Monolith: Circuit-Friendly Hash Functions with New Nonlinear Layers for Fast and Constant-Time Implementations
Rattachement africain : de, lu, ch, at, us. Niveau de preuve : code pays fourni par la source.
Le résumé fourni par la source
Hash functions are a crucial component in incrementally verifiable computation (IVC) protocols and applications. Among those, recursive SNARKs and folding schemes require hash functions to be both fast in native CPU computations and compact in algebraic descriptions (constraints). However, neither SHA-2/3 nor newer algebraic constructions, such as Poseidon, achieve both requirements. In this work we overcome this problem in several steps. First, for certain prime field domains we propose a new design strategy called Kintsugi, which explains how to construct nonlinear layers of high algebraic degree which allow fast native implementations and at the same time also an efficient circuit description for zeroknowledge applications. Then we suggest another layer, based on the Feistel Type-3 scheme, and prove wide trail bounds for its combination with an MDS matrix. We propose a new permutation design named Monolith to be used as a sponge or compression function. It is the first arithmetization-oriented function with a native performance comparable to SHA3-256. At the same time, it outperforms Poseidon in a circuit using the Merkle tree prover in the Plonky2 framework. Contrary to previously proposed designs, Monolith also allows for efficient constant-time native implementations which mitigates the risk of side-channel attacks.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Le contrôle bibliographique ouvert
DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.
- Titre Crossref
- Monolith: Circuit-Friendly Hash Functions with New Nonlinear Layers for Fast and Constant-Time Implementations
- Date Crossref
- 06/09/2024
- Éditeur
- Universitatsbibliothek der Ruhr-Universitat Bochum
- Type
- journal-article
Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.
Où se fait cette recherche
-
Ruhr University Bochum Switzerland pays non établi dans la noticeUniversité ou école supérieure
-
University of Luxembourg pays non établi dans la noticeUniversité ou école supérieure
-
Ethereum Foundation pays non établi dans la noticeOrganisation à but non lucratif
-
Graz University of Technology pays non établi dans la noticeUniversité ou école supérieure
-
Austin Speech Labs pays non établi dans la noticeOrganisation à but non lucratif
-
Horizen Labs pays non établi dans la noticeInstitution
Switzerland — Ruhr University Bochum, University of Luxembourg et Ethereum Foundation, avec 3 autres affiliations.
Une affiliation ne permet pas de déduire la nationalité d’un auteur.