Information processing systems, information processing methods, servers, blockchain nodes, and programs
The system verifies raw material composition through commitment values, ensuring transaction integrity and confidentiality, addressing the challenge of balancing transparency and competitive protection in blockchain-based tracking systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- CHAINTOPE INC
- Filing Date
- 2023-02-09
- Publication Date
- 2026-05-07
AI Technical Summary
Existing blockchain-based systems for tracking item components struggle to balance the need for transparency in raw material information with the requirement to protect proprietary know-how and competitive information, as public recording can undermine business competitiveness.
An information processing system using blockchain nodes, servers, and terminals that calculate commitment values based on raw material quantities and identities, allowing verification of raw material composition without revealing exact quantities, ensuring data confidentiality while maintaining transaction integrity.
Enables fraud detection in raw material transactions while keeping the quantity of raw materials secret, thus protecting proprietary information and maintaining competitive advantage.
Smart Images

Figure 0007854718000008 
Figure 0007854718000009 
Figure 0007854718000010
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing system, an information processing method, a server, a blockchain node, and a program.
Background Art
[0002] Conventionally, a technique for recording tracking information of an item to be moved on a blockchain while reducing the amount of data of the tracking information of the item has been known (for example, Patent Document 1). In the technique disclosed in Patent Document 1, when the server receives a request signal including identification information of an item to be tracked, a series of transaction data in which the item corresponding to the identification information included in the request signal has been moved, and a series of accumulators corresponding to the series of transaction data are acquired from the blockchain. Then, the server verifies whether or not the identification information of the item to be tracked is stored in each accumulator in the acquired series of accumulators, and outputs the verification result.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] By the way, a user who uses an item that is a product or service may want to know what elements the item is composed of. For example, consider the case where a certain industrial product is manufactured. Note that industrial products often include various raw materials (for example, rare metals, etc.).
[0005] In particular, in recent years, the United Nations has established the Sustainable Development Goals (SDGs), and there is a demand for the provision of items that consider the global environment. Therefore , if it is possible to verify whether the elements constituting the item are environmentally friendly, it is considered that the verification results can also be used as SDGs indicators. However, for processed products or industrial products made of the same kind of raw materials, it is difficult to distinguish the differences from their appearance or the like. On the other hand, if information on the raw materials of the item (or information on the process in which energy is supplied) can be traced, it will be possible to set, measure, and evaluate indicators based on that information, and it will also be possible to restrict the movement of items whose indicators do not meet the predetermined criteria.
[0006] Note that before industrial products are supplied to consumers, a supply chain of raw materials and intermediate materials is often formed by multiple operators. For example, a certain operator A procures a plurality of raw materials a1, a2, a3, and manufactures an intermediate material M A from those raw materials a1, a2, a3. Next, operator B procures the intermediate material M A from operator A, and adds raw materials b1, b2 to the intermediate material M A to manufacture an intermediate material M B . Next, operator C procures the intermediate material M B from operator B, and combines the intermediate material M B with some other different intermediate materials to manufacture an industrial product M C . Then, the industrial product M C is supplied from operator C to consumers.
[0007] In this case, for example, consumers or institutions that conduct quality inspections may want to know information regarding the origin of the raw materials contained in the industrial product M C , the content rate of recycled materials, the purity measured during the refining process, and the blending ratio of components such as elements or molecules. Furthermore, consumers or institutions that supervise the distribution may want to know information regarding the industrial product M CInformation about which businesses manufactured and supplied the product may also be desired. Furthermore, individual businesses may want information about the raw materials or components they procured.
[0008] If data related to such traded items were made public using network technologies such as blockchain, multiple businesses and consumers would be able to freely access information related to the traded items. For example, multiple businesses and consumers could access information such as the origin of raw materials contained in a particular part, the percentage of recycled materials, the purity measured during the refining process, and the blending ratio of elements or molecules, etc., to confirm what raw materials make up the parts or intermediate materials they have acquired. They could then use this information to label the products they ship or to identify parts or intermediate materials that do not meet the standards they have set for themselves.
[0009] However, if such data is recorded on a blockchain and made public, an unspecified number of third parties will be able to freely view that data. For example, if data related to know-how for manufacturing industrial products is recorded on a blockchain, it could potentially undermine the competitiveness of that business.
[0010] For example, a particular business may want to keep information regarding the blending ratio of raw materials secret from its competitors, and may be willing to disclose that information to businesses with which it has a direct contractual relationship, but not to third parties with whom it does not have a contractual relationship.
[0011] This invention was made in view of the above circumstances, and aims to verify that there is no fraud in the trading of raw materials contained in an item, while keeping the quantity of raw materials contained in the item secret. [Means for solving the problem]
[0012] To achieve the above objective, the information processing system according to the present invention is an information processing system including a server, a plurality of blockchain nodes, and a plurality of terminals, wherein the terminals transmit to the server: a target item identification data representing the identification information of the item to be generated, raw material identification data which is the identification information of the raw materials used when generating the target item, quantity data representing the quantity of the raw materials, and source item identification data representing the identification information of the source item; the server calculates the commitment value of the target item by performing a secure calculation based on the parameter values corresponding to the raw materials and the quantity data; stores the combination of the raw material identification data and the target item identification data in a predetermined data structure; obtains first transaction data which is transaction data recorded in the blockchain stored in the storage unit of the blockchain node and in which the source item identification data is included in the output data; and obtains an address representing the source of the target item and an address representing the destination of the target item. Transaction data including a response and the data structure, wherein the source item identification data is included in the input data and the data structure including the target item identification data is included in the output data, is broadcast to multiple blockchain nodes, and each of the multiple blockchain nodes reads from the blockchain each of the first transaction data which is past transaction data associated with the second transaction data broadcast by the server, and verifies whether the target item of the second transaction data is composed of the raw materials included in the source item of the first transaction data based on the relationship between the commitment value of the target item included in the second transaction data and the commitment value of the source item included in the first transaction data, and if it is determined that the target item of the second transaction data is composed of the raw materials of the first transaction data,This is an information processing system that records the aforementioned second transaction data onto the blockchain.
[0013] Furthermore, the server of the present invention is a server in an information processing system including a server, a plurality of blockchain nodes, and a plurality of terminals, wherein the terminal transmits to the server: a target item identification data representing identification information of the item to be generated, raw material identification data which is identification information of the raw materials used when generating the target item, quantity data representing the quantity of the raw materials, and source item identification data representing identification information of the source item; the server calculates the commitment value of the target item by performing a secure calculation based on the parameter values corresponding to the raw materials and the quantity data; stores the combination of the raw material identification data and the target item identification data in a predetermined data structure; obtains first transaction data which is transaction data recorded in the blockchain stored in the storage unit of the blockchain node and in which the source item identification data is included in the output data; and a transaction data including an address representing the sender of the target item, an address representing the destination of the target item, and the data structure. The system broadcasts second transaction data, which is a transaction data in which the source item identification data is included in the input data and the data structure including the target item identification data is included in the output data, to multiple blockchain nodes. Each of the multiple blockchain nodes reads from the blockchain each of the first transaction data, which is past transaction data associated with the second transaction data broadcast by the server, and verifies whether the target item in the second transaction data is composed of the raw materials included in the source item in the first transaction data, based on the relationship between the commitment value of the target item included in the second transaction data and the commitment value of the source item included in the first transaction data. If it is determined that the target item in the second transaction data is composed of the raw materials in the first transaction data, the system records the second transaction data to the blockchain.It is a server.
[0014] Furthermore, the blockchain node of the present invention is a blockchain node in an information processing system including a server, a plurality of blockchain nodes, and a plurality of terminals, wherein the terminal transmits to the server: a target item identification data representing the identification information of the item to be generated, raw material identification data which is the identification information of the raw materials used when generating the target item, quantity data representing the quantity of the raw materials, and source item identification data representing the identification information of the source item; the server calculates the commitment value of the target item by performing a secure calculation based on the parameter values corresponding to the raw materials and the quantity data, stores the combination of the raw material identification data and the target item identification data in a predetermined data structure, obtains first transaction data which is transaction data recorded in the blockchain stored in the storage unit of the blockchain node and in which the source item identification data is included in the output data, and provides an address representing the sender of the target item and a destination of the target item. Transaction data including an address and the data structure, wherein the source item identification data is included in the input data and the data structure including the target item identification data is included in the output data, is broadcast to multiple blockchain nodes, and each of the multiple blockchain nodes reads from the blockchain each of the first transaction data which is past transaction data associated with the second transaction data broadcast by the server, and verifies whether the target item in the second transaction data is composed of the raw materials included in the source item in the first transaction data based on the relationship between the commitment value of the target item included in the second transaction data and the commitment value of the source item included in the first transaction data, and if it is determined that the target item in the second transaction data is composed of the raw materials in the first transaction data,This is a blockchain node that records the aforementioned second transaction data onto the blockchain.
[0015] Furthermore, the information processing method of the present invention is an information processing method executed by an information processing system including a server, a plurality of blockchain nodes, and a plurality of terminals, wherein the terminals transmit to the server: a target item identification data representing identification information of a target item to be generated, raw material identification data which is identification information of raw materials used when generating the target item, quantity data representing the quantity of the raw materials, and source item identification data representing identification information of the source item; the server calculates the commitment value of the target item to be generated by performing a secure calculation based on the parameter values corresponding to the raw materials and the quantity data; stores the combination of the raw material identification data and the target item identification data in a predetermined data structure; obtains first transaction data which is transaction data recorded in the blockchain stored in the storage unit of the blockchain node and in which the source item identification data is included in the output data; and a transaction including an address representing the source of the target item, an address representing the destination of the target item, and the data structure. The system broadcasts second transaction data, which is transaction data in which the source item identification data is included in the input data and the data structure including the target item identification data is included in the output data, to multiple blockchain nodes. Each of the multiple blockchain nodes reads from the blockchain each of the first transaction data, which is past transaction data associated with the second transaction data broadcast by the server, and verifies whether the target item in the second transaction data is composed of the raw materials included in the source item in the first transaction data, based on the relationship between the commitment value of the target item included in the second transaction data and the commitment value of the source item included in the first transaction data. If it is determined that the target item in the second transaction data is composed of the raw materials in the first transaction data, the system records the second transaction data to the blockchain.It is an information processing method.
[0016] The present invention is a program to be executed by a server in an information processing system including a server, a plurality of blockchain nodes, and a plurality of terminals, wherein the terminal transmits to the server: a target item identification data representing identification information of a target item to be generated, raw material identification data which is identification information of raw materials used when generating the target item, quantity data representing the quantity of the raw materials, and source item identification data representing identification information of the source item; the server calculates the commitment value of the target item by performing a secure calculation based on the parameter values corresponding to the raw materials and the quantity data; stores the combination of the raw material identification data and the target item identification data in a predetermined data structure; obtains first transaction data which is transaction data recorded in the blockchain stored in the storage unit of the blockchain node and in which the source item identification data is included in the output data; and obtains second transaction data which includes an address representing the sender of the target item, an address representing the destination of the target item, and the data structure, wherein the source item identification data is included in the input data and the data structure including the target item identification data is included in the output data. This program broadcasts transaction data to multiple blockchain nodes, and each of the multiple blockchain nodes reads from the blockchain each of the first transaction data, which is past transaction data associated with the second transaction data broadcast by the server, and verifies whether the target item of the second transaction data is composed of the raw materials included in the raw materials included in the first transaction data, based on the relationship between the commitment value of the target item of the second transaction data and the commitment value of the source item included in the first transaction data, and if it is determined that the target item of the second transaction data is composed of the raw materials of the first transaction data, it records the second transaction data to the blockchain.
[0017] The present invention is a program to be executed by a blockchain node in an information processing system including a server, a plurality of blockchain nodes, and a plurality of terminals, wherein the terminal transmits to the server: a target item identification data representing the identification information of the item to be generated, raw material identification data which is the identification information of the raw materials used when generating the target item, quantity data representing the quantity of the raw materials, and source item identification data representing the identification information of the source item; the server calculates the commitment value of the target item by performing a secure calculation based on the parameter values corresponding to the raw materials and the quantity data; stores the combination of the raw material identification data and the target item identification data in a predetermined data structure; obtains first transaction data which is transaction data recorded in the blockchain stored in the storage unit of the blockchain node and in which the source item identification data is included in the output data; and obtains the address representing the sender of the target item and the sender of the target item. Transaction data including an address representing a destination and the data structure, wherein the source item identification data is included in the input data and the data structure including the target item identification data is included in the output data, is broadcast to multiple blockchain nodes, and each of the multiple blockchain nodes reads from the blockchain each of the first transaction data which is past transaction data associated with the second transaction data broadcast by the server, and verifies whether the target item of the second transaction data is composed of the raw materials included in the source item of the first transaction data based on the relationship between the commitment value of the target item included in the second transaction data and the commitment value of the source item included in the first transaction data, and if it is determined that the target item of the second transaction data is composed of the raw materials of the first transaction data,This is a program that records the aforementioned second transaction data onto the blockchain. [Effects of the Invention]
[0018] According to the present invention, it is possible to verify that there is no fraud in the trading of raw materials contained in an item, while keeping the quantity of raw materials contained in the item secret. [Brief explanation of the drawing]
[0019] [Figure 1] This figure shows an example of the schematic configuration of the information processing system of this embodiment. [Figure 2] This is a schematic block diagram of computers that function as individual components of an information processing system. [Figure 3] This is an explanatory diagram illustrating the processing of the information processing system of this embodiment. [Figure 4] This is a diagram illustrating this embodiment. [Modes for carrying out the invention]
[0020] The embodiments will be described in detail below with reference to the drawings.
[0021] <System Configuration of Information Processing System>
[0022] Figure 1 is a block diagram of the information processing system 10 of this embodiment. As shown in Figure 1, the information processing system 10 of this embodiment is composed of a terminal 12, a server 14, and a blockchain node 16. Each device of the information processing system 10 is connected by a network 20, such as the Internet. Note that unless a specific node among the multiple blockchain nodes 16A, 16B, 16C is being described, the blockchain node will simply be referred to as "blockchain node 16". Similarly, unless a specific terminal among the multiple terminals 12A, 12B, 12C, ..., 12X is being described, the terminal will simply be referred to as "terminal 12".
[0023] Note that while Figure 1 shows three blockchain nodes, it may include more blockchain nodes. Also, while Figure 1 shows four terminals, it may include more terminals.
[0024] In recent years, there has been an increasing demand for the disclosure of some of the events that occurred during the production or distribution of goods or services (hereinafter also simply referred to as "items"). For example, as evidence of efforts to address environmental issues, businesses may be required to disclose figures such as the rate of renewable energy utilization, CO2 emissions, or the recycling rate of raw materials used in the provision of an item.
[0025] Currently, such information is often reported as a sum of corporate activities over a certain period (for example, one year). On the other hand, if details are added to individual items, that information can be considered added value for those items. Furthermore, by adding details to items, it becomes possible to prove that those items comply with international regulations on distribution.
[0026] Let's consider a scenario where item X is handed over from one business U1 to another U2, and business U2 manufactures a new item Y based on item X. This entire sequence of events is represented as data representing a single transaction slip. This transaction slip data is then recorded on the blockchain. Since the transaction slip data is stored in the memory units (not shown) of multiple blockchain nodes 16A, 16B, and 16C, the transaction data recorded on the blockchain becomes public. Third parties can view this transaction data. As a result, details are assigned to the item, and a series of pieces of information regarding the manufacture or provision of the item becomes public.
[0027] However, on the other hand, there is information that companies wish to keep confidential when manufacturing or supplying items. For example, for a company that manufactures intermediate materials by mixing multiple raw materials, information regarding the mixing ratio of those raw materials is considered proprietary know-how and is likely to be kept confidential. Since this know-how information is also the intellectual property of each company, it is common for companies to want to avoid disclosing their intellectual property to third parties free of charge.
[0028] Therefore, in the information processing system 10 of this embodiment, information regarding the quantity of raw materials contained in an item is not recorded on the blockchain. Instead, the quantity of raw materials contained in an item is kept secret, while verifying that there is no fraud in the transaction of the raw materials contained in the item.
[0029] Specifically, in the information processing system 10 of this embodiment, a commitment value for each item is calculated by performing a predetermined secret calculation based on quantity data representing the quantity of raw materials contained in the item and parameter values set for each raw material. In the information processing system 10 of this embodiment, this commitment value is recorded on the blockchain, and the transaction of the raw materials contained in each item is verified to be free from fraud based on the commitment value. This makes it possible to verify that the transaction of the raw materials contained in an item is free from fraud while keeping the quantity of raw materials contained in the item secret, without recording information about the quantity of raw materials contained in the item on the blockchain.
[0030] Each device included in the information processing system 10 is implemented by a computer that includes a CPU (Central Processing Unit), ROM (Read Only Memory) which stores programs for implementing each processing routine, RAM (Random Access Memory) which temporarily stores data, memory as a means of storage, a network interface, and the like.
[0031] The terminal 12, server 14, and blockchain node 16 can be implemented, for example, by the computer 70 shown in Figure 2. The computer 70 includes a CPU 71, memory 72 as a temporary storage area, and a non-volatile storage unit 73. The computer 70 also includes an input / output interface (I / F) 74 to which input / output devices (not shown) are connected, and a read / write (R / W) unit 75 that controls the reading and writing of data to the recording medium. The computer 70 also includes a network I / F 76 that connects to a network such as the Internet. The CPU 71, memory 72, storage unit 73, input / output I / F 74, R / W unit 75, and network I / F 76 are connected to each other via a bus 77.
[0032] The storage unit 73 can be implemented using a hard disk drive (HDD), solid state drive (SSD), flash memory, etc. The storage unit 73, as a storage medium, stores the program necessary for the computer 70 to function. The CPU 71 reads the program from the storage unit 73, loads it into memory 72, and sequentially executes the processes contained in the program.
[0033] <Operation of Information Processing System 10>
[0034] Next, the operation of the information processing system 10 in this embodiment will be described. In this embodiment, the case in which the information processing system 10 records the details of product C to the blockchain will be described as an example.
[0035] Product C is assumed to be composed of cobalt, nickel, and manganese as its raw materials. The following explanation uses the example of extracting cobalt, nickel, and manganese—the raw materials for Product C—from Product A and Product B, and then using the extracted raw materials to produce Product C. Furthermore, the explanation will consider the case where, in the process of producing Product C, some (or all) of the raw materials constituting Product A or Product B are not consumed, and Product D is produced using the remaining unconsumed raw materials. Therefore, Products A and B are examples of source items, and Product C is an example of a target item.
[0036] In this embodiment, the combination of an item (product) and its raw materials (for example, product C is composed of cobalt: 5, nickel: 4, and manganese: 9) can be traced. However, the quantity data of the raw materials must be kept confidential. On the other hand, it is necessary to prove to third parties, for example, that product C is produced from product A and product B.
[0037] Therefore, in this embodiment, it is possible to prove that an item is properly manufactured while keeping the quantity data of the raw materials constituting the item confidential. This will be explained in detail below.
[0038] When a user operating terminal 12 inputs information about product C, the item to be generated, into terminal 12, the sequence shown in Figure 3 is executed.
[0039] In step S100, terminal 12 receives information about an item entered by the user. This information about the item includes, for example, quantity data representing the quantity of raw materials that make up product C, which is the item to be generated. For example, the quantity (or proportion) of the raw materials that make up product C is as follows.
[0040] Cobalt: 5 Nickel: 4 Manganese: 9
[0041] Furthermore, the quantities of raw materials that make up Product A, the source item, are as follows:
[0042] Cobalt: 3 Nickel: 7 Manganese: 5
[0043] Furthermore, the quantities of raw materials that make up Product B, the source item, are as follows:
[0044] Cobalt: 4 Manganese: 8
[0045] Furthermore, the quantities of raw materials that make up Product D, which corresponds to the surplus raw materials that are not consumed, are as follows:
[0046] Cobalt: 2 Nickel: 3 Manganese: 4
[0047] In step S102, terminal 12 sends to server 14 item identification data (hereinafter simply referred to as "item ID") representing the identification information of product C to be generated, the item ID of product A from which it was generated, the item ID of product B from which it was generated, raw material identification data (hereinafter simply referred to as "raw material ID") which is the identification information of the raw materials that make up product C, and quantity data representing the quantity (or ratio) of raw materials consumed when generating product C.
[0048] In step S104, the server 14 receives the data transmitted from the terminal 12 in step S102. Also in step S104, the server 14 obtains the parameter value corresponding to the raw material of the received raw material ID, the blind parameter value G corresponding to the blind factor, and a random coefficient r for the blind parameter value G. The blind factor rG is data representing a hypothetical raw material that is not actually included in product C. The random coefficient r for the blind parameter value G is also the value of the blind quantity data corresponding to the quantity of the blind factor.
[0049] The parameter values and blind parameter values G are obtained by calculation using a commitment scheme with additive homomorphism. For example, the parameter values and blind parameter values G are calculated using the Pedersen commitment, which is one example of a known method (see Section 3 of https: / / link.springer.com / content / pdf / 10.1007%2F3-540-46766-1_9.pdf#page=3!). The parameter values and blind parameter values G are calculated using the Pedersen commitment. When parameter values G are calculated, points (coordinates) on the elliptic curve with unknown discrete logarithms are selected as the parameter values and blind parameter values G corresponding to each raw material. This yields parameter values and blind parameter values G that exhibit additive homomorphism. For example, the following parameter values are obtained for each raw material:
[0050] Cobalt:H C Nickel: H N Manganese: H M Blind parameter value: G
[0051] Note that the commitment value C of product A, the source item, is... A And the commitment value C of product B, which is the source item. BThis is calculated according to the following formula, where r1 and r2 are random coefficients for the blind parameter value G. These commitment values C A ,C B As will be explained later, this is recorded in the past transaction data on the blockchain.
[0052]
number
[0053] In step S106, the server 14 sets the parameter value H corresponding to each raw material, as shown in the following formula. C ,H N ,H M Furthermore, by performing a secure calculation that involves summing up the products of the blind parameter value G, the quantity data of each raw material, and a random coefficient r3 for the blind parameter value G, the commitment value C of product C is determined. C Calculate.
[0054]
number
[0055] Note that the above commitment value corresponds to a single point on an elliptic curve where the discrete logarithm is unknown. Therefore, the above commitment value C C It is not possible to calculate how much of the raw material is contained in product C from this.
[0056] Furthermore, in step S106, the server 14 sets the parameter value H corresponding to each raw material, as shown in the following formula. C ,H N ,H M Furthermore, by performing a secure calculation that involves summing up the products of the blind parameter value G, the quantity data of each raw material, and a random coefficient r4 for the blind parameter value G, the commitment value C of product D is determined. D Calculate.
[0057]
number
[0058] When calculating commitment values without introducing the blind factor rG, different items will have the same commitment value if they are composed of the same quantity of raw materials or the same ratio of raw materials. By introducing the blind factor rG, it becomes possible to assign different commitment values to different items, even if they are composed of the same quantity of raw materials or the same ratio of raw materials.
[0059] Furthermore, in order to satisfy equation (A), which will be described later, the random coefficients r1, r2, r3, and r4 are pre-adjusted and set so that equation (B) is satisfied.
[0060]
number
[0061] In step S108, the server 14 stores the combination of the item ID of product C and the raw material ID of each raw material in an accumulator, for example, as disclosed in Japanese Patent Publication No. 2021-064219. By storing various data in the accumulator, it becomes possible to record item tracking information on the blockchain while reducing the amount of data for item tracking information. Similarly, the server 14 also stores the combination of the item ID of product D and the raw material ID of each raw material in a predetermined data structure.
[0062] As mentioned above, server 14 has parameter value H C ,H N ,H M And set the blind parameter value G. Parameter value HC ,H N ,H M The commitment value calculated based on the blind parameter value G, the quantity data corresponding to the raw material combination, and random coefficients is unique and differs from the commitment value calculated for other raw material combinations. Therefore, the commitment value can also be used as identification data. The parameter value H used when calculating the commitment value. C ,H N ,H M The blind parameter value G is stored and managed in the storage unit (not shown) of the server 14.
[0063] Next, server 14 accesses blockchain node 16 to obtain transaction data containing an accumulator with the item ID of the originating product A in the output data, and transaction data containing an accumulator with the item ID of the originating product B in the output data. Server 14 obtains the transaction data based on the transaction ID assigned to the transaction data.
[0064] Specifically, in step S110, the server 14 sends a request signal to the blockchain node 16 to obtain transaction data in which an accumulator is recorded, which includes the item ID of the originating product A and the item ID of the originating product B in the output data.
[0065] In step S112, when the blockchain node 16 receives the request signal sent from the server 14 in step S110, it sends to the server 14 past transaction data in which the item ID of product A is recorded as output information, and past transaction data in which the item ID of product B is recorded as output data. In this embodiment, such past transaction data is also referred to as first transaction data.
[0066] In step S114, the server 14 obtains the first transaction data output from the blockchain node 16.
[0067] In step S116, the server 14 generates second transaction data, which is transaction data that includes an address representing the source of product C, which is the item to be generated, an address representing the destination of product C, and the above data structure.
[0068] Specifically, Server 14 includes the output data of the past first transaction data in the input data of the second transaction data. Furthermore, Server 14 generates the second transaction data by including the transaction ID on the blockchain related to the past first transaction data in the input data of the second transaction data. Server 14 also includes the item ID, raw material ID, and commitment value of Product C in the output data that constitutes the second transaction data. As mentioned above, the item ID and raw material ID of Product C are stored in an accumulator, which is a predetermined data structure. The commitment value may also be stored in the accumulator. In this embodiment, the case where the item ID and raw material ID are stored in the accumulator is described as an example, but the item ID and raw material ID may not be stored in the accumulator and may instead be recorded directly in the output data that constitutes the second transaction data.
[0069] As mentioned above, if some (or all) of the raw materials are not consumed during the process of generating product C, data related to product D, which corresponds to the remaining unused raw materials, is also included in the accumulator. This recording method is one example of an implementation that expresses the conservation law between the raw materials represented by the input data and the raw materials represented by the output data within a single transaction data. Another possible method is to record the waste, which is the remaining raw material generated when generating the item to be generated, on a separate blockchain and reference it between different blockchains.
[0070] Figure 4 shows a diagram illustrating the data structure of transaction data. As shown in Figure 4, transaction data TX2 contains an address representing the source of the product and an address representing the destination of the product.
[0071] Furthermore, as shown in Figure 4, the input data for transaction data TX2 includes the output data of past transaction data TX1-1 and the output data of past transaction data TX1-2.
[0072] On the other hand, as shown in Figure 4, the output data of transaction data TX2 includes an accumulator containing the item ID and raw material ID of product C, which is the product to be generated. Furthermore, this accumulator also contains the item ID and raw material ID of product D, which is generated from the remaining raw materials. In addition, the output data of transaction data TX1-1 and transaction data TX1-2, which are the transaction data of the source items, include an accumulator that stores the item IDs and raw material IDs of products A and B, which were previously the products to be generated.
[0073] In step S118, the server 14 broadcasts the second transaction data generated in step S118 to multiple blockchain nodes 16.
[0074] In step S120, each of the multiple blockchain nodes 16 receives the second transaction data. In step S120, each of the multiple blockchain nodes 16 reads each of the first transaction data, which is past transaction data associated with the second transaction data, from the blockchain. Specifically, each of the multiple blockchain nodes 16 reads each of the first transaction data from the blockchain in accordance with a predetermined protocol, based on the identification data on the blockchain relating to the past first transaction data contained in the second transaction data.
[0075] In step S122, each of the multiple blockchain nodes 16 sets the commitment value C of product C contained in the second transaction data TX2. C and the remaining commitment value C of product D D And the commitment value C of product A included in the first transaction data TX1-1. A and the commitment value C of product B included in the first transaction data TX1-2 B Based on the relationship between them, we verify whether product C, the item to be generated in the second transaction data TX2, is composed of the raw materials of products A and B, the source items for generating the first transaction data TX1-1 and TX1-2.
[0076] As mentioned above, if each parameter value and blind factor is generated by Pedersen commitment, the commitment values of past transaction data included in the input data within the second transaction data should be equal to the commitment values included in the output data. Therefore, for example, if the sum of the commitment values included in the input data within the second transaction data is not equal to the sum of the commitment values included in the output data within the second transaction data, it means that the items to be generated have not been generated properly for some reason.
[0077] Therefore, each of the multiple blockchain nodes 16 records the second transaction data on the blockchain if the sum of the commitment values contained in the output data within the first transaction data (the sum of the commitment values contained in the input data within the second transaction data) is equal to the sum of the commitment values contained in the output data within the second transaction data.
[0078] On the other hand, if each of the multiple blockchain nodes 16 finds that the sum of commitment values contained in the output data within the first transaction data (the sum of commitment values contained in the input data within the second transaction data) is not equal to the sum of commitment values contained in the output data within the second transaction data, it discards the second transaction data without recording it on the blockchain.
[0079] For example, if the output data contains multiple item IDs, the sum of the multiple commitment values included in the transaction data's output data will be made public on the blockchain.
[0080] Specifically, each of the multiple blockchain nodes 16 calculates the commitment value C of product C contained in the second transaction data TX2, as shown in the following formula.C And commitment value C, which corresponds to the surplus raw materials generated when producing product C. D The sum of these is the sum of the commitment values of raw materials included in multiple first transaction data TX1-1,TX2 (C A and C B If the sum of the two is equal, it is determined that product C of the second transaction data TX2 is composed of raw materials from multiple first transaction data TX1-1 and TX-2.
[0081]
number
[0082] In step S124, each of the multiple blockchain nodes 16 records the second transaction data TX2 on the blockchain if it determines that product C of the second transaction data TX2 is composed of the raw materials of the first transaction data TX1-1 and TX-2.
[0083] Furthermore, depending on the commitment value recorded in the transaction data, an overflow may occur during the addition process of the commitment value performed by each blockchain node 16, potentially leading to an incorrect calculation result. Therefore, it is preferable to include proof that the commitment value is within an appropriate range. This can be done, for example, by including a range proof. Examples of known methods include proof schemes such as Borromean Ring Signatures (https: / / www.semanticscholar.org / paper / Borromean-Ring-Signatures-%E2%88%97-Maxwell-Poelstra / 4160470c7f6cf05ffc81a98e8fd67fb0c84836ea) and Bulletproofs (https: / / eprint.iacr.org / 2017 / 1066.pdf).
[0084] Furthermore, when server 14 receives a request signal from terminal 12 representing a request for disclosure of parameter values corresponding to the raw material ID, it performs authentication processing with terminal 12, the source of the request signal. Then, if terminal 12, the source of the request signal, is a terminal that has been previously authorized to disclose parameter values, server 14 discloses the parameter values to terminal 12. Terminal 12 then verifies whether product C has been properly manufactured based on the disclosed parameter values and the commitment value recorded in the transaction data.
[0085] For example, a user who receives product C to be generated can decommit product C using the commitment value recorded on the blockchain to verify whether or not product C was manufactured using the appropriate raw materials.
[0086] Furthermore, if Pedersen commitment is used to calculate the commitment value, decommitment may be performed according to the following procedure.
[0087] Specifically, for example, a terminal 12X operated by a user who has received product C, or a third party, sends a predetermined request signal to the server 14 in response to the user's operation. In response to the request signal, the server 14, after the authentication process described above, sets the parameter value H C ,H N ,H M The quantity data of the raw materials (cobalt: 5, nickel: 4, manganese: 9) and the blind factor rG are sent to the terminal 12X operated by the user. The terminal 12X also accesses the blockchain node 16 and receives the commitment value C of product C recorded in the second transaction data. C Obtain it.
[0088] Terminal 12X has parameter value H C ,H N ,H MThis includes the quantity data of the raw materials (cobalt: 5, nickel: 4, manganese: 9), the blind factor rG, and the commitment value C of the second transaction data recorded on the blockchain. C Based on this, a verification result is generated using a known decommitment method to indicate whether product C was properly manufactured from products A and B. Terminal 12X receives the commitment value C of product C recorded in the second transaction data. C If the product C is calculated based on the quantity data of the raw materials and product C is properly manufactured from products A and B (hereinafter simply referred to as "product C is properly generated"), the verification result to that effect is displayed on the display unit (not shown). On the other hand, if product C is not properly generated, terminal 12X displays the verification result to that effect on the display unit (not shown).
[0089] Furthermore, it is highly likely that the user who received Product C has received the ingredient list and other information for Product C from the user who created Product C. Therefore, the terminal 12X operated by the user who received Product C will have the raw material quantity data (cobalt: 5, nickel: 4, manganese: 9) recorded in the ingredient list and the parameter value H C ,H N ,H M Based on the blind factor rG, the commitment value C of product C is calculated. C It is also possible to calculate ' yourself. For this reason, the terminal 12X operated by the user who received product C will use the commitment value C that it calculated itself. C 'and the commitment value C recorded on the blockchain C The system may also be configured to compare the two and generate a verification result indicating whether or not product C was generated correctly.
[0090] In addition, the blind factor rG may be generated by the terminal 12X operated by the user receiving product C, and the generated values may be sent to the server 14. In this case, in step S104, the terminal 12X operated by the user receiving product C sends the blind factor rG to the server 14.
[0091] Furthermore, without disclosing the blind factor rG to terminal 12X, it is also possible to generate a verification result indicating whether or not product C was properly generated, based on the subtracted value obtained by subtracting the blind factor rG from each commitment value using a known decommitment method, and the digital signature generated from the blind factor rG.
[0092] It is also possible to use the KZG commitment (see, for example, https: / / www.iacr.org / archive / asiacrypt2010 / 6477178 / 6477178.pdf) to calculate the commitment value. When using the Pedersen commitment, when decommitting, it is necessary to disclose the quantity data of the raw materials included in the commitment value. In contrast, when using the KZG commitment, which is a commitment scheme that uses polynomials, it is possible to disclose only the quantity data of some of the raw materials.
[0093] Specifically, when KZG commitment is used to calculate the commitment value, it is possible to disclose quantity data for only some of the raw materials that make up the item, while keeping the quantity data for other raw materials confidential. When KZG commitment is used to calculate the commitment value, the commitment value is calculated using a polynomial. Furthermore, when KZG commitment is used to calculate the commitment value, commitment values calculated using different polynomials can be added together due to the property of additive homomorphism.
[0094] When using KZG commitment to calculate the commitment value, the parameter value representing the target raw material and the blind parameter value are denoted as x, and the value calculated by the polynomial f(x) is used as the quantity of the target raw material and the blind factor value to construct the polynomial f(x), and a KZG commitment is generated for that polynomial to create a commitment value that conceals the raw material and its quantity.
[0095] Furthermore, when constructing the polynomial, it is acceptable to omit the aforementioned blind parameter values.
[0096] In the examples above, we explained the use of Pedersen commitment and KZG commitment in calculating the commitment value, but any commitment scheme that exhibits additive homomorphism can be used.
[0097] As described above, the terminal of the information processing system according to this embodiment transmits to the server: item identification data representing the identification information of the item to be generated, raw material identification data which is the identification information of the raw materials used when generating the item to be generated, quantity data representing the quantity of the raw materials, and source item identification data representing the identification information of the source item. The server calculates the commitment value of the item to be generated by performing a secure computation based on the parameter values and quantity data corresponding to the raw materials. The server stores the combination of the commitment value, raw material identification data and item identification data to be generated in a predetermined data structure. The server obtains first transaction data which is transaction data recorded in the blockchain stored in the memory of the blockchain node and in which source item identification data is included in the output data. The server then broadcasts second transaction data to multiple blockchain nodes, which is transaction data including an address representing the source of the item to be generated, an address representing the destination of the item to be generated, and a data structure, in which source item identification data is included in the input data and the data structure including the item identification data to be generated is included in the output data. Each of the multiple blockchain nodes reads from the blockchain each of the first transaction data, which is past transaction data associated with the second transaction data broadcast by the server. Each of the multiple blockchain nodes verifies whether the items in the second transaction data are composed of the raw materials included in the raw materials included in the raw materials included in the first transaction data, based on the relationship between the commitment value of the item to be generated in the second transaction data and the commitment value of the source item included in the first transaction data. If it is determined that the item to be generated in the second transaction data is composed of the raw materials included in the first transaction data, the second transaction data is recorded on the blockchain.This allows for the verification that there is no fraud in the trading of raw materials contained in an item, while keeping the quantity of raw materials contained in the item a secret.
[0098] Furthermore, by introducing a blind factor rG when calculating the commitment value of an item, it is possible to prevent different items from having the same commitment value.
[0099] It should be noted that the present invention is not limited to the embodiments described above, and various modifications and applications are possible without departing from the spirit of the invention.
[0100] For example, items can include not only real-world objects but also specific data.
[0101] Furthermore, although the above embodiment describes the case in which a blind factor rG is introduced when calculating the commitment value, it is not limited to this. The commitment value may also be calculated without introducing a blind factor rG.
[0102] Furthermore, in the above embodiment, the example described was that the random coefficients r1, r2, r3, and r4 are pre-adjusted so that equation (B) is satisfied, but the invention is not limited to this. If the random coefficients r1, r2, r3, and r4 do not satisfy equation (B), it is also possible to verify whether the product to be generated is properly manufactured from the original product using known methods by attaching a digital signature to the value corresponding to the right-hand side of the following equation.
[0103]
number
[0104] In this case, as described above, when the server 14 calculates the commitment value of the product C to be generated, it uses the blind factor rG to calculate the commitment value of the product C to be generated. CThe server calculates the commitment value C of the product C to be generated, which is included in the second transaction data. C And the commitment value C, which corresponds to the surplus raw materials. D The sum of (C C +C D ) and the sum of the commitment values of the originating products A and B included in multiple first transaction data (C A +C B A digital signature is generated on the information representing the difference between (C) and (C), and this digital signature is added to the second transaction data. A +C B )-(C C +C D Even if the result of the calculation is not 0, a digital signature is attached to the result, so it is possible to verify whether the product being generated is properly manufactured from the original product based on that digital signature.
[0105] Furthermore, although the above embodiment was described using the example of a case where product D, which corresponds to the excess raw materials not consumed when producing product C, is produced, it is not limited to this, and this embodiment can also be applied even when no excess raw materials are generated.
[0106] Furthermore, although the above embodiment was described using the example of a case where the server 14 performs various processes, some or all of these processes may be performed by the terminal 12 or the blockchain node 16.
[0107] Furthermore, although this specification describes an embodiment in which the program is pre-installed, it is also possible to provide the program stored on a computer-readable recording medium. For example, the program may be stored on a CD-ROM (Compact Disk Read Only). The program may be provided in a form stored on non-transitory storage media such as Memory, DVD-ROM (Digital Versatile Disk Read Only Memory), and USB (Universal Serial Bus) memory. Alternatively, the program may be provided in a form downloaded from an external device via a network.
[0108] In the above embodiment, the processing that the CPU reads and executes software (programs) may be executed by various processors other than the CPU. Examples of such processors include PLDs (Programmable Logic Devices) such as FPGAs (Field-Programmable Gate Arrays) whose circuit configuration can be changed after manufacturing, and dedicated electrical circuits that are processors with circuit configurations specifically designed to execute specific processing, such as ASICs (Application Specific Integrated Circuits). Alternatively, a GPGPU (General-purpose graphics processing Unit) may be used as the processor. Furthermore, each processing may be executed by one of these various processors, or by a combination of two or more processors of the same or different types (for example, multiple FPGAs, and a combination of a CPU and an FPGA). More specifically, the hardware structure of these various processors is an electrical circuit that combines circuit elements such as semiconductor elements.
[0109] Furthermore, each process in this embodiment may be configured by a computer or server equipped with a general-purpose processing unit and storage device, and each process may be executed by a program. This program is stored in the storage device and can be recorded on a recording medium such as a magnetic disk, optical disk, or semiconductor memory, or provided over a network. Of course, none of the other components have to be implemented by a single computer or server; they may be implemented in a distributed manner across multiple computers connected by a network.
[0110] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.
[0111] In the embodiments described above, please note that unless the word "only" is used, such as "based only on XX," "according only to XX," or "in the case of XX only," it is assumed in this specification that additional information may also be considered. For example, the statement "do b in the case of a" does not necessarily mean "always do b in the case of a" unless explicitly stated otherwise.
[0112] Furthermore, even if there are aspects of a method, program, terminal, device, server, or system (hereinafter referred to as "method, etc.") that perform operations different from those described herein, each aspect of the disclosed technology is intended to cover the same operations as any of those described herein, and the existence of operations different from those described herein does not mean that such method, etc. is outside the scope of each aspect of the disclosed technology. [Explanation of symbols]
[0113] 10 Information Processing Systems 12, 12A, 12B, 12C, 12X terminals 14 Servers 16,16A,16B,16C Blockchain Nodes 20 Networks 70 Computers 72 memory 73 Memory section
Claims
1. An information processing system including a server, multiple blockchain nodes, and a terminal operated by a user, When an item is traded between multiple users, the first user generates the item to be generated, and when the item is sent from the first user, who is the sender of the item to be generated, to the second user, who is the recipient of the item, In response to the operation of the first user, the terminal operated by the first user transmits to the server the following: item identification data representing the identification information of the item to be generated, raw material identification data which is the identification information of the raw materials used when generating the item to be generated, quantity data representing the quantity of the raw materials, and source item identification data representing the identification information of the source item. The aforementioned server, Based on the parameter values corresponding to the raw materials and the quantity data, the commitment value of the item to be generated is calculated by performing a secure computation using the KZG commitment, a commitment scheme that utilizes polynomials, which makes only the quantity data of some raw materials publicly available. The combination of the raw material identification data and the target item identification data is stored in a predetermined data structure. A first transaction data is obtained, which is transaction data recorded in the blockchain stored in the memory unit of the blockchain node, and in which the origin item identification data and the commitment value of the origin item are included in the output data. A second transaction data is obtained, which includes a transaction data containing an address representing the source of the item to be generated, an address representing the destination of the item to be generated, and the data structure, wherein the source item identification data is included in the input data, and the data structure containing the item to be generated and the commitment value of the item to be generated are included in the output data, and the second transaction data is broadcast to multiple blockchain nodes. Each of the multiple blockchain nodes, Each of the first transaction data, which is past transaction data associated with the second transaction data broadcast by the server, is read from the blockchain. Based on the relationship between the commitment value of the item to be generated included in the second transaction data and the commitment value of the source item included in the first transaction data, it is verified whether the item to be generated in the second transaction data is composed of the raw materials included in the source item of the first transaction data, and if it is determined that the item to be generated in the second transaction data is composed of the raw materials of the first transaction data, the second transaction data is recorded on the blockchain. When the server calculates the commitment value of the item to be generated, The commitment value of the item to be generated is calculated by adding the result of a sum-of-products operation between a blind parameter value corresponding to a blind factor that does not actually contain raw materials in the item to be generated, and blind quantity data that represents a pre-adjusted random quantity of the blind factor, to the result of a sum-of-products operation between the parameter value and the quantity data. When the plurality of blockchain nodes verify whether the item to be generated in the second transaction data is composed of the raw materials of the plurality of first transaction data, If the sum of the commitment value of the item to be generated included in the second transaction data and the commitment value corresponding to the remainder of the raw materials generated when generating the item to be generated is equal to the sum of the commitment values of the source items included in a plurality of the first transaction data, it is determined that the item to be generated in the second transaction data is composed of the raw materials from a plurality of the first transaction data. Information processing system.
2. When the server receives a request signal representing a request for disclosure of the parameter value, it performs an authentication process with the terminal that sent the request signal, and if the terminal that sent the request signal is a terminal that has been previously authorized to disclose the parameter value, it discloses the parameter value to the terminal that sent the request signal. The information processing system according to claim 1.
3. The server in an information processing system including a server, multiple blockchain nodes, and a terminal operated by a user, When an item is traded between multiple users, the first user generates the item to be generated, and when the item is sent from the first user, who is the sender of the item to be generated, to the second user, who is the recipient of the item, In response to the operation of the first user, the terminal operated by the first user transmits to the server the following: item identification data representing the identification information of the item to be generated, raw material identification data which is the identification information of the raw materials used when generating the item to be generated, quantity data representing the quantity of the raw materials, and source item identification data representing the identification information of the source item. The aforementioned server, Based on the parameter values corresponding to the raw materials and the quantity data, the commitment value of the item to be generated is calculated by performing a secure computation using the KZG commitment, a commitment scheme that utilizes polynomials, which makes only the quantity data of some raw materials publicly available. The combination of the raw material identification data and the target item identification data is stored in a predetermined data structure. A first transaction data is obtained, which is transaction data recorded in the blockchain stored in the memory unit of the blockchain node, and in which the origin item identification data and the commitment value of the origin item are included in the output data. A second transaction data is obtained, which includes a transaction data containing an address representing the source of the item to be generated, an address representing the destination of the item to be generated, and the data structure, wherein the source item identification data is included in the input data, and the data structure containing the item to be generated and the commitment value of the item to be generated are included in the output data, and the second transaction data is broadcast to multiple blockchain nodes. Each of the multiple blockchain nodes, Each of the first transaction data, which is past transaction data associated with the second transaction data broadcast by the server, is read from the blockchain. Based on the relationship between the commitment value of the item to be generated included in the second transaction data and the commitment value of the source item included in the first transaction data, it is verified whether the item to be generated in the second transaction data is composed of the raw materials included in the source item of the first transaction data, and if it is determined that the item to be generated in the second transaction data is composed of the raw materials of the first transaction data, the second transaction data is recorded on the blockchain. When the server calculates the commitment value of the item to be generated, The commitment value of the item to be generated is calculated by adding the result of a sum-of-products operation between a blind parameter value corresponding to a blind factor that does not actually contain raw materials in the item to be generated, and blind quantity data that represents a pre-adjusted random quantity of the blind factor, to the result of a sum-of-products operation between the parameter value and the quantity data. When the plurality of blockchain nodes verify whether the item to be generated in the second transaction data is composed of the raw materials of the plurality of first transaction data, If the sum of the commitment value of the item to be generated included in the second transaction data and the commitment value corresponding to the remainder of the raw materials generated when generating the item to be generated is equal to the sum of the commitment values of the source items included in a plurality of the first transaction data, it is determined that the item to be generated in the second transaction data is composed of the raw materials from a plurality of the first transaction data. server.
4. The blockchain node in an information processing system including a server, multiple blockchain nodes, and a terminal operated by a user, When an item is traded between multiple users, the first user generates the item to be generated, and when the item is sent from the first user, who is the sender of the item to be generated, to the second user, who is the recipient of the item, In response to the operation of the first user, the terminal operated by the first user generates: the generated item identification data which represents the identification information of the item to be generated, the raw material identification data which is the identification information of the raw materials used when generating the item to be generated, and the raw The quantity data representing the quantity of the material and the origin item identification data representing the identification information of the origin item are sent to the server. The aforementioned server, Based on the parameter values corresponding to the raw materials and the quantity data, the commitment value of the item to be generated is calculated by performing a secure computation using the KZG commitment, a commitment scheme that utilizes polynomials, which makes only the quantity data of some raw materials publicly available. The combination of the raw material identification data and the target item identification data is stored in a predetermined data structure. A first transaction data is obtained, which is transaction data recorded in the blockchain stored in the memory unit of the blockchain node, and in which the origin item identification data and the commitment value of the origin item are included in the output data. A second transaction data is obtained, which includes a transaction data containing an address representing the source of the item to be generated, an address representing the destination of the item to be generated, and the data structure, wherein the source item identification data is included in the input data, and the data structure containing the item to be generated and the commitment value of the item to be generated are included in the output data, and the second transaction data is broadcast to multiple blockchain nodes. Each of the multiple blockchain nodes, Each of the first transaction data, which is past transaction data associated with the second transaction data broadcast by the server, is read from the blockchain. Based on the relationship between the commitment value of the item to be generated included in the second transaction data and the commitment value of the source item included in the first transaction data, it is verified whether the item to be generated in the second transaction data is composed of the raw materials included in the source item of the first transaction data, and if it is determined that the item to be generated in the second transaction data is composed of the raw materials of the first transaction data, the second transaction data is recorded on the blockchain. When the server calculates the commitment value of the item to be generated, The commitment value of the item to be generated is calculated by adding the result of a sum-of-products operation between a blind parameter value corresponding to a blind factor that does not actually contain raw materials in the item to be generated, and blind quantity data that represents a pre-adjusted random quantity of the blind factor, to the result of a sum-of-products operation between the parameter value and the quantity data. When the plurality of blockchain nodes verify whether the item to be generated in the second transaction data is composed of the raw materials of the plurality of first transaction data, If the sum of the commitment value of the item to be generated included in the second transaction data and the commitment value corresponding to the remainder of the raw materials generated when generating the item to be generated is equal to the sum of the commitment values of the source items included in a plurality of the first transaction data, it is determined that the item to be generated in the second transaction data is composed of the raw materials from a plurality of the first transaction data. Blockchain node.
5. An information processing method performed by an information processing system including a server, multiple blockchain nodes, and a terminal operated by a user, When an item is traded between multiple users, the first user generates the item to be generated, and when the item is sent from the first user, who is the sender of the item to be generated, to the second user, who is the recipient of the item, In response to the operation of the first user, the terminal operated by the first user transmits to the server the following: item identification data representing the identification information of the item to be generated, raw material identification data which is the identification information of the raw materials used when generating the item to be generated, quantity data representing the quantity of the raw materials, and source item identification data representing the identification information of the source item. The aforementioned server, Based on the parameter values corresponding to the raw materials and the quantity data, the commitment value of the item to be generated is calculated by performing a secure computation using the KZG commitment, a commitment scheme that utilizes polynomials, which makes only the quantity data of some raw materials publicly available. The combination of the raw material identification data and the target item identification data is stored in a predetermined data structure. A first transaction data is obtained, which is transaction data recorded in the blockchain stored in the memory unit of the blockchain node, and in which the origin item identification data and the commitment value of the origin item are included in the output data. A second transaction data is obtained, which includes a transaction data containing an address representing the source of the item to be generated, an address representing the destination of the item to be generated, and the data structure, wherein the source item identification data is included in the input data, and the data structure containing the item to be generated and the commitment value of the item to be generated are included in the output data, and the second transaction data is broadcast to multiple blockchain nodes. Each of the multiple blockchain nodes, Each of the first transaction data, which is past transaction data associated with the second transaction data broadcast by the server, is read from the blockchain. Based on the relationship between the commitment value of the item to be generated included in the second transaction data and the commitment value of the source item included in the first transaction data, it is verified whether the item to be generated in the second transaction data is composed of the raw materials included in the source item of the first transaction data, and if it is determined that the item to be generated in the second transaction data is composed of the raw materials of the first transaction data, the second transaction data is recorded on the blockchain. When the server calculates the commitment value of the item to be generated, The commitment value of the item to be generated is calculated by adding the result of a sum-of-products operation between a blind parameter value corresponding to a blind factor that does not actually contain raw materials in the item to be generated, and blind quantity data that represents a pre-adjusted random quantity of the blind factor, to the result of a sum-of-products operation between the parameter value and the quantity data. When the plurality of blockchain nodes verify whether the item to be generated in the second transaction data is composed of the raw materials of the plurality of first transaction data, If the sum of the commitment value of the item to be generated included in the second transaction data and the commitment value corresponding to the remainder of the raw materials generated when generating the item to be generated is equal to the sum of the commitment values of the source items included in a plurality of the first transaction data, it is determined that the item to be generated in the second transaction data is composed of the raw materials from a plurality of the first transaction data. Information processing methods.
6. A program to be executed on a server in an information processing system including a server, multiple blockchain nodes, and a terminal operated by a user, When an item is traded between multiple users, the first user generates the item to be generated, and when the item is sent from the first user, who is the sender of the item to be generated, to the second user, who is the recipient of the item, In response to the operation of the first user, the terminal operated by the first user transmits to the server the following: item identification data representing the identification information of the item to be generated, raw material identification data which is the identification information of the raw materials used when generating the item to be generated, quantity data representing the quantity of the raw materials, and source item identification data representing the identification information of the source item. The aforementioned server, Based on the parameter values corresponding to the raw materials and the quantity data, the commitment value of the item to be generated is calculated by performing a secure computation using the KZG commitment, a commitment scheme that utilizes polynomials, which makes only the quantity data of some raw materials publicly available. The combination of the raw material identification data and the target item identification data is stored in a predetermined data structure. A first transaction data is obtained, which is transaction data recorded in the blockchain stored in the memory unit of the blockchain node, and in which the origin item identification data and the commitment value of the origin item are included in the output data. A second transaction data is obtained, which includes a transaction data containing an address representing the source of the item to be generated, an address representing the destination of the item to be generated, and the data structure, wherein the source item identification data is included in the input data, and the data structure containing the item to be generated and the commitment value of the item to be generated are included in the output data, and the second transaction data is broadcast to multiple blockchain nodes. Each of the multiple blockchain nodes, Each of the first transaction data, which is past transaction data associated with the second transaction data broadcast by the server, is read from the blockchain. Based on the relationship between the commitment value of the item to be generated included in the second transaction data and the commitment value of the source item included in the first transaction data, it is verified whether the item to be generated in the second transaction data is composed of the raw materials included in the source item of the first transaction data, and if it is determined that the item to be generated in the second transaction data is composed of the raw materials of the first transaction data, the second transaction data is recorded on the blockchain. When the server calculates the commitment value of the item to be generated, The commitment value of the item to be generated is calculated by adding the result of a sum-of-products operation between a blind parameter value corresponding to a blind factor that does not actually contain raw materials in the item to be generated, and blind quantity data that represents a pre-adjusted random quantity of the blind factor, to the result of a sum-of-products operation between the parameter value and the quantity data. When the plurality of blockchain nodes verify whether the item to be generated in the second transaction data is composed of the raw materials of the plurality of first transaction data, If the sum of the commitment value of the item to be generated included in the second transaction data and the commitment value corresponding to the remainder of the raw materials generated when generating the item to be generated is equal to the sum of the commitment values of the source items included in a plurality of the first transaction data, it is determined that the item to be generated in the second transaction data is composed of the raw materials from a plurality of the first transaction data. program.
7. A program to be executed by a blockchain node in an information processing system including a server, multiple blockchain nodes, and a terminal operated by a user, When an item is traded between multiple users, the first user generates the item to be generated, and when the item is sent from the first user, who is the sender of the item to be generated, to the second user, who is the recipient of the item, In response to the operation of the first user, the terminal operated by the first user transmits to the server the following: item identification data representing the identification information of the item to be generated, raw material identification data which is the identification information of the raw materials used when generating the item to be generated, quantity data representing the quantity of the raw materials, and source item identification data representing the identification information of the source item. The aforementioned server, Based on the parameter values corresponding to the raw materials and the quantity data, the commitment value of the item to be generated is calculated by performing a secure computation using the KZG commitment, a commitment scheme that utilizes polynomials, which makes only the quantity data of some raw materials publicly available. The combination of the raw material identification data and the target item identification data is stored in a predetermined data structure. A first transaction data is obtained, which is transaction data recorded in the blockchain stored in the memory unit of the blockchain node, and in which the origin item identification data and the commitment value of the origin item are included in the output data. A second transaction data is obtained, which includes a transaction data containing an address representing the source of the item to be generated, an address representing the destination of the item to be generated, and the data structure, wherein the source item identification data is included in the input data, and the data structure containing the item to be generated and the commitment value of the item to be generated are included in the output data, and the second transaction data is broadcast to multiple blockchain nodes. Each of the multiple blockchain nodes, Each of the first transaction data, which is past transaction data associated with the second transaction data broadcast by the server, is read from the blockchain. Based on the relationship between the commitment value of the item to be generated included in the second transaction data and the commitment value of the source item included in the first transaction data, it is verified whether the item to be generated in the second transaction data is composed of the raw materials included in the source item of the first transaction data, and if it is determined that the item to be generated in the second transaction data is composed of the raw materials of the first transaction data, the second transaction data is recorded on the blockchain. When the server calculates the commitment value of the item to be generated, The commitment value of the item to be generated is calculated by adding the result of a sum-of-products operation between a blind parameter value corresponding to a blind factor that does not actually contain raw materials in the item to be generated, and blind quantity data that represents a pre-adjusted random quantity of the blind factor, to the result of a sum-of-products operation between the parameter value and the quantity data. When the plurality of blockchain nodes verify whether the item to be generated in the second transaction data is composed of the raw materials of the plurality of first transaction data, If the sum of the commitment value of the item to be generated included in the second transaction data and the commitment value corresponding to the remainder of the raw materials generated when generating the item to be generated is equal to the sum of the commitment values of the source items included in a plurality of the first transaction data, it is determined that the item to be generated in the second transaction data is composed of the raw materials from a plurality of the first transaction data. program.
Citation Information
Patent Citations
Production anti-counterfeiting traceability system and method based on block chain
CN110503438A
Traceability management system for wine industry supply chain based on block chain
CN112330345A
Traceability system for pet food
JP2020035436A
Transaction method, program, verifying apparatus and creating method
JP2020071617A
Distributed Ledger of Physical Materials
JP2020524924A