Succinct Vector, Polynomial, and Functional
Description: Succinct Vector, Polynomial, and Functional Commitments from Lattices Hoeteck Wee and David Wu April 2023 Functional Commitments opening commitment Functional Commitments Takes a common reference string and commits to a message
Related Topics
Download Presentation
"Succinct Vector, Polynomial, and Functional" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Succinct Vector, Polynomial, andFunctional Commitments from Lattices Hoeteck Wee and David Wu
April 2023<br>
slide2. Functional Commitments “opening” “commitment”<br>
slide3. Functional Commitments Takes a common reference string and commits to a message “commitment”<br>
slide4. Functional Commitments<br>
slide5. Functional Commitments<br>
slide6. Functional Commitments Special cases: vector commitments, polynomial commitments<br>
slide7. Functional Commitment Constructions (not an exhaustive list!) non-falsifiable, non-black box<br>
slide8. Functional Commitment Constructions (not an exhaustive list!) supports private openings, commitments to large values, linearly-homomorphic<br>
slide9. Functional Commitment Constructions (not an exhaustive list!)<br>
slide10. Functional Commitment Constructions (not an exhaustive list!) Concurrent works [BCFL22, dCP23]: lattice-based constructions of functional commitments for Boolean circuits<br>
slide11. Functional Commitment Constructions (not an exhaustive list!) Concurrent works [BCFL22, dCP23]: lattice-based constructions of functional commitments for Boolean circuits<br>
slide12. Framework for Lattice Commitments Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22]<br>
slide13. Framework for Lattice Commitments Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] linear combination of target vectors Honest opening:<br>
slide14. Framework for Lattice Commitments Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] suffices for vector commitments (from SIS)<br>
slide15. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22]<br>
slide16. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] “powers of two matrix”<br>
slide17. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] Common reference string:<br>
slide18. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] Common reference string:<br>
slide19. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22]<br>
slide20. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] Supports statistically private openings
(commitment + opening hides unopened positions)<br>
slide21. Computational Binding Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] Our scheme<br>
slide22. Basis-Augmented SIS (BASIS) Assumption Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] Basis-augmented SIS (BASIS) assumption: Our scheme<br>
slide23. Basis-Augmented SIS (BASIS) Assumption (follows from standard lattice trapdoor extension techniques)<br>
slide24. Basis-Augmented SIS (BASIS) Assumption Implication: vector commitment that supports committing to large values and private openings based on SIS Previously: could only commit to small values and without hiding<br>
slide25. Functional Commitments for Circuits Starting point: lattice-based homomorphic commitments [GSW13, BGGHNSVV14, GVW15] homomorphic evaluation<br>
slide26. Functional Commitments for Circuits Starting point: lattice-based homomorphic commitments [GSW13, BGGHNSVV14, GVW15]<br>
slide27. Functional Commitments for Circuits<br>
slide28. Functional Commitments for Circuits Homomorphic computation + opening verification now proceed as in [GVW15]<br>
slide29. Functional Commitments from Lattices Security follows from BASIS assumption with a structured matrix: Falsifiable assumption but does not appear to reduce to standard SIS<br>
slide30. Extensions Our functional commitment: [see paper for details]<br>
slide31. Summary<br>
slide32. Open Questions Analyzing BASIS family of assumptions (new reductions to SIS or attacks)
Describe and analyze knowledge variants of the assumption or the constructions
Reducing CRS size: functional commitments with linear-size CRS?
Constructing lattice-based subvector commitments Thank you! https://eprint.iacr.org/2022/1515<br>
slide33. Concurrent Work<br>
April 2023<br>
slide2. Functional Commitments “opening” “commitment”<br>
slide3. Functional Commitments Takes a common reference string and commits to a message “commitment”<br>
slide4. Functional Commitments<br>
slide5. Functional Commitments<br>
slide6. Functional Commitments Special cases: vector commitments, polynomial commitments<br>
slide7. Functional Commitment Constructions (not an exhaustive list!) non-falsifiable, non-black box<br>
slide8. Functional Commitment Constructions (not an exhaustive list!) supports private openings, commitments to large values, linearly-homomorphic<br>
slide9. Functional Commitment Constructions (not an exhaustive list!)<br>
slide10. Functional Commitment Constructions (not an exhaustive list!) Concurrent works [BCFL22, dCP23]: lattice-based constructions of functional commitments for Boolean circuits<br>
slide11. Functional Commitment Constructions (not an exhaustive list!) Concurrent works [BCFL22, dCP23]: lattice-based constructions of functional commitments for Boolean circuits<br>
slide12. Framework for Lattice Commitments Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22]<br>
slide13. Framework for Lattice Commitments Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] linear combination of target vectors Honest opening:<br>
slide14. Framework for Lattice Commitments Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] suffices for vector commitments (from SIS)<br>
slide15. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22]<br>
slide16. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] “powers of two matrix”<br>
slide17. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] Common reference string:<br>
slide18. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] Common reference string:<br>
slide19. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22]<br>
slide20. Our Approach Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] Supports statistically private openings
(commitment + opening hides unopened positions)<br>
slide21. Computational Binding Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] Our scheme<br>
slide22. Basis-Augmented SIS (BASIS) Assumption Captures and generalizes previous lattice-based functional commitments [PPS21, ACLMT22] Basis-augmented SIS (BASIS) assumption: Our scheme<br>
slide23. Basis-Augmented SIS (BASIS) Assumption (follows from standard lattice trapdoor extension techniques)<br>
slide24. Basis-Augmented SIS (BASIS) Assumption Implication: vector commitment that supports committing to large values and private openings based on SIS Previously: could only commit to small values and without hiding<br>
slide25. Functional Commitments for Circuits Starting point: lattice-based homomorphic commitments [GSW13, BGGHNSVV14, GVW15] homomorphic evaluation<br>
slide26. Functional Commitments for Circuits Starting point: lattice-based homomorphic commitments [GSW13, BGGHNSVV14, GVW15]<br>
slide27. Functional Commitments for Circuits<br>
slide28. Functional Commitments for Circuits Homomorphic computation + opening verification now proceed as in [GVW15]<br>
slide29. Functional Commitments from Lattices Security follows from BASIS assumption with a structured matrix: Falsifiable assumption but does not appear to reduce to standard SIS<br>
slide30. Extensions Our functional commitment: [see paper for details]<br>
slide31. Summary<br>
slide32. Open Questions Analyzing BASIS family of assumptions (new reductions to SIS or attacks)
Describe and analyze knowledge variants of the assumption or the constructions
Reducing CRS size: functional commitments with linear-size CRS?
Constructing lattice-based subvector commitments Thank you! https://eprint.iacr.org/2022/1515<br>
slide33. Concurrent Work<br>