首页> 外文会议>Annual international cryptology conference >New Constructions of Reusable Designated-Verifier NIZKs

New Constructions of Reusable Designated-Verifier NIZKs




Non-interactive zero-knowledge arguments (NIZKs) for NP are an important cryptographic primitive, but we currently only have instantiations under a few specific assumptions. Notably, we are missing constructions from the learning with errors (LWE) assumption, the Diffie-Hellman (CDH/DDH) assumption, and the learning parity with noise (LPN) assumption. In this paper, we study a relaxation of NIZKs to the designated-verifier setting (DV-NIZK), where a trusted setup generates a common reference string together with a secret key for the verifier. We want reusable schemes, which allow the verifier to reuse the secret key to verify many different proofs, and soundness should hold even if the malicious prover learns whether various proofs are accepted or rejected. Such reusable DV-NIZKs were recently constructed under the CDH assumption, but it was open whether they can also be constructed under LWE or LPN. We also consider an extension of reusable DV-NIZKs to the malicious designated-verifier setting (MDV-NIZK). In this setting, the only trusted setup consists of a common random string. However, there is also an additional untrusted setup in which the verifier chooses a public/secret key needed to generate/verify proofs, respectively. We require that zero-knowledge holds even if the public key is chosen maliciously by the verifier. Such reusable MDV-NIZKs were recently constructed under the "one-more ODH" assumption, but constructions under CDH/LWE/LPN remained open. In this work, we give new constructions of (reusable) DV-NIZKs and MDV-NIZKs using generic primitives that can be instantiated under CDH, LWE, or LPN.
机译:NP的非交互式零知识参数(NIZK)是重要的密码原语,但是我们目前仅在一些特定假设下具有实例化。值得注意的是,我们缺少学习有错误(LWE)假设,Diffie-Hellman(CDH / DDH)假设和学习与噪声的平价(LPN)假设的构造。在本文中,我们研究了将NIZK放宽到指定验证者设置(DV-NIZK)的情况,在该设置中,受信任的设置会为验证者生成一个公共参考字符串以及一个秘密密钥。我们需要可重用的方案,该方案允许验证者重用秘密密钥来验证许多不同的证明,并且即使恶意证明者知道各种证明被接受还是被拒绝,合理性也应保持。这种可重复使用的DV-NIZK最近是在CDH假设下构建的,但是,无论它们是否也可以在LWE或LPN下构建,都是公开的。我们还考虑将可重复使用的DV-NIZK扩展到恶意的指定验证者设置(MDV-NIZK)。在此设置中,唯一受信任的设置由公共随机字符串组成。但是,还有另外一种不受信任的设置,在该设置中,验证者分别选择生成/验证证明所需的公共/秘密密钥。即使验证者恶意选择了公钥,我们也要求拥有零知识。此类可重复使用的MDV-NIZK最近是在“一个以上的ODH”假设下构建的,但CDH / LWE / LPN下的构建仍处于开放状态。在这项工作中,我们使用可以在CDH,LWE或LPN下实例化的通用原语,给出了(可重用的)DV-NIZK和MDV-NIZK的新构造。



  • 外文文献
  • 中文文献
  • 专利


京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号