In applications involving zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARK), there often exists a requirement for the proof system to be combined with encryption. As a typical example, a user may want to encrypt his identity, while proving that his identity satisfies a given authorized function (e.g. credit checks). However, depending on the functionalities and message types, including encryption constraints inside the SNARK input may lead to impractically large proving time and CRS sizes. In this paper, we propose a SNARK-compatible verifiable encryption or in short SAVER, which is a novel encrypt-and-prove approach to modularize the encryption apart from SNARK circuits. The SAVER holds many useful properties. It is SNARK-compatible: the encryption scheme is combined with an existing SNARK, in a way that the encryptor can prove pre-defined properties while encrypting the message apart from SNARKs. It is additively-homomorphic: the ciphertext holds a homomorphic property by following an ElGamal-like design. It is a verifiable encryption: one can verify arbitrary properties of encrypted messages by using the combined SNARK. It provides a verifiable decryption: the public can verify that the plaintext claimed by decryptor is equal to the original decryption of ciphertext. It also provides rerandomization: the proof and the ciphertext can be rerandomized as independent objects so that even the encryptor (or prover) herself cannot identify the origin.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SAVER: SNARK-Compatible Verifiable Encryption

  • Jiwon Lee,
  • Jaekyoung Choi,
  • Jihye Kim,
  • Hyunok Oh

摘要

In applications involving zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARK), there often exists a requirement for the proof system to be combined with encryption. As a typical example, a user may want to encrypt his identity, while proving that his identity satisfies a given authorized function (e.g. credit checks). However, depending on the functionalities and message types, including encryption constraints inside the SNARK input may lead to impractically large proving time and CRS sizes. In this paper, we propose a SNARK-compatible verifiable encryption or in short SAVER, which is a novel encrypt-and-prove approach to modularize the encryption apart from SNARK circuits. The SAVER holds many useful properties. It is SNARK-compatible: the encryption scheme is combined with an existing SNARK, in a way that the encryptor can prove pre-defined properties while encrypting the message apart from SNARKs. It is additively-homomorphic: the ciphertext holds a homomorphic property by following an ElGamal-like design. It is a verifiable encryption: one can verify arbitrary properties of encrypted messages by using the combined SNARK. It provides a verifiable decryption: the public can verify that the plaintext claimed by decryptor is equal to the original decryption of ciphertext. It also provides rerandomization: the proof and the ciphertext can be rerandomized as independent objects so that even the encryptor (or prover) herself cannot identify the origin.