SnarkPack: Practical SNARK Aggregation

SnarkPack: Practical SNARK Aggregation
复制标题

SnarkPack:实用的 SNARK 聚合

DOI:
--
复制
发表时间:
2021
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Anca Nitulescu
Anca Nitulescu
中科院分区:
--
文献类型:
--
作者:
Nicolas Gailly;Mary Maller;Anca Nitulescu

文献摘要

被引文献

相似文献

。零知识Snarks(ZK-Snarks)是一种非交互的证明系统,具有简短而有效的(ffifi)可验证的证明。ZK-snark被广泛用于分散的系统,以解决隐私和可扩展性方面的问题。其中一个主要的应用是区块链,其中snark被用来证明具有私有输入的计算,并减少链上占用的fi验证和交易规模。我们设计并实现了SnarkPack,这是一种新的证明方法,它通过聚合的方式进一步减少了Snark证明的规模。我们的目标是提供一个现成的解决方案,在以下意义上是实用的:(1)它与现有的已部署系统兼容,(2)它不需要任何额外的设置。(2)我们的目标是提供一种实用的ff解决方案:(1)与现有的已部署系统兼容;(2)不需要任何额外的设置。SnarkPack被设计为与Groth16方案一起工作,并且具有对数大小的证明和在对数时间内运行的Verifier以待聚集的证明的数量。最重要的是,SnarkPack重用了来自Groth16系统的公共参数,因此它不需要单独的可信设置过程。我们建设的关键工具是一个新的承诺计划,它使用两个现有的“tau的力量”仪式记录作为公共参数。承诺方案允许我们实例化Büunz等人的内积配对变元(IPP)的新的优化版本。而不需要额外的可信设置。SnarkPack可以在8.7s内聚合8192个证明,并在163ms内验证它们,包括非序列化时间,产生的Verifi阳离子机制比批处理和fi领域中以前的解决方案快得多。
. Zero-knowledge SNARKs (zk-SNARKs) are non-interactive proof systems with short and efficiently verifiable proofs. zk-SNARKs are widely used in decentralised systems to address privacy and scalability concerns. One of the main applications is the blockchain, were SNARKs are used to prove computations with private inputs and reduce on-chain footprint verification and transaction sizes. We design and implement SnarkPack, a new argument that further reduces the size of SNARK proofs by means of aggregation. Our goal is to provide an off-the-shelf solution that is practical in the following sense: (1) it is compatible with existing deployed systems, (2) it does not require any extra setup. SnarkPack is designed to work with Groth16 scheme and has logarithmic size proofs and a verifier that runs in logarithmic time in the number of proofs to be aggregated. Most importantly, SnarkPack reuses the public parameters from Groth16 system, so it does not require a separate trusted setup ceremony. The key tool for our construction is a new commitment scheme that uses as public parameters two existing ”powers of tau” ceremony transcripts. The commitment scheme allows us to in-stantiate a new optimised version of the inner product pairing arguments (IPP) of B¨unz et al. without additional trusted setup. SnarkPack can aggregate 8192 proofs in 8.7s and verify them in 163ms, including un-serialization time, yielding a verification mechanism that is exponentially faster than batching and previous solutions in the field.