Non-interactive zero-knowledge proofs (NIZK) are essential building blocks in threshold cryptosystems like multiparty signatures, distributed key generation, and verifiable secret sharing, allowing parties to prove correct behavior without revealing secrets. Furthermore, universally composable (UC) NIZKs enable seamless composition in larger cryptosystems. A popular way to construct NIZKs is to compile interactive protocols using the Fiat-Shamir transform. Unfortunately, a Fiat-Shamir transformed NIZK requires rewinding the adversary and is not straight-line extractable, making it at odds with UC. Using Fischlin’s transform gives straight-line extractability, but at the expense of many repetitions of the underlying protocol leading to poor concrete efficiency and difficulty in setting parameters. In this work, we propose a simple new transform that compiles a Sigma protocol for an algebraic relation into a UC-NIZK protocol without any overheads of repetition.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Universally Composable Non-interactive Zero-Knowledge from Sigma Protocols via a New Straight-Line Compiler

  • Megan Chen,
  • Pousali Dey,
  • Chaya Ganesh,
  • Pratyay Mukherjee,
  • Pratik Sarkar,
  • Swagata Sasmal

摘要

Non-interactive zero-knowledge proofs (NIZK) are essential building blocks in threshold cryptosystems like multiparty signatures, distributed key generation, and verifiable secret sharing, allowing parties to prove correct behavior without revealing secrets. Furthermore, universally composable (UC) NIZKs enable seamless composition in larger cryptosystems. A popular way to construct NIZKs is to compile interactive protocols using the Fiat-Shamir transform. Unfortunately, a Fiat-Shamir transformed NIZK requires rewinding the adversary and is not straight-line extractable, making it at odds with UC. Using Fischlin’s transform gives straight-line extractability, but at the expense of many repetitions of the underlying protocol leading to poor concrete efficiency and difficulty in setting parameters. In this work, we propose a simple new transform that compiles a Sigma protocol for an algebraic relation into a UC-NIZK protocol without any overheads of repetition.