Paper 2025/1759

Plonk is Simulation Extractable in ROM Under Falsifiable Assumptions

Helger Lipmaa, University of Tartu
Abstract

Solving a long-standing open problem, Faonio, Fiore, and Russo proved that the widely used Plonk zk-SNARK is simulation extractable. However, their proof assumes both the random oracle model (ROM) and the algebraic group model. We prove that the same holds in the ROM under falsifiable assumptions. We combine the template of Faust et al., who proved that simulation extractability follows from knowledge soundness, (weak) unique response, and trapdoorless zero-knowledge, with the recent result of Lipmaa, Parisella, and Siim (Crypto 2025), who proved that Plonk has knowledge soundness in the ROM under falsifiable assumptions. For this, we prove that Plonk satisfies new variants of the weak unique response and trapdoorless zero-knowledge properties. We prove that several commonly used gadgets, like the linearization trick, are not trapdoorless zero-knowledge when considered as independent commit-and-prove zk-SNARKs.

Note: Full version of a TCC 2025 paper

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A minor revision of an IACR publication in TCC 2025
Keywords
Fiat-ShamirPlonksimulation extractabilitytrapdoorless zero-knowledgeunique responsezk-SNARK
Contact author(s)
helger lipmaa @ gmail com
History
2025-09-26: approved
2025-09-26: received
See all versions
Short URL
https://ia.cr/2025/1759
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1759,
      author = {Helger Lipmaa},
      title = {Plonk is Simulation Extractable in {ROM} Under Falsifiable Assumptions},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1759},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1759}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.