Public blockchains impose an inherent tension between regulatory compliance and user privacy. Existing on-chain identity solutions require centralized KYC attestors, specialized hardware, or Decentralized Identifier (DID) frameworks needing entirely new credential infrastructure. Meanwhile, over four billion active X.509 certificates constitute a globally deployed, government-grade trust infrastructure largely unexploited for decentralized identity. This paper presents zk-X509, a privacy-preserving identity system bridging legacy Public Key Infrastructure (PKI) with public ledgers via a RISC-V zero-knowledge virtual machine (zkVM). Users prove ownership of standard X.509 certificates without revealing private keys or personal identifiers. Crucially, the private key never enters the ZK circuit; ownership is proven via OS keychain signature delegation (macOS Security.framework, Windows CNG). The circuit verifies certificate chain validity, temporal validity, key ownership, trustless CRL revocation, blockchain address binding, and Sybil-resistant nullifier generation. It commits 13 public values, including a Certificate Authority (CA) Merkle root hiding the issuing CA, and four selective disclosure hashes. We formalize eight security properties under a Dolev-Yao adversary with game-based definitions and reductions to sEUF-CMA, SHA-256 collision resistance, and ZK soundness. Evaluated on the SP1 zkVM, the system achieves 11.8M cycles for ECDSA P-256 (17.4M for RSA-2048), with on-chain Groth16 verification costing ~300K gas. By leveraging certificates deployed at scale across jurisdictions, zk-X509 enables adoption without new trust establishment, complementing emerging DID-based systems.


翻译:摘要:公有区块链在监管合规与用户隐私之间固有存在张力。现有链上身份解决方案需要中心化的KYC认证者、专用硬件,或需构建全新凭证基础设施的去中心化标识符(DID)框架。与此同时,全球超过四十亿活跃的X.509证书构成了已广泛部署的政府级信任基础设施,但其在去中心化身份领域的潜力尚未得到充分开发。本文提出zk-X509系统,通过RISC-V零知识虚拟机(zkVM)桥接传统公钥基础设施(PKI)与公有账本,实现隐私保护型身份认证。用户可证明对标准X.509证书的所有权,同时不泄露私钥或个人标识符。关键在于,私钥始终不进入零知识电路:所有权验证通过操作系统密钥链签名委派机制(macOS Security.framework、Windows CNG)完成。电路验证内容包括证书链有效性、时间有效性、密钥所有权、无信任CRL撤销、区块链地址绑定及抗女巫攻击的无效化标识符生成。电路提交13个公开值,包括隐藏颁发CA的证书颁发机构(CA)默克尔根,以及四个选择性披露哈希值。我们在Dolev-Yao敌手模型下形式化定义了八项安全属性,通过基于游戏的规约归约至sEUF-CMA、SHA-256抗碰撞性与零知识完备性。在SP1 zkVM上评估,系统对ECDSA P-256(RSA-2048)实现1180万(1740万)个执行周期,链上Groth16验证消耗约30万Gas。通过利用已跨司法管辖区大规模部署的现有证书体系,zk-X509无需建立新信任机制即可实现应用落地,为新兴的DID系统形成补充。

0
下载
关闭预览

相关内容

区块链技术在指控装备领域的应用
专知会员服务
41+阅读 · 2023年10月30日
重磅!工信部《数据传输安全白皮书》发布,90页pdf
专知会员服务
87+阅读 · 2022年8月6日
区块链数据安全服务综述
专知会员服务
56+阅读 · 2021年11月10日
专知会员服务
30+阅读 · 2021年9月30日
专知会员服务
66+阅读 · 2021年1月25日
「联邦学习隐私保护 」最新2022研究综述
专知
16+阅读 · 2022年4月1日
《人工智能安全测评白皮书》,99页pdf
专知
36+阅读 · 2022年2月26日
【资源】Blockchain 区块链中文资源阅读列表
区块链隐私保护研究综述——祝烈煌详解
计算机研究与发展
23+阅读 · 2018年11月28日
差分隐私保护:从入门到脱坑
FreeBuf
17+阅读 · 2018年9月10日
从人脸识别到行人重识别,下一个风口
计算机视觉战队
13+阅读 · 2017年11月24日
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
0+阅读 · 2017年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2014年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
VIP会员
最新内容
边缘计算的军事应用
专知会员服务
6+阅读 · 8月9日
一种考虑资源机动性的武器目标分配混合算法
专知会员服务
8+阅读 · 8月8日
《多域冲突比较支持模型》60页
专知会员服务
13+阅读 · 8月7日
相关VIP内容
区块链技术在指控装备领域的应用
专知会员服务
41+阅读 · 2023年10月30日
重磅!工信部《数据传输安全白皮书》发布,90页pdf
专知会员服务
87+阅读 · 2022年8月6日
区块链数据安全服务综述
专知会员服务
56+阅读 · 2021年11月10日
专知会员服务
30+阅读 · 2021年9月30日
专知会员服务
66+阅读 · 2021年1月25日
相关基金
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
0+阅读 · 2017年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2014年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员