ETH Global Paris黑客松Circom SHA256生日哈希电路断言失败求助
问题:Circom SHA256电路运行时断言失败
我在ETH Global Paris黑客松期间,参考Medium教程尝试将生日日期哈希功能集成到Circom电路中,用来证明用户知晓该日期,但运行时触发断言失败错误。
电路代码
pragma circom 2.0.0; include "./circomlib/circuits/sha256/sha256.circom"; template Birthday(){ component SHA = Sha256(6); signal input date[6]; SHA.in <== date; signal output date_out[256]; date_out <== SHA.out; } component main { public [ date ] } = Birthday(); /* INPUT = { "date": [10, 3, 0, 3, 0, 1] } */
错误栈信息
Error in template BinSum_17 line: 100
Error in template SigmaPlus_18 line: 44
Error in template Sha256compression_97 line: 83
Error in template Sha256_98 line: 73
Error in template Birthday_99 line: 7
解决方案
这个错误的核心原因是Circomlib的Sha256模板要求输入长度必须是512位(64字节)的整数倍,SHA256原生处理的是512位数据块。你当前传入6个256位信号,总长度不符合块大小要求,导致内部压缩函数的断言验证失败。
修复方案一:使用Sha256Packed模板(推荐)
Sha256Packed是circomlib提供的封装模板,可自动处理任意长度输入的填充和分组,无需手动对齐块大小,更适合你的场景:
pragma circom 2.0.0; include "./circomlib/circuits/sha256/sha256packed.circom"; template Birthday(){ // 参数为输入信号的数量(每个信号代表1字节) component SHA = Sha256Packed(6); signal input date[6]; SHA.in <== date; signal output date_out[256]; date_out <== SHA.out; } component main { public [ date ] } = Birthday(); /* INPUT = { "date": [10, 3, 0, 3, 0, 1] } */
修复方案二:手动填充到512位块
若坚持使用原始Sha256模板,需手动将输入填充至64字节(512位):
pragma circom 2.0.0; include "./circomlib/circuits/sha256/sha256.circom"; template Birthday(){ component SHA = Sha256(64); // 64字节=512位 signal input date[6]; signal padding[58]; // 补充58个0字节凑够64字节 // 赋值日期部分 for (var i=0; i<6; i++) { SHA.in[i] <== date[i]; } // 赋值填充部分 for (var i=6; i<64; i++) { SHA.in[i] <== padding[i-6]; } signal output date_out[256]; date_out <== SHA.out; } component main { public [ date ] } = Birthday(); /* INPUT = { "date": [10, 3, 0, 3, 0, 1], "padding": [0,0,...] // 需填入58个0 } */
内容的提问来源于stack exchange,提问作者Pavel Fedotov
相关产品推荐
相关产品推荐

