IP Library › Granted Patent US 11,848,917
Granted Patent B2
US 11,848,917 · App. 17/357,959 · Granted Dec 19, 2023

Blockchain-based anonymous transfers zero-knowledge proofs

Inventors: Theo Kevin Gauthier (Tokyo, JP); Robin Salen (Tokyo, JP); Jawad Tariq (Tokyo, JP)
Assignee: ToposWare, Inc.
H04L63/0421G06F16/2379H04L9/30H04L9/3218H04L9/0643H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,848,917
App. No.
17/357,959
Granted
Dec 19, 2023
Kind
B2
Abstract

Disclosed is a mechanism for performing an anonymous transfer using a blockchain. A sender's device generates a commitment based on a serial number of a zero-knowledge token and a value of the zero-knowledge token. Moreover, the sender's device generates a range proof and a balance proof for the commitment. The range proof verifies that the value of the zero-knowledge token is within a preset range. The balance proof verifies that the value of a set of input tokens is greater than or equal to the value of the zero-knowledge token. The sender's device sends a conversion request to the blockchain network. The conversion request consumes the set of input tokens and generates the zero-knowledge token. The conversion request includes the generated commitment, the generated range proof, and the generated balance proof.

Claims (58)

1. A computer-implemented method comprising:

generating a commitment based on a serial number of a zero-knowledge token, and a value of the zero-knowledge token, wherein generating the commitment comprises:

receiving, from a recipient, a seed value,

generating a random value, and

generating the commitment based on the seed value, the random value, and the value of the zero-knowledge token;

generating a range proof for the commitment, the range proof for verifying that the value of the zero-knowledge token is within a preset range;

generating a balance proof, the balance proof for verifying that a value of a set of input tokens is greater than or equal to the value of the zero-knowledge token; and

transmitting a conversion request, the conversion request for consuming the set of input tokens and for generating the zero-knowledge token, the conversion request including the generated commitment, the generated range proof, and the generated balance proof.

2. The computer-implemented method of claim 1 , further comprising:

generating a knowledge proof, the knowledge proof for verifying knowledge of a set of parameters for generating the commitment, and

wherein the conversion request further includes the generated knowledge proof.

3. The computer-implemented method of claim 2 , wherein at least one of the range proof, the balance proof, and the knowledge proof are generated using a zero-knowledge proof protocol.

4. The computer-implemented method of claim 1 , wherein generating the commitment further comprises:

generating a private key and public key pair; and

generating the serial number for the zero-knowledge token based on the public key.

5. The computer-implemented method of claim 4 , further comprising:

transmitting a spending request for spending the zero-knowledge token, the spending request identifying the serial number of the zero-knowledge token and a set of output tokens.

6. The computer-implemented method of claim 5 , wherein transmitting the spending request comprises:

generating a zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments, the zero-knowledge proof based on the serial number of the zero-knowledge token used to generate the commitment.

7. The computer-implemented method of claim 6 , wherein the zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments is a 1-out-of-N proof.

8. The computer-implemented method of claim 5 , wherein transmitting the spending request comprises:

generating a second balance proof, the second balance proof for verifying that a value of a set of input tokens of the spending request is greater than or equal to a value of the set of output tokens of the spending request.

9. The computer-implemented method of claim 5 , wherein the spending request is signed using the private key corresponding to the public key used for generating the serial number of the zero-knowledge token.

10. A non-transitory computer readable storage medium configured to store instructions, the instructions when executed by a processor cause the processor to:

generate a commitment based on a serial number of a zero-knowledge token, and a value of the zero-knowledge token, wherein generating the commitment comprises:

receiving, from a recipient, a seed value,

generating a random value, and

generating the commitment based on the seed value, the random value, and the value of the zero-knowledge token;

generate a range proof for the commitment, the range proof for verifying that the value of the zero-knowledge token is within a preset range;

generate a balance proof, the balance proof for verifying that a value of a set of input tokens is greater than or equal to the value of the zero-knowledge token; and

transmit a conversion request, the conversion request for consuming the set of input tokens and for generating the zero-knowledge token, the conversion request including the generated commitment, the generated range proof, and the generated balance proof.

11. The non-transitory computer readable storage medium of claim 10 , further comprising instructions that when executed by the processor causes the processor to:

generate a knowledge proof, the knowledge proof for verifying knowledge of a set of parameters for generating the commitment, wherein the conversion request further includes the generated knowledge proof.

12. The non-transitory computer readable storage medium of claim 11 , wherein at least one of the range proof, the balance proof, and the knowledge proof are generated using a zero-knowledge proof protocol.

13. The non-transitory computer readable storage medium of claim 10 , wherein the instructions for generating the commitment comprises further instructions that when executed by the processor causes the processor to:

generate a private key and public key pair; and

generate the serial number for the zero-knowledge token based on the public key.

14. The non-transitory computer readable storage medium of claim 13 , further comprising instructions that when executed by the processor causes the processor to:

transmit a spending request for spending the zero-knowledge token, the spending request identifying the serial number of the zero-knowledge token and a set of output tokens.

15. The non-transitory computer readable storage medium of claim 14 , wherein the instructions to transmit the spending request comprises further instructions that when executed by the processor causes the processor to:

generate a zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments, the zero-knowledge proof based on the serial number of the zero-knowledge token used to generate the commitment.

16. The non-transitory computer readable storage medium of claim 15 , wherein the zero-knowledge proof that the commitment for the zero-knowledge token is included in a set of commitments is a 1-out-of-N proof.

17. The non-transitory computer readable storage medium of claim 14 , wherein the instructions to transmit the spending request comprises further instructions that when executed by the processor causes the processor to:

generate a second balance proof, the second balance proof for verifying that a value of a set of input tokens of the spending request is greater than or equal to a value of the set of output tokens of the spending request.

18. The non-transitory computer readable storage medium of claim 14 , further comprising instructions that when executed by the processor causes the processor to confirm the spending request is signed using the private key corresponding to the public key used to generate the serial number of the zero-knowledge token.

19. A system comprising:

one or more processors; and

memory configured to store code comprising instructions, wherein the instructions, when executed by the one or more processors, cause the one or more processors to:

generate a commitment based on a serial number of a zero-knowledge token, and a value of the zero-knowledge token, wherein generating the commitment comprises:

receiving, from a recipient, a seed value,

generating a random value, and

generating the commitment based on the seed value, the random value, and the value of the zero-knowledge token;

generate a range proof for the commitment, the range proof for verifying that the value of the zero-knowledge token is within a preset range;

generate a balance proof, the balance proof for verifying that a value of a set of input tokens is greater than or equal to the value of the zero-knowledge token; and

transmit a conversion request, the conversion request for consuming the set of input tokens and for generating the zero-knowledge token, the conversion request including the generated commitment, the generated range proof, and the generated balance proof.

20. The system of claim 19 , wherein the instructions, when executed, further cause the one or more processors to:

generate a knowledge proof, the knowledge proof for verifying knowledge of a set of parameters for generating the commitment, and

wherein the conversion request further includes the generated knowledge proof.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2022
From: GAUTHIER, THEO KEVIN; SALEN, ROBIN; TARIQ, JAWAD
To: TOPOSWARE INC.
Reel/Frame 059641/0502 →
Continuity (2)
Provisional Application 63050355 · Jul 10, 2020
Related Publication 20220014502A1 · Jan 13, 2022