Chainable Functional Commitments for Unbounded-Depth Circuits

被引:8
|
作者
Balbas, David [1 ,2 ]
Catalano, Dario [3 ]
Fiore, Dario [1 ]
Lai, Russell W. F. [4 ]
机构
[1] IMDEA Software Inst, Madrid, Spain
[2] Univ Politecnica Madrid, Madrid, Spain
[3] Univ Catania, Catania, Italy
[4] Aalto Univ, Espoo, Finland
来源
THEORY OF CRYPTOGRAPHY, TCC 2023, PT III | 2023年 / 14371卷
基金
欧洲研究理事会;
关键词
ZERO-KNOWLEDGE SETS;
D O I
10.1007/978-3-031-48621-0_13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A functional commitment (FC) scheme allows one to commit to a vector x and later produce a short opening proof of (f, f(x)) for any admissible function f. Since their inception, FC schemes supporting ever more expressive classes of functions have been proposed. In this work, we introduce a novel primitive that we call chainable functional commitment (CFC), which extends the functionality of FCs by allowing one to 1) open to functions of multiple inputs f( x(1),..., x(m)) that are committed independently, 2) while preserving the output also in committed form. We show that CFCs for quadratic polynomial maps generically imply FCs for circuits. Then, we efficiently realize CFCs for quadratic polynomials over pairing groups and lattices, resulting in the first FC schemes for circuits of unbounded depth based on either pairingbased or lattice-based falsifiable assumptions. Our FCs require fixing a-priori only the maximal width of the circuit to be evaluated, and have opening proof size depending only on the circuit depth. Additionally, our FCs feature other nice properties such as being additively homomorphic and supporting sublinear-time verification after offline preprocessing. Using a recent transformation that constructs homomorphic signatures (HS) from FCs, we obtain the first pairing- and lattice-based realisations of HS for bounded-width, but unbounded-depth, circuits. Prior to this work, the only HS for general circuits is lattice-based and requires bounding the circuit depth at setup time.
引用
收藏
页码:363 / 393
页数:31
相关论文
共 6 条
  • [1] Succinct Functional Commitments for Circuits from k-Lin
    Wee, Hoeteck
    Wu, David J.
    ADVANCES IN CRYPTOLOGY, PT II, EUROCRYPT 2024, 2024, 14652 : 280 - 310
  • [2] Vector and Functional Commitments from Lattices
    Peikert, Chris
    Pepin, Zachary
    Sharp, Chad
    THEORY OF CRYPTOGRAPHY, TCC 2021, PT III, 2021, 13044 : 480 - 511
  • [3] Succinct Vector, Polynomial, and Functional Commitments from Lattices
    Wee, Hoeteck
    Wu, David J.
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2023, PT III, 2023, 14006 : 385 - 416
  • [4] Additive-Homomorphic Functional Commitments and Applications to Homomorphic Signatures
    Catalano, Dario
    Fiore, Dario
    Tucker, Ida
    ADVANCES IN CRYPTOLOGY- ASIACRYPT 2022, PT IV, 2022, 13794 : 159 - 188
  • [5] Concise ID-based mercurial functional commitments and applications to zero-knowledge sets
    Wu, Chunhui
    Chen, Xiaofeng
    Susilo, Willy
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2020, 19 (04) : 453 - 464
  • [6] Concise ID-based mercurial functional commitments and applications to zero-knowledge sets
    Chunhui Wu
    Xiaofeng Chen
    Willy Susilo
    International Journal of Information Security, 2020, 19 : 453 - 464