This paper proposes a protocol for Proof of Assets of a bitcoin exchange using the Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (ZK-SNARK) without revealing either the bitcoin addresses of the exchange or balances associated with those addresses. The proof of assets is a mechanism to prove the total value of bitcoins the exchange has authority to spend using its private keys. We construct a privacy-preserving ZK-SNARK proof system to prove the knowledge of the private keys corresponding to the bitcoin assets of an exchange. The ZK-SNARK tool-chain helps to convert an NP-Statement for proving the knowledge of the private keys (known to the exchange) into a circuit satisfiability problem. In this protocol, the exchange creates a Pedersen commitment to the value of bitcoins associated with each address without revealing the balance. The simulation results show that the proof generation time, size, and verification time are efficient in practice.
翻译:本文建议了一个比特币交换资产证明协议, 使用“ 零知识奇特非互动知识争论”( ZK- SNARK) 来证明比特币交换资产的证据, 但不披露交易所的比特币地址或与这些地址相关的余额。 资产证明是一种机制, 用以证明交易所拥有使用其私人钥匙的权力比特币总价值。 我们建立了一个保护隐私的ZK- SNARK验证系统, 以证明对与交易所比特币资产相对应的私人钥匙的了解。 ZK- SNARK 工具链有助于将证明私人钥匙( 交易所已知的)知识的NP- 声明转换为巡回可诉性问题。 在这项协议中, 交换产生了对与每个地址相关的比特币价值的Pedersen承诺, 而没有披露平衡。 模拟结果显示, 证据生成的时间、 大小和核查时间在实践中是有效的。