Blockchain-based anonymous transfers zero-knowledge proofs
Abstract
Disclosed is a mechanism for performing an anonymous transfer using a blockchain. A sender's device generates a commitment based on a serial number of a zero-knowledge token and a value of the zero-knowledge token. Moreover, the sender's device generates a range proof and a balance proof for the commitment. The range proof verifies that the value of the zero-knowledge token is within a preset range. The balance proof verifies that the value of a set of input tokens is greater than or equal to the value of the zero-knowledge token. The sender's device sends a conversion request to the blockchain network. The conversion request consumes the set of input tokens and generates the zero-knowledge token. The conversion request includes the generated commitment, the generated range proof, and the generated balance proof.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method comprising:
generating a commitment based on a serial number of a zero-knowledge token, and a value of the zero-knowledge token, wherein generating the commitment comprises:
generating a private key and public key pair, and
generating the serial number for the zero-knowledge token based on the public key;
generating a range proof for the commitment, the range proof for verifying that the value of the zero-knowledge token is within a preset range; generating a balance proof, the balance proof for verifying that a value of a set of input tokens is greater than or equal to the value of the zero-knowledge token; transmitting a conversion request, the conversion request for consuming the set of input tokens and for generating the zero-knowledge token, the conversion request including the generated commitment, the generated range proof, and the generated balance proof; and transmitting a spending request for spending the zero-knowledge token, the spending request identifying the serial number of the zero-knowledge token and a set of output tokens.
2 . The computer-implemented method of claim 1 , further comprising:
generating a knowledge proof, the knowledge proof for verifying knowledge of a set of parameters for generating the commitment, and wherein the conversion request further includes the generated knowledge proof.
3 . The computer-implemented method of claim 2 , wherein at least one of the range proof, the balance proof, and the knowledge proof are generated using a zero-knowledge proof protocol.
4 . The computer-implemented method of claim 1 , wherein generating the commitment comprises:
receiving, from a recipient, a seed value; generating a random value; and generating the commitment based on the seed value, the random value, and the value of the zero-knowledge token.
5 . The computer-implemented method of claim 1 , wherein transmitting the spending request comprises:
generating a zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments, the zero-knowledge proof based on the serial number of the zero-knowledge token used to generate the commitment.
6 . The computer-implemented method of claim 5 , wherein the zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments is a 1-out-of-N proof.
7 . The computer-implemented method of claim 1 , wherein transmitting the spending request comprises:
generating a second balance proof, the second balance proof for verifying that a value of a set of input tokens of the spending request is greater than or equal to a value of the set of output tokens of the spending request.
8 . The computer-implemented method of claim 1 , wherein the spending request is signed using the private key corresponding to the public key used for generating the serial number of the zero-knowledge token.
9 . A non-transitory computer readable storage medium configured to store code comprising instructions, the instructions, when executed by one or more processors, cause the one or more processors to:
generate a commitment based on a serial number of a zero-knowledge token, and a value of the zero-knowledge token, wherein generating the commitment comprises:
generating a private key and public key pair, and
generating the serial number for the zero-knowledge token based on the public key;
generate a range proof for the commitment, the range proof for verifying that the value of the zero-knowledge token is within a preset range; generate a balance proof, the balance proof for verifying that a value of a set of input tokens is greater than or equal to the value of the zero-knowledge token; and transmit a conversion request, the conversion request for consuming the set of input tokens and for generating the zero-knowledge token, the conversion request including the generated commitment, the generated range proof, and the generated balance proof; and transmit a spending request for spending the zero-knowledge token, the spending request identifying the serial number of the zero-knowledge token and a set of output tokens.
10 . The non-transitory computer readable storage medium of claim 9 , wherein the instructions, when executed, further cause causes the processor to:
generate a knowledge proof, the knowledge proof for verifying knowledge of a set of parameters for generating the commitment, wherein the conversion request further includes the generated knowledge proof.
11 . The non-transitory computer readable storage medium of claim 10 , wherein at least one of the range proof, the balance proof, and the knowledge proof are generated using a zero-knowledge proof protocol.
12 . The non-transitory computer readable storage medium of claim 9 , wherein the instructions for generating the commitment comprises further instructions to:
receive, from a recipient, a seed value; generate a random value; and generate the commitment based on the seed value, the random value, and the value of the zero-knowledge token.
13 . The non-transitory computer readable storage medium of claim 9 , wherein the instructions to transmit the spending request comprises further instructions to:
generate a zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments, the zero-knowledge proof based on the serial number of the zero-knowledge token used to generate the commitment.
14 . The non-transitory computer readable storage medium of claim 13 , wherein the zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments is a 1-out-of-N proof.
15 . The non-transitory computer readable storage medium of claim 9 , wherein the instructions to transmit the spending request comprises further instructions to:
generate a second balance proof, the second balance proof for verifying that a value of a set of input tokens of the spending request is greater than or equal to a value of the set of output tokens of the spending request.
16 . The non-transitory computer readable storage medium of claim 9 , wherein the instructions, when executed, further cause the one or more processors to confirm the spending request is signed using the private key corresponding to the public key used to generate the serial number of the zero-knowledge token.
17 . A system comprising:
one or more processors; and memory configured to store code comprising instructions, wherein the instructions, when executed by the one or more processors, cause the one or more processors to:
generate a commitment based on a serial number of a zero-knowledge token, and a value of the zero-knowledge token, wherein generating the commitment comprises:
generating a private key and public key pair, and
generating the serial number for the zero-knowledge token based on the public key;
generate a range proof for the commitment, the range proof for verifying that the value of the zero-knowledge token is within a preset range;
generate a balance proof, the balance proof for verifying that a value of a set of input tokens is greater than or equal to the value of the zero-knowledge token; and
transmit a conversion request, the conversion request for consuming the set of input tokens and for generating the zero-knowledge token, the conversion request including the generated commitment, the generated range proof, and the generated balance proof; and
transmit a spending request for spending the zero-knowledge token, the spending request identifying the serial number of the zero-knowledge token and a set of output tokens.
18 . The system of claim 17 , wherein the instructions, when executed, further cause causes the processor to:
generate a knowledge proof, the knowledge proof for verifying knowledge of a set of parameters for generating the commitment, wherein the conversion request further includes the generated knowledge proof.
19 . The system of claim 18 , wherein at least one of the range proof, the balance proof, and the knowledge proof are generated using a zero-knowledge proof protocol.
20 . The system of claim 17 , wherein the instructions, when executed, further cause the one or more processors to confirm the spending request is signed using the private key corresponding to the public key used to generate the serial number of the zero-knowledge token.Join the waitlist — get patent alerts
Track US2023388276A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.