SAVER: Snark-friendly, Additively-homomorphic, and Verifiable Encryption and decryption with Rerandomization

SAVER: Snark-friendly, Additively-homomorphic, and Verifiable Encryption and decryption with Rerandomization
复制标题

SAVER:Snark 友好、加法同态、可验证的重新随机化加密和解密

DOI:
--
复制
发表时间:
2019
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Hyunok Oh
Hyunok Oh
中科院分区:
--
文献类型:
--
作者:
Jiwon Lee;Jaekyoung Choi;Jihye Kim;Hyunok Oh

文献摘要

被引文献

相似文献

.在基于配对的零知识简洁非交互式知识论证(zk-SNARK)中,经常存在将证明系统与加密相结合的要求。作为一个典型的例子,基于区块链的投票系统要求投票是保密的(使用加密),同时验证投票的有效性(使用zk-SNARKs)。在这些组合应用中,典型的解决方案是扩展zk-SNARK电路以包括加密代码。然而,加密算法中复杂的密码操作增加了电路大小,这导致不切实际的大的证明时间和CRS大小。在本文中,我们提出了SNARK友好的,加法同态的,可验证的加密和解密与Rerandomization或SAVER,这是一种新的方法,分离的加密从SNARK电路。SAVER中的加密具有许多有用的属性。这是一个友好的snark:加密与现有的基于配对的SNARK相结合,以这样的方式,加密器可以证明预定义的属性,同时除了SNARK之外加密消息。它是加法同态的:密文保持来自基于ElGamal的加密的同态属性。它是一种可验证的加密:人们可以通过连接SNARK系统来验证加密消息的任意属性。它提供了一个可验证的解密:任何没有秘密的人仍然可以验证解密的消息确实来自给定的密文。它提供了重新随机化:证明和密文可以被重新随机化为独立的对象,使得即使验证者(或证明者)自己也不能识别来源。对于代表性的应用,我们还提出了一个基于SAVER的Vote-SAVER,这是一个新颖的投票系统,投票人的秘密密钥只属于投票人自己。萨蒂斯满足了无收据(意味着选票隐私),个人可验证性(意味着不可否认性),投票可验证性,计票唯一性和选民匿名性。实验结果表明,我们的SAVER相对于Vote-SAVER关系的zk-SNARK证明时间为0.7s,加密时间为10 ms,CRS大小为16 MB。
. In the pairing-based zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARK), there often exists a requirement for the proof system to be combined with encryption. As a typical example, a blockchain-based voting system requires the vote to be confidential (using encryption), while verifying voting validity (using zk-SNARKs). In these combined applications, a typical solution is to extend the zk-SNARK circuit to include the encryption code. However, complex cryptographic operations in the encryption algorithm increase the circuit size, which leads to impractically large proving time and CRS size. In this paper, we propose SNARK-friendly, Additively-homomorphic, and Verifiable Encryption and decryption with Rerandomization or SAVER , which is a novel approach to detach the encryption from the SNARK circuit. The encryption in SAVER holds many useful properties. It is SNARK-friendly : the encryption is conjoined with an existing pairing-based SNARK, in a way that the encryptor can prove pre-defined properties while encrypting the message apart from the SNARK. It is additively-homomorphic : the ciphertext holds a homomorphic property from the ElGamal-based encryption. It is a verifiable encryption : one can verify arbitrary properties of encrypted messages by connecting with the SNARK system. It provides a verifiable decryption : anyone without the secret can still verify that the decrypted message is indeed from the given ciphertext. It provides rerandomization : the proof and the ciphertext can be rerandomized as independent objects so that even the encryptor (or prover) herself cannot identify the origin. For the representative application, we also propose a Vote-SAVER based on SAVER, which is a novel voting system where voter’s secret key lies only with the voter himself. The Vote-SAVER satisfies receipt-freeness (which implies ballot privacy), individual verifiability (which implies non-repudiation), vote verifiability, tally uniqueness, and voter anonymity. The experimental results show that our SAVER with respect to the Vote-SAVER relation yields 0.7s for zk-SNARK proving time and 10ms for encryption, with the CRS size of 16MB.