Paper 2025/902

On the Fiat–Shamir Security of Succinct Arguments from Functional Commitments

Alessandro Chiesa, École Polytechnique Fédérale de Lausanne
Ziyi Guan, École Polytechnique Fédérale de Lausanne
Christian Knabenhans, École Polytechnique Fédérale de Lausanne
Zihan Yu, École Polytechnique Fédérale de Lausanne
Abstract

We study the security of a popular paradigm for constructing SNARGs, closing a key security gap left open by prior work. The paradigm consists of two steps: first, construct a public-coin succinct interactive argument by combining a functional interactive oracle proof (FIOP) and a functional commitment scheme (FC scheme); second, apply the Fiat–Shamir transformation in the random oracle model. Prior work did not consider this generalized setting nor prove the security of this second step (even in special cases). We prove that the succinct argument obtained in the first step satisfies state-restoration security, thereby ensuring that the second step does in fact yield a succinct non-interactive argument. This is provided the FIOP satisfies state-restoration security and the FC scheme satisfies a natural state-restoration variant of function binding (a generalization of position binding for vector commitment schemes). Moreover, we prove that notable FC schemes satisfy state-restoration function binding, allowing us to establish, via our main result, the security of several SNARGs of interest (in the random oracle model). This includes a security proof of Plonk, in the ROM, based on ARSDH (a falsifiable assumption).

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Preprint.
Keywords
Fiat-Shamir securitysuccinct argumentsfunctional commitment schemes
Contact author(s)
alessandro chiesa @ epfl ch
ziyi guan @ epfl ch
christian knabenhans @ epfl ch
zihan yu @ epfl ch
History
2025-05-27: last of 3 revisions
2025-05-20: received
See all versions
Short URL
https://ia.cr/2025/902
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/902,
      author = {Alessandro Chiesa and Ziyi Guan and Christian Knabenhans and Zihan Yu},
      title = {On the Fiat–Shamir Security of Succinct Arguments from Functional Commitments},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/902},
      year = {2025},
      url = {https://eprint.iacr.org/2025/902}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.