Witness Authenticating NIZKs and Applications
Hanwen Feng, Qiang Tang
Abstract
We initiate the study of witness authenticating NIZK proof systems (waNIZKs), in which one can use a witness of a statement to identify whether a valid proof for is indeed generated using . Such a new identification functionality enables more diverse applications, and it also puts new requirements on soundness that: (1) no adversary can generate a valid proof that will not be identified by any witness; (2) or forge a proof using some valid witness to frame others. To work around the obvious obstacle towards conventional zero-knowledgeness, we define entropic zero-knowledgeness that requires the proof to leak no partial information, if the witness has sufficient computational entropy. We give a formal treatment of this new primitive. The modeling turns out to be quite involved and multiple subtle points arise and particular cares are required. We present general constructions from standard assumptions. We also demonstrate three applications in non-malleable (perfectly one-way) hash, group signatures with verifier-local revocations and plaintext-checkable public-key encryption. Our waNIZK provides a new tool to advance the state of the art in all these applications.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Unique NIZKs and Steganography DetectionWilly Quach, LaKyah Tyner, Daniel WichsEUROCRYPT 2025 · 2 citations
- How to Use (Plain) Witness Encryption: Registered ABE, Flexible Broadcast, and MoreCody Freitag, Brent Waters, David J. WuCRYPTO 2023 · 49 citations
- Witness Semantic SecurityPaul Lou, Nathan Manohar, Amit SahaiEUROCRYPT 2024
- On Witness Encryption and Laconic Zero-Knowledge ArgumentsYanyi Liu, Noam Mazor, Rafael PassCRYPTO 2025 · 1 citation
- GZKP: A GPU Accelerated Zero-Knowledge Proof SystemWeiliang Ma, Qian Xiong, Xuanhua Shi, Xiaosong Ma et al.ASPLOS 2023 · 47 citations
