On subversion-resistant SNARKs
… of zk-SNARKs as possible, we will start with non-subversion-resistant security definitions …
three different algorithms also in the non-subversion-resistant case. As motivated in Sect. 4.1…
three different algorithms also in the non-subversion-resistant case. As motivated in Sect. 4.1…
Subversion-resistant simulation (knowledge) sound NIZKs
K Baghery - Cryptography and Coding: 17th IMA International …, 2019 - Springer
… By considering the summarized subversion-resistant constructions, one … non-subversion-resistant
simulation-extractable zk-SNARKs, … Table 1 summarizes current subversion-resistant …
simulation-extractable zk-SNARKs, … Table 1 summarizes current subversion-resistant …
Subversion-zero-knowledge SNARKs
G Fuchsbauer - Public-Key Cryptography–PKC 2018: 21st IACR …, 2018 - Springer
… For completeness we give a subversion-resistant analogue for knowledge soundness (not
considered in [BFS16]), as this is the relevant notion for SNARKs. We modify game \(\mathrm{…
considered in [BFS16]), as this is the relevant notion for SNARKs. We modify game \(\mathrm{…
Subversion-resistant quasi-adaptive NIZK and applications to modular zk-SNARKs
B Abdolmaleki, D Slamanig - International Conference on Cryptology and …, 2021 - Springer
… on (SE) subversion zk-SNARKS represent an important step … As in [2] in context of subversion
zk-SNARKs, we also need … We note, however, that there are also subversion zk-SNARKs […
zk-SNARKs, we also need … We note, however, that there are also subversion zk-SNARKs […
[PDF][PDF] Unbounded Simulation-Sound Subversion Resistant Quasi-Adaptive NIZK Proofs and Applications to Modular zk-SNARKs.
B Abdolmaleki, D Slamanig - IACR Cryptol. ePrint Arch., 2020 - scholar.archive.org
… Roughly speaking, we show how one can make the unbounded SS QA-NIZK of [KW15]
subversion resistant by slightly changing the CRS to be publicly verifiable defining a new Vcrs …
subversion resistant by slightly changing the CRS to be publicly verifiable defining a new Vcrs …
Lift-and-shift: obtaining simulation extractable subversion and updatable SNARKs generically
… them on top of subversionresistant zk-SNARKs, they followed an … For instance, the CRS for
Pinocchio zk-SNARKs [96] was … up with a subversion-resistant zk-SNARK with a polynomial …
Pinocchio zk-SNARKs [96] was … up with a subversion-resistant zk-SNARK with a polynomial …
[PDF][PDF] Sok: Lifting transformations for simulation extractable subversion and updatable snarks
B Abdolmaleki, S Ramacher… - The 3rd ZKProof …, 2020 - docs.zkproof.org
… on top of subversion-resistant zk-SNARKs, they … SNARKs [PHGR13] was generated in
a large “ceremony” [BGG19]. Coincidentally, they end up with a subversion-resistant zk-SNARK …
a large “ceremony” [BGG19]. Coincidentally, they end up with a subversion-resistant zk-SNARK …
Subversion-resistant commitment schemes: definitions and constructions
K Baghery - Security and Trust Management: 16th International …, 2020 - Springer
… on constructing subversion-resistant commitment schemes, by showing that some combinations
of notions are not compatible while presenting subversion-resistant constructions that …
of notions are not compatible while presenting subversion-resistant constructions that …
Benchmarking the setup of updatable zk-SNARKs
K Baghery, A Mertens, M Sedaghat - International Conference on …, 2023 - Springer
… We adopt the definition of subversion-resistant and updatable zk-SNARKs from [2, 27].
Let \(\mathcal {R}\) be a relation generator, such that \(\mathcal {R}(1^\lambda )\) returns a …
Let \(\mathcal {R}\) be a relation generator, such that \(\mathcal {R}(1^\lambda )\) returns a …