Special Soundness and Binding Properties: A Framework for Tightly Secure zk-SNARKs
Erki Külaots, Helger Lipmaa, Roberto Parisella, Janno Siim
2026Year
Abstract
Interactive arguments often combine polynomial IOPs with polynomials commitment schemes (PCSs). Frequently, the interactive argument is proven to be knowledge sound, but this incurs a high security loss when applying the Fiat-Shamir transformation to obtain a non-interactive argument in the random oracle model (ROM).
We introduce the notion of special soundness for polynomial IOPs, which surprisingly has not been considered before.
We study relations between various binding properties of univariate PCSs. In the case of the KZG PCS, these properties can be based on falsifiable assumptions.
We prove that a special-sound polynomial IOP plus a PCS under suitable binding notions gives a computationally special-sound interactive argument. By Attema, Fehr, and Klooss (TCC 2022), applying Fiat-Shamir to this argument yields a tightly knowledge-sound argument (or zk-SNARK) in the ROM under the same assumptions.
In the case of the KZG PCS, we add various batching optimizations to our compiler and prove that they preserve computational special soundness.
This yields a generic approach for achieving efficient zk-SNARKs with constant proof size and tight knowledge soundness in the ROM under falsifiable assumptions.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get e0e4a272-18fb-41f5-a0f8-13b1c9b1f40dRelated papers
- Constant-Size zk-SNARKs in ROM from Falsifiable AssumptionsHelger Lipmaa, Roberto Parisella, Janno SiimEUROCRYPT 2024 · 14 citations
- On Knowledge-Soundness of Plonk in ROM from Falsifiable AssumptionsHelger Lipmaa, Roberto Parisella, Janno SiimCRYPTO 2025 · 10 citations
- Transparent SNARKs from DARK CompilersBenedikt Bünz, Ben Fisch, Alan SzepieniecEUROCRYPT 2020 · 240 citations
- On Extractability of the KZG Family of Polynomial Commitment SchemesJuraj Belohorec, Pavel Dvorák, Charlotte Hoffmann, Pavel Hubácek et al.CRYPTO 2025 · 3 citations
- On the Fiat-Shamir Security of Succinct Arguments from Functional CommitmentsAlessandro Chiesa, Ziyi Guan, Christian Knabenhans, Zihan YuCRYPTO 2026
