TY - GEN
T1 - Non-malleable zero knowledge
T2 - 9th International Conference on Security and Cryptography for Networks, SCN 2014
AU - Jain, Abhishek
AU - Pandey, Omkant
N1 - Publisher Copyright:
© Springer International Publishing Switzerland 2014.
PY - 2014
Y1 - 2014
N2 - This paper deals with efficient non-malleable zero-knowledge proofs for NP, based on general assumptions. We construct a simulationsound zero-knowledge (ZK) protocol for NP, based only on the black-box use of one-way functions. Constructing such a proof system has been an open question ever since the original work of Dolev, Dwork, and Naor [18]. In addition to the feasibility result, our protocol has a constant number of rounds, which is asymptotically optimal. Traditionally, the term non-malleable zero-knowledge (NmZK) refers to the original definition of [18]; but today it is used loosely to also refer to simulation-soundness (SimSound) [51], and simulation-extractability (SimExt) [47]. While SimExt implies NmZK, the common perception is that SimExt is strongest of the three notions. However, very few results about their exact relationship are known. In the second part of this work, we provide further results about the exact relationship between these notions. We show that in the “static” case, if an NmZK protocol is also an argument-of-knowledge, then it is in fact SimExt. Furthermore, in the most strict sense of the definition, SimSound does not necessarily follow from SimExt. These results are somewhat surprising because they are opposite to the common perception that SimExt is the strongest of the three notions.
AB - This paper deals with efficient non-malleable zero-knowledge proofs for NP, based on general assumptions. We construct a simulationsound zero-knowledge (ZK) protocol for NP, based only on the black-box use of one-way functions. Constructing such a proof system has been an open question ever since the original work of Dolev, Dwork, and Naor [18]. In addition to the feasibility result, our protocol has a constant number of rounds, which is asymptotically optimal. Traditionally, the term non-malleable zero-knowledge (NmZK) refers to the original definition of [18]; but today it is used loosely to also refer to simulation-soundness (SimSound) [51], and simulation-extractability (SimExt) [47]. While SimExt implies NmZK, the common perception is that SimExt is strongest of the three notions. However, very few results about their exact relationship are known. In the second part of this work, we provide further results about the exact relationship between these notions. We show that in the “static” case, if an NmZK protocol is also an argument-of-knowledge, then it is in fact SimExt. Furthermore, in the most strict sense of the definition, SimSound does not necessarily follow from SimExt. These results are somewhat surprising because they are opposite to the common perception that SimExt is the strongest of the three notions.
UR - https://www.scopus.com/pages/publications/84927593979
U2 - 10.1007/978-3-319-10879-7_25
DO - 10.1007/978-3-319-10879-7_25
M3 - Conference contribution
AN - SCOPUS:84927593979
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 435
EP - 454
BT - Security and Cryptography for Networks - 9th International Conference, SCN 2014, Proceedings
A2 - Abdalla, Michel
A2 - de Prisco, Roberto
PB - Springer Verlag
Y2 - 3 September 2014 through 5 September 2014
ER -