Zero-Knowledge Sets With Short Proofs
TL;DR: The notion of trapdoor q -mercurial commitments (\ssr qTMCs), a notion of mercurial commitment that allows the sender to commit to an ordered sequence of exactly q messages, rather than to a single one is introduced.
read more
Abstract: Zero knowledge sets (ZKS), introduced by Micali, Rabin, and Kilian in 2003, allow a prover to commit to a secret set S in a way such that it can later prove, non interactively, statements of the form x ∈ S (or x ∉ S), without revealing any further information (on top of what explicitly revealed by the inclusion/exclusion statements above) on S, not even its size. Later, Chase abstracted away the Micali, Rabin, and Kilian's construction by introducing an elegant new variant of commitments that they called (trapdoor) mercurial commitments. Using this primitive, it was shown how to construct zero knowledge sets from a variety of assumptions (both general and number theoretic). This paper introduces the notion of trapdoor q -mercurial commitments (\ssr qTMCs), a notion of mercurial commitment that allows the sender to commit to an ordered sequence of exactly q messages, rather than to a single one. Following the previous work, it is shown how to construct ZKS from \ssr qTMCs and collision resistant hash functions. Then, it is presented an efficient realization of \ssr qTMCs that is secure under the so called Strong Diffie Hellman (SDH) assumption, a number theoretic conjecture recently introduced by Boneh and Boyen. Using such scheme as basic building block, it is obtained a construction of ZKS that allows for proofs that are much shorter with respect to the best previously known implementations. In particular, for an appropriate choice of the parameters, our proofs are up to 33% shorter for the case of proofs of membership, and up to 73% shorter for the case of proofs of nonmembership. Experimental tests confirm practical time performances.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
I and i
TL;DR: There is, I think, something ethereal about i —the square root of minus one, which seems an odd beast at that time—an intruder hovering on the edge of reality.
38.1K
Constant-size commitments to polynomials and their applications
Aniket Kate,Gregory M. Zaverucha,Ian Goldberg +2 more
- 05 Dec 2010
TL;DR: The polynomial commitment schemes are useful tools to reduce the communication cost in cryptographic protocols and are applied to four problems in cryptography: verifiable secret sharing, zero-knowledge sets, credentials and content extraction signatures.
Vector Commitments and Their Applications
Dario Catalano,Dario Fiore +1 more
- 26 Feb 2013
TL;DR: The study of a new primitive that allows to commit to an ordered sequence of q values in such a way that one can later open the commitment at specific positions (e.g., prove that mi is the i-th committed message).
New Publicly Verifiable Databases with Efficient Updates
TL;DR: A new VDB framework from vector commitment based on the idea of commitment binding is proposed that is not only public verifiable but also secure under the FAU attack and it is proved that the construction can achieve the desired security properties.
283
Concise mercurial vector commitments and independent zero-knowledge sets with short proofs
Benoît Libert,Moti Yung +1 more
- 09 Feb 2010
TL;DR: This paper describes a new qTMC scheme where hard and short position-wise openings, both, have constant size and shows how this scheme is amenable to constructing independent zero-knowledge sets (i.e., ZKS’s that prevent adversaries from correlating their set to the sets of honest provers, as defined by Gennaro and Micali).
References
I and i
TL;DR: There is, I think, something ethereal about i —the square root of minus one, which seems an odd beast at that time—an intruder hovering on the edge of reality.
38.1K
Random oracles are practical: a paradigm for designing efficient protocols
Mihir Bellare,Phillip Rogaway +1 more
- 01 Dec 1993
TL;DR: It is argued that the random oracles model—where all parties have access to a public random oracle—provides a bridge between cryptographic theory and cryptographic practice, and yields protocols much more efficient than standard ones while retaining many of the advantages of provable security.
5.7K
Non-Interactive and Information-Theoretic Secure Verifiable Secret Sharing
Torben P. Pedersen
- 11 Aug 1991
TL;DR: It is shown how to distribute a secret to n persons such that each person can verify that he has received correct information about the secret without talking with other persons.
2.9K
A Digital Signature Based on a Conventional Encryption Function
Ralph C. Merkle
- 16 Aug 1987
TL;DR: A new digital signature based only on a conventional encryption function (such as DES) is described which is as secure as the underlying encryption function -- the security does not depend on the difficulty of factoring and the high computational costs of modular arithmetic are avoided.
Short Signatures Without Random Oracles
Dan Boneh,Xavier Boyen +1 more
- 02 May 2004
TL;DR: The Strong Diffie-Hellman assumption has been used in this article to construct a short signature scheme which is existentially unforgeable under a chosen message attack without using random oracles.
Related Papers (5)
[...]
Silvio Micali,Michael O. Rabin,J. Kilian +2 more
- 11 Oct 2003
Siavosh Benabbas,Rosario Gennaro,Yevgeniy Vahlis +2 more
- 14 Aug 2011