Proofs of Space with Maximal Hardness
Leonid Reyzin
Abstract
In a proof of space, a prover performs a complex computation with a large output. A verifier periodically checks that the prover still holds the output. The security goal for a proof of space construction is to ensure that a prover who erases even a portion of the output has to redo a large portion of the complex computation in order to satisfy the verifier. In existing constructions of proofs of space, the computation that a cheating prover is forced to redo is a small fraction (van-ishing or small constant) of the original complex computation. The only exception is a construction of Pietrzak (ITCS 2019) that requires extremely depth-robust graphs, which result in impractically high complexity of the initialization process. We present the first proof of space of reasonable complexity that ensures that the prover has to redo almost the entire computation (fraction arbitrarily close to 1) when trying to save even an arbitrarily small constant fraction of the space. Our construction is a generalization of an existing construction called SDR (Fisch, Eurocrypt 2019) deployed on the Filecoin blockchain. Our improvements, while general, also demonstrate that the already deployed construction has considerably better security than previously shown. Technically, our construction can be viewed as amplifying predecessor-robust graphs. These are directed acyclic graphs in which every sufficiently large set of nodes contains a large subset of nodes whose induced sub graph has just one sink. We take a predecessor-robust graph with constant-fraction parameters for the sizes of the set and subset, and build a bigger predecessor-robust graph with a near-optimal set of parameters and additional guarantees on sink placement, while increasing the degree only by a small additive constant.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 363b89ae-c1e1-4746-a1e6-c8e7ee69ae4fRelated papers
- Proof of Storage-Time: Efficiently Checking Continuous Data AvailabilityGiuseppe Ateniese, Long Chen, Mohammad Etemad, Qiang TangNDSS 2020
- Scalable and Adaptively Secure Any-Trust Distributed Key Generation and All-hands CheckpointingHanwen Feng, Tiancheng Mai, Qiang TangCCS 2024 · 4 citations
- Advancing Scalability in Decentralized Storage: A Novel Approach to Proof-of-Replication via Polynomial EvaluationGiuseppe Ateniese, Foteini Baldimtsi, Matteo Campanelli, Danilo Francati et al.CRYPTO 2024 · 5 citations
- Dynamic proofs of retrievability with low server storageGaspard Anthoine, Jean-Guillaume Dumas, Mélanie de Jonghe, Aude Maignan et al.USENIX Security 2021 · 28 citations
- PIEs: Public Incompressible Encodings for Decentralized StorageEthan Cecchetti, Ben Fisch, Ian Miers, Ari JuelsCCS 2019 · 18 citations
