Languages wit h Efficient Zer o-Knowledge PCP are in SZK i SZK - - PowerPoint PPT Presentation

languages wit h efficient zer o knowledge pcp are in szk
SMART_READER_LITE
LIVE PREVIEW

Languages wit h Efficient Zer o-Knowledge PCP are in SZK i SZK - - PowerPoint PPT Presentation

Languages wit h Efficient Zer o-Knowledge PCP are in SZK i SZK MOHAMMAD MA HMOODY (CORNELL) DAVID XIAO (LIAFA) Probabilistically y Checkable y Proofs (PCPs) accept / reject Z Zero-Knowledge PC K l d PC CPs CP statisti ically


slide-1
SLIDE 1

Languages wit Efficient Zer i SZK are in SZK

MOHAMMAD MA DAVID XIAO

h

  • -Knowledge PCP

HMOODY (CORNELL) (LIAFA)

slide-2
SLIDE 2

Probabilistically Proofs (PCPs) y Checkable y

accept / reject

slide-3
SLIDE 3

Z K l d PC Zero-Knowledge PC

actual statisti (default Def: View of any efficient verifier can be efficientl execution (default Def: View of any efficient verifier can be efficientl

  • Harder to achieve zero‐knowledge PCPs (than pr
  • Easier to achieve sound PCPs (than provers)
  • Easier to achieve sound PCPs (than provers).

[Kilian‐Petrank‐Tardos’97] NEXP has (statistical) ze I h tl f l i l l th ( f

  • Inherently of super‐polynomial length (even for

CP CPs

generated ically close in this talk) SIM y “simulated” (similar to ZK interactive proofs) generated efficiently in this talk) y simulated (similar to ZK interactive proofs) rovers) verifier can read any PCP answers. ero‐knowledge PCPs NP) NP)

slide-4
SLIDE 4

Efficient Zero-Kn Efficient Zero-Kn nowledge PCPs nowledge PCPs

accept / reject

slide-5
SLIDE 5

Main Q estion A th efficie Main Question: Are there efficient ( t ti ti l) ZK PCP f NP ? nt (statistical) ZK PCPs for NP ?

slide-6
SLIDE 6

Motivation: Basin Motivation Basin Proof Hardware

[Kat07, MS08, CGS08,

ng Crypto on Tamper ng Crypto on Tamper

GKR08, GISVW10, Kol10, GIMS10, ... ]

slide-7
SLIDE 7

Motivation: Reset Zero-Knowledge

give me answer to q FORGET q and FORGET q and answer to p

ttable Statistical

answer to q d answer p d answer p

slide-8
SLIDE 8

Limits of Efficie Limits of Efficie Zero-Knowledge PC

Main Question: Are there efficient [Ishai‐M‐Sahai’12] Any language w [Ishai M Sahai 12] Any language w non‐adaptive verifier is in co‐AM Corollary: No efficient ZK for NP us l h l i l i hi unless the polynomial‐time hierarc

ent (statistical) ent (statistical) CPs?

t ZK PCPs for NP ? with an efficient ZK PCP using a with an efficient ZK PCP using a sing a non‐adaptive verifier h ll [BHZ’87] chy collapses [BHZ’87]

slide-9
SLIDE 9

Our Result

slide-10
SLIDE 10

Id b hi d Ideas behind th f d the proof

slide-11
SLIDE 11

Approach of [IMS’ Approach of [IMS’12] 12]

slide-12
SLIDE 12

Naïve Approach Naïve Approach

slide-13
SLIDE 13

Our Approach Our Approach

slide-14
SLIDE 14

Our Approach Our Approach

slide-15
SLIDE 15

Our Approach Our Approach

Conditional Entropy Approxim py pp in SZK [Vadhan’04] mation:

slide-16
SLIDE 16

Putting Things To Putting Things To

  • gether
  • gether
slide-17
SLIDE 17

Summary

Theorem: No efficient statistical Z hi h ll i th hierarchy collapses ‐‐ removing th Open: Characterize languages wit Conjecture: All of SZK (sufficient Open: Number of messages (2 or Open: Number of messages (2 or efficient PCP (hardware token) to ZK PCP for NP unless polynomial‐tim h d ti it b i f [IMS’12 he non‐adaptivity barrier of [IMS’12 th efficient ZK PCPs. to make compiler of [GOVW] efficie r 3 or 4) needed in addition to an r 3 or 4) needed in addition to an

  • get statistical zero‐knowledge for N
slide-18
SLIDE 18

Th k Thank Y ! You !