Hadamard Product Proof Method and Apparatus

The method and apparatus for proving the Hadamard product without a trusted setup address the inefficiencies of existing methods by using a processor to generate random vectors and eliminate random values, enabling efficient and cost-effective verification in zero-knowledge proof systems.

JP7692132B2Active Publication Date: 2025-06-13INDUSTRY UNIVERSITY COOPERATION FOUNDATION HANYANG UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023223348
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-10-31
Filing Date
2023-12-28
Publication Date
2025-06-13
Estimated Expiration
2043-12-28

AI Technical Summary

Technical Problem

Existing methods for proving the Hadamard product in zero-knowledge proof systems require a trusted setup, which is inefficient and limits their application in constraint systems like R1CS.

Method used

A method and apparatus for proving the Hadamard product without a trusted setup, utilizing a processor to generate a random vector, perform inner product proof, and eliminate random values from the calculation process, allowing the use of the most efficient inner product proof method (Dory).

Benefits of technology

Enables efficient Hadamard product proof without a trusted setup, reducing verification costs for the verifier and allowing its use in constraint systems like R1CS for concise non-interactive zero-knowledge proofs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007692132000022
    Figure 0007692132000022
  • Figure 0007692132000023
    Figure 0007692132000023
  • Figure 0007692132000024
    Figure 0007692132000024
Patent Text Reader

Abstract

To provide a method and a device for proving the Hadamard product without setting reliability.SOLUTION: A method for proving the Hadamard product in a device including at least one processor includes steps of: receiving a random value from a verifier's terminal; generating a random vector using the random value; generating a proof value for the Hadamard product of a first target vector and a second target vector using the random vector and an inner product proof; and transmitting the proof value to the verifier's terminal.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a Hadamard product proof method and apparatus, and more particularly, to a method and apparatus for proving a Hadamard product without a trusted setup.

Background Art

[0002] The Hadamard product is an operation that multiplies each component of two vectors of the same length. Through the Hadamard product, a vector of the same length as the input vector is output as the result of the operation. The Hadamard product operation is utilized in succinct non-interactive zero-knowledge proofs (zk-SNARKs), and by succinctly proving the Hadamard product operation, a more efficient zero-knowledge proof protocol is developed.

[0003] Proving the Hadamard product is to prove that the result of the Hadamard product operation of two given vectors is correct. According to the paper "Linear algebra with sub-linear zero-knowledge arguments Groth, Jens, Annual International Cryptology Conference. Berlin, Heidelberg: Springer Berlin Heidelberg, 2009.", the proof of the Hadamard product is known to be performed through inner product proof (IPA). Inner product proof is a method of proving that the result of the inner product operation of two committed vectors is correct without disclosing the two committed vectors. That is, the proof of the Hadamard product using inner product proof is performed by converting the Hadamard product into an inner product operation and then checking whether the result of the inner product operation is correct through inner product proof.

[0004] Among such inner product proof methods, the inner product proof method known as the most efficient one without trust setup is the method presented in the paper "Dory: Efficient, Transparent arguments for Generalised Inner Products and Polynomial Commitments. Lee, Jonathan. 'Theory of Cryptography Conference'. Springer, Cham, 2021." However, when proving the Hadamard product of two vectors through inner product proof, although the random values used in the proof process are included in the inner product operation result of the vectors, the above-mentioned most efficient inner product proof method (Dory) is a method in which the verifier verifies the operations on the prover's commitment key, so it cannot be used for Hadamard product proof.

[0005] Therefore, there is a need for a method to prove the Hadamard product without trust setup by utilizing the above-mentioned most efficient inner product proof method (Dory).

Prior Art Documents

Patent Documents

[0006]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0007] The present invention has been made in view of the above conventional problems, and an object of the present invention is to provide a Hadamard product proof method and apparatus that are efficiently performed without trust setup.

Means for Solving the Problems

[0008] The method for proving the Hadamard product of an apparatus comprising at least one processor according to an aspect of the present invention made to achieve the above object includes: a step of receiving a random value from a verifier's terminal by the processor; a step of generating a random vector using the random value; a step of generating a proof value for the Hadamard product of a first target vector and a second target vector using the random vector and inner product proof; and a step of transmitting the proof value to the verifier's terminal.

[0009] The method for proving the Hadamard product of an apparatus comprising at least one processor according to another aspect of the present invention made to achieve the above object includes: a step of receiving a random value from a verifier's terminal by the processor; a step of generating a random vector using the random value; a step of generating a proof value for the Hadamard product of a first target vector and a second target vector by using the random vector and inner product proof and eliminating the random value in the calculation process of the inner product proof; and a step of transmitting the proof value to the verifier's terminal.

[0010] The Hadamard product proof apparatus according to an embodiment of the present invention made to achieve the above object includes: a communication module that receives a random value from a verifier's terminal and transmits a proof value to the verifier's terminal; a memory; and at least one processor electrically connected to the memory, wherein the processor is configured to generate a random vector using the random value and generate the proof value for the Hadamard product of a first target vector and a second target vector using the random vector and inner product proof.

Advantages of the Invention

[0011] According to the present invention, Hadamard product proof is possible without a trust setup, thereby reducing the verification cost of the verifier. Therefore, it can be efficiently utilized in a constraint system such as R1CS used for simple non-interactive zero-knowledge proof.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Embodiments for Carrying Out the Invention

[0013] The present invention can have various modifications and various embodiments, and specific embodiments are illustrated in the drawings and will be described in detail in the detailed description. However, this is not intended to limit the present invention to specific embodiments, and it should be understood to include all modifications, equivalents, or alternatives included in the spirit and technical scope of the present invention. When explaining each drawing, similar reference numerals are used for similar components.

[0014] As described above, since the Hadamard product proof using the inner product proof includes random values in the inner product operation result of the vector, the most efficient inner product proof method (Dory) cannot be used for the proof of the Hadamard product.

[0015] Therefore, the present invention proposes a Hadamard product proof method that eliminates random values from the inner product operation result of a vector and performs the inner product operation in order to be able to use the most efficient inner product proof method (Dory) for the Hadamard product proof. In one embodiment of the present invention, a random elimination folding technique used for inner product proof is utilized to eliminate random values from the inner product operation result of the vector.

[0016] According to an embodiment of the present invention, it is possible to prove an Hadamard product without a trust setting, thereby reducing the verification cost of a verifier. Therefore, it can be efficiently utilized in a constraint system such as R1CS that is used for a concise non-interactive zero-knowledge proof.

[0017] The Hadamard product proof method according to an embodiment of the present invention is performed by a computing device including a communication module, a memory, and at least one processor electrically connected to the memory.

[0018] Hereinafter, specific examples of embodiments for implementing the present invention will be described in detail with reference to the drawings.

[0019] FIG. 1 is a diagram for explaining the Hadamard product proof method of a prover and a verifier according to an embodiment of the present invention.

[0020] Referring to FIG. 1, a prover (the computing device of the prover, hereinafter omitted) transmits (S110) a commitment value for first and second target vectors that are the objects of the Hadamard product to a verifier (the terminal of the verifier, hereinafter omitted). The commitment value is transmitted to the verifier in order to prevent the prover from operating on the first and second target vectors.

[0021] Then, the verifier generates a random value and transmits it (S120) to the prover.

[0022] The prover generates (S130) a proof value for Hadamard product proof using the random value. That is, the proof value is a value for the verifier to verify that the calculation result of the Hadamard product for the first and second target vectors is correct, and the method for generating the proof value will be described in detail with reference to FIG. 2 later.

[0023] The prover transmits (S140) the generated proof value to the verifier, and the verifier verifies (S150) whether the calculation result of the Hadamard product of the first target vector and the second target vector is correct using the proof value.

[0024] FIG. 2 is a flowchart for explaining a Hadamard product proof method according to an embodiment of the present invention. In FIG. 2, a Hadamard product proof method performed by a prover's computing device is described as an embodiment.

[0025] Referring to FIG. 2, a computing device according to an embodiment of the present invention receives a random value from a verifier (S210) and generates a random vector using the random value (S220). As described above, before receiving the random value, the computing device transmits the agreed values for the first and second target vectors to the verifier.

[0026] The computing device generates a random vector represented by the following [Equation 1]. Here, the length of the random vector is the same as the lengths of the first and second target vectors.

[0027]

Equation

[0028] Here, γ is a random value, m represents the lengths of the first and second target vectors, and the length of the vector corresponds to the number of elements of the vector.

[0029] Then, the computing device generates a proof value for the Hadamard product of the first target vector and the second target vector using the random vector and the inner product proof (S230), and transmits the generated proof value to the verifier (S240). The computing device generates a proof value for the Hadamard product of the first target vector and the second target vector by eliminating the random value in the calculation process of the inner product proof, and uses the random value elimination folding technique to eliminate the random value.

[0030] As an embodiment, the computing device uses the following [Equation 2] for the w 1 vector and w 2Generate a vector and generate a proof value indicating whether the following [Mathematical Formula 2] and the following [Mathematical Formula 3] are satisfied. At this time, the computing device is w 1 vector and w 2 By also transmitting the commitment values for the vector and the w 1 vector to the verifier, the prover is prevented from operating on the w 2 vector and the w

[0031]

Number

[0032]

Number

[0033] Here, TIFF0007692132000004.tif8136 is the Hadamard product, <> is the inner product operation, r is a random vector, v 1 is the first target vector, and u represents the Hadamard product operation value of the first target vector and the second target vector.

[0034] The computing device uses the following [Mathematical Formula 4] to generate a proof value for the above [Mathematical Formula 2] in order to eliminate the random value and generate a proof value. Here, v 2 represents the second target vector.

[0035]

Number

[0036] In the above [Mathematical Formula 4], TIFF0007692132000006.tif10129 is a mathematical formula for generating a proof value for in the above [Mathematical Formula 2]. In the above [Mathematical Formula 4], TIFF0007692132000008.tif10129 is the mathematical formula for generating a proof value for TIFF0007692132000009.tif8128.

[0037] The computing device uses the random value elimination folding technique to generate scalar values for the left and right sides of the above [Mathematical Formula 3] and the above [Mathematical Formula 4] as proof values. That is, instead of calculating the inner product of the above [Mathematical Formula 3] and the above [Mathematical Formula 4] in a form containing random values, the computing device uses the random value elimination folding technique to calculate scalar values for the left and right sides of the above [Mathematical Formula 3] and the above [Mathematical Formula 4] in a form where the random values are eliminated. The computing device calculates the inner product of vectors containing random values, that is Applies the random value elimination folding technique to TIFF0007692132000010.tif9128 to calculate a scalar value.

[0038] By eliminating the random values, the inner product results of the left and right sides of the above [Mathematical Formula 3] and the above [Mathematical Formula 4] become the same. Therefore, the verifier can confirm whether the Hadamard product operation value of the first target vector and the second target vector is correct by verifying whether the scalar values for the left and right sides of the above [Mathematical Formula 3] and the above [Mathematical Formula 4] are the same.

[0039] The random value elimination folding technique is a technique that divides the elements of a vector containing random values into two equal parts in the listed order, and then combines the elements of the divided vectors with each other to reduce the vector length. At this time, the inverse value of the random value is multiplied by the vector containing the higher-order random value among the divided vectors so that the degrees of the elements at the same positions contained in each of the divided vectors are the same.

[0040] For example, w 1When the vector is as shown in the following [Mathematical Formula 5], the computing device is w 1 vector After dividing it into TIFF0007692132000011.tif12128, Multiply by TIFF0007692132000012.tif12128.

[0041]

Number

[0042] And when the elements of the divided vectors are combined with each other, the length of the w1 vector decreases as shown in the following [Mathematical Formula 6].

[0043]

Number

[0044] In this way, w 1 Until the length of the vector becomes 1, w 1 When the random value erasure folding technique is applied to the vector, w 1 Since the vector will contain one element without random values, the inner product operation values in the above [Mathematical Formula 3] and the above [Mathematical Formula 4] will also not contain random values.

[0045] According to an embodiment of the present invention, by eliminating random values from the inner product operation result of the vector, the most efficient inner product proof method (Dory) can be applied to the Hadamard product proof. Therefore, Hadamard product proof is possible without a trust setup, and the verification cost of the verifier is maintained at O(log m).

[0046] FIG. 3 is a diagram for explaining a Hadamard product proof apparatus according to an embodiment of the present invention.

[0047] Referring to FIG. 3, a Hadamard product proof apparatus according to an embodiment of the present invention includes a memory 310, at least one processor 320, and a communication module 330.

[0048] A processor 320 electrically connected to the memory 310 performs a series of processes for the Hadamard product proof described above. The processor 320 generates a random vector using a random value, and generates a proof value for the Hadamard product of the first target vector and the second target vector using the random vector and the inner product proof. At this time, the random value is eliminated in the operation process of the inner product proof to generate a proof value for the Hadamard product.

[0049] Then, the communication module 330 receives a random value from the verifier and transmits the proof value for the Hadamard product of the first target vector and the second target vector to the verifier.

[0050] The above-described technical content can be embodied in the form of program instructions executed through various computer means and recorded on a computer-readable recording medium. The computer-readable recording medium includes program instructions, data files, data structures, etc. alone or in combination. The program instructions recorded on the recording medium are either specially designed and configured for the embodiments or are available and known to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy (registered trademark) disks, and magnetic tapes, optical media such as CD-ROMs, DVDs, magneto-optical media such as floptical disks, and hardware devices specially configured to store and execute program instructions such as ROMs, RAMs, and flash memories. Examples of program instructions include not only machine language codes made by compilers but also high-level language codes executed by computers using interpreters and the like. The hardware device can be configured to operate with one or more software modules to perform the operations of the embodiments, and vice versa.

[0051] As described above, the embodiments of the present invention have been described in detail with reference to the drawings. However, the present invention is not limited to the above-described embodiments, and various modifications can be made without departing from the technical idea of the present invention.

Explanation of Reference Numerals

[0052] 310 Memory 320 Processor 330 Communication Module

Claims

1. A method for proving the Hadamard product of a device comprising at least one processor, comprising: by the processor, receiving a random value from a verifier's terminal; generating a random vector using the random value; generating a proof value for the Hadamard product of a first target vector and a second target vector using the random vector and inner product proof; transmitting the proof value to the verifier's terminal, the step of generating the proof value generates a w1 vector and a w2 vector using the following Mathematical Formula 2, generates the proof value indicating whether the following Mathematical Formula 2 and the following Mathematical Formula 3 are satisfied, generates a proof value for the following Mathematical Formula 2 using the following Mathematical Formula 4, and uses the random value elimination folding technique to generate scalar values for the left and right sides of the following Mathematical Formula 3 and the following Mathematical Formula 4 as the proof value, the scalar value is a value obtained by eliminating the random value, and the Hadamard product proof method is characterized in that. 【Number 2】 【Mathematics 3】 【Number 4】 Here, r is the random vector, v1 is the first target vector, u is the Hadamard product operation value of the first target vector and the second target vector, and v2 is the second target vector.

2. The Hadamard product proof method according to claim 1, wherein the random vector is a vector represented by the following Mathematical Formula 1. 【Number 1】 Here, γ is the random value, and m is the length of the first target vector and the second target vector.

3. The Hadamard product proof method according to claim 1, wherein the verifier's terminal verifies whether scalar values for the left and right sides of the Mathematical Formula 3 and the Mathematical Formula 4 are the same.

4. The processor further transmits, to the verifier's terminal, the first target vector, the second target vector, the w 1 vector, and the w 2 vector, and a commitment value for the w vector. The Hadamard product proof method according to claim 1, characterized by further comprising the step of transmitting the commitment value for the w vector to the verifier's terminal.

5. a communication module that receives a random value from a verifier's terminal and transmits a proof value to the verifier's terminal; a memory; at least one processor electrically connected to the memory, the processor generates a random vector using the random value, is configured to generate the proof value for the Hadamard product of a first target vector and a second target vector using the random vector and inner product proof, The processor is configured to generate a w1 vector and a w2 vector using the following mathematical formula 2, generate the proof value indicating whether the following mathematical formula 2 and the following mathematical formula 3 are satisfied, generate a proof value for the following mathematical formula 2 using the following mathematical formula 4, and generate scalar values for the left and right sides of the following mathematical formula 3 and the following mathematical formula 4 as the proof value using a random value elimination folding technique. The scalar value is an Hadamard product proof device characterized in that the value is obtained by eliminating the random value. 【Number 2】 [Number 3] [Number 4] Here, r is the random vector, v1 is the first target vector, u represents the Hadamard product operation value of the first target vector and the second target vector, and v2 represents the second target vector.

Citation Information

Patent Citations

  • Zero knowledge range proving method based on Lagrange three-integer theorem and inner product with constant size

    CN113886871A

  • Variable optimization system

    JP2022184274A