You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Risc Zero证明链上验证失败但链下验证成功问题排查

问题:Risc Zero证明链上验证失败但链下成功

问题背景

我正在开发一个使用Risc Zero验证Rust程序生成证明的智能合约。已成功从Risc Zero Rust程序生成seal、imageID和journalDigest,通过Rust脚本可在链下成功验证,但链上验证时出现错误。

复现步骤

  • 使用Risc Zero Rust程序生成证明(seal、imageID、journalDigest)
  • 通过Rust脚本链下验证证明(成功)
  • 在本地测试网和BSC测试网部署RiscZeroGroth16Verifier合约
  • 向链上验证合约提交seal、imageID和journalDigest

预期行为

证明应像链下一样在链上验证成功

实际行为

交易回滚,错误信息:

call to RiscZeroGroth16Verifier.verify errored: Error occurred: revert.

revert
    The transaction has been reverted to the initial state.
Error provided by the contract:
VerificationFailed : Error raised when cryptographic verification of the zero-knowledge proof fails.
Parameters:
{}

补充信息

  • 使用Risc Zero官方的RiscZeroGroth16Verifier合约源码
  • 相同的seal、imageID、journalDigest可在链下验证成功
  • 已尝试提高gas限制,问题仍存在

代码片段

简化智能合约代码

function _verifyIntegrity(bytes calldata seal, bytes32 claimDigest) internal view {
        // Check that the seal has a matching selector. Mismatch generally indicates that the
        // prover and this verifier are using different parameters, and so the verification
        // will not succeed.
        if (SELECTOR != bytes4(seal[:4])) {
            revert SelectorMismatch({received: bytes4(seal[:4]), expected: SELECTOR});
        }

        // Run the Groth16 verify procedure.
        (bytes16 claim0, bytes16 claim1) = splitDigest(claimDigest);
        Seal memory decodedSeal = abi.decode(seal[4:], (Seal));
        bool verified = this.verifyProof(
            decodedSeal.a,
            decodedSeal.b,
            decodedSeal.c,
            [
                uint256(uint128(CONTROL_ROOT_0)),
                uint256(uint128(CONTROL_ROOT_1)),
                uint256(uint128(claim0)),
                uint256(uint128(claim1)),
                uint256(BN254_CONTROL_ID)
            ]
        );

        // Revert is verification failed.
        if (!verified) {
            revert VerificationFailed();
        }
    }    

    function verify(bytes calldata seal, bytes32 imageId, bytes32 journalDigest) external view {
        _verifyIntegrity(seal, ReceiptClaimLib.ok(imageId, journalDigest).digest());
    }

部署时使用的验证器参数

control_root (bytes32): 0x8cdad9242664be3112aba377c5425a4df735eb1c6966472b561d2855932c0469

bn254_control_id (bytes32): 0x04446e66d300eb7fb45c9726bb53c793dda407a62e9601618bb43c5c14657ac0

交易详情

call to RiscZeroGroth16Verifier.verify errored: Error occurred: revert.

    revert
        The transaction has been reverted to the initial state.
Error provided by the contract:
VerificationFailed : Error raised when cryptographic verification of the zero-knowledge proof fails.
Parameters:
{}
    If the transaction failed for not having enough gas, try increasing the gas limit gently.

环境

  • Solidity版本:0.8.26+commit.8a97fa7a
  • 以太坊测试网合约地址:0xAC292cF957Dd5BA174cdA13b05C16aFC71700327
  • BSC测试网合约地址:0x21ee758fe996c8b6bef57cf81b35fe9f4057e037

疑问

  1. 为何证明链上验证失败但链下成功?潜在问题及解决方法是什么?
  2. 调用verify函数前是否需设置额外参数(如公开输入、验证密钥)?
  3. 链上与链下的验证器参数配置是否存在差异?

内容的提问来源于stack exchange,提问作者user59066

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 18:56:06