Succinct Vector, Polynomial, and Functional Commitments from Lattices

被引:21
|
作者
Wee, Hoeteck [1 ,2 ]
Wu, David J. [3 ]
机构
[1] NTT Res, Sunnyvale, CA USA
[2] ENS, Paris, France
[3] Univ Texas Austin, Austin, TX 78712 USA
来源
ADVANCES IN CRYPTOLOGY - EUROCRYPT 2023, PT III | 2023年 / 14006卷
关键词
ZERO-KNOWLEDGE SETS; ARGUMENTS;
D O I
10.1007/978-3-031-30620-4_13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Vector commitment schemes allow a user to commit to a vector of values x epsilon {0, 1}(l) and later, open up the commitment to a specific set of positions. Both the size of the commitment and the size of the opening should be succinct (i.e., polylogarithmic in the length l of the vector). Vector commitments and their generalizations to polynomial commitments and functional commitments are key building blocks for many cryptographic protocols. We introduce a new framework for constructing non-interactive lattice-based vector commitments and their generalizations. A simple instantiation of our framework yields a new vector commitment scheme from the standard short integer solution (SIS) assumption that supports private openings and large messages. We then show how to use our framework to obtain the first succinct functional commitment scheme that supports openings with respect to arbitrary bounded-depth Boolean circuits. In this scheme, a user commits to a vector x epsilon {0, 1}(l), and later on, open the commitment to any function f(x). Both the commitment and the opening are non-interactive and succinct: namely, they have size poly(lambda, d, log l), where lambda is the security parameter and d is the depth of the Boolean circuit computing f. Previous constructions of functional commitments could only support constant-degree polynomials, or require a trusted online authority, or rely on non-falsifiable assumptions. The security of our functional commitment scheme is based on a new falsifiable family of "basis-augmented" SIS assumptions (BASIS) we introduce in this work. We also show how to use our vector commitment framework to obtain (1) a polynomial commitment scheme where the user can commit to a polynomial f. Z(q)[x] and subsequently open the commitment to an evaluation f(x) epsilon Z(q); and (2) an aggregatable vector (resp., functional) commitment where a user can take a set of openings to multiple indices (resp., function evaluations) and aggregate them into a single short opening. Both of these extensions rely on the same BASIS assumption we use to obtain our succinct functional commitment scheme.
引用
收藏
页码:385 / 416
页数:32
相关论文
共 16 条
  • [1] Orbweaver: Succinct Linear Functional Commitments from Lattices
    Fisch, Ben
    Liu, Zeyu
    Vesely, Psi
    ADVANCES IN CRYPTOLOGY - CRYPTO 2023, PT II, 2023, 14082 : 106 - 131
  • [2] Vector and Functional Commitments from Lattices
    Peikert, Chris
    Pepin, Zachary
    Sharp, Chad
    THEORY OF CRYPTOGRAPHY, TCC 2021, PT III, 2021, 13044 : 480 - 511
  • [3] Succinct Functional Commitments for Circuits from k-Lin
    Wee, Hoeteck
    Wu, David J.
    ADVANCES IN CRYPTOLOGY, PT II, EUROCRYPT 2024, 2024, 14652 : 280 - 310
  • [4] Vector Commitments and Their Applications
    Catalano, Dario
    Fiore, Dario
    PUBLIC-KEY CRYPTOGRAPHY - PKC 2013, 2013, 7778 : 55 - 72
  • [5] Functional Commitments for All Functions, with Transparent Setup and from SIS
    de Castro, Leo
    Peikert, Chris
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2023, PT III, 2023, 14006 : 287 - 320
  • [6] Non-malleable Vector Commitments via Local Equivocability
    Rotem, Lior
    Segev, Gil
    JOURNAL OF CRYPTOLOGY, 2023, 36 (04)
  • [7] Vector Commitments with Proofs of Smallness: Short Range Proofs and More
    Libert, Benoit
    PUBLIC-KEY CRYPTOGRAPHY, PT II, PKC 2024, 2024, 14602 : 36 - 67
  • [8] Chainable Functional Commitments for Unbounded-Depth Circuits
    Balbas, David
    Catalano, Dario
    Fiore, Dario
    Lai, Russell W. F.
    THEORY OF CRYPTOGRAPHY, TCC 2023, PT III, 2023, 14371 : 363 - 393
  • [9] Lattice-Based Functional Commitments: Fast Verification and Cryptanalysis
    Wee, Hoeteck
    Wu, David J.
    ADVANCES IN CRYPTOLOGY, ASIACRYPT 2023, PT V, 2023, 14442 : 201 - 235
  • [10] Additive-Homomorphic Functional Commitments and Applications to Homomorphic Signatures
    Catalano, Dario
    Fiore, Dario
    Tucker, Ida
    ADVANCES IN CRYPTOLOGY- ASIACRYPT 2022, PT IV, 2022, 13794 : 159 - 188