Lune

CRYPTO2025Top-tier venue

Rate-1 Statistical Non-interactive Zero-Knowledge

Pedro Branco, Nico Döttling, Akshayaram Srinivasan

2025Year
2Citations

Abstract

We give the first construction of a rate-1 statistical non-interactive zero-knowledge argument of knowledge. For the circuitSAT\mathsf{circuitSAT} language, our construction achieves a proof length of ∣w∣+∣w∣ϵ⋅poly(λ)|w| + |w|^\epsilon \cdot \mathsf{poly}(\lambda) where ww denotes the witness, λ\lambda is the security parameter, ϵ\epsilon is a constant less than 1, and poly(⋅)\mathsf{poly}(\cdot) is a fixed polynomial that is independent of the instance or the witness size. The soundness of our construction follows from the sub-exponential hardness of either the LWE assumption, or the O(1)O(1)-LIN\mathsf{LIN} assumption on prime-order groups with efficiently computable bilinear maps, or the DDH assumption. Previously, Gentry et al. (Journal of Cryptology, 2015) achieved NIZKs with statistical soundness and computational zero-knowledge with the aforementioned proof length by relying on (circular-secure) Learning with Errors assumption.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines