Polynomial commitment-based method, electronic device, and readable storage medium

By generating sets of elements in the target form, the complexity and efficiency problems of traditional polynomial commitments are solved, and more efficient algorithm processing is achieved.

WO2025092734A1PCT designated stage expired Publication Date: 2025-05-08HANGZHOU QULIAN TECHNOLOGY CO LTD

Patent Information

Application Number
PCT/CN2024/128173
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-31
Filing Date
2024-10-29
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

Traditional polynomial commitments are more complex and less efficient in terms of proof size and verification time, especially when multiple polynomial commitments and proofs are required.

Method used

By obtaining the point value polynomial corresponding to the business data, and generating a set of elements in the target form based on the generators of random numbers and elliptic curves, directly generating the promise and proof of the point value polynomial, reducing the computational complexity and improving the algorithm processing efficiency.

Benefits of technology

This method effectively reduces the complexity and calculation amount of promised operations, improves the algorithm processing efficiency in encryption application scenarios, and has strong ease of use and practicality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024128173_08052025_PF_FP_ABST
    Figure CN2024128173_08052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of encryption, and in particular to a polynomial commitment-based method, an electronic device, and a readable storage medium. The method comprises: acquiring a point value polynomial corresponding to service data, wherein the service data is secret data to be proved; generating an element set in a target form on the basis of a random number and a generator of an elliptic curve, wherein the element set comprises elements related to an independent variable of the point value polynomial; and generating a commitment of the point value polynomial on the basis of the elements in the element set, and generating a proof of the point value polynomial on the basis of an obtained target independent variable, wherein the commitment and the proof are used for verifying the presence of the secret data. The problems of high complexity and low operation efficiency of traditional polynomial commitment implementation modes in the aspects of proof size and verification time can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Method, electronic device and readable storage medium based on polynomial commitment

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on October 31, 2023, with application number 202311423529.X and invention name “Method, electronic device and readable storage medium based on polynomial commitment”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of encryption technology, and in particular to a method, electronic device and readable storage medium based on polynomial commitment. Background Art

[0003] Commitment is a type of cryptographic algorithm, just like encryption, signature, and message digest algorithms, which can provide basic modular cryptographic functions and are called cryptographic primitives.

[0004] Currently, polynomial commitment encryption is widely used in the fields of zero-knowledge proof and blockchain. For example, whether a zero-knowledge proof requires a trusted setup and the size of the proof depend on the polynomial commitment encryption method. Polynomial commitment can also replace the Merkle tree of the blockchain, allowing the blockchain to provide clients with more convincing proof of transaction existence.

[0005] However, traditional implementations of polynomial commitments have high complexity in terms of proof size and verification time, especially when multiple polynomial commitments and proofs are required, resulting in low computational efficiency. Technical issues

[0006] One of the purposes of the embodiments of the present application is to provide a method, electronic device and readable storage medium based on polynomial commitment, which can solve the problem that the traditional implementation method of polynomial commitment has high complexity in terms of proof size and verification time and low computational efficiency. Technical Solutions

[0007] The technical solution adopted in the embodiment of this application is:

[0008] In a first aspect, a method based on polynomial commitment is provided, comprising:

[0009] Obtain a point-valued polynomial corresponding to business data, where the business data is the secret data to be proved; generate a target element set based on random numbers and elliptic curve generators, where the element set contains elements related to the independent variables of the point-valued polynomial; generate a commitment to the point-valued polynomial based on the elements in the element set, and generate a proof of the point-valued polynomial based on the obtained target independent variables; the commitment and proof are used to verify the existence of the secret data.

[0010] Through the above method, based on the generators of random numbers and elliptic curves, various elements related to the independent variables of the point-valued polynomial are generated to obtain a target element set. The commitment of the point-valued polynomial is directly generated based on the element set, which can reduce the computational complexity. There is no need to convert the point-valued polynomial into a coefficient expression and then calculate the commitment based on the coefficients of the coefficient expression. While reducing the amount of calculation, the complexity of the commitment operation is reduced, and the algorithm processing efficiency in various encryption application scenarios is improved; it has strong ease of use and practicality.

[0011] In one embodiment, after generating the proof of the point-valued polynomial, the method further comprises:

[0012] The committer sends the commitment and the proof to the verifier, and the verifier verifies the point value polynomial based on the commitment and the proof.

[0013] In one embodiment, in a possible implementation of the first aspect, generating a target set of elements based on a generator of a random number and an elliptic curve includes:

[0014] Based on a random number and an elliptic curve generator, a target form element set containing n elements is generated; the target form element set containing n elements is expressed as:

[0015] Where n is an integer greater than or equal to 1, ω n is the independent variable corresponding to the point-valued polynomial, α is the random number, G is the generator, and srs is the structured reference string.

[0016] In one embodiment, generating the commitment of the point-valued polynomial based on each element in the set of elements includes:

[0017] The commitment to the point-valued polynomial is generated based on the following formula:

[0018] Where com(f(X)) is the commitment, f(X) is a point-valued polynomial, and f i is the dependent variable corresponding to the i-th independent variable among the n independent variables of the point-valued polynomial, ω i is the independent variable of the point-valued polynomial, which satisfies ω i n = n roots of 1, n is a power of 2, α is the random number, G is the generator, For each element.

[0019] In one embodiment, generating a proof of the point-valued polynomial based on the obtained target independent variable includes:

[0020] Based on the obtained target independent variable, generate an intermediate polynomial corresponding to the point-valued polynomial;

[0021] Based on the intermediate polynomial, a proof of the point-valued polynomial is generated.

[0022] In one embodiment, generating an intermediate polynomial corresponding to the point-valued polynomial based on the acquired target independent variable includes:

[0023] The intermediate polynomial corresponding to the point-value polynomial is generated based on the following formula:

[0024] The proof of the point-valued polynomial is generated based on the following formula:

[0025] Where W is the proof, p(x) is the intermediate polynomial generated based on f(x), z is the obtained target variable, f(z) is the value of the point-valued polynomial at z, and p i is the dependent variable corresponding to the i-th independent variable among the n independent variables of the point-valued polynomial, ω i is the independent variable of the point-valued polynomial, which satisfies ω i n = n roots of 1, n is a power of 2, α is the random number, G is the generator, For each element.

[0026] In one embodiment, the verifier verifies the point-value polynomial based on the commitment and the proof, including:

[0027] The verifier verifies the point-valued polynomial based on the commitment and the proof based on a bilinear pairing function; the bilinear pairing function is expressed as follows: A1 = e(C - yG1, G2) A2 = e(W, αG2 - zG2)

[0028] Among them, when A1=A2, the verification passes, otherwise the verification fails; C is the commitment, y is the dependent variable of the point-valued polynomial corresponding to the target independent variable z, α is the random number, G1 and G2 are generators on two preset elliptic curves respectively, W is the proof, and e is the bilinear pairing function.

[0029] In a second aspect, a device based on polynomial commitment is provided, comprising:

[0030] an acquisition unit, which acquires a point-value polynomial corresponding to business data, wherein the business data is secret data to be proved;

[0031] a processing unit, configured to generate a target-form element set based on a random number and a generator of an elliptic curve, the element set comprising elements associated with an independent variable of the point-valued polynomial;

[0032] a commitment unit, configured to generate a commitment of the point-valued polynomial based on each element in the element set, and to generate a proof of the point-valued polynomial based on the obtained target independent variable;

[0033] The commitment and the proof are used to verify the existence of the secret data.

[0034] According to a third aspect, an electronic device is provided, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements any one of the methods according to the first aspect when executing the computer program.

[0035] According to a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the method according to any one of the first aspects is implemented.

[0036] In a fifth aspect, a computer program product is provided. When the computer program product is run on an electronic device, the electronic device executes any one of the methods in the first aspect.

[0037] It can be understood that the beneficial effects of the second to fifth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0039] FIG1 is a schematic diagram of a flow chart of a method based on polynomial commitment according to an embodiment of the present application;

[0040] FIG2 is a schematic diagram of an interaction process based on polynomial commitment provided in an embodiment of the present application;

[0041] FIG3 is a schematic diagram of a polynomial commitment-based device structure according to an embodiment of the present application;

[0042] FIG4 is a schematic structural diagram of an electronic device provided in an embodiment of the present application. Modes for Carrying Out the Invention

[0043] The following embodiments of the technical solution of the present application will be described in detail with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present application and are therefore only examples and are not intended to limit the scope of protection of the present application.

[0044] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned figure descriptions are intended to cover non-exclusive inclusions.

[0045] In the description of the embodiments of this application, the technical terms "first" and "second" are used only to distinguish different objects and should not be understood to indicate or imply relative importance or implicitly specify the quantity, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, the meaning of "plurality" is more than two, unless otherwise clearly and specifically defined.

[0046] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0047] In the description of the embodiments of this application, the term "and / or" is simply a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent the following three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally indicates that the associated objects are in an "or" relationship.

[0048] A commitment is a public value that is bound to the original business message provided by the submitter (computation binding). The submitter does not disclose the specific business message (hiding). The submitter needs to open this commitment and send the message to the verifier to verify the correspondence between the commitment and the message. A polynomial commitment is a commitment to a polynomial. The submitter can prove that the value of the polynomial satisfies the functional relationship of the polynomial without revealing the specific content of the polynomial.

[0049] Polynomial commitments play an important role in various cryptographic application scenarios. For example, in the field of zero-knowledge proof, privacy data protection, identity verification, and IoT security, polynomial commitment schemes can provide valid proof of data existence while protecting the data.

[0050] The following describes the implementation of the embodiments of the present application through specific examples.

[0051] Please refer to Figure 1, which is a flowchart of the method based on polynomial commitment provided in an embodiment of the present application. As shown in the figure, the method may include the following steps:

[0052] S101, obtaining a point-value polynomial corresponding to business data, where the business data is secret data to be proved.

[0053] In the embodiment of the present application, the business data may be blockchain transaction data, or other data that needs to be kept confidential, such as private data related to login information, etc. Based on the business data, an associated point value polynomial is determined, i.e., a point value expression represented by the ordinate.

[0054] For example, a polynomial can be represented by coefficients or uniquely represented by different points. A polynomial of degree n can be represented by n+1 coefficients. For example, a first-degree polynomial is a straight line, which can be represented by two coefficients a and b in the form of ax+b, or by two points (two points determine a straight line). The first method is called a coefficient expression, and the second method is called a point value expression of the polynomial. When using a point value expression, the scope of the definition domain is generally agreed upon, that is, the horizontal coordinates of these points are agreed upon, and then only the vertical coordinates are used to uniquely represent the polynomial (i.e., n+1 values); therefore, compared with the coefficient expression, the point value expression does not take up more storage space.

[0055] For example, the expression of a point-valued polynomial is {f0,f1...,f n-1}, that is, the point value polynomial is in the horizontal coordinate {ω0, ω1..., ω n-1} is the value of {f0,f1...,f n-1 Because the point value expression is raw data related to business data, calculations based on this point value expression are more regular and sparse.

[0056] S102: Generate a target element set based on a random number and an elliptic curve generator, where the element set includes elements related to the independent variable of the point-valued polynomial.

[0057] In this embodiment of the present application, before generating a commitment to a point-valued polynomial, a trusted setup is required. This involves selecting a generator G on the elliptic curve and a random number α, and then calculating each elliptic curve element. This calculation process can also be performed by a trusted third party, and the random number is guaranteed to be destroyed after use. The target form element set is the set containing each elliptic curve element.

[0058] Among them, the generator can be a known and determined point on the elliptic curve, and the elements related to the independent variables of the point-valued polynomial include scalars generated based on random numbers and the horizontal coordinates of each point. These elements are obtained by calculating the dot product of each scalar and the generator (elliptic curve point).

[0059] In some embodiments, generating a set of elements of a target form based on a random number and an elliptic curve generator includes:

[0060] Based on a random number and an elliptic curve generator, a target form element set containing n elements is generated; the target form element set containing n elements is expressed as:

[0061] Where n is an integer greater than or equal to 1, ω n is the independent variable corresponding to the point-valued polynomial, α is the random number, G is the generator, and srs is a structured reference string.

[0062] For example, unlike the existing method of calculating scalars based on coefficient expressions, the scalars in the embodiment of the present application are calculated based on the horizontal coordinate and random numbers, for example

[0063] S103: Generate a commitment of the point-valued polynomial based on each element in the element set, and generate a proof of the point-valued polynomial based on the obtained target independent variable.

[0064] Among them, commitment and proof are used to verify the existence of secret data.

[0065] In an embodiment of the present application, before calculating the commitment of a point-valued polynomial, since the calculated scalars and the corresponding elliptic curve elements are different, it is no longer necessary to perform a Fourier transform on the point-valued polynomial into a coefficient expression and then calculate the commitment. Moreover, the transformed coefficient polynomial generally loses sparsity and involves a large number of relatively complex calculation processes.

[0066] Illustratively, the embodiment of the present application calculates the commitment com(f(x))←Setup(srs,f(x)) of the point value polynomial based on the sparse point values ​​corresponding to the point value polynomial and the elements in the element set.

[0067] In some embodiments, generating a commitment to a point-valued polynomial based on each element in the set of elements includes:

[0068] Generate a commitment C of a point-valued polynomial based on the following formula:

[0069] Where com(f(X)) is a commitment, f(X) is a point-valued polynomial, and f i is the dependent variable (point value) corresponding to the i-th independent variable among the n independent variables of the point-valued polynomial, ω i is the independent variable of the point-valued polynomial, which satisfies ω i n = n roots of 1, n is a power of 2, α is a random number, G is a generator, For each element. srs is calculated based on the above table. The specific value can be obtained by looking up the table. The specific calculation process is to multiply each point value by the corresponding element and sum them to obtain the commitment.

[0070] For example, the commitment calculated above cannot obtain the specific information of the point-value polynomial f(x), and it is also difficult to construct another polynomial commitment C, which satisfies the concealment and binding properties.

[0071] In some embodiments, generating a proof of a point-valued polynomial based on the obtained target argument includes:

[0072] Based on the obtained target independent variable, an intermediate polynomial corresponding to the point-valued polynomial is generated; based on the intermediate polynomial, a proof of the point-valued polynomial is generated.

[0073] For example, after calculating the commitment, a proof of the point-valued polynomial is calculated based on the commitment and the target variable proposed by the verifier. The purpose of generating this proof is to prove to the verifier (or recipient) that the point-valued polynomial satisfies a functional relationship, such as f(z)=y, that is, f(x) satisfies the functional relationship that the value of z is y.

[0074] Here, z and y are both fixed numbers, values ​​that the committer (sender) needs to prove to the verifier (receiver). z can be a value determined by a trusted third party, the recipient, or other requirements, i.e., the acquired target variable. The committer calculates the correct y based on z and then generates a proof, i.e., W←prove(srs,f(x),z).

[0075] In some embodiments, generating an intermediate polynomial corresponding to the point-valued polynomial based on the obtained target independent variable includes:

[0076] Generate the intermediate polynomial corresponding to the point-valued polynomial based on the following formula:

[0077] Proof of generating a point-valued polynomial based on the following formula:

[0078] Where W is the proof, p(x) is the intermediate polynomial generated based on f(x), z is the target independent variable obtained, f(z) is the point value of the point value polynomial at z, p i is the dependent variable corresponding to the i-th independent variable among the n independent variables of the point-valued polynomial, ω i is the independent variable of the point-valued polynomial, which satisfies ω i n = n roots of 1, n is a power of 2, α is a random number, G is a generator, For each element, the scalar can be obtained based on the above table lookup.

[0079] In some embodiments, after generating the proof of the point-valued polynomial, the method further comprises:

[0080] The committer sends the commitment and proof to the verifier, and the verifier verifies the point value polynomial based on the commitment and proof.

[0081] For example, the committer sends W, z, and y to the verifier (receiver), where W is the proof that f(z) = y. The recipient does not know the specific expression of f(x), and the committer's proof does not reveal the expression of f(x). However, through subsequent verification steps, the recipient can confirm that the polynomial f(x) corresponding to C sent by the committer in the commitment step does indeed satisfy f(z) = y, that is, verify(W,com(f(x),z,f(z))).

[0082] In some embodiments, the verifier verifies the point-valued polynomial based on the commitment and the proof, including:

[0083] Based on the bilinear pairing function, the verifier verifies the point-valued polynomial based on the commitment and proof; the bilinear pairing function is expressed as follows: A1=e(C-yG1,G2) A2=e(W,αG2-zG2)

[0084] Among them, when A1=A2, the verification passes, otherwise the verification fails; C is the commitment, y is the dependent variable (i.e., the point value) of the point-valued polynomial corresponding to the target independent variable z, α is a random number, G1 and G2 are generators on two preset known elliptic curves, W is the proof, and e is the bilinear pairing function.

[0085] For example, based on the bilinear pairing function, the relationship between C, W, z, and y is verified. If A1=A2, the verification succeeds, proving that the point-valued polynomial does exist and the value at z is y, which can further prove the existence of the undisclosed business data; otherwise, the verification fails.

[0086] It should be noted that the ω mentioned in the above description i is satisfied The n roots of , and they are powers of 2, thus completing the commitment to the largest n-1 degree polynomial.

[0087] As shown in Figure 2, an interactive process diagram based on polynomial commitment is provided in an embodiment of the present application. The committer obtains an element set generated based on a generator and a random number, generates a point-valued polynomial commitment C based on the element set, and sends the commitment to the verifier. The verifier can issue a challenge to the committer, randomly select a target independent variable z, and send it to the committer. The committer generates a proof W based on the target independent variable z, the value y, the commitment C, and the element set, and sends W, z, and y to the verifier. The verifier performs verification (verify(W, C, z, y)).

[0088] Through the embodiments of the present application, since the point value expressions are original data related to the business, these values ​​are more regular and sparse. However, these business data will lose these regularities after a fast Fourier transform, and the results are difficult to predict simply. According to the original algorithm, the coefficient expression must be calculated after the fast Fourier transform. The present application omits the Fourier transform process, reducing the computational complexity of the overall algorithm. In addition, in most cases, such as zero-knowledge proofs, since the point value expressions are original data related to the business, they are more sparse. The amount of calculation based on the point value commitment is much smaller than the amount of calculation based on the coefficient commitment, which greatly accelerates the algorithm when the point value expression is sparse.

[0089] It should be understood that the order of execution of each step in the above embodiment does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present application.

[0090] Corresponding to the polynomial commitment-based method provided in the above embodiment, FIG3 shows a structural diagram of the polynomial commitment-based device provided in an embodiment of the present application. For ease of explanation, only the parts related to the embodiment of the present application are shown.

[0091] Referring to Figure 3, the device includes:

[0092] An acquisition unit 31 acquires a point-value polynomial corresponding to business data, where the business data is secret data to be proven;

[0093] a processing unit 32 configured to generate a target-form element set based on a random number and a generator of an elliptic curve, the element set comprising elements associated with an independent variable of the point-valued polynomial;

[0094] a commitment unit 33 for generating a commitment of the point-valued polynomial based on each element in the element set, and generating a proof of the point-valued polynomial based on the obtained target independent variable;

[0095] The commitment and the proof are used to verify the existence of the secret data.

[0096] In a possible implementation, the apparatus further includes a verification unit configured to cause the committer to send the commitment and the proof to a verifier, and for the verifier to verify the point-value polynomial based on the commitment and the proof.

[0097] In one possible implementation, the processing unit 32 is further configured to generate a target set of n elements based on the random number and the generator of the elliptic curve; the target set of n elements is represented as follows:

[0098] Where n is an integer greater than or equal to 1, ω n is the independent variable corresponding to the point-valued polynomial, α is the random number, G is the generator, and srs is the structured reference string.

[0099] In a possible implementation, the commitment unit 33 is further configured to generate a commitment of the point-value polynomial based on the following formula:

[0100] Where com(f(X)) is the commitment, f(X) is a point-valued polynomial, and f i is the dependent variable corresponding to the i-th independent variable among the n independent variables of the point-valued polynomial, ω i is the independent variable of the point-valued polynomial, which satisfies ω i n = n roots of 1, n is a power of 2, α is the random number, G is the generator, For each element.

[0101] In a possible implementation, the commitment unit 33 is further configured to generate an intermediate polynomial corresponding to the point-valued polynomial based on the acquired target independent variable; and generate a proof of the point-valued polynomial based on the intermediate polynomial.

[0102] In a possible implementation, the commitment unit 33 is further configured to generate an intermediate polynomial corresponding to the point value polynomial based on the following formula:

[0103] The proof of the point-valued polynomial is generated based on the following formula:

[0104] Where W is the proof, p(x) is the intermediate polynomial generated based on f(x), z is the obtained target variable, f(z) is the value of the point-valued polynomial at z, and p i is the dependent variable corresponding to the i-th independent variable among the n independent variables of the point-valued polynomial, ω i is the independent variable of the point-valued polynomial, which satisfies ω i n = n roots of 1, n is a power of 2, α is the random number, G is the generator, For each element.

[0105] In one possible implementation, the verification unit is further configured to verify the point-valued polynomial based on the commitment and the proof by the verifier based on a bilinear pairing function; the bilinear pairing function is expressed as follows: A1 = e(C - yG1, G2) A2 = e(W, αG2 - zG2)

[0106] Among them, when A1=A2, the verification passes, otherwise the verification fails; C is the commitment, y is the dependent variable corresponding to the point-valued polynomial target variable z, α is the random number, G1 and G2 are generators on two preset elliptic curves, W is the proof, and e is the bilinear pairing function.

[0107] FIG4 shows a schematic diagram of the hardware structure of the electronic device 4 .

[0108] As shown in FIG4 , the electronic device 4 of this embodiment includes: at least one processor 40 (only one is shown in FIG4 ) and a memory 41. The memory 41 stores a computer program 42 that can be executed on the processor 40. When the processor 40 executes the computer program 42, it implements the steps of the above-described method embodiment, such as S101 to S103 shown in FIG1 . Alternatively, when the processor 40 executes the computer program 42, it implements the functions of each unit / unit in the above-described device embodiments.

[0109] It should be understood that the structures illustrated in the embodiments of the present application do not constitute a specific limitation on the electronic device 4. In other embodiments of the present application, the electronic device 4 may include more or fewer components than shown, or may combine or separate certain components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0110] The electronic device 4 can be a node of the aforementioned blockchain system, such as a computing device such as a desktop computer, laptop, PDA, or cloud server. The electronic device 4 may include, but is not limited to, a processor 40 and a memory 41. Those skilled in the art will appreciate that FIG4 is merely an example of an electronic device 4 and does not limit the electronic device 4. The electronic device 4 may include more or fewer components than shown, or may combine certain components or different components. For example, the server may also include an input and transmission device, a network access device, a bus, and the like.

[0111] The processor 40 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.

[0112] Processor 40 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 40 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 40. If processor 40 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 40 latency, and thus improves system efficiency.

[0113] In some embodiments, the memory 41 may be an internal storage unit of the electronic device 4, such as a hard disk or memory of the electronic device 4. The memory 41 may also be an external storage device of the electronic device 4, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device 4. Furthermore, the memory 41 may include both an internal storage unit of the electronic device 4 and an external storage device. The memory 41 is used to store an operating system, application programs, a boot loader, data, and other programs, such as program code of a computer program. The memory 41 may also be used to temporarily store data that has been sent or is about to be sent.

[0114] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0115] It should be noted that the structure of the electronic device described above is merely exemplary and may include other physical structures based on different application scenarios, and the physical structure of the electronic device is not limited herein.

[0116] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0117] An embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it can implement the steps in the above-mentioned various method embodiments.

[0118] An embodiment of the present application provides a computer program product. When the computer program product runs on a server, the server can implement the steps in the above-mentioned method embodiments when executing the computer program product.

[0119] If the integrated unit / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the process in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form, etc. Computer-readable media may include: any entity or device that can carry computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium, etc.

[0120] The algorithm development platform, electronic device, computer storage medium, and computer program product provided in the above-mentioned embodiments of the present application are all used to execute the methods provided above. Therefore, the beneficial effects that can be achieved can refer to the corresponding beneficial effects of the methods provided above, and will not be repeated here.

[0121] It should be understood that the above is only to help those skilled in the art better understand the embodiments of the present application, and is not intended to limit the scope of the embodiments of the present application. Based on the above examples given, those skilled in the art can obviously make various equivalent modifications or changes. For example, certain steps in each embodiment of the above detection method may be unnecessary, or certain new steps may be added. Or a combination of any two or any multiple embodiments described above. Such modifications, changes, or combined solutions also fall within the scope of the embodiments of the present application.

[0122] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0123] It should be understood that the above is only to help those skilled in the art better understand the embodiments of the present application, and is not intended to limit the scope of the embodiments of the present application. Based on the above examples given, those skilled in the art can obviously make various equivalent modifications or changes. For example, certain steps in each embodiment of the above detection method may be unnecessary, or certain new steps may be added. Or a combination of any two or any multiple embodiments described above. Such modifications, changes, or combined solutions also fall within the scope of the embodiments of the present application.

[0124] It should also be understood that the division of the modes, situations, categories and embodiments in the embodiments of the present application is only for the convenience of description and should not constitute a special limitation. The features of various modes, categories, situations and embodiments can be combined without contradiction.

[0125] It should also be understood that in the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced to each other, and the technical features in different embodiments can be combined to form new embodiments according to their internal logical relationships.

[0126] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0127] In the embodiments provided in this application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are merely illustrative. For example, the division of the units or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0128] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0129] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.

[0130] Finally, it should be noted that the above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A method based on polynomial commitment, characterized in that: include: Obtaining a point value polynomial corresponding to business data, where the business data is secret data to be proved; Generate a target form of element set based on a random number and an elliptic curve generator, wherein the element set includes elements related to an independent variable of the point-valued polynomial; Generate a commitment of the point-valued polynomial based on each element in the element set, and generate a proof of the point-valued polynomial based on the obtained target independent variable; The commitment and the proof are used to verify the existence of the secret data.

2. The method according to claim 1, characterized in that After generating the proof of the point-valued polynomial, the method further comprises: The committer sends the commitment and the proof to the verifier, and the verifier verifies the point value polynomial based on the commitment and the proof.

3. The method according to claim 1, characterized in that The generator based on random numbers and elliptic curves generates a set of elements in a target form, including: Based on the generator of the random number and the elliptic curve, a target form of an element set containing n elements is generated; the target form of the element set containing n elements is expressed as: Where n is an integer greater than or equal to 1, ω n is the independent variable corresponding to the point-valued polynomial, α is the random number, G is the generator, and srs is the structured reference string.

4. The method according to any one of claims 1 to 3, characterized in that: The step of generating the commitment of the point-value polynomial based on each element in the element set includes: The commitment of the point-valued polynomial is generated based on the following formula: Where com(f(X)) is the commitment, f(X) is a point-valued polynomial, and f i is the dependent variable corresponding to the ith independent variable among the n independent variables of the point-valued polynomial, ω i is the independent variable of the point-valued polynomial, which satisfies ω i n = n roots of 1, n is a power of 2, α is the random number, G is the generator, For each element.

5. The method according to any one of claims 1 to 3, characterized in that: The step of generating the proof of the point-valued polynomial based on the acquired target independent variable includes: Based on the obtained target independent variable, generate an intermediate polynomial corresponding to the point value polynomial; Based on the intermediate polynomial, a proof of the point-valued polynomial is generated.

6. The method according to claim 5, characterized in that The step of generating an intermediate polynomial corresponding to the point-value polynomial based on the acquired target independent variable includes: The intermediate polynomial corresponding to the point value polynomial is generated based on the following formula: The proof of the point-valued polynomial is generated based on the following formula: Where W is the proof, p(x) is the intermediate polynomial generated based on f(x), z is the obtained target independent variable, f(z) is the value of the point-valued polynomial at z, and p i is the dependent variable corresponding to the ith independent variable among the n independent variables of the point-valued polynomial, ω i is the independent variable of the point-valued polynomial, which satisfies ω i n = n roots of 1, n is a power of 2, α is the random number, G is the generator, For each element.

7. The method according to claim 2 or 6, characterized in that: The verifier verifies the point value polynomial based on the commitment and the proof, including: Based on a bilinear pairing function, the verifier verifies the point value polynomial based on the commitment and the proof; the bilinear pairing function is expressed as follows: A1=e(C-yG1,G2) A2=e(W,αG2-zG2) Among them, when A1=A2, the verification passes, otherwise the verification fails; C is the commitment, y is the dependent variable of the point-valued polynomial corresponding to the target independent variable z, α is the random number, G1 and G2 are respectively generators on two preset elliptic curves, W is the proof, and e is the bilinear pairing function.

8. The method according to claim 1, characterized in that: The generator based on random numbers and elliptic curves generates a set of elements in a target form, including: Based on the random number and the horizontal coordinates of each point, a scalar is generated; the generator is a known and determined point on the elliptic curve; Each element is calculated by performing a dot product of each scalar and a generator to obtain the element set.

9. The method according to claim 1 or 8, characterized in that: The step of generating the commitment of the point-value polynomial based on each element in the element set includes: Based on each point value corresponding to the point value polynomial and each element in the element set, the commitment of the point value polynomial is calculated.

10. The method according to any one of claims 1 to 9, characterized in that: The method further comprises: The committer obtains a set of elements generated based on the generator and the random number, generates a commitment C of the point value polynomial based on the set of elements, and sends the commitment C to the verifier; The verifier randomly selects a target independent variable z, and sends the target independent variable z to the committer; The committer generates a proof W based on the target independent variable z, the value y of the point value polynomial at the target independent variable z, the commitment C and the element set, and sends the proof W, the target independent variable z and the value y to the verifier; The verifier performs verification verify(W, C, z, y).

11. A device based on polynomial commitment, characterized in that: include: An acquisition unit, which acquires a point value polynomial corresponding to business data, wherein the business data is secret data to be proved; A processing unit, configured to generate an element set of a target form based on a random number and a generator of an elliptic curve, wherein the element set includes elements related to an independent variable of the point-valued polynomial; A commitment unit, configured to generate a commitment of the point-valued polynomial based on each element in the element set, and to generate a proof of the point-valued polynomial based on the acquired target independent variable; The commitment and the proof are used to verify the existence of the secret data.

12. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, and the processor implements the method according to any one of claims 1 to 10 when executing the computer program.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.

14. A chip system, characterized in that: The chip system is applied to an electronic device, and the chip system includes one or more processors, and the one or more processors are used to call computer instructions so that the electronic device executes the method as described in any one of claims 1 to 10.

15. A computer program product, characterized in that When the computer program product runs on an electronic device, the electronic device is enabled to execute the method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Privacy-protecting data relationship proving method and system

    CN114978538A

  • Consensus method and device for block chain nodes

    CN116228407A

  • Method for creating account in block chain and block chain node

    CN116303425A

  • Method based on polynomial commitment, electronic equipment and readable storage medium

    CN117278213A

  • Information processing system and information processing method

    JP2022121846A

Cited By

  • Decentralized identity authentication method combining Merkel tree and zero-knowledge proof and related equipment

    CN121644085A

  • Verifiable calculation method based on polynomial commitment

    CN121664437A