### On the efficiency of pairing-based proofs under the d-PKE

Ariel Gabizon

##### Abstract

We investigate the minimal number of group elements and prover running time in a zk-SNARK when using only a symmetric linear'' knowledge assumption, like the $d$-Power Knowledge of Exponent assumption, rather than a quadratic'' one as implicitly happens in the most efficient known construction by Groth [Groth16]. The proofs of [Groth16] contain only 3 group elements. We present 4 element proofs for quadratic arithmetic programs/rank 1 constraint systems under the $d$-PKE with very similar prover running time to [Groth16]. Central to our construction is a simple lemma for batching'' knowledge checks, which allows us to save one proof element.

Cryptographic protocols
Preprint. MINOR revision.
zk-SNARKsKnowledge Assumptions
ariel gabizon @ gmail com
2019-03-18: last of 3 revisions
https://ia.cr/2019/148

CC BY

