How to Prove Megabytes (Per Second)

نویسنده

  • Yaron Gvili
چکیده

We propose the first provably secure zero-knowledge (ZK) argument of knowledge (AoK) protocol running at close to 1 megabyte per second (MBps) on commodity hardware – about an order of magnitude faster than relevant current protocols. It is a post-quantum, (efficientprover) honest-verifier (HV) statistical zero-knowledge (SZK) sigma protocol in the standard model under a hardness assumption on ideal lattices. We further propose an overhead-efficient low-latency amortization yielding a witness indistinguishable (WI) and witness hiding (WH) AoK protocol running at> 100 MBps. Both protocols have absolute soundness slack 1, or zero for small completeness error, and an argument size growing linearly, where amortization has slope 2 and latency 1 microsecond. Non-interactive (NI), non-HV, resettable ZK (rZK) and resettable WI (rWI) variations of the protocols are obtained using standard transforms. Choices of parameters with concrete security ≥ 2 against known attacks are given along with experimental results showing practicality.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Parallel storage and retrieval of pixmap images

Professionals in various fields such as medical imaging, biology and civil engineering require rapid access to huge amounts of uncompressed pixmap image data. To fulfill these requirements, a parallel image server architecture is proposed, based on arrays of intelligent disk nodes, with each disk node composed of one processor and one disk. This contribution shows how images can be partitioned ...

متن کامل

Improving DES Coprocessor Throughput for Short Operations

Over the last several years, our research team built a commercially-offered secure coprocessor that, besides other features, offers high-speed DES: over 20 megabytes/second. However, it obtains these speeds only on operations with large data lengths. For DES operations on short data (e.g., 8-80 bytes), our commercial offering was benchmarked at less than 2 kilobytes/second. The programmability ...

متن کامل

Performance Characteristics of Large and Long Fibre Channel Arbitrated Loops

The bandwidth performance of a Fibre Channel Arbitrated Loop (FCAL) is roughly defined to be 100 MegaBytes (10 bytes) per second. Furthermore, FCAL is capable of a theoretical peak of 40,000 I/O operations (transactions) per second., These performance levels, however, are largely not realized by the applications that use Fibre Channel as an interface to disk subsystems. The bandwidth and transa...

متن کامل

VIRAM1: A Media-Oriented Vector Processor with Embedded DRAM

Processors for mobile multimedia devices must be low power while having excellent performance on media applications. Our processor, VIRAM1, accomplishes this by combining vector processing with embedded DRAM. VIRAM1 includes a scalar core, 13 megabytes (104 megabits) of DRAM, and four vector datapaths. It consumes 2 watts at 200 MHz and executes up to 9.6 giga-ops (16 bit) per second.

متن کامل

Error Correction Code in SoC FPGA-Based Memory Systems

Continuously advancing semiconductor process technologies have enabled increased component integration, functionality, and performance in embedded systems. While the increased capabilities reap huge rewards, one of the side effects of higherperformance systems is that more attention must be paid to the probability of soft errors. Decreasing supply voltages cause integrated circuits to be increa...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2017  شماره 

صفحات  -

تاریخ انتشار 2017