Efficient Proofs of Possession for Legacy Signatures
Anna P. Y. Woo, Alex Ozdemir, Chad Sharp, Thomas Pornin, Paul Grubbs
摘要
Digital signatures underpin identity, authenticity, and trust in modern computer systems. Cryptography research has shown that it is possible to prove possession of a valid message and signature for some public key, without revealing the message or signature. These proofs of possession work only for specially-designed signature schemes. Though these proofs of possession have many useful applications to improving security, privacy, and anonymity, they are not currently usable for widely deployed, legacy signature schemes—like RSA, ECDSA, and Ed25519. Unlocking practical proofs of possession for these legacy signature schemes requires closing a huge efficiency gap. This work brings proofs of possession for legacy signature schemes very close to practicality. Our design strategy is to encode the signature's verification algorithm as a rank-one constraint system (R1CS), then use a zkSNARK to prove knowledge of a solution. To do this efficiently we (1) design and analyze a new zkSNARK called Dorian that supports randomized computations, (2) introduce several new techniques for encoding hashes, elliptic curve operations, and modular arithmetic, (3) give a new approach that allows performing the most expensive parts of ECDSA and Ed25519 verifications outside R1CS, and (4) generate a novel elliptic curve that allows expressing Ed25519 curve operations very efficiently. Our techniques reduce R1CS sizes by up to 200× and prover times by more than 20×. We can generate a 240-byte proof of possession of an RSA signature over a message the size of a typical TLS certificate—two kilobytes—in only three seconds.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- NoisePrints: Distortion-Free Watermarks for Authorship in Private Diffusion ModelsNir Goren, Oren Katzir, Abhinav Nakarmi, Eyal Ronen 等ICLR 2026 · 被引用 5 次
- Vega: Low-Latency Zero-Knowledge Proofs over Existing CredentialsDarya Kaviani, Srinath SettyS&P 2026 · 被引用 5 次
- BABE: Verifying Proofs on Bitcoin Made 1000x CheaperSanjam Garg, Dimitris Kolonelos, Mikhail Sergeevitch, Srivatsan Sridhar 等CCS 2026
- 3PaaS: Privacy-Preserving Post-Compromise Security as a ServiceCas Cremers, Abhinav Nakarmi, Aleksi Peltonen, Eyal RonenCCS 2026
- Prezta: Provable Remote Execution of Zero-Trust Authorization using SNARKsZhongjing Wei, Osaid Muhammad Ameer, Yupeng Zhang, Nikita BorisovUSENIX Security 2026
它引用的顶会 Paper26
- Poseidon: A New Hash Function for Zero-Knowledge Proof SystemsLorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy 等USENIX Security 2021 · 被引用 410 次
- Spartan: Efficient and General-Purpose zkSNARKs Without Trusted SetupSrinath T. V. SettyCRYPTO 2020 · 被引用 262 次
- Fast Secure Multiparty ECDSA with Practical Distributed Key Generation and Applications to Cryptocurrency CustodyYehuda Lindell, Ariel NofCCS 2018 · 被引用 220 次
- Coconut: Threshold Issuance Selective Disclosure Credentials with Applications to Distributed LedgersAlberto Sonnino, Mustafa Al-Bassam, Shehar Bano, Sarah Meiklejohn 等NDSS 2019 · 被引用 218 次
- Secure Two-party Threshold ECDSA from ECDSA AssumptionsJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2018 · 被引用 171 次
相关 Paper
- The Provable Security of Ed25519: Theory and PracticeJacqueline Brendel, Cas Cremers, Dennis Jackson, Mang ZhaoS&P 2021 · 被引用 78 次
- Lattice Signature with Efficient Protocols, Application to Anonymous CredentialsCorentin Jeudy, Adeline Roux-Langlois, Olivier SandersCRYPTO 2023 · 被引用 29 次
- Hekaton: Horizontally-Scalable zkSNARKs Via Proof AggregationMichael Rosenberg, Tushar Mopuri, Hossein Hafezi, Ian Miers 等CCS 2024 · 被引用 7 次
- Orion: Zero Knowledge Proof with Linear Prover TimeTiancheng Xie, Yupeng Zhang, Dawn SongCRYPTO 2022 · 被引用 83 次
- Lattice-Based zk-SNARKs from Square Span ProgramsRosario Gennaro, Michele Minelli, Anca Nitulescu, Michele OrrùCCS 2018 · 被引用 62 次
