HeRZ: Hierarchical Recursive Zero-Knowledge Verification for Canonical and Auditable Asset-State Evolution in Blockchain-Cyber-Physical Systems
Ningyuan Chen, Yibei Lin, Siu-Yeung Cho, Yu ZhengBlockchain-Cyber-Physical Systems (BCPSs) use sensor-generated IoT events to update ledger representations of physical assets. Authenticating individual reports does not by itself establish an admissible trajectory from the canonical predecessor or authenticate a selected historical interval. We formulate Verifiable State-Evolution Integrity (VSEI): accepted states must be reachable through ordered, device-bound, policy-compliant trajectories. HeRZ realizes this requirement through a BCPS-specific relation combining event authentication, physical guards, deterministic updates, and temporal linkage. Recursive folding preserves the relation in a fixed-width incremental proof state, while a KZG/Groth16 Decider exposes the interval boundaries. A stateful EVM wrapper atomically consumes the canonical predecessor for forward settlement and verifies retained intervals between anchored checkpoints without publishing intermediate event records. The implementation supports both paths, producing 384-byte compressed proofs and 1156-byte settlement calldata. Mean complete online peak memory remains 27.92–28.68 GiB over 100–2000 events. At 2000 events, HeRZ reduces peak memory by 34.1% relative to the equivalent stateful FlatZK baseline, at 3.63 times its online time. Layered tests and anchored audits validate the implemented state semantics. One parameter set and deployed verifier accept different interval lengths, supporting incremental construction and selective historical auditing within a fixed protocol version. HeRZ thus provides an executable path from authenticated sensor events to canonically settled and retrospectively auditable asset histories.