Lune

USENIX Security2023Top-tier venue

VeriZexe: Decentralized Private Computation with Universal Setup

Alex Luoyuan Xiong, Binyi Chen, Zhenfei Zhang, Benedikt Bünz, Ben Fisch, Fernando Krell, Philippe Camacho

2023Year
3Top-tier citations

Abstract

Traditional blockchain systems execute program state transitions on-chain, requiring each network node participating in state-machine replication to re-compute every step of the program when validating transactions. This limits both scalability and privacy. Recently, Bowe et al. introduced a primitive called decentralized private computation (DPC) and provided an instantiation called ZEXE, which allows users to execute arbitrary computations off-chain without revealing the program logic to the network. Moreover, transaction validation takes only constant time, independent of the off-chain computation. However, ZEXE required a separate trusted setup for each application, which is highly impractical. Prior attempts to remove this per-application setup incurred significant performance loss. We propose a new DPC instantiation VERIZEXE that is highly efficient and requires only a single universal setup to support an arbitrary number of applications. Our benchmark improves the state-of-the-art by 9x in transaction generation time and by 3.4x in memory usage. Along the way, we also design efficient gadgets for variable-base multi-scalar multiplication and modular arithmetic within the PLONK constraint system, leading to a PLONK verifier gadget using only ∼ 21k constraints. Implementation Universal Setup Transaction Generation Memory Verification Proof Size Original ZEXE [12] ✗ 14.3 s 6.56 GB 15 ms 0.482 KB SnarkVM testnet-2 ✓ 151.4 s 22.81 GB 15 ms 0.482 KB VERIZEXE (this work) ✓ 16.9 s 6.61 GB 18 ms 4.138 KB 1 https://github.com/AleoHQ/snarkVM/tree/testnet1 2 The PLONK constraint system is very extensible from just add and mul gate to customized gates (TURBOPLONK), to support the lookup argument (ULTRAPLONK). These different flavors only affect the concrete encodings of the same constraint logic. Technically we encode a TURBOPLONK verifier in a ULTRAPLONK constraint system using 21k constraints. 3 Another promising application of our PLONK verifier gadget is private zkRollup protocols (such as Aztec [25] ) which aggregates already private transactions into a single rollup transaction with proof attesting to the correctness of all private transactions, achieving higher computation compression for the blockchain validator (who now only needs to verify the final rollup proof) while maintaining privacy.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 01dcc761-5687-4677-b65f-82e77e71df55

Cited by top-tier papers3

Ask how each one uses it

Builds on8

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines