\begin{itemize} \item For sub-exponential (or smaller) $T(\cdot)$, \emph{polynomial-time} black-box reductions cannot be used to prove soundness of 2-message $T(\cdot)$-simulatable arguments based on any polynomial-time intractability assumption. This matches known 2-message quasi-polynomial-time simulatable arguments using a quasi-polynomial-time reduction (Pass'03), and 2-message exponential-time simulatable proofs using a polynomial-time reduction (Dwork-Naor'00, Pass'03).
\item $\poly(T(\cdot))$-time black-box reductions cannot be used to prove soundness of 2-message \emph{strong} $T(\cdot)$-simulatable (efficient prover) arguments based on any $\poly(T(\cdot))$-time intractability assumption; strong $T(\cdot)$-simulatability means that the output of the simulator is indistinguishable also for $\poly(T(\cdot))$-size circuits. This matches known 3-message strong quasi-polynomial-time simulatable proofs (Blum'86, Canetti et al'00). \end{itemize}
Category / Keywords: foundations / zero-knowledge, super-polynomial-time simulation, black-box lower bound, falsifiable assumptions, non-uniform Date: received 19 Dec 2012 Contact author: chung at cs cornell edu Available format(s): PDF | BibTeX Citation Version: 20121219:163415 (All versions of this report) Short URL: ia.cr/2012/711 Discussion forum: Show discussion | Start new discussion