Arnon et al. proposed a publicly verifiable SNARG, which only contains two group elements and no additional bits, achieving the minimum proof size in GGM + ROM, and establishing a lower bound for single group element SNARGs. Arnon等人提出了一种公开可验证SNARG,证明仅含两个群元素且无额外比特,在GGM + ROM中实现最小证明尺寸,并建立了单群元素SNARG的下界。
Notes
Proposed the first publicly verifiable SNARG, which only contains two group elements and no additional bits, achieving the minimum proof size in GGM + ROM, and establishing a lower bound for single group element SNARGs.
Achieves the minimum proof size in GGM + ROM, with BLS12-381 instance size of 768 bits
Tight security analysis with no hidden security losses
Establishes a new lower bound: single group element SNARGs are impossible in GGM + ROM
Proof size is nearly twice that of existing schemes, but not yet specifically efficient
Paves the way for future practical instantiation, reinforcing Groth's lower bound