Zero-Knowledge Proof Method, Apparatus, and System for Polylicit Syntax
The proposed zero-knowledge proof method addresses the limitations of existing technologies by decomposing statements, generating garbled circuits, and using oblivious transfer for efficient verification of complex statements with multiple variables, achieving strong privacy and reduced computational overhead.
Patent Information
- Application Number
- JP2024500211
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-07-06
- Filing Date
- 2022-07-06
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-07-06
AI Technical Summary
Existing zero-knowledge proof technologies are limited to monolithic states, allowing only single arguments at a time, and suffer from significant computational overhead due to repeated executions required to achieve negligible soundness error.
The method involves policy syntax decomposition of a statement to be proved, generating a garbled circuit, dividing it into parts, and transmitting these parts to multiple verifiers for joint calculation and verification, utilizing techniques like oblivious transfer and multi-party non-interactive lossy transfer.
This approach enables efficient verification of complex statements with multiple variables while maintaining strong privacy guarantees and reducing computational overhead, facilitating applications in secure information exchange and blockchain technology.
Smart Images

Figure 0007684506000077 
Figure 0007684506000078 
Figure 0007684506000079
Abstract
Description
Technical Field
[0001] The present invention generally relates to the field of secure information exchange and cryptographic computing, and more particularly to zero-knowledge proofs in computerized communication systems.
Background Art
[0002] Zero-knowledge proof, also called zero-knowledge protocol, is a protocol in which one party (the prover) can prove (or demonstrate) to another party (the verifier) that a certain statement is true without revealing any information beyond the validity of the statement itself. For example, when given a hash of a random number, the prover can use zero-knowledge proof to convince the verifier that the prover actually owns (or knows) the random number. In particular, without revealing what the number is, the prover can construct a proof system that, when implemented, persuasively leads the verifier to conclude that the prover owns or knows the number. Ideally, zero-knowledge proof convinces the verifier of a statement while revealing nothing other than the validity of the statement itself.
[0003] Since its introduction by Goldwasser, Micali, and Rackoff, zero-knowledge (ZK) proof has found applications in various areas such as user or device authentication, as well as signature schemes, private computing, and new shielded transactions in blockchain technology. Zero-knowledge proof has various applications in, for example, cryptographic and secure communication between electronic devices.
[0004] Two examples of zero-knowledge technologies are zk-SNARK and zkBoo. Such technologies can be used to bring new versatile functions to the infrastructure of existing communication and computing networks. When such a technology is used and an interactive proof for any NP-complete problem is given, a device can construct a zero-knowledge proof or argument for any NP statement. An NP statement is a statement associated with an NP-complete problem, and a prover attempts to prove through a zero-knowledge proof scheme that this is true (or false). However, existing zero-knowledge technologies are limited to a monolithic state. That is, the target NP statement is restricted to contain only one argument at a time. Another limitation of existing zero-knowledge technologies is that the computational overhead is significantly large and there is room for improvement. This is because, for example, in such technologies, in order to achieve an acceptably small (e.g., negligible) soundness error, many repeated executions (e.g., many repetitions of finding the arithmetic root of a polynomial, etc.) are often required. Soundness error refers to the property that when an NP statement is false, except for an acceptably small probability, a prover cannot mislead a verifier into believing that the NP statement is true.
[0005] Therefore, there is a need for methods, apparatuses, and systems for secure information exchange that include zero-knowledge proofs to avoid or mitigate one or more limitations in the prior art.
[0006] This background information is provided for the purpose of providing information that may be relevant to the present disclosure. It is not necessarily intended to recognize, nor should it be construed to recognize, that any of the foregoing information constitutes prior art to the present disclosure.
Summary of the Invention
[0007] Embodiments of the present disclosure provide a zero - knowledge proof method, apparatus, and system. In particular, the embodiments present a policy syntax function and the property of consistency verification. Embodiments of the present disclosure can be applied to secure information exchange, cryptography, user authentication or device authentication, secure computing, blockchain, or other computing technologies or communication technologies.
[0008] According to an embodiment of the present disclosure, a method for performing zero - knowledge proof is provided. The method includes a step of performing policy syntax decomposition on a statement to be proved by a prover. The method further includes a step of generating a garbled circuit representing the statement after policy syntax decomposition by the prover. The method further includes a step of dividing the garbled circuit into a plurality of garbled circuit parts that collectively form the divided garbled circuit by the prover. The method further includes a step of transmitting the divided garbled circuit to a plurality of verifiers via a shared repository by the prover. The method further includes a step of jointly calculating a digest of the garbled circuit by a plurality of verifiers, wherein each of the plurality of verifiers calculates an output of a corresponding one of the plurality of garbled circuit parts. The method further includes a step of calculating a value of a unified Boolean operation that is collectively applied to all of the aforementioned outputs in the plurality of garbled circuit parts by an aggregator belonging to the plurality of verifiers. The method further includes a step of determining by the aggregator whether the value of the unified Boolean operation is equal to an expected value, and indicating that the proof is verified only if the value of the unified Boolean operation is equal to the expected value.
[0009] In some embodiments, the statement has a plurality of phases or variables, and the policy syntax decomposition includes generating a Boolean circuit representation of the statement using a plurality of wires and a plurality of gates. The garbled circuit in such embodiments is generated from the Boolean circuit representation.
[0010] In some embodiments, the method further includes converting the statement into one or more regular expressions and generating a Boolean circuit representation from the regular expression. The obfuscated circuit is generated directly or indirectly from the Boolean circuit representation. In some further embodiments, the method further includes performing a Karnaugh Map operation on the Boolean circuit representation to generate a simplified version of the Boolean circuit representation. In such further embodiments, the obfuscated circuit is generated directly or indirectly from the simplified version of the Boolean circuit representation.
[0011] In some embodiments, the step of sending the split obfuscated circuit to a plurality of verifiers is performed using oblivious transfer.
[0012] In some embodiments, the method further includes performing a multi-party oblivious transfer scheme to facilitate the interaction between the prover and the verifiers, the interaction between the verifiers, or both.
[0013] According to one embodiment of the present disclosure, there is provided an apparatus comprising a processor operably coupled to a memory and configured to execute the method as described above by execution of program instructions stored in the memory by the processor.
[0014] According to one embodiment of the present disclosure, there is provided a system comprising a plurality of computing devices, the computing devices being cooperatively configured to execute the method as described above.
[0015] According to one embodiment of the present disclosure, there is provided a computer program product comprising a non-transitory computer-readable medium having stored thereon instructions that, when executed by a computer processor, cause the computer to execute the method as described above.
[0016] According to one embodiment of the present disclosure, there is provided an apparatus configured to execute the above-described method. The apparatus can be a computing device having a processor operably coupled to a memory, and the memory stores program instructions to be executed by the processor to perform operations according to the method. The apparatus can be a plurality of computing devices.
[0017] According to one embodiment of the present disclosure, there is provided a system configured to execute the above-described method. The system can include a plurality of computing devices, each having a respective processor operably coupled to a respective memory. Each memory stores program instructions to be executed by the respective processor to perform operations according to the method. The system can include a computing device operated by a prover and other computing devices operated by respective ones of one or more verifiers. The system can include an intermediate computing device operated by a party of an arbiter that is not necessarily one of the prover or the verifier.
[0018] According to an embodiment, the system includes a computing device of a prover and computing devices of a plurality of verifiers. The computing device of the prover is configured to perform a policy syntactic decomposition on a statement to be proven, generate a secret circuit indicating the statement after the policy syntactic decomposition, divide the secret circuit into a plurality of secret circuit parts that collectively form the divided secret circuit, and transmit the divided secret circuit to the devices of the plurality of verifiers via a shared repository. The computing devices of the plurality of verifiers are configured to jointly calculate a digest of the secret circuit, where each of the devices of the plurality of verifiers calculates an output of a corresponding one of the plurality of secret circuit parts. The aggregator device belonging to the devices of the plurality of verifiers is configured to calculate a value of a unified Boolean operation that is collectively applied to all of the aforementioned outputs in the plurality of secret circuit parts, determine whether the value of the unified Boolean operation is equal to an expected value, and indicate that the proof has been verified only when the value of the unified Boolean operation is equal to the expected value.
[0019] According to an embodiment, a method is provided that includes a plurality of operations by a prover such as a computing device. The method includes performing a policy syntactic decomposition on a statement to be proven. The method includes generating a secret circuit indicating the statement after the policy syntactic decomposition. The method includes dividing the secret circuit into a plurality of secret circuit parts that collectively form the divided secret circuit. The method includes transmitting the divided secret circuit to a plurality of verifiers via a shared repository.
[0020] According to an embodiment, a method is provided that includes a plurality of operations by a verifier such as a computing device. The method includes receiving, via a shared repository, a confidential circuit split from a prover. The method includes jointly calculating a digest of the confidential circuit in cooperation with one or more other verifiers, the verifier, and the one or more other verifiers each calculating an output of a corresponding one of a plurality of confidential circuit parts. A verifier, or an aggregator belonging to a plurality of verifiers, performs further operations, for example, as part of the method. These further operations include calculating a value of a unified Boolean operation that is collectively applied to all of the aforementioned outputs in a plurality of confidential circuit parts, and determining whether the value of the unified Boolean operation is equal to an expected value, and indicating that the proof is verified only if the value of the unified Boolean operation is equal to the expected value.
[0021] According to an embodiment, a computing device is provided that includes a processor, a memory, and a network interface. The computing device is configured to perform a policy parsing on a statement to be proven. The computing device is configured to generate a confidential circuit representing the statement after the policy parsing. The computing device is configured to split the confidential circuit into a plurality of confidential circuit parts that collectively form the split confidential circuit. The computing device is configured to transmit, via a shared repository, the split confidential circuit to devices of a plurality of verifiers.
[0022] According to an embodiment, a computing device is provided that includes a processor, a memory, and a network interface. The computing device is configured to receive a confidential circuit divided from a prover's device via a shared repository. The computing device is configured to cooperate with one or more other verifier devices to jointly calculate a digest of the confidential circuit, where the computing device and the one or more other verifier devices are each configured to calculate the respective output of the corresponding one of a plurality of confidential circuit parts. An aggregator device belonging to the computing device or the plurality of verifier devices is configured to calculate a value of a unified Boolean operation that is collectively applied to all of the aforementioned outputs in the plurality of confidential circuit parts, and to determine whether the value of the unified Boolean operation is equal to an expected value, and to perform further operations including indicating that the proof is verified only if the value of the unified Boolean operation is equal to the expected value.
Brief Description of the Drawings
[0023]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9a
Figure 9b
Figure 9c
Figure 9d
Figure 10
[0024] Note that throughout the accompanying drawings, like features are identified by like reference numerals.
DETAILED DESCRIPTION OF THE INVENTION
[0025] According to an embodiment of the present disclosure, a zero-knowledge proof method, apparatus, and system are provided. Such a method, apparatus, and system can be essentially regarded as cryptographic technologies.
[0026] Embodiments of the present disclosure can provide a significantly strong privacy guarantee with a complete syntax verification function. Thus, multiple variables (also called phases) within a statement (e.g., an NP statement, etc.) can be substantially verified without substantially revealing the true values of the variables. This is related to the multi-policy characteristics of the embodiments. Thus, such embodiments can be used for applications such as contract verification, auditing, etc. For example, statements indicating multiple items in a contract or multiple operations in an operation list can be created and verified. Some embodiments can be implemented in a blockchain. For example, an embodiment can be deployed within a blockchain system as a plugin module that provides a zero-knowledge proof service. In such an embodiment, multiple verifiers (e.g., anonymous verifiers, etc.) can jointly provide zero-knowledge proofs.
[0027] Embodiments of the present disclosure relate to a method of implementing a joint zero-knowledge proof system using split secret circuits. Such embodiments potentially have less overhead than some conventional systems, complete syntax verification, or both. Embodiments of the present disclosure based on split secret circuits are potentially multi-purpose and can be single-use, meaning that they can be applied to any circuit with more comprehensive statements and can achieve non-interactivity among all parties. Non-interactivity refers to a situation where parties exchange information through an intermediary device such as a public information repository (e.g., a computer web server, etc.) rather than communicating directly (e.g., via a handshake protocol). At least one embodiment can be used to create split secret circuits to match comprehensive Boolean formulas against multiple variables. The term "multi-policy syntax" is used to refer to context-based multiple variables in comprehensive statements. Also disclosed is a joint zero-knowledge proof protocol using split secret circuits. Various variations in this protocol are analyzed and compared with state-of-the-art protocols.
[0028] Embodiments of the present disclosure include a group of verifiers that jointly compute a concise digest of the secret circuit C. The group of verifiers can be a cluster of verifiers that communicate via a network such as the Internet. The group of verifiers can be anonymous. The secret circuit C is prepared by the verifiers. Also, the prover may split the secret circuit C. Also, the prover may send (e.g., randomly) the secret circuit to a shared repository. This shared repository may be publicly accessible. In some embodiments, the shared repository may be implemented as a blockchain. In some embodiments, the shared repository may be implemented as a web portal. As used herein, randomness may refer to pseudo-randomness or true (as far as technically possible) randomness. The prover (Alice) may use randomness to scramble the circuit, and the random transmission of the secret circuit may refer to posting the randomly scrambled circuit to the shared repository.
[0029] The prover and the verifier can be or can be associated with different computing devices communicatively coupled via a communication network. In this regard, the prover can be the prover's computing device or the prover's networked computing device, and the verifier can be the verifier's computing device or the verifier's networked computing device. The computing device can include one or more computer processors operatively coupled to a memory, which can be, for example, a magnetic memory, an electronic memory, or an optical memory. The computing device can further include a communication interface for transmitting, receiving, or both transmitting and receiving information (e.g., as electrical signals, wireless signals, or optical signals) via the communication network. This memory can store program instructions for execution by the processor and can also store information associated with zero-knowledge proof operations. Alternatively, the program instructions and information associated with zero-knowledge proof operations can be stored in separate memories in the computing device.
[0030] Embodiments of the present disclosure can provide a public verification system that can be more comprehensive than currently available public verification systems. This verification system can be capable of verifying statements that are more complex than what is currently possible, considering that prior art in this field has been limited to performing monolithic verification. For example, in monolithic verification, only a single hash value in an arithmetic circuit can be verified at a time. Further, embodiments of the present disclosure can implement substantially complete privacy-preserving computations (encrypted computations) based on oblivious transfer (OT) and secret circuit approaches.
[0031] Accordingly, embodiments of the present disclosure can efficiently generate multi-party zero-knowledge proofs based on the secret circuit regime. Further, the embodiments can maintain what is regarded as an important feature of an online zero-knowledge proof system, e.g., being essentially non-interactive and concise, and being publicly disclosed on a blockchain to provide publicly searchable information. This may be particularly applicable, for example, when providing a shield auditing service as used in blockchain technology.
[0032] Various terms as used herein will be readily understood by, for example, those skilled in the art considering zero-knowledge proofs. For example, a secret circuit refers to a cryptographic protocol and is typically described in "How to Generate and Exchange Secrets," Yao, Andrew Chi-Chih, Proceedings of the 27th Annual Symposium on Foundations of Computer Science (SFCS 1986), Foundations of Computer Science, 1986, 27th Annual Symposium, pages 162-167. Karnaugh maps are a well-known technique in circuit optimization. Secret circuits and the related "circuits" refer to logical data structures rather than physical electrical circuits. Oblivious transfer is another cryptographic protocol known in the art. A function can be understood as a functional aspect of a computer. That is, a function corresponds to, for example, an aspect of a computer device configured to generate an output in a prescribed manner from a given input through computer program instructions.
[0033] As will be easily understood, the garbled circuit is a tool used to "encrypt computations", revealing only the output of the computation and nothing about the input or intermediate values. By "circuit", we mean a combination of logical operations on inputs, and its syntax is expressed as a Boolean circuit using Boolean gates such as (AND, OR, NOT) gates in the circuit. Examples of logical circuits are as follows. The classical Yao's "garbling scheme" includes a garbling device, an encoding device, and a verifier. The garbling device converts the (plaintext) circuit C into a garbled circuit
[0034]
Number
[0035] and converts the (plaintext) input x for the circuit into a garbled input
[0036]
Number
[0037] The secret randomness used to garble the circuit is used to encode x into
[0038]
Number
[0039] The verifier takes the garbled circuit
[0040]
Number
[0041] and the garbled input
[0042]
Number
[0043] Operate to calculate the circuit output C(x). To evaluate and determine C(x), x, or
[0044]
Number
[0045] There is no need to know the internal secret randomness. The main idea of security is that
[0046]
Number
[0047] and
[0048]
Number
[0049] even when combined, do not leak information above C(x). In particular,
[0050]
Number
[0051] and
[0052]
Number
[0053] ideally reveals nothing about x, but enables the completion of the calculation of C(x). This approach is often called "encrypted computation."
[0054] FIG. 1 illustrates an apparatus or system 100 provided in accordance with an embodiment of the present disclosure. The apparatus or system 100 can be implemented using networked computing devices, or a plurality of networked computing devices. The apparatus or system 100 can be implemented using only computing hardware or firmware, or a combination of computing hardware and software that causes the computing hardware to execute in a specified manner. The apparatus or system 100 includes a plurality of components referred to as modules. Each module can be a separate structural device, a functional device, or both a structural device and a functional device. The modules can communicate with each other via a specified communication protocol. A first module is referred to as a policy parsing module 110. A second module is referred to as a secret circuit generation module 120, which is implemented to construct a split secret circuit. A third module is referred to as a multi-party non-interactive loss transfer module 130, which is implemented to execute a non-interactive OT-based multi-party agreement verification scheme. A posting module 125 that posts information to a publicly accessible location or medium, such as a web server or a blockchain, may also be included. The posting module 125 may be omitted in some embodiments.
[0055] According to FIG. 1, the prober 140, conveniently called “Alice”, starts the device or system 100 in a self-initiated manner by invoking the first module 110 and the second module 120. In such a step, the first module and the second module are used to prepare a partitioned secret circuit for providing to a plurality of verifiers 145, examples of which are conveniently called “Bob” and “Charlie”. It should be noted that the prober and the verifier may be or include computing devices. The generated secret circuit is distributed by the prober 140 to the verifiers, for example, using the third module 130. This distribution requires an extended OT scheme. This distribution includes the posting module 125 posting to an online system, such as a blockchain or a web portal, which may be publicly accessible. Using the online system, the verifiers 145 calculate intermediate circuit outputs, each corresponding to one of the partitioned secret circuits. Next, the OT aggregator 150 of the secret circuit, which may be another verifier (e.g., called “David”), evaluates the output Y i Calculate the value Y of the unified Boolean operation applied to all the circuits before the last circuit (the aggregate circuit). i The OT aggregator of the confidentiality circuit also determines whether Y is equal to a value y, which represents the expected value of Y. The OT aggregator 150 of the confidentiality circuit (David) can then provide a result 135 indicating whether the prober is verified (if Y=y) or not (otherwise).
[0056] 1 also illustrates auxiliary inputs 102 that may be provided to the first module 110 by the prober 140. The auxiliary inputs 102 may include inputs that provide information redundancy, which may be used to aid in the decoding of the hidden circuit.
[0057] Embodiments of the present disclosure provide a protection mechanism that suppresses the problem of false proofs, for example, according to the semi-honest model of zero-knowledge proofs, as illustrated in FIG. 1, so that this problem can be easily understood by those skilled in the art. For example, when a party has access to the secret randomness used to generate certain parameters in a proof (e.g., corresponding to the seed and algorithm of a pseudorandom number generator), these embodiments can create false proofs that are interpreted as true proofs by the verifier. Embodiments of the present disclosure use split secret circuits to generate public parameters in a multi-party setting, which has the effect of suppressing the occurrence or feasibility of such false proofs.
[0058] Embodiments of the present disclosure enable a cluster of verifiers to calculate a concise digest of a secret circuit C prepared by a prover in an anonymous and collaborative manner online. This concise digest includes a short indicator such as a 1-bit binary output (e.g., "0" or "1"). Also, the prover can perform the splitting of the secret circuit and randomly transmit the split secret circuit to a publicly accessible repository (e.g., a blockchain, or a web portal, etc.). This can provide a more comprehensive public verification system that can verify more complex statements compared to other techniques that can only perform monolithic verification. Monolithic verification can only calculate a single hash value in an arithmetic circuit at a time. Also, the embodiments can implement substantially complete privacy-protected calculations (encrypted calculations) based on OT circuits and secret circuits.
[0059] Regarding security evaluation, embodiments can obtain privacy for a semi-honest threat model. This can be formalized using the generalized Fiat-Shamir secret sharing scheme (Fiat A., Shamir A., (1987) How to Prove Yourself: Practical Solutions to Identification and Signature Problems, Source: Odlyzko A.M., (ed.) Advances in Cryptology - CRYPTO’86, CRYPTO 1986, Lecture Notes in Computer Science, Volume 263, Springer, Berlin, Heidelberg, https: / / doi.org / 10.1007 / 3-540-47721-7_12), which defines a t-secure n-party protocol and
[0060]
Number
[0061] packs the secrets into a single polynomial. By sending a fixed number of field elements to the prover, one can perform congruence calculations for all inputs.
[0062]
Number
[0063] As a result of packing the secrets into a single polynomial, the security bound t in the embodiments of the present disclosure can be reduced from
[0064]
Number
[0065] to
[0066]
Number
[0067] by using multiple verifiers.
[0068] In various embodiments, OT is used to facilitate protection against potentially semi - honest (and thus semi - dishonest) parties. Various embodiments can achieve computational efficiency using one or both of the following two improvements. First, Karnaugh map techniques are used to reduce the number of logic gates using simplified expressions. Second, by integrating the verification procedure (e.g., tightly) with the multi - party OT scheme, the secret circuit is generated by splitting. This can reduce the computational cost on the verifier side compared to other approaches. Security definitions and efficiency requirements may mean that the hash algorithm used for the calculation of the concise digest is collision - resistant. Therefore, a key is usually set for the hash function, and the key may be set by a common reference string.
[0069] Figure 2 illustrates an embodiment of the present disclosure in relation to an example of two - policy inputs where "blind" verification is performed by three offline verifiers involving the construction of a split secret circuit. The prover (Alice) 140 starts the process in a self - starting manner by invoking the first module 110 and the second module 120. In step 204, it prepares a secret circuit split for a plurality of verifiers. The prover (Alice) 140 distributes the secret circuit through the third module 130 using an extended (e.g., 1 - 2) OT scheme 220 with the verifier 145 via an online system such as a publicly accessible blockchain or a web portal. Through the public online system, in step 204, the verifiers Bob and Charlie, who are the verifier 145, calculate the intermediate circuit output Y corresponding to each split secret circuit C. i corresponding to C i Alice 140 collects Y and Y from Bob and Charlie 145 respectively (via the OT scheme 220). Then, Alice 140 collects Y and Y via the OT scheme 226. 1 and Y 2 respectively. Next, Alice 140 collects Y and Y 1 via the OT scheme 226.2 Provide it to David 150. In subsequent steps, the OT aggregator (David) 150 of the secret circuit calculates Y in step 228 and verifies whether Y = y in step 232.
[0070] Circuit C can be regarded as a secret circuit evaluation problem. In this problem, the prover (Alice) constructs circuit C consisting of Boolean gate operations over the finite field GF(2), which is a two-element Galois field. Generally, circuit C can be divided by the degree m using the input vector X. Therefore, circuit C can be represented using the vector C: (C 1 , C 2 ,...) m . As used herein, the superscript following the parentheses usually represents the length of the vector or the corresponding circuit. The goal of the evaluation is to evaluate C for the input X. In the non-interactive proof for this problem, the prover sends the output vector Y: (Y 1 , Y 2 ,...) of C for the input X, and the verifier determines whether Y = C(X).
[0071] Referring back to FIG. 1, the policy parsing module 110 can be functionally regarded as performing the operation
[0072]
Number
[0073] . The module 110 receives the input vector m: (m 1 , m 2 ,...) and, as the input of the security parameter 1 λ , the hashed vector of the input vector
[0074]
Number
[0075] Map it to. Module 110 outputs a Boolean gate-based expression C.
[0076] The secret circuit generation module 120 can be regarded as functionally performing an operation
[0077]
Number
[0078] Module 120 receives the Boolean gate-based expression C as an input and uses the original secret circuit generation operation to output a secret circuit (C 1 , C 2 ,...) of enumerated length m.
[0079] The multi-party non-interactive loss transfer module 130 can be regarded as functionally performing an operation
[0080]
Number
[0081] Module 130 receives an input from the output (Y 1 , Y 2 ,...) m-1 of the split secret circuit and generates an aggregated output Y. That is, module 130 operates on the output of the split secret circuit. The verification operation can be performed (e.g., by module 130) to verify whether Y is equal to the expected output for the extended secret circuit operation denoted as xgc. That is,
[0082]
Number
[0083] is.
[0084] Embodiments of the present disclosure are
[0085]
Number
[0086] Use the universal hash operation denoted as. The universal hash operation takes the common reference string (crs) S i as input and uses the universal hash function h to output a uniform distribution digest.
[0087] Embodiments of the present disclosure
[0088]
Number
[0089] Use the extended secret circuit operation gc denoted as. Gb is a randomizing and secretizing operation that converts f into a triplet (C i , e i , d i ), where C i is the i-th divided secret circuit, e i is the encoded information corresponding to the circuit C i , and d i is the corresponding decoding information. En is
[0090]
Number
[0091] is an encoding operation that maps the input X i to a secret input via. De is
[0092]
Number
[0093] is a decoding operation that maps the secret output Y i to a plaintext output via. Ev is the secret output
[0094]
Number
[0095] Input X that generates i , F i is an operation having
[0096] Certain embodiments of the present disclosure can visualize the security characteristics of accuracy and privacy. In some embodiments, accuracy can be formally described as follows. Input size
[0097]
Number
[0098] All common reference strings having i with respect to
[0099]
Number
[0100] is
[0101] In some embodiments, privacy is an arbitrary non-interactive multi-party loss transfer protocol (S, R i between the transmitting device S and a plurality of receiving devices R i ) with respect to which the receiving device R i has a probability that can be ignored, for example,
[0102]
Number
[0103] is the input size of the reference string, of the order
[0104]
Number
[0105] Except for the probability, it can be formally described as a characteristic of not learning any information regarding the input bits mapped to the corresponding circuit C i It can be formally described as a characteristic of not learning any information regarding the input bits mapped to the corresponding circuit C, except for the probability.
[0106] [Polysyntax Decomposition Module] Here, specific details regarding the polysyntax decomposition module 110 will be described. This module can operate to convert a complete semantic statement from a prover into a polysyntax logical formula involving Boolean operations. Module 110 reduces the complete semantic statement to Boolean operations. This conversion can transform a complex input statement into an output in a manner suitable for efficiently constructing operations based on Boolean gates from the output. The prover 140 owns the composite statement to be verified without revealing the actual values in the composite statement. The composite statement is converted, for example, by the polysyntax decomposition module 110 into one or more regular expressions representing a corresponding set of character strings. For example, tools such as available intrusion detection systems can be used at www.snort.org. The polysyntax decomposition module 110 that generates these regular expressions is configured to implement a regular expression matching operation. This operation is executed to detect a pattern (described by the regular expression) from the input character string.
[0107] Examples of composite statements include simple statements. That is, " The car only starts [if] the ”start” button is pressed [and] the brake pedal is pressed ." ("The car starts only when the'start' button is pressed and the brake pedal is depressed.") The underlined part of the statement between the terms [·] enclosed in square brackets in the sentence represents the variable S i to be verified in the operator vector O, and the terms [·] enclosed in square brackets represent these variables S iIt represents the logical relationship therein. Compared with the original monolithic zero-knowledge proof system that can process only one variable at a time, the embodiments of the present disclosure can operate to match a regular expression with a pattern and construct a corresponding circuit. A composite statement can be converted into a Boolean syntax having a plurality of variables and a plurality of Boolean operations, and the composite statement or the Boolean syntax can be treated as a Boolean circuit. The Boolean circuit can then be split to facilitate multi-party computation and subsequent multi-party verification.
[0108] The polylithic syntax decomposition module 110 can be configured to implement Karnaugh map operations to mitigate the complexity of logical formulas. Since the efficiency of the embodiments of the present disclosure generally depends on the complexity of the target circuit generated and processed, this can improve the overall efficiency. In some embodiments, the input vector S has 6 or fewer inputs.
[0109] FIG. 3 illustrates a series of operations performed by the polylithic syntax decomposition module 110 using pseudocode. This pseudocode can be easily visualized by another means such as a flowchart and can be easily implemented by a computer that executes the corresponding coded instructions. According to FIG. 3, the polylithic syntax decomposition module 110 receives, as input, a composite string "string" and provides, as output, a logical construct (e.g., Boolean) circuit C. The circuit C can include, for example, an indication of a variable and operations such as logical or Boolean operations applied to the variable. The circuit C can be composed of Boolean gate operations over a finite field.
[0110] The operations in FIG. 3 are performed over the length of the composite string and include a step of performing an Extractor operation on the composite string and a step of performing hash generation on the output of the Extractor operation (using a universal hash function). Two Extractor operations are defined as follows. That is, Extractor V() recognizes and / or matches variables in a composite string, Extractor O () recognizes and / or matches operators in a composite string. These extractor operations correspond to generalized extraction functions that can match composite expressions in strings having key variables and logical relationships expressed in boolean operators [AND, OR, XOR, etc.].
[0111] Once the composite string is processed in this manner, the function Regexp() is applied to the output of the illustrated extractor operations and hash operations. Regexp() is a generalized regular expression function configured to match a regular expression in a string to a specific pattern and convert parameters and patterns to the regular expression.
[0112] The output of the regular expression function is provided as input to the generalized conversion function CircuitGen(). This generalized conversion function is configured to convert the input regular expression string into a logic circuit (e.g., a boolean circuit representation of the composite string, etc.).
[0113] The output of the generalized conversion function CircuitGen() is provided to the Karnaugh mapping function K-map(). The Karnaugh mapping function is configured to relax (as much as possible) the complexity of the logic gates in the logic circuit provided to it according to the principles of Karnaugh mapping. The Karnaugh mapping function provides the output circuit C of the polylithic syntax decomposition module 110.
[0114] [Confidential Circuit Generation Module] When given a circuit C that represents a list of truth tables along the depth of a logical gate operation, embodiments of the present disclosure implement a secure circuit scheme with non-interactive commitment, as described, for example, in "The Curious Case of Non-Interactive Commitment," M. Mahmoody and R. Pass, September 10, 2012, cs.cornell.edu. This can facilitate the verifier in achieving the desired accuracy and privacy characteristics of verification. A secure transformation scheme as described in M. Bellare, V. T. Hoang, and P. Rogaway, Foundations of Secure Circuits, Source: T. Yu, G. Danezis, and V. D. Gligorov, editors, ACM CCS 12, pages 784-796, ACM Press, October 2012 can be used. In some embodiments, when k represents a security parameter, the accuracy characteristic of the secure transformation scheme is defined as follows. That is,
[0115]
Number
[0116] It is.
[0117] A Boolean circuit can be regarded as a directed acyclic graph (DAG), that is, a graph without loops, where each edge is directed from a source node to a destination node, and each node represents a computational unit that executes a specific operation op (e.g., AND or XOR, etc.). Furthermore, all gates are fixed to have two input wires, a left wire and a right wire, which are respectively
[0118]
Number
[0119] and r. The gate functions to return a bit value of 0 or 1 when given a wire. The depth of the circuit is denoted by d, and its width is denoted by n. There are multiple ways to represent a Boolean circuit, and one such representation is as a matrix M of d rows and n columns. In this representation, each layer of the circuit
[0120] [Number]
[0121] has a fixed width n, and each entry becomes a gate.
[0122] The secure circuit generation module is implemented to execute the divided secure circuit construction operation. The divided secure circuit can be created based on a previously generated polyrithmic syntax representation, and a secure circuit with public cryptographic primitives can be prepared. In particular, a division scheme suitable for use with multiple verifiers that interact using a multi-party OT verification protocol is implemented. Accordingly, xGC (divided secure circuit) can appropriately divide the secure circuit C into a plurality of independent secure circuits, as represented by the vector C (C 1 , C 2 ,...) or recorded in the vector vector C (C 1 , C 2 ,...). This can facilitate securely dividing information (such as a truth table or corresponding matrix, etc.) into multiple representations. Given a Yao's secure circuit C with a matrix of inputs [x i and outputs [o i in the truth table, the embodiment securely divides the table into multiple representations in the truth table matrix T. This makes the cryptographic proof more suitable for multi-party verification. Thus, a Boolean circuit representing a composite statement can be divided, and the resulting circuit can be subjected to a masking operation, for example, to obscure the true values of the inputs.
[0123] Figure 4 illustrates the operation 400 of the secret circuit generation module 120 according to an embodiment of the present disclosure. Figure 5 illustrates another mode of operation in Figure 4. Figure 6 illustrates another mode of operation in Figure 4.
[0124] Referring to Figure 4, operation 400 includes a preparation step 410. According to the preparation step 410, Yao's multi-party secret circuit is represented using the shuffled inputs x 1 , x 2 ,..., x n . The shuffled inputs are paired with corresponding Boolean gates two at a time. If n is odd, as an auxiliary input, for example, one additional (e.g., random, binary, etc.) value given by
[0125]
Number
[0126] is added, where a 0 and a 1 are underlying random binary values. In a trusted setup, the auxiliary input may be required to be discarded as "toxic waste" after being used. Toxic waste includes parameters that assist in initialization and are deleted (e.g., securely) after use. The new circuit C' is defined as follows as the output of the preparation step 410. That is,
[0127]
Number
[0128] .
[0129] According to the first secret circuit configuration step 420, for each input pair (x i , x j ), x i represents the input from the prover, and x jrepresents the input from the verifier, and for the wires and internal wires w of the circuit, a key pair
[0130]
Number
[0131] is assigned.
[0132] According to the second secret circuit construction step 430, for each gate of the circuit, four ciphertexts are generated that encrypt the corresponding key associated with the output wire according to the truth table of the table T. FIG. 5 illustrates the wire assignment and output.
[0133] According to the third secret circuit construction step 440, for each gate connected to the output wire of the circuit, 0 or 1 is encrypted according to the same truth table used in Yao's secret circuit scheme. (Encryption in Yao's secret circuit can be to obfuscate the output result by applying an encryption algorithm such as the Advanced Encryption Standard (AES) algorithm).
[0134] According to the first secret circuit splitting step 450, based on the truth table T, the circuit matrix M is sliced (split) horizontally with respect to the last gate (i.e., the (m - 1)-th gate (or circuit) before the last aggregation gate (or circuit)). The splitting of the secret circuit is performed so as to maintain the input / output integrity. In various embodiments, the splitting can be implemented using an n-to-1 fan-in to fan-out ratio. Specifically, in such a scheme, the leftmost input gate is sliced for each obfuscated logic gate, and after the first layer of inputs, the gates of the middle and final layers may be required to be aggregated into one secret circuit.
[0135] An example of gate splitting is illustrated in FIG. 5. Obfuscation in the i-th secret circuit Ci is a means of obfuscating the truth table of the Boolean gate. The prover corresponds to a random input of 0 or 1
[0136]
Number
[0137] or
[0138]
Number
[0139] Select the input of. Then, the prover uses all pairs of inputs (00, 01, 10, 11) corresponding to the wire inputs to encrypt the output and create a truth table. The process of Yao's oblivious circuit can be found in Yao, Andrew Chi-Chih (1986). That is, "Secret Generation and Secret Exchange", Proceedings of the 27th Annual Symposium on Foundations of Computer Science (SFCS 1986), Foundations of Computer Science, 1986, 27th Annual Symposium, pages 162-167, doi:10.1109 / SFCS.1986.25, ISBN 978-0-8186-0740-0.
[0140] According to Figure 5,
[0141]
Number
[0142] represents the input of the i-th oblivious circuit having 0,
[0143]
Number
[0144] represents the input of the i-th oblivious circuit having 1,
[0145]
Number
[0146] represents the output truth table of the i-th secret circuit. The initial circuit C510, the division circuit 520, and the verification circuit 540 are illustrated.
[0147] According to the second secret circuit division step 460, the divided (sliced) secret circuits (C 1 , C 2 ,..., C m ) are added. Then, for each circuit, an iteration of the secret circuit protocol is executed. As part of the division step 460, further sub-steps can be repeatedly executed. Alice (the prover) uses a plurality of verifiers to execute a non-interactive multi-party OT scheme for each of the divided circuits. This OT scheme may be executed offline. The OT scheme is executed to obtain the verification of the divided secret circuit Y m = C i = C i (x i , x j ) except for the last circuit C
[0148] For the last circuit Cm, a multi-party non-interactive loss transfer module 130 may be used. Such use can be used to obtain a composite loss transfer (OT) verification expressed by the following formula. That is,
[0149]
Number
[0150] is.
[0151] In some embodiments, the above-described non-interactive multi-party OT transfer scheme executed offline can be described as follows with respect to FIG. 6. In the first step 650, Alice 605 is the function
[0152]
Number
[0153] is represented as a circuit, and circuit C i is anonymized.
[0154]
Number
[0155] has a total of two input wires corresponding to (x i , x j ). In the next step 654, Alice 605 sends all the ciphertexts generated for the anonymized circuit C i to a public repository 610 such as DLT in the blockchain or a publicly accessible web portal. In the next step 658, via the verification assignment system, verifiers {Bob 615, Charlie 620,...} work on each of the anonymized circuit verifications by exchanging a randomly generated number
[0156]
Number
[0157] with Alice in the OT commitment message OT. In the next step, Alice sends the keys corresponding to her input wires
[0158]
Number
[0159] to. In the next step, Alice 605 and the verifiers {Bob 615, Charlie 620,...} are made to engage in the lost transfer protocol. Subsequently, for each split gate, the verifiers {Bob 615, Charlie 620,...} use the key
[0160]
Number
[0161] Learn. The verifier individually starts evaluating the circuit using the previously obtained keys. Subsequently, the verifiers {Bob 615, Charlie 620,...} also learn the output of C(x i , x j ). Alice 605 also learns that the verifier is evaluating the result using the outputs of Y 1 , Y 2 ,.... If Y i ≠ yi, Alice may choose to abort the proof. Otherwise, Alice may proceed to call the multi-party non-interactive lossy transfer module 130 for OT aggregation.
[0162] [Multi-party non-interactive lossy transfer] Following syntax analysis and secret circuit generation, for example, an OT aggregation OT protocol is implemented using the multi-party non-interactive lossy transfer module 130 for OT aggregation in FIG. 1. This protocol combines all the previously executed split secret circuit verifications into an overall verification conclusion to complete the proof verification. In various embodiments, this requires a secret circuit C m constructed using XOR gates to reduce the computational cost. The formula for circuit C m can be given as
[0163]
Number
[0164] . For the calculated Y = y, it is desirable for both the prover (Alice) and the aggregator (David) to agree, where y = f(x). OT aggregation promotes security integrity. FIG. 7 illustrates the operation of the OT aggregator OT protocol according to an embodiment of the present disclosure. Lossy transfer can substantially maintain the anonymity of the parties. The aggregator (David) can be regarded as a verifier that aggregates the verifications of other verifiers and provides a pass / fail result indicating whether the proof has been verified.
[0165] According to FIG. 7, in the first step 750, using the obfuscation circuit generation module 120, the verifier posts the calculation result Y using the public repository 710 that Alice 705 and David 715 can retrieve from the portal. i In the next step 754, Alice creates random bits
[0166]
Number
[0167] and, for example,
[0168]
Number
[0169] sets them as such. In the next step 758, Alice obfuscates the circuit using an obfuscation operation as described elsewhere in this specification. The obfuscation operation
[0170]
Number
[0171] outputs. Here, gc(·) represents Yao's obfuscation circuit generation algorithm,
[0172]
Number
[0173] and is
[0174]
Number
[0175] the obfuscated circuit, the encoding function e m , and the decoding function d mis included. In the next step 762, Alice executes the deterministic encoding operation Enc(), which takes m and
[0176]
Number
[0177] as the secret input
[0178]
Number
[0179] and converts it to
[0180] In the next step 766, Alice 705 sends the tuple
[0181]
Number
[0182] to the public repository 710, e.g., a DLT in a blockchain, or a web portal. David 715 retrieves the information 770 non-interactively from the public repository 710. Then, David creates random bits
[0183]
Number
[0184] In another operation 774, David executes the deterministic evaluation operation Ev(·), whichis
[0185]
Number
[0186] Output it. In the next step 778, David sends the output Y back to Alice via the public repository 710. In the next step 782, Alice executes the deterministic decryption operation De(·) to calculate the output
[0187]
Number
[0188] where d m represents the decryption key. At the same time in step 786, David also executes the deterministic decryption operation De(·) to calculate the output
[0189]
Number
[0190] Next, in step 790, Alice and David check whether
[0191]
Number
[0192] where f(·) is the logical Boolean function before becoming the secret circuit function C(·).
[0193]
Number
[0194] If so, the OT aggregation protocol will accept the verification result. Otherwise, the verification result will not be accepted and Alice may abort the verification.
[0195] Overall methods, apparatuses, and systems according to embodiments of the present disclosure that include stealth circuits require multiple functions involving adaptations of Yao's stealth circuit algorithm. FIG. 8 illustrates the interaction of cryptographic functions according to one embodiment. Components within such an embodiment can be formalized as follows. The stealth operation gc(·) 810 is a random operation that converts the function
[0196]
Number
[0197] into a tuple
[0198]
Number
[0199] as illustrated as a series of operations in FIG. 9a. As illustrated in FIG. 9b, the encoding operation Enc(·) 820 changes the common reference character string input
[0200]
Number
[0201] to the stealth circuit input X = enc(x). The encoding operation is
[0202]
Number
[0203] Use the function H operating above to generate the output X. As illustrated in FIG. 9c, the evaluation operation Eval(·) 830 represents the evaluation function of a specific secret function C for the secret input x that gives the secret output Y = C(X). In the evaluation operation, the function Decryption operating on the inputs C and X is used to generate the output Y. As illustrated in FIG. 9d, the decryption function de(·) 840 changes the secret output Y to the final output y = de(Y) which is done according to the original (before encryption) function f(m). The decryption function executes an XOR operation on the inputs d and Y to generate the output y. The deterministic evaluation operation Ev(·) 850 is also shown to be executed, for example, by an aggregator (David) as described above.
[0204] According to various embodiments, the OT scheme can be implemented based on an adaptation of the Bellare-Micali scheme (M. Bellare and S. Micali, Non-Interactive Lossy Transfer and Applications, Proceedings, Advances in Cryptology - CRYPTO’89, Springer-Verlag LNCS, 435 (1990), 547 - 557). The split secret circuit and the OT aggregator can be based on a lossy transfer scheme.
[0205] More specifically, for purposes of illustration in one embodiment, let G be a group of prime degree p with a generator g, and let H be a hash function that can be modeled as a random oracle
[0206]
Number
[0207] Let it be. m 0 and m 1 as the messages of the transmitting device,
[0208]
Number
[0209] Use it as the input of the receiving device. The OT protocol can be as follows. First, the transmitting device S selects
[0210]
Number
[0211] and sends c to the receiving device R. Next, the receiving device R selects a random key
[0212]
Number
[0213] and calculates two public keys
[0214]
Number
[0215] and
[0216]
Number
[0217] and sends y 0 and y 1 to the transmitting device.
[0218] Next,
[0219]
Number
[0220] if it is, the transmitting device S interrupts (for example, immediately). Otherwise, S
[0221]
Number
[0222] Select and encrypt the text
[0223]
Number
[0224] and
[0225]
Number
[0226] Calculate. The transmitting device sends c 0 and c 1 to the receiving device R. Next, the receiving device R analyzes the encrypted text
[0227]
Number
[0228] and then decrypts the knowledge of k, that is
[0229]
Number
[0230] and outputs m b
[0231] As described above, the embodiments of the present disclosure provide a zero-knowledge proof method, apparatus, and system that can handle complex semantics in multiple sentences. Such embodiments can be applied, for example, in a distributed computing environment such as a blockchain environment. The embodiments of the present disclosure provide an online verification method, apparatus, and system for maintaining privacy on a blockchain. The embodiments are expected to have less overhead and a more practical implementation than some conventional implementations from both the perspectives of communication overhead and computational overhead.
[0232] Embodiments of the present disclosure provide substantially complete syntax verification that enables policy verification. Embodiments may present improved obfuscation circuits. Embodiments may be implemented with little need for prior trust setup. Embodiments may potentially present proof generation times and sizes that are linear with respect to input size O(n). Embodiments may provide complete syntax verification to achieve more comprehensive tasks. Embodiments may provide security soundness with provable security. Embodiments may be essentially non-interactive. Embodiments may substantially facilitate overall privacy protection using fully homomorphic encryption (FHE) capabilities.
[0233] Embodiments of the present disclosure can potentially improve the operation of a networked computing environment by providing a secure and trustworthy way to transfer information between devices controlled by different entities. Further, the above-described potential features in embodiments can also improve network operation. Such embodiments promote the integrity of networking and communication, improving overall networking operation and computing operation. Embodiments of the present disclosure require a specific set of steps to be performed by a party in a networked computing environment to achieve goals such as secure and trustworthy network communication. A plurality of different computing devices receive data, process that data, and provide the data as output (e.g., to another one of the computing devices) to further such goals.
[0234] FIG. 10 is a schematic diagram showing a computing device 1100 that can perform any or all of the operations of the methods and features explicitly or implicitly described herein according to different embodiments of the present disclosure. For example, a computer equipped with network capabilities can be configured as the computing device 1100. A system as described herein can be provided by network connecting such a plurality of computing devices together so that different computing devices are potentially operated by different parties.
[0235] As shown, the device 1100 can include a processor 1110, such as a central processing unit (CPU), or a special processor such as a graphics processing unit (GPU) or other such processing unit, a memory 1120, a non-transitory mass storage device 1130, an input / output interface 1140, a network interface 1150, and a transceiver 1160, all of which are communicatively coupled via a bidirectional bus 1170. According to certain embodiments, any or all of the depicted elements may be utilized, or only a subset of the elements may be utilized. Further, the device 1100 may include multiple instances of certain elements, such as multiple processors, memories, or transceivers. Also, the elements of the hardware device may be directly coupled to other elements without going through a bidirectional bus. In addition to or instead of the processor and memory, other electronic devices, such as integrated circuits, may be used to perform the required logical operations.
[0236] It may include any type of non-transitory memory, such as memory 1120, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), read-only memory (ROM), or any combination thereof. The mass storage device 1130 may include any type of non-transitory storage device, such as a solid state drive, hard disk drive, magnetic disk drive, optical disk drive, USB drive, or any computer program product configured to store data and machine-executable program code. According to certain embodiments, the memory 1120 or the mass storage device 1130 may store therein statements and instructions executable by the processor 1110 to perform any of the method operations described above.
[0237] Embodiments of the present disclosure can be implemented using the hardware, software, or a combination thereof of an electronic device. In some embodiments, the present disclosure is implemented by one or more computer processors that execute program instructions stored in a memory. In some embodiments, the present disclosure is implemented partially or fully in hardware using, for example, one or more field programmable gate arrays (FPGAs) or application specific integrated circuits (ASICs) to execute processing operations quickly.
[0238] Certain embodiments of the present disclosure are described herein for illustrative purposes, but it will be understood that various changes can be made without departing from the scope of the present disclosure. Accordingly, the present specification and drawings should be regarded as merely illustrative of the present disclosure as defined by the appended claims, and it is intended to cover any changes, modifications, combinations, or equivalents that fall within the scope of the present disclosure. In particular, a computer program product or program element, or a program storage device or memory device such as a magnetic wire or optical wire, tape or disk, for storing a machine-readable signal for controlling the operation of a computer according to the method of the present disclosure and / or for configuring some or all of its components according to the system of the present disclosure, is within the scope of the present disclosure.
[0239] The acts associated with the methods described herein can be implemented as encoded instructions in a computer program product. In other words, a computer program product is a computer-readable medium on which software code for performing the method is recorded when the computer program product is loaded into memory and executed on a microprocessor of a wireless communication device.
[0240] Furthermore, each operation of the method can be executed according to one or more of a plurality of program elements, modules or objects generated from any programming language such as C++ or Java on any computing device such as a personal computer, server, or PDA. (Registered Trademark) In addition, each operation, or a file or object implementing each of the foregoing operations, etc., can be executed by special-purpose hardware or a circuit module designed for that purpose.
[0241] Through the description of the foregoing embodiments, the present disclosure can be implemented by using only hardware or by using software and the necessary universal hardware platform. Based on such an understanding, the technical solution of the present disclosure may be embodied in the form of a software product. The software product may be stored in a non-volatile or non-transitory storage medium, which may be a compact disc read-only memory (CD-ROM), a USB flash drive, or a removable hard disk. The software product includes a number of instructions that enable a computer device (personal computer, server, or network device) to execute the methods provided in the embodiments of the present disclosure. For example, such execution may correspond to the simulation of the logical operations as described herein. The software product may additionally or alternatively include a number of instructions that enable a computer device to perform operations for configuring or programming a digital logic device according to the embodiments of the present disclosure.
[0242] The present disclosure and the inventions associated therewith have been described with reference to specific features and embodiments, but it is obvious that various changes and combinations can be made thereto without departing from such inventions. Therefore, the present specification and drawings should be regarded as merely illustrative of the embodiments of the present disclosure, as defined, for example, by the appended claims, and it is intended to cover any changes, modifications, combinations, or equivalents that fall within the scope of the present disclosure and its inventions.
Claims
1. A method for performing zero-knowledge proof, comprising: by a prover, performing a policy syntax decomposition on a statement to be proved; generating a secret circuit representing the statement after the policy syntax decomposition; dividing the secret circuit into a plurality of secret circuit parts that collectively form a divided secret circuit; sending the divided secret circuit to a plurality of verifiers via a shared repository; by the plurality of verifiers, collectively calculating a digest of the secret circuit, wherein each of the plurality of verifiers calculates an output of a corresponding one of the plurality of secret circuit parts; calculating a value of a unified Boolean operation that is collectively applied to all of the outputs of the plurality of secret circuit parts by an aggregator belonging to the plurality of verifiers; determining, by the aggregator, whether the value of the unified Boolean operation is equal to an expected value, and indicating that the proof is verified only if the value of the unified Boolean operation is equal to the expected value A method comprising the above steps.
2. The statement has a plurality of phases or variables, the policy syntax decomposition includes generating a Boolean circuit representation of the statement using a plurality of wires and a plurality of gates, and the secret circuit is generated from the Boolean circuit representation. The method according to claim 1.
3. The method according to claim 1, further comprising converting the statement into one or more regular expressions and generating a Boolean circuit representation from the regular expressions, and the secret circuit is generated directly or indirectly from the Boolean circuit representation.
4. The method according to claim 3, further comprising implementing a Karnaugh map operation on the Boolean circuit representation to generate a simplified version of the Boolean circuit representation, and the secret circuit is generated directly or indirectly from the simplified version of the Boolean circuit representation.
5. The step of sending the divided secret circuit to a plurality of verifiers is performed using non-interactive lossy transfer. The method according to claim 1.
6. The method of claim 1, further comprising the step of executing a multi-party loss transfer scheme to facilitate interaction between the prover and the verifier, interaction between verifiers, or both.
7. A non-transitory computer-readable medium storing instructions that, when executed by a computer processor, cause the computer to execute the method of claim 1.
8. A system, A computing device of a prover, Performing poly-licit syntactic decomposition on a statement to be proven; Generating a secret circuit representing the statement after poly-licit syntactic decomposition; Dividing the secret circuit into a plurality of secret circuit parts that collectively form a divided secret circuit; Transmitting the divided secret circuit to devices of a plurality of verifiers via a shared repository; A computing device of a prover configured to perform the above; The computing devices of the plurality of verifiers, Collectively calculating a digest of the secret circuit, wherein each of the devices of the plurality of verifiers calculates an output of a corresponding one of the plurality of secret circuit parts; Calculating a value of a unified Boolean operation that is collectively applied to all of the outputs of the plurality of secret circuit parts by a device of an aggregator belonging to the devices of the plurality of verifiers; Determining by the device of the aggregator whether the value of the unified Boolean operation is equal to an expected value, and indicating that the proof is verified only if the value of the unified Boolean operation is equal to the expected value; A computing device of a plurality of verifiers configured to perform the above; A system comprising the above.
9. The system of claim 8, wherein the statement has a plurality of phases or variables, the poly-licit syntactic decomposition includes generating a Boolean circuit representation of the statement using a plurality of wires and a plurality of gates, and the secret circuit is generated from the Boolean circuit representation.
10. The system of claim 8 or 9, wherein the prover is further configured to convert the statement into one or more regular expressions and generate a Boolean circuit representation from the regular expressions, and the secret circuit is generated directly or indirectly from the Boolean circuit representation.
11. Further configured to implement Karnaugh map operations on the Boolean circuit representation to generate a simplified version of the Boolean circuit representation, wherein the secret circuit is generated directly or indirectly from the simplified version of the Boolean circuit representation, the system of claim 10.
12. The prover is configured to transmit the split secret circuit to the devices of the plurality of verifiers using non-interactive lossy transfer, the system of claim 8.
13. The device of the prover and the device of the verifier, the devices of the plurality of verifiers, or both are configured to execute a multi-party lossy transfer scheme to facilitate interaction therebetween, the system of claim 8.
14. A method for performing zero-knowledge proof, comprising: by a prover, performing a polyrithmic syntactic decomposition on a statement to be proven; generating a secret circuit representing the statement after polyrithmic syntactic decomposition; dividing the secret circuit into a plurality of secret circuit parts that collectively form a split secret circuit; transmitting the split secret circuit to a plurality of verifiers via a shared repository and a method.
15. The statement has a plurality of phases or variables, and the polyrithmic syntactic decomposition includes generating a Boolean circuit representation of the statement using a plurality of wires and a plurality of gates, wherein the secret circuit is generated from the Boolean circuit representation, the method of claim 14.
16. Further comprising converting the statement into one or more regular expressions and generating a Boolean circuit representation from the regular expressions, wherein the secret circuit is generated directly or indirectly from the Boolean circuit representation, the method of claim 14.
17. Further comprising implementing Karnaugh map operations on the Boolean circuit representation to generate a simplified version of the Boolean circuit representation, wherein the secret circuit is generated directly or indirectly from the simplified version of the Boolean circuit representation, the method of claim 16.
18. The step of transmitting the split secret circuit to a plurality of verifiers is performed using non-interactive lossy transfer, the method of claim 14.
19. The method according to claim 14, further comprising the step of executing a multi-party loss transfer scheme to facilitate interaction between the prover and the verifier.
20. A method for performing a zero-knowledge proof, comprising: receiving, by a verifier, a split secret circuit from a prover via a shared repository; and cooperating with one or more other verifiers to jointly compute a digest of the secret circuit, wherein the verifier and the one or more other verifiers each compute an output of a corresponding one of a plurality of secret circuit parts; comprising wherein an aggregator belonging to the verifier or the one or more other verifiers computes a value of a unified Boolean operation that is collectively applied to all of the outputs of the plurality of secret circuit parts; and determines whether the value of the unified Boolean operation is equal to an expected value, and indicates that the proof is verified only if the value of the unified Boolean operation is equal to the expected value. A method.
21. The method according to claim 20, further comprising the step of executing a multi-party loss transfer scheme to facilitate interaction between the prover and the verifier, between a plurality of the verifiers, or both.
22. A computer program comprising instructions that, when executed by a computer processor, cause a computer to execute the method according to any one of claims 1 to 7.
23. A computer program comprising instructions that, when executed by a computer processor, cause a computer to execute the method according to any one of claims 14 to 19.
24. A computer program comprising instructions that, when executed by a computer processor, cause a computer to execute the method according to claim 20 or 21.
25. An apparatus comprising a processor configured to execute instructions stored in a memory, causing the method according to any one of claims 1 to 7 to be implemented.
26. An apparatus comprising a processor, the processor being configured to execute instructions stored in a memory, the apparatus causing the method according to any one of claims 14 to 19 to be implemented.
27. An apparatus comprising a processor, the processor being configured to execute instructions stored in a memory, the apparatus causing the method according to claim 20 or 21 to be implemented.
Citation Information
Patent Citations
Improvements in multi-party computations
EP3754898A1
System And Method For A Practical, Secure And Verifiable Cloud Computing For Mobile Systems
US20150341326A1