Zero-knowledge proof method and electronic device

US11550952B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-11550952-B1
Application numberUS-202217751646-A
CountryUS
Kind codeB1
Filing dateMay 23, 2022
Priority dateSep 22, 2021
Publication dateJan 10, 2023
Grant dateJan 10, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Disclosed is a method and an apparatus a zero-knowledge proof and an electronic device. That method comprise the following steps: selecting a data processing relationship, and processing private data and public data to obtain a calculation result; respectively committing the private data and the calculation result according to a commitment parameter to obtain a first commitment value and a second commitment value, wherein the commitment parameter is generated by a trusted third party; generating a non-interactive zero-knowledge proof according to the data processing relationship; wherein the commitment parameter, the first commitment value and the second commitment value are used by a verifier to verify the non-interactive zero-knowledge proof. The present disclosure solves the technical problem that bilinear pairing cannot be used in the scenario where bilinear pairing cannot be used in related technologies.

First claim

Opening claim text (preview).

What is claimed is: 1. An electronic device, comprising: one or more processors; and a memory for storing one or more programs; wherein when the one or more programs are executed by the one or more processors, the one or more processors is caused to realize a zero-knowledge proof method applied to a proof sender, comprising the following steps of: selecting a data processing relationship, and processing private data and public data to obtain a calculation result; committing the private data and the calculation result, respectively, according to a commitment parameter to obtain a first commitment value and a second commitment value, wherein the commitment parameter is generated by a trusted third party; and generating a non-interactive zero-knowledge proof according to the data processing relationship to enable a verifier to verify the non-interactive zero-knowledge proof according to the commitment parameter, the public data, the first commitment value and the second commitment value; wherein the step of selecting a data processing relationship, and processing private data and public data to obtain a calculation result comprises: selecting one relationship from two data processing relationships, namely a linear relationship and a generalized multiplication relationship, as the data processing relationship; wherein when the data processing relationship is a linear relationship, the private data is a i , the public data is b i , a number of data of the private data and the public data is n, and the calculation result is c=Σ n i=1 a i b i ; and wherein when a generalized multiplication relation is selected, the private data is d i , e i , the public data is x i , y i , the number of data of the private data d i and the public data x i is n 1 , the number of data of the private data e i and the public data y i , is n 2 , and the calculation result is z=Σ n1 i=1 d i x i ·Σ n2 i=1 e i y i ; the step of generating a non-interactive zero-knowledge proof according to the data processing relationship comprises: generating an offset term according to the data processing relationship; inputting the commitment parameter, the first commitment value, the second commitment value and the offset term into a random oracle machine to generate a challenge value according to the data processing relationship; obtaining a response value by calculation according to the private data, the public data and the challenge value; and generating the non-interactive zero-knowledge proof according to the offset term and the response value. 2. The method according to claim 1 , further comprising: sending the first commitment value, the second commitment value and the non-interactive zero-knowledge proof to a public data storage system, wherein the commitment parameter is stored in the public data storage system by the trusted third party, and the public data is stored in the public data storage system. 3. The method according to claim 1 , wherein the step of the verifier verifying the non-interactive zero-knowledge proof according to the commitment parameter, the public data, the first commitment value and the second commitment value comprises: inputting the commitment parameter, the first commitment value, the second commitment value and the offset term into the random oracle machine to output the challenge value; and verifying the non-interactive zero-knowledge proof according to the public data, the first commitment value, the second commitment value and the challenge value. 4. An electronic device, comprising: one or more processors; and a memory for storing one or more programs; wherein when the one or more programs are executed by the one or more processors, the one or more processors is caused to realize a zero-knowledge proof method applied to a verifier, comprising the following steps of: acquiring a commitment parameter, public data, a first commitment value, a second commitment value and a non-interactive zero-knowledge proof, wherein the commitment parameter is generated by a trusted third party; the first commitment value and the second commitment value are obtained by selecting, by a proof sender, a data processing relationship to process private data and public data to obtain a calculation result, and committing the private data and the calculation result according to the commitment parameter, respectively; the non-interactive zero-knowledge proof is generated by the proof sender according to the data processing relationship; and verifying the non-interactive zero-knowledge proof according to the commitment parameter, the public data, the first commitment value and the second commitment value; wherein the step of selecting a data processing relationship to process private data and public data to obtain a calculation result comprises: selecting one relationship from two data processing relationships, namely a linear relationship and a generalized multiplication relationship, as the data proc wherein when the data processing relationship is a linear relationship, the private data is a i , the public data is b i , a number of data of the private data and the public data is n, and the calculation result is c=Σ n i=1 a i b i ; and wherein when a generalized multiplication relation is selected, the private data is d i , e i , the public data is x i , y i , the number of data of the private data d i and the public data x i is n 1 , the number of data of the private data e i and the public data y i , is n 2 , and the calculation result is z=Σ n1 i=1 d i x i ·Σ n2 i=1 e i y i , the step of generating a non-interactive zero-knowledge proof according to the data processing relationship comprises: generating an offset term according to the data processing relationship; inputting the commitment parameter, the first commitment value, the second commitment value and the offset term into a random oracle machine to generate a challenge value according to the data processing relationship; obtaining a response value by calculation according to the private data, the public data and the challenge value; and generating the non-interactive zero-knowledge proof according to the offset term and the response value.

Assignees

Inventors

Classifications

  • using proof of knowledge, e.g. Fiat-Shamir, GQ, Schnorr, ornon-interactive zero-knowledge proofs · CPC title

  • Protecting personal data, e.g. for financial or medical purposes · CPC title

  • Multiplying only · CPC title

  • involving a third party or a trusted authority · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11550952B1 cover?
Disclosed is a method and an apparatus a zero-knowledge proof and an electronic device. That method comprise the following steps: selecting a data processing relationship, and processing private data and public data to obtain a calculation result; respectively committing the private data and the calculation result according to a commitment parameter to obtain a first commitment value and a seco…
Who is the assignee on this patent?
Univ Zhejiang, Hangzhou Abmatrix Tech Co Ltd
What technology area does this patent fall under?
Primary CPC classification G06F21/6245. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jan 10 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).