Conventional hash functions are often inefficient in zero-knowledge proof settings, leading to design of several ZK-friendly hash functions. On the other hand, lookup arguments have recently been incorporated into zero-knowledge protocols, allowing for more efficient handling of “ZK-unfriendly” operations, and hence ZK-friendly hash functions based on lookup tables. In this paper, we propose a new ZK-friendly hash function, dubbed \(\textsf{Polocolo}\) , that employs an S-box constructed using power residues. Our approach reduces the numbers of gates required for table lookups, in particular, when combined with Plonk, allowing one to use such nonlinear layers over multiple rounds. We also propose a new MDS matrix for the linear layer of \(\textsf{Polocolo}\) . In this way, \(\textsf{Polocolo}\) requires fewer Plonk gates compared to the state-of-the-art ZK-friendly hash functions. For example, when \(t = 8\) , \(\textsf{Polocolo}\) requires \(21\%\) less Plonk gates compared to Anemoi, which is currently the most efficient ZK-friendly hash function, where t denotes the size of the underlying permutation in blocks of \(\mathbb {F}_p\) . For \(t = 3\) , \(\textsf{Polocolo}\) requires \(24\%\) less Plonk gates than Reinforced Concrete, which is one of the recent lookup-based ZK-friendly hash functions.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

\(\textsf{Polocolo}\) : A ZK-Friendly Hash Function Based on S-Boxes Using Power Residues

  • Jincheol Ha,
  • Seongha Hwang,
  • Jooyoung Lee,
  • Seungmin Park,
  • Mincheol Son

摘要

Conventional hash functions are often inefficient in zero-knowledge proof settings, leading to design of several ZK-friendly hash functions. On the other hand, lookup arguments have recently been incorporated into zero-knowledge protocols, allowing for more efficient handling of “ZK-unfriendly” operations, and hence ZK-friendly hash functions based on lookup tables. In this paper, we propose a new ZK-friendly hash function, dubbed \(\textsf{Polocolo}\) , that employs an S-box constructed using power residues. Our approach reduces the numbers of gates required for table lookups, in particular, when combined with Plonk, allowing one to use such nonlinear layers over multiple rounds. We also propose a new MDS matrix for the linear layer of \(\textsf{Polocolo}\) . In this way, \(\textsf{Polocolo}\) requires fewer Plonk gates compared to the state-of-the-art ZK-friendly hash functions. For example, when \(t = 8\) , \(\textsf{Polocolo}\) requires \(21\%\) less Plonk gates compared to Anemoi, which is currently the most efficient ZK-friendly hash function, where t denotes the size of the underlying permutation in blocks of \(\mathbb {F}_p\) . For \(t = 3\) , \(\textsf{Polocolo}\) requires \(24\%\) less Plonk gates than Reinforced Concrete, which is one of the recent lookup-based ZK-friendly hash functions.