
Snarky signatures: minimal signatures of knowledge from simulation-extractable snarks. (English) Zbl 1410.94077

Katz, Jonathan (ed.) et al., Advances in cryptology – CRYPTO 2017. 37th annual international cryptology conference, Santa Barbara, CA, USA, August 20–24, 2017. Proceedings. Part II. Cham: Springer. Lect. Notes Comput. Sci. 10402, 581-612 (2017).
Summary: We construct a pairing based simulation-extractable SNARK (SE-SNARK) that consists of only 3 group elements and has highly efficient verification. By formally linking SE-SNARKs to signatures of knowledge, we then obtain a succinct signature of knowledge consisting of only 3 group elements.SE-SNARKs enable a prover to give a proof that they know a witness to an instance in a manner which is: (1) succinct – proofs are short and verifier computation is small; (2) zero-knowledge – proofs do not reveal the witness; (3) simulation-extractable – it is only possible to prove instances to which you know a witness, even when you have already seen a number of simulated proofs.{ }We also prove that any pairing based signature of knowledge or SE-NIZK argument must have at least 3 group elements and 2 verification equations. Since our constructions match these lower bounds, we have the smallest size signature of knowledge and the smallest size SE-SNARK possible.
94A60 Cryptography


