Lune

CRYPTO2025Top-tier venue

Designated-Verifier SNARGs with One Group Element

Gal Arnon, Jesko Dujmovic, Yuval Ishai

2025Year
1Citations
1Top-tier citations

Abstract

We revisit the question of minimizing the proof length of designated-verifier succinct non-interactive arguments (dv-SNARGs) in the generic group model. Barta et al. (Crypto 2020) constructed such dvSNARGs with inverse-polynomial soundness in which the proof consists of only two group elements. For negligible soundness, all previous constructions required a super-constant number of group elements. We show that one group element suffices for negligible soundness. Concretely, we obtain dv-SNARGs (in fact, dv-SNARKs) with 2−τ soundness where proofs consist of one element of a generic group G and O(τ) additional bits. In particular, the proof length in group elements is constant even with 1/|G| soundness error. In more concrete terms, compared to the best known SNARGs using bilinear groups, we get dvSNARGs with roughly 2x shorter proofs (with 2−80 soundness at a 128-bit security level). We are not aware of any practically feasible proof systems that achieve similar succinctness, even fully interactive or heuristic ones. Our technical approach is based on a novel combination of techniques for trapdoor hash functions and group-based homomorphic secret sharing with linear multi-prover interactive proofs.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 0d281659-3fb2-4654-a1d8-73f1cdb72289

Cited by top-tier papers1

Ask how each one uses it

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines