Proofs for Inner Pairing Products and Applications
Proofs for Inner Pairing Products and Applications
复制标题
DOI:
10.1007/978-3-030-92078-4_3
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Benedikt Bünz;Mary Maller;Pratyush Mishra;Nirvan Tyagi;Psi Vesely
中科院分区:
文献类型:
--
作者:
Benedikt Bünz;Mary Maller;Pratyush Mishra;Nirvan Tyagi;Psi Vesely
We present a generalized inner product argument and demonstrate its applications to pairing-based languages. We apply our generalized argument to prove that an inner pairing product is correctly evaluated with respect to committed vectors ofnsource group elements. With a structured reference string (SRS), we achieve a logarithmic-time verifier whose work is dominated bytarget group exponentiations. Proofs are of sizetarget group elements, computed using 6npairings and 4nexponentiations in each source group.We apply our inner product arguments to build the first polynomial commitment scheme with succinct (logarithmic) verification,prover complexity for degreedpolynomials (not including the cost to evaluate the polynomial), and a SRS of size. Concretely, this means that for, producing an evaluation proof in our protocol isfaster than doing so in the KZG commitment scheme, and the CRS in our protocol issmaller: 13 MB vs 13 GB for KZG.As a second application, we introduce an argument for aggregatingnGroth16 zkSNARKs into ansized proof. Our protocol is significantly faster () than aggregating SNARKs via recursive composition: we aggregateproofs in 25 min, versus 90 proofs via recursive composition. Finally, we further apply our aggregation protocol to construct a low-memory SNARK for machine computations that does not rely on recursive composition. For a computation that requires timeTand spaceS, our SNARK produces proofs in space, which is significantly more space efficient than a monolithic SNARK, which requires space.