conflict, the embodiments and features in the embodiments of the present invention can be combined with each other.

[0028] Example 1 This embodiment focuses on an account-based cryptocurrency system. Based on homomorphic public-key encryption (PKE) and non-interactive zero-knowledge proofs (NIZK), it designs a Supervised Privacy-Preserving Account-Based Cryptocurrencies (SPPABC) system that supports transparent supervision. Figure 1 This illustrates a privacy-preserving distributed transaction method with transparent oversight.

[0029] The design principles of this method include: I. Privacy Protection Mechanism.

[0030] (1) First, when the sender to the recipient Transfer amount The sender first selects -Anonymous Collection , to their own account and recipient account Separately with Anonymous Set The first in and Bit-to-bit correspondence enables the hiding of information between the two parties in a transaction.

[0031] (2) Then, generate the transaction amount vector. ,in, Indicates whether the sender is transferring out or transferring in the first... The amount in each account, It is a negative value. ,the remaining All are 0.

[0032] (3) Finally, the transaction amount vector is encrypted using homomorphic public key encryption (PKE) under the anonymous set public key vector to generate the encrypted transaction amount vector. And use NIZK to prove: (i) the legality of secret-state transactions; (ii) regarding The private key knowledge ensures the verifiability of transactions.

[0033] II. Penetrating supervision mechanism.

[0034] The initiator uses a homomorphic public key to encrypt the PKE and the regulator's public key. For transaction amount vector Encryption is performed to generate a encrypted copy of the transaction. And use NIZK to prove the ciphertext in sequence. With secret transaction amount The encrypted values ​​are identical to ensure the transaction's regulatory compliance.

[0035] The method of this embodiment will be described in detail below.

[0036] Includes 7 polynomial-time algorithms: Initialization algorithm Account generation algorithm Balance query algorithm Transaction generation algorithm Transaction verification algorithm Transaction update algorithm and transaction opening algorithm .

[0037] make This is a homomorphic public-key encryption scheme, which contains four algorithms that together form a complete encryption scheme. It is a general construct, requiring only that this PKE scheme satisfies the homomorphic property. It is a non-interactive zero-knowledge proof about the validity of transactions. As above, these four algorithms form a complete non-interactive zero-knowledge proof system. It is a general construction and can use any general or targeted NIZK (such as the common zkSNARK).

[0038] S1: Initial Setup Algorithm : Input security parameters ,run , , , Output public parameters and secret parameters .

[0039] Fixed public parameters , The algorithm naturally derives as follows: (Non-deterministic Polynomial, a nondeterministic problem with polynomial complexity) Relationship: ; The selected random number; For all key generation algorithms The exported set of public and private key pairs.

[0040] S2: Account Generation Algorithm : Enter the initial account balance ,run Output the user's public key and private key According to the public key Initial account balance and random numbers ,calculate As the initial dense state balance.

[0041] S3: Balance Inquiry Algorithm : Based on the private key and initial dense state balance ,run The balance is calculated. .

[0042] This step allows users to check their account balance and is introduced for the sake of system functionality.

[0043] S4: Transaction Generation Algorithm Input sender key pair Recipient's public key and transaction amount Generate a transaction by following these steps : (1) Use homomorphic public key to encrypt PKE to generate encrypted transaction information ; Specifically, it includes: (i) Randomly select a size of Anonymous collection , will sender and the recipient Each with the first and Bit correspondence.

[0044] (ii) Generate the transfer amount vector ,in, For the sender to transfer out or transfer in the third The amount in each account, It is a negative value. , ,the remaining .

[0045] (iii) Select a random vector Using homomorphic public-key encryption, PKE pairs of transaction amount vectors are encrypted. Based on anonymous set public key Encryption is performed to generate a secret transaction amount vector. Among them, the amount of secret transactions .

[0046] (iv) Select a random vector Use homomorphic public key encryption PKE to verify transaction amounts Based on the regulator's public key Generate a copy of a secret transaction ciphertext .

[0047] (2) Use NIZK to generate transaction validity proofs : Given secret transaction information First, obtain the cryptographic balance of all accounts in the anonymous set. Then run The algorithm proves the following five points: (i) Conservation of transfer amount: for all They all Established, and .

[0048] (ii) Interference with account integrity: exists Set of sizes ,have For all Both are valid.

[0049] (iii) Valid receiver: Index exists ,have .

[0050] (iv) Sender reimbursable: Index exists ,have and .

[0051] (v) Consistent regulatory information: for all They all and Established, and both of them We must be consistent.

[0052] (3) Generate transactions based on transaction validity proof and confidential transaction information. ,in ,like Figure 2 As shown.

[0053] S5: Transaction Validation Algorithm : Enter transaction Analysis Obtain the cryptographic balance of all accounts in the anonymous central repository. ,run Algorithm verification and The transaction is verified by meeting the above five conditions. The effectiveness.

[0054] Understandably, the proof generation algorithm in step S4, which generates the proof of transaction validity, is run by the transaction sender to generate the proof of transaction validity. The transaction verification algorithm in step S5 is run by the verifier to verify the transaction validity. In zero-knowledge proofs, proof generation and proof verification are two distinct stages. Similarly, in a transaction system, generating a transaction requires generating a corresponding proof; verifying a transaction requires verifying the proof.

[0055] S6: Transaction Update Algorithm : Enter the verified transaction Analysis For anonymous sets Each account in Verification nodes update the blockchain The confidential balance of this account , that is to say .

[0056] The purpose of the update is to ensure the integrity of system functions. After a transaction is verified, the relevant accounts need to update their balance information. For example, if A transfers X to B, A's account needs to be reduced by X yuan, and B's account needs to be updated by X yuan.

[0057] S7: Transaction Opening Algorithm : Input secret parameters and transactions Analysis For all ,run Decrypt the transaction amount to obtain the transfer amount vector. Output transaction information ,in They are respectively The index corresponding to the only negative and positive values ​​in the table.

[0058] Example 2 This embodiment designs another privacy-preserving account model cryptocurrency system that supports transparent oversight, and proposes another privacy-preserving distributed transaction method for transparent oversight, such as... Figure 3 As shown.

[0059] In terms of design concept, the privacy protection mechanism of this embodiment is the same as that of the method in Embodiment 1, but the penetration monitoring mechanism is different. The penetration monitoring mechanism of the method in this embodiment is as follows: The transaction initiator uses a homomorphic public key to encrypt the PKE and the regulator's public key. Index of the initiator Receiver Index and transaction amount Encryption is performed to generate a compact, encrypted copy of the transaction. and And use NIZK to prove that the information encrypted by these three ciphertexts is related to the encrypted transaction amount vector. The transaction information contained within is consistent, ensuring the transaction's regulatory oversight.

[0060] Therefore, the initial setting algorithm of the method in this embodiment Account generation algorithm Balance query algorithm Transaction verification algorithm and transaction update algorithm Similar to Example 1, in the transaction generation algorithm And transaction opening algorithm There are differences.

[0061] The specific constructions of these two algorithms are as follows: I. Transaction Generation Algorithm : Input sender key pair Recipient's public key and transfer amount Generate a transaction by following these steps : (1) Use homomorphic public key to encrypt PKE to generate encrypted transaction information : Specifically, it includes: (i) Randomly select a size of Anonymous collection ,Will and Each with the first and Bit correspondence.

[0062] (ii) Generate the transfer amount vector ,in, For the sender to transfer out or transfer in the third The amount in each account, It is a negative value. , ,the remaining .

[0063] (iii) Select a random vector Using homomorphic public-key encryption, PKE pairs of transaction amount vectors are encrypted. Based on anonymous set public key Encryption is performed to generate a secret transaction amount vector. Among them, the amount of secret transactions .

[0064] (iv) Select random numbers Generate an index corresponding to the sender's account. ciphertext Index corresponding to the recipient's account ciphertext and transaction amount ciphertext .

[0065] (2) Use NIZK to generate transaction validity proofs : Given secret transaction information First, obtain the cryptographic balance of all accounts in the anonymous set. Then run The algorithm proves the following five points: (i) Conservation of transfer amount: for all They all Established, and ; (ii) Interference with account integrity: exists Set of sizes ,have For all All are true; (iii) Valid receiver: Index exists ,have ; (iv) Sender reimbursable: Index exists ,have and ; (v) Consistent Regulatory Information: The three ciphertexts are in the correct form (proof needs to be generated to prove that the "form is correct" (i.e., the three ciphertexts were correctly generated)). , , Furthermore, to ensure that regulatory information is consistent with actual transaction information, it is required that... That is, verifying the information encrypted by the three ciphertexts and the encrypted transaction amount vector. The transaction information is consistent.

[0066] (3) Output ,in ,like Figure 4 As shown.

[0067] II. Transaction Opening Algorithm : Input secret parameters and transactions Analysis Calculate the index corresponding to the sender's account. Index corresponding to the recipient's account and transaction amount Output transaction information .

[0068] It should be noted that all data acquisition is conducted in accordance with laws and regulations and with user consent, and the data is used legally.

[0069] Example 3 This embodiment provides a privacy-preserving distributed trading system with transparent oversight, including: The hidden module is configured to randomly select an anonymous set and map the initiator's account and the receiver's account to the anonymous set; The encryption module is configured to use a homomorphic public-key encryption algorithm to encrypt the transaction amount based on the anonymous set public key to obtain the encrypted transaction amount, and to encrypt the transaction amount based on the regulator's public key to obtain an encrypted transaction copy; The verification module is configured to generate a transaction validity proof using non-interactive zero-knowledge proofs, generate a transaction based on the transaction validity proof, the anonymous set, the encrypted transaction amount, and the encrypted transaction copy, and verify that the encrypted transaction amount and the encrypted transaction copy are the same using non-interactive zero-knowledge proofs. The transaction opening module is configured to update the encrypted balance of each account in the anonymous set based on the encrypted transaction amount for verified transactions, and obtain transaction information based on the set secret parameters and the encrypted transaction copy.

[0070] It should be noted that the above modules correspond to the steps described in Embodiment 1, and the examples and application scenarios implemented by the above modules and the corresponding steps are the same, but are not limited to the content disclosed in Embodiment 1. It should also be noted that the above modules, as part of the system, can be executed in a computer system such as a set of computer-executable instructions.

[0071] Example 4 This embodiment provides a privacy-preserving distributed trading system with transparent oversight, including: The hidden module is configured to randomly select an anonymous set and map the initiator's account and the receiver's account to the anonymous set; The encryption module is configured to use a homomorphic public key encryption algorithm to encrypt the transaction amount based on the anonymous set public key to obtain the encrypted transaction amount. The encrypted transaction copy is obtained by encrypting the sender's account index, the receiver's account index, and the transaction amount based on the regulator's public key. The verification module is configured to generate a transaction validity proof using non-interactive zero-knowledge proofs. Based on the transaction validity proof, the anonymous set, the encrypted transaction amount, and the encrypted transaction copy, a transaction is generated. The non-interactive zero-knowledge proof is then used to verify that the information encrypted by the three ciphertexts in the encrypted transaction copy is consistent with the transaction information in the encrypted transaction amount vector. The transaction opening module is configured to update the encrypted balance of each account in the anonymous set based on the encrypted transaction amount for verified transactions, and obtain transaction information based on the set secret parameters and the encrypted transaction copy.

[0072] It should be noted that the above modules correspond to the steps described in Embodiment 2, and the examples and application scenarios implemented by the above modules and corresponding steps are the same, but are not limited to the content disclosed in Embodiment 1. It should also be noted that the above modules, as part of the system, can be executed in a computer system such as a set of computer-executable instructions.

[0073] In further embodiments, the following is also provided: An electronic device includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor, wherein the computer instructions, when executed by the processor, perform the method described in Embodiment 1. For brevity, further details are omitted here.

[0074] It should be understood that in this embodiment, the processor can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0075] Memory may include read-only memory and random access memory, and provides instructions and data to the processor. A portion of memory may also include non-volatile random access memory. For example, memory may also store information about the device type.

[0076] A computer-readable storage medium for storing computer instructions, which, when executed by a processor, perform the method described in Embodiment 1.

[0077] The method in Example 1 can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor. The software modules can reside in readily available storage media in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, a detailed description is not provided here.

[0078] A computer program product includes a computer program that, when executed by a processor, implements the method described in Embodiment 1.

[0079] The present invention also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as instructions included in program modules, which execute in a device on a target real or virtual processor to perform the processes / methods described above. Typically, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., that perform specific tasks or implement specific abstract data types. In various embodiments, the functionality of program modules can be combined or divided among program modules as needed. The machine-executable instructions for the program modules can execute within a local or distributed device. In a distributed device, the program modules can reside in both local and remote storage media.

[0080] The computer program code used to implement the methods of the present invention may be written in one or more programming languages. This computer program code may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the computer or other programmable data processing device, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a computer, partially on a computer, as a stand-alone software package, partially on a computer and partially on a remote computer, or entirely on a remote computer or server.

[0081] In the context of this invention, computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, and the like. Examples of signals may include electrical, optical, radio, sound, or other forms of propagation signals, such as carrier waves, infrared signals, etc.

[0082] Those skilled in the art will recognize that the units and algorithm steps described in conjunction with the embodiments herein can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0083] While the specific embodiments of the present invention have been described above in conjunction with the accompanying drawings, this is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solutions of the present invention are still within the scope of protection of the present invention.

Claims

1. A privacy-preserving distributed transaction method with transparent oversight, characterized in that, include: Randomly select an anonymous set and associate the initiator's account and the receiver's account with the anonymous set; The transaction amount is encrypted using a homomorphic public-key encryption algorithm based on the anonymous set public key to obtain the encrypted transaction amount. The transaction amount is then encrypted using the regulator's public key to obtain an encrypted transaction copy. A transaction validity proof is generated using non-interactive zero-knowledge proofs. Based on the transaction validity proof, the anonymous set, the encrypted transaction amount, and the encrypted transaction copy, a transaction is generated. Non-interactive zero-knowledge proofs are then used to verify that the encrypted values ​​of the encrypted transaction amount and the encrypted transaction copy are the same. For verified transactions, update the encrypted balance of each account in the anonymous set according to the encrypted transaction amount, and obtain transaction information based on the set secret parameters and the encrypted transaction copy.

2. The privacy-preserving distributed transaction method with transparent supervision as described in claim 1, characterized in that, The verification process includes: for all All of them have secret transaction amounts And ciphertext Established; Indicates whether the sender is transferring out or transferring in the first... The amount in each account, For the anonymous set public key; , It is a random number; This is the public key for the regulator.

3. The privacy-preserving distributed transaction method with transparent supervision as described in claim 1, characterized in that, Input secret parameters and transactions Analysis For all ,run Obtain the vector of transfer amount Output transaction information ,in They are respectively The index corresponding to the only negative or positive value in the table; Proof of the validity of the transaction; An anonymous set, Let be the dense transaction amount vector. For a copy of a confidential transaction, for The ciphertext in Indicates whether the sender is transferring out or transferring in the first... The amount in each account, For the sender's public key, For the recipient's public key, This indicates that the initiator's public key and the receiver's public key are related to the first one in the anonymous set. Position and The public key corresponding to the bit.

4. A privacy-preserving distributed transaction method with transparent oversight, characterized in that, include: Randomly select an anonymous set and associate the initiator's account and the receiver's account with the anonymous set; The transaction amount is encrypted using a homomorphic public-key encryption algorithm based on the anonymous set public key to obtain the encrypted transaction amount. The encrypted transaction copy is then obtained by encrypting the sender's account index, the receiver's account index, and the transaction amount based on the regulator's public key. A non-interactive zero-knowledge proof is used to generate a proof of transaction validity. Based on the proof of transaction validity, the anonymous set, the encrypted transaction amount, and the encrypted transaction copy, a transaction is generated. The non-interactive zero-knowledge proof is then used to verify that the information encrypted by the three ciphertexts in the encrypted transaction copy is consistent with the transaction information in the encrypted transaction amount vector. For verified transactions, update the encrypted balance of each account in the anonymous set according to the encrypted transaction amount, and obtain transaction information based on the set secret parameters and the encrypted transaction copy.

5. The privacy-preserving distributed transaction method with transparent supervision as described in claim 4, characterized in that, The verification process includes: three ciphertexts being correct, namely the sender's account corresponding index. ciphertext Index corresponding to the recipient's account ciphertext Transaction amount ciphertext In addition, to ensure that regulatory information is consistent with actual transaction information, the transfer amount is required to be... ; For the regulator's public key; These are vectors of transfer amounts. The index corresponding to the only negative or positive value in the table; , , It is a random number.

6. The privacy-preserving distributed transaction method with transparent supervision as described in claim 4, characterized in that, Input secret parameters and transactions Analysis Calculate the index corresponding to the sender's account. Index corresponding to the recipient's account and transaction amount Output transaction information ; Proof of the validity of the transaction; An anonymous set, Let be the dense transaction amount vector. The index corresponding to the sender's account Ciphertext, recipient account corresponding index ciphertext and transaction amount The ciphertext, For the sender's public key, For the recipient's public key, This indicates that the initiator's public key and the receiver's public key are related to the first one in the anonymous set. Position and The public key corresponding to the bit.

7. A privacy-preserving distributed transaction method with transparent oversight as described in any one of claims 1 or 4, characterized in that, The verification process also includes: Transfer amount conservation: for all All of them have secret transaction amounts Established, and ; Interference with account integrity: Exists Set of sizes ,have For all All are true; Receiver valid: Index exists There is a transfer amount ; Sender is reimbursable: Index exists There is a transfer amount and ; in, These are vectors of transfer amounts. The index corresponding to the only negative or positive value in the table; Indicates whether the sender is transferring out or transferring in the first... The amount in each account, For the anonymous set public key; It is a random number; The sender's private key; For anonymous centralized indexing The encrypted balance of the account; For anonymous centralized indexing The amount of secret transactions.

8. A privacy-preserving distributed transaction method with transparent oversight as described in any one of claims 1 or 4, characterized in that, Input security parameters ,run , , , Output public parameters and secret parameters ; Enter the initial account balance ,run Output public key and private key According to the public key Initial account balance and random numbers ,calculate As the initial dense state balance; Based on the private key and initial dense state balance ,run The balance is calculated. .

9. A privacy-preserving distributed trading system with transparent oversight, characterized in that, include: The hidden module is configured to randomly select an anonymous set and map the initiator's account and the receiver's account to the anonymous set; The encryption module is configured to use a homomorphic public-key encryption algorithm to encrypt the transaction amount based on the anonymous set public key to obtain the encrypted transaction amount, and to encrypt the transaction amount based on the regulator's public key to obtain an encrypted transaction copy; The verification module is configured to generate a transaction validity proof using non-interactive zero-knowledge proofs, generate a transaction based on the transaction validity proof, the anonymous set, the encrypted transaction amount, and the encrypted transaction copy, and verify that the encrypted transaction amount and the encrypted transaction copy are the same using non-interactive zero-knowledge proofs. The transaction opening module is configured to update the encrypted balance of each account in the anonymous set based on the encrypted transaction amount for verified transactions, and obtain transaction information based on the set secret parameters and the encrypted transaction copy.

10. A privacy-preserving distributed trading system with transparent oversight, characterized in that, include: The hidden module is configured to randomly select an anonymous set and map the initiator's account and the receiver's account to the anonymous set; The encryption module is configured to use a homomorphic public key encryption algorithm to encrypt the transaction amount based on the anonymous set public key to obtain the encrypted transaction amount. The encrypted transaction copy is obtained by encrypting the sender's account index, the receiver's account index, and the transaction amount based on the regulator's public key. The verification module is configured to generate a transaction validity proof using non-interactive zero-knowledge proofs. Based on the transaction validity proof, the anonymous set, the encrypted transaction amount, and the encrypted transaction copy, a transaction is generated. The non-interactive zero-knowledge proof is then used to verify that the information encrypted by the three ciphertexts in the encrypted transaction copy is consistent with the transaction information in the encrypted transaction amount vector. The transaction opening module is configured to update the encrypted balance of each account in the anonymous set based on the encrypted transaction amount for verified transactions, and obtain transaction information based on the set secret parameters and the encrypted transaction copy.