Paper 2026/1284

Zero-Knowledge Proofs of Generalized Regular Expression Matching for Anonymized Email Verification

Shreyas Londhe, ZK Email
Aayush Gupta, ZK Email
Sora Suegami, Ethereum Foundation
Yogesh Shahi, ZK Email
Rute Figueiredo, ZK Email
Parisa Hassanizadeh, IPPT PAN, Zero Savvy
Shahriar Ebrahimi, The Alan Turing Institute, Zero Savvy
Abstract

Digital communication increasingly underpins identity, financial transactions, and regulatory compliance. In many settings, possession of a DKIM-signed email serves as evidence of account control, transaction confirmation, or institutional affiliation. Yet demonstrating such properties typically requires revealing the full email or relying on centralized intermediaries, introducing privacy risks and additional trust assumptions. A framework called ZK Email addresses this limitation by applying zero-knowledge proofs (ZKPs) to email verification, enabling publicly verifiable proofs of authenticity while preserving message confidentiality. However, its existing implementations struggle to support complex, real-world messages due to the inefficiency of regular-expression verification over structured formats and rich alphabets. We address this limitation with a new ZKP system for regex matching based on path verification over $\varepsilon$-free NFAs, yielding prover complexity linear in the captured path and independent of the original email's size. This approach enables practical validation of expressive standard structures required for full DKIM-signed email verification. To fully integrate our constructions into ZK Email, we design complete end-to-end ZK circuits that combine (i) DKIM signature verification, (ii) an arbitrary-length SHA-256 circuit with partial precomputation for $\texttt{rsa-sha256}$ under RFC 6376, and (iii) a general-purpose regex primitive enforcing structural constraints over email headers and body. We formalize the associated zero-knowledge relations and analyze their security under realistic adversary models. We implement the system (fully integrated with ZK Email and released under the MIT license) in $\texttt{Circom}$ and $\texttt{Noir}$, targeting $\texttt{Groth16}$ and $\texttt{UltraHonk}$ backends, and evaluate it in both client-side and zkVM (SP1) deployment settings. Experimental results on commodity hardware demonstrate substantial efficiency improvements over prior DFA-based approaches, achieving a $2$-$6\times$ speedup in proving time using the $\texttt{UltraHonk}$ backend, while supporting a significantly richer class of regex languages.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Minor revision. Proceedings on Privacy Enhancing Technologies (PoPETs)
Keywords
Zero-knowledge proofsregexfinite automataemail provenance
Contact author(s)
shreyas @ zk email
aayush @ zk email
sora suegami @ ethereum org
yogesh @ zk email
rutefig @ zk email
parisa @ zerosavvy xyz
shahriar @ zerosavvy xyz
History
2026-06-20: approved
2026-06-18: received
See all versions
Short URL
https://ia.cr/2026/1284
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1284,
      author = {Shreyas Londhe and Aayush Gupta and Sora Suegami and Yogesh Shahi and Rute Figueiredo and Parisa Hassanizadeh and Shahriar Ebrahimi},
      title = {Zero-Knowledge Proofs of Generalized Regular Expression Matching for Anonymized Email Verification},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1284},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1284}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.