Database verification method based on polynomial commitment and memory correctness verification

WO2026199182A1PCT designated stage Publication Date: 2026-10-01SHENZHEN INST OF ADVANCED TECH CHINESE ACAD OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/084800
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2026-10-01

Smart Images

  • Figure CN2025084800_01102026_PF_FP_ABST
    Figure CN2025084800_01102026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a database verification method based on polynomial commitment and memory correctness verification. The method is applied to a prover, and comprises: determining an initial state and a final state of data in a database during data processing, adding the initial state to a read set of a memory, and adding the final state to a write set of the memory; generating state commitments for the initial state and the final state, and sending the state commitments to a verifier; receiving a first challenge value from the verifier, and processing log records in the read set and the write set in the memory on the basis of the first challenge value, to obtain a log processing result and feeding back same to the verifier; and sending the read set and the write set to the verifier, so that the verifier verifies correctness of the read set and the write set on the basis of the state commitments and the log processing result, to determine correctness of memory verification. In the present solution, correctness of memory and correctness of execution can be verified during database data processing.
Need to check novelty before this filing date? Find Prior Art

Description

Database Validation Methods Based on Multinomial Commitment and Memory Correctness Check Technical Field

[0001] This application relates to the field of computer information technology, and more specifically, to a database verification method based on polynomial commitment and memory correctness detection. Background Technology

[0002] Existing databases typically determine the address of data by querying the index tree based on the user's data processing request, and then process the retrieved data accordingly, such as reading, modifying, or deleting. However, users cannot know whether the data processing is correct. Summary of the Invention

[0003] The embodiments of this application provide a database verification method based on polynomial commitment and memory correctness detection, which can record the initial and final states of the database and generate corresponding log records for verification by the verifier, so that the verifier can verify whether the data processing process is correct.

[0004] The technical solution is as follows:

[0005] In a first aspect, this application provides a database verification method based on multinomial commitment and memory correctness detection. The method is applied to the proving party and includes: determining the initial and final states of data in the database during data processing, adding the initial state to a read set in memory, and adding the final state to a write set in memory. The read set stores log records generated when accessing data in the database, and the write set stores log records generated when reading or modifying data in the database. The method also includes: generating state commitments for the initial and final states and sending them to the proving party; receiving a first challenge value from the proving party, and processing the log records in the read and write sets in memory based on the first challenge value to obtain log processing results and feed them back to the proving party; and sending the read and write sets to the proving party, which then verifies the correctness of the read and write sets based on the state commitments and the log processing results to determine the correctness of the memory verification.

[0006] Furthermore, the database data processing procedure includes: obtaining a data processing request, and indexing the database index tree according to the data processing request to determine the target address, wherein the database index tree includes a first node and a second node, the first node is used to store key-value information, and the second node is used to store data records, the data processing request includes data query, data addition, data deletion, data modification, and data reading; determining the target data at the target address, and executing the database operation corresponding to the data processing request to return the data processing result to the verification party.

[0007] Furthermore, the steps for generating log records include: when accessing target data at a target address in the database, generating log records based on the target address, target data, and timestamp, or the target address, target data, and counter, and storing them in the read set; when reading or modifying target data at a target address in the database, generating log records based on the target address, target data, and timestamp, or the target address, target data, and counter, and storing them in the write set.

[0008] Furthermore, sending the read set and write set to the verifier includes: receiving a second challenge value, processing the read set and write set based on the second challenge value to obtain a polynomial expansion result, and sending it to the verifier. The verifier verifies the correctness of the polynomial expansion result based on the state commitment and log processing result to determine the correctness of the memory verification.

[0009] Furthermore, the method also includes: generating an index polynomial based on the relevant nodes when indexing the database index tree according to the data processing request, and generating a polynomial commitment; sending the polynomial commitment and the index polynomial to the verifier, and the verifier verifying the index polynomial based on the polynomial commitment.

[0010] Furthermore, the first and second nodes of the database index tree correspond to a polynomial, with the first node containing a node commitment and the second node containing a hash value of the node content. The process of generating the index polynomial and generating the polynomial commitment includes: determining a target polynomial based on the first and second nodes in the relevant nodes; determining the coefficients of the target polynomial based on the node commitment of the first node and the hash value of the second node in the relevant nodes to form an index polynomial; and aggregating the node commitments of the first node in the relevant nodes to form a polynomial commitment.

[0011] Furthermore, the steps for updating the database index tree include: when inserting a second node, determining the node position of the second node and checking whether the capacity of the node position has reached the capacity limit; if so, splitting the node to generate hash values ​​for two second nodes; if not, updating the hash value of the node at the node position; determining the first node associated with the second node and updating the node commitment of the first node.

[0012] Furthermore, the memory is divided into a first memory and a second memory. The first memory is used to process data processing requests for reading data, and the second memory is used to process data processing requests for querying data, adding data, deleting data, and modifying data. The step of determining the initial and final states of data in the database during the data processing process, and adding the initial state to the read set and the final state to the write set in the memory, includes: when the second memory processes the data processing request, determining the initial and final states of data in the database during the data processing process, adding the initial state to the read set in the memory, and adding the final state to the write set in the memory.

[0013] Secondly, this application provides a database verification method based on multinomial commitment and memory correctness detection. The method is applied to the verifier and includes: generating a data processing request and sending it to the prover; the prover performing data processing based on the request and providing feedback on the processing results; the prover determining the initial and final states of data in the database during the data processing process, adding the initial state to a read set in memory, and adding the final state to a write set in memory. The read set stores log records generated when accessing data in the database, and the write set stores data read or modified. The data in the database is generated as log records; the prover generates initial and final state commitments and sends them to the verifier; the verifier receives the data processing results and state commitments sent by the prover and generates a first challenge value to send to the prover. The prover processes the log records in the read and write sets in memory based on the first challenge value, obtains the log processing results, and feeds them back to the verifier; the prover sends the read and write sets to the verifier; the verifier receives the log processing results, read and write sets, and verifies the correctness of the read and write sets based on the state commitments and log processing results to determine the correctness of the memory verification and the correctness of the data processing results.

[0014] Thirdly, this application provides a database verification device based on multinomial commitment and memory correctness detection. The device is applied on the proving side and includes: a data state processing module, used to determine the initial and final states of data in the database during data processing, adding the initial state to a read set in memory and the final state to a write set in memory, wherein the read set stores log records generated when accessing data in the database, and the write set stores log records generated when reading or modifying data in the database; a state commitment processing module, used to generate state commitments for the initial and final states and send them to the verifying side; a log recording processing module, used to receive a first challenge value from the verifying side and process the log records in the read and write sets in memory based on the first challenge value, obtaining log processing results and feeding them back to the verifying side; and a read and write set sending module, used to send the read and write sets to the verifying side, whereby the verifying side verifies the correctness of the read and write sets based on the state commitments and log processing results to determine the correctness of the memory verification.

[0015] Fourthly, this application provides a network device, including: a memory, a transceiver, and a processor; wherein the memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; and the processor is used to read the computer program in the memory and execute the method as described in the first or second aspect.

[0016] Fifthly, this application provides a storage medium having a computer program stored thereon, which, when executed by a processor, implements the method as described in the first or second aspect.

[0017] The beneficial effects of the technical solution provided in this application are:

[0018] The proposed solution can be applied to database-based data processing scenarios. It can perform corresponding operations in the database based on user data processing requests and provide proof of memory correctness and execution correctness of the data processing process, thereby determining the reliability of the data processing results. Specifically, this solution can include a verifier and a proviser. The verifier initiates the data processing request, while the proviser receives the request, performs the corresponding data processing, and provides verification services to the verifier. The verifier initiates the data processing request to the proviser. The proviser receives the request, indexes the database index tree, determines the target address of the target data corresponding to the data processing request, performs the corresponding data processing operation, and returns the data processing result to the verifier. Furthermore, the proving party determines the initial and final states of the data in the database during data processing, adding the initial state to the read set in memory and the final state to the write set in memory. The read set stores log records generated when accessing data in the database, while the write set stores log records generated when reading or modifying data in the database. The proving party generates state commitments for the initial and final states and sends them to the verifier. The proving party receives the verifier's first challenge value and processes the log records in the read and write sets in memory based on the first challenge value, obtaining the log processing results and feeding them back to the verifier. The proving party sends the read and write sets to the verifier, who verifies the correctness of the read and write sets based on the state commitments and the log processing results to determine the correctness of the memory verification. Additionally, the proving party can generate an index polynomial and a polynomial commitment based on the relevant nodes in the database index tree for the data processing request, sending this to the verifier. The verifier verifies the execution of the data processing process based on the polynomial commitments and the index polynomials. If both memory correctness and execution correctness verifications pass, the verifier confirms that the data processing process is correct and reliable. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below.

[0020] Figure 1 is a schematic diagram of the interaction between a verifiable database and a client according to an embodiment of this application;

[0021] Figure 2 is a schematic diagram of the log records stored in the read set and write set according to an embodiment of this application;

[0022] Figure 3 is a schematic diagram of the interaction between the prover and the verifier in one embodiment of this application;

[0023] Figure 4 is a schematic diagram of the process of inserting a leaf node into a data index tree according to an embodiment of this application;

[0024] Figure 5 is a flowchart illustrating a database verification method based on multinomial commitment and memory correctness detection according to an embodiment of this application;

[0025] Figure 6 is a flowchart illustrating a database verification method based on multinomial commitment and memory correctness detection according to another embodiment of this application;

[0026] Figure 7 is a schematic diagram of the structure of a database verification device based on multinomial commitment and memory correctness detection according to an embodiment of this application;

[0027] Figure 8 is a structural block diagram of a network device according to an embodiment of this application;

[0028] Figure 9 is a structural block diagram of a user equipment according to an embodiment of this application. Detailed Implementation

[0029] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals identify the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application.

[0030] Those skilled in the art will understand that, unless specifically stated otherwise, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms, while “a plurality” refers to two or more, and other quantifiers are similarly understood. It should be further understood that the word “comprising” as used in this application’s specification means the presence of the stated feature, integer, step, operation, element, and / or component, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we say an element is “connected” or “coupled” to another element, it can be directly connected or coupled to the other element, or there may be intermediate elements. Furthermore, “connected” or “coupled” as used herein can include wireless connection or wireless coupling. The word “and / or” as used herein describes the relationship between related objects, indicating that three relationships can exist; for example, A and / or B can represent: A alone, A and B simultaneously, and B alone. The character “ / ” generally indicates that the preceding and following related objects are in an “or” relationship.

[0031] The proposed solution can be applied to database-based data processing scenarios. It can perform corresponding operations in the database based on user data processing requests and provide proof of memory correctness and execution correctness of the data processing process, thereby determining the reliability of the data processing results. Specifically, the verifier initiates a data processing request to the proviser. The proviser receives the request, indexes the database index tree, determines the target address of the target data corresponding to the data processing request, executes the corresponding data processing operations, and returns the data processing result to the verifier. Furthermore, the proving party determines the initial and final states of the data in the database during data processing, adding the initial state to the read set in memory and the final state to the write set in memory. The read set stores log records generated when accessing data in the database, while the write set stores log records generated when reading or modifying data in the database. The proving party generates state commitments for the initial and final states and sends them to the verifier. The proving party receives the verifier's first challenge value and processes the log records in the read and write sets in memory based on the first challenge value, obtaining the log processing results and feeding them back to the verifier. The proving party sends the read and write sets to the verifier, who verifies the correctness of the read and write sets based on the state commitments and the log processing results to determine the correctness of the memory verification. Additionally, the proving party can generate an index polynomial and a polynomial commitment based on the relevant nodes in the database index tree for the data processing request, sending this to the verifier. The verifier verifies the execution of the data processing process based on the polynomial commitments and the index polynomials. If both memory correctness and execution correctness verifications pass, the verifier confirms that the data processing process is correct and reliable.

[0032] Below are the definitions of several key terms used in this application, specifically:

[0033] B+ Tree: A B+ tree is a self-balancing multi-way search tree specifically designed for external storage devices such as disks. Its main characteristics are: all data records are stored in leaf nodes, while non-leaf nodes only store key-value information as indexes. Leaf nodes are connected by linked lists to form ordered linked lists. This structure allows B+ trees to achieve both efficient random retrieval and sequential scanning. Furthermore, due to its short height and numerous branches, its tree structure is ideal for reducing disk I / O operations, making it the most commonly used index structure in database systems. The database index tree in this solution is based on a modified B+ tree.

[0034] Commitment: A basic cryptographic primitive, similar to sealing information in an encrypted box: the committer first locks a value and generates a commitment value to seal the information, and only reveals the original value in a later stage. This process needs to satisfy both binding property, that is, the original value cannot be changed after the commitment, and concealment property, that is, the original information cannot be inferred from the commitment value before it is revealed.

[0035] Multinomial commitment, or KZG commitment (Kate-Zaverucha-Goldberg Commitment), is a multinomial commitment scheme based on bilinear pairing. It allows the committer to generate a short commitment value for a polynomial, and then provide a concise proof for the polynomial's value at any point. Its core advantage is that both the commitment value and the proof are of constant size, the verification process is computationally efficient, and it has homomorphic properties, enabling the verifier to efficiently verify whether the polynomial's value at certain points is correct without knowing the complete polynomial.

[0036] Multilinear Extension: A function originally defined only on Boolean values ​​(0 and 1) is extended into a multilinear polynomial function that can take values ​​across the entire real number range. This extension ensures that the new function retains its original Boolean values ​​while providing richer verification possibilities, allowing verifiers to efficiently verify the correctness of calculations by checking at random points without knowing the complete function.

[0037] The basic contents of this solution include: (1) This invention proposes a new verifiable index data structure for relational database indexes, which integrates polynomial commitments and the B-tree structure widely used in databases, specifically for verifying the integrity of database memory pages. (2) This invention designs an interactive, SQL-friendly memory correctness checking protocol, which proves that the query is effectively executed by recording the read-write consistency of memory in the query, ensuring the validity and completeness of the query results, and avoiding the computational overhead caused by generating arithmetic circuits for the query in traditional interactive proof systems. (3) This invention generates a concise proof process based on polynomial expansion detection for the query results, enabling clients with fewer computational resources to still complete the verification of the query, enhancing the versatility of this invention and its ability to be applied in practical scenarios.

[0038] The following is a detailed description of this plan:

[0039] This solution can be applied to database verification scenarios. Verifiable databases, as a tool that can provide a high degree of protection for data integrity and traceability, will help promote the development of application areas such as privacy protection, data sharing, and decentralized storage verification through technological breakthroughs. This will ensure the immutability of data and end-to-end trustworthiness, making the data storage and sharing process more secure, transparent, and reliable.

[0040] As shown in Figure 1, the verifiable database of this invention mainly consists of three components: a verifiable virtual database engine, a polynomial index tree (or polynomial commitment B-tree), and a memory proof protocol generator. The verifiable virtual database engine is a virtual machine used to execute database query opcodes, and simultaneously generates memory correctness check records for generating query proofs. After receiving a query statement, the database performs syntax checks on the executed query statement through a tokenizer and analyzer, then generates a syntax tree and further generates database query opcodes, which are executed in the verifiable virtual database engine. The polynomial commitment B-tree is an improvement on the B+ tree, an index structure for storing data used to index data. It maintains complex relationships between pages, facilitating quick retrieval of required data. This invention guarantees the integrity proof of accessing all data during the query through polynomial commitments, quickly checks data consistency without downloading the entire database, and provides binding for subsequent query proofs through commitments. The memory proof protocol generator is responsible for generating proofs. It transforms the received memory correctness check records onto a finite field and can quickly verify the proofs based on multivariate polynomial extensions. The proofs and query results are sent to the client together. The client can then rely on the query results, polynomial commitments, and query proofs to verify the integrity of the database and the correctness of the query.

[0041] This invention does not require converting database queries into arithmetic circuits for proof; its core is to utilize a verifiable virtual database engine to transform the query process from a syntax tree into a deterministic state transition relation, which is then executed by a virtual machine. The virtual machine's memory changes are retained as a log for correctness checks. If a series of memory reads is correct and conforms to the database engine's operating rules, then the memory execution is correct. During virtual machine operation, an execution log is maintained. This log is a triple of (address, data, timestamp / counter), stored in two sets: read and write. As shown in Figure 2, when the virtual machine accesses data at an address, it first generates a log entry with the data and time / counter stored at the current address and places it in the read set. After reading / modifying the data at this address, it generates a log entry with the address, data, and the new time / counter and places it in the write set. Finally, the initial states of all addresses are placed in the write set, and the final states are placed in the read set. After the virtual machine finishes running, the verifier can check whether the read and write sets are the same set, thus verifying whether the virtual machine was executed correctly.

[0042] In this scheme, determining whether two sets are identical element by element is a complex task. This invention uses a random value provided by the client (verifier) ​​to merge the address, data, and time / count as a single number, and merges each log entry in the read set using another random number. The verifier only needs to verify the result and verifies the log integrity through polynomial expansion. Since the database stores different data types, this invention maps different data types to a finite field. In designing the verifiable virtual database engine, this invention partitions memory into regular memory, sorting memory, aggregation result memory, read-only memory, and output memory, maximizing memory reuse to reduce the number of logs generated, thereby optimizing proof generation efficiency.

[0043] Since the verification mechanism of this invention does not rely on hardware trusted memory, this invention relies on the memory correctness interactive verification framework shown in Figure 3, which is generated in the memory proof protocol generator, and consists of the following steps:

[0044] The prover sends the initial and final state commitments of memory during the database query process to the verifier. These commitments need to be homomorphic so that the verifier can verify the read and write sets sent afterward based on the commitments.

[0045] The validator sends a random number as a challenge value. The prover uses this challenge value to merge the triples in the log into a single value and sends it back to the validator. The new commitment generated from this result matches the commitment previously received by the validator with the challenge value, thus allowing the validator to believe that the received read / write set is correct and valid.

[0046] The prover sends the read and write sets to the verifier, and as the database size increases, the generated logs also become larger. In order to reduce the computational cost for the verifier, the prover sends the read and write sets as intermediate results of the binary tree product as a multivariate polynomial extension, thereby changing the product calculation process that the verifier needs to calculate into a multivariate polynomial challenge result verification problem composed of the set and its intermediate results.

[0047] The validator sends a new random number as a challenge for a multivariate polynomial extension.

[0048] The prover sends the challenge result to the verifier as a multivariate polynomial consisting of a set and its intermediate results. Since colliding a higher-order polynomial is a mathematically difficult problem, the verifier can trust that the challenge result is correct.

[0049] The verifier completes all verifications. If the verifications are correct, the query results can be trusted; if they are incorrect, the query results cannot be fully trusted.

[0050] This scheme optimizes the B+ tree, commonly used for storing indexes in databases, by combining polynomial commitments with the index structure to verify the database. The invention uses the hash value of each leaf node's content and the commitment results of child nodes stored in non-leaf nodes as coefficients of the polynomial to generate KZG commitments for each child node of a non-leaf node, which are then stored in the non-leaf node. Simple query processes do not change the results in the polynomial commitment B-tree. However, during database operations such as CRUD operations, the hash values ​​of leaf nodes change, and even due to significant changes caused by the self-balancing structure of the B-tree, the polynomial commitments are regenerated based on the hash values ​​generated from the leaf node content. The verifier can also be called the verifier, and the prover can also be called the prover. Taking the insertion and splitting algorithm in Figure 4 as an example, the polynomial commitment generation logic of this invention is introduced as follows: Find the position of the leaf node to be inserted. Check whether the target leaf node has reached its capacity limit, and decide whether to insert directly or split based on the check result. When the node is not full, directly update the hash value of the current node; when the node is full, split the node, generate the hash values ​​of the two nodes, and generate a new KZG commitment. Since the content of the child node has changed, the parent node is retrieved and recursively modified until the root node is modified.

[0051] The method for deleting nodes is similar to that for insertion, with the main difference being the handling of B+ tree balancing, which will not be elaborated upon here. Hash values ​​are used because B+ trees serve as a unified index structure for data management, while different types of representations and memory usage vary in actual storage, making management inconvenient. KZG commitments from leaf nodes to the root node can be opened at the same point, meaning that all KZG commitments traversing all nodes in all data queries can be merged to generate a fixed-size KZG commitment for the verifier. The memory proof protocol generator will complete the merging of relevant commitments and will also generate a log for the generated hash value and KZG commitment using memory correctness methods, merging it with the previous read / write set, thus binding the two proof methods.

[0052] The main technical points of this solution include: providing a verifiable database verification scheme, designing a verifiable virtual database engine, constructing an interactive, database-friendly memory correctness checking protocol, and proving that the query was executed correctly through the memory read / write log set in the query. A polynomial expansion challenge verification scheme is adopted, distributing the verifier's computational burden to the prover, greatly accelerating the verifier's verification time. The B+ tree index in the database is improved to a polynomial commitment B-tree, providing a solution for data integrity verification in the database. An insertion, deletion, and update algorithm for the polynomial commitment B-tree is designed, and polynomial commitments are merged and sent, and polynomial commitments are bound to the memory correctness checking protocol.

[0053] This solution offers the following advantages: The verifiable database of this invention fulfills the complete query and data processing requirements of a relational database, transforming data authentication into a protocol, thereby enabling verification of various relational implementations and data integrity. Compared to verifiable databases based on interactive proof systems, this invention eliminates the need to convert the entire database query process into an arithmetic circuit for verification. Since the inputs and outputs of arithmetic circuits require additional generation and are unique, they are impractical for real-world applications. This invention provides a database-friendly proof method that proves the query process without generating circuits. Furthermore, this invention places extremely low computational demands on client-side verification. Compared to proof systems based on secure multi-party computation, this invention can provide verification for any third party. By transferring the computational burden to the server-side prover, this invention allows clients lacking powerful computing capabilities and consistent stability to complete queries and verifications.

[0054] Specifically, this application provides a database verification method based on multinomial commitment and memory correctness detection. The method is applied to the proof side, as shown in Figure 5, and includes:

[0055] Step 102: Determine the initial and final states of the data in the database during the data processing process, add the initial state to the read set in memory, and add the final state to the write set in memory. The read set is used to store log records generated when accessing data in the database, and the write set is used to store log records generated when reading or modifying data in the database.

[0056] Step 104: Generate state commitments for the initial and final states and send them to the verifier.

[0057] Step 106: Receive the first challenge value from the verifier, and process the log records in the read set and write set in memory based on the first challenge value to obtain the log processing result and feed it back to the verifier.

[0058] Step 108: Send the read set and write set to the verifier. The verifier verifies the correctness of the read set and write set based on the state commitment and log processing results to determine the correctness of the memory verification.

[0059] The proposed solution can be applied to database-based data processing scenarios. It can perform corresponding operations in the database based on user data processing requests and provide proof of memory correctness and execution correctness of the data processing process, thereby determining the reliability of the data processing results. Specifically, the verifier initiates a data processing request to the proviser. The proviser receives the request, indexes the database index tree, determines the target address of the target data corresponding to the data processing request, executes the corresponding data processing operations, and returns the data processing result to the verifier. Furthermore, the proving party determines the initial and final states of the data in the database during data processing, adding the initial state to the read set in memory and the final state to the write set in memory. The read set stores log records generated when accessing data in the database, while the write set stores log records generated when reading or modifying data in the database. The proving party generates state commitments for the initial and final states and sends them to the verifier. The proving party receives the verifier's first challenge value and processes the log records in the read and write sets in memory based on the first challenge value, obtaining the log processing results and feeding them back to the verifier. The proving party sends the read and write sets to the verifier, who verifies the correctness of the read and write sets based on the state commitments and the log processing results to determine the correctness of the memory verification. Additionally, the proving party can generate an index polynomial and a polynomial commitment based on the relevant nodes in the database index tree for the data processing request, sending this to the verifier. The verifier verifies the execution of the data processing process based on the polynomial commitments and the index polynomials. If both memory correctness and execution correctness verifications pass, the verifier confirms that the data processing process is correct and reliable.

[0060] In this scheme, the verifier can initiate a data processing request to the proviser, who then performs the corresponding operation and returns the data processing result. Specifically, as an optional embodiment, the database data processing process includes: obtaining a data processing request and indexing the database index tree according to the request to determine the target address. The database index tree includes a first node and a second node. The first node stores key-value information, and the second node stores data records. The data processing request includes data query, data addition, data deletion, data modification, and data reading. The verifier then determines the target data at the target address and executes the database operation corresponding to the data processing request to return the data processing result to the verifier.

[0061] During data processing, memory can record data based on the address, content, and time / counter of the processed data to generate log records and store them in the read and write sets. Specifically, as an optional embodiment, the step of generating log records includes: when accessing target data at a target address in the database, generating a log record based on the target address, target data, and timestamp, or the target address, target data, and counter, and storing it in the read set; when reading or modifying target data at a target address in the database, generating a log record based on the target address, target data, and timestamp, or the target address, target data, and counter, and storing it in the write set.

[0062] Sending the entire read and write sets directly would require the verifier to process an excessive amount of data. Therefore, this solution obtains a second challenge value and performs corresponding transformations based on the second challenge value and the read and write sets to obtain a polynomial expansion result, which is then fed back to the verifier for verification. Specifically, as an optional embodiment, sending the read and write sets to the verifier includes: receiving the second challenge value, processing the read and write sets based on the second challenge value to obtain a polynomial expansion result, and sending this result to the verifier. The verifier then verifies the correctness of the polynomial expansion result based on the state commitment and log processing results to determine the correctness of the memory verification.

[0063] This solution can not only verify memory correctness but also prove the execution process of data indexing. Specifically, as an optional embodiment, the method further includes: generating an index polynomial and a polynomial commitment based on the relevant nodes in the database index tree during data processing requests; sending the polynomial commitment and the index polynomial to the verifier, who then verifies the index polynomial based on the polynomial commitment. The polynomial can be used to prove the relevant nodes in the database index tree, thereby proving the corresponding data situation and the data involved in the verifier's processing. This solution can pre-configure node commitments for the first node and generate hash values ​​for the second node. Specifically, as an optional embodiment, the first and second nodes of the database index tree correspond to the polynomial; the first node contains a node commitment, and the second node contains a hash value of the node content. Generating the index polynomial and generating the polynomial commitment includes: determining a target polynomial based on the first and second nodes in the relevant nodes; determining the coefficients of the target polynomial based on the node commitment of the first node and the hash value of the second node in the relevant nodes to form the index polynomial; and aggregating the node commitments of the first node in the relevant nodes to form the polynomial commitment.

[0064] When processing data in the database, this solution can update the corresponding database index tree. Specifically, as an optional embodiment, the steps of updating the database index tree include: when inserting a second node, determining the node position of the second node and checking whether the capacity of the node position has reached the capacity limit; if so, splitting the node to generate hash values ​​of two second nodes; if not, updating the hash value of the node at the node position; determining the first node related to the second node and updating the node commitment of the first node.

[0065] In cases where some data is read-only, proof to the verifier may not be required. Therefore, this solution can divide the memory into multiple regions and execute different data processing requests, thereby reducing the amount of data that the read and write sets need to process. Specifically, as an optional embodiment, the memory is divided into a first memory and a second memory. The first memory is used to process data processing requests for reading data, and the second memory is used to process data processing requests corresponding to data querying, data addition, data deletion, and data modification. Determining the initial and final states of the data in the database during the data processing process, and adding the initial state to the read set in memory and the final state to the write set in memory, includes: when the second memory processes the data processing request, determining the initial and final states of the data in the database during the data processing process, adding the initial state to the read set in memory, and adding the final state to the write set in memory.

[0066] Based on the above embodiments, this application also provides a database verification method based on multinomial commitment and memory correctness detection. The method is applied to the verification side, as shown in Figure 6, and includes:

[0067] Step 202: Generate a data processing request and send it to the prover. The prover processes the data based on the data processing request and provides feedback on the data processing results. During the data processing, the prover determines the initial and final states of the data in the database and adds the initial state to the read set in memory and the final state to the write set in memory. The read set is used to store log records generated when accessing data in the database, and the write set is used to store log records generated when reading or modifying data in the database. The prover generates state commitments for the initial and final states and sends them to the verifier.

[0068] Step 204: Receive the data processing results and state commitment sent by the prover, and generate a first challenge value to send to the prover. The prover processes the log records in the read set and write set in memory based on the first challenge value, obtains the log processing results, and feeds them back to the verifier. The prover sends the read set and write set to the verifier.

[0069] Step 206: Receive the log processing results, read set, and write set, and verify the correctness of the read set and write set based on the state commitment and log processing results to determine the correctness of the memory verification and the correctness of the data processing results.

[0070] The implementation methods of this application are similar to those of the above embodiments. For specific implementation methods, please refer to the specific implementation methods of the above embodiments, which will not be repeated here.

[0071] The proposed solution can be applied to database-based data processing scenarios. It can perform corresponding operations in the database based on user data processing requests and provide proof of memory correctness and execution correctness of the data processing process, thereby determining the reliability of the data processing results. Specifically, the verifier initiates a data processing request to the proviser. The proviser receives the request, indexes the database index tree, determines the target address of the target data corresponding to the data processing request, executes the corresponding data processing operations, and returns the data processing result to the verifier. Furthermore, the proving party determines the initial and final states of the data in the database during data processing, adding the initial state to the read set in memory and the final state to the write set in memory. The read set stores log records generated when accessing data in the database, while the write set stores log records generated when reading or modifying data in the database. The proving party generates state commitments for the initial and final states and sends them to the verifier. The proving party receives the verifier's first challenge value and processes the log records in the read and write sets in memory based on the first challenge value, obtaining the log processing results and feeding them back to the verifier. The proving party sends the read and write sets to the verifier, who verifies the correctness of the read and write sets based on the state commitments and the log processing results to determine the correctness of the memory verification. Additionally, the proving party can generate an index polynomial and a polynomial commitment based on the relevant nodes in the database index tree for the data processing request, sending this to the verifier. The verifier verifies the execution of the data processing process based on the polynomial commitments and the index polynomials. If both memory correctness and execution correctness verifications pass, the verifier confirms that the data processing process is correct and reliable.

[0072] Based on the above embodiments, this application also provides a database verification device based on multinomial commitment and memory correctness detection. The device is applied on the proving side, as shown in Figure 7. The device includes:

[0073] The data state processing module 302 is used to determine the initial state and final state of data in the database during the data processing process, and add the initial state to the read set in memory and add the final state to the write set in memory. The read set is used to store log records generated when accessing data in the database, and the write set is used to store log records generated when reading or modifying data in the database.

[0074] The state commitment processing module 304 is used to generate state commitments for the initial state and the final state, and send them to the verifier.

[0075] The log processing module 306 is used to receive the first challenge value from the verifier, process the log records in the read set and write set in memory based on the first challenge value, obtain the log processing result, and feed it back to the verifier.

[0076] The read and write set sending module 308 is used to send the read set and write set to the verifier. The verifier verifies the correctness of the read set and write set based on the state commitment and log processing results to determine the correctness of the memory verification.

[0077] The implementation methods of this application are similar to those of the above embodiments. For specific implementation methods, please refer to the specific implementation methods of the above embodiments, which will not be repeated here.

[0078] The proposed solution can be applied to database-based data processing scenarios. It can perform corresponding operations in the database based on user data processing requests and provide proof of memory correctness and execution correctness of the data processing process, thereby determining the reliability of the data processing results. Specifically, the verifier initiates a data processing request to the proviser. The proviser receives the request, indexes the database index tree, determines the target address of the target data corresponding to the data processing request, executes the corresponding data processing operations, and returns the data processing result to the verifier. Furthermore, the proving party determines the initial and final states of the data in the database during data processing, adding the initial state to the read set in memory and the final state to the write set in memory. The read set stores log records generated when accessing data in the database, while the write set stores log records generated when reading or modifying data in the database. The proving party generates state commitments for the initial and final states and sends them to the verifier. The proving party receives the verifier's first challenge value and processes the log records in the read and write sets in memory based on the first challenge value, obtaining the log processing results and feeding them back to the verifier. The proving party sends the read and write sets to the verifier, who verifies the correctness of the read and write sets based on the state commitments and the log processing results to determine the correctness of the memory verification. Additionally, the proving party can generate an index polynomial and a polynomial commitment based on the relevant nodes in the database index tree for the data processing request, sending this to the verifier. The verifier verifies the execution of the data processing process based on the polynomial commitments and the index polynomials. If both memory correctness and execution correctness verifications pass, the verifier confirms that the data processing process is correct and reliable.

[0079] It should be noted that the division of units and / or modules in the embodiments of this application is illustrative and only represents a logical functional division. In actual implementation, there may be other division methods. Furthermore, the functional units and / or modules in the various embodiments of this application can be integrated into one processing unit and / or module, or each unit and / or module can exist physically separately, or two or more units and / or modules can be integrated into one unit and / or module. The integrated units and / or modules described above can be implemented in hardware or as software functional units and / or modules.

[0080] If the integrated units and / or modules are implemented as software functional units and / or modules and sold or used as independent products, they can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0081] Furthermore, the data transmission apparatus and data transmission method provided in the above embodiments are based on the same application concept. Since the methods and apparatus solve problems in similar principles, the implementation of the apparatus and methods can refer to each other, and repeated parts will not be described again.

[0082] Figure 8 is a structural block diagram of a network device according to an exemplary embodiment.

[0083] As shown in Figure 8, the network device 1100 includes at least: a processor 1110, a memory 1120, and a transceiver 1130.

[0084] The transceiver 1130 is used to receive and send data under the control of the processor 1110.

[0085] In Figure 8, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1110 and memory represented by memory 1120. The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 1130 may be multiple elements, including transmitters and receivers, providing units and / or modules for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, and other transmission media.

[0086] The processor 1110 is responsible for managing the bus architecture and general processing, and the memory 1120 can store the data used by the processor 1110 when performing operations.

[0087] Optionally, the processor 1110 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor 1110 may also adopt a multi-core architecture. The processor 1110 and the memory 1120 may also be physically separated.

[0088] The processor 1110 calls the computer program stored in the memory 1120 to execute any of the cell wireless network temporary identifier allocation methods provided in the above embodiments of this application according to the obtained executable instructions.

[0089] Figure 9 is a structural block diagram of a user equipment according to an exemplary embodiment.

[0090] As shown in Figure 9, the user equipment 1300 includes at least: a processor 1310, a memory 1320, and a transceiver 1330.

[0091] The transceiver 1330 is used to receive and send data under the control of the processor 1310.

[0092] In Figure 9, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1310 and memory represented by memory 1320. The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 1330 may be multiple elements, including transmitters and receivers, providing units and / or modules for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. For different user equipment, user interface 1340 may also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.

[0093] The processor 1310 is responsible for managing the bus architecture and general processing, and the memory 1320 can store the data used by the processor 1310 when performing operations.

[0094] Optionally, the processor 1310 can be a CPU (Central Processing Unit), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a CPLD (Complex Programmable Logic Device). The processor 1310 can also adopt a multi-core architecture. The processor 1310 and the memory 1320 can also be physically separated.

[0095] The processor 1310 calls the computer program stored in the memory 1320 to execute any of the cell wireless network temporary identifier allocation methods provided in the above embodiments of this application according to the obtained executable instructions.

[0096] It should be noted that the apparatus provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0097] Furthermore, this application provides a storage medium storing a computer program, which, when executed by a processor, implements the data transmission methods described in the above embodiments. The storage medium can be any available medium or data storage device accessible to the processor, including but not limited to magnetic storage (e.g., floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical storage (e.g., CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (e.g., ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs)).

[0098] This application provides a program product, such as an FPGA chip or a DSP chip, which includes executable instructions stored in a storage medium. A processor reads the executable instructions from the storage medium, causing the processor to execute the executable instructions to implement the data transmission methods described in the above embodiments.

[0099] The proposed solution can be applied to database-based data processing scenarios. It can perform corresponding operations in the database based on user data processing requests and provide proof of memory correctness and execution correctness of the data processing process, thereby determining the reliability of the data processing results. Specifically, the verifier initiates a data processing request to the proviser. The proviser receives the request, indexes the database index tree, determines the target address of the target data corresponding to the data processing request, executes the corresponding data processing operations, and returns the data processing result to the verifier. Furthermore, the proving party determines the initial and final states of the data in the database during data processing, adding the initial state to the read set in memory and the final state to the write set in memory. The read set stores log records generated when accessing data in the database, while the write set stores log records generated when reading or modifying data in the database. The proving party generates state commitments for the initial and final states and sends them to the verifier. The proving party receives the verifier's first challenge value and processes the log records in the read and write sets in memory based on the first challenge value, obtaining the log processing results and feeding them back to the verifier. The proving party sends the read and write sets to the verifier, who verifies the correctness of the read and write sets based on the state commitments and the log processing results to determine the correctness of the memory verification. Additionally, the proving party can generate an index polynomial and a polynomial commitment based on the relevant nodes in the database index tree for the data processing request, sending this to the verifier. The verifier verifies the execution of the data processing process based on the polynomial commitments and the index polynomials. If both memory correctness and execution correctness verifications pass, the verifier confirms that the data processing process is correct and reliable.

[0100] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0101] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.

[0102] These processor-executable instructions may also be stored in a processor-readable memory that can instruct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the processor-readable memory produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.

[0103] These processor-executable instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.

[0104] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0105] The above description is only a partial embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be included in the protection scope of this application.

Claims

1. A database verification method based on multinomial commitment and memory correctness detection, wherein the method is applied to the proof side, characterized in that, The method includes: Determine the initial and final states of data in the database during data processing, add the initial state to the read set in memory, and add the final state to the write set in memory. The read set is used to store log records generated when accessing data in the database, and the write set is used to store log records generated when reading or modifying data in the database. Generate state commitments for the initial and final states and send them to the verifier; The system receives the first challenge value from the verifier and processes the log records in the read and write sets in memory based on the first challenge value, obtains the log processing results, and feeds them back to the verifier. The read set and write set are sent to the verifier, who verifies the correctness of the read set and write set based on the state commitment and log processing results to determine the correctness of the memory verification.

2. The method as described in claim 1, characterized in that, The data processing procedures of a database include: A data processing request is obtained, and an index is performed on the database index tree based on the data processing request to determine the target address. The database index tree includes a first node and a second node. The first node is used to store key-value information, and the second node is used to store data records. The data processing request includes data query, data addition, data deletion, data modification, and data reading. Determine the target data at the target address and execute the database operation corresponding to the data processing request to return the data processing result to the verifier.

3. The method as described in claim 2, characterized in that, The steps for generating log records include: When accessing target data at a target address in the database, a log record is generated and stored in the read set based on the target address, target data, and timestamp, or the target address, target data, and counter. When reading or modifying target data at a target address in the database, a log record is generated and stored in the write collection based on the target address, target data, and timestamp, or the target address, target data, and counter.

4. The method as described in claim 3, characterized in that, Sending the read set and write set to the verifier includes: The second challenge value is received, and the read and write sets are processed based on the second challenge value to obtain the polynomial expansion result, which is then sent to the verifier. The verifier verifies the correctness of the polynomial expansion result based on the state commitment and log processing results to determine the correctness of the memory verification.

5. The method as described in claim 2, characterized in that, The method further includes: Based on the relevant nodes in the database index tree when the data processing request is indexed, an index polynomial is generated, and a polynomial commitment is generated. The polynomial commitment and the index polynomial are sent to the verifier, who then verifies the index polynomial based on the polynomial commitment.

6. The method as described in claim 5, characterized in that, The first and second nodes of the database index tree correspond to a polynomial. The first node contains the node commitment, and the second node contains the hash value of the node content. The generation of the indexed polynomial and the generation of the polynomial commitment include: Determine the target polynomial based on the first and second nodes among the relevant nodes; Based on the node commitment of the first node and the hash value of the second node in the relevant nodes, the coefficients of the target polynomial are determined to form the index polynomial; Aggregate the node commitments of the first node among the relevant nodes to form a multinomial commitment.

7. The method as described in claim 6, characterized in that, The steps to update the database index tree include: When inserting the second node, determine the node position of the second node and check whether the capacity of the node position has reached the capacity limit; If yes, split the node and generate two second node hash values; if no, update the hash value of the node at the node's position. Identify the first node related to the second node and update the node commitments of the first node.

8. The method as described in claim 2, characterized in that, The memory is divided into a first memory and a second memory. The first memory is used to process data processing requests for data reading, and the second memory is used to process data processing requests for data querying, data adding, data deleting, and data modifying. The step of determining the initial and final states of data in the database during data processing, and adding the initial state to the read set in memory and the final state to the write set in memory, includes: When processing data processing requests in the second memory, the initial and final states of the data in the database during the data processing process are determined, and the initial state is added to the read set in memory, while the final state is added to the write set in memory.

9. A database verification method based on multinomial commitment and memory correctness detection, wherein the method is applied in the verification process, characterized in that, The method includes: A data processing request is generated and sent to the proving party. The proving party processes the data based on the data processing request and provides feedback on the data processing results. During the data processing, the proving party determines the initial and final states of the data in the database and adds the initial state to the read set in memory and the final state to the write set in memory. The read set is used to store log records generated when accessing data in the database, and the write set is used to store log records generated when reading or modifying data in the database. The proving party generates state commitments for the initial and final states and sends them to the validating party. The system receives the data processing results and state commitments sent by the proving party, generates a first challenge value, and sends it to the proving party. The proving party processes the log records in the read and write sets in memory based on the first challenge value, obtains the log processing results, and feeds them back to the validator. The proving party then sends the read and write sets to the validator. Receive log processing results, read sets, and write sets, and verify the correctness of read sets and write sets based on state commitments and log processing results to determine the correctness of memory verification, thereby determining the correctness of data processing results.

10. A database verification device based on multinomial commitment and memory correctness detection, the device being used on the proving side, characterized in that, The device includes: The data state processing module is used to determine the initial and final states of data in the database during the data processing process, and add the initial state to the read set in memory and the final state to the write set in memory. The read set is used to store log records generated when accessing data in the database, and the write set is used to store log records generated when reading or modifying data in the database. The state commitment processing module is used to generate state commitments for the initial and final states and send them to the verifier. The log processing module is used to receive the first challenge value from the verifier, process the log records in the read set and write set in memory based on the first challenge value, obtain the log processing result and feed it back to the verifier; The read and write set sending module is used to send the read set and write set to the verifier. The verifier verifies the correctness of the read set and write set based on the state commitment and log processing results to determine the correctness of the memory verification.