Paper 2025/1811
Anchored Merkle Range Proof for Pedersen Commitments
Abstract
We present a simple range-proof mechanism for Pedersen commitments that avoids per- transaction heavy ZK verification and pairings. The idea is to commit once to a Merkleized range table of points {(U, aX·G)}X∈{1,...,2n} for a secret a ∈ Zq and a public anchor U = a·B. At transaction time, a prover shows set membership of the leaf (U, ax · G), proves via a Chaum–Pedersen DLEQ that logB U = logC C′ where C′ = a · C and C is the Pedersen commitment, and finally proves (Schnorr) that C′ − (ax·G) lies in the H-direction. These three checks enforce x to be the in-range value indexed by the Merkle leaf while preserving privacy. Verification costs a single Merkle proof plus a DLEQ and a Schnorr discrete-log proof over an elliptic curve group.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- Pedersen commitmentrange proofset membershipMerkle treeDLEQChaum– PedersenSchnorrEVM gas
- Contact author(s)
- leona hioki @ intmax io
- History
- 2025-10-08: approved
- 2025-10-03: received
- See all versions
- Short URL
- https://ia.cr/2025/1811
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1811,
author = {Leona Hioki},
title = {Anchored Merkle Range Proof for Pedersen Commitments},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1811},
year = {2025},
url = {https://eprint.iacr.org/2025/1811}
}