US2023388276A1PendingUtilityA1

Blockchain-based anonymous transfers zero-knowledge proofs

Assignee: TOPOSWARE INCPriority: Jul 10, 2020Filed: Aug 11, 2023Published: Nov 30, 2023
Est. expiryJul 10, 2040(~13.9 yrs left)· nominal 20-yr term from priority
H04L 63/0421G06F 16/2379H04L 9/30H04L 9/3218H04L 9/0643H04L 9/3239H04L 2209/42H04L 2209/56H04L 9/50
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Disclosed is a mechanism for performing an anonymous transfer using a blockchain. A sender's device generates a commitment based on a serial number of a zero-knowledge token and a value of the zero-knowledge token. Moreover, the sender's device generates a range proof and a balance proof for the commitment. The range proof verifies that the value of the zero-knowledge token is within a preset range. The balance proof verifies that the value of a set of input tokens is greater than or equal to the value of the zero-knowledge token. The sender's device sends a conversion request to the blockchain network. The conversion request consumes the set of input tokens and generates the zero-knowledge token. The conversion request includes the generated commitment, the generated range proof, and the generated balance proof.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method comprising:
 generating a commitment based on a serial number of a zero-knowledge token, and a value of the zero-knowledge token, wherein generating the commitment comprises:
 generating a private key and public key pair, and 
 generating the serial number for the zero-knowledge token based on the public key; 
   generating a range proof for the commitment, the range proof for verifying that the value of the zero-knowledge token is within a preset range;   generating a balance proof, the balance proof for verifying that a value of a set of input tokens is greater than or equal to the value of the zero-knowledge token;   transmitting a conversion request, the conversion request for consuming the set of input tokens and for generating the zero-knowledge token, the conversion request including the generated commitment, the generated range proof, and the generated balance proof; and   transmitting a spending request for spending the zero-knowledge token, the spending request identifying the serial number of the zero-knowledge token and a set of output tokens.   
     
     
         2 . The computer-implemented method of  claim 1 , further comprising:
 generating a knowledge proof, the knowledge proof for verifying knowledge of a set of parameters for generating the commitment, and   wherein the conversion request further includes the generated knowledge proof.   
     
     
         3 . The computer-implemented method of  claim 2 , wherein at least one of the range proof, the balance proof, and the knowledge proof are generated using a zero-knowledge proof protocol. 
     
     
         4 . The computer-implemented method of  claim 1 , wherein generating the commitment comprises:
 receiving, from a recipient, a seed value;   generating a random value; and   generating the commitment based on the seed value, the random value, and the value of the zero-knowledge token.   
     
     
         5 . The computer-implemented method of  claim 1 , wherein transmitting the spending request comprises:
 generating a zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments, the zero-knowledge proof based on the serial number of the zero-knowledge token used to generate the commitment.   
     
     
         6 . The computer-implemented method of  claim 5 , wherein the zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments is a 1-out-of-N proof. 
     
     
         7 . The computer-implemented method of  claim 1 , wherein transmitting the spending request comprises:
 generating a second balance proof, the second balance proof for verifying that a value of a set of input tokens of the spending request is greater than or equal to a value of the set of output tokens of the spending request.   
     
     
         8 . The computer-implemented method of  claim 1 , wherein the spending request is signed using the private key corresponding to the public key used for generating the serial number of the zero-knowledge token. 
     
     
         9 . A non-transitory computer readable storage medium configured to store code comprising instructions, the instructions, when executed by one or more processors, cause the one or more processors to:
 generate a commitment based on a serial number of a zero-knowledge token, and a value of the zero-knowledge token, wherein generating the commitment comprises:
 generating a private key and public key pair, and 
 generating the serial number for the zero-knowledge token based on the public key; 
   generate a range proof for the commitment, the range proof for verifying that the value of the zero-knowledge token is within a preset range;   generate a balance proof, the balance proof for verifying that a value of a set of input tokens is greater than or equal to the value of the zero-knowledge token; and   transmit a conversion request, the conversion request for consuming the set of input tokens and for generating the zero-knowledge token, the conversion request including the generated commitment, the generated range proof, and the generated balance proof; and   transmit a spending request for spending the zero-knowledge token, the spending request identifying the serial number of the zero-knowledge token and a set of output tokens.   
     
     
         10 . The non-transitory computer readable storage medium of  claim 9 , wherein the instructions, when executed, further cause causes the processor to:
 generate a knowledge proof, the knowledge proof for verifying knowledge of a set of parameters for generating the commitment, wherein the conversion request further includes the generated knowledge proof.   
     
     
         11 . The non-transitory computer readable storage medium of  claim 10 , wherein at least one of the range proof, the balance proof, and the knowledge proof are generated using a zero-knowledge proof protocol. 
     
     
         12 . The non-transitory computer readable storage medium of  claim 9 , wherein the instructions for generating the commitment comprises further instructions to:
 receive, from a recipient, a seed value;   generate a random value; and   generate the commitment based on the seed value, the random value, and the value of the zero-knowledge token.   
     
     
         13 . The non-transitory computer readable storage medium of  claim 9 , wherein the instructions to transmit the spending request comprises further instructions to:
 generate a zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments, the zero-knowledge proof based on the serial number of the zero-knowledge token used to generate the commitment.   
     
     
         14 . The non-transitory computer readable storage medium of  claim 13 , wherein the zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments is a 1-out-of-N proof. 
     
     
         15 . The non-transitory computer readable storage medium of  claim 9 , wherein the instructions to transmit the spending request comprises further instructions to:
 generate a second balance proof, the second balance proof for verifying that a value of a set of input tokens of the spending request is greater than or equal to a value of the set of output tokens of the spending request.   
     
     
         16 . The non-transitory computer readable storage medium of  claim 9 , wherein the instructions, when executed, further cause the one or more processors to confirm the spending request is signed using the private key corresponding to the public key used to generate the serial number of the zero-knowledge token. 
     
     
         17 . A system comprising:
 one or more processors; and   memory configured to store code comprising instructions, wherein the instructions, when executed by the one or more processors, cause the one or more processors to:
 generate a commitment based on a serial number of a zero-knowledge token, and a value of the zero-knowledge token, wherein generating the commitment comprises:
 generating a private key and public key pair, and 
 generating the serial number for the zero-knowledge token based on the public key; 
 
 generate a range proof for the commitment, the range proof for verifying that the value of the zero-knowledge token is within a preset range; 
 generate a balance proof, the balance proof for verifying that a value of a set of input tokens is greater than or equal to the value of the zero-knowledge token; and 
 transmit a conversion request, the conversion request for consuming the set of input tokens and for generating the zero-knowledge token, the conversion request including the generated commitment, the generated range proof, and the generated balance proof; and 
 transmit a spending request for spending the zero-knowledge token, the spending request identifying the serial number of the zero-knowledge token and a set of output tokens. 
   
     
     
         18 . The system of  claim 17 , wherein the instructions, when executed, further cause causes the processor to:
 generate a knowledge proof, the knowledge proof for verifying knowledge of a set of parameters for generating the commitment, wherein the conversion request further includes the generated knowledge proof.   
     
     
         19 . The system of  claim 18 , wherein at least one of the range proof, the balance proof, and the knowledge proof are generated using a zero-knowledge proof protocol. 
     
     
         20 . The system of  claim 17 , wherein the instructions, when executed, further cause the one or more processors to confirm the spending request is signed using the private key corresponding to the public key used to generate the serial number of the zero-knowledge token.

Join the waitlist — get patent alerts

Track US2023388276A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.