Hyperplonk: Plonk with linear-time prover and high-degree custom gates

B Chen, B Bünz, D Boneh, Z Zhang - … on the Theory and Applications of …, 2023 - Springer
Plonk is a widely used succinct non-interactive proof system that uses univariate polynomial
commitments. Plonk is quite flexible: it supports circuits with low-degree “custom” gates as …

Proofs, arguments, and zero-knowledge

J Thaler - Foundations and Trends® in Privacy and Security, 2022 - nowpublishers.com
Interactive proofs (IPs) and arguments are cryptographic protocols that enable an untrusted
prover to provide a guarantee that it performed a requested computation correctly …

Eos: Efficient Private Delegation of {zkSNARK} Provers

A Chiesa, R Lehmkuhl, P Mishra, Y Zhang - 32nd USENIX Security …, 2023 - usenix.org
Succinct zero knowledge proofs (ie zkSNARKs) are powerful cryptographic tools that enable
a prover to convince a verifier that a given statement is true without revealing any additional …

Witness-succinct universally-composable snarks

C Ganesh, Y Kondi, C Orlandi, M Pancholi… - … Conference on the …, 2023 - Springer
Abstract Zero-knowledge Succinct Non-interactive ARguments of Knowledge (zkSNARKs)
are becoming an increasingly fundamental tool in many real-world applications where the …

{VeriZexe}: Decentralized Private Computation with Universal Setup

AL Xiong, B Chen, Z Zhang, B Bünz, B Fisch… - 32nd USENIX Security …, 2023 - usenix.org
Traditional blockchain systems execute program state transitions on-chain, requiring each
network node participating in state-machine replication to re-compute every step of the …

SymmeProof: Compact zero-knowledge argument for blockchain confidential transactions

S Gao, Z Peng, F Tan, Y Zheng… - IEEE Transactions on …, 2022 - ieeexplore.ieee.org
To reduce the transmission cost of blockchain confidential transactions, we propose
SymmeProof, a novel communication efficient non-interactive zero-knowledge range proof …

Baloo: nearly optimal lookup arguments

A Zapico, A Gabizon, D Khovratovich… - Cryptology ePrint …, 2022 - eprint.iacr.org
We present Baloo, the first protocol for lookup tables where the prover work is linear on the
amount of lookups and independent of the size of the table. Baloo is built over the lookup …

Algebraic group model with oblivious sampling

H Lipmaa, R Parisella, J Siim - Theory of Cryptography Conference, 2023 - Springer
In the algebraic group model (AGM), an adversary has to return with each group element a
linear representation with respect to input group elements. In many groups, it is easy to …

Sumcheck arguments and their applications

J Bootle, A Chiesa, K Sotiraki - … in Cryptology–CRYPTO 2021: 41st Annual …, 2021 - Springer
We introduce a class of interactive protocols, which we call sumcheck arguments, that
establishes a novel connection between the sumcheck protocol (Lund et al. JACM 1992) …

Counting vampires: from univariate sumcheck to updatable ZK-SNARK

H Lipmaa, J Siim, M Zając - International Conference on the Theory and …, 2022 - Springer
We propose a univariate sumcheck argument Count of essentially optimal communication
efficiency of one group element. While the previously most efficient univariate sumcheck …