Skip to main navigation Skip to search Skip to main content

Malleable SNARKs and Their Applications

  • Suvradip Chakraborty
  • , Dennis Hofheinz
  • , Roman Langrehr (Author and Speaker)
  • , Jesper Buus Nielsen
  • , Christoph Striecks
  • , Daniele Venturi
    • Visa Inc
    • ETH Zurich
    • Aarhus University
    • University of Rome La Sapienza

    Research output: Chapter in Book or Conference ProceedingsConference Proceedings with Oral Presentationpeer-review

    Abstract

    Succinct non-interactive arguments of knowledge (SNARKs) are variants of non-interactive zero-knowledge proofs (NIZKs) in which complex statements can be proven in a compact way. SNARKs have had tremendous impact in several areas of cryptography, including verifiable computing, blockchains, and anonymous communication. A recurring concept in many applications is the concept of recursive SNARKs, in which a proof references a previous proof to show an evolved statement.

    In this work, we investigate malleable SNARKs, a generalization of this concept of recursion. An adaptation of the existing concept of malleable NIZKs, malleable SNARKs allow to modify SNARK proofs to show related statements, but such that such mauled proofs are indistinguishable from “properly generated” fresh proofs of the related statement. We show how to instantiate malleable SNARKs for universal languages and relations, and give a number of applications: the first post-quantum RCCA-secure rerandomizable and updatable encryption schemes, a generic construction of reverse firewalls, and an unlinkable (i.e., computation-hiding) targeted malleable homomorphic encryption scheme.

    Technically, our malleable SNARK construction relies on recursive proofs, but with a twist: in order to support the strong indistinguishability properties of mauled and fresh SNARK proofs, we need to allow an unbounded recursion depth. To still allow for a reasonable notion of extractability in this setting (and in particular to guarantee that extraction eventually finishes with a “proper” witness that does not refer to a previous SNARK proof), we rely on a new and generic computational primitive called adversarial one-way function (AOWF) that may be of independent interest. We give an AOWF candidate and prove it secure in the random oracle model.
    Original languageEnglish
    Title of host publicationAdvances in Cryptology – EUROCRYPT 2025
    Subtitle of host publication44th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Madrid, Spain, May 4–8, 2025, Proceedings, Part IV
    EditorsSerge Fehr, Pierre-Alain Fouque
    Pages184–213
    Number of pages29
    Volume15604
    Edition1
    ISBN (Electronic)978-3-031-91134-7
    DOIs
    Publication statusPublished - 27 Apr 2025
    Event44th Annual International Conference on the Theory and Applications of Cryptographic Techniques - EUROCRYPT 2025 Affiliated Events - Madrid, Spain
    Duration: 4 May 20258 May 2025
    https://eurocrypt.iacr.org/2025/

    Publication series

    NameLecture Notes in Computer Science
    PublisherSpringer
    Volume15604
    ISSN (Print)0302-9743
    ISSN (Electronic)1611-3349

    Conference

    Conference44th Annual International Conference on the Theory and Applications of Cryptographic Techniques - EUROCRYPT 2025 Affiliated Events
    Country/TerritorySpain
    CityMadrid
    Period4/05/258/05/25
    Internet address

    Research Field

    • Cyber Security

    Fingerprint

    Dive into the research topics of 'Malleable SNARKs and Their Applications'. Together they form a unique fingerprint.

    Cite this