How to avoid repetitions in lattice-based deniable zero-knowledge proofs

Interactive zero-knowledge systems are a very important cryptographic primitive, used in many applications, especially when deniability (also known as non-transferability) is desired. In the lattice-based setting, the currently most efficient interactive zero-knowledge systems employ the technique o...

Descripción completa

Detalles Bibliográficos
Autores: Arnal i Clemente, Xavier, Cano Aguilera, Abraham, Finogina, Tamara, Herranz Sotoca, Javier|||0000-0001-5141-7234
Tipo de recurso: informe técnico
Fecha de publicación:2022
País:España
Institución:Universitat Politècnica de Catalunya (UPC)
Repositorio:UPCommons. Portal del coneixement obert de la UPC
Idioma:inglés
OAI Identifier:oai:upcommons.upc.edu:2117/376989
Acceso en línea:https://hdl.handle.net/2117/376989
Access Level:acceso abierto
Palabra clave:Information theory
Coding theory
zero-knowledge
lattices
rejection sampling
deniability
Informació, Teoria de la
Codificació, Teoria de la
Classificació AMS::94 Information And Communication, Circuits
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica::Criptografia
Descripción
Sumario:Interactive zero-knowledge systems are a very important cryptographic primitive, used in many applications, especially when deniability (also known as non-transferability) is desired. In the lattice-based setting, the currently most efficient interactive zero-knowledge systems employ the technique of rejection sampling, which implies that the interaction does not always finish correctly in the first execution; the whole interaction must be re-run until abort does not happen. While repetitions due to aborts are acceptable in theory, in some practical applications it is desirable to avoid re-runs for usability reasons. In this work we present a generic technique that departs from an interactive zero-knowledge system (that might require multiple re-runs to complete the protocol) and obtains a 3-moves zero-knowledge system (without re-runs). The transformation combines the well-known Fiat-Shamir technique with a couple of initially exchanged messages. The resulting 3-moves system enjoys honest-verifier zero-knowledge and can be easily turned into a fully deniable proof using standard techniques. We show some practical scenarios where our transformation can be beneficial and we also discuss the results of an implementation of our transformation.