04
Functional Commitments<br>
05
Functional Commitments<br>
06
Functional Commitments<br>
07
Functional Commitments<br>
08
Functional Commitments<br>
09
Functional Commitments<br>
10
Lattice-Based Functional Commitments Scheme Function Class Assumption [KLVW23] Boolean circuits LWE FV BB 1 1 1 ✓ ✗ [BCFL23] 1 1 ✓ ✓ [WW23] 1 1 ✗ ✓ [ACLMT22] 1 1 ✓ ✓ [BCFL23]* 1 1 ✓ ✓ This work 1 1 ✓ ✓ This talk: only consider lattice-based functional commitment schemes *can decrease CRS size at the cost of longer openings<br>
11
Lattice-Based Functional Commitments Scheme Function Class Assumption [KLVW23] Boolean circuits LWE FV BB 1 1 1 ✓ ✗ [BCFL23] 1 1 ✓ ✓ [WW23] 1 1 ✗ ✓ [ACLMT22] 1 1 ✓ ✓ [BCFL23]* 1 1 ✓ ✓ This work 1 1 ✓ ✓<br>
12
Lattice-Based Functional Commitments Scheme Function Class Assumption This talk: only consider lattice-based functional commitment schemes FV BB [KLVW23] Boolean circuits LWE 1 1 ✓ ✗ [dCP23] SIS 1 ✗ ✓ This work 1 1 ✓ ✓ dual functional commitments functional commitments [KLVW23] Boolean circuits LWE 1 1 1 ✓ ✗ [BCFL23] 1 1 ✓ ✓ [WW23] 1 1 ✗ ✓ [ACLMT22] 1 1 ✓ ✓ [BCFL23]* 1 1 ✓ ✓ This work 1 1 ✓ ✓<br>
13
This Work Functional commitments with fast verification (and black-box use of cryptography) Cryptanalysis of knowledge versions of the new lattice assumptions This talk This talk<br>
14
Starting Point: the Wee-Wu Functional Commitment [WW23] Common reference string (CRS) commitment gadget matrix opening (matrix with short entries)<br>
15
Our Approach: A “Chaining” Structure Common reference string (CRS) This work: More structure in the CRS<br>
16
Our Approach: A “Chaining” Structure function of commitment and public parameters<br>
17
Our Approach: A “Chaining” Structure function of commitment and public parameters<br>
18
Our Approach: A “Chaining” Structure function of commitment and public parameters<br>
19
Our Approach: A “Chaining” Structure function of commitment and public parameters<br>
20
Our Approach: A “Chaining” Structure function of commitment and public parameters<br>
21
Our Approach: A “Chaining” Structure function of commitment and public parameters<br>
22
Approach: sample trapdoor for following matrix<br>
23
Approach: sample trapdoor for following matrix Shorter CRS: leverage homomorphism<br>
24
Evaluation Binding Trapdoor for above matrix suffices to simulate CRS [see paper for details]<br>
25
Evaluation Binding Trapdoor for above matrix suffices to simulate CRS [see paper for details]<br>
26
Cryptanalysis of Lattice-Based Knowledge Assumptions<br>
27
Cryptanalysis of Lattice-Based Knowledge Assumptions Typical lattice-based knowledge assumption (to get extractable commitment / SNARK): short<br>
28
Obliviously Sampling a Solution Typical lattice-based knowledge assumption (to get extractable commitment / SNARK): short<br>
29
Obliviously Sampling a Solution<br>
30
Obliviously Sampling a Solution<br>
31
Template for Analyzing Lattice-Based Knowledge Assumptions Start with the key verification relation (i.e., knowledge of a short solution to a linear system)
Express verification relation as finding non-zero vector in the kernel of a lattice defined by the verification equation
Use components in the CRS to derive a basis for the related lattice 1 2 3<br>
32
Template for Analyzing Lattice-Based Knowledge Assumptions Start with the key verification relation (i.e., knowledge of a short solution to a linear system)
Express verification relation as finding non-zero vector in the kernel of a lattice defined by the verification equation
Use components in the CRS to derive a basis for the related lattice<br>
33
Template for Analyzing Lattice-Based Knowledge Assumptions Start with the key verification relation (i.e., knowledge of a short solution to a linear system)
Express verification relation as finding non-zero vector in the kernel of a lattice defined by the verification equation
Use components in the CRS to derive a basis for the related lattice The SNARK considers extractable commitment for quadratic functions while our current oblivious sampler only works for linear functions in the case of [ACLMT22]<br>
34
This Work Functional commitments with fast verification (and black-box use of cryptography) Cryptanalysis of knowledge versions of the new lattice assumptions [see paper for details]<br>
35
Open Questions (Black-box) functional commitments with fast verification from standard SIS? Our oblivious sampler (heuristically) falsifies the assumption, but does not break existing constructions Formulation of new lattice-based knowledge assumptions that avoids our attacks Thank you!<br>