Fiat-Shamir Bulletproofs are Non-Malleable (in the Algebraic Group Model)
Chaya Ganesh, Claudio Orlandi, Mahak Pancholi, Akira Takahashi, Daniel Tschudi
摘要
Bulletproofs (Bünz et al. IEEE S&P 2018) are a celebrated ZK proof system that allows for short and efficient proofs, and have been implemented and deployed in several real-world systems. In practice, they are most often implemented in their non-interactive version obtained using the Fiat-Shamir transform, despite the lack of a formal proof of security for this setting. Prior to this work, there was no evidence that malleability attacks were not possible against Fiat-Shamir Bulletproofs. Malleability attacks can lead to very severe vulnerabilities, as they allow an adversary to forge proofs re-using or modifying parts of the proofs provided by the honest parties. In this paper, we show for the first time that Bulletproofs (or any other similar multi-round proof system satisfying some form of weak unique response property) achieve simulation-extractability in the algebraic group model . This implies that Fiat-Shamir Bulletproofs are non-malleable .
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper6
- Riggs: Decentralized Sealed-Bid AuctionsNirvan Tyagi, Arasu Arun, Cody Freitag, Riad S. Wahby 等CCS 2023 · 被引用 15 次
- SNARKs for Virtual Machines Are Non-malleableMatteo Campanelli, Antonio Faonio, Luigi RussoEUROCRYPT 2025 · 被引用 6 次
- Real-World Universal zkSNARKs are Non-MalleableAntonio Faonio, Dario Fiore, Luigi RussoCCS 2024 · 被引用 5 次
- Universally Composable SNARKs with Transparent Setup without Programmable Random OracleChristian Badertscher, Matteo Campanelli, Michele Ciampi, Luigi Russo 等CRYPTO 2025 · 被引用 3 次
- Lattice-Based Threshold Blind SignaturesSebastian Faller, Guilhem Niot, Michael ReichleS&P 2026 · 被引用 2 次
相关 Paper
- Spartan and Bulletproofs are Simulation-Extractable (for Free!)Quang Dao, Paul GrubbsEUROCRYPT 2023 · 被引用 26 次
- Tight State-Restoration Soundness in the Algebraic Group ModelAshrujit Ghoshal, Stefano TessaroCRYPTO 2021 · 被引用 27 次
- Weak Fiat-Shamir Attacks on Modern Proof SystemsQuang Dao, Jim Miller, Opal Wright, Paul GrubbsS&P 2023
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra 等S&P 2018 · 被引用 1,285 次
- Fiat-Shamir for Repeated Squaring with Applications to PPAD-Hardness and VDFsAlex Lombardi, Vinod VaikuntanathanCRYPTO 2020 · 被引用 40 次
