Paper 2024/526

Optimizing and Implementing Fischlin's Transform for UC-Secure Zero-Knowledge

Yi-Hsiu Chen, Coinbase, USA
Yehuda Lindell, Coinbase, USA
Abstract

Fischlin's transform (CRYPTO 2005) is an alternative to the Fiat-Shamir transform that enables straight-line extraction when proving knowledge. In this work we focus on the problem of using the Fischlin transform to construct UC-secure zero-knowledge from Sigma protocols, since UC security -- that guarantees security under general concurrent composition -- requires straight-line (non-rewinding) simulators. We provide a slightly simplified transform that is much easier to understand, and present algorithmic and implementation optimizations that significantly improve the running time. It appears that the main obstacles to the use of Fischlin in practice is its computational cost and implementation complexity (with multiple parameters that need to be chosen). We provide clear guidelines and a simple methodology for choosing parameters, and show that with our optimizations the running-time is far lower than expected. For just one example, on a 2023 MacBook, the cost of proving the knowledge of discrete log with Fischlin is only 0.41ms (on a single core). We also extend the transform so that it can be applied to batch proofs, and show how this can be much more efficient than individually proving each statement. As a contribution of independent interest, we present a new algorithm for polynomial evaluation on any series of sequential points that does not require roots of unity. We hope that this paper will both encourage and help practitioners implement the Fischlin transform where relevant.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
zero-knowledge proofs of knowledgestraight-line extractionUC security
Contact author(s)
yihsiuc @ pm me
yehuda lindell @ gmail com
History
2024-04-06: approved
2024-04-04: received
See all versions
Short URL
https://ia.cr/2024/526
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/526,
      author = {Yi-Hsiu Chen and Yehuda Lindell},
      title = {Optimizing and Implementing Fischlin's Transform for UC-Secure Zero-Knowledge},
      howpublished = {Cryptology ePrint Archive, Paper 2024/526},
      year = {2024},
      note = {\url{https://eprint.iacr.org/2024/526}},
      url = {https://eprint.iacr.org/2024/526}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.