On the Impossibility of Algebraic NIZK in Pairing-Free Groups
Emanuele Giunta
Abstract
Non-Interactive Zero-Knowledge proofs (NIZK) allow a prover to convince a verifier that a statement is true by sending only one message and without conveying any other information. In the CRS model, many instantiations have been proposed from group-theoretic assumptions. On the one hand, some of these constructions use the group structure in a black-box way but rely on pairings, an example being the celebrated Groth-Sahai proof system. On the other hand, a recent line of research realized NIZKs from sub-exponential DDH in pairing-free groups using Correlation Intractable Hash functions, but at the price of making non black-box usage of the group.
As of today no construction is known to simultaneously reduce its security to pairing-free group problems and to use the underlying group in a black-box way.
This is indeed not a coincidence: in this paper, we prove that for a large class of NIZK either a pairing-free group is used non black-box by relying on element representation, or security reduces to external hardness assumptions. More specifically our impossibility applies to two incomparable cases. The first one covers Arguments of Knowledge (AoK) which proves that a preimage under a given one way function is known. The second one covers NIZK (not necessarily AoK) for hard subset problems, which captures relations such as DDH, Decision-Linear and Matrix-DDH.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get e72f5acd-0ea2-481e-877b-5da534082a1bRelated papers
- New Constructions of Statistical NIZKs: Dual-Mode DV-NIZKs and MoreBenoît Libert, Alain Passelègue, Hoeteck Wee, David J. WuEUROCRYPT 2020 · 17 citations
- A Note on Non-interactive Zero-Knowledge from CDHGeoffroy Couteau, Abhishek Jain, Zhengzhong Jin, Willy QuachCRYPTO 2023 · 6 citations
- Non-interactive Zero Knowledge from Sub-exponential DDHAbhishek Jain, Zhengzhong JinEUROCRYPT 2021 · 49 citations
- Non-interactive Zero-Knowledge in Pairing-Free Groups from Weaker AssumptionsGeoffroy Couteau, Shuichi Katsumata, Bogdan UrsuEUROCRYPT 2020 · 28 citations
- Shorter Non-interactive Zero-Knowledge Arguments and ZAPs for Algebraic LanguagesGeoffroy Couteau, Dominik HartmannCRYPTO 2020 · 34 citations
