Ze Zero-Kn Knowledge Pr Proofs
- n
- n Se
Secr cret-Sh Shared Data ta
via via Fully Lin inear ear PCPs PCPs
Dan Boneh Elette Boyle Henry Corrigan-Gibbs Niv Gilboa Yuval Ishai Stanford IDC Herzliya Stanford Ben-Gurion University Technion
Ze Zero-Kn Knowledge Pr Proofs on on Se Secr cret-Sh Shared - - PowerPoint PPT Presentation
Ze Zero-Kn Knowledge Pr Proofs on on Se Secr cret-Sh Shared Data ta via via Fully Lin inear ear PCPs PCPs Dan Boneh Elette Boyle Henry Corrigan-Gibbs Niv Gilboa Yuval Ishai Ben-Gurion Stanford IDC Herzliya Stanford Technion
Dan Boneh Elette Boyle Henry Corrigan-Gibbs Niv Gilboa Yuval Ishai Stanford IDC Herzliya Stanford Ben-Gurion University Technion
Rev Review ew
36
Γ πβ le learns ns no nothing hing els lse about π»
[GMR89]
Rev Review ew
37
Γ πβ le learns ns no nothing hing els lse about π»
[GMR89]
Rev Review ew
38
Γ πβ le learns ns no nothing hing els lse about π»
[GMR89]
Th This is pa pape per
39
*
,
*, π , .
*, π ,).
* β (or π , β) learns only that π»* + π», β 3COL.
Γ π
* le
learns ns no nothing hing els lse about π»,
Th This is pa pape per
40
*
,
*, π , .
*, π ,).
* β (or π , β) learns only that π»* + π», β 3COL.
Γ π
* le
learns ns no nothing hing els lse about π»,
Th This is pa pape per
41
*
,
*, π , .
*, π ,).
* β (or π , β) learns only that π»* + π», β 3COL.
Γ π
* le
learns ns no nothing hing els lse about π»,
Th This is pa pape per
42
*
,
Sp Specia ial case
43
*
,
for π¦ = π¦* + π¦,
44
[OS97], [BGI16], Riposte, β¦
Adnostic, Adscale, Prio, β¦
for large πΎ
45
[OS97], [BGI16], Riposte, β¦
Adnostic, Adscale, Prio, β¦
for large πΎ
46
[OS97], [BGI16], Riposte, β¦
Adnostic, Adscale, Prio, β¦
for large πΎ
47
48
49
50
51
52
53
54
55
[IKO07]
56
query q β πΎK answer π = q, π β πΎ
[This work]
57
query q β πΎ5NK answer π = q, πβπ β πΎ
58
*
,
ππβππ β β
59
*
,
ππβππ β β
60
*
,
ππβππ β β
61
*
,
ππβππ β β
62
*
,
63
*
,
64
*
,
65
*
,
66
*
,
67
*
,
68
*
,
69
*
,
70
*
71
,
*
72
,
*
73
,
*
74
,
*
75
,
*
76
,
*
77
,
*
78
,
d π¦, d
*
79
,
d π¦, d
80
81
82
83
84
[AFLNO16]
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
β Protocol hides verifiersβ inputs from each other
β Can unify with sum-check-based proofs? [GKR08], [CTY11], [T16], β¦
β Also to other models of distributed proof? [KOS18], [NPY18], β¦
Dan Boneh, Elette Boyle, Henry Corrigan-Gibbs, Niv Gilboa, Yuval Ishai https://eprint.iacr.org/2019/188
101