中国科学:技术科学(英文版)2024,Vol.67Issue(9) :2853-2866.DOI:10.1007/s11431-023-2580-5

Simulation extractable SNARKs based on target linearly collision-resistant oracle

WANG LiGuan LI Yuan ZHANG ShuangJun CAI DongLiang KAN HaiBin
中国科学:技术科学(英文版)2024,Vol.67Issue(9) :2853-2866.DOI:10.1007/s11431-023-2580-5

Simulation extractable SNARKs based on target linearly collision-resistant oracle

WANG LiGuan 1LI Yuan 1ZHANG ShuangJun 1CAI DongLiang 1KAN HaiBin2
扫码查看

作者信息

  • 1. Shanghai Key Laboratory of Intelligent Information Processing,School of Computer Science,Fudan University,Shanghai 200433,China;Shanghai Engineering Research Center of Blockchain,Shanghai 200433,China
  • 2. Shanghai Key Laboratory of Intelligent Information Processing,School of Computer Science,Fudan University,Shanghai 200433,China;Shanghai Engineering Research Center of Blockchain,Shanghai 200433,China;Yiwu Research Institute of Fudan University,Yiwu 322000,China
  • 折叠

Abstract

The famous zero-knowledge succinct non-interactive arguments of knowledge(zk-SNARK)was proposed by Groth in 2016.Typically,the construction is based on quadratic arithmetic programs which are highly efficient concerning the proof length and the verification complexity.Since then,there has been much progress in designing zk-SNARKs,achieving stronger security,and simulated extractability,which is analogous to non-malleability and has broad applications.In this study,following Groth's pairing-based zk-SNARK,a simulation extractability zk-SNARK under the random oracle model is constructed.Our construction relies on a newly proposed property named target linearly collision-resistant,which is satisfied by random oracles under discrete logarithm assumptions.Compared to the original Groth 16 zk-SNARK,in our construction,both parties are allowed to use such a random oracle,aiming to get the same random number.The resulting proof consists of 3 group elements and only 1 pairing equation needs to be verified.Compared to other related works,our construction is shorter in proof length and simpler in verification while preserving simulation extractability.The results also extend to achieve subversion zero-knowledge SNARKs.

Key words

quadratic arithmetic program/simulation extractability/subversion zero-knowledge/succinct non-interactive arguments of knowledge/target linearly collision-resistant

引用本文复制引用

基金项目

National Key R&D Program of China(2019YFB2101703)

National Natural Science Foundation of China(62272107)

National Natural Science Foundation of China(U19A2066)

Innovation Action Plan of Shanghai Science and Technology(21511102200)

Key R&D Program of Guangdong Province(2020B0101090001)

出版年

2024
中国科学:技术科学(英文版)
中国科学院

中国科学:技术科学(英文版)

CSTPCDEI
影响因子:1.056
ISSN:1674-7321
段落导航相关论文