Lune

CRYPTO2025顶会

How to Share an NP Statement or Combiners for Zero-Knowledge Proofs

Benny Applebaum, Eliran Kachlon

2025年份
2被引次数

摘要

In Crypto'19, Goyal, Jain, and Sahai (GJS) introduced the elegant notion of secret-sharing of an NP statement (NPSS). Roughly speaking, a t-out-of-n secret sharing of an NP statement is a reduction that maps an instance-witness pair to n instance-witness pairs such that any subset of (t -1) reveals no information about the original witness, while any subset of t allows full recovery of the original witness. Although the notion was formulated for general t ≤ n, the only existing construction (due to GJS) applies solely to the case where t = n and provides only computational privacy. In this paper, we further explore NPSS and present the following contributions.

Definition. We revisit the notion of NPSS by formulating a new definition of informationtheoretically secure NPSS. This notion serves as a cryptographic analogue of standard NPreductions and can be compiled into the GJS definition using any one-way function.

Construction. We construct information-theoretic t-out-of-n NPSS for any values of t ≤ n with complexity polynomial in n. Along the way, we present a new notion of secure multiparty computation that may be of independent interest.

Our NPSS framework enables the non-interactive combination of n instances of zero-knowledge proofs, where only t s of them are sound and only t z are zero-knowledge, provided that t s + t z > n. Our combiner preserves various desirable properties, such as the succinctness of the proof. Building on this, we establish the following results under the minimal assumption of one-way functions: 1. Standard NIZK implies NIZK in the Multi-String Model (Groth and Ostrovsky, J. Cryptology, 2014), where security holds as long as a majority of the n common reference strings were honestly generated. Previously, such a transformation was only known in the common random string model, where the reference string is uniformly distributed. 2. A Designated-Prover NIZK in the Multi-String Model, achieving a strong form of two-round Multi-Verifier Zero-Knowledge in the honest-majority setting. 3. A threeround secure multiparty computation protocol for general functions in the honest-majority setting. The round complexity of this protocol is optimal, resolving a line of research that previously relied on stronger assumptions

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper7

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖