Pairing-Based SNARGs with Two Group Elements
Gal Arnon, Jesko Dujmovic, Eylon Yogev
Abstract
SNARGs are cryptographic primitives that allow a prover to demonstrate membership in an NP language while sending a proof that is much smaller than the witness. In this work, we focus on the succinctness of publicly-verifiable group-based SNARGs, analyzed in a model that combines both a generic (asymmetric) bilinear group and a random oracle (the GGM + ROM).
We construct the first publicly-verifiable SNARG in the GGM + ROM where the proof consists of exactly elements of and no additional bits, achieving the smallest proof size among all known publicly verifiable group-based SNARGs. Our security analysis is tight, ensuring that the construction incurs no hidden security losses. Concretely, when instantiated with the BLS12-381 curve for 128-bit security, our scheme yields a proof size of bits, nearly a improvement over the best known pairing-based SNARG. While our scheme is not yet concretely efficient, it demonstrates the feasibility of ultra-short proofs and opens the door to future practical instantiations.
Complementing this construction, we establish a new lower bound for group-based SNARGs. We prove that under mild and natural restrictions on the verifier (which are satisfied by all known schemes) no SNARG exists in the Maurer GGM + ROM with a proof that consists of a single group element (assuming one-way functions). This substantially strengthens the lower bound of Groth, which was more restrictive and did not extend to settings with a random oracle.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 563a0348-b8f2-4ca9-a857-08dcf1b501d5Related papers
- On Succinct Arguments and Witness Encryption from GroupsOhad Barta, Yuval Ishai, Rafail Ostrovsky, David J. WuCRYPTO 2020 · 18 citations
- Lower Bound on SNARGs in the Random Oracle ModelIftach Haitner, Daniel Nukrai, Eylon YogevCRYPTO 2022 · 3 citations
- Designated-Verifier SNARGs with One Group ElementGal Arnon, Jesko Dujmovic, Yuval IshaiCRYPTO 2025 · 1 citation
- Subquadratic SNARGs in the Random Oracle ModelAlessandro Chiesa, Eylon YogevCRYPTO 2021 · 12 citations
- SNARGs for P from Sub-exponential DDH and QRJames Hulett, Ruta Jawale, Dakshita Khurana, Akshayaram SrinivasanEUROCRYPT 2022 · 41 citations
