SMILE: Set Membership from Ideal Lattices with Applications to Ring Signatures and Confidential Transactions
Vadim Lyubashevsky, Ngoc Khanh Nguyen, Gregor Seiler
Abstract
In a set membership proof, the public information consists of a set of elements and a commitment. The prover then produces a zero-knowledge proof showing that the commitment is indeed to some element from the set. This primitive is closely related to concepts like ring signatures and ``one-out-of-many'' proofs that underlie many anonymity and privacy protocols. The main result of this work is a new succinct lattice-based set membership proof whose size is logarithmic in the size of the set.
We also give a transformation of our set membership proof to a ring signature scheme. The ring signature size is also logarithmic in the size of the public key set and has size KB for a set of elements, and KB for a set of size . At an approximately -bit security level, these outputs are between 1.5X and 7X smaller than the current state of the art succinct ring signatures of Beullens et al. (Asiacrypt 2020) and Esgin et al. (CCS 2019).
We then show that our ring signature, combined with a few other techniques and optimizations, can be turned into a fairly efficient Monero-like confidential transaction system based on the MatRiCT framework of Esgin et al. (CCS 2019). With our new techniques, we are able to reduce the transaction proof size by factors of about 4X - 10X over the aforementioned work. For example, a transaction with two inputs and two outputs, where each input is hidden among other accounts, requires approximately KB in our protocol.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5b323bfc-3a88-451f-b202-141523ca32e1Cited by top-tier papers9
- Lattice-Based Zero-Knowledge Proofs and Applications: Shorter, Simpler, and More GeneralVadim Lyubashevsky, Ngoc Khanh Nguyen, Maxime PlançonCRYPTO 2022 · 125 citations
- Group Signatures and More from Isogenies and Lattices: Generic, Simple, and EfficientWard Beullens, Samuel Dobson, Shuichi Katsumata, Yi-Fu Lai et al.EUROCRYPT 2022 · 51 citations
- Practical Lattice-Based Zero-Knowledge Proofs for Integer RelationsVadim Lyubashevsky, Ngoc Khanh Nguyen, Gregor SeilerCCS 2020 · 41 citations
- A Framework for Practical Anonymous Credentials from LatticesJonathan Bootle, Vadim Lyubashevsky, Ngoc Khanh Nguyen, Alessandro SorniottiCRYPTO 2023 · 34 citations
- Compact Ring Signatures from Learning with ErrorsRohit Chatterjee, Sanjam Garg, Mohammad Hajiabadi, Dakshita Khurana et al.CRYPTO 2021 · 22 citations
Related papers
- MatRiCT: Efficient, Scalable and Post-Quantum Blockchain Confidential Transactions ProtocolMuhammed F. Esgin, Raymond K. Zhao, Ron Steinfeld, Joseph K. Liu et al.CCS 2019 · 104 citations
- MatRiCT+: More Efficient Post-Quantum Private Blockchain PaymentsMuhammed F. Esgin, Ron Steinfeld, Raymond K. ZhaoS&P 2022 · 59 citations
- Omniring: Scaling Private Payments Without Trusted SetupRussell W. F. Lai, Viktoria Ronge, Tim Ruffing, Dominique Schröder et al.CCS 2019 · 1 citation
- Lattice-Based Group Signatures and Zero-Knowledge Proofs of Automorphism StabilityRafaël del Pino, Vadim Lyubashevsky, Gregor SeilerCCS 2018 · 84 citations
- Leaking Arbitrarily Many Secrets: Any-out-of-Many Proofs and Applications to RingCT ProtocolsTianyu Zheng, Shang Gao, Yubo Song, Bin XiaoS&P 2023
