Paper 2024/2038
Adaptive Special Soundness: A new framework for knowledge extraction with applications to Kilian’s protocol
Abstract
The knowledge soundness of an interactive proof is often proven via various ``special soundness (SS)'' frameworks which separate knowledge extraction into: (1) extracting accepting transcripts conforming to some structure; (2) recovering a witness from structure-conforming transcripts. However, even access-structure SS [TCC'23], one of the most general, does not handle proof systems employing probabilistic tests, a protocol design technique common in more advanced and especially succinct proof systems. The reason is that its extraction strategy decides whether a challenge is ``useful'' from the challenges used in previous transcripts alone, ignoring the prover messages. While predicate SS [CRYPTO'24] captures probabilistic tests, it does not capture access structures and forgoes the combinatorial nature and simplicity of SS. We introduce adaptive special soundness (AdSS), which generally captures extraction strategies that adaptively pick challenges for the prover taking the history of entire transcripts into account. AdSS in particular captures protocols employing probabilistic tests, formally generalises access-structure SS, and provides a simpler interface than predicate SS while retaining the same expressiveness under mild conditions. We provide knowledge extractors for AdSS protocols with optimal knowledge error $\kappa$ and almost optimal tradeoffs between extraction probability and runtime. To demonstrate the utility of AdSS, we provide a new (knowledge) soundness analysis of Kilian's succinct argument, resolving an open problem in [TCC'24]. In passing, we tighten the existing soundness error bound and unify the analyses in the strict and expected polynomial time regimes. We also provide a range of other examples, from simple ones showing how AdSS captures prior notions, to a new analysis of lattice-based Bulletproofs with unstructured challenges, which improves modularity and covers certain rings beyond $\mathbb{Z}$ compared to [TCC'23].
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- A major revision of an IACR publication in ASIACRYPT 2026
- Keywords
- Knowledge SoundnessSpecial SoundnessSoundness SlackLattice-based Bulletproofs
- Contact author(s)
-
thomas attema @ tno nl
klooss @ mail informatik kit edu
russell lai @ aalto fi
p yatsyna @ mff cuni cz - History
- 2026-09-25: last of 2 revisions
- 2024-12-17: received
- See all versions
- Short URL
- https://ia.cr/2024/2038
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/2038,
author = {Thomas Attema and Michael Klooß and Russell W. F. Lai and Pavlo Yatsyna},
title = {Adaptive Special Soundness: A new framework for knowledge extraction with applications to Kilian’s protocol},
howpublished = {Cryptology {ePrint} Archive, Paper 2024/2038},
year = {2024},
url = {https://eprint.iacr.org/2024/2038}
}