Amortized Efficient zk-SNARK from Linear-Only RLWE Encodings

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

2

초록

This paper addresses a new lattice-based designatedzk-SNARK having the smallest proof size in the amortized sense,from the linear-only ring learning with the error (RLWE) encod-ings. We first generalize a quadratic arithmetic programming(QAP) over a finite field to a ring-variant over a polynomialring Zp[X]/(XN + 1) with a power of two N. Then, wepropose a zk-SNARK over this ring with a linear-only encodingassumption on RLWE encodings. From the ring isomorphismZp[X]/(XN + 1) ∼= ZpN , the proposed scheme packs multiplemessages from Zp, resulting in much smaller amortized proofsize compared to previous works. In addition, we present a refined analysis on the noise floodingtechnique based on the Hellinger divergence instead of theconventional statistical distance, which reduces the size of a proof. In particular, our proof size is 276.5 KB and the amortizedproof size is only 156 bytes since our protocol allows to batchN proofs into a single proof. Therefore, we achieve the smallestamortized proof size in the category of lattice-based zk-SNARKsand comparable proof size in the (pre-quantum) zk-SNARKscategory.

키워드

Post-quantum cryptographyRLWESNARKzero-knowledge proofsSECURITYLATTICES
제목
Amortized Efficient zk-SNARK from Linear-Only RLWE Encodings
저자
Chung, HeewonKim, DongwooKim, Jeong HanKim, Jiseung
DOI
10.23919/JCN.2023.000012
발행일
2023-06
유형
Article
저널명
Journal of Communications and Networks
25
3
페이지
271 ~ 284