Towards Non-Interactive Witness Hiding
Towards Non-Interactive Witness Hiding
复制标题
DOI:
10.1007/978-3-030-64375-1_22
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
Benjamin Kuykendall;Mark Zhandry
中科院分区:
文献类型:
--
作者:
Benjamin Kuykendall;Mark Zhandry
Witness hiding proofs require that the verifier cannot find a witness after seeing a proof. The exact round complexity needed for witness hiding proofs has so far remained an open question. In this work, we provide compelling evidence that witness hiding proofs are achievablenon-interactivelyfor wide classes of languages. We use non-interactive witness indistinguishable proofs as the basis for all of our protocols. We give four schemes in different settings under different assumptions:Auniversalnon-interactive proof that is witness hiding as long as any proof system, possibly an inefficient and/or non-uniform scheme, is witness hiding, has a known bound on verifier runtime, and has short proofs of soundness.Anon-uniformnon-interactive protocol justified under a worst-case complexity assumption that is witness hiding and efficient, but may not have short proofs of soundness.A new security analysis of thetwo-message argumentof Pass [Crypto 2003], showing witness hiding for any non-uniformly hard distribution. We propose a heuristic approach to removing the first message, yielding a non-interactive argument.A witness hiding non-interactive proof system for languages withunique witnesses, assuming the non-existence of a weak form of witness encryption for any language in.