On the Size of Pairing-Based Non-interactive Arguments
نویسنده
چکیده
Non-interactive arguments enable a prover to convince a verifier that a statement is true. Recently there has been a lot of progress both in theory and practice on constructing highly efficient non-interactive arguments with small size and low verification complexity, so-called succinct non-interactive arguments (SNARGs) and succinct non-interactive arguments of knowledge (SNARKs). Many constructions of SNARGs rely on pairing-based cryptography. In these constructions a proof consists of a number of group elements and the verification consists of checking a number of pairing product equations. The question we address in this article is how efficient pairing-based SNARGs can be. Our first contribution is a pairing-based (preprocessing) SNARK for arithmetic circuit satisfiability, which is an NP-complete language. In our SNARK we work with asymmetric pairings for higher efficiency, a proof is only 3 group elements, and verification consists of checking a single pairing product equations using 3 pairings in total. Our SNARK is zero-knowledge and does not reveal anything about the witness the prover uses to make the proof. As our second contribution we answer an open question of Bitansky, Chiesa, Ishai, Ostrovsky and Paneth (TCC 2013) by showing that 2-move linear interactive proofs cannot have a linear decision procedure. It follows from this that SNARGs where the prover and verifier use generic asymmetric bilinear group operations cannot consist of a single group element. This gives the first lower bound for pairing-based SNARGs. It remains an intriguing open problem whether this lower bound can be extended to rule out 2 group element SNARGs, which would prove optimality of our 3 element construction.
منابع مشابه
Sub-linear Size Pairing-based Non-interactive Zero-Knowledge Arguments
We construct non-interactive zero-knowledge arguments for circuit satisfiability and arithmetic circuits with perfect completeness, perfect zero-knowledge and computational (co-)soundness. The non-interactive zeroknowledge arguments have sub-linear size and very efficient public verification. Our construction uses bilinear groups and is only proven secure in the generic group model, but does no...
متن کاملShort Pairing-Based Non-interactive Zero-Knowledge Arguments
We construct non-interactive zero-knowledge arguments for circuit satisfiability with perfect completeness, perfect zero-knowledge and computational soundness. The non-interactive zero-knowledge arguments have sub-linear size and very efficient public verification. The size of the non-interactive zero-knowledge arguments can even be reduced to a constant number of group elements if we allow the...
متن کاملProgression-Free Sets and Sublinear Pairing-Based Non-Interactive Zero-Knowledge Arguments
In 2010, Groth constructed the only previously known sublinear-communication NIZK circuit satisfiability argument in the common reference string model. We optimize Groth’s argument by, in particular, reducing both the CRS length and the prover’s computational complexity from quadratic to quasilinear in the circuit size. We also use a (presumably) weaker security assumption, and have tighter sec...
متن کاملA Comparative Study of Interactive and Interactional Metadiscourse Markers in Sales Contract Written by English Natives vs. Iranian Non-natives
This study investigated two major types of metadiscourse markers as used in typical sales contracts, written by English natives and Iranian non-natives. In so doing, 60 sales contracts were selected, 30 written by native English and 30 by Iranian non-natives. Based on Hyland and Tse’s taxonomy, the contracts were codified and classified in terms of the frequency and percentage of the interactiv...
متن کاملSuppression of Four Wave Mixing Based on the Pairing Combinations of Differently Linear-Polarized Optical Signals in WDM System
Data transmission in optical systems and increased transmission distance capacity benefit by using optical amplification wavelength division multiplexing (WDM) technology. The combination of four waves (FWM) is a non-linear effect in the wavelength division multiplex (WDM), when more than two wavelengths of light in a fiber launch will occur. FWM amount depends on the channel, the channel spaci...
متن کامل