Lunar: a Toolbox for More Efficient Universal and Updatable zkSNARKs and Commit-and-Prove Extensions

Lunar: a Toolbox for More Efficient Universal and Updatable zkSNARKs and Commit-and-Prove Extensions
复制标题

Lunar:更高效的通用和可更新 zkSNARK 以及提交和证明扩展的工具箱

DOI:
--
复制
发表时间:
2020
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Martin Armbrecht
Martin Armbrecht
中科院分区:
--
文献类型:
--
作者:
Michael B Dreifke;M. Fröba;Martin Armbrecht

文献摘要

被引文献

相似文献

我们解决了构建 zkSNARK 的问题,其 SRS 是通用的(对大小限制内的所有关系都有效)并且可更新——一组动态参与者可以无限期地为其添加秘密随机性,从而增加对设置的信心。我们研究正式的框架和技术,以设计具有线性大小 SRS 及其提交和证明变体的高效通用可更新 zkSNARK。我们实现了具有不同权衡的 zkSNARK 集合。与算术电路证明的现有技术相比,我们的结构之一实现了最小的证明尺寸和证明时间。该方案支持的语言是本工作引入的 R1CS 的变体,称为 R1CS-lite。我们的另一个结构直接支持标准 R1CS,并改进了之前的工作,实现了此类约束系统的最快证明时间。我们通过结合不同的贡献来实现这一结果:(1)一种新的代数风格的 IOP 变体,我们称之为多项式全息 IOP(PHP),(2)一个新的编译器,它将我们的 PHP 与用于提交多项式的提交和证明 zkSNARK 相结合,(3)这些用于多项式的 CP-SNARK 的基于配对的实现,(4)用于 R1CS 和 R1CS-lite 的 PHP 构造, (5) 编译器的一个变体,它产生一个提交并证明的通用 zkSNARK。
We address the problem of constructing zkSNARKs whose SRS is universal—valid for all relations within a size-bound—and updatable—a dynamic set of participants can add secret randomness to it indefinitely thus increasing confidence in the setup. We investigate formal frameworks and techniques to design efficient universal updatable zkSNARKs with linear-size SRS and their commit-and-prove variants. We achieve a collection of zkSNARKs with different tradeoffs. One of our constructions achieves the smallest proof size and proving time compared to the state of art for proofs for arithmetic circuits. The language supported by this scheme is a variant of R1CS, called R1CS-lite, introduced by this work. Another of our constructions supports directly standard R1CS and improves on previous work achieving the fastest proving time for this type of constraint systems. We achieve this result via the combination of different contributions: (1) a new algebraicallyflavored variant of IOPs that we call Polynomial Holographic IOPs (PHPs), (2) a new compiler that combines our PHPs with commit-and-prove zkSNARKs for committed polynomials, (3) pairingbased realizations of these CP-SNARKs for polynomials, (4) constructions of PHPs for R1CS and R1CS-lite, (5) a variant of the compiler that yields a commit-and-prove universal zkSNARK.