Universally Composable SNARKs with Transparent Setup without Programmable Random Oracle
Christian Badertscher, Matteo Campanelli, Michele Ciampi, Luigi Russo, Luisa Siniscalchi
摘要
Non-interactive zero-knowledge (NIZK) proofs allow a prover to convince a verifier about the validity of an NP-statement by sending a single message and without disclosing any additional information (besides the validity of the statement). Single-message cryptographic proofs are very versatile, which has made them widely used both in theory and in practice. This is particularly true for succinct proofs, where the length of the message is sublinear in the size of the NP relation. This versatility, unfortunately, comes at a price, since any NIZK proof system requires some form of setup, like a common reference string. One way to circumvent the need for a setup is by relying on a Random Oracle. Unfortunately, if the Random Oracle is modeled as a Global resource that the simulator is not allowed to program, then it is impossible to obtain a secure NIZK. This impossibility has been circumvented by allowing the simulator (and the real-world adversary) to program the RO, and allowing the honest parties to check, via a special interface, if the RO outputs have been programmed. In this work, we show that this impossibility can be circumvented by meaningfully weakening the Universal Composability framework following the model proposed by Broadnax et al. (Eurocrypt 2017). In this model, the ideal world functionalities are allowed to interact with oracles that have quasi-polynomial time capabilities. As our main result, we propose the first composable NIZK proof system that relies on a global (non-programmable) random oracle as its only form of setup. The NIZK scheme we propose is witness-succinct (with proofs logarithmic in the size of the witness). Our results break both the barrier of programmability of the random oracle and of polylogarithmic proof size for UC-secure NIZKs with transparent setups. We are able to construct our NIZK using the framework proposed by Ganesh et al. (Eurocrypt
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDHPaul Gerhart, Davide Li Calsi, Luigi Russo, Dominique SchröderEUROCRYPT 2026 · 被引用 1 次
- Sumcheck-Based zkSNARKs are Non-malleableAntonio Faonio, Luigi RussoCRYPTO 2026
它引用的顶会 Paper7
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra 等S&P 2018 · 被引用 1,285 次
- Doubly-Efficient zkSNARKs Without Trusted SetupRiad S. Wahby, Ioanna Tzialla, Abhi Shelat, Justin Thaler 等S&P 2018 · 被引用 356 次
- Marlin: Preprocessing zkSNARKs with Universal and Updatable SRSAlessandro Chiesa, Yuncong Hu, Mary Maller, Pratyush Mishra 等EUROCRYPT 2020 · 被引用 356 次
- Fiat-Shamir Bulletproofs are Non-Malleable (in the Algebraic Group Model)Chaya Ganesh, Claudio Orlandi, Mahak Pancholi, Akira Takahashi 等EUROCRYPT 2022 · 被引用 34 次
- Spartan and Bulletproofs are Simulation-Extractable (for Free!)Quang Dao, Paul GrubbsEUROCRYPT 2023 · 被引用 26 次
相关 Paper
- Witness-Succinct Universally-Composable SNARKsChaya Ganesh, Yashvanth Kondi, Claudio Orlandi, Mahak Pancholi 等EUROCRYPT 2023 · 被引用 24 次
- Unique NIZKs and Steganography DetectionWilly Quach, LaKyah Tyner, Daniel WichsEUROCRYPT 2025 · 被引用 2 次
- A New Approach to Arguments of Quantum KnowledgeJames Bartusek, Ruta Jawale, Justin Raizes, Kabir TomerCRYPTO 2026
- Gödel in Cryptography: Effectively Zero-Knowledge Proofs for NP with No Interaction, No Setup, and Perfect SoundnessRahul IlangoFOCS 2025 · 被引用 1 次
- How to Simulate Random Oracles with Auxiliary InputYevgeniy Dodis, Aayush Jain, Huijia Lin, Ji Luo 等FOCS 2024
