Non-interactive Zero-Knowledge in Pairing-Free Groups from Weaker Assumptions
Geoffroy Couteau, Shuichi Katsumata, Bogdan Ursu
摘要
We provide two new constructions of non-interactive zero-knowledge arguments (NIZKs) for NP from discrete-logarithm-style assumptions over cyclic groups, without relying on pairings. A previous construction from (Canetti et al., Eurocrypt'18) achieves such NIZKs under the assumption that no efficient adversary can break the key-dependent message (KDM) security of (additive) ElGamal with respect to all (even inefficient) functions over groups of size , with probability better than . This is an extremely strong, non-falsifiable assumption. In particular, even mild (polynomial) improvements over the current best-known attacks on the discrete logarithm problem would already contradict this assumption. (Canetti et al. STOC'19) describe how to improve the assumption to rely only on KDM security with respect to efficient functions while additionally assuming public-key encryption schemes, therefore obtaining an assumption that is (in spirit) falsifiable.
Our first construction improves this state of affairs. We provide a construction of NIZKs for NP under the CDH assumption together with the assumption that no efficient adversary can break the key-dependent message one-wayness of ElGamal with respect to efficient functions over groups of size , with probability better than (denoted -OWKDM), for a constant . Unlike the previous assumption, our assumption leaves an exponential gap between the best-known attack and the required security guarantee.
Our second construction is interested in the case where CDH does not hold. Namely, as a second contribution, we construct an infinitely often NIZK argument system for NP (where soundness and zero-knowledge are only guaranteed to hold for infinitely many security parameters), under the assumption that CDH is easy together with the -OWKDM security of ElGamal with and the existence of low-depth pseudorandom generators (PRG).
Combining our two results, we obtain a construction of (infinitely-often) NIZKs for NP under the -OWKDM security of ElGamal with and the existence of low-depth PRG, independently of whether CDH holds. To our knowledge, since neither OWKDM security of ElGamal nor low-depth PRGs are known to imply public key encryption, this provides the first construction of NIZKs from concrete and falsifiable Minicrypt-style assumptions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Correlation Intractability and SNARGs from Sub-exponential DDHArka Rai Choudhuri, Sanjam Garg, Abhishek Jain, Zhengzhong Jin 等CRYPTO 2023 · 被引用 49 次
- One-Shot Fiat-Shamir-Based NIZK Arguments of Composite Residuosity and Logarithmic-Size Ring Signatures in the Standard ModelBenoît Libert, Khoa Nguyen, Thomas Peters, Moti YungEUROCRYPT 2022 · 被引用 8 次
- A Note on Non-interactive Zero-Knowledge from CDHGeoffroy Couteau, Abhishek Jain, Zhengzhong Jin, Willy QuachCRYPTO 2023 · 被引用 6 次
它引用的顶会 Paper2
相关 Paper
- Public-Coin 3-Round Zero-Knowledge from Learning with Errors and Keyless Multi-Collision-Resistant HashSusumu KiyoshimaCRYPTO 2022 · 被引用 5 次
- Rate-1 Statistical Non-interactive Zero-KnowledgePedro Branco, Nico Döttling, Akshayaram SrinivasanCRYPTO 2025 · 被引用 2 次
- Non-interactive Zero Knowledge from Sub-exponential DDHAbhishek Jain, Zhengzhong JinEUROCRYPT 2021 · 被引用 49 次
- Time- and Space-Efficient Arguments from Groups of Unknown OrderAlexander R. Block, Justin Holmgren, Alon Rosen, Ron D. Rothblum 等CRYPTO 2021 · 被引用 67 次
- New Constructions of Statistical NIZKs: Dual-Mode DV-NIZKs and MoreBenoît Libert, Alain Passelègue, Hoeteck Wee, David J. WuEUROCRYPT 2020 · 被引用 17 次
