Concise non-interactive zero-knowledge proof generation method based on distributed calculation
By employing distributed computing-based multinomial commitment and verification techniques, the high computational cost and security issues associated with zkSNARK proof generation are resolved, achieving efficient and secure distributed zkSNARK generation, which is applicable to the field of information security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANGHAI JIAOTONG UNIV
- Filing Date
- 2026-02-09
- Publication Date
- 2026-05-15
AI Technical Summary
Existing concise non-interactive zero-knowledge proof protocols (zkSNARK) have high computational costs and large memory overhead when generating proofs, and their reliance on trusted third-party initialization and cryptographic assumptions that are not resistant to quantum attacks are insecure, hindering their widespread application.
A distributed computing approach is used to perform multinomial commitment, summation test, zero test, fractional summation test, elemental reset test, and permutation test. Combined with the Fiat-Shamir transformation, distributed zkSNARK generation is achieved, eliminating the need for trusted initialization and possessing quantum-resistant security.
It significantly improves the proof generation speed and reduces the communication volume. The time and communication volume for generating proofs are only on the order of logarithmic polynomials, improving efficiency by 15.4 to 15.6 times, while also providing security and scalability.
Smart Images

Figure CN122053082A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a technology in the field of information security, specifically a concise, non-interactive zero-knowledge proof generation method based on distributed computing. Background Technology
[0002] The efficiency and security issues of existing concise non-interactive zero-knowledge proof protocols (zkSNARKs) hinder their widespread adoption. One major problem is that as the size of the claims to be proven increases, the computational and memory costs of generating proofs become enormous, especially with multiplication on elliptic curve groups and Fast Fourier Transforms on large-scale polynomials. Furthermore, these protocols typically require the proof-witness relationship to be converted into an arithmetic circuit at the outset, relying on a trusted third party to initialize the circuit, thus placing demands on the trustworthiness of the participants in practical applications. Thirdly, with the continuous advancement of quantum computing technology, many zkSNARKs constructed based on elliptic curve and bilinear pairing techniques become insecure due to their reliance on cryptographic assumptions that are not resistant to quantum attacks. Summary of the Invention
[0003] To address the aforementioned shortcomings of existing technologies, this invention proposes a concise, non-interactive zero-knowledge proof generation method based on distributed computing. This method supports distributed zkSNARK using general-purpose arithmetic circuits (without requiring special structures). It can significantly improve the speed of zkSNARK proof generation through distributed computing while eliminating the need for trusted initialization settings and taking into account potential quantum-resistant security. Moreover, the distributed system requires only logarithmic polynomial-level communication to generate proofs.
[0004] This invention is achieved through the following technical solution:
[0005] This invention relates to a concise, non-interactive zero-knowledge proof generation method based on distributed computing, which involves performing ① distributed zero-test and ② distributed permutation test respectively. The system employs a meta-distributed reset test and a distributed fractional summation test. The results of these two tests are then subjected to a distributed summation test before a distributed multinomial commitment is made to achieve secure authentication.
[0006] The aforementioned distributed polynomial commitment refers to: for a finite field Multiple linear polynomials on The committer obtains its commitment through distributed computing. And hand it over to the other party, so that the latter can do so without knowing... Ask the promisor for specific information. At a random point function value at .
[0007] The distributed computing methods mentioned include: setting algorithm, commitment algorithm, opening algorithm and evaluation protocol.
[0008] The setting algorithm selects one - Linear code, determine its corresponding generator matrix Then, a diagonal matrix with all non-zero diagonal elements is selected uniformly and randomly. And calculate in sequence ,satisfy ,in ,and .
[0009] The commitment algorithm described will coefficient Equal intervals are divided into By each sub-prover get And obtain Merkle tree roots That is, given a length of After obtaining the vector, hash the adjacent two elements to get the vector of length . The vector is used to iterate through the tree to obtain a single element, the root. This is proven by the sub-prover. Collect Then send it to .
[0010] The opening algorithm mentioned refers to: input Post-verification With commitment value Are they equal?
[0011] The evaluation protocol mentioned above refers to: the prover Need to be verified I don't know a certain polynomial The specific structure is the proof At some point The value on .to this end, Call the commitment algorithm to obtain And sent to Then, perform the following operations:
[0012] i) Define the polynomial , calculate And sent to , verify In the first wheel, Uniform random selection And sent to . calculate And sent to examine .when hour, The computation and subsequent interaction are by Alone and Finish.
[0013] ii) From the above interaction up to the first At the start of the round, each child prover... The calculation obtained in the previous commitment algorithm In the In the round, for all subscripts Calculate linear polynomials ,in: Represents a diagonal matrix of The element at position, express Subscript The element at that location, Indicates that and After the linear polynomial is established, set up And calculate .at last Collected And sent to .
[0014] iii) Obtain back, for For each All are randomly selected from a single index. And sent to the child prover ,ask , and After obtaining the value, interpolation is performed. And verify whether it is true. . iv) according to Compared with the previously selected random number ,from arrive ,for Updated sequentially Then, verify whether it is true. .
[0015] The distributed summation test mentioned above refers to: given ,prove exist Wieburg The sum of the values on is a certain claimed value. Therefore, the prover First, the commitment algorithm in distributed multinomial commitment is used to calculate... promise Send to verifier Then each of the sub-proof-provers Based on its own number Determine its Bit binary , making Then, proceed as follows: Wheel interaction:
[0016] i) in the Wheel, all child provers calculate Then sent to the host . After receiving the polynomial, summing it yields... And send to the verifier . verify And whether it is valid If true, then select uniformly and randomly. And sent to The latter passed it on to the rest .
[0017] ii) in the Wheel, all child provers calculate By host Collect and calculate this round Then sent to the verifier . verify And whether it is valid If true, then select uniformly and randomly. And sent to The latter passed it on to the rest .
[0018] iii) in the Wheels, main engine calculate And send to the verifier . verify And whether it is valid If true, then select uniformly and randomly. And sent to .
[0019] iv) In the final round, the host calculate And send to the verifier . verify And whether it is valid If true, then select uniformly and randomly. And invoke the evaluation protocol in the distributed polynomial commitment to prove the... Inquire about commitment At point value at Then, confirm whether it is equal to .
[0020] v) When the above verifier If all verifications pass, then it is accepted. Otherwise, we will refuse.
[0021] The distributed zero check mentioned above refers to: given ,prove exist The value of is zero everywhere. Therefore, the prover... First, the commitment algorithm in distributed multinomial commitment is used to calculate... promise Send to verifier Then by Select random points And send to Then distributed to all Then, a distributed summation check is invoked to prove it. exist The sum of the values on the given surface is 0.
[0022] The distributed fractional summation test refers to: given ,prove exist The sum of the values on is a certain claimed value. Therefore, the prover First, the commitment is calculated using the commitment algorithm in distributed multinomial commitment. , Send to the verifier And calculate the following polynomials in sequence:
[0023] i) For ,calculate Make , Similarly, calculate... .
[0024] ii) For ,calculate , so that for any , , .
[0025] iii) in the Wheel, Proof send For the verifier . Verify whether it is true If true, then select uniformly and randomly. And send to .
[0026] iv) in the Wheel, Verifier Select evenly and randomly And send to . calculate and the verifier Calling distributed summation verification to prove exist The sum of the evaluations on is Let the randomness used in the above summation test be denoted as . In the final round, by Send directly , , Give To complete the test. If true, then select uniformly and randomly. And send to .
[0027] v) in the Wheel, Verifier Select evenly and randomly And send to After the latter forwards it to all child provers, the prover... calculate and the verifier Calling distributed summation verification to prove exist The sum of the evaluations on is Let the randomness used in the above summation test be denoted as . In the final round, by Send directly , , Give To complete the test. If true, then select uniformly and randomly. And send to .
[0028] vi) Verifier Select evenly and randomly And send to The latter forwards the proof to all child provers and then invokes a distributed summation check to prove it. exist The sum of the values above is .
[0029] The aforementioned Meta-distributed reset test refers to: given ,prove Therefore, the prover First, the distributed multinomial commitment scheme is used to calculate... Send to verifier Uniformly and randomly selected And sent to The latter then forwards the message to all child provers. Calculate two polynomials and Then, calculate and Then call the distributed summation verification to prove it. exist The sum of the values on it is 0.
[0030] The distributed permutation test mentioned above refers to: given With replacement Prove that for any All Therefore, the initializer according to calculate ,make will any Mapped to its corresponding integer will any Mapped to Corresponding integer Calling the polynomial commitment calculation and ,Will Send to the witness ,Will Send to verifier Finally, the binary distributed reset test is invoked to prove... .
[0031] The Fiat-Shamir transformation refers to the following: For most zero-knowledge proof scenarios, in any round of an interactive model, the random value that should be chosen by the verifier can be replaced by the hash value output by the prover using a public hash function after inputting all the content up to this round, thereby transforming the interactive model into a non-interactive one. Technical effect
[0032] Compared to existing zkSNARK methods for generating proofs of large-scale arguments, this invention features original methods for multinomial commitments, summation tests, zero tests, and fractional summation tests. The distributed computing techniques used for meta-reset testing and permutation testing, combined into a distributed zkSNARK, can efficiently generate proofs for arbitrary arithmetic circuits without relying on trusted third-party initialization and with potential resistance to quantum attacks. Specifically, 16 distributed machines are used to process a scale of... The time required to generate the proof using the random arithmetic circuit is 2.51 seconds, which is 15.4 times faster than the non-distributed case (38.6 seconds); when the scale is further increased to The time required is 20.5 seconds, which is 15.6 times faster than the non-distributed 319 seconds. Attached Figure Description
[0033] Figure 1 This is a flowchart of the present invention;
[0034] Figure 2 This is a flowchart of an example implementation. Detailed Implementation
[0035] like Figure 1 As shown, this embodiment relates to a concise non-interactive zero-knowledge proof generation method based on distributed computing, which involves performing ① distributed zero-test and ② distributed permutation test respectively. The results of the two tests are then subjected to a distributed summation test and a distributed polynomial commitment.
[0036] like Figure 2 As shown, this embodiment specifically includes:
[0037] In such Figure 2 The scale shown is the size after the transformation of the assertion-witness relationship. Arithmetic circuits The initializer of the public processing circuit , Proofers composed of distributed machines and validators Implementation in various scenarios, including:
[0038] Step 1, Initialization Phase: Circuit Initializer Received arithmetic circuit Then, the proof parameters are generated openly and transparently. With verification parameters Specifically: the initializer According to arithmetic circuits The structure determines four polynomials , respectively representing the first Is the nth gate an addition gate, multiplication gate, input gate, or output gate (e.g., if the nth gate is an addition gate, multiplication gate, input gate, or output gate)? If each circuit gate is an adder gate, then (Otherwise, it is 0) and these four polynomials are collected into In the middle, satisfy , ;at the same time, Determine one On the substitution As a circuit The connection method of internal wiring. Specifically, if we remember... Circuit representation The values of each gate, i.e. , and They represent The Middle The left input, right input, and output of each gate are then... satisfy ).
[0039] Step 2, Initializer Calling the initializer in the distributed permutation verification protocol ,get and Related commitments , , Then, respectively Send to the witness ,Will , , Send to verifier .
[0040] Step 3, Witness With the validator Each finds Representing vectorized arguments . Additional calculations to find the satisfying Witness and use This indicates that, makes , and They represent the first in the circuit. The left input, right input, and output of each gate. After that, The commitment algorithm in distributed multinomial commitment is called to calculate promise And sent to .
[0041] Step 4 For polynomials Invoke the distributed zero-check protocol to prove its validity. The sum of the values on is 0. Specifically, this includes: the prover. First, the commitment algorithm in distributed multinomial commitment is used to calculate... promise Send to verifier Then by Select random points And send to Then distributed to all Then, a distributed summation check is invoked to prove it. exist The sum of the values on the given surface is 0.
[0042] Step 5 right Proof by calling the distributed permutation verification protocol .
[0043] Step 6 Select random points Invoke the distributed multinomial commitment scheme to query At point The value on And check if its value is equal to .
[0044] Through specific practical experiments, the aforementioned distributed zkSNARK was implemented using Rust and deployed in a local area network environment using an Ubuntu 24.04 operating system, a c7n.16xlarge.4 instance, 64 vCPUs, and 256GB of memory server provided by Alibaba Cloud. The scaled-up circuits were tested progressively using 1, 2, 4, 8, and 16 machines, and compared with a non-distributed scenario (using a single machine). Evaluation metrics included proof generation time, communication throughput, proof size, and verification time.
[0045] As shown in Table 1, in the experimental environment, 8 machines were used to respectively... When generating proofs using arithmetic circuits of a certain scale, the distributed zkSNARK proof generation time of this invention is improved by 8.08 times, 8.27 times, 8.11 times, and 7.10 times compared to the non-distributed method. When using 16 machines, the efficiency improvement further reaches 15.4 times, 15.2 times, 16.3 times, and 15.6 times, consistent with the expected linear increase in efficiency with the number of machines. Furthermore, when using a fixed number of 16 machines, [the following is a more detailed description of the improvements]. The communication volume generated during the arithmetic circuit generation proof process of the scale was 166MB, 187MB, 211MB and 237MB respectively, and its growth rate was much lower than linear, only on the order of logarithmic polynomials.
[0046] Table 1
[0047] Compared with existing technologies, this invention performs a bottom-up distributed design of each module in the zkSNARK proof generation process according to its internal dependencies, resulting in distributed multinomial commitments, distributed summation checks, distributed zero checks, and distributed fractional summation checks. The distributed zkSNARK combines meta-distributed reset checks and distributed permutation checks. The resulting distributed zkSNARK not only exhibits a linear increase in proof generation efficiency with the number of distributed machines, but also generates proofs with only logarithmic-polynomial-level communication while eliminating the need for trusted initialization settings and ensuring potential quantum resistance, demonstrating good scalability and security.
[0048] The above-described specific implementations can be partially adjusted by those skilled in the art in different ways without departing from the principles and purpose of the present invention. The scope of protection of the present invention is defined by the claims and is not limited to the above-described specific implementations. All implementation schemes within the scope of the claims are bound by the present invention.
Claims
1. A distributed, concise, non-interactive zero-knowledge proof method, characterized in that, By performing ① distributed zero test and ② distributed permutation test respectively, The system employs a meta-distributed reset test and a distributed fractional summation test. The results of these two tests are then subjected to a distributed summation test before a distributed multinomial commitment is made to achieve secure authentication.
2. The distributed, concise, non-interactive zero-knowledge proof method according to claim 1, characterized in that, The aforementioned distributed polynomial commitment refers to: for a finite field Multiple linear polynomials on The committer obtains its commitment through distributed computing. And then handed it over to the other party, so that the latter would not know... Ask the promisor for specific information. At a random point function value at ; The distributed computing methods mentioned include: setting algorithm, commitment algorithm, opening algorithm and evaluation protocol.
3. The distributed, concise, non-interactive zero-knowledge proof method according to claim 2, characterized in that, The setting algorithm selects one - Linear code, determine its corresponding generator matrix Then, a diagonal matrix with all non-zero diagonal elements is selected uniformly and randomly. And calculate in sequence ,satisfy ,in ,and ; The commitment algorithm described will coefficient Equal intervals are divided into By each sub-prover get And obtain Merkle tree roots That is, until the fixed length is After obtaining the vector, hash the adjacent two elements to get the vector of length . The vector, in this loop, yields a single element, the root of the tree, which is proven by the sub-prover. Collect Then send it to ; The opening algorithm mentioned refers to: input Post-verification With commitment value Are they equal? The evaluation protocol mentioned above refers to: the prover Need to be verified I don't know a certain polynomial The specific structure is the proof At some point The value on Call the commitment algorithm to obtain And sent to Then, perform the following operations: i) Define the polynomial , calculate And sent to , verify In the wheel, Uniform random selection And sent to calculate And sent to examine ,when hour, The computation and subsequent interaction are by Alone and Finish; ii) From the above interaction up to the first At the start of the round, each child prover... The calculation obtained in the previous commitment algorithm In the In the round, for all subscripts Calculate linear polynomials ,in: Represents a diagonal matrix of The element at position, express Subscript The element at that location, Indicates that and After the linear polynomial is established, set up And calculate ,at last Collected And sent to ; iii) Obtain back, for For each All are randomly selected from a single index. And sent to the child prover ,ask , and After obtaining the value, interpolation is performed. And verify whether it is true. ; iv) according to Compared with the previously selected random number ,from arrive ,for Updated sequentially Then, verify whether it is true. .
4. The distributed, concise, non-interactive zero-knowledge proof method according to claim 1, characterized in that, The aforementioned distributed summation test refers to: until a certain value is reached. ,prove exist Wieburg The sum of the values on is a certain claimed value. Afterwards, the witness First, the commitment algorithm in distributed multinomial commitment is used to calculate... promise Send to verifier Then each of the sub-proof-provers Based on its own number Determine its Bit binary , making Then, proceed as follows: Wheel interaction: i) in the Wheel, all child provers calculate Then sent to the host After receiving the polynomial, summing it yields... And send to the verifier verify And whether it is valid If true, then select uniformly and randomly. And sent to The latter passed it on to the rest ; ii) in the Wheel, all child provers calculate By host Collect and calculate this round Then sent to the verifier verify And whether it is valid If true, then select uniformly and randomly. And sent to The latter passed it on to the rest ; iii) in the Wheels, main engine calculate And send to the verifier verify And whether it is valid If true, then select uniformly and randomly. And sent to ; iv) In the final round, the host calculate And send to the verifier verify And whether it is valid If true, then select uniformly and randomly. And invoke the evaluation protocol in the distributed polynomial commitment to prove the... Inquire about commitment At point value at Then, confirm whether it is equal to ; v) When the above verifier If all verifications pass, then it is accepted. Otherwise, we will refuse.
5. The distributed, concise, non-interactive zero-knowledge proof method according to claim 1, characterized in that, The aforementioned distributed zero-check refers to: until the end ,prove exist After the value of is zero everywhere, the prover First, the commitment algorithm in distributed multinomial commitment is used to calculate... promise Send to verifier Then by Select random points And sent to And then distributed to all Then, a distributed summation check is invoked to prove it. exist The sum of the values on the given surface is 0.
6. The distributed, concise, non-interactive zero-knowledge proof method according to claim 1, characterized in that, The aforementioned distributed fractional summation test refers to: until a certain value is reached. ,prove exist The sum of the values on is a certain claimed value. Afterwards, the witness First, the commitment is calculated using the commitment algorithm in distributed multinomial commitment. , Send to verifier And calculate the following polynomials in sequence: i) For ,calculate Make , Similarly, calculate ; ii) For ,calculate , so that for any , , ; iii) in the Wheel, Proof send To the verifier Verify whether it is true If true, then select uniformly and randomly. And sent to ; iv) in the Wheel, Verifier Select evenly and randomly And sent to calculate and the verifier Calling distributed summation verification to prove exist The sum of the evaluations on is The randomness used in the summation test is... In the final round, by Send directly , , To complete the test, if the result is valid, then select uniformly and randomly. And sent to ; v) in the Wheel, Verifier Select evenly and randomly And sent to After the latter forwards to all child provers, the prover... calculate and the verifier Calling distributed summation verification to prove exist The sum of the evaluations on is The randomness used in the summation test is... In the final round, by Send directly , , To complete the test, if the result is valid, then select uniformly and randomly. And sent to ; vi) Verifier Select evenly and randomly And sent to The latter forwards the proof to all child provers and then invokes a distributed summation check to prove it. exist The sum of the values above is .
7. The distributed, concise, non-interactive zero-knowledge proof method according to claim 1, characterized in that, The aforementioned Meta-distributed reset testing refers to: until fixed ,prove Afterwards, the witness First, the distributed multinomial commitment scheme is used to calculate... Send to verifier Uniformly and randomly selected And sent to The latter forwards the message to all child provers, who in turn forward it to all child provers. Calculate two polynomials and Then, calculate and Then call the distributed summation verification to prove it. exist The sum of the values on it is 0.
8. The distributed, concise, non-interactive zero-knowledge proof method according to claim 1, characterized in that, The distributed permutation test mentioned above refers to: until the end of time With replacement Prove that for any All Afterwards, the initializer according to calculate ,make will any Mapped to its corresponding integer will any Mapped to Corresponding integer Calling the polynomial commitment calculation and ,Will Send to the witness ,Will Send to verifier Finally, the binary distributed reset test is invoked to prove... .
9. The distributed, concise, non-interactive zero-knowledge proof method according to claim 1, characterized in that, The Fiat-Shamir transformation refers to the following: For most zero-knowledge proof scenarios, in any round of an interactive model, the random value that should have been chosen by the verifier is replaced by the hash value output by the prover using a public hash function after inputting all the content up to this round, thereby transforming the interactive model into a non-interactive one.
10. The distributed, concise, non-interactive zero-knowledge proof method according to any one of claims 1-9, characterized in that, specifically... include: Step 1, Initializer According to arithmetic circuits The structure determines four polynomials , respectively representing the first Is the nth gate an addition gate, multiplication gate, input gate, or output gate (e.g., if the nth gate is an addition gate, multiplication gate, input gate, or output gate)? If each circuit gate is an adder gate, then (Otherwise, it is 0) and these four polynomials are collected into In the middle, satisfy , ;at the same time, Determine one On the substitution As a circuit The internal wiring connection method, specifically, if remember Circuit representation The values of each gate, i.e. , and They represent The Middle The left input, right input, and output of each gate are then... satisfy ), Step 2, Initializer Calling the initializer in the distributed permutation verification protocol ,get and Related commitments , , Then, respectively Send to the witness ,Will , , Send to verifier ; Step 3, Witness With the validator Each finds Representing vectorized arguments Additional calculations to find the satisfying Witness and use This indicates that, makes , and They represent the first in the circuit. The left input, right input, and output of each gate, and then... The commitment algorithm in distributed multinomial commitment is called to calculate promise And sent to ; Step 4 For polynomials Invoke the distributed zero-check protocol to prove its validity. The sum of the values on is 0, specifically including: the prover First, the commitment algorithm in distributed multinomial commitment is used to calculate... promise Send to verifier Then by Select random points And sent to And then distributed to all Then, a distributed summation check is invoked to prove it. exist The sum of the values on the interval is 0; Step 5 right Proof by calling the distributed permutation verification protocol ; Step 6 Select random points Invoke the distributed multinomial commitment scheme to query At point The value on And check if its value is equal to .