Spartan and Bulletproofs are Simulation-Extractable (for Free!)
Quang Dao, Paul Grubbs
摘要
Increasing deployment of advanced zero-knowledge proof systems, especially zkSNARKs, has raised critical questions about their security against real-world attacks. Two classes of attacks of concern in practice are adaptive soundness attacks, where an attacker can prove false statements by choosing its public input after generating a proof, and malleability attacks, where an attacker can use a valid proof to create another valid proof it could not have created itself. Prior work has shown that simulation-extractability (SIM-EXT), a strong notion of security for proof systems, rules out these attacks.
In this paper, we prove that two transparent, discrete-log-based zkSNARKs, Spartan and Bulletproofs, are simulation-extractable (SIM-EXT) in the random oracle model if the discrete logarithm assumption holds in the underlying group. Since these assumptions are required to prove standard security properties for Spartan and Bulletproofs, our results show that SIM-EXT is, surprisingly, "for free" with these schemes. Our result is the first SIM-EXT proof for Spartan and encompasses both linear- and sublinear-verifier variants. Our result for Bulletproofs encompasses both the aggregate range proof and arithmetic circuit variants, and is the first to not rely on the algebraic group model (AGM), resolving an open question posed by Ganesh et al. (EUROCRYPT '22). As part of our analysis, we develop a generalization of the tree-builder extraction theorem of Attema et al. (TCC '22), which may be of independent interest.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper7
- SNARKs for Virtual Machines Are Non-malleableMatteo Campanelli, Antonio Faonio, Luigi RussoEUROCRYPT 2025 · 被引用 6 次
- Real-World Universal zkSNARKs are Non-MalleableAntonio Faonio, Dario Fiore, Luigi RussoCCS 2024 · 被引用 5 次
- Universally Composable SNARKs with Transparent Setup without Programmable Random OracleChristian Badertscher, Matteo Campanelli, Michele Ciampi, Luigi Russo 等CRYPTO 2025 · 被引用 3 次
- Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDHPaul Gerhart, Davide Li Calsi, Luigi Russo, Dominique SchröderEUROCRYPT 2026 · 被引用 1 次
- Efficient Proofs of Possession for Legacy SignaturesAnna P. Y. Woo, Alex Ozdemir, Chad Sharp, Thomas Pornin 等S&P 2025
相关 Paper
- Fiat-Shamir Bulletproofs are Non-Malleable (in the Algebraic Group Model)Chaya Ganesh, Claudio Orlandi, Mahak Pancholi, Akira Takahashi 等EUROCRYPT 2022 · 被引用 34 次
- Sumcheck-Based zkSNARKs are Non-malleableAntonio Faonio, Luigi RussoCRYPTO 2026
- Spartan: Efficient and General-Purpose zkSNARKs Without Trusted SetupSrinath T. V. SettyCRYPTO 2020 · 被引用 262 次
- Witness-Succinct Universally-Composable SNARKsChaya Ganesh, Yashvanth Kondi, Claudio Orlandi, Mahak Pancholi 等EUROCRYPT 2023 · 被引用 24 次
- On Knowledge-Soundness of Plonk in ROM from Falsifiable AssumptionsHelger Lipmaa, Roberto Parisella, Janno SiimCRYPTO 2025 · 被引用 10 次
