Designated-Verifier SNARGs with One Group Element
Gal Arnon, Jesko Dujmovic, Yuval Ishai
Abstract
We revisit the question of minimizing the proof length of designated-verifier succinct non-interactive arguments (dv-SNARGs) in the generic group model. Barta et al. (Crypto 2020) constructed such dvSNARGs with inverse-polynomial soundness in which the proof consists of only two group elements. For negligible soundness, all previous constructions required a super-constant number of group elements. We show that one group element suffices for negligible soundness. Concretely, we obtain dv-SNARGs (in fact, dv-SNARKs) with 2−τ soundness where proofs consist of one element of a generic group G and O(τ) additional bits. In particular, the proof length in group elements is constant even with 1/|G| soundness error. In more concrete terms, compared to the best known SNARGs using bilinear groups, we get dvSNARGs with roughly 2x shorter proofs (with 2−80 soundness at a 128-bit security level). We are not aware of any practically feasible proof systems that achieve similar succinctness, even fully interactive or heuristic ones. Our technical approach is based on a novel combination of techniques for trapdoor hash functions and group-based homomorphic secret sharing with linear multi-prover interactive proofs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 0d281659-3fb2-4654-a1d8-73f1cdb72289Cited by top-tier papers1
Ask how each one uses itRelated papers
- On Succinct Arguments and Witness Encryption from GroupsOhad Barta, Yuval Ishai, Rafail Ostrovsky, David J. WuCRYPTO 2020 · 18 citations
- Pairing-Based SNARGs with Two Group ElementsGal Arnon, Jesko Dujmovic, Eylon YogevCRYPTO 2026
- Boosting Batch Arguments and RAM DelegationYael Kalai, Alex Lombardi, Vinod Vaikuntanathan, Daniel WichsSTOC 2023 · 42 citations
- SNARGs for P from Sub-exponential DDH and QRJames Hulett, Ruta Jawale, Dakshita Khurana, Akshayaram SrinivasanEUROCRYPT 2022 · 41 citations
- Adaptively Sound Zero-Knowledge SNARKs for UPSurya Mathialagan, Spencer Peters, Vinod VaikuntanathanCRYPTO 2024 · 17 citations
