Special Soundness and Binding Properties: A Framework for Tightly Secure zk-SNARKs
Erki Külaots, Helger Lipmaa, Roberto Parisella, Janno Siim
2026年份
摘要
Interactive arguments often combine polynomial IOPs with polynomials commitment schemes (PCSs). Frequently, the interactive argument is proven to be knowledge sound, but this incurs a high security loss when applying the Fiat-Shamir transformation to obtain a non-interactive argument in the random oracle model (ROM).
We introduce the notion of special soundness for polynomial IOPs, which surprisingly has not been considered before.
We study relations between various binding properties of univariate PCSs. In the case of the KZG PCS, these properties can be based on falsifiable assumptions.
We prove that a special-sound polynomial IOP plus a PCS under suitable binding notions gives a computationally special-sound interactive argument. By Attema, Fehr, and Klooss (TCC 2022), applying Fiat-Shamir to this argument yields a tightly knowledge-sound argument (or zk-SNARK) in the ROM under the same assumptions.
In the case of the KZG PCS, we add various batching optimizations to our compiler and prove that they preserve computational special soundness.
This yields a generic approach for achieving efficient zk-SNARKs with constant proof size and tight knowledge soundness in the ROM under falsifiable assumptions.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Constant-Size zk-SNARKs in ROM from Falsifiable AssumptionsHelger Lipmaa, Roberto Parisella, Janno SiimEUROCRYPT 2024 · 被引用 14 次
- On Knowledge-Soundness of Plonk in ROM from Falsifiable AssumptionsHelger Lipmaa, Roberto Parisella, Janno SiimCRYPTO 2025 · 被引用 10 次
- Transparent SNARKs from DARK CompilersBenedikt Bünz, Ben Fisch, Alan SzepieniecEUROCRYPT 2020 · 被引用 240 次
- On Extractability of the KZG Family of Polynomial Commitment SchemesJuraj Belohorec, Pavel Dvorák, Charlotte Hoffmann, Pavel Hubácek 等CRYPTO 2025 · 被引用 3 次
- On the Fiat-Shamir Security of Succinct Arguments from Functional CommitmentsAlessandro Chiesa, Ziyi Guan, Christian Knabenhans, Zihan YuCRYPTO 2026
