Lattice-based Zero-knowledge Proofs for Blockchain Confidential Transactions Shang GAO, Tianyu ZHENG, Yu GUO, Zhe PENG, Bin XIAO 2025515 PKC 2025 Bitcoin Transactions Public ledger for verification Alice Bob Verifier Bitcoin Transactions
Related Topics
Share
Embed code
Download this presentation From Below
"Lattice-based Zero-knowledge Proofs for Blockchain" is the property of its rightful owner. Permission is granted to
download and print the materials on this website for personal, non-commercial use only, and to display it
on your personal computer provided you do not modify the materials and that you retain all copyright
notices contained in the materials. By downloading content from our website, you accept the terms of this
agreement.
Bitcoin Transactions Public ledger for verification Alice Bob Verifier<br>
03
Bitcoin Transactions Public ledger for verification Alice Bob Verifier<br>
04
Bitcoin Transactions Public ledger for verification I know account IDs and amounts accordingly. Alice Bob Verifier<br>
05
Anonymous Cryptocurrency ID and amounts should be private Alice Bob Verifier I learn nothing about IDs and amounts.<br>
06
Confidential Transactions Range proofs to hide the amount and allow verification at the same time Confidentiality Alice Bob Verifier Convinced that both two relations hold, but still know nothing about amounts<br>
07
Ring Confidential Transactions Ring signature to hide the identity. Anonymity Alice Bob Verifier<br>
08
Problems and Challenges<br>
09
Some lattice-based solutions are proposed, but not efficient in RingCT protocols [EZS+19, ESZ20].
Proof size is about 5~40x larger than traditional solutions.
Proving/verification time is about 2-4x slower.
Some techniques are not well-designed in lattice settings! Problems and Challenges<br>
10
To propose efficient and post-quantum RingCT protocols for anonymous cryptocurrencies.
New balance proofs under HMC.
New relations for linkable ring signatures.
New post-quantum RingCT protocol.
Beneficiaries
Anonymous cryptocurrencies.
Privacy-preserving applications (e.g., anonymous e-voting).
Zk-Rollups. Objective [GZGX21] S. Gao, T. Zheng, Y. Guo, and B. Xiao, “Efficient and Post-Quantum Zero-Knowledge Proofs for Blockchain Confidential Transaction Protocols,” IACR Cryptology ePrint Archive, 2021<br>
11
Balance Proof<br>
12
Range Proof and Balance Proof<br>
13
Range Proof and Balance Proof Binary proof<br>
14
Balance Proof<br>
15
Balance Proof<br>
16
Balance Proof<br>
17
Ring Signature<br>
18
One-out-of-many Proof User group Verifier Binary proof<br>
19
MatRiCT [EZS+19] and MatRiCT+ [ESZ20] use this technique [GK15] directly in lattice-based RingCT protocols.
Unfortunately, in lattice settings, the binary proof requires larger parameters than other parts, which results in a larger proof size. One-out-of-many Proof<br>
20
Can we remove the costly binary proof ?
This indicates a weaker relation: the “linear sum relation”.
Is this weaker relation still secure for ring signatures?
Linear sum relation is sufficient for ring signatures! (see our paper for the detailed proofs). Linear Sum Proof<br>
21
Can we remove the costly binary proof [GZGX21]?
This indicates a weaker relation: the “linear sum relation”.
Is this weaker relation still secure for ring signatures?
Linear sum relation is sufficient for ring signatures! (see our paper for the detailed proofs).
Unfortunately, the linear sum proof cannot use some techniques in [GK15] to reduce the proof size.
But we may consider an unbalanced relation: the prover runs with a stricter relation, and the verifier checks with a relaxed relation [GZGX21]. Linear Sum Proof<br>
22
Lattice-based RingCT<br>
23
Linkable Ring Signature<br>
24
Balance proof: reduce 90% size of MatRiCT and 30% of MatRiCT+.
Ring signature: reduce 60% size of MatRiCT and 20% of MatRiCT+. Performance<br>
25
Balance proof: reduce 70% size of MatRiCT and 20% of MatRiCT+.
Ring signature: reduce 60% size of MatRiCT and 15% of MatRiCT+. Performance<br>
26
Conclusion<br>
27
Reference [EZS+19] M. F. Esgin, R. K. Zhao, R. Steinfeld, J. K. Liu, and D. Liu, “MatRiCT: Efficient, Scalable and Post-Quantum Blockchain Confidential Transactions Protocol,” in Proc. of the ACM Conference on Computer & Communications Security (CCS). ACM, 2019.
[ESZ20] M. F. Esgin, R. Steinfeld, and R. K. Zhao, “MatRiCT+: More Efficient Post-Quantum Private Blockchain Payments,” in Proc. of the IEEE Symposium on Security and Privacy (S&P), 2022.
[GK15] J. Groth and M. Kohlweiss, “One-Out-of-Many Proofs: Or How to Leak a Secret and Spend a Coin,” in Proc. of the Annual International Conference on the Theory and Applications of Cryptographic Techniques (EUROCRYPT). Springer, 2015.<br>