Delegation with Updatable Unambiguous Proofs and PPAD-Hardness
Lisa Yang MIT
Based on joint work with Yael Tauman Kalai and Omer Paneth
Delegation with Updatable Unambiguous Proofs and PPAD-Hardness - - PowerPoint PPT Presentation
Delegation with Updatable Unambiguous Proofs and PPAD-Hardness Lisa Yang MIT Based on joint work with Yael Tauman Kalai and Omer Paneth time computation = ? Delegation () = y Proof checks in time
Based on joint work with Yael Tauman Kalai and Omer Paneth
[Micali94]
[Paneth-Rothblum17]
[Canetti-Chen-Holmgren-Lombardi-Rothblum-Rothblum-Wichs19]
[Kalai-Zhang20]
[Kalai-Paneth-Y19] [Groth10, Lipma12, Gennaro-Gentry-Parno-Raykova12, Bitansky- Canetti-Chiesa-Tromer12, Bitansky-Chiesa-Ishai-Ostrovsky-Paneth13β¦] [Bitansky-Sanjam-Lin-Pass-Telang14,Canetti-Holmgren-Jain- Vaikuntanathan14,Koppula-Lewko-Waters14, Canetti- Holmgren16, Chen-Chow-Chung-Lai16]
Ξ π Ξ π+1
[Reingold-Rothblum-Rothblum]
For a bilinear group π» of order π = 2Ξ(π) and π½ = π(log π) given for random π β π» and π‘ β β€π it is hard to distinguish whether π’ = π‘2π½+1 or π’ is an independent random element in β€π.
[Kalai-Paneth-Y19]
polynomial space)
(non-uniform ETH) suffices
[Choudhuri-Hubacek-Kamath-Pietrzak-Rosen-Rothblum19]
[Abbot-Kane-Valiant04, Bitanski-Paneth-Rosen15, Hubacek-Yogev17] [Choudhuri-Hubacek-Kamath-Pietrzak-Rosen- Rothblum19, Ephraim-Freitag-Komargodski-Pass19] [Lombardi-Vaikuntanathan20, Kalai-Zhang20, Jawale-Khurana20] [Bitansky-Gerichter20]
Local extraction [Kalai-Paneth-Y19]
π·ππΆ β¦ π·π2 π·π1 π·0 π·ππΆ Verify Ξ πΆ β¦ π·π2 Verify Ξ 2 π·π1 Verify Ξ 1 π·0 Ξ β² Ξ 1 Ξ πΆ Ξ 2 β¦ πππ ππ π·ππβ1, Ξ π, π·ππ πβ[πΆ] replaces this with π·0, Ξ β², π·ππΆ
Ξ contains πΆ proofs Ξ π:π·ππβ1 β π·ππ
Ξ β² βͺ Ξ 1 + β―+ |Ξ πΆ|
π§ π¦
[Paneth-Rothblum17]
Homomorphic encryption
π§ π¦
Notion of local multilinearity!
Evaluate encryptions of (π΅π, πΆπ) such that πΊ Τ¦ π = π΅π β ππ + πΆπ π checks consistency using the Zero-Test
β²,πΆπ β²
β²,πΆπ β²
lisayang@mit.edu