Paper 2009/390
Short Pairing-based Non-interactive Zero-Knowledge Arguments
Abstract
We construct non-interactive zero-knowledge arguments for circuit satisfiability with perfect completeness, perfect zero knowledge and computational soundness. The non-interactive zero-knowledge arguments have sublinear size and very efficient public verification. Their size can even be reduced to a constant number of group elements if we allow the common reference string to be large. Our constructions rely on groups with pairings, and security is based on two new cryptographic assumptions; we do not use the Fiat-Shamir heuristic or random oracles.
Note: First pairing-based zk-SNARK, first non-Fiat-Shamir SNARK, published at ASIACRYPT 2010 This revision: polished and fixed typos, added context on relation to later zk-SNARKs Lipmaa12, GGPR13 and on universal and updatable CRS from GKMMM18, addendum on preprocessing for fixed circuit
Metadata
- Available format(s)
-
PDF
- Category
- Foundations
- Publication info
- A minor revision of an IACR publication in ASIACRYPT 2010
- Keywords
- SNARKNIZKpairing
- Contact author(s)
- j groth @ ucl ac uk
- History
- 2026-04-19: revised
- 2009-08-15: received
- See all versions
- Short URL
- https://ia.cr/2009/390
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2009/390,
author = {Jens Groth},
title = {Short Pairing-based Non-interactive Zero-Knowledge Arguments},
howpublished = {Cryptology {ePrint} Archive, Paper 2009/390},
year = {2009},
url = {https://eprint.iacr.org/2009/390}
}