A computer-implemented system and method for serialization of arithmetic circuits
By compressing arithmetic circuits using entropy encoding and simplification rules, the method addresses the inefficiencies in blockchain systems, reducing storage and computational resources while maintaining data integrity.
Patent Information
- Application Number
- JP2024006284
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2018-03-27
- Filing Date
- 2024-01-18
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2039-03-15
AI Technical Summary
Existing blockchain-based systems face inefficiencies in storing and executing arithmetic circuits due to large data footprints, which can be addressed by lossless compression and serialization techniques to reduce storage requirements and improve computational efficiency.
A method for compressing arithmetic circuits using entropy coding and simplification rules, allowing for lossless reconstruction, which includes removing redundant data fields and applying entropy encoding to reduce the data footprint, enabling efficient storage and transmission.
The method reduces the data storage and computational resources required for arithmetic circuits, enhancing data transmission bandwidth and hardware efficiency in blockchain networks.
Smart Images

Figure 0007711237000005 
Figure 0007711237000006 
Figure 0007711237000007
Abstract
Description
Technical Field
[0001] The present invention generally relates to techniques for reducing the data footprint used by arithmetic circuits (e.g., when stored on a disk or in memory), and more particularly to techniques for generating serialization circuits from arithmetic services using the compression techniques described herein. The arithmetic circuit may be compressed in a lossless manner to generate a serialization circuit that can be used to generate the original circuit at a later time. The arithmetic circuit may be used to generate a program. Execution of the program may be delegated to one or more nodes in a distributed computing environment. A protocol may be used to ensure correct execution of the program. Here, a first computer system delegates execution of the program to a second computer system. The present invention is particularly suitable for use in blockchain networks, but is not limited thereto.
Background Art
[0002] In this specification, we use the term "blockchain" to encompass all forms of electronic, computer-based, distributed ledgers. These include consensus-based blockchains and transaction chain technologies, permissioned and permissionless ledgers, shared ledgers, and variations thereof. While other blockchain implementations have been proposed and developed, the most widely known application of blockchain technology is the Bitcoin ledger. Bitcoin is referred to here for convenience and illustrative purposes, but the present invention is not limited to use with the Bitcoin blockchain, and alternative blockchain implementations and protocols are within the scope of the present invention. It should be noted that the term "Bitcoin" is considered to include any protocol derived from or a variation of the Bitcoin protocol in this specification.
[0003] A blockchain is a peer-to-peer electronic ledger implemented as a computer-based decentralized distributed system, composed of blocks, which are in turn composed of transactions. Each transaction is a data structure that encodes the transfer of control of digital assets between participants in the blockchain system and includes at least one input and at least one output. Each block contains the hash of the previous block, and these blocks are linked together to produce a permanent and immutable record of all the transactions written to the blockchain since its origin. Transactions contain small programs known as scripts. Scripts embed their inputs and outputs and specify how and by whom the outputs of the transaction are accessible. In the Bitcoin platform, these scripts are written using a stack-based scripting language.
[0004] For a transaction to be written to the blockchain, it must be verified. Network nodes (miners) perform work to ensure that invalid transactions are rejected from the network and that each transaction is valid. The software client installed on the nodes performs this verification work on the unspent transaction (UTXO) by executing the lock and unlock scripts of the UTXO. If the execution of the lock and unlock scripts evaluates to true, the transaction is valid and the transaction is written to the blockchain. Thus, for a transaction to be written to the blockchain, it is necessary that (i) it is verified by the first node that receives the transaction and, if the transaction is valid, the node relays the transaction to other nodes within the network, (ii) it is added to a new block constructed by the miner, and (iii) it is mined, i.e., added to the public ledger of past transactions.
[0005] Blockchain technology is most widely known for its use in the implementation of cryptocurrencies, but digital entrepreneurs are beginning to develop the use of both Bitcoin-based cryptographic security systems and data that can be stored on the blockchain for implementing new systems. If the blockchain can be used for automated tasks and processes that are not limited to the field of cryptocurrencies, it would be highly advantageous. Such solutions can diversify their applications while leveraging the benefits of the blockchain (e.g., permanence, tamper resistance of event records, distributed processing, etc.).
[0006] One area of current research is the use of blockchain-based computer programs for the implementation of "smart contracts." These are computer programs designed to automate the execution of machine-readable contracts or the terms of an agreement. Unlike traditional contracts written in natural language, smart contracts are machine-executable programs that contain rules for processing inputs to generate results, which then cause actions to be executed depending on those results. SUMMARY OF THE INVENTION
[0007] Accordingly, it is desirable to provide a method for lossless compression and serialization of a bitstream of an arithmetic circuit. Serialization of the circuit can provide various advantages in the context of circuit templates (e.g., circuits or sub-circuits to be reused) or standard circuits that need to be stored and read. In this way, by eliminating the need for encoding and computing entities to repeatedly generate instances of circuits or sub-circuits for multiple programs having shared circuits or sub-circuits, performance improvement can be achieved. The arithmetic circuit can be efficiently compressed using entropy coding for the most frequent elements within a data structure such as arithmetic operator types. Instructions for deserialization and decompression can also be embedded in the bitstream, thereby enabling the original circuit to be reconstructed losslessly.
[0008] Such an improved solution is devised here.
[0009] Accordingly, according to the present invention, a system and / or method as defined in the appended claims are provided.
[0010] According to the present invention, a method implemented by a computer for a node of a blockchain network, wherein the method implemented by the computer is usable for reducing a data footprint of an arithmetic circuit, the method comprising: removing a first subset of data fields of a set of data fields related to the arithmetic circuit, the first subset of the data fields being obtainable from a second subset of the data fields of the set of the data fields, the first subset and the second subset being independent sets; applying an entropy coding scheme to the second subset to generate a compressed arithmetic circuit; There may be provided a method including reducing the data footprint of the arithmetic circuit thereby. The resulting compressed arithmetic circuit may be stored as data in a volatile memory (e.g., RAM), a data storage system (e.g., a hard disk drive), etc.
[0011] Preferably, the first subset of the data fields includes identifiers of an input set to the arithmetic circuit, and the second subset includes the cardinality of the input set. The cardinality of the set (alternatively, the cardinal number of the set) may represent the number of inputs in the input set. Thus, the compressed circuit can be represented using fewer data bits than the uncompressed circuit.
[0012] Preferably, the first subset of the data fields includes identifiers of a gate output set of the arithmetic circuit. Thus, the compressed circuit can be represented using fewer data bits than the uncompressed circuit.
[0013] Preferably, the second subset includes a gate set, and the first subset includes a first input of a first gate of the gate set. The order of the gates may be determined based on the order in which the gates are evaluated. Accordingly, the compression circuit can be represented using fewer data bits than the uncompressed circuit.
[0014] Preferably, the second subset includes a gate set, and the first subset includes a last output of the last gate of the gate set. The order of the gates may be determined based on the order in which the gates are evaluated. Accordingly, the compression circuit can be represented using fewer data bits than the uncompressed circuit.
[0015] The step of applying the entropy encoding method to the second subset includes determining a symbol set from the second subset, and assigning a corresponding code to each symbol of the symbol set. In many cases, the symbols of the symbol set are larger in size than the corresponding codes of the symbols (e.g., bit-width representation), but such a requirement is not necessary. For example, in Huffman coding, symbols that occur with low frequency may have corresponding codes of larger size.
[0016] Preferably, the symbols of the symbol set are repeated at least twice within the second subset. A symbol may be, for example, a sequence of bits or operations that occur more than once within the circuit. Preferably, the length of the code is inversely proportional to the frequency of the symbol corresponding to the code. The codes generated by the entropy encoding method may have variable lengths (e.g., some codes are of larger size than other codes), and shorter codes may be assigned to symbols that occur with higher frequency.
[0017] The code corresponding to the symbol is generated according to an optimal prefix code such as Huffman code.
[0018] Desirably, the method further includes a step of generating a serialization circuit, wherein the serialization circuit includes a result based at least in part on applying the entropy encoding method to the second subset and a header data structure. The header data structure may include a version number and a total number of wires.
[0019] Desirably, the header data structure further includes a bit width that can be used to enable optimization of execution based at least in part on a target architecture.
[0020] Desirably, the version number indicates an encoding method that can be used to determine symbols from the code.
[0021] Advantageously, unlike known interpreters and compilers, the present invention provides an architecture-independent solution. Further, it does not require the use of a virtual machine (VM) to enable execution. An architecture-independent circuit may represent a representation of a circuit that is not configured to operate or be used with a particular hardware or software architecture or platform. This is in contrast to conventional compilers and interpreters, each of which is architecture-specific or requires the use of a VM.
[0022] Also provided is a system including a processor and a memory including executable instructions that, as a result of execution by the processor, cause the system to execute the method according to any one of the claims.
[0023] Also provided is a non-transitory computer-readable storage medium storing executable instructions that, as a result of execution by one or more processors of a computer system, cause the computer system to execute the method according to any one of the claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The above and other aspects of the present invention are apparent from and taught with reference to the embodiments described herein. Embodiments of the present invention are described below by way of example only and with reference to the accompanying drawings.
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
DETAILED DESCRIPTION OF THE INVENTION
[0025] The following provides an explanation of how the present invention may operate in accordance with an embodiment. The present invention may be implemented in the context of a distributed computing environment. Here, a first computing entity utilizes an arithmetic circuit to generate a program that can be entrusted to a computing entity (e.g., a node of a blockchain network) in a distributed computing environment for execution. Further, the correct execution of the program is computationally verifiable. Thus, a client computing entity that has entrusted the execution of a program generated at least partially based on the arithmetic circuit can verify that the program has been correctly executed by the working computing entity. In this way, various efficiencies for the distributed computing environment may be realized, including enabling a client computing entity to entrust and verify the execution of a program to a computer system under the control of another entity.
[0026] As will be described in more detail below, possible implementations for compressing and serializing the arithmetic circuit into a binary data stream are described. The binary data stream is deserialized and decompressed in a lossless manner. Various advantages of serializing the circuit are to achieve, for example, a reduction in the data storage footprint of the circuit (such as by storing a serialization circuit instead of the arithmetic circuit). For example, in the context of a blockchain network, the arithmetic circuit or a program derived from the arithmetic may be at least partially encoded in the ledger of the blockchain network. By reducing the data storage footprint of the arithmetic circuit using the techniques described herein, the amount of data stored in the blockchain ledger can be reduced. Since the blockchain ledger can be replicated by some or all of the nodes of the blockchain network, even a slight reduction in the data storage footprint of the data stored in the blockchain is highly valued.
[0027] Specific structures or building blocks can be used to assist with this transformation. In one or more embodiments, this representation is considered the first step in constructing an inclusive pipeline that can provide distributed verifiable computation. The building blocks presented in this example are not intended to be an inclusive list of all possible high-level language constructs addressed by embodiments of the present invention. Further, alternative implementations of the presented examples may be provided. These are within the scope of those skilled in the art.
[0028] We provide embodiments for the description of the present invention. However, importantly, this is an example of an application where the present invention can be used. Those skilled in the art will understand that the present invention can be advantageously used in other contexts and applications.
[0029] In our example, consider a protocol that enables a user to generate an application using a Domain Specific Language (DSL). Once the application is generated, its execution can be entrusted to an untrusted party (referred to as a "worker" or "prover"), while its accuracy can be publicly verified. The protocol utilizes cryptographic primitives that guarantee the following: · Completeness. That is, if the protocol is correctly adhered to, an honest verifier is convinced of the validity of the output. · Soundness. That is, a dishonest prover cannot convince an honest verifier about the credibility of the output. · Zero-knowledge. That is, a dishonest prover knows nothing other than the validity of the output.
[0030] The advantages of the protocol are: · Since communication between participants is not required, a man-in-the-middle attack is prevented. · The use of blockchain technology makes it difficult for malicious nodes to tamper with data. · A reliable third party such as a reliable hardware device is avoided. · Verification of the contract does not mean re - execution of the code. The calculation is not replicated by all nodes in the network. Instead, a proof of honest execution is stored in a public blockchain and used only for verification purposes.
[0031] Such a system can handle various applications corresponding to various types of tasks and products. Due to this decentralized and distributed characteristic, the (Bitcoin) blockchain provides a well - suited environment for resolving consensus between two (or more) parties.
[0032] Such a system requires providing and facilitating programmability in a decentralized cryptocurrency system. However, conventionally, smart contract programming has been recognized as an error - prone process. See: Delmolino, K., et al. (2015). Step by Step Towards Creating a Safe Smart Contract: Lessons and Insights from a Cryptocurrency Lab, and Juels, A., et al. (2013), The Ring of Gyges: Using Smart Contracts for Crime.
[0033] Therefore, it is advantageous for a DSL that facilitates the description and reading of applications to be available to programmers, thus reducing errors and reducing the time, effort, cost, and resources during the programming process. Ideally, non - expert programmers should be able to describe various applications without the need to implement cryptographic methods. Instead, a compiler / interpreter automatically compiles the source code into a cryptographic protocol between the user and the blockchain. These are technical problems particularly solved by the present invention.
[0034] Figure 1 is an explanatory diagram 100 of one embodiment that can be implemented according to the present disclosure. The technology described in this specification may be used to serialize and de-serialize arithmetic circuits utilized in the execution of a computer program. The arithmetic circuit may be used to construct a Quadratic Arithmetic Problem (QAP) that is compiled into a set of cryptographic routines for a client (e.g., key generation and verification) and a prover (e.g., calculation and proof generation) according to one embodiment. The client and the prover may utilize a protocol to delegate the execution of a program to the prover in a way that the client can efficiently verify that the prover executes the program correctly. The serialized circuit may be used to improve the operation of a computer system by reducing the computational resources (e.g., hard disk space) required in relation to the arithmetic circuit. In one embodiment, the arithmetic circuit includes information represented as a symbol set (e.g., arithmetic gates and values) that is compressed to generate a serialized circuit including a code set. Here, the symbol set is derivable from the code set in a lossless manner. Transmitting the compressed circuit may improve the efficient data transmission bandwidth of a computer system by enabling more circuits to be transmitted. For example, if the compressed circuit reduces the size of the arithmetic circuit by 50%, the efficient data transmission bandwidth may be doubled. This is because up to twice the amount of compressed arithmetic circuits can be transmitted using the same number of bytes (note that the actual improvement in data transmission bandwidth may be less than double due to data overhead such as uncompressed packet headers). Reducing the data footprint of the arithmetic circuit may reduce the computer hardware requirements associated with the use of the arithmetic circuit. For example, reduce the amount of short-term memory (e.g., RAM) data storage utilized by a computer system that uses, stores, or otherwise interacts with the circuits described in this specification, and / or the data bandwidth. Transmitting the compressed circuit may improve the efficient data transmission bandwidth of a computer system by enabling more circuits to be transmitted.For example, if the compression circuit reduces the size of the arithmetic circuit by 50%, the efficient data transmission bandwidth may be doubled. This is because a compression arithmetic circuit that is up to twice as large can transmit the same number of bytes (it should be noted that the actual improvement in data transmission bandwidth may be less than twice due to data overhead such as uncompressed packet headers). Reducing the data footprint of the arithmetic circuit can reduce the computer hardware requirements associated with the use of the arithmetic circuit. For example, the short-term memory (e.g., RAM) data storage utilized by a computer system that uses, stores, or otherwise interacts with the circuits described herein, and / or the amount of data bandwidth, is reduced.
[0035] Generally, the arithmetic circuit C includes wires that carry values from the field F and connect logical and / or arithmetic gates. In one embodiment, the circuit C can be represented by a set of data fields including arithmetic gates, input wires, and output wires. The circuit may further include a header containing information such as a version number, the total number of wires, and the bit width nbit that enables optimization of execution depending on the target execution environment (e.g., processor architecture). Compression of the arithmetic circuit may be achieved by removing data fields that can be determined from other fields, applying an entropy encoding scheme, and combinations thereof. Various types of simplification rules may be used as part of the compression routine based on the format in which the arithmetic circuit is encoded. For example, some information may not be required. For example, the wire identifier for the input, the wire identifier for the output gate, the first input of the first gate, the final output wire identifier may be compressed (e.g., not explicitly encoded as part of the serialization circuit), or any combination thereof.
[0036] In various embodiments, the entropy encoding or encoding scheme is applied to an arithmetic circuit or a part thereof (e.g., based on the simplified rules described above). Entropy encoding may be utilized to generate a variable - length code table for serialization of source symbols. Huffman encoding may be utilized to generate the code table. In the code table, source symbols that occur with higher frequency are encoded using shorter codes, and source symbols that occur with lower frequency are encoded using longer codes, and the length of the code may be inversely proportional to the frequency of occurrence of the source symbol or sequence. Using these techniques, the arithmetic circuit can be compressed into a serialization circuit that requires few computational resources for storage in long - term data storage media (e.g., hard disk drives) and short - term data storage media (e.g., random access memories).
[0037] As described above, Huffman codes may be utilized to generate a code table. Huffman codes represent a particular type of optimal prefix code that can be used to achieve lossless data compression. The output from the Huffman algorithm may be a variable - length code table (e.g., a codebook) for encoding source symbols, such as characters or commands in a file. In one embodiment, the algorithm derives the table from the estimated or measured occurrence probabilities or frequencies (weights) for each possible value from the source symbols. Typically, more common symbols are represented using fewer bits than less common symbols. In one embodiment, Huffman encoding can be efficiently implemented to find the code in linear time with respect to the number of input weights, where the input weights are in sorted order. This approach may be optimal among methods of encoding symbols separately. Huffman encoding may use a particular method of selecting a representation for each symbol, resulting in a prefix code. That is, a bit string representing any particular symbol will never be a prefix of a bit string representing any other symbol.
[0038] A set of symbols {a0, a1,..., a from an alphabet A having size n n-1}, and usually, their weights {p0, p1,..., p n-1} are given, a tree with the minimum weighted path length from the root is required. The output code C(P) = {c0, c1,..., c n-1} is a tuple of binary codewords having the minimum weighted path length L(C).
[0039] As defined by Shannon's source coding theorem, for each symbol a having a non-zero probability i the information content h (in bits) is h(a i ) = log2(1 / p i ). The entropy H (in bits) is the weighted sum over all symbols a i having non-zero probabilities p i of the information content of each symbol: [Number]
[0040] Entropy is an indicator of the theoretically possible minimum codeword length for a given alphabet with associated weights. Usually, Huffman codes need not be unique. The set of Huffman codes for a given probability distribution is a non-empty subset of the codes that minimize L(C) for that probability distribution.
[0041] The serialization circuit can be used to derive the original arithmetic circuit using an extension or elongation routine in a lossless manner. It should be noted that in this context, "lossless (reversible)" represents a type of compression algorithm where the source data can be fully derived from the compressed data. In the context of digital compression, lossless compression may mean that each bit of the source bitstream can be derived from the compressed data containing the symbol set. Conversely, lossy compression (irreversible compression) may represent a type of compression algorithm where the compressed data cannot derive each bit of the source bitstream from the compressed data. An example of lossy compression is the MP3 audio coding format.
[0042] FIG. 2 is a diagram showing an example of a flowchart 200 of verifiable computation and related actors included in one embodiment of the present disclosure. As shown in FIG. 2, the flowchart 200 of verifiable computation may include a client node 240, a worker (e.g., prover) node 250, and a verifier node 260, which are related to performing steps of a verifiable computation protocol in one embodiment of the present disclosure. In an embodiment, one or more of the client node 240, the worker node 250, or the verifier node 260 are nodes within a blockchain network.
[0043] In one embodiment, the setup phase includes the step of describing the contract in a domain-specific language (DSL). The interpreter may be the client node 240, which takes the source code as input and generates an arithmetic circuit C composed of "wires" that carry data from the field F and connect to addition and multiplication gates. The arithmetic circuit itself may be a DAG, rather than a hardware circuit. The wires may be edges within the DAG. However, it is conceivable that the arithmetic circuit can be implemented in a physical circuit having wires and logic gates. At 202, the client node 240 compiles the computation P described in GPL into the arithmetic circuit C. In an embodiment, the client node 240 supplies the arithmetic circuit C and the input x to the worker node 250.
[0044] From the circuit C, one embodiment of the present disclosure can generate a quadratic program Q including a set of polynomials that provide a complete description of the original circuit C. Next, public parameters that should be used by the worker node 250 and the verifier node 260 when executing and verifying the quadratic program may be generated.
[0045] At 204, the worker node 250 executes circuit C or the quadratic program Q on the input x and claims that the output is y. In some embodiments, the worker node 250 (i.e., the prover) is expected to obtain a valid transcript for {C, x, y}. Thus, at 206, the worker node 250 encodes the transcript. In some examples, a valid transcript {C, x, y} is an assignment of values to the circuit wires. As a result, the values assigned to the input wires are those of x, the intermediate values correspond to the correct operation of each gate in C, and the value assigned to the output wire is y. If the claimed output is incorrect (i.e., y ≠ P(x)), there is no valid transcript for {C, x, y}.
[0046] At 208, the worker node 250 provides the output y to the client node 240. In an embodiment, the public evaluation key EK and the public verification key VK are selected by the j client node 240 or derived using a secret value s from the client node 240. In an embodiment, the worker node 250 uses these public keys to evaluate the computation for a particular input x. In an embodiment, the output y, the values of the internal circuit wires, and EK are used to generate a proof-of-correctness π. The proof π is stored on the blockchain and verified by multiple parties (e.g., the verifier node 260), and the worker node 250 does not need to interact individually with multiple parties. In this way, at 210, the verifier node 260 can verify the payment transaction using the public verification key VK and the proof π, thereby validating the contract.
[0047] Verifiable computation is a technology that enables the generation of proofs of computation. In one embodiment, such technology is utilized by a client to delegate the evaluation of a function f with respect to an input x to another computing entity, referred to herein as an operator. In some examples, the client is computationally limited and unable to execute the evaluation of the function (e.g., the expected execution time of the computation using the computing resources available to the client exceeds a maximum allowable threshold). However, such a requirement is not necessary, and the client may, typically, delegate the evaluation of the function f with respect to the input x based on any suitable criteria such as computational execution time, computational cost (e.g., the economic cost of allocating computing resources to execute the evaluation of the function), and the like.
[0048] In one embodiment, the operator is any suitable computing entity such as a blockchain node as described in more detail elsewhere in this disclosure. In one embodiment, the operator (e.g., a blockchain node) evaluates the function f with respect to the input x and generates a proof π of the correctness of the output y that is verifiable by the client and / or other computing entities such as other nodes of the blockchain network described above. The proof may also be referred to as an argument and can be verified more quickly than performing the actual computation by recomputing the function f with respect to the input x to determine the correctness of the output generated by the operator described above, thus reducing computational overhead (e.g., reducing power overhead and the costs associated with powering and operating computing resources). In zero-knowledge verifiable computation, the operator provides an attestation (proof) to the client that the operator knows an input with certain properties.
[0049] An efficient variant of zero-knowledge proof of knowledge is zk-SNARK (Succinct Non-interactive ARgument of Knowledge). In one embodiment, all pairings based on zk-SNARK involve a process where the prover computes a number of group elements using general group operations and the verifier checks the proof using a number of pairing product equations. In one embodiment, linear interactive proofs function over finite fields, and the prover's and verifier's messages include vectors of field elements, encoded, referenced, or otherwise information that can be used to determine field elements.
[0050] In one embodiment, the systems and methods described herein enable a blockchain miner (e.g., a node) to perform a computation (e.g., evaluation of a function f for an input x) once and generate a proof that can be used to verify the correctness of the output. Here, evaluating the correctness of the proof is computationally less expensive than evaluating the function. In this context, the cost of an operation or task (i.e., how expensive it is) may represent the computational complexity of performing the operation or task. In one embodiment, the computational complexity represents the average computational cost or the worst-case computational cost when executing a sorting algorithm. For example, the heap sort algorithm or the quicksort algorithm, both of which have an average computational cost of O(n log n), but quicksort has a worst-case computational cost of O(n 2) and heapsort has a worst-case computational cost of O(n log n). In one embodiment, the average and / or worst-case computational cost for evaluating function f for input x is worse than that for evaluating the correctness of the proof. Thus, the use of the systems and methods described herein is highly advantageous, for example, it can enable the execution of even more computationally expensive contracts, for example, the contract does not need to proportionally increase the time required to verify the blockchain. Further advantages can include reducing the power consumption of the verifier system. This improves the efficiency of the verifier computer system and reduces the energy cost associated with operating the verifier computer system when evaluating the correctness of the proof.
[0051] In one embodiment, the verification key V K or a portion thereof can be extracted from public parameters generated during the setup phase of the zero-knowledge protocol and can be used, together with the proof π and the input / output data, to verify the calculation of the declared correctness proof provided by the prover. For example, as described above and below, a lock script enables secure protection of the verification key V K from modification, and systems and methods for checking the validity of the proof π enable the execution of zero-knowledge protocols on the blockchain during transaction verification. Thus, the present disclosure proposes systems and methods for performing the verification phase using blockchain scripts that store elements used in the verification of computations (e.g., in a Bitcoin-based network).
[0052] Figure 3 shows an example 300 of a workflow from a domain-specific language (DSL) code to a quadratic arithmetic program (QAP) according to an embodiment of the present disclosure. Specifically, FIG. 3 shows DSL code 302 that is converted by converter 204 into GPL code 306. A GPL precompiler 308 (also known as a preprocessor) incorporates external library 310 referenced by GPL code 306 to generate GPL preprocessed code 312. The GPL preprocessed code 312 is converted into an arithmetic circuit 314. The arithmetic circuit 314 is optimized to generate a reduced arithmetic circuit 316 that is compressed to generate a serialization circuit 320. From the serialization circuit 320, a QAP polynomial 318 is derived.
[0053] In one embodiment, the domain-specific language (DSL) code 302 is an application described in a formal language having precise semantics. In one embodiment, the code 302 includes a set of conditions, and the result of the DSL code 302 depends on the satisfaction of the set of conditions. An example of an application (e.g., a smart contract) is an insurance contract that takes as input the insurance premium of the insured and the possible compensation to the insured by the insurance company. If the insured incurs a loss during the period of the smart contract (e.g., satisfaction of the first condition), the execution of the smart contract distributes the insurance premium to the insurance company and distributes the compensation for the loss to the insured. On the other hand, if the insured does not incur a loss during the period of the smart contract, the execution of the smart contract distributes the insurance premium to the insurance company and distributes the possible compensation to the insurance company.
[0054] In one embodiment, the converter 304 is a software program. As a result of execution, the software program receives a set of conditions such as DSL code 302 described in DSL and converts the DSL code into GPL source code such as GPL code 306. In one embodiment, the GPL code 306 is a GPL program such as a C++ program and includes the code defined by the DSL code 302. In some examples, a general-purpose language (GPL), as opposed to a DSL, is widely applicable. Examples of general-purpose programming languages are Ada, ALGOL, assembly language, BASIC, Boo, C, C++, C#, Clojure, COBOL, Crystal, D, Dart, Elixir, Erlang, F#, Fortran, Go, Harbour, Haskell, Idris, Java, JavaScript, Julia, Lisp, Lua, Modula-2, NPL, Oberon, Objective-C, Pascal, Perl, PHP, Pike, PL / I, Python, Ring, RPG, Ruby, Rust, Scala, Simula, Swift, and Tcl. C++ is included and may be referenced in embodiments of the present disclosure and is a general-purpose programming language with imperative, object-oriented, general-purpose programming capabilities but also provides capabilities for low-level memory operations. It should be noted that in the context of FIG. 3, alternatively, "code" may represent executable code (e.g., object code), source code, both of them, or a combination thereof, based on the context in which it is described.
[0055] In one embodiment, the GPL precompiler 308 is a computer-executable program that processes the GPL code 306 and the required external libraries 310 to generate the stand-alone type GPL code 306 preprocessing code 312. In an embodiment, the GPL precompiler 308 evaluates constant expressions and register symbols found within the GPL code 306.
[0056] In one embodiment, the external library 310 is a set of pre-written subroutines, functions, classes, containers, values, and / or variable types that are utilized by the GPL code 306 by means of a call. For example, by calling the external library 310, the GPL code 306 can obtain the functions of the library without having to implement the functions themselves.
[0057] In one embodiment, the GPL preprocessing code 312 includes a set of expressions and operators. The operators may include arithmetic operators (e.g., addition (+), multiplication (*), etc.), comparison operators (e.g., less than (<), equal to (=), greater than or equal to (≧), etc.), conditional statements (e.g., if-then (?,:)), or logical operations (e.g., AND (&&), OR (||), NOT (!), XOR (plus sign in a circle), etc.). In some embodiments, the main function is generated to have a predetermined name and format.
[0058] In one embodiment, the arithmetic circuit 314 is a DAG for a set of variables. In one embodiment, all nodes of the DAG with an in-degree of 0 are input gates representing variables (e.g., x i ) and all other nodes of the DAG are sum gates (+) or product gates (×). In embodiments, all gates (nodes) have an out-degree of 1, and thus the basic graph is a directed tree. In embodiments, the arithmetic circuit 314 has two metrics of complexity: size and depth. In some examples, the "size" of the arithmetic circuit is based on the number of gates in the arithmetic circuit 314. In some examples, the "depth" of the arithmetic circuit is based on the length of the longest directed path in the arithmetic circuit.
[0059] In one embodiment, the reduction operation circuit 316 is a reduction or minimum directed acyclical graph (DAG) that can be used to determine the result of a set of conditions as specified in the DSL code 302 when an input set is provided. In some embodiments, the reduction operation circuit 316 is a minimized (i.e., reduced to the minimum degree) operation circuit. In some embodiments, the optimal operation circuit may not necessarily be the minimum operation circuit (e.g., depending on the number and type of arithmetic operations in the circuit, a particular larger operation circuit may be evaluated to be faster than a smaller operation circuit). Also, in such embodiments, the reduction operation circuit 316 is optimized (e.g., for maximum speed, less memory usage, maximum efficiency processor utilization, etc.), but is not necessarily a minimized operation circuit. The reduction operation circuit 316 may be generated using the techniques described in UK Patent Application No. GB1718505.9.
[0060] An operation circuit such as the reduction operation circuit 316 may be compressed according to the techniques described herein to generate a serialization circuit 320. The serialization circuit 320 may be used in the case of code templates or standard applications that need to be stored and read. By utilizing the serialization circuit 320, a party can eliminate the need to generate instances of the circuit from the GPL each time a new application is generated. Thereby, improving the efficiency of the protocol for clients and verifiers to reuse specific code templates or portions of such applications. The serialization circuit 320 may be generated using entropy encoding for the most frequent elements in the data structure such as arithmetic operator types. Instructions for deserialization and expansion (e.g., a codebook that maps the serialized code to source symbols) may be embedded in the serialized bitstream such that the recipient of the serialization circuit can reconstruct the source circuit.
[0061] In one embodiment, the QAP polynomial 318 is one or more expressions having variables and coefficients expressed in a mathematical expression that provides a complete description of the original arithmetic circuit (e.g., the arithmetic circuit 314 in FIG. 4). In an embodiment, the polynomials among the QAP polynomials are defined from the perspective of their evaluation at the roots of the arithmetic circuit. For example, as described in Gennaro, R. et al., Quadratic Span Programs and Succint NIZKs without PCPs (2013). In an embodiment, the QAP polynomial is encoded within the lock script of a blockchain transaction as a representation of the smart contract. In an embodiment, the lock script, when executed, receives a set of parameter values (e.g., as a result of the execution of the lock script). The set of parameter values is input as variables into the QAP polynomial to determine the result of the smart contract.
[0062] In an embodiment, the GPL polynomial 308 generates GPL preprocessing code 312 which may be an arithmetic circuit having arithmetic gates. However, note that complex arithmetic circuits also embed logical submodules with conditional and flow control statements.
[0063] FIG. 4 shows a process 400 for reducing the size of an arithmetic circuit. In one embodiment, the arithmetic circuit has a header associated with or encoded thereby to the body. In one embodiment, the body of the circuit includes wire identifiers and gate types of the gates. The header may include information such as metadata associated with the body. In one embodiment, the arithmetic circuit is converted into a binary stream of data characterized by a measure of entropy approaching the theoretical limit as defined by Shannon's source coding theory. In some examples, the serialization circuit represents the binary data stream and has a higher entropy value than the arithmetic circuit. The "entropy" described in the present disclosure represents the entropy according to the principles of information theory described in Shannon, C., A Mathematical Theory of Communication (1955).
[0064] Process 400 may be performed by any suitable computer system as described in connection with FIG. 2. The circuit may be compressed and optimized by the client described in FIG. 2, or another computing entity such as an operator tasked with serializing the arithmetic circuit. Given a general-purpose circuit, the system identifies a list of global parameters. The transmitting and receiving sides in the serialization scheme exchange the following information: a version number including additional information such as an encoding scheme or codebook used to serialize the circuit in some embodiments; the total number of wires N; the bit width n bit ; and combinations thereof;.
[0065] In one embodiment, a system for performing process 400 includes a memory storing executable code that, when executed by one or more processors, causes the system to obtain (402) an arithmetic circuit that can be represented by a set of data fields. In one embodiment, the set of data fields includes gates or operations and wires representing inputs and outputs. It should be noted that a wire may simultaneously be the output of a first gate and the input of another gate. A wire may be both an input and an output to a gate. The system may use a simplification rule to remove data fields of the arithmetic circuit 404. The simplification rule may be used to remove a first subset of the data fields of the arithmetic circuit that is derivable from the remaining data fields that may be referred to as a second subset of the data fields of the arithmetic circuit. The first subset and the second subset may be independent sets having no common elements based on the characteristics of the data fields of the arithmetic circuit. Each data field of the arithmetic circuit can be classified into a field to be calculated or a field to be stored. The field to be calculated is assigned to the first subset, and the field to be stored is assigned to the second subset. It is possible that a data field may not be characterized as both a field to be calculated and a field to be stored at the same time. The field to be calculated represents, in one embodiment, a data field that cannot be derived from one or more stored fields. Generally, this concept can be described using examples for illustration. If there are respective data fields that store a start time, an end time, and a time interval period, the end time can be identified as a field to be calculated, and the start time and the period are fields to be stored. Because the end time can be determined from one or more fields to be stored (e.g., EndTime = StartTime + Duration). Of course, in this example, the period can also be represented as a field to be calculated, and the start time and the end time can be represented as fields to be stored (e.g., Duration = EndTime - StartTime). As described above, none of the fields become either one or the other based on a representation that can be selected programmatically (e.g., selected by executing an algorithm) or by a user, but rather become both a field to be calculated and a field to be stored at the same time.
[0066] In one embodiment, the system identifies one or more data fields of a set of data fields based at least in part on a determination of whether the data field is derivable from other data fields of the set. As a first example, starting from id0, the first n inputsSince the individual identifiers are reserved for input, the simplification rules may remove the input wire identifiers. Thus, the value n inputs is sufficient to determine that the identifiers from id0 to id ninputs-1 are input identifiers. The inputs may be automatically incremented such that the first input is assigned to id0, the second input is assigned to id1, and so on.
[0067] Additional simplification rules may exist. As a second example, starting from id inputs , the wire identifiers of the output gates may be removed such that all wire identifiers of the output gates are automatically incremented. For example, if the circuit includes only two gates, the output of the first gate is characterized by id inputs and the output of the second gate is characterized by id inputs+1 . The order of the gates may be the sequential order of arithmetic operations as specified by an interpreter such as the interpreter described with respect to FIG. 2. The interpreter may be implemented using the technique described in UK Patent Application No. GB1801753.3. As a third example, the first input of the first gate (e.g., having the order determined by the interpreter) is assigned id0 by default. As a fourth example, given the total number of wires N, the last output wire identifier is not needed since by default id N-1 is the output wire. Embodiments may implement none, all, or some of the described exemplary simplification rules. FIG. 5 shows an example of an arithmetic circuit to which the described simplification rules are applied. It should be noted that the simplification rules as described above are merely examples, and various embodiments may implement some or all of the simplification rules, and other simplification rules may be known to those skilled in the art.
[0068] Entropy encoding may be applied to the arithmetic circuit to reduce the amount of data required to encode parts of the arithmetic circuit that are heavily repeated (e.g., arithmetic operations). In some examples, the system may determine a codebook that maps the data of a set of data fields to a set of codes 406. Huffman encoding may be utilized to generate a variable-length code table for serialization of source symbols. Generally speaking, given a set of M different source symbols that may include the types of operations defined for the arithmetic circuit, for each symbol i, 0 ≦ i < M, a probability p i is specified. In one embodiment, a binary tree is generated by taking in the two least likely symbols and combining them to form a new symbol. For example, p a and p b are the two least likely symbols, they form a new symbol p ab , and p ab = p a + p b . This process is repeated until only one symbol remains. The tree may be read backwards while assigning different codes to different branches. The codes may be assigned according to the Huffman encoding scheme. It should be noted that the resulting tree may have leaf nodes with different tree depths. In such examples, generally, symbols with higher probabilities are closer to the root than symbols with relatively lower probabilities. Thus, symbols that occur more frequently can be encoded using fewer bits than symbols that occur less frequently. In other words, in one embodiment, the length of the code is inversely proportional to the frequency of the symbol.
[0069] The binary tree and symbol codes may vary according to the value of M and the individual symbol probabilities p i , 0 ≦ i < M. For example, if M is a power of 2, p i = 2p i+1 , and p M-2 = 2p M-1 = 2p M+1 , the total number of bits S required to encode the arithmetic circuitops is as follows:
Number
[0070] Therefore, the compression ratio R for encoding the arithmetic circuit is as follows:
Number
[0071] Due to the linearity between p and ω, that is, ω M-2 = ω M-1 = 1, and ω i = 2ω i+1 , from 0 ≦ i < M - 1, the above formula can be simplified as follows:
Number
[0072] When M > 5, the normalized ratio R / n0 is less than 1. That is, in fact, no compression is performed with respect to n0. The larger M is, the larger the compression ratio is. With the method described above, the arithmetic circuit can be compressed well 408. In one embodiment, the compression circuit is a serialized bit stream of data encoding the circuit representation (for example, the simplified and / or encoded version of the original circuit as described above). In one embodiment, the serialization circuit includes a body encoding the circuit representation and a header including one or more of the following: a version number, the total number of wires, the bit width n bit , a codebook, or any combination thereof. In some examples, the codebook is selected from a plurality of codebooks, and the appropriate codebook can be selected based on querying the version number. For example, the first codebook in the list of codebooks corresponds to version 1, the second codebook in the list corresponds to version 2, and so on. The codebook may be pre-generated in one embodiment.
[0073] FIG. 5 shows a diagram 500 of an arithmetic circuit 502 and a serialization circuit 504 according to one embodiment. The serialization circuit 504 shown in FIG. 5 may be a compressed version of the arithmetic circuit generated using a set of simplification rules. A lossless compression routine may be applied to the arithmetic circuit 502 to generate the serialization circuit 504, and a lossy decompression routine may be applied to the serialization circuit 504 to reproduce the serialization circuit 504 completely (e.g., with bit-for-bit accuracy).
[0074] As shown in FIG. 5, an exemplary arithmetic circuit may include header metadata including version information, a field N indicating the number of wires, and identifiers of the circuit inputs (0, 1, 2) and outputs (4, 5). It should be noted that some wires may be neither circuit inputs nor outputs (e.g., wires that are intermediate inputs or outputs of the circuit). The information in the header need not be encoded at the beginning of the data structure, nor need it be encoded contiguously. As shown in the arithmetic circuit 502 of FIG. 5, the output data is encoded at the end of the data structure. The arithmetic circuit further encodes a data field of gates followed by a set of inputs and outputs. For example, as shown in the arithmetic circuit 502, ADD 0 1 3 represents an addition gate that adds the values of the wires corresponding to identifiers id0 and id1 to generate an output to the wire corresponding to identifier id3.
[0075] As a second example, MUL 1 2 4 represents a multiplication gate that multiplies the values of the wires corresponding to identifiers id1 and id2 to generate a product at the wire corresponding to identifier id4. The uncompressed arithmetic circuit 502 may thus be represented as follows: VERSION 1 N 6 IN 0 1 2 ADD 0 1 3 MUL 1 2 4 MUL 3 4 5 OUT 4 5
[0076] The arithmetic circuit 502 may be compressed into the serialization circuit 504 by applying simplification rules. The first simplification rule may be that when the number of inputs is encoded, the wire identifiers of the inputs are not necessary. Alternatively, the number of inputs may represent the cardinality or density of the input set. For example, the above inputs (0, 1, 2) have a density of 2. Therefore, according to this simplification rule, the arithmetic circuit is compressed as follows: VERSION 1 N 6 2 ADD 0 1 3 MUL 1 2 4 MUL 3 4 5 OUT 4 5
[0077] The second simplification rule may be that the wire identifier of the output gate is not necessary because it can be automatically incremented starting from n ininputs Therefore, according to the first and second simplification rules, the arithmetic circuit is compressed as follows: VERSION 1 N 6 ADD 0 1 MUL 1 2 MUL 3 4 4 5
[0078] The third simplification rule may be that the first input to the first gate is not necessary because the first identifier is assigned to that wire by default. Therefore, according to the first, second, and third simplification rules, the arithmetic circuit is compressed as follows: VERSION 1 N 6 2 ADD 1 MUL 1 2 MUL 3 4 4 5
[0079] The fourth simplification rule may be that the last output wire identifier is not required since it is defined as the output wire by default. Therefore, according to the first, second, third, and fourth simplification rules, the arithmetic circuit is compressed as follows: VERSION 1 N 6 2 ADD 1 MUL 1 2 MUL 3 4 4
[0080] It should be noted that the serialization circuit 504 may be further compressed, for example, by using entropy encoding techniques.
[0081] FIG. 6 shows a circuit serialization diagram 600. The upper input arithmetic circuit 602 is represented in ASCII. The first serialization circuit 604 is, in one embodiment, the result of applying a serialization technique where n w = 32, and the second serialization circuit 606 is the result of applying a serialization technique where n w = 8. The black squares represent unused bits that are padded with zeros in one embodiment.
[0082] In one embodiment, the rules for simplifying data fields and the entropy encoding of arithmetic operations are utilized to constitute an efficient serialization of the arithmetic circuit. The header of the data structure may include a version byte, an integer value (e.g., signed or unsigned) of the number of inputs / outputs, the number of wires, a list of output wire identifiers excluding the last one (the last output wire identifier may be omitted while achieving lossless compression as described in relation to the simplification rules), and combinations thereof. In one embodiment, the version byte embeds a configuration that is valid for a particular circuit. The receiving side of the serialization circuit may use the version byte to determine how to deserialize the serialization circuit. For example, <the version byte (or bytes) may be structured as follows: Bits 0 and 1: Instruction set. The instruction set defines the types of instructions defined for the circuit. Addition and multiplication are always defined, but the addition operator may be defined according to the circuit function. For example, wire compression, wire expansion, equal to 0, and operators that compare with 0. Therefore, the following configurations may be introduced: 00: Instruction set with operators of type M = 2. 01: Instruction set with operators of type M = 4. 10: Instruction set with operators of type M = 8. 11: Instruction set with operators of type M = 16.
[0083] Bits 2, 3, and 4: Number of inputs / outputs. This field specifies the bit width of the field that includes the number of inputs and the number of outputs. For example, the following configurations may be introduced: 000: 2-bit input, 2-bit output 001: 2-bit input, 4-bit output 010: 2-bit input, 8-bit output 011: 4-bit input, 2-bit output 100: 4-bit input, 4-bit output 101: 4-bit input, 8-bit output 110: 8-bit input, 4-bit output 111: 8-bit input, 8-bit output
[0084] Bits 5 and 6: Wire identifier width n w (Wire identifiers width). Depending on the number N of wires in circuit N, a specific number of bits are allocated to encode the wire identifiers. For example, the following configurations may be introduced: 00: Wire identifier encoded in 8 bits and N 01: Wire identifier encoded in 16 bits and N 10: Wire identifier encoded in 32 bits and N 11: Wire identifier encoded in 64 bits and N
[0085] Bit 7: Bit width n bit (Bit-width). The circuit can be optimized for a specific computer architecture. For example, the following configurations can be introduced: 0: 32-bit architecture 1: 64-bit architecture
[0086] In some embodiments, more bytes can be reserved for version information, enabling the definition of additional configurations and fields.
[0087] The instruction set field may be used for the selection of the correct dictionary for entropy encoding. If a specific number of dictionaries are predefined, the correct dictionary does not need to be encoded within the circuit. For example, if M is a power of 2, a scheme with the above symbol probabilities can be defined. Thus, given a specific instruction set, a specific dictionary is read out.
[0088] In one embodiment, the body of the circuit includes a serialization wire identifier of the input gate and the gate type. In one embodiment, the size of the wire identifier is predefined and encoded into a positive number of bytes. As a result, the wire identifier is first encoded, and then the encoded gate is embedded. This results in more efficient serialization and deserialization in an architecture where data fields need to be padded to the nearest full byte. It should be noted that in at least one embodiment, an advanced encoding scheme may also be applied, and the wire identifier does not need to be encoded into a positive number of bytes. During deserialization, the receiving side knows the value of N from the header. After reading the wire identifier, the remaining bitstream represents the encoded arithmetic operation. The encoded gates do not need to be byte-aligned, but multiple gates can be embedded into a single byte using bitwise operations. For example, if two symbols a1 and a2 are independently encoded into 4 bits, a single byte b can be used to aggregate the information: b = (a1 << 4) + a2
[0089] The bitwise operator "<< " is a left shift. Gates can also be divided into two or more bytes depending on a particular dictionary.
[0090] In one embodiment, the entropy coder constructs the code such that the decoder can detect where each symbol code starts and ends. Thus, the correct wire identifiers are sequentially assigned to each arithmetic operation depending on the required number of inputs. For example, if the next wire is read as the i-th in the sequence and the next operator starts at bit j in the stream, the following operations are performed: 1. Detect symbol a with the first bit at position jn j . 2. Calculate the symbol size s(a j ) using information from the dictionary. 3. Calculate the number of input wires n(a i ) of symbol a j . 4. Store the arithmetic operation with the code and the wire identifiers (i, i + 1,..., i + n(a i ) - 1). 5. Move the pointer to the next symbol to j + s(a j ). 6. Move the counter to the next wire to i + n(a j ).
[0091] In one embodiment, the process ends when N wires are read. If the stream is correctly encoded, the pointer to the next symbol is the end of the stream when the N-th wire is read. In one embodiment, the last symbol does not have to be byte-aligned, and padding may not be used, for example, 0-padding, 1-padding, or 01-padding is used to align the last symbol.
[0092] Accordingly, FIG. 6 shows a comprehensive example for the serialization process considering a dictionary with M = 3 and an initial arithmetic circuit encoded in ASCII (i.e., n0 = 8). Huffman coding may be utilized in connection with the serialization process. For example, according to Huffman coding, the multiply operation is encoded as a 1-bit value (e.g., MUL is encoded as “0”), the second multiply operation is encoded as a 2-bit value (e.g., ADD is encoded as “10”), and so on (e.g., the third operation y is encoded as “11”). The compression ratio for ASCII encoding is n w = 2.44 when n w = 32, and is 8.11 when n
[0093] FIG. 7 shows a simplified block diagram of a computing device 700 that can be used to implement at least one embodiment of the present disclosure. In various embodiments, the computing device 700 can be used to implement any of the illustrated systems described above. For example, the computing device 700 can be configured to be used as a data server, a web server, a portable computing device, a personal computer, or any electronic computing device. As shown in FIG. 7, the computing device 700 can include one or more processors 702 configured and operatively coupled to communicate with a number of peripheral subsystems via a bus subsystem 704 in an embodiment. In some embodiments, these peripheral subsystems include a memory subsystem 706 including a memory subsystem 708 and a file / disk storage subsystem 710, one or more user interface input devices 712, one or more user interface output devices 714, and a network interface subsystem 716. Such a memory subsystem 706 can be used for temporary or long-term storage of information.
[0094] In some embodiments, bus subsystem 704 provides a mechanism that enables the various components and subsystems of computing device 700 to communicate with each other as intended. Although bus subsystem 704 is shown schematically as a single bus, alternative embodiments of the bus subsystem utilize multiple buses. In some embodiments, network interface subsystem 716 provides an interface to other computing devices and to a network. Network interface subsystem 716 functions, in some embodiments, as an interface for receiving data from and transmitting data to other systems from computing device 700. In some embodiments, bus subsystem 704 is utilized to communicate data such as details, search terms, and the like.
[0095] In some embodiments, the user interface input device 712 includes one or more user input devices such as a keyboard, an integrated mouse, a trackball, a touchpad, or a pointing device such as a graphics tablet, a scanner, a barcode scanner, a touch screen incorporated into a display, a voice recognition system, an audio input device such as a microphone, and other types of input devices. Generally, the use of the term "input device" is intended to include all possible types of devices and mechanisms for inputting information into the computing device 700. In some embodiments, one or more user interface output devices 714 include a display subsystem, a printer, or a non-visual display such as an audio output device, etc. In some embodiments, the display subsystem includes a cathode ray tube (CRT), a liquid crystal display (LCD), a light emitting diode (LED) display, or a flat panel device such as a projection, or other display devices. Generally, the use of the term "output device" is intended to include all possible types of devices and mechanisms for outputting information from the computing device 700. The one or more user interface output devices 714 can be used, for example, to present a user interface and to enable user interaction with an application that executes the processes and variations described herein when such interaction is appropriate.
[0096] In some embodiments, the memory subsystem 706 provides a computer-readable storage medium that stores basic programming and data structures that provide the functionality of at least one embodiment of the present disclosure. Applications (programs, code modules, instructions), when executed by one or more processors, in some embodiments provide the functionality of one or more embodiments of the present disclosure and, in embodiments, are stored in the memory subsystem 706. These application modules or instructions can be executed by one or more processors 702. In various embodiments, the memory subsystem 706 further provides a repository for storing data used in accordance with the present disclosure. In some embodiments, the memory subsystem 706 includes a memory subsystem 708 and a file / disk storage subsystem 710.
[0097] In embodiments, the memory subsystem 708 includes a number of memories such as a main random access memory (RAM) 718 for storing instructions and data during program execution and / or a read-only memory (ROM) 720 in which fixed instructions can be stored. In some embodiments, the file / disk storage subsystem 710 provides non-transitory persistent (non-volatile) storage for program and data files and may include a hard disk drive, a floppy disk drive in conjunction with a related removable medium, a compact disk read-only memory (CD-ROM) drive, an optical drive, a removable media cartridge, or other similar storage media.
[0098] In some embodiments, computing device 700 has at least one local clock 724. In some embodiments, local clock 724 represents a counter that represents the number of time elapsed since a specific start date, and in some embodiments, is disposed inside computing device 700. In various embodiments, local clock 724 is used to synchronize data transfers within the processor for computing device 700 and the subsystems included therein at specific clock pulses, and can be used to coordinate motoring operations between computing device 700 and other systems in a data center. In another embodiment, the local clock is a programmable internal timer. Computing device 700 may be any of a variety of types including a portable computing device, a tablet computer, a workstation, or any of the other devices described hereinafter. Further, in some embodiments, computing device 700 may include another device connectable to computing device 700 through one or more ports (e.g., USB, headphone jack, optical connector, etc.). In an embodiment, such a device includes a port configured to receive an optical fiber connector. Thus, in some embodiments, this device is configured to convert an optical signal into an electrical signal transmitted to computing device 700 through the port connecting the device for processing. Due to the constantly changing nature of computers and networks, the description of computing device 700 shown in FIG. 7 is intended only as a specific example for the purpose of illustrating a preferred embodiment of the device. Many other configurations with more or fewer components than the system shown in FIG. 7 are possible.
[0099] The specification and drawings are to be regarded, therefore, as illustrative rather than restrictive. However, it is clear that various changes and modifications may be made therein without departing from the scope of the invention as set forth in the claims. Similarly, other variations are within the scope of the disclosure. Accordingly, the disclosed technology is subject to various changes and alternative configurations, although the specific illustrated embodiments have been shown and described in detail above. However, there is no intention to limit the invention to one or more specific forms of the disclosure; on the contrary, it is intended to cover all changes, alternative configurations, and equivalents falling within the scope of the invention as defined by the appended claims.
[0100] The terms "a" and "an," "the," and similar references in the context of describing embodiments of the disclosure are intended to cover both the singular and the plural (in the context of the following claims in particular), unless the context clearly indicates otherwise or is clearly negated. Terms such as "having," "comprising," "including," "containing," etc. are to be considered as open-ended terms (i.e., meaning "including but not limited to") unless otherwise specified. The term "connected," when unmodified and referring to a physical connection, is to be considered as including, adding, or joining, in whole or in part, even where there is no intervening member. The recitation of ranges of values in this disclosure is, unless otherwise specified, merely a shorthand notation for referring individually to each of the separate values within that range, and each separate value is to be considered as incorporated herein as if it were individually recited. The use of the terms "set or collection" (e.g., "a set of items") or "subset or subcollection" is to be considered as a non-empty collection containing one or more elements, unless otherwise specified or clearly negated in the context. Further, unless otherwise specified or clearly negated in the context, the term "subset" of a corresponding set does not necessarily denote a proper subset of the corresponding set, and the subset and the corresponding set may be equal.
[0101] Conjunctive language, such as "at least one of A, B, and C" or "at least one of A, B and C", unless otherwise specified or clearly negated in context, is generally understood in context to be used to indicate that an item, term, etc. can be any one of A or B or C, or any non-empty subset of the set of A and B and C. For example, in an example for the description of a set having three members, the conjunctive phrase "at least one of A, B, and C" or "at least one of A, B and C" represents any one of the following sets: {A}, {B}, {C}, {A,B}, {A,C}, {B,C}, {A,B,C}. Thus, such conjunctive language is not generally intended to mean that a particular embodiment requires the presence of at least one A, at least one B, and at least one C respectively.
[0102] The operations of the described process can be executed in any suitable order, unless otherwise specified or clearly negated in context. The described process (or variations and / or combinations thereof) can be executed under the control of one or more computer systems configured by executable instructions and implemented as code (e.g., executable instructions, one or more computer programs or one or more applications) that execute in cooperation on one or more processors by hardware or a combination thereof. In some embodiments, the code can be stored in a computer-readable storage medium in the form of a computer program having, for example, a plurality of instructions executable by one or more processors. In some embodiments, the computer-readable storage medium is non-transitory.
[0103] The use of any and all examples, or the use of provided exemplary language (e.g., "such as"), is merely intended to better illustrate embodiments of the present invention and does not limit the scope of the present invention unless otherwise specified. No language in the specification should be construed as indicating that any non-claimed element is essential for the practice of the present invention.
[0104] Embodiments of the disclosure are described that include the best mode known to the inventors as of the filing date of this application. These various embodiments will be apparent to those of ordinary skill in the art upon reading the foregoing description. The inventors expect those of ordinary skill in the art to appropriately utilize such variations, and the inventors intend for the embodiments of the disclosure to be practiced otherwise than as particularly described herein. Accordingly, the scope of the disclosure includes all modifications and equivalents of the subject matter recited in the appended claims as permitted by applicable law. Further, any combination of the above-described elements in all possible variations thereof is included within the scope of the disclosure unless otherwise specifically noted or clearly precluded by context.
[0105] All references, including publications, patent applications, and patents, cited herein are hereby incorporated by reference as if each reference were individually and specifically indicated to be incorporated by reference and were set forth in its entirety herein. This includes UK Patent Application Nos. GB1719998.5, GB1718505.9, and GB1720768.9.
[0106] The above embodiments do not limit the present invention. It should be noted that the present invention is for explanation, and those skilled in the art can devise many alternative embodiments without departing from the scope of the present invention defined by the appended claims. In the claims, any reference signs in parentheses are not intended to limit the claims. Terms such as "having" and "comprising" do not exclude the presence of elements or steps other than those listed in any claim or the entire specification. In this specification, "having" means "having or being composed of", and "comprising" means "comprising or being composed of". A single reference to an element does not exclude a plurality of references to that element. Vice versa. The present invention can be implemented by means of several distinct elements of hardware and by a suitably programmed computer. In apparatus claims listing several means, several of these means can be embodied by one and the same item of hardware. The mere fact that certain means are recited in mutually different dependent claims does not indicate that a combination of these means cannot be used advantageously.
Explanation of Signs
[0107] 102 Arithmetic circuit 104 Serialization circuit
Claims
1. A method implemented by a computer for reconfiguring a compression arithmetic circuit from an instruction, wherein the compression arithmetic circuit and the instruction are provided in a serialized bit stream, and the compression arithmetic circuit is as follows: Generating a serialization circuit from an arithmetic circuit having a plurality of data fields by applying a simplification rule, the simplification rule including removing a first subset of the data fields; Encoding the serialization circuit by an entropy encoding method; Thereby being compressed; The method for reconfiguring the compression arithmetic circuit is: Extending the compression arithmetic circuit according to the instruction to determine the serialization circuit; Deserializing the serialization circuit according to the instruction to determine the arithmetic circuit; A method including.
2. The arithmetic circuit includes information represented by a set of symbols for generating a program, and the execution of the program is entrusted to one or more nodes of a blockchain network. The method according to claim 1.
3. The arithmetic circuit includes information including the total number of wire identifiers, the wire identifiers of the inputs and outputs of the arithmetic circuit, gates, and the wire identifiers of the inputs and outputs of the gates. The method according to claim 1 or 2.
4. The first subset of the data fields includes a first subset of wire identifiers from the extended arithmetic circuit, and the first subset of wire identifiers is as follows: The remaining wire identifiers; The total number of wire identifiers; Derivable from one of them. The method according to claim 3.
5. The compression arithmetic circuit includes a main body that encodes the circuit representation, and a header including one or more of a version number, the total number of the wire identifiers, a bit width n bit , a codebook, or any combination thereof, according to the method of claim 3 or 4
6. The instruction includes the codebook for mapping the code to the set of symbols. The method according to claim 5, which depends on claim 2.
7. The codebook is selected from a plurality of codebooks based on querying the version number. The method according to claim 6.
8. The entropy coder of the entropy encoding method constructs a code such that the decoder can detect the start and end positions of the symbol code so that the symbol code is sequentially assigned to each arithmetic operation depending on the required number of inputs of the wire identifier. The method according to any one of claims 2 to 7.
9. If the next wire is the i-th wire in the sequence and the next operator starts at bit j in the stream, the method is as follows: Symbol a having the first bit at position j j detecting step; Step of calculating symbol size s(a j ) using information from a dictionary, and Symbol a i The number of input wires n(a j ) is calculated, and Code a i performing arithmetic operations having and storing wire identifiers (i, i + 1,..., i + n(a i )) - 1); Move the pointer to the next symbol to j + s(a j ), and Move the counter to the next wire at i + n(a j ), and When N wires have been read, ending the process; The method according to claim 8, comprising:
10. The arithmetic circuit is a text file, and the text file includes: Version information; The total number of the wire identifiers; The numbers indicating the wire identifiers of the inputs to the arithmetic circuit; An ordered list of at least one gate, each gate including an operator, at least one input wire identifier, and one output wire identifier; The numbers indicating the wire identifiers of the outputs from the arithmetic circuit; The method according to claim 3, comprising:
11. The method according to claim 10, wherein the first subset of the wire identifiers includes all the wire identifiers of the inputs to the arithmetic circuit, and the simplification rule further includes inserting the total number of the inputs to the arithmetic circuit.
12. The method according to claim 10 or 11, wherein the first subset of the wire identifiers includes the wire identifiers of the outputs of the gates.
13. The method according to any one of claims 11 to 12, wherein the first subset of the wire identifiers includes the first input of the first gate in the ordered list.
14. The method according to any one of claims 11 to 13, wherein the first subset of the wire identifiers includes the wire identifier of the output from the arithmetic circuit having the highest number.
15. A system, comprising: A processor; A memory including executable instructions that, as a result of being executed by the processor, cause the system to execute the computer-implemented method according to any one of claims 1 to 14; A system comprising:
16. A non-transitory computer-readable storage medium storing executable instructions, which, as a result of being executed by a processor of a computer system, cause the computer system to at least execute the computer-implemented method according to any one of claims 1 to 14.
Citation Information
Patent Citations
Redundant type removing device
JP1995168719A
Smartphone fraud-proof authorization and authentication for secure interactions
JP2017187777A
Blockchain implemented method and system
WO2018020389A2
Computer-implemented method and system of tamper-evident recording of a plurality of service data items
WO2018026727A1