Reserve contract method utilizing Pedersen commitment and reserve verification method utilizing Pedersen commitment-based zero-knowledge proof algorithm

By utilizing Pedersen commitments and zero-knowledge proof algorithms, the method addresses the slow processing times of existing reserve proof systems, achieving secure, efficient, and private reserve verification.

JP7686057B1Active Publication Date: 2025-05-30DICRYPT INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2023218647
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-12-25
Publication Date
2025-05-30
Estimated Expiration
2043-12-25

AI Technical Summary

Technical Problem

Existing reserve proof methods, such as those using Merkle Trees, are excessively time-consuming, necessitating a high-speed alternative for verifying reserves in a transparent and secure manner.

Method used

The method employs Pedersen commitments and zero-knowledge proof algorithms to facilitate rapid reserve contracting and verification, ensuring that user reserves are securely and efficiently managed without exposing personal information.

Benefits of technology

This approach enables fast and secure reserve verification, enhancing trust among users by ensuring the integrity and availability of funds, while maintaining user privacy and reducing processing time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007686057000001_ABST
    Figure 0007686057000001_ABST
Patent Text Reader

Abstract

Provided is a reserve verification method. 【Solution means】 The present invention relates to a reserve contract method utilizing Pedersen commitment and a reserve verification method utilizing a Pedersen commitment-based zero-knowledge proof algorithm. In a reserve contract method performed by at least one processor according to an embodiment of the present disclosure, a step of loading a reserve database in which a plurality of reserves corresponding to a plurality of accounts are stored, a step of generating a plurality of commit values respectively corresponding to the plurality of accounts by using a commit key and a plurality of random values, a step of generating a transaction on a smart contract based on the calculated plurality of commit values, a step of calculating an integrated commit value based on the commit key, an integrated random value corresponding to the sum of the plurality of random values, and an integrated reserve, and a step of generating a dataset including the integrated commit value, the integrated reserve, and the commit key can be included.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a reserve contract method using a Pedersen commitment and a reserve verification method using a zero-knowledge proof algorithm based on a Pedersen commitment.

Background Art

[0002] In finance, "reserve" refers to assets held by a company for various purposes. Generally, maintaining an amount that exactly matches the customer deposits is included in this purpose. "Proof of Reserves (PoR)" is a term that describes an independent audit conducted to confirm whether the audited party holds sufficient reserves to protect all customer balances.

[0003] In the case of virtual asset reserve proof, it means that the auditor confirms that the on-chain assets held by the company match 100% of the customer assets as shown in the balance at the time of the audit. Through this, customers can be confident that the company has sufficient payment ability and liquidity, and that they can withdraw funds at any time if they wish.

[0004] Reserve proof has very important significance in strengthening trust by transparently disclosing information on the safety and availability of funds to customers and enabling all customers to confirm their assets through reserve proof in an encrypted manner.

[0005] Conventionally, Merkle Tree data structure has been used to perform reserve proof. However, in the case of Merkle Tree, there is a problem that the time required for reserve contract and proof is excessively long. Therefore, the need for a high-speed reserve proof method that can replace the Merkle Tree has emerged.

Summary of the Invention

Problems to be Solved by the Invention

[0006] One object of the present invention is to provide a method for contracting a reserve by utilizing a Pedersen commitment.

[0007] Still another object of the present invention is to provide a method for performing verification on a reserve contracted by utilizing a Pedersen commitment.

Means for Solving the Problems

[0008] In a reserve contract method performed by at least one processor according to an embodiment of the present disclosure, a step of loading a reserve database in which a plurality of reserves corresponding to a plurality of accounts are stored, a step of generating a plurality of commit values respectively corresponding to the plurality of accounts by using a commit key and a plurality of random values, a step of generating a transaction on a smart contract based on the calculated plurality of commit values, a step of calculating an integrated commit value based on the commit key, an integrated random value corresponding to the sum of the plurality of random values, and an integrated reserve, and a step of generating a data set including the integrated commit value, the integrated reserve, and the commit key can be included.

[0009] According to an embodiment, the reserve contract method may further include a step of binding the data set to a blockchain.

[0010] According to an embodiment, the reserve contract method may further include a step of uploading the data set to a network.

[0011] According to one embodiment, the reserve contract method may further include receiving a first reserve corresponding to a first account among the plurality of accounts, updating the reserve database by utilizing the first reserve, generating a first random value corresponding to the first account, generating a first commit value corresponding to the first account based on the first random value, the commit key, and the first reserve, and updating the smart contract by utilizing the first commit value.

[0012] According to one embodiment, the reserve contract method may further include updating the integrated random value based on the first random value, updating the integrated reserve, calculating an integrated commit value based on the commit key, the updated integrated reserve, and the updated integrated random value, and generating a dataset including the integrated commit value, the integrated reserve, and the commit key.

[0013] According to one embodiment, the step of generating the plurality of commit values may include calculating each of the plurality of commit values in the form of a power of the reserve of the commit key and the random value.

[0014] According to one embodiment, the commit key com i includes a first key g and a second key h, and the step of generating the plurality of commit values may be characterized by generating a commit value com i by utilizing the following formula for the reserve mi and the random value ri corresponding to the i-th (i is a natural number) account.

[0015]

Equation

[0016] A reserve verification method (Method of proving reserves) performed by at least one processor according to an embodiment of the present disclosure and utilizing a zero knowledge proof algorithm may include obtaining an integrated commitment value, obtaining a plurality of commitment values corresponding to a plurality of accounts from a plurality of account owners from a smart contract, verifying the integrity of the integrated commitment value based on the plurality of commitment values and the integrated commitment value, and verifying the integrity of the first commitment value based on a commitment key, a first random value corresponding to a first user, a first reserve, and the first commitment value.

[0017] According to one embodiment, the step of verifying the integrity of the integrated commitment value may include multiplying all of the plurality of commitment values, comparing the multiplied result value with the integrated commitment value, and, if the multiplied result value and the integrated commitment value are the same as a result of the comparison, verifying the integrity of the integrated commitment value.

[0018] According to one embodiment, the step of verifying the integrity of the integrated commitment value may include receiving a first verification value and a second verification value, obtaining a first value, calculating a resulting hash value by hashing the first value, the commitment key, and the first verification value, and determining whether the integrated commitment value is appropriate based on whether the result of operating on the hash value, the first value, and the first verification value is the same as the result of operating on the commitment key and the second verification value.

[0019] According to one embodiment, the commitment key includes a first key g and a second key h, and when the integrated reserve is TRsv and the integrated commitment value is TCOM, the first value y may be calculated by the following formula.

[0020]

Equation

[0021] According to an embodiment, when the first verification value is t, the second verification value is s, and the hash value is c, it can be characterized in that when the following formula is satisfied, it is determined that the integrated commit value is appropriate.

[0022]

Equation

[0023] According to an embodiment, the step of verifying the integrity of the integrated commit value can be characterized in that it is verified without the integrated random value used in the calculation of the integrated commit value.

[0024] According to an embodiment, the step of verifying the integrity of the first commit value can include the step of obtaining the commit key, the step of calculating a verification commit value based on the commit key, the first secret key, and the first reserve, and verifying the integrity of the first commit value by comparing the verification commit value with the first commit value obtained from the smart contract.

[0025] According to an embodiment, when verifying the integrity of the first commit value, it can be characterized in that it is verified that the first reserve is reflected in the integrated reserve.

[0026] According to an embodiment, the integrated commit value can be obtained from a blockchain network.

Advantages of the Invention

[0027] According to the technical idea of the present invention, by utilizing Pedersen commit to contract reserves and also performing verification of reserves by using the properties of Pedersen commit, contracts and verification can be performed without exposing the user's personal information (for example, the reserve balance of an individual user) during the verification process, and verification can be performed at high speed according to the properties of Pedersen commit.

Brief Description of the Drawings

[0028]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Modes for Carrying Out the Invention

[0029] Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the attached drawings. The advantages and features of the present invention, and the methods for achieving them, will become clear by referring to the embodiments described in detail below together with the attached drawings. However, the technical idea of the present invention is not limited to the following embodiments and can be embodied in various different forms. However, the following embodiments make the technical idea of the present invention complete, and are provided to fully inform those with ordinary knowledge in the technical field to which the present invention belongs of the scope of the present invention. The technical idea of the present invention is only defined by the scope of the claims.

[0030] When adding reference numerals to the components of each drawing, it should be noted that the same components should have the same numerals as much as possible even if they are shown on other drawings. Also, in the description of the present invention, when it is determined that a detailed description of a related known configuration or function may obscure the gist of the present invention, the detailed description thereof will be omitted.

[0031] Unless otherwise defined, all terms (including technical and scientific terms) used in this specification can be used in a meaning commonly understood by those with ordinary knowledge in the technical field to which the present invention belongs. Also, terms defined in commonly used dictionaries are not ideally or overly interpreted unless specifically defined otherwise. The terms used in this specification are for the purpose of explaining the embodiments and are not intended to limit the present invention. In this specification, the singular form includes the plural form unless specifically stated otherwise in the context.

[0032] In addition, when describing the components of the present invention, terms such as first, second, A, B, (a), (b), etc. can be used. Such terms are merely for distinguishing the components from other components, and do not limit the essence, order or sequence of the corresponding components. When a component is described as being "connected", "coupled" or "connected" to another component, the component can be directly connected or connected to the other component, but it should be understood that other components may be further "connected", "coupled" or "connected" between each component.

[0033] As used in the present invention, "comprises" and / or "comprising" do not exclude the presence or addition of one or more other components, steps, operations and / or elements of the recited components, steps, operations and / or elements.

[0034] Components included in any one embodiment and components having a common function may be described using the same name in other embodiments. Unless otherwise stated, the description given in any one embodiment may also be applied to other embodiments, and specific descriptions may be omitted within the overlapping scope or within the scope that can be clearly understood by those of ordinary skill in the art.

[0035] Hereinafter, some embodiments of the present invention will be described in detail with reference to the accompanying drawings.

[0036] Hereinafter, the present invention will be described in detail with reference to the preferred embodiments of the present invention and the attached drawings.

[0037] FIG. 1 is a block diagram showing a reserve management system according to an exemplary embodiment of the present disclosure.

[0038] Referring to FIG. 1, the reserve management system 10 can contract for a reserve and perform an audit or verification on the contracted reserve, and for this purpose, it can include a reserve receiving terminal 100, a network NW, and a user terminal 200. Although not shown, an audit terminal for reserve audit may further be included according to an embodiment.

[0039] The reserve receiving terminal 100 can receive a reserve and be operated by a receiving institution that manages the received reserve. In one example, the receiving institution can include a bank, an exchange, etc. Also, in this specification, a reserve is an asset owned by a user, and can mean a financial asset or a physical asset deposited or received by a receiving institution, and can mean a deposit in one example. The user terminal 200 can entrust the reserve owned by the user to the receiving institution that operates the reserve receiving terminal 100.

[0040] The reserve receiving terminal 100 and the user terminal 200 can include various communicable terminal devices such as a cellular phone, a smart phone, a laptop, a PC (Personal Computer), a navigation device, a PCS (Personal Communication System), a GSM (Global System for Mobile communications), a PDC (Personal Digital Cellular), a PHS (Personal Handyphone System), a PDA (Personal Digital Assistant), an IMT (International Mobile Telecommunication)-2000, a CDMA (Code Division Multiple Access)-2000, a W-CDMA (W-Code Division Multiple Access), a Wibro (Wireless Broadband Internet) terminal, a smart pad, a tablet PC, etc. In still another example, the reserve receiving terminal 100 and the user terminal 200 can be implemented by a server.

[0041] The reserve trustee terminal 100 and the user terminal 200 can be connected through a network NW that can communicate with each other by wire or wirelessly. When connected by wire, the network NW can use the serial method, and when connected wirelessly, the network NW can communicate using a wireless communication network. The wireless communication network includes, but is not limited to, a short-range communication network (LAN: Local Area Network), a wide-area communication network (WAN: Wide Area Network), the Internet (WWW: World Wide Web), a wired / wireless data communication network, a telephone network, a wired / wireless television communication network, 3G, 4G, 5G, 3GPP (registered trademark) (3rd Generation Partnership Project), 5GPP (5th Generation Partnership Project), LTE (Long Term Evolution), WIMAX (World Interoperability for Microwave Access), Wi-Fi, the Internet, LAN (Local Area Network), Wireless LAN (Wireless Local Area Network), WAN (Wide Area Network), PAN (Personal Area Network), RF (Radio Frequency), Bluetooth (registered trademark) network, NFC (Near-Field Communication) network, satellite broadcast network, analog broadcast network, DMB (Digital Multimedia Broadcasting) network, blockchain network (Blockchain Network), etc.

[0042] The user terminal 200 can have a unique account (e.g., an account), and can deposit a reserve in its own account. In one embodiment, the user terminal 200 can deposit a reserve through the reserve receiving terminal 100 and the first network SC. In one example, the first network SC can be a smart contract utilizing a blockchain network.

[0043] The reserve receiving terminal 100 can calculate a commit value corresponding to the reserve based on the reserve reception of the user terminal 200. In this specification, the commit value can mean a value converted into the form of a Pedersen Commit based on the reserve, a commit key ck, and a random value. In one embodiment, the reserve receiving terminal 100 utilizes the following mathematical formula 1 for the reserve mi corresponding to the user's i-th (i is a natural number) account, the random value ri, and the commit keys g, h to calculate the commit value com i can be calculated.

[0044]

Equation

[0045] In one embodiment, the reserve receiving terminal 100 can generate the commit value com i and a proof by performing a zero-knowledge proving method in the contract process. In this specification, the zero-knowledge proving method is a method of verifying the integrity of a message without verifying the message (e.g., reserve / commit value). In one example, zk-SNARK (zero-knowledge SNARK), cc-SNARK (commit carrying SNARK) can be utilized as the zero-knowledge proving method. Also, the proof can indicate a value that can prove whether the commit value com i was generated normally.

[0046] The reserve trustee terminal 100 can upload the calculated commit values com1 to comN to the first network SC. In one embodiment, the reserve trustee terminal 100 can bind the calculated commit values com1 to comN to a block on the smart contract.

[0047] The reserve trustee terminal 100 can calculate the integrated commit value TCOM by multiplying the commit values of all users. In one embodiment, for the integrated reserve (TRsv, the sum of all mis or the total reserve deposited with the reserve trustee terminal 100), the commit keys g, h, and the integrated random value (R, the sum of all ris), the integrated commit value TCOM can be calculated as shown in the following mathematical formula 2.

[0048]

Equation

[0049] The reserve trustee terminal 100 can upload the calculated integrated commit value TCOM, the integrated reserve TRsv, and the commit key ck to the second network BC. In one embodiment, the second network BC can be a blockchain network, and the reserve trustee terminal 100 can bind the integrated commit value TCOM, the integrated reserve TRsv, and the commit key ck onto the blockchain network. In yet another embodiment, the second network BC can be the World Wide Web, and the reserve trustee terminal 100 can upload the commit value TCOM, the integrated reserve TRsv, and the commit key ck to a predetermined website.

[0050] According to the technical idea of the present disclosure, the reserve management system 10 can upload to the network NW by utilizing a commitment value in Pedersen commitment form. Also, based on the addition homomorphism property of the Pedersen commitment form as described later, the reserve management system 10 can verify whether the reserve receiving terminal 100 has completely deposited the entire reserve without exposing the random value by using the integrated commitment value TCOM and the integrated reserve TRsv. As a result of such a verification method, the auditing function for the reserve receiving terminal 100 can be improved, and the reserve of the user terminal 200 can be completely received.

[0051] In this specification, the operations of the reserve receiving terminal 100 and the user terminal 200 may mean operations performed by a processor included in each configuration based on a computer program including at least one instruction word stored in a storage device included in each configuration, and the storage device may include a non-volatile memory, a volatile memory, a flash memory, a hard disk drive (HDD), or a solid state drive (SSD), etc. Also, the processor may include at least one of a CPU (Central Processing Unit), a GPU (Graphic Processing Unit), an NPU (Neural Processing Unit), a RAM, a ROM, a system bus, and an application processor.

[0052] FIG. 2 is a drawing showing a reserve transaction method according to an exemplary embodiment of the present disclosure.

[0053] Referring to FIG. 2, the user terminal 200 can receive a reserve from the reserve receiving terminal 100 (T110). In one example, the user terminal 200 can receive a reserve by depositing the reserve corresponding to the account of the reserve receiving terminal 100.

[0054] The reserve receiving terminal 100 can load a reserve database in which account-specific reserves are stored (T120). In one embodiment, the reserve database can store a reserve corresponding to an account and a random value.

[0055] The reserve receiving terminal 100 can generate an account-specific commit value based on a commit key and an account-specific random value (T130). In one embodiment, the commit key can be generated and distributed by a trustworthy institution (e.g., various certification institutions), and the reserve receiving terminal 100 can utilize the publicly available commit key, random value, and reserve to generate a commit value as in Mathematical Formula 1.

[0056] The reserve receiving terminal 100 can generate a transaction on a smart contract based on the commit value (T140). In one embodiment, the reserve receiving terminal 100 can generate a transaction by concluding a new block in the smart contract based on the commit value. Zero-knowledge proof can be performed for the commit value corresponding to the generated transaction (T150). In one embodiment, CC-SNARK can be utilized to perform zero-knowledge proof for a commit value in the form of an exponent by the Pedersen commit form.

[0057] In one embodiment of the present disclosure, by generating a transaction for a reserve using a commit value in the form of an exponent, high-speed CC-SNARK can be utilized, and as a result, rapid proof and transaction can be made possible.

[0058] The reserve receiving terminal 100 can calculate an integrated commit value TCOM based on a commit key ck, an integrated random value R, and an integrated reserve TRsv (T160). In one embodiment, the reserve receiving terminal 100 can generate the integrated commit value TCOM by the method detailed in Mathematical Formula 2.

[0059] The reserve trustee terminal 100 can generate a data set including an integrated commit value TCOM, an integrated reserve TRsv, and a commitment key ck (T170). In one embodiment, the data set can further include an integrated random value R. The reserve trustee terminal 100 can bind the generated data set to the blockchain (T180). The network NW can store the data set (T190).

[0060] According to one embodiment of the present disclosure, the reserve trustee terminal 100 can utilize the reserve to generate a commitment value in the Pedersen form, and utilize this to perform a zero-knowledge proof, so that the auditing process for confirming whether the reserve trustee terminal 100 completely stores the reserve can proceed quickly, and the reliability of the user terminal 200 for the reserve trustee can be increased.

[0061] FIG. 3 is a drawing showing a reserve transaction method according to an exemplary embodiment of the present disclosure. Specifically, FIG. 3 shows a reserve transaction method when the reserve is updated. Contents overlapping with FIG. 2 are omitted.

[0062] Referring to FIG. 3, the user terminal 200 can update a first reserve corresponding to the account of the user terminal to the reserve trustee terminal 100 (T210). In one example, operations such as depositing an additional reserve of the user terminal 200 or withdrawing a previously deposited reserve can be included in the operation of updating the reserve.

[0063] The reserve trustee terminal 100 can utilize the first reserve to update the reserve database (T220). The reserve trustee terminal 100 can generate a first random value corresponding to the user's account (T230). In one embodiment, the reserve trustee terminal 100 can utilize a random number generator to generate the first random value.

[0064] The reserve trustee terminal 100 can generate a first commit value by utilizing a first random value, a commit key, and a first reserve (T240), and can update a smart contract by utilizing the first commit value (T250). A zero-knowledge proof can be performed on the first commit value (T260). In one embodiment, the zero-knowledge proof can be performed by a member included in the network NW.

[0065] The reserve trustee terminal 100 can update an integrated random value R and an integrated reserve TRsv based on the first random value and the first reserve (T270). The reserve trustee terminal 100 can calculate an integrated commit value corresponding to the updated integrated reserve (T275), and can generate a data set based on the updated integrated reserve and the calculated integrated commit value (T280).

[0066] The reserve trustee terminal 100 fastens the generated data set to the blockchain (T290), and the network can store the data set (T295).

[0067] FIG. 4 is a drawing showing a reserve contract method according to an exemplary embodiment of the present disclosure.

[0068] Referring to FIG. 4, the reserve receiving terminal 100 can store the reserve database DB_R. The reserve database DB_R can store a random value RV for each user account Acc and a reserve Rsv. In the example of FIG. 4, the first user 210 can receive the first reserve Rsv1, and the first random value RV1 randomly generated can be matched with the first reserve Rsv1 in the first account Acc1 corresponding to the first user 210. Also, the second user 220 can receive the second reserve Rsv2, and the second random value RV2 randomly generated can be matched with the second reserve Rsv2 in the second account Acc2 corresponding to the second user 220. Similarly, the third user 230 can receive the third reserve Rsv3, and the third random value RV3 randomly generated can be matched with the third reserve Rsv3 in the third account Acc3 corresponding to the third user 230.

[0069] Also, multiple users 210 to 230 can independently store their accounts, reserves, and random values. In one example, the first user 210 can store the first reserve Rsv1 and the first random value RV1 corresponding to the first account Acc1, the second user 220 can store the second reserve Rsv2 and the second random value RV2 corresponding to the second account Acc2, and the third user 230 can store the third reserve Rsv3 and the third random value RV3 corresponding to the third account Acc3.

[0070] The reserve trustee terminal 100 can calculate a plurality of commit values com1 to com3 based on the reserve Rsv and the random value RV, and perform contract results with a plurality of users 210 to 230, and upload or update the plurality of commit values com1 to com3 to the first network SC. Further, the reserve trustee terminal 100 generates an integrated commit value TCOM as a result of multiplying the plurality of commit values com1 to com3, generates an integrated reserve TRsv as a result of adding the plurality of reserves Rsv1 to Rsv3, and uploads or updates the integrated commit value TCOM, the integrated reserve TRsv, and the commit key ck to the second network BC.

[0071] In FIG. 4, an example in which the reserve is entrusted by three user terminals is illustrated, but this is only one embodiment, and it goes without saying that the technical idea of the present disclosure can also be applied to an example in which the reserve is entrusted by more or less than three user terminals.

[0072] FIG. 5 is a flowchart showing a reserve verification method according to an exemplary embodiment of the present disclosure.

[0073] Referring to FIG. 5, the user terminal 200 can obtain the integrated commit value TCOM, the integrated reserve TRsv, and the commit key ck from the network NW (T310). In one embodiment, the user terminal 200 can parse the integrated commit value TCOM, the integrated reserve TRsv, and the commit key ck from a data set bound to the blockchain network. The user terminal 200 can obtain a plurality of commit values com1 to comN from the smart contract (T320).

[0074] The user terminal 200 can verify the integrity of the integrated commit value TCOM based on a plurality of commit values com1 to comN and the integrated commit value TCOM (T330). In one embodiment, the user terminal 200 can verify the integrity of the integrated commit value TCOM based on whether the value obtained by multiplying the plurality of commit values com1 to comN acquired from the smart contract is the same as the integrated commit value TCOM.

[0075] If the sum of the reserves deposited by all users is the same as the total reserve held by the reserve receiving terminal 100, it can be proven that the reserve receiving terminal 100 stores all the reserves without omission. Also, according to the nature of the commit composed of the reserve and the power of the random value, the product of each commit value must be the same as the commit value for the total reserve by the exponential law. According to one embodiment of the present disclosure, by performing the integrity verification for the total reserve using the commit values com1 to comN and the integrated commit value TCOM, the verification for the reserve can be easily performed, and the assets of the user terminal 200 can be safely protected by performing the reserve verification.

[0076] Details of the method for verifying the integrity of the integrated commit value (T330) will be described in detail with reference to FIGS. 7 to 9 later.

[0077] Although the verification of the integrity of the integrated commit value (T330) is illustrated as being performed by the user terminal in FIG. 5, this is merely an example, and the verification of the integrity of the integrated commit value (T330) can be performed by an audit terminal (when tasting) of an audit institution that performs an audit on the reserve receiving institution 100.

[0078] In addition to verifying the integrity of the integrated commit value, the user terminal 200 can perform integrity verification for user assets. In this specification, user assets can mean the reserves entrusted by the user himself / herself and can be performed by an individual user terminal 200.

[0079] Specifically, the user terminal 200 can obtain the first commit value com1 corresponding to the user terminal 200 from among a plurality of commit values com1 to comN from the smart contract (T340). The user terminal 200 can calculate a verification commit value based on a commit key (including ck, the first key g, and the second key h) managed by itself, the first random value RV1, and the first reserve Rsv1. In one embodiment, the verification commit value comv can be calculated by the following mathematical formula 3.

[0080]

Equation

[0081] The user terminal 200 can verify the integrity of the first commit value com1 based on whether the verification commit value comv is the same as the first commit value com1.

[0082] According to an embodiment of the present disclosure, the user terminal 200 does not disclose the reserved amount, and can confirm whether its reserve is accurately deposited based on the disclosed commit value instead of the reserve. As a result, according to the reserve verification method, it is possible to confirm whether the user's assets are fully entrusted without disclosing the reserve, which is the user's personal information, and the auditing function for the reserve trustee 100 can be efficiently performed.

[0083] In one embodiment, the user terminal 200 can additionally confirm whether the first commit value com1 is a correctly generated value by performing a zero-knowledge proof algorithm for the first commit value com1.

[0084] FIG. 6 is a drawing showing a reserve verification method according to an exemplary embodiment of the present disclosure. Specifically, FIG. 6 shows in detail the integrity verification stage (T340 to T360) of the user's commit value. Contents overlapping with FIG. 4 are omitted.

[0085] Referring to FIG. 6, the first user 210 can obtain a first commit value com1 corresponding to the first account Acc1 of the first user 210 from the smart contract sc. The first user 210 can calculate a verification commit value comv based on the user data Duser1. In one example, the first user 210 can calculate the verification commit value based on Mathematical Formula 3.

[0086] The first commit value com1 is a value generated by the reserve trustee institution 100 based on the first random value RV and the first reserve Rsv, and the first reserve Rsv cannot be extracted from the first commit value com1 unless the first random value RV is exposed. That is, according to an embodiment of the present disclosure, instead of the first reserve Rsv corresponding to personal information, the encrypted first commit value com1 is publicly disclosed, and the verification operation can be performed by utilizing the first commit value com1.

[0087] Also, since the first commit value com1 is a value generated based on the reserve amount deposited with the reserve trustee institution 100, and the verification commit value comv is a value generated based on the amount recorded as being deposited by the first user terminal 210, if the reserve is properly deposited, the two values must be the same. Therefore, the first user 210 can verify the first commit value com1 by comparing the verification commit value with the first commit value com1. In a similar manner, the second user 220 and the third user 230 can also verify the second commit value com2 and the third commit value com3, respectively. According to an embodiment of the present disclosure, it is possible to verify whether the user's assets are properly deposited by comparing the commit value with the verification commit value without using the reserve, and the user assets can be effectively protected by such a verification procedure.

[0088] FIG. 7 is a flowchart showing a reserve verification method according to an exemplary embodiment of the present disclosure. Specifically, FIG. 7 shows in detail the integrity verification stage (T330) of the integrated commit value.

[0089] Referring to FIG. 7, the user terminal 200 can perform a product operation on a plurality of commit values (T331). As detailed in Mathematical Formula 2, when the integrated reserve TRsv matches the total amount deposited by all users, based on the homomorphic property of the pedal sen commit, the sum of the commit values of all users must be the same as the integrated commit value TCOM determined based on the integrated reserve TRsv.

[0090] The user terminal 200 can compare the multiplied result value with the integrated commit value TCOM (T332). If the multiplied result value is the same as the integrated commit value (T333), the user terminal 200 can determine that it has succeeded in verifying the integrity of the integrated commit value TCOM (T334). If the multiplied result value is not the same as the integrated commit value (T333), the user terminal 200 can determine that it has failed in verifying the integrity of the integrated commit value TCOM (T335).

[0091] According to an embodiment of the present disclosure, by utilizing the properties of the pedal sen commit to verify the integrated commit value, it is possible to verify whether all reserves have been fully received, and as a result, fast verification of the reserves may be possible.

[0092] FIG. 8 is a flowchart showing a reserve verification method according to an exemplary embodiment of the present disclosure. Specifically, FIG. 8 shows in detail the integrity verification stage (T330) of the integrated commit value.

[0093] Referring to FIG. 8, the user terminal 200 can receive a first verification value and a second verification value (S331). In one embodiment, the first verification value t and the second verification value s can be generated by the reserve receiving terminal 100 or the certification authority.

[0094] In one embodiment, for the commit keys g, h, any integer (a), the integrated random value RV, the integrated commit value TCOM, the integrated reserve TRsv, and the first value y, the first verification value t and the second verification value s can be generated as shown in the following Mathematical Formula 4. (hash is a hash function)

[0095]

Number

[0096] The user terminal 200 can obtain the first value y (S332). In one embodiment, the user terminal 200 can obtain the first value y through an authentication institution or a supervision institution.

[0097] The user terminal 200 can calculate the hash value c by hashing the first value y, the commit keys g, h, and the first verification value t (S333). The user terminal 200 can determine the appropriateness of the integrated commit value based on whether the result of operating on the hash value c, the first value y, and the first verification value t is the same as the result of operating on the commit keys g, h, and the second verification value s (S334). In one embodiment, the user terminal 200 can determine the appropriateness of the integrated commit value based on whether the following mathematical formula 5 is satisfied.

[0098]

Number

[0099] According to an embodiment of the present disclosure, the appropriateness of the integrated commit value TCOM can be determined by using the first value y instead of the random value RV. Accordingly, an asset outflow accident that may occur due to the exposure of the random value RV can be prevented, and as a result, the safety of the reserve management system 10 can be improved.

[0100] FIG. 9 is a drawing showing a reserve verification method according to an exemplary embodiment of the present disclosure. Specifically, FIG. 9 shows in detail the integrity verification stage (T330) of the integrated commit value. The content overlapping with FIG. 4 is omitted.

[0101] Referring to FIG. 9, the auditing terminal 300 can receive the first verification value t and the second verification value s generated by the reserve trustee terminal 100 based on Mathematical Formula 4. Further, the auditing terminal 300 can obtain the integrated commit value TCOM, the integrated reserve TRsv, and the commit key ck from the second network BC. Further, the auditing terminal 300 can additionally obtain the first value y from a supervision institution or the like. In still other embodiments, the auditing terminal 300 can calculate the first value y based on the integrated commit value TCOM, the integrated reserve TRsv, and the commit key ck based on Mathematical Formula 4.

[0102] The auditing terminal 300 calculates the hash value c based on the first key h, the first value, and the first verification value t, and can primarily verify the integrated commit value TCOM based on whether the hash value c, the first key h, the first value y, the first verification value t, and the second verification value s satisfy Mathematical Formula 5.

[0103] The auditing terminal 300 can obtain a plurality of commit values com1 to com3 from the smart contract sc and obtain the integrated commit value TCOM from the second network BC. The auditing terminal 300 can secondarily verify the integrity of the integrated commit value by comparing the product of the plurality of commit values com1 to com3 with the integrated commit value TCOM based on Mathematical Formula 2.

[0104] According to an embodiment of the present disclosure, by secondarily verifying based on the commit value in the Pedersen commit form, the auditing terminal 300 can first utilize CC-SNARK, which is a high-speed zero-knowledge proof, and as a result, high-speed verification is possible. Further, by verifying using the commit values com1 to comN and the first value y instead of random values, the auditing terminal 300 can prevent the random values from being externally exposed, and as a result, the stability of the reserve management system 10 can be improved.

[0105] FIG. 10 is a block diagram showing a computing system according to an exemplary embodiment of the present disclosure.

[0106] Referring to FIG. 10, the computing system 1000 can be configured as either one of the reserve trustee terminal 100 and the user terminal 200, and can include a processor 1100, a memory device 1200, a storage device 1300, a power supply 1400, and a display device 1500. On the other hand, although not shown in FIG. 10, the computing system 1000 can further include a port that can communicate with a video card, a sound card, a memory card, a USB device, etc., or can communicate with other electronic devices.

[0107] Thus, the processor 1100, the memory device 1200, the storage device 1300, the power supply 1400, and the display device 1500 included in the computing system 1000 constitute either one of the reserve trustee terminal 100 and the user terminal 200 according to an embodiment based on the technical idea of the present invention, and can perform a reserve contract method and a reserve verification method. Specifically, the processor 1100 can perform the reserve contract method and the reserve verification method detailed in FIGS. 1 to 9 by controlling the memory device 1200, the storage device 1300, the power supply 1400, and the display device 1500.

[0108] The processor 1100 can perform specific calculations or tasks. According to an embodiment, the processor 1100 can be a micro-processor or a Central Processing Unit (CPU). The processor 1100 can communicate with the memory device 1200, the storage device 1300, and the display device 1500 through a bus 1600 such as an address bus, a control bus, and a data bus. According to an embodiment, the processor 1100 can also be connected to an expansion bus such as a Peripheral Component Interconnect (PCI) bus.

[0109] The memory device 1200 can store data necessary for the operation of the computing system 1000. For example, the memory device 1200 can be embodied in dynamic random access memory (DRAM), mobile DRAM, static random access memory (SRAM), phase change random access memory (PRAM), ferroelectric random access memory (registered trademark: FRAM), resistive random access memory (RRAM), and / or magnetic random access memory (MRAM). The storage device 1300 can include a solid state drive, a hard disk drive, a CD-ROM, and the like. The storage device 1300 can store programs, application data, system data, operation system data, etc. related to the reservation contract method and the reservation verification method detailed in FIGS. 1 to 10.

[0110] The display device 1500 is an output means for performing notifications to the user, and can display and notify information about the virtual private network formation method to the user and the like. The power supply device 1400 can supply the operating voltage necessary for the operation of the computing system 1000.

[0111] As described above, exemplary embodiments have been invented in the drawings and the specification. Although specific terms have been used in this specification to describe the embodiments, this is merely for the purpose of explaining the technical idea of the present invention, and is not used to limit the meaning or the scope of the present invention described in the claims. Therefore, those of ordinary skill in the art will understand that various modifications and equivalent other embodiments will be possible hereafter. Therefore, the true technical protection scope of the present invention should be determined by the technical idea of the appended claims.

[0112] This research (invention) was supported by a grant from the Institute of Information & communications Technology Planning & Evaluation (IITP) funded by the Korean government (MSIT) (No. 2021-0-00532-003, Project Name: Blockchain Technology Development for IITP Data Economy, Task Name: Blockchain scalability solutions supporting high performance / capacity transactions, Contribution Rate: 100%).

Claims

1. In a reserve contract method performed by at least one processor, loading a reserve database in which a plurality of reserves corresponding to a plurality of accounts are stored; generating a plurality of commit values respectively corresponding to the plurality of accounts by using a commit key and a plurality of random values, the step of generating the plurality of commit values by performing a zero-knowledge proof method; generating a transaction on a smart contract based on the calculated plurality of commit values; calculating an integrated commit value based on the commit key, an integrated random value corresponding to the sum of the plurality of random values, and an integrated reserve corresponding to the sum of the plurality of reserves; and generating a data set including the integrated commit value, the integrated reserve, and the commit key; fastening the generated data set to a blockchain to verify the integrity of the integrated commit value; receiving a first reserve corresponding to a first account among the plurality of accounts; updating the reserve database by utilizing the first reserve; generating a first random value corresponding to the first account; generating a first commit value corresponding to the first account based on the first random value, the commit key, and the first reserve; updating the smart contract by utilizing the first commit value; updating the integrated random value based on the first random value; updating the integrated reserve; obtaining the integrated commit value based on the commit key, the updated integrated reserve, and the updated integrated random value; and generating a data set including the integrated commit value, the integrated reserve, and the commit key; A reserve contract method including the above steps.

2. The reserve contract method according to claim 1, further including the step of uploading the data set to a network.

3. The step of generating the plurality of commit values includes performing an operation on each of the plurality of commit values in the form of a power of the reserve and the random value of the commit key; The reserve contract method according to claim 1.

4. The commit key (com i ) includes a first key (g) and a second key (h), The step of generating the plurality of commit values is For the reserve (m i ) corresponding to the i-th (i is a natural number) account and the random value ri, the following formula is utilized to generate a commit value (com i ), the reserve contract method according to claim 3, characterized in that. 【Number 9】

5. performed by at least one processor, in a method of proving reserves that utilizes a zero knowledge proof algorithm, a step of obtaining an integrated commit value, the integrated commit value being calculated based on a commit key, an integrated random value corresponding to the sum of a plurality of random values, and an integrated reserve corresponding to the sum of a plurality of reserves; a step of obtaining, from a smart contract, a plurality of commit values respectively corresponding to a plurality of accounts from a plurality of account owners, and generating the plurality of commit values by performing a zero knowledge proof method; a step of verifying the integrity of the integrated commit value based on the plurality of commit values and the integrated commit value; and a step of verifying the integrity of the first commit value based on the commit key, a first random value corresponding to a first user, a first reserve, and the first commit value; comprising The step of verifying the integrity of the integrated commit value is a step of receiving a first verification value and a second verification value; a step of obtaining a first value; a step of hashing the first value, the commit key, and the first verification value to calculate a hash value; and a step of determining the integrity of the integrated commit value based on whether the result of calculating the hash value, the first value, and the first verification value is the same as the result of calculating the commit key and the second verification value; A reserve verification method comprising.

6. The step of verifying the integrity of the integrated commit value is a step of multiplying all of the plurality of commit values; a step of comparing the multiplied result value with the integrated commit value; and a step of verifying the integrity of the integrated commit value when, as a result of the comparison, the multiplied result value and the integrated commit value are the same; The reserve verification method according to claim 5, comprising.

7. The commit key includes a first key (g) and a second key (h), and when the integrated reserve is (TR sv ), and the integrated commit value is TCOM, the first value (y) is calculated by the following formula, the reserve verification method according to claim 5. 【Number 10】

8. When the first verification value is t, the second verification value is s, and the hash value is c, the reserve verification method according to claim 7, characterized in that it is determined that the integrated commit value is appropriate when the following formula is satisfied. 【Number 11】

9. The step of verifying the integrity of the integrated commit value is The reserve verification method according to claim 5, characterized in that it is verified without the integrated random value utilized in the calculation of the integrated commit value.

10. The step of verifying the integrity of the first commit value includes: The step of obtaining the commit key; The step of calculating a verification commit value based on the commit key, the first secret key, and the first reserve; and The step of verifying the integrity of the first commit value by comparing the verification commit value with the first commit value obtained from the smart contract; The reserve verification method according to claim 5.

11. The reserve verification method according to claim 10, characterized in that when verifying the integrity of the first commit value, it is verified that the first reserve is reflected in the integrated reserve.

12. The reserve verification method according to claim 5, characterized in that the integrated commit value is obtained from a blockchain network.

Citation Information

Patent Citations

  • Multi-cloud data storage method based on block chain

    CN111698278A

  • Systems and methods for protecting information

    JP2019537744A

  • Computer-implemented system and method for exchanging data

    JP2021518685A

  • How to generate random numbers in a blockchain smart contract

    JP2022523643A

  • Signature generation method, electronic device, and storage medium

    US20200076586A1