Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Non-interactive zero-knowledge proof</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Non-interactive_zero-knowledge_proof"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Non-interactive_zero-knowledge_proof rootpage-Non-interactive_zero-knowledge_proof skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Non-interactive zero-knowledge proof</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p><b>Non-interactive <a href="Zero-knowledge_proof" title="Zero-knowledge proof">zero-knowledge proofs</a></b> are <a href="Cryptographic_primitives" class="mw-redirect" title="Cryptographic primitives">cryptographic primitives</a>, where information between a prover and a verifier can be authenticated by the prover, without revealing any of the specific information beyond the validity of the statement itself. This makes direct communication between the prover and verifier unnecessary, effectively removing any intermediaries.
</p><p>The key advantage of non-interactive <a href="Zero-knowledge_proof" title="Zero-knowledge proof">zero-knowledge proofs</a> is that they can be used in situations where there is no possibility of interaction between the prover and verifier, such as in online transactions where the two parties are not able to communicate in real time. This makes non-interactive zero-knowledge proofs particularly useful in decentralized systems like <a href="Blockchain" title="Blockchain">blockchains</a>, where transactions are verified by a network of <a href="Node_(networking)" title="Node (networking)">nodes</a> and there is no central authority to oversee the verification process.<sup id="cite_ref-:0_1-0" class="reference"><a href="#cite_note-:0-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p><p>Most non-interactive zero-knowledge proofs are based on mathematical constructs like <a href="Elliptic_curve_cryptography" class="mw-redirect" title="Elliptic curve cryptography">elliptic curve cryptography</a> or <a href="Pairing-based_cryptography" title="Pairing-based cryptography">pairing-based cryptography</a>, which allow for the creation of short and easily verifiable proofs of the truth of a statement. Unlike interactive zero-knowledge proofs, which require multiple rounds of interaction between the prover and verifier, non-interactive zero-knowledge proofs are designed to be efficient and can be used to verify a large number of statements simultaneously.<sup id="cite_ref-:0_1-1" class="reference"><a href="#cite_note-:0-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="History">History</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1251242444">
/* start https://en.wikipedia.org/ */


.mw-parser-output .ambox{border:1px solid #a2a9b1;border-left:10px solid #36c;background-color:#fbfbfb;box-sizing:border-box}.mw-parser-output .ambox+link+.ambox,.mw-parser-output .ambox+link+style+.ambox,.mw-parser-output .ambox+link+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+style+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+link+.ambox{margin-top:-1px}html body.mediawiki .mw-parser-output .ambox.mbox-small-left{margin:4px 1em 4px 0;overflow:hidden;width:238px;border-collapse:collapse;font-size:88%;line-height:1.25em}.mw-parser-output .ambox-speedy{border-left:10px solid #b32424;background-color:#fee7e6}.mw-parser-output .ambox-delete{border-left:10px solid #b32424}.mw-parser-output .ambox-content{border-left:10px solid #f28500}.mw-parser-output .ambox-style{border-left:10px solid #fc3}.mw-parser-output .ambox-move{border-left:10px solid #9932cc}.mw-parser-output .ambox-protection{border-left:10px solid #a2a9b1}.mw-parser-output .ambox .mbox-text{border:none;padding:0.25em 0.5em;width:100%}.mw-parser-output .ambox .mbox-image{border:none;padding:2px 0 2px 0.5em;text-align:center}.mw-parser-output .ambox .mbox-imageright{border:none;padding:2px 0.5em 2px 0;text-align:center}.mw-parser-output .ambox .mbox-empty-cell{border:none;padding:0;width:1px}.mw-parser-output .ambox .mbox-image-div{width:52px}@media(min-width:720px){.mw-parser-output .ambox{margin:0 10%}}@media print{body.ns-0 .mw-parser-output .ambox{display:none!important}}


/* end https://en.wikipedia.org/ */
</style>
<p><a href="Manuel_Blum" title="Manuel Blum">Blum</a>, Feldman, and <a href="Silvio_Micali" title="Silvio Micali">Micali</a><sup id="cite_ref-bfm_2-0" class="reference"><a href="#cite_note-bfm-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> showed in 1988 that a common reference string shared between the prover and the verifier is sufficient to achieve computational zero-knowledge without requiring interaction. <a href="Oded_Goldreich" title="Oded Goldreich">Goldreich</a> and Oren<sup id="cite_ref-goldreich1994_3-0" class="reference"><a href="#cite_note-goldreich1994-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> gave impossibility results for one shot zero-knowledge protocols in the <a href="Standard_model_(cryptography)" title="Standard model (cryptography)">standard model</a>. In 2003, <a href="Shafi_Goldwasser" title="Shafi Goldwasser">Shafi Goldwasser</a> and <a href="Yael_Tauman_Kalai" title="Yael Tauman Kalai">Yael Tauman Kalai</a> published an instance of an identification scheme for which any hash function will yield an insecure digital signature scheme.<sup id="cite_ref-goldwasser2003_4-0" class="reference"><a href="#cite_note-goldwasser2003-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p><p>The model influences the properties that can be obtained from a zero-knowledge protocol. Pass<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> showed that in the common reference string model non-interactive zero-knowledge protocols do not preserve all of the properties of interactive zero-knowledge protocols; e.g., they do not preserve deniability. Non-interactive zero-knowledge proofs can also be obtained in the <a href="Random_oracle_model" class="mw-redirect" title="Random oracle model">random oracle model</a> using the <a href="Fiat%E2%80%93Shamir_heuristic" title="Fiat–Shamir heuristic">Fiat–Shamir heuristic</a>.
</p>
<div class="mw-heading mw-heading3"><h3 id="Blockchain_applications">Blockchain applications</h3></div>

<p>In 2012, <a href="Alessandro_Chiesa" title="Alessandro Chiesa">Alessandro Chiesa</a> et al developed the zk-SNARK protocol, an acronym for <i><a href="Zero-knowledge_proof" title="Zero-knowledge proof">zero-knowledge</a> succinct non-interactive <a href="Proof_of_knowledge" title="Proof of knowledge">argument of knowledge</a></i>.<sup id="cite_ref-bitansky2012_6-0" class="reference"><a href="#cite_note-bitansky2012-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> The first widespread application of zk-SNARKs was in the <a href="Zcash" title="Zcash">Zerocash</a> <a href="Blockchain" title="Blockchain">blockchain</a> protocol, where zero-knowledge cryptography provides the computational backbone, by facilitating mathematical proofs that one party has possession of certain information without revealing what that information is.<sup id="cite_ref-sasson2016_7-0" class="reference"><a href="#cite_note-sasson2016-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> Zcash utilized zk-SNARKs to facilitate four distinct transaction types: private, shielding, deshielding, and public. This protocol allowed users to determine how much data was shared with the public ledger for each transaction.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> <a href="Ethereum" title="Ethereum">Ethereum</a> zk-Rollups also utilize zk-SNARKs to increase scalability.<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
</p><p>In 2017, <i>Bulletproofs</i><sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> was released, which enable proving that a committed value is in a range using a logarithmic (in the bit length of the range) number of field and group elements.<sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> Bulletproofs was later implemented into Mimblewimble protocol (the basis for Grin and Beam, and <a href="Litecoin" title="Litecoin">Litecoin</a> via extension blocks) and <a href="Monero_(cryptocurrency)" class="mw-redirect" title="Monero (cryptocurrency)">Monero cryptocurrency</a>.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p><p>In 2018, the <i>zk-STARK</i> (<a href="Zero-knowledge_proof" title="Zero-knowledge proof">zero-knowledge</a> Scalable Transparent <a href="Proof_of_knowledge" title="Proof of knowledge">Argument of Knowledge</a>) protocol was introduced by Eli Ben-Sasson, Iddo Bentov, Yinon Horesh, and Michael Riabzev,<sup id="cite_ref-iacr2018_13-0" class="reference"><a href="#cite_note-iacr2018-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> offering transparency (no trusted setup), quasi-linear proving time, and poly-logarithmic verification time.
<i>Zero-Knowledge Succinct Transparent Arguments of Knowledge</i> are a type of cryptographic proof system that enables one party (the prover) to prove to another party (the verifier) that a certain statement is true, without revealing any additional information beyond the truth of the statement itself. zk-STARKs are succinct, meaning that they allow for the creation of short proofs that are easy to verify, and they are transparent, meaning that anyone can verify the proof without needing any secret information.<sup id="cite_ref-iacr2018_13-1" class="reference"><a href="#cite_note-iacr2018-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p><p>Unlike the first generation of zk-SNARKs, zk-STARKs, by default, do not require a trusted setup, which makes them particularly useful for decentralized applications like blockchains. Additionally, zk-STARKs can be used to verify many statements at once, making them scalable and efficient.<sup id="cite_ref-:0_1-2" class="reference"><a href="#cite_note-:0-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p><p>In 2019, HALO recursive zk-SNARKs without a trusted setup were presented.<sup id="cite_ref-:1_14-0" class="reference"><a href="#cite_note-:1-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> Pickles<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> zk-SNARKs, based on the former construction, power Mina, the first succinctly verifiable blockchain.<sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup>
</p><p>A list of zero-knowledge proof protocols and libraries is provided below along with comparisons based on transparency, universality, and plausible post-quantum security. A transparent protocol is one that does not require any trusted setup and uses public randomness. A universal protocol is one that does not require a separate trusted setup for each circuit. Finally, a plausibly post-quantum protocol is one that is not susceptible to known attacks involving quantum algorithms.
</p>
<table class="wikitable">
<caption>Non-interactive zero-knowledge proof systems
</caption>
<tbody><tr>
<th>ZKP system
</th>
<th>Publication year
</th>
<th>Protocol
</th>
<th>Transparent
</th>
<th>Universal
</th>
<th>Plausibly post-quantum secure
</th></tr>
<tr>
<td>Pinocchio<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup>
</td>
<td>2013
</td>
<td>zk-SNARK
</td>
<td>No
</td>
<td>No
</td>
<td>No
</td></tr>
<tr>
<td>Geppetto<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</td>
<td>2015
</td>
<td>zk-SNARK
</td>
<td>No
</td>
<td>No
</td>
<td>No
</td></tr>
<tr>
<td>TinyRAM<sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup>
</td>
<td>2013
</td>
<td>zk-SNARK
</td>
<td>No
</td>
<td>No
</td>
<td>No
</td></tr>
<tr>
<td>Buffet<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup>
</td>
<td>2015
</td>
<td>zk-SNARK
</td>
<td>No
</td>
<td>No
</td>
<td>No
</td></tr>
<tr>
<td>vRAM<sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>
</td>
<td>2018
</td>
<td>zk-SNARG
</td>
<td>No
</td>
<td>Yes
</td>
<td>No
</td></tr>
<tr>
<td>vnTinyRAM<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup>
</td>
<td>2014
</td>
<td>zk-SNARK
</td>
<td>No
</td>
<td>Yes
</td>
<td>No
</td></tr>
<tr>
<td>MIRAGE<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup>
</td>
<td>2020
</td>
<td>zk-SNARK
</td>
<td>No
</td>
<td>Yes
</td>
<td>No
</td></tr>
<tr>
<td>Sonic<sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup>
</td>
<td>2019
</td>
<td>zk-SNARK
</td>
<td>No
</td>
<td>Yes
</td>
<td>No
</td></tr>
<tr>
<td>Marlin<sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup>
</td>
<td>2020
</td>
<td>zk-SNARK
</td>
<td>No
</td>
<td>Yes
</td>
<td>No
</td></tr>
<tr>
<td>PLONK<sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup>
</td>
<td>2019
</td>
<td>zk-SNARK
</td>
<td>No
</td>
<td>Yes
</td>
<td>No
</td></tr>
<tr>
<td>SuperSonic<sup id="cite_ref-27" class="reference"><a href="#cite_note-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup>
</td>
<td>2020
</td>
<td>zk-SNARK
</td>
<td>Yes
</td>
<td>Yes
</td>
<td>No
</td></tr>
<tr>
<td>Bulletproofs<sup id="cite_ref-28" class="reference"><a href="#cite_note-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup>
</td>
<td>2018
</td>
<td>Bulletproofs
</td>
<td>Yes
</td>
<td>Yes
</td>
<td>No
</td></tr>
<tr>
<td>Hyrax<sup id="cite_ref-29" class="reference"><a href="#cite_note-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup>
</td>
<td>2018
</td>
<td>zk-SNARK
</td>
<td>Yes
</td>
<td>Yes
</td>
<td>No
</td></tr>
<tr>
<td>Halo<sup id="cite_ref-:1_14-1" class="reference"><a href="#cite_note-:1-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup>
</td>
<td>2019
</td>
<td>zk-SNARK
</td>
<td>Yes
</td>
<td>Yes
</td>
<td>No
</td></tr>
<tr>
<td>Virgo<sup id="cite_ref-30" class="reference"><a href="#cite_note-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup>
</td>
<td>2020
</td>
<td>zk-SNARK
</td>
<td>Yes
</td>
<td>Yes
</td>
<td>Yes
</td></tr>
<tr>
<td>Ligero<sup id="cite_ref-31" class="reference"><a href="#cite_note-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup>
</td>
<td>2017
</td>
<td>zk-SNARK
</td>
<td>Yes
</td>
<td>Yes
</td>
<td>Yes
</td></tr>
<tr>
<td>Aurora<sup id="cite_ref-32" class="reference"><a href="#cite_note-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup>
</td>
<td>2019
</td>
<td>zk-SNARK
</td>
<td>Yes
</td>
<td>Yes
</td>
<td>Yes
</td></tr>
<tr>
<td>zk-STARK<sup id="cite_ref-iacr2018_13-2" class="reference"><a href="#cite_note-iacr2018-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-33" class="reference"><a href="#cite_note-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup>
</td>
<td>2019
</td>
<td>zk-STARK
</td>
<td>Yes
</td>
<td>Yes
</td>
<td>Yes
</td></tr>
<tr>
<td>Zilch<sup id="cite_ref-34" class="reference"><a href="#cite_note-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Mouris_2021_3269–3284_35-0" class="reference"><a href="#cite_note-Mouris_2021_3269–3284-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup>
</td>
<td>2021
</td>
<td>zk-STARK
</td>
<td>Yes
</td>
<td>Yes
</td>
<td>Yes
</td></tr></tbody></table>
<div class="mw-heading mw-heading2"><h2 id="Definition">Definition</h2></div>
<p>Originally,<sup id="cite_ref-bfm_2-1" class="reference"><a href="#cite_note-bfm-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> non-interactive zero-knowledge was only defined as a single theorem-proof system. In such a system each proof requires its own fresh common reference string. A common reference string in general is not a random string. It may, for instance, consist of randomly chosen group elements that all protocol parties use. Although the group elements are random, the reference string is not as it contains a certain structure (e.g., group elements) that is distinguishable from randomness. Subsequently, Feige, Lapidot, and <a href="Adi_Shamir" title="Adi Shamir">Shamir</a><sup id="cite_ref-36" class="reference"><a href="#cite_note-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup> introduced multi-theorem zero-knowledge proofs as a more versatile notion for non-interactive zero-knowledge proofs.
</p>
<div class="mw-heading mw-heading2"><h2 id="Pairing-based_non-interactive_proofs">Pairing-based non-interactive proofs</h2></div>
<p><a href="Pairing-based_cryptography" title="Pairing-based cryptography">Pairing-based cryptography</a> has led to several cryptographic advancements. One of these advancements is more powerful and more efficient non-interactive zero-knowledge proofs. The seminal idea was to hide the values for the pairing evaluation in a <a href="Commitment_scheme" title="Commitment scheme">commitment</a>. Using different commitment schemes, this idea was used to build zero-knowledge proof systems under the <a href="Sub-group_hiding" title="Sub-group hiding">sub-group hiding</a><sup id="cite_ref-groth2006a_37-0" class="reference"><a href="#cite_note-groth2006a-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup> and under the <a href="Decisional_linear_assumption" class="mw-redirect" title="Decisional linear assumption">decisional linear assumption</a>.<sup id="cite_ref-groth2006b_38-0" class="reference"><a href="#cite_note-groth2006b-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup> These proof systems prove <a href="Circuit_satisfiability_problem" title="Circuit satisfiability problem">circuit satisfiability</a>, and thus by the <a href="Cook%E2%80%93Levin_theorem" title="Cook–Levin theorem">Cook–Levin theorem</a> allow proving membership for every language in NP. The size of the common reference string and the proofs is relatively small; however, transforming a statement into a boolean circuit incurs considerable overhead.
</p><p>Proof systems under the <a href="Sub-group_hiding" title="Sub-group hiding">sub-group hiding</a>, <a href="Decisional_linear_assumption" class="mw-redirect" title="Decisional linear assumption">decisional linear assumption</a>, and <a href="XDH_assumption" title="XDH assumption">external Diffie–Hellman assumption</a> that allow directly proving the pairing product equations that are common in <a href="Pairing-based_cryptography" title="Pairing-based cryptography">pairing-based cryptography</a> have been proposed.<sup id="cite_ref-39" class="reference"><a href="#cite_note-39"><span class="cite-bracket">[</span>39<span class="cite-bracket">]</span></a></sup>
</p><p>Under strong knowledge assumptions, it is known how to create sublinear-length computationally-sound proof systems for <a href="NP-complete" class="mw-redirect" title="NP-complete">NP-complete</a> languages. More precisely, the proof in such proof systems consists only of a small number of bilinear group elements.<sup id="cite_ref-40" class="reference"><a href="#cite_note-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-41" class="reference"><a href="#cite_note-41"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-:0-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-:0_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:0_1-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-:0_1-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFGongJinLiLiu2022" class="citation book cs1">Gong, Yinjie; Jin, Yifei; Li, Yuchan; Liu, Ziyi; Zhu, Zhiyi (January 2022). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/9758531">"Analysis and comparison of the main zero-knowledge proof scheme"</a>. <i>2022 International Conference on Big Data, Information and Computer Network (BDICN)</i>. pp.&nbsp;<span class="nowrap">366–</span>372. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FBDICN55575.2022.00074">10.1109/BDICN55575.2022.00074</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-6654-8476-3</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:248267862">248267862</a>.</cite></span>
</li>
<li id="cite_note-bfm-2"><span class="mw-cite-backlink">^ <a href="#cite_ref-bfm_2-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-bfm_2-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text">Manuel Blum, Paul Feldman, and Silvio Micali. Non-Interactive Zero-Knowledge and Its Applications. Proceedings of the twentieth annual ACM symposium on Theory of computing (STOC 1988). 103–112. 1988</span>
</li>
<li id="cite_note-goldreich1994-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-goldreich1994_3-0">^</a></b></span> <span class="reference-text">Oded Goldreich and Yair Oren. Definitions and Properties of Zero-Knowledge Proof Systems. Journal of Cryptology. Vol 7(1). 1–32. 1994 <a rel="nofollow" class="external text" href="http://www.wisdom.weizmann.ac.il/~oded/PS/oren.ps">(PS)</a></span>
</li>
<li id="cite_note-goldwasser2003-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-goldwasser2003_4-0">^</a></b></span> <span class="reference-text">Shafi Goldwasser and Yael Kalai. On the (In)security of the Fiat–Shamir Paradigm. Proceedings of the 44th Annual IEEE Symposium on Foundations of Computer Science (FOCS'03). 2003</span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text">Rafael Pass. On Deniability in the Common Reference String and Random Oracle Model. Advances in Cryptology – CRYPTO 2003. 316–337. 2003 <a rel="nofollow" class="external text" href="http://www.nada.kth.se/~rafael/papers/denzk.ps">(PS)</a></span>
</li>
<li id="cite_note-bitansky2012-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-bitansky2012_6-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFBitanskyCanettiChiesaTromer2012" class="citation book cs1">Bitansky, Nir; Canetti, Ran; Chiesa, Alessandro; Tromer, Eran (January 2012). <a rel="nofollow" class="external text" href="http://dl.acm.org/citation.cfm?id=2090263">"From extractable collision resistance to succinct non-interactive arguments of knowledge, and back again"</a>. <i>Proceedings of the 3rd Innovations in Theoretical Computer Science Conference on - ITCS '12</i>. <a href="Association_for_Computing_Machinery" title="Association for Computing Machinery">ACM</a>. pp.&nbsp;<span class="nowrap">326–</span>349. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1145%2F2090236.2090263">10.1145/2090236.2090263</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-4503-1115-1</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:2576177">2576177</a>.</cite></span>
</li>
<li id="cite_note-sasson2016-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-sasson2016_7-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFBen-SassonChiesaGarmanGreen2014" class="citation web cs1">Ben-Sasson, Eli; Chiesa, Alessandro; Garman, Christina; Green, Matthew; Miers, Ian; Tromer, Eran; Virza, Madars (18 May 2014). <a rel="nofollow" class="external text" href="http://zerocash-project.org/media/pdf/zerocash-extended-20140518.pdf">"Zerocash: Decentralized Anonymous Payments from Bitcoin"</a> <span class="cs1-format">(PDF)</span>. IEEE<span class="reference-accessdate">. Retrieved <span class="nowrap">26 January</span> 2016</span>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite id="CITEREFBen-SassonChiesa" class="citation web cs1">Ben-Sasson, Eli; Chiesa, Alessandro. <a rel="nofollow" class="external text" href="https://z.cash/technology/zksnarks/">"What are zk-SNARKs?"</a>. z.cash<span class="reference-accessdate">. Retrieved <span class="nowrap">3 November</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://ethereum.org/">"Zero-Knowledge rollups"</a>. <i>ethereum.org</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-02-25</span></span>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite id="CITEREFBünzBootleBonehPoelstra2018" class="citation book cs1">Bünz, Benedikt; Bootle, Jonathan; Boneh, Dan; Poelstra, Andrew; Wuille, Pieter; Maxwell, Greg (May 2018). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/8418611">"Bulletproofs: Short Proofs for Confidential Transactions and More"</a>. <i>2018 IEEE Symposium on Security and Privacy (SP)</i>. pp.&nbsp;<span class="nowrap">315–</span>334. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FSP.2018.00020">10.1109/SP.2018.00020</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-5386-4353-2</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:3337741">3337741</a>.</cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite id="CITEREFBünzBootleBonehPoelstra2018" class="citation book cs1">Bünz, Benedikt; Bootle, Jonathan; Boneh, Dan; Poelstra, Andrew; Wuille, Pieter; Maxwell, Greg (May 2018). <a rel="nofollow" class="external text" href="https://web.stanford.edu/~buenz/pubs/bulletproofs.pdf">"Bulletproofs: Short Proofs for Confidential Transactions and More"</a> <span class="cs1-format">(PDF)</span>. <i>2018 IEEE Symposium on Security and Privacy (SP)</i>. pp.&nbsp;<span class="nowrap">315–</span>334. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FSP.2018.00020">10.1109/SP.2018.00020</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-5386-4353-2</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:3337741">3337741</a><span class="reference-accessdate">. Retrieved <span class="nowrap">2 December</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite id="CITEREFOdendaalSharrockHeerden" class="citation web cs1">Odendaal, Hansie; Sharrock, Cayle; Heerden, SW. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200929160834/https://tlu.tarilabs.com/cryptography/bulletproofs-and-mimblewimble/MainReport.html">"Bulletproofs and Mimblewimble"</a>. Tari Labs University. Archived from <a rel="nofollow" class="external text" href="https://tlu.tarilabs.com/cryptography/bulletproofs-and-mimblewimble/MainReport.html#current-and-past-efforts">the original</a> on 29 September 2020<span class="reference-accessdate">. Retrieved <span class="nowrap">3 December</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-iacr2018-13"><span class="mw-cite-backlink">^ <a href="#cite_ref-iacr2018_13-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-iacr2018_13-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-iacr2018_13-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFEli_Ben-SassonIddo_BentovYinon_HoreshMichael_Riabzev2018" class="citation web cs1">Eli Ben-Sasson; Iddo Bentov; Yinon Horesh; Michael Riabzev (March 6, 2018). <a rel="nofollow" class="external text" href="https://eprint.iacr.org/2018/046.pdf">"Scalable, transparent, and post-quantum secure computational integrity"</a> <span class="cs1-format">(PDF)</span>. <a href="International_Association_for_Cryptologic_Research" title="International Association for Cryptologic Research">International Association for Cryptologic Research</a><span class="reference-accessdate">. Retrieved <span class="nowrap">October 24,</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-:1-14"><span class="mw-cite-backlink">^ <a href="#cite_ref-:1_14-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:1_14-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFBoweGriggHopwood2019" class="citation journal cs1">Bowe, Sean; Grigg, Jack; Hopwood, Daira (2019). <a rel="nofollow" class="external text" href="https://eprint.iacr.org/2019/1021">"Recursive Proof Composition without a Trusted Setup"</a>. <i>Cryptology ePrint Archive</i>.</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://minaprotocol.com/blog/meet-pickles-snark-enabling-smart-contracts-on-coda-protocol">"Meet Pickles SNARK: Enabling Smart Contracts on Coda Protocol"</a>. <i>Mina Protocol</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-02-25</span></span>.</cite></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-16">^</a></b></span> <span class="reference-text"><cite id="CITEREFBonneauMecklerRaoEvan2021" class="citation web cs1">Bonneau, Joseph; Meckler, Izaak; Rao, V.; Evan; Shapiro (2021). <a rel="nofollow" class="external text" href="https://docs.minaprotocol.com/assets/technicalWhitepaper.pdf">"Mina: Decentralized Cryptocurrency at Scale"</a> <span class="cs1-format">(PDF)</span>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:226280610">226280610</a>.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite id="CITEREFParnoHowellGentryRaykova2013" class="citation book cs1">Parno, Bryan; Howell, Jon; Gentry, Craig; Raykova, Mariana (May 2013). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/6547113">"Pinocchio: Nearly Practical Verifiable Computation"</a>. <i>2013 IEEE Symposium on Security and Privacy</i>. pp.&nbsp;<span class="nowrap">238–</span>252. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FSP.2013.47">10.1109/SP.2013.47</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-0-7695-4977-4</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:1155080">1155080</a>.</cite></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-18">^</a></b></span> <span class="reference-text"><cite id="CITEREFCostelloFournetHowellKohlweiss2015" class="citation book cs1">Costello, Craig; Fournet, Cédric; Howell, Jon; Kohlweiss, Markulf; Kreuter, Benjamin; Naehrig, Michael; Parno, Bryan; Zahur, Samee (May 2015). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/7163030">"Geppetto: Versatile Verifiable Computation"</a>. <i>2015 IEEE Symposium on Security and Privacy</i>. pp.&nbsp;<span class="nowrap">253–</span>270. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FSP.2015.23">10.1109/SP.2015.23</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-4673-6949-7</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:3343426">3343426</a>.</cite></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><cite id="CITEREFBen-SassonChiesaGenkinTromer2013" class="citation book cs1">Ben-Sasson, Eli; Chiesa, Alessandro; Genkin, Daniel; Tromer, Eran; Virza, Madars (2013). <a rel="nofollow" class="external text" href="https://link.springer.com/chapter/10.1007/978-3-642-40084-1_6">"SNARKs for C: Verifying Program Executions Succinctly and in Zero Knowledge"</a>. In Canetti, Ran; Garay, Juan A. (eds.). <i>Advances in Cryptology – CRYPTO 2013</i>. Lecture Notes in Computer Science. Vol.&nbsp;8043. Berlin, Heidelberg: Springer. pp.&nbsp;<span class="nowrap">90–</span>108. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F978-3-642-40084-1_6">10.1007/978-3-642-40084-1_6</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-3-642-40084-1</bdi>.</cite></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-20">^</a></b></span> <span class="reference-text"><cite id="CITEREFWahbySettyRenBlumberg2015" class="citation book cs1">Wahby, Riad S.; Setty, Srinath; Ren, Zuocheng; Blumberg, Andrew J.; Walfish, Michael (2015). <a rel="nofollow" class="external text" href="https://www.ndss-symposium.org/ndss2015/ndss-2015-programme/efficient-ram-and-control-flow-verifiable-outsourced-computation/"><i>Efficient RAM and Control Flow in Verifiable Outsourced Computation</i></a>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.14722%2Fndss.2015.23097">10.14722/ndss.2015.23097</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-891562-38-9</bdi><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-02-25</span></span>.</cite></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite id="CITEREFZhangGenkinKatzPapadopoulos2018" class="citation book cs1">Zhang, Yupeng; Genkin, Daniel; Katz, Jonathan; Papadopoulos, Dimitrios; Papamanthou, Charalampos (May 2018). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/8418645">"VRAM: Faster Verifiable RAM with Program-Independent Preprocessing"</a>. <i>2018 IEEE Symposium on Security and Privacy (SP)</i>. pp.&nbsp;<span class="nowrap">908–</span>925. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FSP.2018.00013">10.1109/SP.2018.00013</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-5386-4353-2</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:41548742">41548742</a>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite id="CITEREFBen-SassonChiesaTromerVirza2014" class="citation book cs1">Ben-Sasson, Eli; Chiesa, Alessandro; Tromer, Eran; Virza, Madars (2014). <a rel="nofollow" class="external text" href="https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/ben-sasson"><i>Succinct {Non-Interactive} Zero Knowledge for a von Neumann Architecture</i></a>. pp.&nbsp;<span class="nowrap">781–</span>796. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-931971-15-7</bdi>.</cite></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-23">^</a></b></span> <span class="reference-text"><cite id="CITEREFKosbaPapadopoulosPapamanthouSong2020" class="citation journal cs1">Kosba, Ahmed; Papadopoulos, Dimitrios; Papamanthou, Charalampos; Song, Dawn (2020). <a rel="nofollow" class="external text" href="https://eprint.iacr.org/2020/278">"MIRAGE: Succinct Arguments for Randomized Algorithms with Applications to Universal zk-SNARKs"</a>. <i>Cryptology ePrint Archive</i>.</cite></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-24">^</a></b></span> <span class="reference-text"><cite id="CITEREFMallerBoweKohlweissMeiklejohn2019" class="citation book cs1">Maller, Mary; Bowe, Sean; Kohlweiss, Markulf; Meiklejohn, Sarah (2019-11-06). <a rel="nofollow" class="external text" href="https://doi.org/10.1145/3319535.3339817">"Sonic"</a>. <a rel="nofollow" class="external text" href="https://www.research.ed.ac.uk/en/publications/739b94f1-54f0-4ec3-9644-3c95eea1e8f5"><i>Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security</i></a>. CCS '19. New York, NY, USA: Association for Computing Machinery. pp.&nbsp;<span class="nowrap">2111–</span>2128. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1145%2F3319535.3339817">10.1145/3319535.3339817</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-4503-6747-9</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:60442921">60442921</a>.</cite></span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><b><a href="#cite_ref-25">^</a></b></span> <span class="reference-text"><cite id="CITEREFChiesaHuMallerMishra2020" class="citation book cs1">Chiesa, Alessandro; Hu, Yuncong; Maller, Mary; Mishra, Pratyush; Vesely, Noah; Ward, Nicholas (2020). <a rel="nofollow" class="external text" href="https://link.springer.com/chapter/10.1007/978-3-030-45721-1_26">"Marlin: Preprocessing zkSNARKs with Universal and Updatable SRS"</a>. In Canteaut, Anne; Ishai, Yuval (eds.). <i>Advances in Cryptology – EUROCRYPT 2020</i>. Lecture Notes in Computer Science. Vol.&nbsp;12105. Cham: Springer International Publishing. pp.&nbsp;<span class="nowrap">738–</span>768. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F978-3-030-45721-1_26">10.1007/978-3-030-45721-1_26</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-3-030-45721-1</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:204772154">204772154</a>.</cite></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><cite id="CITEREFGabizonWilliamsonCiobotaru2019" class="citation journal cs1">Gabizon, Ariel; Williamson, Zachary J.; Ciobotaru, Oana (2019). <a rel="nofollow" class="external text" href="https://eprint.iacr.org/2019/953">"PLONK: Permutations over Lagrange-bases for Oecumenical Noninteractive arguments of Knowledge"</a>. <i>Cryptology ePrint Archive</i>.</cite></span>
</li>
<li id="cite_note-27"><span class="mw-cite-backlink"><b><a href="#cite_ref-27">^</a></b></span> <span class="reference-text"><cite id="CITEREFBünzFischSzepieniec2020" class="citation book cs1">Bünz, Benedikt; Fisch, Ben; Szepieniec, Alan (2020). <a rel="nofollow" class="external text" href="https://link.springer.com/chapter/10.1007/978-3-030-45721-1_24">"Transparent SNARKs from DARK Compilers"</a>. In Canteaut, Anne; Ishai, Yuval (eds.). <i>Advances in Cryptology – EUROCRYPT 2020</i>. Lecture Notes in Computer Science. Vol.&nbsp;12105. Cham: Springer International Publishing. pp.&nbsp;<span class="nowrap">677–</span>706. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F978-3-030-45721-1_24">10.1007/978-3-030-45721-1_24</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-3-030-45721-1</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:204892714">204892714</a>.</cite></span>
</li>
<li id="cite_note-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-28">^</a></b></span> <span class="reference-text"><cite id="CITEREFBünzBootleBonehPoelstra2018" class="citation book cs1">Bünz, Benedikt; Bootle, Jonathan; Boneh, Dan; Poelstra, Andrew; Wuille, Pieter; Maxwell, Greg (May 2018). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/8418611">"Bulletproofs: Short Proofs for Confidential Transactions and More"</a>. <i>2018 IEEE Symposium on Security and Privacy (SP)</i>. pp.&nbsp;<span class="nowrap">315–</span>334. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FSP.2018.00020">10.1109/SP.2018.00020</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-5386-4353-2</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:3337741">3337741</a>.</cite></span>
</li>
<li id="cite_note-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-29">^</a></b></span> <span class="reference-text"><cite id="CITEREFWahbyTziallaShelatThaler2018" class="citation book cs1">Wahby, Riad S.; Tzialla, Ioanna; Shelat, Abhi; Thaler, Justin; Walfish, Michael (May 2018). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/8418646">"Doubly-Efficient zkSNARKs Without Trusted Setup"</a>. <i>2018 IEEE Symposium on Security and Privacy (SP)</i>. pp.&nbsp;<span class="nowrap">926–</span>943. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FSP.2018.00060">10.1109/SP.2018.00060</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-5386-4353-2</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:549873">549873</a>.</cite></span>
</li>
<li id="cite_note-30"><span class="mw-cite-backlink"><b><a href="#cite_ref-30">^</a></b></span> <span class="reference-text"><cite id="CITEREFZhangXieZhangSong2020" class="citation book cs1">Zhang, Jiaheng; Xie, Tiancheng; Zhang, Yupeng; Song, Dawn (May 2020). <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/9152704">"Transparent Polynomial Delegation and Its Applications to Zero Knowledge Proof"</a>. <i>2020 IEEE Symposium on Security and Privacy (SP)</i>. pp.&nbsp;<span class="nowrap">859–</span>876. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FSP40000.2020.00052">10.1109/SP40000.2020.00052</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-7281-3497-0</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:209467198">209467198</a>.</cite></span>
</li>
<li id="cite_note-31"><span class="mw-cite-backlink"><b><a href="#cite_ref-31">^</a></b></span> <span class="reference-text"><cite id="CITEREFAmesHazayIshaiVenkitasubramaniam2017" class="citation book cs1">Ames, Scott; Hazay, Carmit; Ishai, Yuval; Venkitasubramaniam, Muthuramakrishnan (2017-10-30). <a rel="nofollow" class="external text" href="https://doi.org/10.1145/3133956.3134104">"Ligero"</a>. <i>Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security</i>. CCS '17. New York, NY, USA: Association for Computing Machinery. pp.&nbsp;<span class="nowrap">2087–</span>2104. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1145%2F3133956.3134104">10.1145/3133956.3134104</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-4503-4946-8</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:5348527">5348527</a>.</cite></span>
</li>
<li id="cite_note-32"><span class="mw-cite-backlink"><b><a href="#cite_ref-32">^</a></b></span> <span class="reference-text"><cite id="CITEREFBen-SassonChiesaRiabzevSpooner2019" class="citation book cs1">Ben-Sasson, Eli; Chiesa, Alessandro; Riabzev, Michael; Spooner, Nicholas; Virza, Madars; Ward, Nicholas P. (2019). <a rel="nofollow" class="external text" href="https://link.springer.com/chapter/10.1007/978-3-030-17653-2_4">"Aurora: Transparent Succinct Arguments for R1CS"</a>. In Ishai, Yuval; Rijmen, Vincent (eds.). <i>Advances in Cryptology – EUROCRYPT 2019</i>. Lecture Notes in Computer Science. Vol.&nbsp;11476. Cham: Springer International Publishing. pp.&nbsp;<span class="nowrap">103–</span>128. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F978-3-030-17653-2_4">10.1007/978-3-030-17653-2_4</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-3-030-17653-2</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:52832327">52832327</a>.</cite></span>
</li>
<li id="cite_note-33"><span class="mw-cite-backlink"><b><a href="#cite_ref-33">^</a></b></span> <span class="reference-text"><cite id="CITEREFBen-SassonBentovHoreshRiabzev2019" class="citation book cs1">Ben-Sasson, Eli; Bentov, Iddo; Horesh, Yinon; Riabzev, Michael (2019). <a rel="nofollow" class="external text" href="https://link.springer.com/chapter/10.1007/978-3-030-26954-8_23">"Scalable Zero Knowledge with No Trusted Setup"</a>. In Boldyreva, Alexandra; Micciancio, Daniele (eds.). <i>Advances in Cryptology – CRYPTO 2019</i>. Lecture Notes in Computer Science. Vol.&nbsp;11694. Cham: Springer International Publishing. pp.&nbsp;<span class="nowrap">701–</span>732. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F978-3-030-26954-8_23">10.1007/978-3-030-26954-8_23</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-3-030-26954-8</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:199501907">199501907</a>.</cite></span>
</li>
<li id="cite_note-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-34">^</a></b></span> <span class="reference-text"><cite id="CITEREFComputing2021" class="citation web cs1">Computing, Trustworthy (2021-08-30). <a rel="nofollow" class="external text" href="https://trustworthy-computing.medium.com/transparent-zero-knowledge-proofs-with-zilch-2031a63fcef3">"Transparent Zero-Knowledge Proofs With Zilch"</a>. <i>Medium</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-02-25</span></span>.</cite></span>
</li>
<li id="cite_note-Mouris_2021_3269–3284-35"><span class="mw-cite-backlink"><b><a href="#cite_ref-Mouris_2021_3269–3284_35-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFMourisTsoutsos2021" class="citation journal cs1">Mouris, Dimitris; Tsoutsos, Nektarios Georgios (2021). <span class="id-lock-subscription" title="Paid subscription required"><a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/9410618">"Zilch: A Framework for Deploying Transparent Zero-Knowledge Proofs"</a></span>. <i>IEEE Transactions on Information Forensics and Security</i>. <b>16</b>: <span class="nowrap">3269–</span>3284. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FTIFS.2021.3074869">10.1109/TIFS.2021.3074869</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1556-6021">1556-6021</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:222069813">222069813</a>.</cite></span>
</li>
<li id="cite_note-36"><span class="mw-cite-backlink"><b><a href="#cite_ref-36">^</a></b></span> <span class="reference-text">Uriel Feige, Dror Lapidot, Adi Shamir: Multiple Non-Interactive Zero-Knowledge Proofs Under General Assumptions. SIAM J. Comput. 29(1): 1–28 (1999)</span>
</li>
<li id="cite_note-groth2006a-37"><span class="mw-cite-backlink"><b><a href="#cite_ref-groth2006a_37-0">^</a></b></span> <span class="reference-text">Jens Groth, Rafail Ostrovsky, Amit Sahai: Perfect Non-interactive Zero Knowledge for NP. EUROCRYPT 2006: 339–358</span>
</li>
<li id="cite_note-groth2006b-38"><span class="mw-cite-backlink"><b><a href="#cite_ref-groth2006b_38-0">^</a></b></span> <span class="reference-text">Jens Groth, Rafail Ostrovsky, Amit Sahai: Non-interactive Zaps and New Techniques for NIZK. CRYPTO 2006: 97–111</span>
</li>
<li id="cite_note-39"><span class="mw-cite-backlink"><b><a href="#cite_ref-39">^</a></b></span> <span class="reference-text">Jens Groth, Amit Sahai: Efficient Non-interactive Proof Systems for Bilinear Groups. EUROCRYPT 2008: 415–432</span>
</li>
<li id="cite_note-40"><span class="mw-cite-backlink"><b><a href="#cite_ref-40">^</a></b></span> <span class="reference-text">Jens Groth. Short Pairing-Based Non-interactive Zero-Knowledge Arguments. ASIACRYPT 2010: 321–340</span>
</li>
<li id="cite_note-41"><span class="mw-cite-backlink"><b><a href="#cite_ref-41">^</a></b></span> <span class="reference-text">Helger Lipmaa. Progression-Free Sets and Sublinear Pairing-Based Non-Interactive Zero-Knowledge Arguments. TCC 2012: 169–189</span>
</li>
</ol></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-08-04" href="https://en.wikipedia.org/wiki/?title=Non-interactive_zero-knowledge_proof&amp;oldid=1304147270">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>