LaBRADOR: Compact Proofs for R1CS from Module-SIS.

IACR Cryptology ePrint Archive(2022)

引用 3|浏览2
暂无评分
摘要
The most compact quantum-safe proof systems for large circuits are PCP-type systems such as Ligero, Aurora, and Shockwave, that only use weak cryptographic assumptions, namely hash functions modeled as random oracles. One would expect that by allowing for stronger assumptions, such as the hardness of Module-SIS, it should be possible to design more compact proof systems. But alas, despite considerable progress in lattice-based proofs, no such proof system was known so far. We rectify this situation by introducing a Lattice-Based Recursively Amortized Demonstration Of R1CS (LaBRADOR), with more compact proof sizes than known hash-based proof systems. At the 128 bits security level, LaBRADOR proves knowledge of a solution for an R1CS mod 2 64 + 1 with 2 20 constraints, with a proof size of only 58 KB, an order of magnitude more compact than previous quantum-safe proofs.
更多
查看译文
关键词
r1cs,compact proofs,module-sis
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要