Paper 2025/2000

Trust, But Verify When Using the Powers of Tau

Karim Baghery, KU Leuven
Abstract

To mitigate trust concerns in the setup phase of pairing-based zk-SNARKs, the primary solution has been the sampling of the Structured Reference String (SRS) using an MPC protocol. In 2017, Bowe, Gabizon, and Miers introduced the Powers of Tau MPC protocol for sampling a universal SRS, which has since become the main SRS generation protocol for numerous practical projects. The protocol's designers showed that for a circuit with $2^{21}$ multiplication gates, verifying the universal SRS for Groth16 zk-SNARK could take $55$ minutes for a single update. However, they clarified that "the verification is not run by individual users; it is done by the coordinator and anyone who wishes to verify the transcript of the protocol after completion". This note demonstrates the importance of verifying the final SRS by either $\textit{each}$ individual end-user or $\textit{all}$ ceremony participants to mitigate potential attacks. We discuss simple attack scenarios that highlight vulnerabilities if $\textit{each}$ end-user or $\textit{all}$ participants fail to verify the final SRS. Additionally, by leveraging batching and aggregating techniques, we introduce an efficient verification algorithm for the (original) Powers of Tau protocol, substantially reducing SRS verification time and making it practical even for large-scale ceremonies. In the case of rejection, a more efficient recursive verification approach aids in identifying malicious parties more effectively. This note aims to enhance procedural understanding of SRS generation ceremonies through the Powers of Tau protocol and improve the reliability of current ceremonies against potential threats.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Powers of TauCRS GenerationSetup Ceremonieszk-SNARKs
Contact author(s)
baghery karim @ gmail com
History
2025-10-30: approved
2025-10-26: received
See all versions
Short URL
https://ia.cr/2025/2000
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2000,
      author = {Karim Baghery},
      title = {Trust, But Verify When Using the Powers of Tau},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2000},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2000}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.