How to Share an NP Statement or Combiners for Zero-Knowledge Proofs
Benny Applebaum, Eliran Kachlon
摘要
In Crypto'19, Goyal, Jain, and Sahai (GJS) introduced the elegant notion of secret-sharing of an NP statement (NPSS). Roughly speaking, a t-out-of-n secret sharing of an NP statement is a reduction that maps an instance-witness pair to n instance-witness pairs such that any subset of (t -1) reveals no information about the original witness, while any subset of t allows full recovery of the original witness. Although the notion was formulated for general t ≤ n, the only existing construction (due to GJS) applies solely to the case where t = n and provides only computational privacy. In this paper, we further explore NPSS and present the following contributions.
Definition. We revisit the notion of NPSS by formulating a new definition of informationtheoretically secure NPSS. This notion serves as a cryptographic analogue of standard NPreductions and can be compiled into the GJS definition using any one-way function.
Construction. We construct information-theoretic t-out-of-n NPSS for any values of t ≤ n with complexity polynomial in n. Along the way, we present a new notion of secure multiparty computation that may be of independent interest.
Our NPSS framework enables the non-interactive combination of n instances of zero-knowledge proofs, where only t s of them are sound and only t z are zero-knowledge, provided that t s + t z > n. Our combiner preserves various desirable properties, such as the succinctness of the proof. Building on this, we establish the following results under the minimal assumption of one-way functions: 1. Standard NIZK implies NIZK in the Multi-String Model (Groth and Ostrovsky, J. Cryptology, 2014), where security holds as long as a majority of the n common reference strings were honestly generated. Previously, such a transformation was only known in the common random string model, where the reference string is uniformly distributed. 2. A Designated-Prover NIZK in the Multi-String Model, achieving a strong form of two-round Multi-Verifier Zero-Knowledge in the honest-majority setting. 3. A threeround secure multiparty computation protocol for general functions in the honest-majority setting. The round complexity of this protocol is optimal, resolving a line of research that previously relied on stronger assumptions
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- NIZK from LPN and Trapdoor Hash via Correlation Intractability for Approximable RelationsZvika Brakerski, Venkata Koppula, Tamer MourCRYPTO 2020 · 被引用 52 次
- New Constructions of Statistical NIZKs: Dual-Mode DV-NIZKs and MoreBenoît Libert, Alain Passelègue, Hoeteck Wee, David J. WuEUROCRYPT 2020 · 被引用 17 次
- Verifiable Relation Sharing and Multi-verifier Zero-Knowledge in Two Rounds: Trading NIZKs with Honest Majority - (Extended Abstract)Benny Applebaum, Eliran Kachlon, Arpita PatraCRYPTO 2022 · 被引用 12 次
- Amplification of Non-interactive Zero Knowledge, RevisitedNir Bitansky, Nathan GeierCRYPTO 2024 · 被引用 7 次
- One-Way Functions and Zero KnowledgeShuichi Hirahara, Mikito NanashimaSTOC 2024 · 被引用 4 次
相关 Paper
- NIZK Amplification via Leakage-Resilient Secure ComputationBenny Applebaum, Eliran KachlonCRYPTO 2025 · 被引用 2 次
- Multi-Key Homomorphic Secret SharingGeoffroy Couteau, Lalita Devadas, Aditya Hegde, Abhishek Jain 等EUROCRYPT 2025 · 被引用 11 次
- Multi-party Homomorphic Secret Sharing and Sublinear MPC from Sparse LPNQuang Dao, Yuval Ishai, Aayush Jain, Huijia LinCRYPTO 2023 · 被引用 30 次
- Robust Non-interactive Zero-Knowledge CombinersMichele Ciampi, Lorenzo Magliocco, Daniele Venturi, Yu XiaEUROCRYPT 2026
- Constrained Pseudorandom Functions from Homomorphic Secret SharingGeoffroy Couteau, Pierre Meyer, Alain Passelègue, Mahshid RiahiniaEUROCRYPT 2023 · 被引用 19 次
