WO2020041069A1

Methods and systems for enhancing privacy and efficiency on distributed ledger-based networks

Abstract

One or more embodiments described herein disclose methods and systems that are directed at providing enhanced privacy, efficiency and security to distributed ledger-based networks (DLNs) via the implementation of zero-knowledge proofs (ZKPs) in the DLNs. ZKPs allow participants of DLNs to make statements on the DLNs about some private information and to prove the truth of the information without having to necessarily reveal the private information publicly. As such, the disclosed methods and systems directed at the ZKP-enabled DLNs provide privacy and efficiency to participants of the DLNs while still allowing the DLNs to remain as consensus-based networks.

WO2020041069A1, drawing sheet 1
Sheet 1 of 4

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

2 claims: 1 independent, 1 dependent

  1. 1
    Claims1. A method, comprising:receiving a request that is configured to cause a transfer of a combined asset from a sender to a recipient, the combined asset including a first asset and a second asset, the first asset and the second asset represented on a distributed ledger-based network (DLN) by a first token commitment and a second token commitment, respectively;generating, upon receiving the request, a combined asset token that includes a combination of: 1) a first asset token obtained via an application of a first hashing function on a first identifying parameter of the first asset, and 2) a second asset token obtained via an application of a second hashing function on a second identifying parameter of the second asset;providing, by a provider and to a self-executing code segment on the DLN, a zero- knowledge proof (ZKP) that the provider has knowledge of an identity of: (1) the first asset token, the first token commitment obtained via an application of a third hashing function on the first asset token;
  2. 2
    (2) the second asset token, the second token commitment obtained via an application of a fourth hashing function on the second asset token; and/or (3) the combined asset token, a third token commitment representing the combined asset on the DLN obtained via an application of a fifth hashing function on the combined asset token; and receiving, upon verification of the ZKP by the self-executing code segment, a confirmation confirming an addition of the third token commitment onto a commitments data structure of the DLN. 2. The method of claim 1, wherein the combined asset token consists the first asset token and the second asset token. 3. The method of claim 1, wherein:the combined asset token consists the first asset token and the second asset token;and the ZKP includes the ZKP that the provider has knowledge of the combined asset token consisting the first asset token and the second asset token. 4. The method of claim 1, wherein the ZKP includes the ZKP that the provider has knowledge of an identity of: (a) a first identifier associated with the sender, (i) the first token commitment obtained via the application of the third hashing function on the first identifier;and/or (ii) the second token commitment obtained via the application of the fourth hashing function on the first identifier;and/or (b) a second identifier associated with the recipient, the third token commitment obtained via the application of the fifth hashing function on the second identifier. 5. The method of claim 1, wherein the ZKP includes the ZKP that the provider has knowledge of an identity of: (a) a first identifier associated with the sender, (i) the first token commitment obtained via the application of the third hashing function on the first identifier;and/or (ii) the second token commitment obtained via the application of the fourth hashing function on the first identifier, the first identifier including a public key of the sender on the DLN;and/or (b) a second identifier associated with the recipient, the third token commitment obtained via the application of the fifth hashing function on the second identifier, the second identifier including a public key of the recipient on the DLN. 6. The method of claim 1, wherein the ZKP includes the ZKP that the provider has knowledge of an identity of a first nullifier and/or a second nullifier, (a) the first nullifier obtained via an application of a sixth hashing function on a first cryptographic nonce and/or a secret identifier associated with the sender, and/or (b) the second nullifier obtained via an application of a seventh hashing function on a second cryptographic nonce and/or the secret identifier associated with the sender, a presence of the first nullifier and/or the second nullifier in a nullifier data structure on the DLN indicating invalidity of the first token commitment and/or the second token commitment, respectively. 7. The method of claim 1, wherein the ZKP includes the ZKP that the provider has knowledge of an identity of a first nullifier and/or a second nullifier, (a) the first nullifier obtained via an application of a sixth hashing function on a first cryptographic nonce and/or a secret identifier associated with the sender, and/or (b) the second nullifier obtained via an application of a seventh hashing function on a second cryptographic nonce and/or the secret identifier associated with the sender, (i) a presence of the first nullifier and/or the second nullifier in a nullifier data structure on the DLN indicating invalidity of the first token commitment and/or the second token commitment, respectively, (ii) the application of the third hashing function including the application of the third hashing function on the first cryptographic nonce, (iii) the application of the fourth hashing function including the application of the fourth hashing function on the second cryptographic nonce. 8. The method of claim 1, wherein the ZKP includes the ZKP that the provider has knowledge of an identity of a first nullifier and/or a second nullifier, (a) the first nullifier obtained via an application of a sixth hashing function on a first cryptographic nonce and/or a secret identifier associated with the sender, and/or (b) the second nullifier obtained via an application of a seventh hashing function on a second cryptographic nonce and/or the secret identifier associated with the sender, (i) a presence of the first nullifier and/or the second nullifier in a nullifier data structure on the DLN indicating invalidity of the first token commitment and/or the second token commitment, respectively, (ii) the secret identifier including the private key of the sender. 9. The method of claim 1, wherein the ZKP includes the ZKP that the provider is capable of deriving a public identifier associated with the sender from a secret identifier associated with the sender. 10. The method of claim 1, wherein the ZKP includes the ZKP that the provider is capable of deriving a public identifier associated with the sender from a secret identifier associated with the sender, the public identifier and the secret identifier including a public key and a private key, respectively, of the sender on the DLN. 11. The method of claim 1, wherein the application of the first hashing function and/or the application of the second hashing function are performed off-the-DLN. 12. The method of claim 1, wherein the third token commitment is added onto the commitments data structure after the self-executing code segment verifies a first nullifier and a second nullifier are not stored in a nullifier data structure on the DLN prior to the addition of the third token commitment onto the commitments data structure, presence of the first nullifier and the second nullifier in the nullifier data structure indicating invalidity of the first token commitment and the second token commitment, respectively. 13. The method of claim 1, wherein the third token commitment is added onto the commitments data structure after the self-executing code segment adds a first nullifier and a second nullifier into a nullifier data structure on the DLN after verifying that the first nullifier and the second nullifier are not stored in the nullifier data structure prior to the addition of the third token commitment onto the commitments data structure, presence of the first nullifier and the second nullifier in the nullifier data structure indicating invalidity of the first token commitment and the second token commitment, respectively. 14. The method of claim 1, wherein the first token commitment, the second token commitment and/or the third token commitment represent non-fungible tokens. 15. The method of claim 1, wherein the application of the third hashing function and/or the application of the fourth hashing function include the application of the third hashing function and/or the application of the fourth hashing function, respectively, on an identifier associated with the sender on the DLN. 16. The method of claim 1, wherein the application of the third hashing function and/or the application of the fourth hashing function include the application of the third hashing function and/or the application of the fourth hashing function, respectively, on an identifier associated with the sender on the DLN, the identifier including a public key of the sender on the DLN. 17. The method of claim 1, wherein the application of the fifth hashing function includes the application of the fifth hashing function on a cryptographic nonce and/or an identifier associated with the recipient. 18. The method of claim 1, wherein the application of the fifth hashing function includes the application of the fifth hashing function on an identifier associated with the recipient, the identifier including a public key on the DLN of the recipient. 19. The method of claim 1, wherein receiving the confirmation occurs without revealing any identifying information of the first asset, the second asset, the combined asset, the first identifying parameter of the first asset and/or the second identifying parameter of the second asset. 20. The method of claim 1, wherein receiving the confirmation occurs without revealing any identifying information of the sender and/or the recipient, the identifying information of the sender and/or the recipient including a public key of the sender, a private key of the sender, a public key of the recipient and/or a private key of the recipient, on the DLN. 21. The method of claim 1, wherein receiving the confirmation occurs without revealing any identifying information of the first token commitment, the second token commitment, a first cryptographic nonce and/or a second cryptographic nonce, the first token commitment obtained via the application of the third hashing function on the first cryptographic nonce, the second token commitment obtained via the application of the fourth hashing function on the first cryptographic nonce. 22. A method, comprising: receiving a request that is configured to cause a first asset and a second asset to be combined into a combined asset;generating, in response to the request, a combined asset token that includes a combination of a first asset token and a second asset token, the first asset token obtained via an application of a first hashing function on a first identifying parameter of the first asset, and the second asset token obtained via an application of a second hashing function on a second identifying parameter of the second asset;providing, by a provider and to a self-executing code segment on a distributed ledger- based network (DLN), a zero-knowledge proof (ZKP) that the provider has knowledge of an identity of the first asset token, the second asset token and/or the combined asset token;and receiving, upon verification of the ZKP by the self-executing code segment, a confirmation of a registration of the combined asset on the DLN. 23. The method of claim 22, wherein receiving the confirmation occurs after addition of the combined asset token into a double-spend preventer data structure on the DLN after verifying that the hash of the combined asset token is not stored in the double-spend preventer data structure prior to the registration of the combined asset on the DLN. 24. The method of claim 22, wherein receiving the confirmation occurs without revealing any identifying information of the first asset, the second asset, the combined asset, the first identifying parameter of the first asset and/or the second identifying parameter of the second asset. 25. The method of claim 22, wherein receiving the confirmation occurs without revealing any identifying information of an owner of the first asset, the second asset and/or the combined asset, the identifying information of the owner including a public key of the owner and/or a private key of the owner on the DLN. 26. A method, comprising: receiving a request that is configured to bring about a transfer of a combined asset from a sender to a recipient, the combined asset including a first asset and a second asset, the first asset and the second asset represented on a distributed ledger-based network (DLN) by a first token commitment and a second token commitment, respectively;and causing, in response to the request and on the DLN, a registration of the transfer of the combined asset from the sender to the recipient, the registration occurring after verification of a zero-knowledge proof (ZKP) provided by a provider that the provider has knowledge of an identity of: (1) a first asset token of a first identifying parameter of the first asset, the first token commitment obtained via an application of a first hashing function on the first asset token;(2) a second asset token of a second identifying parameter of the second asset, the second token commitment obtained via an application of a second hashing function on the second asset token;and/or (3) a combined asset token including a combination of the first asset token and the second asset token, a third token commitment representing a combined asset on the DLN obtained via an application of a third hashing function on the combined asset token . 27. The method of claim 26, wherein the combined asset token consists the first asset token and the second asset token. 28. The method of claim 26, wherein the registration of the transfer occurs without revealing any identifying information of the first asset, the second asset, the combined asset, the first identifying parameter of the first asset and/or the second identifying parameter of the second asset. 29. The method of claim 26, wherein the first token commitment, the second token commitment and/or the third token commitment represent non-fungible tokens. 30. A method, comprising: receiving a request that is configured to bring about a first asset and a second asset to be combined into a combined asset;and causing, in response to the request and on a distributed ledger-based network (DLN), a registration of the combined asset on the DLN, the registration occurring after verification of a zero-knowledge proof (ZKP) provided by a provider that the provider has knowledge of an identity of a first asset token, a second asset token and/or a combined asset token, the first asset token obtained via an application of a first hashing function on a first identifying parameter of the first asset, the second asset token obtained via an application of a second hashing function on a second identifying parameter of the second asset, the combined asset token including a combination of a first asset token and a second asset token.