Constant-Size zk-SNARKs in ROM from Falsifiable Assumptions
Helger Lipmaa, Roberto Parisella, Janno Siim
Abstract
We prove that the seminal KZG polynomial commitment scheme (PCS) is black-box extractable under a simple falsifiable assumption ARSDH. To create an interactive argument, we construct a compiler that combines a black-box extractable non-interactive PCS and a polynomial IOP (PIOP). The compiler incurs a minor cost per every committed polynomial. Applying the Fiat-Shamir transformation, we obtain slightly less efficient variants of well-known PIOP-based zk-SNARKs, such as Plonk, that are knowledge-sound in the ROM under the ARSDH assumption. Importantly, there is no need for idealized group models or knowledge assumptions. This results in the first known zk-SNARKs in the ROM from falsifiable assumptions with both an efficient prover and constant-size argument.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6aa6158f-12ba-4cc9-a7fa-e012c9dd061bCited by top-tier papers1
Ask how each one uses itRelated papers
- On Knowledge-Soundness of Plonk in ROM from Falsifiable AssumptionsHelger Lipmaa, Roberto Parisella, Janno SiimCRYPTO 2025 · 10 citations
- Special Soundness and Binding Properties: A Framework for Tightly Secure zk-SNARKsErki Külaots, Helger Lipmaa, Roberto Parisella, Janno SiimEUROCRYPT 2026
- On Extractability of the KZG Family of Polynomial Commitment SchemesJuraj Belohorec, Pavel Dvorák, Charlotte Hoffmann, Pavel Hubácek et al.CRYPTO 2025 · 3 citations
- Transparent SNARKs from DARK CompilersBenedikt Bünz, Ben Fisch, Alan SzepieniecEUROCRYPT 2020 · 240 citations
- RedShift: Transparent SNARKs from List Polynomial CommitmentsAssimakis A. Kattis, Konstantin Panarin, Alexander VlasovCCS 2022 · 15 citations
