Device and system for realizing data validation
By using Merkel tree and zero-knowledge proof technology in distributed data systems, the data commitment value is generated and verified, and the security problem of data under multi-node storage is solved, realizing the reliability and privacy protection of data communication.
Patent Information
- Application Number
- PCT/CN2023/136453
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-05
- Publication Date
- 2025-06-12
AI Technical Summary
Since data is stored on multiple nodes and distributed in different geographical locations, distributed in data, it is vulnerable to network attacks and data theft or tampering, and security measures are required to protect the confidentiality and integrity of the data.
Using Merkel tree and zero-knowledge proof technology, the polynomial P(x) is obtained by arithmeticizing the data, and hashing all 2n values in the value range to generate a Merkel tree. The root value of the Merkel tree is used as the promised value. The verification party confirms the integrity and confidentiality of the data by receiving and verifying the verification data.
It realizes the reliability and privacy protection of data communication within a distributed data system, ensures the immutability and confidentiality of data, thereby enhancing the security of the system.
Smart Images

Figure CN2023136453_12062025_PF_FP_ABST
Abstract
Description
Device and system for realizing data verification Technical Field
[0001] This article relates to the field of cryptographic computing technology, and in particular to a device and system for implementing data verification. Background Art
[0002] In the information age, data storage is crucial. Distributed data systems store data across multiple nodes, enabling low-latency storage and efficient processing.
[0003] Because distributed data systems store data on multiple nodes and are distributed across different geographical locations, attackers may steal or tamper with data through the network. Therefore, distributed data systems require security measures to protect the confidentiality and integrity of data.
[0004] Summary of the Invention
[0005] The following is a summary of the subject matter described in detail herein. This summary is not intended to limit the scope of the claims.
[0006] The present disclosure provides a device for implementing data verification, which is applied to a proving party and includes:
[0007] The commitment establishment module is configured to arithmetically transform the prover's data to obtain a polynomial P(x), and to convert all 2 n The hash operation is performed on each value to get 2 n Hash value, composed of 2 n The hash values generate a Merkle tree, and the root value of the Merkle tree is used as the commitment value of the polynomial; where x is [0,2 n -1]; the power exponent n is a positive integer;
[0008] The verification declaration module is configured to use the commitment value of the polynomial as a random source, operate on the random source to generate a random number R, locate the first leaf node and the second leaf node of the Merkle tree according to the random number R, establish a verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and send the values of all nodes on the verification path as verification data to the verifier; wherein R is [0,2 n -1] is a non-negative integer.
[0009] The present disclosure provides a device for implementing data verification, which is applied to a verification party and includes:
[0010] a receiving module configured to receive verification data from a prover, and obtain a commitment value of the polynomial and values of nodes on a verification path of the Merkle tree from the verification data;
[0011] a calculation module configured to use the commitment value of the polynomial as a random source, perform operations on the random source to generate a random number R, locate a first leaf node and a second leaf node of a Merkle tree according to the random number R, determine a verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and calculate a value of the root of the Merkle tree according to the values of the nodes on the verification path;
[0012] The comparison module is configured to compare the calculated root value of the Merkle tree with the received commitment value of the polynomial. If the two are consistent, the verification is successful; if the two are inconsistent, the verification fails.
[0013] The present disclosure provides a system for implementing data verification, including: the above-mentioned prover including the device for implementing data verification and the above-mentioned verifier including the device for implementing data verification.
[0014] Compared with the related art, the apparatus for realizing data verification provided by the present disclosure is applied to the prover, and the commitment establishment module arithmetically converts the prover's data into a polynomial P(x), and converts the polynomial into all 2 n The hash operation is performed on each value to get 2 n Hash value, composed of 2 n A Merkle tree is generated based on hash values, and the value of the root of the Merkle tree is used as the commitment value of the polynomial; the verification declaration module uses the commitment value of the polynomial as a random source, operates on the random source to generate a random number R, locates the first leaf node and the second leaf node of the Merkle tree according to the random number R, establishes a verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and sends the values of all nodes on the verification path as verification data to the verifier. The present disclosure provides a device for implementing data verification for a verifier, wherein a receiving module receives verification data from a prover, obtains a commitment value of a polynomial and the values of nodes on a verification path of a Merkle tree from the verification data; a computing module uses the commitment value of the polynomial as a random source, operates on the random source to generate a random number R, locates the first leaf node and the second leaf node of the Merkle tree according to the random number R, determines the verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and calculates the value of the root of the Merkle tree according to the values of the nodes on the verification path; a comparing module compares the calculated value of the root of the Merkle tree with the received commitment value of the polynomial, and if the two are consistent, the verification passes; if the two are inconsistent, the verification fails. The above-mentioned device for implementing data verification can ensure the reliability and privacy protection of data communication within a distributed data system.
[0015] Other features and advantages of the present disclosure will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present disclosure. Other advantages of the present disclosure can be realized and obtained through the solutions described in the description and the drawings.
[0016] Still other aspects will become apparent upon reading and understanding the accompanying drawings and detailed description.
[0017] Summary of the Figures
[0018] The accompanying drawings are used to provide an understanding of the technical solution of the present disclosure and constitute a part of the specification. Together with the embodiments of the present disclosure, they are used to explain the technical solution of the present disclosure and do not constitute a limitation to the technical solution of the present disclosure.
[0019] FIG1 is a schematic diagram of a device structure for implementing data verification (prover) provided in an embodiment of the present disclosure;
[0020] FIG2 is a schematic diagram of a Merkle tree provided in an embodiment of the present disclosure (n=3);
[0021] FIG3 is a schematic diagram of storing node data of a Merkle tree in a first storage area according to an embodiment of the present disclosure (n=3);
[0022] FIG4 is a schematic diagram of a Merkle tree verification path provided by an embodiment of the present disclosure (n=3, R=2);
[0023] FIG5 is a schematic diagram of storing node data on a verification path of a Merkle tree in a first storage area according to an embodiment of the present disclosure (n=3, R=2);
[0024] FIG6 is a schematic diagram of storing n+2 verification data in a second storage area according to an embodiment of the present disclosure (n=3, R=2);
[0025] FIG7 is a schematic structural diagram of a device for implementing data verification provided by an embodiment of the present disclosure;
[0026] FIG8 is a schematic structural diagram of a device for implementing data verification provided by an embodiment of the present disclosure (verification side);
[0027] FIG9 is a schematic structural diagram of a system for implementing data verification provided by an embodiment of the present disclosure;
[0028] FIG10 is a schematic structural diagram of another system for implementing data verification provided by an embodiment of the present disclosure.
[0029] Details
[0030] The present disclosure describes a plurality of embodiments, but this description is exemplary rather than restrictive, and it will be apparent to those skilled in the art that there may be more embodiments and implementations within the scope of the embodiments described in the present disclosure. Although many possible feature combinations are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically limited, any feature or element of any embodiment may be used in combination with any other feature or element in any other embodiment, or may replace any other feature or element in any other embodiment.
[0031] The present disclosure includes and contemplates combinations of features and elements known to those of ordinary skill in the art. The disclosed embodiments, features, and elements of the present disclosure may also be combined with any conventional features or elements to form a unique inventive solution defined by the claims. Any features or elements of any embodiment may also be combined with features or elements from other inventive solutions to form another unique inventive solution defined by the claims. Therefore, it should be understood that any feature shown and / or discussed in this disclosure may be implemented individually or in any appropriate combination. Therefore, the embodiments are not subject to other limitations except for the limitations set forth in the appended claims and their equivalents. In addition, various modifications and changes may be made within the scope of protection of the appended claims.
[0032] In addition, when describing representative embodiments, the specification may have presented the method and / or process as a specific sequence of steps. However, to the extent that the method or process does not rely on the specific order of the steps described herein, the method or process should not be limited to the steps in the specific order described. As will be understood by those skilled in the art, other orders of steps are also possible. Therefore, the specific order of the steps set forth in the specification should not be interpreted as limiting the claims. In addition, the claims to the method and / or process should not be limited to performing their steps in the order written, and those skilled in the art can readily understand that these orders can be changed without departing from the scope of this disclosure.
[0033] As shown in FIG1 , an embodiment of the present disclosure provides a device for implementing data verification, which is applied to a proving party and includes:
[0034] The commitment establishment module 10 is configured to perform arithmetic on the prover's data to obtain a polynomial P(x), and to convert all 2 n The hash operation is performed on each value to get 2 n Hash value, composed of 2 n The hash values generate a Merkle tree, and the root value of the Merkle tree is used as the commitment value of the polynomial; where x is [0,2 n-1]; the power exponent n is a positive integer;
[0035] The verification declaration module 20 is configured to use the commitment value of the polynomial as a random source, operate on the random source to generate a random number R, locate the first leaf node and the second leaf node of the Merkle tree according to the random number R, establish a verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and send the values of all nodes on the verification path as verification data to the verifier; wherein R is [0,2 n -1] is a non-negative integer.
[0036] The embodiment of the present disclosure provides a device for implementing data verification for a prover, wherein a commitment establishment module performs arithmetic operation on the prover's data to obtain a polynomial P(x), and converts the polynomial into a number of 2 values within the range. n The hash operation is performed on each value to get 2 n Hash value, composed of 2 n The hash values generate a Merkle tree, and the root value of the Merkle tree is used as the commitment value of the polynomial; where x is [0,2 n -1] is a non-negative integer; the power exponent n is a positive integer; the verification declaration module uses the commitment value of the polynomial as a random source, operates on the random source to generate a random number R, locates the first leaf node and the second leaf node of the Merkle tree according to the random number R, establishes a verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and sends the values of all nodes on the verification path as verification data to the verifier; where R is [0,2 n The above-mentioned device for implementing data verification can ensure the reliability and privacy protection of data communication in a distributed data system.
[0037] A Merkle tree is a binary hash tree invented by Ralph Merkle in 1979. It stores data in leaf nodes in a tree-like structure and uses a sequential hashing operation to generate branches (non-leaf nodes) and the root of the Merkle tree. Any changes to leaf node data are propagated to the nodes above it and ultimately reflected in changes to the root of the Merkle tree. Therefore, the Merkle tree ensures data immutability.
[0038] FIG2 shows a schematic diagram of a Merkle tree (n=3). The Merkle tree includes 4 layers. The 0th layer of the Merkle tree is the leaf node layer, which includes 8 (2 n, n=3) leaf nodes, and the data stored are: H0_0 to H0_7. The 0th leaf node stores the polynomial P(x), the hash value H0_0 after the polynomial value when x=0 is hashed. The first layer of the Merkle tree is the first-level non-leaf node layer, which includes 4 first-level non-leaf nodes, and the data stored are: H1_0 to H1_3. Each first-level non-leaf node stores the result of the hash operation of the hash values of two leaf nodes. For example, the 0th first-level non-leaf node stores: H1_0 = hash(H0_0 | H0_1). That is, H1_0 is the result of hashing the hash value H0_0 of the 0th leaf node and the hash value H0_1 of the 1st leaf node. The second layer of the Merkle tree is the second-level non-leaf node layer, which includes 2 second-level non-leaf nodes, and the data stored are: H2_0 to H2_1. Each second-level non-leaf node stores the hash value of two first-level non-leaf nodes after a hash operation. For example, the 0th second-level non-leaf node stores: H2_0 = hash(H1_0 | H1_1). In other words, H2_0 is the result of a hash operation on the hash value H1_0 of the 0th first-level non-leaf node and the hash value H1_1 of the 1st first-level non-leaf node. The third layer of the Merkle tree is the root of the Merkle tree, and the data stored is: H3_0. The root of the Merkle tree stores: H3_0 = hash(H2_0 | H2_1). In other words, H3_0 is the result of a hash operation on the hash value H2_0 of the 0th second-level non-leaf node and the hash value H2_1 of the 1st second-level non-leaf node.
[0039] Zero-knowledge proof (ZKP) is a cryptographic protocol that allows a prover to convince a verifier that a claim is correct without providing any useful information to the verifier. This proof process proves that the prover knows or possesses a certain message while ensuring that the proof process does not reveal any information about the message being proven to the verifier. Merkle trees can implement ZKP.
[0040] In an exemplary embodiment, the claim verification module is configured to generate a random number R by operating the random source using the following method: operating the commitment value of the polynomial using the Fiat-Shamir heuristic transformation to generate the random number R. The random number generated by the Fiat-Shamir heuristic transformation is unpredictable and verifiable by the verifier. By generating the random number locally, the prover can transform an interactive zero-knowledge proof into a non-interactive zero-knowledge proof, thereby improving verification efficiency.
[0041] In an exemplary embodiment, the commitment establishment module is further configured to store the node data of the Merkle tree in a first storage area of the memory.
[0042] In an exemplary embodiment, the commitment establishment module is configured to store the node data of the Merkle tree in the first storage area of the memory in the following manner:
[0043] Starting from the 0th address of the first storage area of the memory, the value of each node of the Merkle tree is continuously stored in the order of increasing addresses. Starting from the leaf node layer of the Merkle tree, the value is stored layer by layer until the root of the Merkle tree. Each layer of the Merkle tree is continuously stored starting from the 0th node in the order of increasing node sequence numbers. The value of one node corresponds to one address.
[0044] In an exemplary embodiment, the data width (hash value width) of the value of the node of the Merkle tree can be set. For example, the hash value width can be 512 bits. The hash value width can be set according to the needs of the application.
[0045] Figure 3 shows a schematic diagram of the storage of node data of a Merkle tree in the first storage area (n=3). The Merkle tree includes 4 layers. The 0th layer (bottom layer) of the Merkle tree is the leaf node layer, including 8 leaf nodes, and the stored data are: H0_0 to H0_7, and the data of the leaf node layer occupy the 0th address (D0) to the 7th address (D7) in the first storage area. The 1st layer of the Merkle tree is the first-level non-leaf node layer, including 4 leaf nodes, and the stored data are: H1_0 to H1_3, and the data of the first-level non-leaf node layer occupy the 8+0th address (D8) to the 8+3rd address (D11) in the first storage area, that is, 2 3 2 after the address 2 The second layer of the Merkle tree is the second-level non-leaf node layer, which includes 2 leaf nodes. The stored data are: H2_0 to H2_1. The data of the second-level non-leaf node layer occupies the 8+4+0th address (D12) to the 8+4+1th address (D13) in the first storage area, that is, 2 3 +2 2 2 after the address 1 The third layer (top layer) of the Merkle tree includes 1 node, which is the root of the Merkle tree. The data stored is: H3_0. The root of the Merkle tree occupies the 8+4+2+0th address (D14) in the first storage area, which is 2 3 +2 2 +2 1 2 after the address 0 an address.
[0046] In an exemplary embodiment, the verification declaration module is configured to send the values of all nodes on the verification path as verification data to the verifier in the following manner:
[0047] Read the values of n+2 nodes on the verification path of the Merkle tree from the first storage area according to the random number R as n+2 verification data Y(0) to Y(n+1);
[0048] Each time a verification data Y(j) is read from the first storage area, the verification data Y(j) is written into the j-th address of the second storage area of the memory; 0≤j≤n-1.
[0049] In an exemplary embodiment, the verification declaration module is configured to read the values of n+2 nodes on the verification path of the Merkle tree from the first storage area according to the random number R as n+2 verification data Y(0) to Y(n+1) respectively in the following manner:
[0050] When reading the 0th layer of the Merkle tree, data of two nodes of the 0th layer of the Merkle tree are read from the first storage area according to the parity of the random number R as the 0th verification data Y(0) and the 1st verification data Y(1);
[0051] When reading the 1st to n-1th layers of the Merkle tree, for any i-th layer, determine the node offset of the node to be read on the i-th layer Merkle tree, and read the data of a node of the i-th layer Merkle tree from the first storage area according to the parity of the node offset as the i+1th verification data Y(i+1); i is an integer, 1≤i≤n-1;
[0052] When reading the nth layer of the Merkle tree, the data of the root node of the Merkle tree is read from the first storage area as the n+1th verification data Y(n+1).
[0053] In an exemplary embodiment, the verification declaration module is configured to read data of two nodes of the 0th layer Merkle tree from the first storage area as the 0th verification data Y(0) and the 1st verification data Y(1) according to the parity of the random number R in the following manner: if the random number R is an odd number, the data of the R-1th address is read from the first storage area and used as the 0th verification data Y(0), and the data of the Rth address is read and used as the 1st verification data Y(1); if the random number R is an even number, the data of the Rth address is read from the first storage area and used as the 0th verification data Y(0), and the data of the R+1th address is read and used as the 1st verification data Y(1).
[0054] In an exemplary embodiment, the verification declaration module is configured to read data of a node of the i-th level Merkle tree from the first storage area as the i+1th verification data Y(i+1) according to the parity of the node offset in the following manner:
[0055] If the node offset d(i) is an odd number, the data at the D(i)+d(i)-1th address is read from the first storage area and used as the i+1th verification data Y(i+1); if the node offset d(i) is an even number, the data at the D(i)+d(i)+1th address is read from the first storage area and used as the i+1th verification data Y(i+1);
[0056] in, D(i)=2 n +2 n-1 +…+2 n+1-i ; is the floor symbol.
[0057] Assume that the Merkle tree consists of three layers (n=3) and the random number R=2. Figure 4 shows a schematic diagram of a Merkle tree verification path (n=3, R=2). As shown in Figure 4, the nodes with a five-pointed star are nodes on the verification path. From the bottom layer (layer 0) of the Merkle tree to the highest layer (top layer) of the Merkle tree, there are a total of five nodes, including two leaf nodes, one first-level non-leaf node, one second-level non-leaf node, and one Merkle tree root. The data stored in the two leaf nodes are: H0_2 to H0_3. The data stored in the first-level non-leaf node is: H1_0. The data stored in the second-level non-leaf node is: H2_1. The data stored in the root of the Merkle tree is: H3_0.
[0058] FIG5 shows a schematic diagram of the storage of node data on a verification path of a Merkle tree in the first storage area (n=3, R=2). As shown in FIG5 , when n=3, R=2, the verification path includes 5 nodes from the bottom layer (0th layer) of the Merkle tree to the top layer (top layer) of the Merkle tree. In the first storage area, the node data with a five-pointed star is the node data on the verification path. Among them, the 0th verification data Y(0) corresponds to H0_2 and is stored at the 2nd address of the first storage area; the 1st verification data Y(1) corresponds to H0_3 and is stored at the 3rd address of the first storage area; the 2nd verification data Y(2) corresponds to H1_0 and is stored at the 8th+0th address of the first storage area; the 3rd verification data Y(3) corresponds to H2_1 and is stored at the 8th+4th+1th address of the first storage area; the 4th verification data Y(4) corresponds to H3_0 and is stored at the 8th+4th+2th address of the first storage area.
[0059] The Merkle tree is stored in the first storage area, and the storage address of the 0th node of the 0th layer of the Merkle tree in the first storage area can be used as the starting storage address of the Merkle tree in the first storage area.
[0060] Obtaining node data on the verification path of the Merkle tree from the first storage area may include the following steps:
[0061] Step S1: Represent the random number R as a binary number r of length n; wherein n is the maximum number of layers of the Merkle tree, the bottom layer of the Merkle tree is layer 0, and the highest layer is layer n.
[0062] Step S2: For the 0th node data to be obtained from the Merkle tree, the storage location of the data in the first storage area is: the location offset by r0 after the starting storage address of the node at the 0th level of the Merkle tree; wherein r0=r;
[0063] Step S3: For the first node data to be obtained from the Merkle tree, the storage location of the data in the first storage area is: the location offset by r1 after the starting storage address of the node at the 0th level of the Merkle tree; wherein r1 is the inverse of the last digit (the lowest digit) of r;
[0064] Step S4: For the i-th node data to be obtained from the Merkle tree, the storage location of the data in the first storage area is: the location offset by r(i) after the starting storage address of the node at the i-1th level of the Merkle tree; where r(i) is r shifted right by i-1 bits and the last digit is inverted; i is an integer, 2≤i≤n;
[0065] Step S5: For the n+1th node data that needs to be obtained from the Merkle tree, the storage location of the data in the first storage area is: a location with an offset of 0 after the starting storage address of the n+1th layer node of the Merkle tree.
[0066] The following example uses n=3 and R=2 to illustrate how to obtain node data on the verification path of the Merkle tree from the first storage area. Assume that the storage address of the 0th node of the 0th layer of the Merkle tree in the first storage area is 0x0, and the data width (hash value width) of the value of the Merkle tree node is 512.
[0067] Step S1: Express the random number R=2 as a binary number 010 with a length of 3;
[0068] Step S2: The storage location of the 0th node data to be obtained from the Merkle tree is: the location with an offset of r0 after the starting storage address 0x0 of the 0th layer node of the Merkle tree, r0=r=010, which is the second data on the Merkle tree;
[0069] Step S3: The first node data to be obtained from the Merkle tree is stored at a location r1 after the starting storage address 0x0 of the node at level 0 of the Merkle tree. r1 is the inverted last digit of 010 to get 011, which is the third data in the Merkle tree.
[0070] Step S4: The storage location of the second node data to be obtained from the Merkle tree is: the location offset by r2 after the starting storage address 1000 of the first-level node of the Merkle tree. r2 is 000 after shifting 010 right by 1 bit and inverting the last digit, which is the 8th data in the Merkle tree.
[0071] Step S5: The storage location of the third node data to be obtained from the Merkle tree is: the location with an offset of r3 after the starting storage address 1100 of the second-level node of the Merkle tree. r3 is 001 after shifting 010 right by 2 bits and inverting the last digit, which is the 13th data in the Merkle tree.
[0072] Step S6: The storage location of the fourth node data that needs to be obtained from the Merkle tree is: the location with an offset of 0 after the starting storage address 1110 of the third-layer node of the Merkle tree, that is, the 14th data on the Merkle tree.
[0073] FIG6 shows a schematic diagram of storing n+2 verification data in the second storage area (n=3, R=2). As shown in FIG6, the 0th verification data Y(0) is stored at the 0th address D(0) of the second storage area, the jth verification data Y(j) is stored at the jth address D(j) of the second storage area, and the n+1th verification data Y(n+1) is stored at the n+1th address D(n+1) of the second storage area.
[0074] Figure 7 shows a schematic diagram of the structure of a device for implementing data verification. As shown in Figure 7, in an exemplary embodiment, the verification declaration module includes: a random number generation unit 201, a configuration unit 202, a memory access unit 203, a control unit 204 and a communication unit 205;
[0075] a random number generation unit configured to receive a commitment value of the polynomial sent by the commitment establishment module, use the commitment value of the polynomial as a random source, perform operations on the random source to generate a random number R, and send the random number R to the configuration unit;
[0076] A configuration unit is configured to receive a random number R sent by a random number generation unit and configuration information sent by a commitment establishment module. Upon receiving a start signal, the configuration unit locates a first leaf node and a second leaf node of the Merkle tree according to the random number R, establishes a verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and sends the storage addresses of the values of all nodes on the verification path in the first storage area and the starting storage address of the verification data in the second storage area to a memory access unit. The configuration information includes: the starting storage address of the Merkle tree in the first storage area, the starting storage address of the verification data in the second storage area, and the data width and power exponent n of the value of the node of the Merkle tree.
[0077] a memory access unit configured to read verification data from the first storage area, write the read verification data into the second storage area, and feedback the progress of the writing operation of the verification data into the second storage area to the control unit;
[0078] The control unit is configured to send a start signal to the configuration unit; receive the write operation progress feedback from the memory access unit, and send a verification data preparation completion message to the communication unit when all the verification data are written into the second storage area;
[0079] The communication unit is configured to read all verification data from the second storage area after receiving the verification data preparation completion message, and send the verification data to the verification party.
[0080] In an exemplary embodiment, the memory access unit includes a DMA (Direct Memory Access). In other embodiments, the memory access unit may also be other types of memory access devices.
[0081] As shown in FIG8 , an embodiment of the present disclosure provides a device for implementing data verification, which is applied to a verification party and includes:
[0082] a receiving module 10 configured to receive verification data from a prover, and obtain a commitment value of the polynomial and values of nodes on a verification path of the Merkle tree from the verification data;
[0083] a computing module 20 configured to use the commitment value of the polynomial as a random source, perform operations on the random source to generate a random number R, locate a first leaf node and a second leaf node of a Merkle tree according to the random number R, determine a verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and calculate a value of the root of the Merkle tree according to the values of the nodes on the verification path;
[0084] The comparison module 30 is configured to compare the calculated root value of the Merkle tree with the received commitment value of the polynomial. If the two are consistent, the verification is successful; if the two are inconsistent, the verification fails.
[0085] The apparatus for implementing data verification applied to a verifier provided by an embodiment of the present disclosure, a receiving module receives verification data from a prover, and obtains a commitment value of a polynomial and values of nodes on a verification path of a Merkle tree from the verification data; a computing module uses the commitment value of the polynomial as a random source, operates on the random source to generate a random number R, locates a first leaf node and a second leaf node of the Merkle tree according to the random number R, determines a verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and calculates the value of the root of the Merkle tree according to the values of the nodes on the verification path; a comparing module compares the calculated value of the root of the Merkle tree with the received commitment value of the polynomial, if the two are consistent, the verification passes, if the two are inconsistent, the verification fails. The above method for implementing data verification can ensure the reliability of data communication and privacy protection in a distributed data system.
[0086] In an exemplary embodiment, the computing module is configured to operate on the random source to generate a random number R in the following manner: use the Fiat-Shamir heuristic transformation to operate on the commitment value of the polynomial to generate a random number R. The random number generated by the Fiat-Shamir heuristic transformation is unpredictable and can be verified by the verifier. The verifier and the prover can obtain the same random number by using the same operation method and input value (the commitment value of the polynomial), which can transform an interactive zero-knowledge proof into a non-interactive zero-knowledge proof, thereby improving the verification efficiency.
[0087] In an exemplary embodiment, the computing module is configured to calculate the value of the root of the Merkle tree according to the values of the nodes on the verification path in the following manner:
[0088] Take the result of the hash operation on the values of the two nodes at the 0th layer of the Merkle tree on the verification path as the value of a node at the 1st layer;
[0089] Perform hash operations on the nodes at the 1st to the n-1th layers of the Merkle tree layer by layer according to the verification path until the value of the root of the Merkle tree is obtained, including performing the following steps a to d;
[0090] Step a: Set j to 1;
[0091] Step b: If j < n, execute step c; if j = n, execute step d;
[0092] Step c: Take the result of the hash operation on the value of the node at the jth layer obtained by the hash operation and the value of the node at the same layer on the verification path as the value of a node at the j+1th layer, increment the value of j by 1, and return to step b;
[0093] Step d: Take the value of the node at the nth layer obtained by the hash operation as the value of the root of the Merkle tree.
[0094] As shown in FIG9 , an embodiment of the present disclosure provides a system for implementing data verification, including: the above-mentioned prover including the device for implementing data verification and the above-mentioned verifier including the device for implementing data verification.
[0095] Figure 10 shows a schematic diagram of another system for data verification. As shown in Figure 10, the prover performs arithmetic on the data to obtain a polynomial P(x), where x is a value between [0,2 n -1], calculate the value of P(x) in [0,2 n -1], totaling 2 n For these 2 n The hash calculation of the value is 2 n hash value. Use 2 n The root of the Merkle tree represents the commitment to the polynomial. The root of the Merkle tree is used as the random source and the Fiat-Shamir heuristic transformation is used to obtain a random point (random number) R, with a value of [0,2 n -1]. The first and second leaf nodes of the Merkle tree are located based on the random number R, a verification path is established from the two leaf nodes to the root of the Merkle tree, and the values of all nodes on the verification path are sent to the verifier as verification data. The random numbers generated by the Fiat-Shamir heuristic transformation are unpredictable and verifiable by the verifier. By generating random numbers locally, the prover can transform an interactive zero-knowledge proof into a non-interactive zero-knowledge proof, thereby improving verification efficiency.
[0096] The verifier receives the verification data from the prover and obtains the commitment value of the polynomial and the value of the node on the verification path of the Merkle tree from the verification data. Using the commitment value of the polynomial as the random source, the Fiat-Shamir heuristic transformation is used to obtain a random point (random number) R. The value of the random number R calculated by the verifier is the same as the value of R calculated by the prover (because the same operation is performed using the commitment value of the same polynomial). The first and second leaf nodes of the Merkle tree are located according to the random number R, and the verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree is determined. The value of the root of the Merkle tree is calculated based on the value of the node on the verification path. The calculated value of the root of the Merkle tree is compared with the commitment value of the received polynomial. If the two are consistent, the verification is passed. If the two are inconsistent, the verification fails.
[0097] It will be appreciated by those skilled in the art that the functional modules / units in the apparatus disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In a hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As is well known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media generally embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.
[0098] It should be noted that the above-described embodiments or implementations are merely illustrative and not restrictive. Therefore, the present disclosure is not limited to what is specifically shown and described herein. Various modifications, substitutions, or omissions may be made to the forms and details of the implementations without departing from the scope of the present disclosure.
Claims
1. A device for implementing data verification, applied to the prover, comprising: Commitment establishment module, configured to arithmetize the prover's data to obtain polynomial P(x), and perform hash operations on all 2 n values within the value range of the polynomial to obtain 2 n hash values, generate a Merkle tree from the 2 n hash values, and use the value of the root of the Merkle tree as the commitment value of the polynomial; where x is a non-negative integer within [0, 2 n - 1]; the power exponent n is a positive integer; The verification statement module is configured to use the committed value of the polynomial as a random source, operate on the random source to generate a random number R, locate the first leaf node and the second leaf node of the Merkle tree according to the random number R, establish a verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and send the values of all nodes on the verification path to the verifier as verification data; where R is a non-negative integer within [0, 2 n - 1].
2. The device according to claim 1, wherein: The verification statement module is configured to generate a random number R by operating on the random source in the following manner: use the Fiat-Shamir heuristic transformation to operate on the commitment value of the polynomial to generate the random number R.
3. The device according to claim 1, wherein: The commitment establishment module is further configured to store the node data of the Merkle tree in the first storage area of the memory: starting from the 0th address of the first storage area of the memory, continuously store the values of each node of the Merkle tree in ascending order of the address, starting from the leaf node layer of the Merkle tree and storing layer by layer until the root of the Merkle tree, and for each layer of the Merkle tree, starting from the 0th node, continuously store in ascending order of the node number, and the value of one node corresponds to one address.
4. The device according to claim 3, wherein: The verification statement module is configured to send the values of all nodes on the verification path as verification data to the verifier in the following manner: Read the values of n + 2 nodes on the verification path of the Merkle tree from the first storage area as n + 2 verification data Y(0) to Y(n + 1) according to the random number R; Each time a verification data Y(j) is read from the first storage area, write the verification data Y(j) to the jth address of the second storage area of the memory; 0 ≤ j ≤ n - 1.
5. The device according to claim 4, wherein: The verification statement module is configured to read the values of n + 2 nodes on the verification path of the Merkle tree from the first storage area as n + 2 verification data Y(0) to Y(n + 1) according to the random number R in the following manner: When reading the 0th layer of the Merkle tree, read the data of two nodes of the 0th layer of the Merkle tree from the first storage area as the 0th verification data Y(0) and the 1st verification data Y(1) according to the parity of the random number R; When reading the 1st layer to the (n - 1)th layer of the Merkle tree, for any ith layer, determine the node offset of the node to be read on the ith layer of the Merkle tree, and read the data of one node of the ith layer of the Merkle tree from the first storage area as the (i + 1)th verification data Y(i + 1) according to the parity of the node offset; i is an integer, 1 ≤ i ≤ n - 1; When reading the nth layer of the Merkle tree, read the data of the root node of the Merkle tree from the first storage area as the (n + 1)th verification data Y(n + 1).
6. The device according to claim 4, wherein: The verification statement module includes: a random number generation unit, a configuration unit, a memory access unit, a control unit, and a communication unit; The random number generation unit is configured to receive the commitment value of the polynomial sent by the commitment establishment module, use the commitment value of the polynomial as a random source, operate on the random source to generate a random number R, and send the random number R to the configuration unit; The configuration unit is set to receive the random number R sent by the random number generation unit and the configuration information sent by the commitment establishment module. After receiving the start signal, it locates the first leaf node and the second leaf node of the Merkle tree according to the random number R, establishes a verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and sends the storage addresses of the values of all nodes on the verification path in the first storage area and the starting storage address of the verification data in the second storage area to the memory access unit; wherein, the configuration information includes: the starting storage address of the Merkle tree in the first storage area, the starting storage address of the verification data in the second storage area, the data width of the values of the nodes of the Merkle tree, and the power exponent n; The memory access unit is set to read the verification data from the first storage area, write the read verification data into the second storage area, and feedback the write operation progress of the verification data written into the second storage area to the control unit; The control unit is set to send a start signal to the configuration unit; receive the write operation progress feedback by the memory access unit, and send a verification data preparation completed message to the communication unit after all the verification data is written into the second storage area; The communication unit is set to read all the verification data from the second storage area after receiving the verification data preparation completed message, and send the verification data to the verifier.
7. A device for implementing data verification, applied to the verifier, comprising: A receiving module, set to receive the verification data from the prover, and obtain the commitment value of the polynomial and the values of the nodes on the verification path of the Merkle tree from the verification data; A calculation module, set to use the commitment value of the polynomial as a random source, perform operations on the random source to generate a random number R, locate the first leaf node and the second leaf node of the Merkle tree according to the random number R, determine the verification path from the two leaf nodes of the Merkle tree to the root of the Merkle tree, and calculate the value of the root of the Merkle tree according to the values of the nodes on the verification path; A comparison module, set to compare the calculated value of the root of the Merkle tree with the received commitment value of the polynomial. If the two are consistent, the verification passes; if the two are inconsistent, the verification fails.
8. The device according to claim 7, wherein: The calculation module is set to perform operations on the random source to generate a random number R in the following manner: use the Fiat-Shamir heuristic transformation to perform operations on the commitment value of the polynomial to generate a random number R.
9. The device according to claim 7, wherein: The calculation module is set to calculate the value of the root of the Merkle tree according to the values of the nodes on the verification path in the following manner: Take the result of the hash operation on the values of the two nodes at the 0th layer of the Merkle tree on the verification path as the value of a node at the 1st layer; Perform hash operations on the nodes at the 1st to the n-1th layers of the Merkle tree layer by layer according to the verification path until the value of the root of the Merkle tree is obtained, including performing the following steps a to d; Step a: Set j to 1; Step b: If j < n, execute step c; if j = n, execute step d; Step c: Use the result of the hashing operation between the value of the node at the j-th layer obtained by the hashing operation and the value of the node at the same layer on the verification path as the value of a node at the (j + 1)-th layer, increment the value of j by 1, and return to step b; Step d: Use the value of the node at the n-th layer obtained by the hashing operation as the value of the root of the Merkle tree.
10. A system for implementing data verification, comprising: a prover including the device for implementing data verification according to any one of claims 1-6 above and a verifier including the device for implementing data verification according to any one of claims 7-9 above.
Citation Information
Patent Citations
Data existence and integrity verification method and system in data storage system
CN112699123A
Data processing method and device based on block chain network and storage medium
CN116488816A
Data verification method for industrial Internet of Things
CN116846579A
Method and apparatus for proving blockchain transaction
WO2022078181A1
Cited By
Sparse Merkel tree storage and verification method and device, medium and equipment
CN120950508A
Verifiable calculation method based on polynomial commitment
CN121664437A