campanelli2020.pdf

Vector Commitment Techniques and Applications to Veriable Decentralized Storage

;2 Matteo Campanelli¹, Dario Fiore¹, Nicola Greco³, Dimitris Kolonelos¹, and Luca Nizzardo³

1 IMDEA Software Institute, Madrid, Spain fmatteo.campanelli,dario.fiore,dimitris.kolonelosg@imdea.org 2 Universidad Politecnica de Madrid, Spain 3 Protocol Labs fnicola,lucag@protocol.ai

independent of both the vector’s length and the number of opened positions. We continue the study of SVC with two goals in mind: improving their eciency and making them more suitable to decentralized settings. We address both problems by proposing a new notion for VC that we call incremental aggregation and that allows one to merge openings in a succinct way an unbounded number of times. We show two applications of this property. The rst one is immediate and is a method to generate openings in a distributed way. For the second one, we use incremental aggregation to design an algorithm for faster generation of openings via preprocessing.

We then proceed to realize SVC with incremental aggregation. We provide two constructions in groups of unknown order that, similarly to that of Boneh et al. (which supports only one-hop aggregation), have constant-size public parameters, commitments and openings. As an additional feature, for the rst construction we propose ecient arguments of knowledge of subvector openings which immediately yields a keyless proof of storage with compact proofs.

Finally, we address a problem closely related to that of SVC: storing a le eciently in completely decentralized networks. We introduce and construct veriable decentralized storage (VDS), a cryptographic primitive that allows to check the integrity of a le stored by a network of nodes in a distributed and decentralized way. Our VDS constructions rely on our new vector commitment techniques.


Table of Contents

1 Introduction 4 1.1 A new notion for SVCs: incremental aggregation 4 1.2 Verifiable Decentralized Storage 7 1.3 Concurrent Work 10

2 Preliminaries 10 2.1 Groups of Unknown Order and Computational Assumptions 11 2.2 Arguments of Knowledge 12

3 Vector Commitments with Incremental Aggregation 13 3.1 Vector Commitments with Subvector Openings 13 3.2 Incrementally Aggregatable Subvector Openings 15

4 Applications of Incremental Aggregation 17 4.1 Divide-and-Conquer Extensions of Aggregation and Disaggregation 17 4.2 Committing and Opening with Precomputation 18

5 Our Realizations of Incrementally Aggregatable Vector Commitments 20 5.1 Our First SVC Construction 20 5.2 Our Second SVC Construction 31 5.3 Comparison with Related Work 36

6 Arguments of Knowledge for Our First SVC 38 6.1 Building block: A Stronger Proof of Product 38 6.2 A Succinct AoK of Opening for our VC Construction 39 6.3 An AoK for commitments with common subvector 42 6.4 A Succinct AoK for Commitment on Subvector 42

7 Verifiable Decentralized Storage 43 7.1 Syntax 44 7.2 Correctness and Efficiency of VDS 46 7.3 Security of VDS 48

8 Our Realizations of VDS in Hidden-Order Groups 49 8.1 Our First VDS Construction 49 8.2 Our Second VDS Construction 56 8.3 Efficiency and Comparison 59

9 Experimental Evaluation 60

A PoProd protocol for Union of RSA Accumulators 64

B Committing and Opening with Precomputation for the [BBF19] SVC 65

C Succinct Arguments of Knowledge for VDS 66

D VDS Proof of Storage 67 D.1 Proof of Storage for our first VDS 69

E A Variant VDS Construction with Strong Security 71 E.1 Strong Security 71 E.2 A VDS Construction with Strong Security 71

7 Veriable Decentralized Storage43


F Experimental Results72


1 Introduction

Commitment schemes are one of the most fundamental cryptographic primitives. They can be seen as the digital equivalent of a sealed envelop: committing to a message m is akin to putting m in the envelop; opening the commitment is like opening the envelop and revealing the value inside. They have two basic properties. Hiding guarantees that a commitment reveals no information about the underlying message. Binding instead ensures that one cannot change its mind about the committed message; namely, it is not possible to open a commitment to two distinct values m 6= m⁰.

$$ \neq m^{\prime} $$

Vector commitments (VC) [LY10,CF13] are a special class of commitment schemes in which one can commit to a vector ~v of length n and to later open the commitment at any position i 2 [n]. The distinguishing feature of VCs is that both the commitment and an opening for a position i have size independent of n. In terms of security, VCs should be position binding, i.e., one cannot open a commitment at position i to two distinct values vi6= v. i0

$$ i\in[n] $$

$$ v_{i}\neq v_{i}^{\prime}. $$

VCs were formalized by Catalano and Fiore [CF13] who also proposed two constructions based on the CDH assumption in bilinear groups and the RSA assumption respectively. Both schemes have constant-size commitments and openings but suer from large public parameters that are O(n²) and O(n) for the CDH- and RSA-based scheme respectively. Noteworthy is that Merkle trees [Mer88] are VCs with O(logn)-size openings.

$$ O(n^{2}) $$

$$ O(n) $$

Two recent works [BBF19,LM19] proposed new constructions of vector commitments that enjoy a new property called subvector openings (also called batch openings in [BBF19]). A VC with subvector openings (called SVC, for short) allows one to open a commitment at a collection of positions I = fi₁;:::;img with a constant-size proof, namely of size independent of the vector’s length n and the subvector length m. This property has been shown useful for reducing communication complexity in several applications, such as PCP/IOP-based succinct arguments [LM19,BBF19] and keyless Proofs of Retrievability (PoR) [Fis18].

$$ I=\left{i_{1},\ldots,i_{m}\right} $$

In this work we continue the study of VCs with subvector openings with two main goals: (1) improving their eciency, and (2) enabling their use in decentralized systems.

With respect to eciency, although the most attractive feature of SVCs is the constant size of their opening proofs, a drawback of all constructions is that generating each opening takes at least time O(n) (i.e., as much as committing). This is costly and may harm the use of SVCs in applications such as the ones mentioned above.

$$ O(n) $$

When it comes to decentralization, VCs have been proposed as a solution for integrity of a distributed ledger (e.g., blockchains in the account model [BBF19]): the commitment is a succinct representation of the ledger, and a user responsible for the i-th entry can hold the corresponding opening and use it to prove validity of vi. In this case, though, it is not obvious how to create a succinct subvector opening for, say, m positions held by dierent users each responsible only of its own position/s in the vector. We elaborate more on the motivation around this problem in Section 1.2.

$$ v_{i} $$

1.1 A new notion for SVCs: incremental aggregation

To address these concerns, we dene and investigate a new property of vector commitments with subvector openings called incremental aggregation. In a nutshell, aggregation means that dierent subvector openings (say, for sets of positions I and J) can be merged together into a single concise (i.e., constant-size) opening (for positions I [J). This operation must be doable without knowing the entire committed vector. Moreover, aggregation is incremental if aggregated proofs can be further aggregated (e.g., two openings for I[J and K can be merged into one for I[J[K, and so on an unbounded number of times) and disaggregated (i.e., given an opening for set I one can create one for any K I).

$$ I\cup J\cup K $$

$$ K\subset I) $$

While a form of aggregation is already present in the VC of Boneh et al. [BBF19], in [BBF19] this can be performed only once. In contrast, we dene (and construct) the rst VC schemes where openings can be aggregated an unbounded number of times. This incremental property is key to address eciency and decentralized applications of SVCs, as we detail below.

Incremental aggregation for eciency. To overcome the barrier of generating each opening in linear time⁴ O (n), we propose an alternative preprocessing-based method. The idea is to precompute at commitment time an auxiliary information consisting of n=B openings, one for each batch of B positions of the vector. Next, to generate an opening for an arbitrary subset of m positions, one uses incremental aggregation in order to disaggregate the relevant subsets of precomputed openings, and then further aggregate for the m positions. Concretely, with this method, in our construction we can do the preprocessing in time O (nlogn) and generate an opening for m positions in time roughly O (mB logn).

$$ \operatorname{t i m e}^{4},O_{\lambda}(n) $$

$$ n/B $$

$$ O_{\lambda}(n\log n) $$

$$ O_{\lambda}(m B\log n) $$

With the VC of [BBF19], a limited version of this approach is also viable: one precomputes an opening for each bit of the vector in O (nlogn) time; and then, at opening time, one uses their onehop aggregation to aggregate relevant openings in time roughly O (mlogn). This however comes with a huge drawback: one must store one opening (of size p() = poly() where is the security parameter) for every bit of the vector, which causes a prohibitive storage overhead, i.e., p() n bits in addition to storing the vector ~v itself.

$$ O_{\lambda}(n\log n) $$

$$ O_{\lambda}(m\log n) $$

$$ \lambda $$

$$ p(\lambda)={\mathsf{p o l y}}(\lambda) $$

$$ p(\lambda)\cdot n $$

$$ \vec{v} $$

With incremental aggregation, we can instead tune the chunk size B to obtain exible time- p p p memory tradeos. For example, with B = n one can use p() n bits of storage to get O (m nlogn) opening time. Or, by setting B = p() as the size of one opening, we can obtain a storage overhead of exactly n bits and opening time O (mlogn).

$$ B={\sqrt{n}} $$

$$ p(\lambda){\sqrt{n}} $$

$$ O_{\lambda}(m{\sqrt{n}}\log n) $$

$$ B=p(\lambda) $$

$$ O_{\lambda}(m\log n) $$

Incremental aggregation for decentralization. Essentially, by its denition, incremental aggregation enables generating subvector openings in a distributed fashion. Namely, consider a scenario where dierent parties each hold an opening of some subvector; using aggregation they can create an opening for the union of their subvectors, moreover the incremental property allows them to perform this operation in a non-coordinated and asynchronous manner, i.e. without the need of a central aggregator. We found this application of incrementally aggregatable SVCs to decentralized systems worth exploring in more detail. To fully address this application, we propose a new cryptographic primitive called veriable decentralized storage which we discuss in Section1.2.

Constructing VCs with incremental aggregation. Turning to realizing SVC schemes with our new incremental aggregation property, we propose two SVC constructions that work in hiddenorder groups [DK02] (instantiatable using classical RSA groups, class groups [BH01] or the recently proposed groups from Hyperelliptic Curves [DG20]).

Our rst SVC has constant-size public parameters and constant-size subvector openings, and its security relies on the Strong RSA assumption and an argument of knowledge in the generic group model. Asymptotically, its eciency is similar to the SVC of Boneh et al. [BBF19], but concretely

4 We use the notation O ( ) to include the factor depending on the security parameter. Writing *O* (t)" essentially means *O*(t) cryptographic operations".

$$ O_{\lambda}(\cdot) $$

$$ “ O _ {\lambda} (t)” $$

$$ ^(O(t) $$ we outperform [BBF19]. We implement⁵ our new SVC and show it can obtain very fast opening times thanks to the preprocessing method described earlier: opening time reduces by several orders of magnitude for various choices of vector and opening sizes, allowing us to obtain practical opening times|of the order of seconds|that would be impossible without preprocessing|of the order of 20 hundred of seconds. In a le of 1 Mibit (2 bits), preprocessing reduces the time to open 2048 bits from one hour to less than 5 seconds!

$$ \ 2^{20}\mathrm{\ b i t s}) $$

For the second construction, we show how to modify the RSA-based SVC of [LM19] (which in turn extends the one of [CF13] to support subvector openings) in order to make it with constant- size parameters and to achieve incremental aggregation. Compared to the rst construction, it is more ecient and based on more standard assumptions, in the standard model.

Ecient Arguments of Knowledge of Subvector Opening. As an additional result, we propose ecient arguments of knowledge (AoK) with constant-size proofs for our rst VC. The rst AoK can prove knowledge of the subvector that opens a commitment at a public set of positions, and it extends to proving that two commitments share a common subvector. The second AoK is similar except that the subvector one proves knowledge of is also committed; essentially one can create two vector commitments C and C⁰ together with a short proof that C⁰ is a commitment to a subvector of the vector committed in C.

$$ C^{\prime} $$

$$ C^{\prime} $$

An immediate application of our rst AoK is a keyless proof of storage (PoS) protocol with compact proofs. PoS allows a client to verify that a server is storing intactly a le via a shortcommunication challenge-response protocol. A PoS is said keyless if no secret key is needed by clients, a property useful in open systems where the client is a set of distrustful parties (e.g., veriers in a blockchain) and the server may even be one of these clients. A classical keyless PoS is based on Merkle trees and random spot-checks [JK07], recently generalized to work with vector commitments [Fis18]. A drawback of this construction is that proofs grow with the number of spotchecks (and the size of the tree) and become undesirably large in some applications, e.g., if need to be stored in a blockchain. With our AoK we can obtain openings of xed size, as short as 2KB, which is 40x shorter than those based on Merkle trees in a representative setting without relying 6 on SNARKs (that would be unfeasible in terms of time and memory).

From Updatable VCs to Veriable Decentralized Storage. In their seminal work on VCs, Catalano and Fiore [CF13] also dened updatable VCs. This means that if one changes the i-th value of a vector from vito v it is possible to update: a commitment C to ~v into a commitment i0 C⁰ to ~v⁰, a valid opening for C (at any position) into a valid opening for C⁰. And importantly, these updates can be done without knowing the entire vector and in time that depends only on the number of modied positions. As an application, in [CF13] it is shown how updatable VCs can be used to realize veriable databases (VDB) [BGV11], a primitive that enables a client to outsource a database to an untrusted server in such a way that the client can retrieve (and update) a DB record and be assured that it has not been tampered with by the server.

$$ v_{i} $$

$$ C^{\prime} $$

$$ v_{i}^{\prime} $$

$$ \vec{v} $$

$$ \vec{v}^{\ j} $$

$$ C^{\prime} $$

In this work we study how to extend this model to a scenario where storage is distributed across dierent nodes of a decentralized network. This problem is motivated by the emerging trend of decentralized storage networks (DSNs), a decentralized and open alternative to traditional cloud

5 Code publicly available at https://github.com/nicola/rust-yinyan

6 We provide further details in Section6 storage and hosting services. Filecoin (which is built on top of IPFS), Storj, Dat, Freenet and general-purpose blockchains like Ethereum⁷ are some emerging projects in this space.

Our contribution is to put forward a new cryptographic primitive called veriable decentralized storage (VDS) that can be used to obtain data integrity guarantees in DSNs. We propose a denition of VDS and a construction obtained by extending the techniques of our VC scheme; in particular, both incremental aggregation and the arguments of knowledge are key ingredients for building a cost-eective VDS solution.

In the following section we elaborate on the VDS problem: we begin by discussing the requirements imposed by DSNs, and then give a description of our VDS primitive and realization.

1.2 Veriable Decentralized Storage

Decentralized Storage Networks. Openness and decentralization are the main characteristics of DSNs: anyone can enter the system (and participate as either a service provider or a consumer) and the system works without any central management or trusted parties. Abstracting from the details of each system, a DSN consists of participants called nodes that can be either a storage provider (aka storage node) or a client node. Akin to centralized cloud storage, a client can outsource the storage of large data; the key dierence of DSN however is that storage is provided by, and distributed across, a collection of nodes that can enter and leave the system at their wish. Also, DSNs can have some reward mechanism to economically incentivize storage nodes.

The openness and the presence of economic incentives raise a number of security questions that need to be solved in order to make these systems viable. In this work, we focus on the basic problem of ensuring that the storage nodes of the DSN are doing their job properly, namely:

How can any client node check that the whole DSN is storing correctly its data (in a distributed fashion)?

While this question is well studied in the centralized setting where the storage provider is a single server, for decentralized systems the situation is less satisfactory. In what follows we elaborate on the problem and the desired requirements, and then on our solution.

The Problem of Veriable Decentralized Storage. Consider a client who outsources the storage of a large le F, consisting of blocks (F₁;:::;FN), to a collection of storage nodes. A storage node can store a portion of F and the network is assumed to be designed in order to self-coordinate so that the whole F is stored, and to be fault-resistant (e.g., by having the same data block stored on multiple nodes). Once the le is stored, clients can request to the network to retrieve or modify a data block Fi(or more), as well as to append (resp. delete) blocks to (resp. from) the le.

$$ (F_{1},\ldots,F_{N}) $$

$$ F_{i} $$

In this scenario, our goal is to formalize a cryptographic primitive that can provide clients with the guarantee of integrity of the outsourced data and its modications. The basic idea of VDS is that: (i) the client retains a short digestFthat \uniquely" points to the le F; (ii) any operation performed by the network, be it a retrieval or a le modication, can be proven by generating a short certicate that is publicly veriable givenF.

$$ \delta_{F} $$

This problem is similar in scope to the one addressed by authenticated data structures (ADS) [Tam03]. But while ADS is centralized, VDS is not. In VDS nodes act as storage in a distributed

$$ \delta_{F} $$

7 https://filecoin.io, https://storj.io, https://datproject.org, https://freenetproject.org, https:// www.ethereum.org and uncoordinated fashion. This is more challenging as VDS needs to preserve some basic properties of the DSN:

Highly Local. The le is stored across multiple nodes and no node is required to hold the entire F : in VDS every node should function with only its own local view of the system, which should be much smaller than the whole F, e.g., logarithmic or constant in the size of F. Another challenge is dynamic les: in VDS both the digest and the local view must be locally updatable, possibly with the help of a short and publicly veriable update advice that can be generated by the node who holds the modied data blocks.

Decentralized Keyless Clients. In a decentralized system the notion of a client who outsources the storage of a le is blurry. It may for example be a set of mutually distrustful parties (even the entire DSN in the most extreme case, e.g., the le is a blockchain), or a collection of storage nodes themselves that decide to make some data available to the network. This comes with two implications:

  1. VDS must work without any secret key on the clients side, so that everyone in the network can delegate and verify storage. This keyless setting captures not only clients requiring no coordination, but also a stronger security model. Here the attacker may control both the storage node and the client, yet it must not be able to cheat when proving correctness of its storage. The latter is crucial in DSNs with economic rewards to well-behaving storage nodes⁸.

  2. In VDS a le F exists as long as some storage nodes provide its storage and a pointer to the le is known to the network through its digest. When a le F is modied into F⁰ and its digestF is updated intoF0, both versions of the le may coexist. Forks are possible and it is left to each client (or the application) to choose which digest to track: the old one, the new one, or both.

$$ F^{\prime} $$

$$ \delta_{F} $$

$$ \delta_{F^{\prime}} $$

Non-Coordinated Certicates Generation. There are multiple ways in which data retrieval queries can be answered in a DSN. In some cases, e.g., IPFS, after executing a P2P protocol to discover the storage nodes holding the desired data blocks, one gets such blocks from these nodes. In other cases (e.g., Freenet [CSWH01] or the original Gnutella protocol), data retrieval is also answered in a peer-to-peer non-coordinated fashion. When a query for blocks i₁;:::;impropagates through the network, every storage node replies with the blocks that it owns and these answers are aggregated and propagated in the network until they reach the client who asked for them. Notably, data 9 aggregation and propagation may follow dierent strategies. To accommodate exible aggregation strategies, in VDS we consider the incremental aggregation of query certicates in an arbitrary and bandwidth-ecient fashion. For example, short certicates for le blocks Fiand Fjshould be mergeable into a short certicate for (Fi;Fj) and this aggregation process should be carried on and on. Noteworthy that having certicates that stay short after each aggregation keeps the 10 communication overhead of the VDS integrity mechanism at a minimum.

$$ i_{1},\ldots,i_{m} $$

$$ F_{i} $$

$$ (F_{i},F_{j}) $$

$$ F_{j} $$

Dening VDS. We dene VDS as a collection of algorithms that capture all the properties above; these are the algorithms that can be executed by clients and storage nodes to maintain the system. A client for a le F is anyone who holds a digestFwith which it can: verify retrieval queries, verify and apply updates of F (that result in forks ofFinto some otherF0). A storage node for

$$ \delta_{F} $$

$$ \delta_{F^{\prime}} $$

$$ \delta_{F} $$

8 Since in a decentralized system a storage node may also be a client, an attacker could \delegate storage to itself" and use the client’s secret key to cheat in the proof in order to steal rewards (akin to the so-called \generation attack" in Filecoin [Lab17]).

9 E.g., in Freenet data is sent back along the same route the query came through, with the goal of providing anonymity between who requests and who delivers data.

10 The motivation of this property is similar to that of sequential aggregate signatures, see e.g., [LMRS04,BGR12].


some blocks FI= fFigi2Iof a le F is anyone that in addition to FIstores the digestFand a local state stFwith which it can: answer and certify retrieval queries for any subset of FI; push I and certify updates of F that involve blocks in FI; verify and apply updates of F from other nodes. Finally, any node can aggregate retrieval certicates for dierent blocks of the same le.

$$ F_{I}={F_{i}}_{i\in I} $$

$$ F_{I} $$

$$ F $$

$$ \delta_{F} $$

$$ \cdot_{F}I $$

$$ F_{I}^{\cdot} $$

$$ F_{I} $$

In our VDS notion, an update of F can be: (i) a modication of some blocks, (ii) appending new blocks, or (iii) deleting some blocks (from the end). In all cases, an update of F results into a le F⁰ and a new digestF0.

$$ F^{\prime} $$

$$ \delta_{F^{\prime}} $$

In terms of eciency, in VDS the digests and every certicate (for both retrieval queries or modications) are required to be of size at most O(log jF j); similarly, the storage node’s local state stFhas size at most O(jFIj + log jF j). In a nutshell, no node should run linearly in the size of the I le (unless it is explicitly storing it in full).

$$ O(\log{|F|}) $$

$$ \mathrm{s t}{F{I}} $$

$$ O(|F_{I}|+\log|F|) $$

The main security property of a VDS scheme intuitively requires that no ecient adversary can create a certicate for falsied data blocks (or updates) that passes verication. As an extra security property, we also consider the possibility that anyone holding a digestFcan check if the DSN is storing correctly F without having to retrieve it. Namely, we let VDS provide a Proof of Storage mechanism, which we dene similarly to Proof of Retrievability [JK07] and Proof of + Data Possession [ABC 07]. Similarly to the case of data retrieval queries, the creation of these proofs of storage must be possible while preserving the aforementioned properties of locality and no-central-coordination.

$$ \delta_{F} $$

$$ [\mathrm{A B C^{+}07}] $$

Constructing VDS. We propose two constructions of VDS in hidden-order groups. Both our VDS schemes are obtained by extending our rst and second SVC scheme respectively, in order to handle updates and to ensure that all such update operations can be performed locally. In particular we show crucial use of the new properties of our construction: subvector openings, incremental aggregation and disaggregation, and arguments of knowledge for sub-vector commitments (the latter for the rst scheme only).

Our two VDS schemes are based on the Strong RSA [BP97] and Strong distinct-prime-product root [LM19], and Low Order [BBF18] assumptions and have similar performances. The second scheme has the interesting property that the storage node can perform and propagate updates by running in time that is independent of even its total local storage. Our rst scheme instead supports an additional type of update that we call \CreateFrom". In it, a storage node holding a prex F⁰ of a le F can publish a new digestF0 corresponding to F⁰ as a new le and convince any client 11 about its correctness without the need for the client to know neither F nor F⁰. As a potential use case for this feature, consider a network that is supposed to store the entire editing history of some data (e.g., one or more les of a Git project); namely the i-th block of the VDS le contains the data value after the i-th edit (e.g., the i-th Git commit). Then \CreateFrom" can be used to veriably create a digest of any past version of the data (e.g., of a fork at any point in the past). Finally, our approach is not limited to a prex of the le but to whatever subset of indices we want to create the new le from.

$$ F^{\prime} $$

$$ \delta_{F^{\prime}} $$

$$ F^{\prime} $$

$$ {F^{\prime}.^{11}} $$

It is worth noting that by abstracting the ideas of our constructions, other VDS schemes can be 12 obtained using Merkle trees or RSA accumulators. Compared to a Merkle-tree based solution, we can achieve constant-size certicates for every operation as well as to (eciently) support compact

11 This can be seen as a deletion that can be performed without holding the blocks to be deleted and is more ecient to verify when the prex F⁰ is much smaller than F.

$$ F^{\prime} $$

12 In fact, a similar idea from RSA accumulators was discussed in [BBF19].


proofs of storage without expensive SNARKs¹³. Compared to RSA Accumulators, our rst VDS scheme takes advantage of our AoK thanks to which it supports CreateFrom updates and compact proofs of storage.

$$ \mathrm{S N A R K s^{13}} $$

Finally, we note that VDS shares similarities with the notion of updatable VCs [CF13] extended with incrementally aggregatable subvector openings. There are two main dierences. First, in VDS updates can be applied with the help of a short advice created by the party who created the update, whereas in updatable VC this is possible having only the update’s description. The second dierence is that in VDS the public parameters must be short, otherwise nodes could not aord storing them. This is not necessarily the case in VCs and in fact, to the best of our knowledge, there exists no VC construction with short parameters that is updatable (according to the updatability notion of [CF13]) and has incrementally aggregatable subvector openings. We believe this is an interesting open problem.

1.3 Concurrent Work

$$ \mathrm{[T A B^{+}20]} $$

$$ \mathrm{[T A B^{+}20]} $$

$$ \mathrm{[T A B^{+}20]} $$

2 Preliminaries

In this section we describe notation and denitions used throughout the paper.

Notation. We denote the security parameter by and the set of all polynomial functions by poly(). A function () is said negligible { denoted () 2 negl() { if it vanishes faster than the inverse of any polynomial. An algorithm A is said PPT if it is modeled as a probabilistic Turing machine that runs in time poly(). We denote by y A (x) the process of running A on input x and assigning the output to y. For a set S, jSj denotes its cardinality, and x $ S denotes selecting x uniformly at random over S. For a positive integer n 2 N we let [n] := f1*;:::;ng*. We denote n vectors ~v in bold, and for ~v 2M viis its entry at position i. We let Primes() be the set of all prime integers less than 2.

$$ \epsilon(\lambda) $$

$$ \epsilon (\lambda) \in \operatorname {n e g l} (\lambda) - \mathrm {i f} $$

$$ y\gets\mathcal{A}(x) $$

$$ x\gets\natural S $$

$$ _x $$

$$ n\in\mathbb{N} $$

$$ \vec{v} $$

$$ \vec{v}\in\mathcal{M}^{n}\ v_{i} $$

$$ [n]:={1,\ldots,n} $$

$$ 2^{\lambda} $$

13 In Merkle trees certicates depend logarithmically on the le size and linearly on the number of blocks (since they are not aggregatable).


2.1 Groups of Unknown Order and Computational Assumptions

Our constructions use a group G of unknown (aka hidden) order, in which the Low Order assumption [BBF18] and the Strong RSA assumption [BP97] or the Strong Distinct-Prime-Product Root assumption [LM19] (dened below) hold.

$$ \mathbb{G} $$

We let Ggen(1 ) be a probabilistic algorithm that generates such a group G with order in a 1 specic range [ordmin;ordmax] such that;; 2 negl(). ord1minord1max ordmax ordmin

$$ \left(1 ^ {\lambda}\right) $$

$$ \mathbb{G} $$

$$ \frac{1}{\mathsf{o r d}{imathrm{}{m i n}}},\frac{1}{\mathsf{o r d}{\mathrm{}{m a x}}},\frac{1}{\mathsf{o r d}{\mathrm{}{m a x}}\mathsf{-d r}{\mathrm{}{m i n}}}\in\mathsf{n e g l}(\lambda) $$

$$ [\mathsf{o r d}{m i n},\mathsf{o r d}{m a x}] $$

Denition 2.1(Low Order Assumption [BBF18]). We say that the low order assumption holds for Ggen if for any PPT adversary A: 2 3

$$ \Pr \left[ \begin{array}{c c} u ^ {\ell} = 1 \ \wedge u \neq 1 \ \wedge 1 < \ell < 2 ^ {\mathrm {p o l y} (\lambda)} & : \mathbb {G} \leftarrow \operatorname {G g e n} (\lambda) \ & (u, \ell) \leftarrow \mathcal {A} (\mathbb {G}) \end{array} \right] = \operatorname {n e g l} (\lambda) $$

Remark 2.1. The Low Order Assumption is implied by the more commonly known Adaptive Root assumption, which is dened below. For the reduction we refer to [BBF18]. We also notice that the denition of the Low Order assumption given in [BBF18] is for smaller ‘, 1 < ‘ < 2 , which was sucient for the application in the paper, whereas ours is for any polynomial-size ‘. We note that the same reduction to the Adaptive Root assumption described in [BBF18] also holds for our denition of the problem.

$$ \ell,,1<\ell<2^{\lambda} $$

Denition 2.2(Adaptive Root Assumption [Wes18]). We say that the adaptive root assumption holds for Ggen if for any PPT adversary (A₁; A₂): 2 3

$$ (\mathcal{A}{1},\mathcal{A}{2}) $$

$$ \Pr \left[ \begin{array}{c c} u ^ {\ell} = w & \mathbb {G} \leftarrow \operatorname {G g e n} (\lambda) \ \wedge w \neq 1 & : (w, \mathrm {s t a t e}) \leftarrow \mathcal {A} _ {1} (\mathbb {G}) \ & \ell \leftarrow $ \mathrm {P r i m e s} (\lambda) \ & u \leftarrow \mathcal {A} _ {2} (\ell , \mathrm {s t a t e}) \end{array} \right] = \operatorname {n e g l} (\lambda) $$

Denition 2.3(Strong-RSA Assumption [BP97]). We say that the strong RSA assumption holds for Ggen if for any PPT adversary A: 2 3

$$ \Pr \left[ \begin{array}{c c} u ^ {e} = g & \mathbb {G} \leftarrow \mathrm {G g e n} (\lambda) \ \wedge e i s p r i m e & : g \leftarrow $ \mathbb {G} \ & (u, e) \leftarrow \mathcal {A} (\mathbb {G}, g) \end{array} \right] = \mathrm {n e g l} (\lambda) $$

Denition 2.4(Strong Distinct-Prime-Product Root assumption [LM19]). We say that the Strong Distinct-Prime-Product Root assumption holds for Ggen if for any PPT adversary A: 2 3

$$ \operatorname*{P r}\left[\begin{matrix}{u\prod_{i\in S}e_{i}=g}&{\mathbb{G}\leftarrow\mathsf{G g e n}(\lambda)}\ {\wedge\forall i:e_{i}\in\mathsf{P r i m e s}(\lambda);:;g\leftarrow\ \ \ &\ \ }\ {\wedge\forall i\neq j,e_{i}\neq e_{j};;;;;;;;\ u({e_{i}}_{i\in S})\leftarrow\mathcal{A}(\mathbb{G},g)}\ \end{matrix}\right]=\mathsf{n e g l}(\lambda) $$

The assumption is implied by the strong RSA assumption over RSA groups.

As discussed in [BBF18,BBF19,LM19], two concrete instantiations of G are class groups [BH01] and the quotient group Z =f1*;* 1g of an RSA group [Wes18]. The reason why we cannot directly N

$$ \mathbb{D}_{N}^{}/{1,-1} $$ use the RSA group is that the order of 12* Z is known, and thus the adaptive root assumption N does not hold. In the quotient group, f1*;* 1g is the identity element; hence, knowing the order of 1 does not help in nding a root for a non-identity element and thus solving the adaptive root assumption.

$$ -1\in\mathbb{D}_{N}^{*} $$

$$ {-1,1} $$

Shamir’s Trick. Informally speaking, Shamir’s trick [Sha83] is a way to compute an xy-root of a group element g given an x-root and a y-root of it in groups of unknown order, when x and y are 1 1 co-prime. That is, given = gx, = gy, x and y, one can compute a;b st ax + by = 1 using x y 1 ax+by a b

$$ a,b $$

$$ y, $$

$$ \rho_{x}=g^{\frac{1}{x}},,\rho_{y}=g^{\frac{1}{y}} $$

$$ a x+b y=1 $$

$$ g^{{\frac{1}{x y}}},=,g^{{\frac{a x+b y}{x y}}},=,g^{{\frac{a}{y}}+{\frac{b}{x}}},=,\rho_{y}^{a}\cdot\rho_{x}^{b} $$

ShamirTrick(x;y;x;y) x y ifx6=ythen return*?* Use the extended Euclidean Algorithm to compute a;b;d s.t. ax + by = d = gcd(x;y) if d 6= 1 then return*?* b a returnx y

$$ (\rho_{x},\rho_{y},x,y) $$

$$ \rho_{x}^{x}\neq\rho_{y}^{y} $$

$$ a x+b y=d=\operatorname*{g c d}(x,y) $$

$$ \rho_{x}^{b}\rho_{y}^{a} $$

2.2 Arguments of Knowledge

Let R : X W ! f0*;* 1g be an NP relation for a language L = fx : 9w s.t. R(x;w) = 1g. An argument system for R is a triple of algorithms (Setup*;* P*;V) such that: Setup(1 ) takes as input a security parameter and outputs a common reference string crs; the prover P(crs;x;w*) takes as input the crs, the statement x and witness w; the verier V(crs*;x*) takes in the crs, the statement x, and after interacting with the prover outputs 0 (reject) or 1 (accept). An execution between the prover and verier is denoted with hP(crs*;x;w*);V(crs;x)i = b, where b 2f0*;* 1g is the output of the verier. If V uses only public randomness, we say that the protocol is public coin.

$$ R:\mathcal{X}\times\mathcal{W}\rightarrow{0,1} $$

$$ \mathcal {L} = \left{x: \exists w \text {s . t .} R (x, w) = 1 \right} $$

$$ \mathsf{S e t u p}(1^{\lambda}) $$

$$ \lambda $$

$$ \mathsf{P}(\mathsf{c r s},x,w) $$

$$ w, $$

$$ x cdot $$

$$ \mathsf{V}(\mathsf{c r s},x) $$

$$ \langle\mathsf{P}(\mathsf{c r s},x,w),\mathsf{V}(\mathsf{c r s},x)\rangle=b $$

$$ b \in {0, 1 } $$

Denition 2.5(Completeness). We say that an argument system (Setup*;* P*;V) for a relation R : XW!f0;* 1g is complete if, for all (x;w) 2XW such that R(x;w) = 1 we have

$$ R:\mathcal{X}\times\mathcal{W}\rightarrow{0,1} $$

$$ (x,w)\in\mathcal{X}\times\mathcal{W} $$

$$ R(x,w)=1 $$

$$ \operatorname*{P r}\left[\langle\mathsf{P}(\mathsf{c r s},x,w),\mathsf{V}(\mathsf{c r s},x)\rangle=1:\mathsf{c r s}\leftarrow\mathsf{S e t u p}(1^{\lambda})\right]=1. $$

Consider an adversary A = (A₀; A₁) modeled as a pair of algorithms such that A₀(crs)! (x; state) (i.e. outputs an instance x 2X after crs Setup() is run) and A₁(crs*;x;* state) interacts with a honest verier. We want an argument of knowledge to satisfy the following properties:

$$ \mathcal{A},=,(\mathcal{A}{0},\mathcal{A}{1}) $$

$$ \mathcal{A}_{0}(\mathsf{c r s});\rightarrow $$

$$ x\in\mathcal{X} $$

$$ {mathsf c r r}\leftarrow{\mathsf S{e e t u p}}(\lambda) $$

$$ \mathcal{A}_{1}(\mathsf{c r s},x $$

Soundness. We say that an argument (Setup*;* P*;*V) is sound if for all PPT adversaries A = (A₀; A₁) we have

$$ \mathcal{A}=(\mathcal{A}{0},\mathcal{A}{1}) $$

$$ \operatorname*{P r}\left[\begin{matrix}{\langle\mathcal{A}{1}(\mathsf{c r s},x,\mathsf{s t a t e}),\mathsf{V}(\mathsf{c r s},x)\rangle=1}&{\mathsf{c r s}\leftarrow\mathsf{S e t u p}(\lambda)}\ {\mathrm{a n d}\nexists{}}&{R{R}(x,w)=1}&{(x,\mathsf{s t a t e})\leftarrow\mathcal{A}{0}(\mathsf{c r s})}\ \end{matrix}\right]\in\mathsf{n e g l}(\lambda). $$

Knowledge Extractability. We say that (Setup*;* P*;*V) is an argument of knowledge if for all polynomial time adversaries A₁ there exists an extractor E running in polynomial time such that, for all adversaries A₀ it holds 2 3

$$ \mathcal{A}_{1} $$

$$ \mathcal{A}_{0} $$

$$ \operatorname*{P r}\left[\begin{matrix}{\langle\mathcal{A}{1}(\mathsf{c r s},x,\mathsf{s t a t e}),\mathsf{V}(\mathsf{c r s},x)\rangle=1}&{\mathsf{c r s}\leftarrow\mathsf{S e t a p}(\lambda)}\ {\operatorname{a n d}\ (x,w^{\prime})\notin\mathcal{R}}&{w x\leftarrow\mathcal{A}{0}(\mathsf{c r s})}\ {\operatorname{a n d}\ (x,w^{\prime})\notin\mathcal{R}}&{w w^{\prime}\leftarrow\mathcal{E}(\mathsf{c r s},x,\mathsf{s t a t e})}\ \end{matrix}\right]\in\mathsf{n e g l}(\lambda). $$


Succinctness. Finally we informally recall the notion of succinct arguments, which requires the communication and verier’s running time in a protocol execution to be independent of the witness length.

Succinct Arguments of Knowledge for Hidden Order Groups. We recall two succinct AoK protocols for the exponentiation relation in groups of unknown order that have been recently proposed by Boneh et. al. [BBF19]. Both protocols work for a hidden order group G generated by Ggen in which the adaptive root assumption holds. Also, they are public-coin protocols that can be made non-interactive in the random oracle model using the Fiat-Shamir [FS87] heuristic and its generalization to multi-round protocols [BCS16].

1.Protocol PoE: is an argument system for the following relation:

$$ R_{\mathsf{P o E}}={((u,w,x)\in\mathbb{G}^{2}\times\mathbb{Z},\varnothing),:,u^{x}=w\in\mathbb{G},,,right, $$

PoE is a sound argument system under the adaptive root assumption for Ggen. It is neither zeroknowledge nor knowledge sound. Its main feature is succinctness, as the verier can get convinced x about u = w without having to execute the exponentiation herself. Moreover the information 14 sent by the prover is only 1 group element.

$$ \boldsymbol{u}^{x}=\boldsymbol{w} $$

2.Protocol PoKE : is an argument of knowledge for the following relation, parametrized by a generator g 2 G: x R = (w;x) 2 G Z : g = w 2 G

$$ g\in\mathbb{G} $$

$$ R_{\mathsf{P o K E}^{*}}=\left{\ w,x\ \in\mathbb{G}\times\mathbb{Z},:,g^{x}=w\in\mathbb{G},,,,\right} $$

PoKE is an argument of knowledge that in [BBF19] is proven secure in the generic group model for hidden order groups [DK02]. This protocol is also succinct consisting of only 1 group element and 1 eld element in Z₂.

$$ \mathbb{Z}_{2^{\lambda}} $$

3.Protocol PoKE2: is an argument of knowledge for the following relation, parametrized by a generator g 2 G: x R = ((w;u) 2 G²*;x 2* Z) : u = w 2 G

$$ g\in\mathbb{G} $$

$$ R _ {\mathrm {P o K E 2}} = \left{\left((w, u) \in \mathbb {G} ^ {2}, x \in \mathbb {Z}\right): u ^ {x} = w \in \mathbb {G} \quad \right} $$

PoKE2 is similar to PoKE but it is secure for arbitrary bases u chosen by the adversary, instead of bases randomly sampled a priori as in PoKE . Similarly, it is an argument of knowledge in the generic group model for hidden order groups and is also succinct, with a proof consisting of 2 group elements and 1 element of Z₂.

$$ \mathbb{Z}_{2^{\lambda}} $$

3 Vector Commitments with Incremental Aggregation

In this section, we recall the notion of vector commitment with subvector openings [CF13,LM19, BBF19] and then we formally dene our new incremental aggregation property.

3.1 Vector Commitments with Subvector Openings

A vector commitment (VC) [LY10,CF13] is a primitive that allows one to commit to a vector ~v of length n in such a way that it can later open the commitment at any position i 2 [n]. For

$$ i\in[n] $$

14 Technically, this protocol is not succinct as there is no witness and the verier must read and process the exponent x; however, verication is still more ecient than running the full exponentiation.

$$ x; $$ security, a VC should be position binding in the sense that it is not possible to open a commitment to two dierent values at the same position. Also, what makes VC interesting is conciseness, which requires commitment and openings to be of xed size, independent of the vector’s length.

In our work we consider a generalization of vector commitments proposed by Lai and Malavolta 15 [LM19] that is called VCs with subvector openings, which is in turn a specialization of the notion of functional vector commitments by Libert et al. [LRY16]. In a nutshell, a functional VC is like a VC with the additional possibility of opening the commitment to a function of the committed vector, i.e., f (~v). Subvector openings are a specic class of functions in which one can open the commitment to an ordered collection of positions (with a short proof).

In this section we recall this generalization of vector commitments with subvector openings (that for brevity we call SVC). It is easy to see that the original notion of Catalano and Fiore [CF13] is a special case when the opened subvector includes one position only.

We begin by recalling the notion of subvectors from [LM19].

Denition 3.1(Subvectors [LM19]). Let M be a set, n 2 N be a positive integer and I = n fi₁;:::;ijIjg [n] be an ordered index set. For a vector ~v 2 M, the I-subvector of ~v is ~vI:= (vi1;:::;vi). jIj

$$ n\in\mathbb{N} $$

$$ I= $$

$$ \left{i_{1},\ldots,i_{|I|}\right}\subseteq\left[n\right] $$

$$ \vec{v}\in\mathcal{M}^{n} $$

$$ \vec{v} $$

$$ {\vec{v}}_{I}\ := $$

$$ \ v_{i_{1}},\ldots,v_{i_{|I|}}) $$

n Let I;J [n] be two sets, and let ~vI;~vJbe two subvectors of some vector ~v 2M. The ordered union of ~vIand ~vJis the subvector ~vI[J:= (vk1;:::;vkm), where I [ J = fk₁;:::;kmg is the ordered sets union of I and J.

$$ I,J\subseteq[n] $$

$$ \vec{v}{I},\vec{v}{J} $$

$$ \vec{v}\in\mathcal{M}^{n} $$

$$ \ {\vec{v}}_{I} $$

$$ \vec{v}{I\cup J}:=\left(v{k_{1}},\ldots,v_{k_{m}}\right) $$

$$ {vec v,} $$

$$ I\cup J=\left{k_{1},\ldots,k_{m}\right} $$

Denition 3.2(Vector Commitments with Subvector Openings). A vector commitment scheme with subvector openings (SVC) is a tuple of algorithms VC = (VC*:* Setup*;VC:* Com*;VC:* Open*;* VC*:* Ver) that work as follows and satisfy correctness*,* position binding and conciseness dened below.

VC*:* Setup(1*; M*)! crs Given the security parameter, and description of a message space M for the vector components, the probabilistic setup algorithm outputs a common reference string crs*.*

$$ {\mathfrak{S e t u p}}(1^{\lambda},{\mathcal{M}})\to{\mathfrak{t}} $$

n VC*:* Com(crs*;~v*)! (C; aux) On input crs and a vector ~v 2M, the committing algorithm outputs a commitment C and an auxiliary information aux*.*

$$ \mathsf{V C.C o m(c r s,\vec{v})}\to\left(\mathcal{C}\right) $$

$$ \vec{v}\in\mathcal{M}^{n} $$

m VC*:* Open(crs*;I;~y;* aux)!IOn input the CRS crs*, a vector ~y 2M, an ordered index set I* N and auxiliary information aux*, the opening algorithm outputs a proof*Ithat ~y is the I-subvector of the committed message.

$$ \ \vec{y}\in\mathcal{M}^{m} $$

$$ I\subset\mathbb{N} $$

VC*:* Ver(crs*;C;I;y;I)! b 2f0;* 1g On input the CRS crs*, a commitment C, an ordered set of in-* m dices I N*, a vector ~y 2M and a proof*I, the verication algorithm accepts (i.e., it outputs 1) only ifIis a valid proof that C was created to a vector ~v = (v₁;:::;vn) such that ~y = *v*I.

$$ \mathcal{C},I,\vec{y},\pi_{I})\rightarrow b\in\left{0,1\right} $$

$$ I\subset\mathbb{N} $$

$$ \vec{y}\in\mathcal{M}^{m} $$

$$ \pi_{I}. $$

$$ i f,\pi_{I} $$

$$ {\vec{v}}=(v_{1},\ldots,v_{n}) $$

$$ {\vec{y}}={\vec{v}}_{I} $$

Correctness. A SVC scheme VC is (perfectly) correct if for all 2 N*, any vector length n any* n ordered set of indices I [n], and any ~v 2M, we have:

$$ I\subseteq[n] $$

$$ \lambda\in\mathbb{N} $$

$$ \ {vec v\in{\mathcal{M}}^{n}} $$

$$ \operatorname*{P r}\left[\mathsf{V C}V e r(\mathsf{c r s},C,I,\vec{v}{I},\pi{I})=1\right.\quad\begin{array}{c}{\mathsf{c r s}\leftarrow\mathsf{V C}.\mathsf{S e t u p}(1^{\lambda},\mathcal{M})}\ {(C,\mathsf{a u x})\leftarrow\mathsf{V C}.\mathsf{C o m}(\mathsf{c r s},\vec{v})}\ {\pi_{I}\leftarrow\mathsf{V C}.\mathsf{O p e n}(\mathsf{c r s},I,\vec{v}_{I},\mathsf{a u x})}\ \end{array} $$

15 This is also called VCs with batchable openings in an independent work by Boneh et al. [BBF19].


Position Binding. A SVC scheme VC satises position binding if for all PPT adversaries A we have: 2 3 VC*:* Ver(crs*;C;I;~y;*) = 1

$$ \operatorname*{P r}\left[\begin{matrix}{\mathsf{V C}\mathsf{V e r}(\mathsf{c r s},C,I,\vec{y},\pi)=1}\ {\wedge\ \vec{y}\neq\vec{y}^{\prime}\wedge}\ {\mathsf{V C}\mathsf{V e r}(\mathsf{c r s},C,I,\vec{y}^{\prime},\pi^{\prime})=1}\ \end{matrix}:\begin{matrix}{\mathsf{c r s}\leftarrow\mathsf{V C}\mathsf{S e t u p}(1^{\lambda},\mathcal{M})}\ {(C,I,\vec{y},\pi,\vec{y}^{\prime},\pi^{\prime})\leftarrow\mathcal{A}(\mathsf{c r s})}\ \end{matrix}\right]\in\mathsf{n e g l}(\lambda) $$

Conciseness. A vector commitment is concise if there is a xed polynomial p() in the security parameter such that the size of the commitment C and the outputs of VC*:* Open are both bounded by p(), i.e., they are independent of n.

$$ p(\lambda) $$

$$ p(\lambda) $$

Vector Commitments with Specializable Universal CRS. The notion of VCs dened above slightly generalizes the previous ones in which the generation of public parameters (aka common reference string) depends on a bound n on the length of the committed vectors. In contrast, in our notion VC*:* Setup is length-independent. To highlight this property, we also call this primitive vector commitments with universal CRS.

Here we formalize a class of VC schemes that lies in between VCs with universal CRS (as dened above) and VCs with length-specic CRS (as dened in [CF13]). Inspired by the recent + work of Groth et al. [GKM 18], we call these schemes VCs with Specializable (Universal) CRS. In a nutshell, these are schemes in which the algorithms VC*:* Com*;VC:* Open and VC*:* Ver work on input a length-specic CRS crsn. However, this crsnis generated in two steps: (i) a length-independent, probabilistic setup crs VC*:* Setup(1*; M*), and (ii) a length-dependent, deterministic specialization crsnVC*:* Specialize(crs*;n*). The advantage of this model is that, being VC*:* Specialize deterministic, it can be executed by anyone, and it allows to re-use the same crs for multiple vectors lengths.

$$ [\mathrm{G K M^{+}18}] $$

$$ \mathsf{c r s}_{n} $$

$$ \mathsf{c r s}_{n} $$

$$ \leftarrow\mathsf{V C.S e t u p(1^{\lambda},M)} $$

$$ \mathsf{c r s}_{n}\leftarrow\mathsf V C.\mathsf{S p e c i a l i z e}(\mathsf{c r s},n) $$

Denition 3.3(VCs with Specializable CRS). A VC scheme VC has a specializable CRS if there exists a DPT algorithm VC*:* Specialize(crs*;n*) that, on input a (universal) CRS crs generated by VC*:* Setup(1*; M*) and an integer n = poly(), produces a specialized CRS crsnsuch that the ?? algorithms VC*:* Com*,* VC*:* Open and VC*:* Ver can be dened in terms of algorithms VC*:* Com*,* VC*:* Open ? and VC*:* Ver as follows:

$$ \mathsf{V C.S p e c i a l i z e(\mathsf{c r s},n)} $$

$$ \mathsf{V C.S e t u p}(1^{\lambda},\mathcal{M}) $$

$$ n,=,\ \mathsf{p o l y}(\lambda) $$

$$ \mathit{C R S6c\ s{}}_{n} $$

$$ \ {vee!.}{\mathsf{C o m}}^{\ } $$

$$ \ {\sf{V C}}.{{psf e n}}^{\star} $$

??? { VC*:* Com(crs*;v*) sets n := *jvj, runs* crsnVC*:* Specialize(crs*;n*) and (C;aux) VC: Com (crsn;~v), ?? and returns C := (C;n) and aux := (aux*;n*).

$$ .mathsf C C o(\mathsf{c r s},\vec{v}) $$

$$ n:=|\vec{v}| $$

$$ \mathsf{c r s}_{n}\leftarrow\mathsf V C.\mathsf{S p e c i a l i z e}(\mathsf{c r s},n) $$

$$ (\hat{C}^{\star},\mathsf{a t x}^{\star})\leftarrow\mathsf{V c m}^{\star}(\mathsf{c t s}_{n},\vec{v}) $$

$$ C:=(C^{\star},n) $$

$$ \mathsf{a u x}:=\left(\mathsf{a u x}^{\star},n\right) $$

? { VC*:* Open(crs*;I;y;* aux) parses aux := (aux*;n*), runs crsnVC*:* Specialize(crs*;n*) and returns ?? IVC*:* Open (crsn*;I;y;* aux ).

$$ :!=;(\mathsf{a u x}^{\star},n) $$

$$ c s_{n}\leftarrow V c.S p e c d i/e(l r s,n) $$

$$ \pi_{I}\leftarrow V C.O D e n^{\star}(\sf{c r S}_{n},I,\vec{y},a lsf^{{\ }!l}{x}^{{\star}}) $$

? { VC*:* Ver(crs*;C;I;y;I) parses C := (C;n), runs* crsnVC*:* Specialize(crs*;n*) and returns ?? VC*:* Ver (crsn*;C;I;y;I).*

$$ -mathsf V C C,\mathsf{V e r}(\mathsf{c r s},\mathcal{C},I,\vec{y},\pi_{I}) $$

$$ C:=(C^{\star},n) $$

$$ C s_{n}\leftarrow V C.S D e c i d l i z e(C1,)nonumber $$

$$ \mathsf{V C.V e r}^{\star}(\mathsf{c r s}{n},\mathcal{C}^{\star},I,\vec{y},\pi{I}) $$

Basically, for a VC with specializable CRS it is sucient to describe the algorithms VC*:* Setup*;* ??? VC*:* Specialize*;VC:* Com*;VC:* Open and VC*:* Ver. Furthermore, a concrete advantage is that when working on multiple commitments, openings and verications that involve the same length n, one can execute crsnVC*:* Specialize(crs*;n*) only once.

$$ \mathsf{V C.e r^{\star}} $$

$$ \mathsf{V C.C o m}^{\star},\mathsf{V C.0p e n}^{\star} $$

$$ n, $$

3.2 Incrementally Aggregatable Subvector Openings

$$ C s_{n}\leftarrow..5!p_a c e a d i e e(c1s,n) $$

In a nutshell, aggregation means that dierent proofs of dierent subvector openings can be merged together into a single short proof which can be created without knowing the entire committed vector.


Moreover, this aggregation is composable, namely aggregated proofs can be further aggregated. Following a terminology similar to that of aggregate signatures, we call this property incremental aggregation (but can also be called multi-hop aggregation). In addition to aggregating openings, we also consider the possibility to \disaggregate" them, namely from an opening of positions in the set I one can create an opening for positions in a set K I.

$$ K\subset I $$

We stress on the two main requirements that make aggregation and disaggregation non-trivial: all openings must remain short (independently of the number of positions that are being opened), and aggregation (resp. disaggregation) must be computable locally, i.e., without knowing the whole committed vector. Without such requirements, one could achieve this property by simply concatenating openings of single positions.

Denition 3.4(Aggregatable Subvector Openings). A vector commitment scheme VC with subvector openings is called aggregatable if there exists algorithms VC*:* Agg*,* VC*:* Disagg working as follows:

VC*:* Agg(crs*;* (I;~vI;I); (J;~vJ;J))!Ktakes as input two triples (I;~vI;I); (J;~vJ;J) where I jIj jJ j and J are sets of indices, ~vI2M and ~vJ2M are subvectors, andIandJare opening proofs. It outputs a proofKthat is supposed to prove opening of values in positions K = I [ J.

$$ \ \ cdot\mathsf{A g g}(\mathsf{c r s},(I,\vec{v}{I},\pi{I}),(J,\vec{v}{J},\pi{J}))\to\pi_{K} $$

$$ (I,\vec{v}{I},\pi{I}),(J,\vec{v}{J},\pi{J}) $$

$$ \vec{v}_{I},\in,\mathcal{M}^{|I|} $$

$$ \vec{v}_{J}\in\mathcal{M}^{|J|} $$

$$ \pi I $$

$$ \pi J $$

$$ \pi_{K} $$

$$ K=I\cup J $$

VC*:* Disagg(crs*;I;v*I;I;K)!Ktakes as input a triple (*I;v*I;I) and a set of indices K I, and it outputs a proofKthat is supposed to prove opening of values in positions K.

$$ I,\vec{v}{I},\pi{I},K)\rightarrow\pi_{K} $$

$$ (I,\vec{v}{I},\pi{I}) $$

$$ K\subset I $$

$$ \pi_{K} $$

$$ K $$

The aggregation algorithm VC*:* Agg must guarantee the following two properties:

Aggregation Correctness. Aggregation is (perfectly) correct if for all 2 N*, all honestly gener-* ated crs VC*:* Setup(1*; M*), any commitment C and triple (I;~vI;I) s.t. VC*:* Ver(crs*;C;I;~v*I;I) = 1*, the following two properties hold:*

$$ \lambda\in\mathbb{N}, $$

$$ \leftarrow\ {mathsf V C C}.{\mathsf{S e t u p}}(1^{\lambda},{\mathcal{M}}) $$

$$ (I,\vec{v}{I},\pi{I}) $$

$$ \ \mathsf V V e(\mathsf{c r s},mathcal{C},I,\vec{v}{I},\pi{I})= $$

1.for any triple (J;~vJ;J) such that VC*:* Ver(crs*;C;J;~v*J;J) = 1*,*

$$ \mathsf{r}(\mathsf{c r s},C,J,\ \ \vec{v}{J},\pi{J})=1 $$

$$ (J,\vec{v}{J},\pi{J}) $$

$$ \Pr \left[ \mathrm {V C}. \operatorname {V e r} \left(\mathrm {c r s}, C, K, \vec {v} _ {K}, \pi_ {K}\right) = 1: \pi_ {K} \leftarrow \mathrm {V C}. \operatorname {A g g} \left(\mathrm {c r s}, \left(I, \vec {v} _ {I}, \pi_ {I}\right), \left(J, \vec {v} _ {J}, \pi_ {J}\right)\right) \right] = 1 $$

where K = I[J and ~vKis the ordered union ~vI[Jof ~vIand ~vJ;

$$ K=I\cup J $$

$$ \vec{v}_{K} $$

$$ \ {\vec{v}}_{I\cup J} $$

$$ \vec{v}_{I} $$

$$ \ {\vec{v}}_{J} $$

2.for any subset of indices K I,

$$ K\subset I $$

$$ \operatorname*{P r}\left[\mathsf{V C,V e r}(\mathsf{c r s},C,K,\vec{v}{K},\pi{K})=1,:,\pi_{K}\gets\mathsf{V C.D i s a g g}(\mathsf{c r s},I,\vec{v}{I},\pi{I},K)\right]=1 $$

$$ \vec{v}{K}=(v{i_{l}}){i{l}\in K} $$

where ~vK= (vi)i 2K, for ~vI= (vi1;:::;vi). l l jIj

$$ {\vec{v}}{I}=(v{i_{1}},\ldots,v_{i_{|I|}}) $$

Aggregation Conciseness. There exists a xed polynomial p( ) in the security parameter such that all openings produced by VC*:* Agg and VC*:* Disagg have length bounded by p().

$$ p(\cdot) $$

$$ p(\lambda) $$

We remark that the notion of specializable CRS can apply to aggregatable VCs as well. In this ?? case, we let VC*:* Agg (resp. VC*:* Disagg) be the algorithm that works on input the specialized crsn instead of crs.

$$ \mathsf{V C.A g g}^{\star} $$

$$ \mathsf{c r s}_{n} $$


4 Applications of Incremental Aggregation

We discuss two general applications of the incremental aggregation property of vector commitments.

One application is generating subvector openings in a distributed and decentralized way. Namely, assume a set of parties hold each an opening of some subvector. Then it is possible to create a (concise) opening for the union of their subvectors by using the VC*:* Agg algorithm. Moreover, the incremental (aka multi-hop) aggregation allows these users to perform this operation in an arbitrary order, hence no coordination or a central aggregator party are needed. This application is particularly useful in our extension to veriable decentralized storage.

The second application is to generate openings in a faster way via preprocessing. As we mentioned in the introduction, this technique is useful in the scenario where a user commits to a vector and then must generate openings for various subvectors, which is for example the use case when the VC is used for proofs of retrievability and IOPs [BBF19].

So, here the goal is to achieve a method for computing subvector openings in time sub-linear in the total size of the vector, which is the barrier in all existing constructions. To obtain this speedup, the basic idea is to (A) compute and store openings for all the position at commitment time, and then (B) use the aggregation property to create an opening for a specic set of positions. In order to obtain eciency using this approach it is important that both steps (A) and (B) can be computed eciently. In particular, step (A) is challenging since typically computing one opening takes linear time, hence computing all of them would take quadratic time.

In this section, we show how steps (A) and (B) can benet from disaggregation and aggregation respectively. As a preliminary for this technique, we begin by describing two generic extensions of (incremental) aggregation (resp. disaggregation) that support many inputs (resp. outputs). Then we show how these extended algorithms can be used for committing and opening with preprocessing.

4.1 Divide-and-Conquer Extensions of Aggregation and Disaggregation

We discuss how the incremental property of our aggregation and disaggregation can be used to dene two extended versions of these algorithms. The rst one is an algorithm that can aggregate many openings for dierent sets of positions into a single opening for their union. The second one does the opposite, namely it disaggregates one opening for a set I into many openings for partitions of I.

Aggregating Many Openings We consider the problem of aggregating several openings for S n sets of positions I₁;:::;Iminto a single opening for Ij. Our syntax in Denition3.4only j=1 considers pairwise aggregation. This can be used to handle many aggregations by executing the pairwise aggregation in a sequential (or arbitrary order) fashion. Sequential aggregation might however be costly since it would require executing VC*:* Agg on increasingly growing sets. If fa(k) is the complexity of VC: Agg on two sets of total size k, then the total complexity of the sequential P Pj 1 m method is f ( jIlj + jIjj), which for example is quadratic in m, for fa(k) = (k). j=2 l=1

$$ I_{1},\ldots,I_{m} $$

$$ \cup_{j=1}^{n}I_{j} $$

$$ f_{a}(k) $$

$$ \textstyle\sum_{j=2}^{m}f\bigl(\sum_{l=1}^{j-1}\left|I_{l}\right|+\left|I_{j}\right|\bigr) $$

$$ m, $$

$$ f_{a}(k)=\theta(k) $$

In Fig.1, we show an algorithm, VC*:* AggManyToOne, that is a nearly optimal solution for aggregating m openings based on a divide-and-conquer methodology. Assuming for simplicity that all Ij’s have size bounded by some s, then the complexity of VC*:* AggManyToOne is given by the following recurrence relation: m

$$ I _ {j} \mathrm {' s} $$

$$ T(m)=2T\left({frac{m}{2}}\right)+f_{a}(s\cdot m) $$


VC: AggManyToOne(crs; (Ij;~vIj;j)j2[m]) 1 : if m = 1 return 1 2 : *m⁰ m=*2 m0m 3 : L [j=1Ij; R [j=m0+1Ij;

VC: DisaggOneToMany(crs;B;I;~vI;I) 1 : if n = jIj = B return I 2 : n⁰ n=2 n0m 3 : L [j=1ij; R [j=n0+1ij;

0 4 : L VC*:* AggManyToOne(crs*;* (Ij;~vIj;j)j=1;:::;m0) 4 :LVC*:* Disagg(crs*;I;vI;I;L*) 0 5 : R VC*:* AggManyToOne(crs*;* (*Ij;vIj;j*)j=m0+1;:::;m) 5 :RVC*:* Disagg(crs*;I;vI;I;R*) 0 6 : L[R VC*:* Agg(crs*;* (*L;vL;L*); (R;~vR;R)) 6 : ~L VC*:* DisaggOneToMany(crs*;B;L;~vL;*L)

7 : return L[R

0 7 : ~R VC*:* DisaggOneToMany(crs*;B;R;vR;*R) 8 : return *Ljj~R*

$$ n^{\prime}\leftarrow n/2 $$

$$ m^{\prime}\leftarrow m/2 $$

$$ L\leftarrow\cup_{j=1}^{m^{\prime}}I_{j},;;;R\leftarrow\cup_{j=m^{\prime}+1}^{m}I_{j}, $$

$$ \pi_{L}\leftarrow\mathsf{V C.A g g M a n y T o O n e}(\mathsf{c r s},(I_{j},\vec{v}{I{j}},\pi_{j})_{j=1,\dots,m^{\prime}}) $$

$$ \pi_{L}^{\prime}\leftarrow\mathsf{V C.D i s a g g}(\mathsf{c r s},I,\vec{v}{I},\pi{I},L) $$

$$ \pi_{R}^{\prime}\leftarrow\mathsf{V C.D i s a g g}(\mathsf{c r s},I,\vec{v}{I},\pi{I},R) $$

$$ \pi_{R}\leftarrow\mathsf{V C.A g g M a n y T o O n e}(\mathsf{c r s},(I_{j},\vec{v}{I{j}},\pi_{j})_{j=m^{\prime}+1,\dots,m}) $$

$$ L\leftarrow\cup_{j=1}^{n^{\prime}}i_{j},;;;R\leftarrow\cup_{j=n^{\prime}+1}^{m}i_{j}, $$

$$ \vec {\pi} _ {L} \leftarrow \mathrm {V C}. \mathrm {D i s a g g O n e T o M a n y} (\mathrm {c r s}, B, L, \vec {v} _ {L}, \pi_ {L} ^ {\prime}) $$

$$ \pi_{L\cup R}\leftarrow\mathsf{V C.A g g}(\mathsf{c r s},(L,\vec{v}{L},\pi{L}),(R,\vec{v}{R},\pi{R})) $$

Fig. 1. Extensions of Aggregation and Disaggregation

which for example solves to (s mlogm) if fa(n) 2 (n), or to (s mlog(sm) logm) if fa(n) 2 (nlogn).

$$ \Theta (s \cdot m \log m) $$

$$ f_{a}(n)\in\Theta(n) $$

$$ \varTheta(s\cdot m\log(s m)\log m){\mathrm{i f}}f_{a}(n)\in $$

$$ \theta(n\log n) $$

Disaggregating from One to Many Openings We consider the problem that is dual of the one above, namely how to disaggregate an opening for a set I into several openings for sets I₁;:::;Im that form a partition of I. Our syntax in Denition3.4only considers disaggregation from one set I to one subset K of I. Similarly to the aggregation case, disaggregating from one set to many subsets can be trivially obtained via a sequential application of VC*:* Disagg on all pairs (I;Ij). This however can be costly if the number of partitions approaches the size of I, e.g., if we want to disaggregate to all the elements of I.

$$ I_{1},\ldots,I_{m} $$

$$ (I,I_{j}) $$

In Fig.1, we show an algorithm, VC*:* DisaggOneToMany, we show a divide-and-conquer algorithm for disaggregating an opening for a set I of size m into m⁰ = m=B openings, each for a partition of size B. For simplicity, we assume that m is a power of 2, and B j m.

$$ m^{\prime}=m/B $$

$$ B\mid m. $$

Let fd(jIj) be the complexity of VC*:* Disagg. Then the complexity of VC*:* DisaggOneToMany is given by the following recurrence relation:

$$ f_{d}(|I|) $$

$$ T(m)=2T\left(\frac{m}{2}\right)+2f_{d}(m/2) $$

which for example solves to (mlog(m=B)) if fd(n) 2 (n), or to (mlogmlog(m=B)) if fd(n) 2 (nlogn).

$$ \theta(m{mathrm l o o}(m/B)){\mathrm{i f}}f_{d}(n)\in\theta(n) $$

$$ f_{d}(n)\in $$

4.2 Committing and Opening with Precomputation

Our preprocessing method works with a exible choice of a parameter B that allows for dierent time-memory tradeos. In a nutshell, ranging from 1 to n, a larger B reduces memory but increases opening time while a smaller B (e.g., B = 1) requires larger storage overhead but gives the fastest opening time.

$$ B\ (\mathrm{e.g.},,B=1) $$

Let B be an integer that divides n, and let n⁰ = n=B: The core of our idea is that, during the commitment stage, one can create openings for n⁰ = n=B subvectors of ~v that cover the all vector (e.g., B contiguous positions). LetP1;:::;Pbe such openings; these elements are stored n0 as advice information.

$$ n^{\prime},=,n/B $$

$$ n^{\prime},=,n/B $$

$$ \pi_{P_{1}},\ldots,\pi_{P_{n^{\prime}}} $$


Next, in the opening phase, in order to compute the opening for a subvector ~vIof m positions, one should: (i) fetch the subset of openingsPjsuch that, for some S, I [j2SPj, (ii) possibly disaggregate some of them and then aggregate in order to computeI. To give a very general example of the above process, assume one has stored and

$$ \pi_{P}{}_{j} $$

$$ S,,I\subseteq\cup_{j\in S}P_{j} $$

$$ {\vec{v}}_{I} $$

$$ \pi I $$

To give a very general example of the above process, assume one has stored $\pi_{{1,2}}$ and $\pi_{{3,4,5}}$ and is asked for $\pi_{{2,3}}$, then she has to compute first $\pi_{2}$ and $\pi_{3}$ by disaggregating $\pi_{{1,2}}$ and $\pi_{{3,4,5}}$ respectively, and then aggregate them to $\pi_{{2,3}}$. Below are two more examples in picture:
B=2 $\vec{v}_{1}$ $\vec{v}_{2}$ $\vec{v}_{3}$ $\vec{v}_{4}$ $\vec{v}_{5}$
B=2 1 0 0 0 1 1 1 0 1 1 1 1 0 1 0 0 0 0 0
$\pi_{{1,2}}$ $\pi_{{3,4}}$ $\pi_{{5}}$
$\approx p(\lambda)\cdot n/2$ bits in opening advice
B=n $\vec{v}_{1}$ $\vec{v}_{2}$ $\vec{v}_{3}$ $\vec{v}_{4}$ $\vec{v}_{5}$
B=n 1 0 0 0 1 1 1 0 1 1 1 1 0 1 0 0 0 0 0

$$ \pi_{{1,2}} $$

$$ \pi_{2} $$

$$ \pi_{{2,3}} $$

$$ \pi_{{3,4,5}} $$

$$ \pi_{3} $$

$$ \pi_{{1,2}} $$

$$ \pi_{{2,3}} $$

$$ \vec{v}_{1} $$

$$ \ {\vec{v}}_{2} $$

$$ \vec{v}_{3} $$

$$ {\vec{v}}_{4} $$

$$ \vec{v}_{5} $$

$$ \pi_{{{5}}} $$

$$ \approx p(\lambda)\cdot n/2 $$

$$ \vec{v}_{1} $$

$$ {vec v}_{2} $$

$$ \vec{v}_{3} $$

$$ \ {\vec{v}}_{4} $$

$$ \vec{v}_{5} $$

p() bits in opening advice

The two algorithms are described in detail in Fig.2.

$$ (C, \mathrm {a u x}) \leftarrow \mathrm {V C}. \operatorname {C o m} (\mathrm {c r s}, \vec {v}) $$

VC: PPCom(crs;B;v) 1 : (C; aux) VC*:* Com(crs*;v*)

VC: FastOpen(crs;B; aux;I) 1 : Let Pj := f(j 1)B + i : i 2 [B]g; 8j 2 [n⁰]

2 : VC*:* Open(crs*;* [n];~v; aux) 2 : Let I := fi₁;:::;img [ 3 : ~ VC*:* DisaggOneToMany(crs*;B;[n];~v;*) 3 : Let S minimal set s.t. P I j

4 : aux := ( 1*;:::;n0;~v*) 5 : return C; aux

j2S 4 : for j 2 S do : 5 : Ij I\Pj 6 :j0VC*:* Disagg(crs*;Pj;vPj;j;Ij*) 7 : endfor 8 : I VC*:* AggManyToOne(crs*;*((*Ij;vIj;*j0))j2S) 9 : return I

$$ P_{j}\ :=={(j-1)B+i\ ::i\in:[B]},\forall j:\in:[n^{\prime}] $$

$$ \pi^{*}\leftarrow\mathsf{V C.O0e n n}(\mathsf{c r s},[n],\vec{v},\mathsf{a u x}) $$

$$ I:={i_{1},\ldots,i_{m}} $$

$$ \vec{\pi}\leftarrow\mathsf{V C.D i s a g g O n e T o M a n y}(\mathsf{c r s},B,[n],\vec{\upsilon},\pi^{*}) $$

$$ \bigcup P_{j}\supseteq I $$

$$ \mathsf{a u x}^{*}:=\left(\pi_{1},\ldots,\pi_{n^{\prime}},\vec{v}\right) $$

$$ j\in S $$

$$ I_{j}\leftarrow I\cap P_{j} $$

$$ \pi_{j}^{\prime}\leftarrow\mathsf{V C.D i s a g g}(\mathsf{c r s},P_{j},\vec{v}{P{j}},\pi_{j},I_{j}) $$

$$ \pi_{I}\leftarrow\mathsf{V C.A g g M a n y T o O n e(\ c r s,:((I_{j},:\vec{\upsilon}{I{j}},::pi_j{j}^{\prime})){j\in S})} $$

Fig. 2. Generic algorithms for committing and opening with precomputation.

In terms of auxiliary storage, in addition to the vector ~v itself, one needs at most (n=B)p() bits, where p() is the polynomial bounding the conciseness of the SVC scheme. In terms of time complexity, VC*:* PPCom requires one execution of VC*:* Com, one execution of VC*:* Open, and one execution of VC*:* DisaggOneToMany, which in turn depends on the complexity of VC*:* Disagg; VC*:* FastOpen 16 requires to perform jSj disaggregations (each with a set jIjj such that their sum is jIj), and one execution of VC*:* AggManyToOne on jSj openings. Note that VC*:* FastOpen’s running time depends only on the size m of the set I and size B of the buckets Pj, and thus oers various tradeos by adjusting B.

$$ \vec{v} $$

$$ (n/B)p(\lambda) $$

$$ p(\lambda) $$

$$ |I_{j}| $$

$$ |I||)^{16} $$

$$ P_{j} $$

More specic running times depend on the complexity of VC*:* Com*;VC:* Open*;VC:* Agg, and VC*:* Disagg of the given SVC scheme. See AppendixBfor these results for our construction.

16 Note that for B = 1 the disaggregation step can be skipped.


5 Our Realizations of Incrementally Aggregatable Vector Commitments

In this section we describe our new SVC realizations.

5.1 Our First SVC Construction

An overview of our techniques. The basic idea underlying our VC can be described as a generic construction from any accumulator with union proofs. Consider a vector of bits ~v = (v₁;:::;vn) 2 n f0*;* 1g. In order to commit to this vector we produce two accumulator, Acc₀ and Acc₁, on two partitions of the set S = f1*;:::;ng*. Each accumulator Accbcompresses the set of positions i such that vi= b. In other words, Accbcompresses the set S=b:= fi 2 S : vi= bg with b 2f0*;* 1g. In order to open to bit b at position i, one can create an accumulator membership proof for the statement i 2 S~ where we denote by S~ the alleged set of positions that have value b. b b

$$ {\vec{v}}=\left(v_{1},\ldots,v_{n}\right)\in $$

$$ {0,1}^{n} $$

$$ \ \mathrm{A c c}_{0} $$

$$ \ \mathsf{A c c}_{1} $$

$$ S={1,\ldots,n} $$

$$ \mathsf{A c c}_{b} $$

$$ \ \mathrm{A c c}_{b} $$

$$ v_{i}=b $$

$$ S_{=b}:=\left{i\in S:v_{i}=b\right} $$

$$ i, $$

$$ b \in {0, 1 } $$

$$ i\in\tilde{S}_{b} $$

$$ \tilde{S}_{b} $$

However, if the commitment to ~v is simply the pair of accumulators (Acc₀*;Acc₁) we do not achieve position binding as an adversary could for example include the same element i in both accumulators. To solve this issue we set the commitment to be the pair of accumulators plus a succinct non-interactive proof that the two sets S~; S*~ they compress constitute together a S 0 1 partition of S. Notably, this proof guarantees that each index i is in either S~ or S~, and thus S 0 1 prevents an adversary from also opening the position i to the complement bit 1 b.

$$ \vec{v} $$

$$ (\mathsf{A c c}{0},\mathsf{A c c}{1}) $$

$$ \pi\ {cal S S} $$

$$ \tilde{S}{0},\tilde{S}{1} $$

$$ \tilde{S}_{0} $$

$$ {tilde\mathcal S}_{1} $$

$$ 1-b $$

The construction described above could be instantiated with any accumulator scheme that admits an ecient and succinct proof of union. We, though, directly present an ecient construction based on RSA accumulators [Bd94,BP97,CL02,Lip12,BBF19] as this is ecient and has some nice extra properties like aggregation and constant-size parameters. Also, part of our technical contribution to construct this VC scheme is the construction of ecient and succinct protocols for proving the union of two RSA accumulators built with dierent generators.

Succinct AoK Protocols for Union of RSA Accumulators Let G be a an hidden order group as generated by Ggen, and let g₁;g₂;g₃ 2 G be three honestly sampled random generators. We propose a succinct argument of knowledge for the following relation

$$ g_{1},g_{2},g_{3}\in\mathbb{G} $$

$$ R_{\mathsf{P o P r o d}{2}}=\left{\left((Y,C),(a,b)\right)\in\mathbb{G}^{2}\times\mathbb{Z}^{2}:::Y=g{1}^{a}g_{2}^{b}\wedge C=g_{3}^{a\cdot b}:::\right} $$

Our protocol (described in Fig.3) is inspired by a similar protocol of Boneh et al. [BBF19], PoDDH, for a similar relation in which there is only one generator (i.e., g₁ = g₂ = g₃, namely for DDH tuples a b ab (g;g;g)). Their protocol has a proof consisting of 3 groups elements and 2 integers of bits.

$$ (\mathrm{i.e.,},g_{1}=g_{2}=g_{3} $$

$$ \left(g ^ {a}, g ^ {b}, g ^ {a b}\right) $$

As we argue later PoProd₂ is still sucient for our construction, i.e., for the goal of proving c that C = g₃ is an accumulator to a set that is the union of sets represented by two accumulators a b A = g₁ and B = g₂ respectively. The idea is to invoke PoProd₂ on (Y;C) with Y = A B.

$$ \mathsf{P o P r o d}_{2} $$

$$ C=g_{3}^{c} $$

$$ B=g_{2}^{b} $$

$$ \mathsf{P o P r o d}_{2} $$

$$ A=g_{1}^{a} $$

$$ (Y,C) $$

$$ Y=A\cdot B $$

To prove the security of our protocol we rely on the adaptive root assumption and, in a nonblack-box way, on the knowledge extractability of the PoKRep and PoKE protocols from [BBF19]. The latter is proven in the generic group model for hidden order groups (where also the adaptive root assumption holds), therefore we state the following theorem.

Theorem 5.1. The PoProd₂ protocol is an argument of knowledge for RPoProd2in the generic group model.

$$ R_{\mathsf{P o P r o d_{2}}} $$


Setup(1) : run G $ Ggen(1), g₁;g₂;g₃ $ G, set crs := (G*;g₁;g₂;g₃*). Prover’s input: (crs*;* (Y;C); (a;b)). Verier’s input: (crs*;* (Y;C)). V! P: ‘ $ Primes() P! V: := ((QY;QC);ra;rb) computed as follows { (qa;qb;qc) (ba=‘c; bb=‘c; bab=‘c) { (ra;rb) (a mod ‘;b mod ‘) qa qb qc { (QY;QC) := (g₁ g₂;g₃) V(crs; (Y;C);‘;): { Compute rc ra rbmod ‘ ‘ ra rb ‘ rc { Output 1 i ra;rb2 [‘] ^ QYg₁ g₂ = Y ^ QCg₃ = C

$$ \mathtt{S e t u p}(1^{\lambda}):;{\tt r u n};\mathbb{G}\leftarrow\mathtt{G g e n}(1^{\lambda}),;g_{1},g_{2},g_{3}\leftarrow\mathfrak{s}\mathbb{G},;\operatorname{s e t};{\tt c r s}:=(\mathbb{G},g_{1},g_{2},g_{3}) $$

$$ \underline{{\mathsf{{V}}}}\to\mathsf{{}}\ {mathsf{{{P}}}}\colon\ell\leftarrow\ \mathsf{{P P g i m e s}}(\lambda) $$

$$ \underline{{\mathcal{P}\to\mathcal{V}}}:\pi:=((Q_{Y},Q_{C}),r_{a},r_{b}) $$

$$ -\ (q_{a},q_{b},q_{c})\leftarrow(\vert a/vert\vert,\vert b/vert\vert,vert a b/vert\vert/\vert)) $$

$$ -\ (r_{a},r_{b})\leftarrow(a $$

$$ \mathsf{V}(\mathsf{c r s},(Y,C),\ell,\pi) $$

$$ -(({{Y}},{{}Q{}{C}}):=(g{1}^{q_{a}}g_{2}^{q_{b}},g_{3}^{q_{c}}) $$

$$ r_{c}\leftarrow r_{a}\cdot r_{b} $$

$$ r _ {a}, r _ {b} \in [ \ell ] \wedge Q _ {Y} ^ {\ell} g _ {1} ^ {r _ {a}} g _ {2} ^ {r _ {b}} = Y \wedge Q _ {C} ^ {\ell} g _ {3} ^ {r _ {c}} = C $$

Fig. 3. PoProd₂ protocol

Proof For ease of exposition we show a security proof for a slight variant of the protocol PoProd₂. Then, towards the end of this proof we show that security of this variant implies security for our 0 protocol. We let PoProd₂ be the same protocol as PoProd₂ with only dierence that the prover computes also rcrarb(mod ‘) and sends rcin the proof, and the verier V checks in the verication if rc= rarb(mod ‘).

$$ \mathsf{P o P r o d}_{2}{}^{\prime} $$

$$ r_{c}\gets r_{a}\cdot r_{b} $$

$$ r_{c} $$

$$ rboldsymbol{}{c}=\boldsymbol{r}{a}\cdot\boldsymbol{r}_{b} $$

0 Let A⁰ = (A⁰0; A⁰1) be an adversary of the Knowledge Extractability of PoProd₂ such that: 0 0 ((Y;C);state) A0(crs), A⁰1(crs; (Y;C);state) executes with V(crs; (Y;C)) the protocol PoProd₂ and the verier accepts with a non-negligible probability. We will construct an extractor E⁰ that having access to the internal state of A⁰1and on input (crs, (Y;C)*;*state), outputs a witness (a;b) of R 0 with overwhelming probability and runs in (expected) polynomial time. PoProd2

$$ \mathcal{A}^{\prime},=,(\mathcal{A}{0}^{\prime},\mathcal{A}{1}^{\prime}) $$

$$ \ ((Y,C),\mathsf{s t a t e});\leftarrow;\mathcal{A}{0}^{\prime}(\mathsf{c r s}),;\mathcal{A}{1}^{\prime}(\mathsf{c r s},(Y,C),\mathsf{s t a} $$

$$ \mathsf{V}(\mathsf{c r s},(Y,C)) $$

$$ \mathcal{E}^{\prime} $$

$$ \mathcal{A}_{1}^{\prime} $$

$$ R_{\sf{P o P r o d}^{\prime}} $$

0 To prove knowledge extractability of PoProd₂ we rely on the knowledge extractability of the protocol PoKRep from [BBF19], which is indeed implicit in our protocol. More precisely, given 0 a PoProd₂ execution between A⁰ and V, (‘;QY;QC;ra;rb;rc), E⁰ constructs an adversary AY= (AY;0; AY;1) of PoKRep Knowledge Extractability and, by using the input and internal state of A⁰1, simulates an execution between AYand V: AY;0outputs (crsY;Y; state) := ((G*;g₁;g₂*);Y; state), AY;1 outputs (QY;ra;rb). It is obvious that if the initial execution is accepted by V so is the PoKRep execution. From Knowledge Extractability of PoKRep we know that there exists an extractor EY a b corresponding to AY;1that outputs (a;b) such that g₁g₂ = Y. Additionally, it is implicit from the extraction that a = ra(mod ‘) and b = rb(mod ‘) (for more details we refer to the Knowledge Extractability proof of PoKRep in [BBF19]). So, E⁰ uses EYand gets (a;b). Similarly, it simulates c PoKE for g₃ = C, uses the extractor Ecand gets c.

$$ \mathrm {P o P r o d} _ {2} ^ {\prime} $$

$$ \mathcal{A}^{\prime} $$

$$ \mathsf{P}{0}\mathsf{P r r}{0}{\ d_{2}}^{\prime} $$

$$ {\mathcal{A}}_{Y},= $$

$$ \mathsf{V},(\ell,Q_{Y},Q_{\mathcal{C}},r_{a},r_{b},r_{c}),,\xi^{\prime} $$

$$ (\mathcal{A}{Y,0},\mathcal{A}{Y,1}) $$

$$ \mathcal{A}_{Y} $$

$$ \ {\mathcal{A}}_{Y,0} $$

$$ (\mathsf{c r s}{Y},Y,\mathsf{s t a t e}):=((\mathbb{G},g{1},g_{2}),Y,\mathsf{s t a t e}),\mathcal{A}_{Y,1} $$

$$ (Q_{Y},r_{a},r_{b}) $$

$$ \mathcal{E}_{Y} $$

$$ \mathcal{A}_{Y,1} $$

$$ (a,b) $$

$$ g_{1}^{a}g_{2}^{b}=Y $$

$$ a=r_{a} $$

$$ b=r_{b} $$

$$ \ell) $$

$$ {\mathcal{E}}^{\prime} $$

$$ \mathcal{E}_{Y} $$

$$ (a,b) $$

$$ g_{3}^{c}=C $$

$$ \mathcal{E}_{c} $$

As one can see, the expected running time of E⁰ is the (expected) time to obtain a successful 1 execution of the protocol plus the running time of the 2 extractors: + tE+ tEc= poly(). Y

$$ {\mathcal{E}}^{\prime} $$

$$ \frac{1}{\epsilon}+t\pm_{Y}+t\pmb{\varepsilon}_{c}=\mathsf{p o l y}(\lambda) $$

Now what is left to prove to conclude our theorem is to show that the extracted a;b;c are such that a b = c with all but negligible probability. To this end, we observe that we could run E⁰ 0 a second time using a dierent random challenge ‘; by using again EY; Ec(after simulating the 0 0 0 a0b0a b corresponding PoKRep and PoKE executions) we would get a;b;c such that g₁ g₂ = Y = g₁g₂, c0c 0 0 0 g₃ = C = g₃. We argue that a = a, b = b and c = c holds over the integers with overwhelming probability under the assumption that computing a multiple of the order of the group G is hard (such assumption is in turn implied by the adaptive root assumption). If such event does not hold one can make a straightforward reduction to this problem. Therefore, we proceed by assuming that from the two executions we have a = a⁰, b = b⁰, and c = c⁰ over the integers. Moreover, since both

$$ \mathcal{E}^{\prime} $$

$$ \mathcal{E}{Y},\mathcal{E}{c} $$

$$ \ell; $$

$$ g_{1}^{a^{\prime}}g_{2}^{b^{\prime}}=Y=g_{1}^{a}g_{2}^{b} $$

$$ g_{3}^{c^{\prime}}=C=g_{3}^{c} $$

$$ a^{\prime},b^{\prime},c^{\prime} $$

$$ c=c^{\prime} $$

$$ a=a^{\prime},,b=b^{\prime} $$

$$ a=a^{\prime},,b=b^{\prime} $$

$$ c=c^{\prime} $$


0 0 0 0 executions are accepted we have rc0= rar (mod ‘)) c⁰ = a⁰ b⁰ (mod ‘)) c = a b (mod ‘), b0 0 but ‘ was sampled uniformly at random from Primes() after a;b;c were determined. So a b = c #ffactors of ab cg poly() over the integers, unless with a negligible probability = negl(). jPrimes()j jPrimes()j

$$ \boldsymbol{r}{c}^{\prime}=\boldsymbol{r}{a}^{\prime}\cdot\boldsymbol{r}_{b}^{\prime} $$

$$ \ell^{\prime})\Rightarrow c^{\prime}=a^{\prime}\cdot b^{\prime} $$

$$ \ell^{\prime})\Rightarrow c=a\cdot b $$

$$ \ell^{\prime}) $$

$$ \ell^{\prime} $$

$$ a,b,c $$

$$ a\cdot b=c $$

$$ \leq \frac {# \left{\text {f a c t o r s o f} a b - c \right}}{\left| \operatorname {P r i m e s} (\lambda) \right|} \leq \frac {\operatorname {p o l y} (\lambda)}{\left| \operatorname {P r i m e s} (\lambda) \right|} = \operatorname {n e g l} (\lambda) $$

Finally, it is trivial to reduce the Knowledge Extractability of PoProd₂ to Knowledge Ex- 0 tractability of PoProd₂. Let a generic adversary A against the Knowledge Extractability of protocol PoProd₂ such that the verier accepts with a non-negligible probability, we can construct a generic 0 adversary A⁰ against Knowledge Extractability of PoProd₂, so that the verier accepts with the same probability. A⁰ runs the crs Setup(1 ) algorithm and sends crs to A. The adversary A outputs ((Y;C);state) A0(crs) and sends it to A⁰0, which outputs as it is. Then A⁰1interacts with 0 V in the protocol PoProd₂ (as a prover) and at the same time with A₁ in PoProd₂ (as a verier). After receiving ‘ from V it forwards it to A₁. A₁ answers with := ((QY;QC);ra;rb). A⁰ computes 1 0 0 rcrarbmod ‘ and sends := ((QY;QC);ra;rb;rc) to V. The verier V accepts with the same probability that a verier of PoProd₂ would accept since rc= rarbmod ‘ in both cases. 0 From Knowledge Extractability of PoProd₂ we know that there is an extractor E⁰ that outputs a witness (a;b). Then E = E⁰ is a valid extractor for PoProd₂.

$$ \mathsf{P o P r o d}_{2}{}^{\prime} $$

$$ \mathsf{P o P r o d}_{2} $$

$$ \epsilon_{,} $$

$$ \mathcal{A}^{\prime} $$

$$ \mathsf{P o P r o d}_{2}{}^{\prime} $$

$$ \mathcal{A}^{\prime} $$

$$ \leftarrow\mathsf{S e t u p}(1^{\lambda}) $$

$$ \mathcal{A}. $$

$$ ((Y,C) $$

$$ \leftarrow\mathcal{A}_{0}(\mathsf{c r s}) $$

$$ \mathcal{A}_{0}^{\prime} $$

$$ \ {\mathcal A}_{1}^{\prime} $$

$$ \mathcal{A}_{1} $$

$$ \mathsf{P}{0}\mathsf{P r r}{0}{\ d_{2}}^{\prime} $$

$$ \mathcal{A}{1},,\mathcal{A}{1} $$

$$ \pi:=((\mathcal{Q}{Y},\mathcal{Q}{\mathcal{C}}),r_{a},r_{b}).\mathcal{A}_{1}^{I} $$

$$ r_{c}\gets r_{a}r_{b} $$

$$ \pi^{\prime}:=((Q_{Y},Q_{\mathcal{C}}),r_{a},r_{b},r_{c}) $$

$$ \pi^{\prime} $$

$$ \mathsf{P o P r o d}_{2} $$

$$ \pi $$

$$ r_{c}=r_{a}r_{b} $$

$$ \mathrm {P o P r o d} _ {2} ^ {\prime} $$

$$ \ {\mathcal{E}}={\mathcal{E}}^{\prime} $$

$$ {\mathcal{E}}^{\prime} $$

$$ \mathsf{P o P r o d}_{2} $$

a b a b In AppendixAwe give a protocol PoProd that proves g₁ = A ^ g₂ = B instead of g₁g₂ = Y (i.e., a version of PoDDH with dierent generators). Despite being conceptually simpler, it is slightly less ecient than PoProd₂, and thus use the latter in our VC construction.

$$ g_{1}^{a}=A\wedge g_{2}^{b}=B $$

$$ g_{1}^{a}g_{2}^{b}=Y $$

$$ \mathsf{P o P r o d}_{2} $$

Hash to prime function and non-interactive PoProd₂. Our protocols can be made noninteractive by applying the Fiat-Shamir transform. For this we need an hash function that can be modeled as a random oracle and that maps arbitrary strings to prime numbers, i.e., Hprime: 17 f0*;* 1g! Primes(2). A simple way to achieve such a function is to apply a standard hash function H : f0*;* 1g! f0*;* 1g² to an input ~y together with a counter i, and if py;i= H(~y;i) is prime then output py;i, otherwise continue to H(~y;i + 1) and so on, until a prime is found. Due to the distribution of primes, the expected running time of this method is O(), assuming that H’s outputs are uniformly distributed. We do not insist, though, in the previous or any other specic instantiation of Hprimein this work. For more discussion on hash-to-prime functions we refer to [GHR99,CMS99,CS99,BBF19,OWB19].

$$ \mathsf{H}_{\mathsf{p r i m e}} $$

$$ {0,1}^{*},\to,\mathsf{P r m e s}(2\lambda)^{17} $$

$$ \ {mathsf H::{{0,1}}^{*}}\rightarrow{{0,1}^{2\lambda}} $$

$$ \vec{y} $$

$$ i, $$

$$ p_{y,i},=,\mathsf{H}(\vec{y},i) $$

$$ p_{y,i} $$

$$ \mathsf{H}(\vec{y},i+1) $$

$$ O(\lambda) $$

$$ \mathsf{H}_{\mathsf{p r i m e}} $$

Our First SVC Construction Now we are ready to describe our SVC scheme. For an intuition we refer the reader to the beginning of this section. Also, we note that while the intuition was given for the case of committing to a vector of bits, our actual VC construction generalizes this idea to vectors where each item is a block of k bits. This is done by creating 2k accumulators, each of them holding sets of indices i for specic positions inside each block vj.

$$ v_{j} $$

Notation and Building Blocks. To describe our scheme we use the notation below:

k n { Our message space is M = f0*;* 1g. Then for a vector ~v 2M, we denote with i 2 [n] the vector’s position, i.e., vi2M, and with j 2 [k] the position of its j’th bit. So vijdenotes the j-th bit in position i.

$$ \mathcal{M}={0,1}^{k} $$

$$ \vec{v}\in\mathcal{M}^{n} $$

$$ i\in[n] $$

$$ \mathrm{i.e.,}\ v v_{i}\in\mathcal{M} $$

$$ j\in[k] $$

$$ j^{\ } $$

$$ v_{i j} $$

$$ j-\mathrm{t h} $$

17 As pointed out in [BBF18], although for the interactive version of such protocols the prime can be of size, the non-interactive version requires at least a double-sized prime 2, as an explicit square root attack was presented. =2 Notably, even in the interactive version a 2-attacker would still be able to succeed in breaking knowledge- =2 soundness with 2 probability, with a-sized prime.

$$ \lambda, $$

$$ 2\lambda, $$

$$ 2^{\lambda/2} $$

$$ 2^{-\lambda/2} $$


{ We make use of a deterministic collision resistant function PrimeGen that maps integers to primes. In our construction we do not need its outputs to be random (see e.g., [BBF19] for possible instantiations).

{ As a building block, we use the PoProd₂ AoK from the previous section.

$$ \mathsf{P}{0}\mathsf{P P r}{0}\mathsf{d}_{2} $$

{ PartndPrimeProd(I;~y)! ((aI1;bI1);:::;(aIk;bIk)): given a set of indices I = fi₁;:::;img [n] m and a vector ~y 2M, this function computes 0 1

$$ (I,\vec{y})\ \to{}\ ((a_{I1},b_{I1}),\dots,(a_{I k},b_{I k})) $$

$$ \vec{y}\in\mathcal{M}^{m} $$

$$ I=\left{i_{1},\ldots,i_{m}\right}\subseteq[n] $$

$$ (a_{I j},b_{I j}):=\left(\prod_{l=1:y_{l j}=0}^{m}p_{i_{l}},\prod_{l=1:y_{l j}=1}^{m}p_{i_{l}}\right)\quad\mathrm{f o r}j=1,\ldots,k $$

where piPrimeGen(i) for all i.

$$ p_{i}\gets{\mathsf{P r i m e G e n}}(i) $$

Basically, for every bit position j 2 [k], the function computes the products of primes that correspond to, respectively, 0-bits and 1-bits.

$$ j,\in,[k] $$

In the special case where I = [n], we omit the set of indices from the notation of the outputs, i.e., PartndPrimeProd([n];~v) outputs ajand bj.

$$ I=[n] $$

$$ ([n],\vec{v}) $$

$$ b_{j} $$

$$ a_{j} $$

{ PrimeProd(I)! uI: given a set of indices I, this function outputs the product of all primes Q corresponding to indices in I. Namely, it returns uI:= pi. In the special case I = [n], we i2I denote the output of PrimeProd([n]) as un.

$$ -{\sf P r P m e P r d}(I),\to,u_{I}: $$

$$ \textstyle u_{I}:=\prod_{i\in I}p_{i} $$

$$ I=[n] $$

$$ u_{n} $$

$$ \mathsf{P r i m e P r o d}([n]) $$

Notice that by construction, for any I and ~y, it always holds aIjbIj= uI.

$$ a_{I j}\cdot b_{I j}=u_{I} $$

$$ \vec{y} $$

SVC Scheme. Below we describe our SVC scheme and then we show its incremental aggregation.

k VC*:* Setup(1*; f0;* 1g)! crs generates a hidden order group G Ggen(1 ) and samples three generators g;g₀;g₁ G. It also determines a deterministic collision resistant function PrimeGen that maps integers to primes. Returns crs = (G*;g;g₀;g₁;*PrimeGen)

$$ \mathsf{V C.S e t u p}(1^{\lambda},{0,1}^{k})\rightarrow $$

$$ \mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda}) $$

$$ g,g_{0},g_{1}\leftarrow\mathbb{G} $$

$$ \ mathrm\ {\mathit{R e t u r n s~c r s}}=(\mathbb{G},g,g_{0},g_{1},\mathsf{P r i m e G e n}) $$

u VC*:* Specialize(crs*;n*)! crsncomputes unPrimeProd([n]) and Un= g, and returns crsn (crs*;U*n). One can think of Unas an accumulator to the set [n].

$$ u_{n}:\leftarrow:\mathsf{P r i m e P r o d}([n]) $$

$$ U_{n},=,g^{u} $$

$$ {mathsf\mathsf c{r s}}_{n}\gets $$

$$ \ {mathsf c c r},U_{n}) $$

$$ U_{n} $$

??? VC*:* Com (crsn;~v)! (*C;*aux)does the following:

$$ \mathsf{V C.C o n}^{\star}(\mathsf{c r s}_{n},{\vec{v}})\to\left({\check{C}}^{\star},\mathsf{a l x}^{\star}\right) $$

$$ \ {{1bf.\ }}o m p u t e\ ((a_{1},b_{1}),\ldots,(a_{k},b_{k}))\leftarrow{{sf P a r t n d P r i m e P r o d}}([n],\vec{v});;{{\bf2n e x t}}, $$

$$ {\mathrm{f o ra l l}}j\in[k]{\mathrm{o c m u u t e}}A_{j}=g_{0}^{a_{j}}{\mathrm{a n d~}}B_{j}=g_{1}^{b_{j}} $$

One can think of each (Aj;Bj) as a pair of RSA accumulators for two sets that constitute a partition of [n] done according to the bits of v₁j;:::;vnj. Namely Ajand Bjaccumulate the sets fi 2 [n] : vij= 0g and fi 2 [n] : vij= 1g respectively.

$$ (A_{j},B_{j}) $$

$$ v_{1j},\ldots,v_{n j} $$

$$ {i\in[n]:v_{i j}=0} $$

$$ A_{j} $$

$$ B_{j} $$

$$ {i\in[n]:v_{i j}=1} $$

(j) 2.For all j 2 [k], compute Cj= AjBj2 G and a proof PoProd₂*:* P(crs*;* (Cj;Un); (aj;bj)). prod Such proof ensures that the sets represented by Ajand Bjare a partition of the set represented by Un. Since Unis part of the CRS (i.e., it is trusted), this ensures the well-formedness of Aj and Bj. n o

$$ C_{j}=A_{j}\cdotp\boldsymbol{B}_{j}\in\mathbb{G} $$

$$ j\in[k] $$

$$ \pi_{\mathsf{p r o d}}^{(j)}\leftarrow\mathsf{P o P r o d_{2}.P}(\mathsf{c r s},(C_{j},U_{n}),(a_{j},b_{j})) $$

$$ B_{j} $$

$$ A_{j} $$

$$ U_{n} $$

$$ U_{n} $$

$$ A_{j} $$

$$ B_{j} $$

$$ \ {operatorname r n n}\ C^{\star}:=\left(\left{A_{1},B_{1},\ldots,A_{k},B_{k}\right},\left{\pi_{\mathsf{p r o d}}^{(1)},...,\pi_{\mathsf{p r o d}}^{(k)}\right}\right)\mathrm{}{a n d}{\mathsf{a u x}}^{\star}:=\vec{v}. $$

?? VC*:* Open (crsn;I;~y; aux)!Iproceeds as follows:

$$ \ {sf V C.p e e}^{\star}({\sf{C r S}}{n},I,\vec{y},{\sf{a l x}}^{\star})\to\pi{I} $$

$$ -\ {\mathrm{l e t}}\ J=[n]\setminus I\ {\mathrm{a n d}}\ {\mathrm{c o m p u t e}}\ ((a_{J1},b_{J1}),\ldots ldots,a_{J\ },b_{J\ }))\leftarrow{\bf P a r t e d r i m e{P r o d}}(J,U_{J}); $$


{ for all j 2 [k] compute

$$ j\in[k] $$

$$ \varGamma_{I j}:=g_{0}^{a_{J j}}\ \mathrm{a n d}\ \varDelta_{I j}=g_{1}^{b_{J j}} $$

Notice that aJj= aj=aIjand bJj= bj=bIj. AlsoIjis a membership witness for the set fil2 I : ylj= 0g in the accumulator Aj, and similarly forIj.

$$ a_{J j}=a_{j}/a_{I j} $$

$$ b_{J j}=b_{j}/b_{I j} $$

$$ P_{I j} $$

$$ {i_{l}\in I $$

$$ A_{j} $$

ReturnI:= fI1;:::;Ikg f (I1;I1);:::;(Ik;Ik)g

$$ \varDelta_{I j} $$

$$ y_{l j}=0} $$

$$ \pi_{I}:={\pi_{I1},\dots,\pi_{I k}}\leftarrow{(\varGamma_{I1},\varDelta_{I1}),\dots,(\varGamma_{I k},\varDelta_{I k})} $$

?? VC*:* Ver (crsn;C;I;~y;I)! b computes ((aI1;bI1);:::;(aIk;bIk)) using

$$ \ {mathsf I C C},{\mathsf{V e r}}^{\star}({\mathsf{c r s}}{n},{\mathcal{C}}^{\star},I,{\vec{y}},\pi{I})\to b $$

$$ ((a_{I1},b_{I1}),\ldots,(a_{I k},b_{I k})) $$

PartndPrimeProd(I;~y), and then returns b bacc^ bprodwhere:

$$ b\gets b_{a c c}\land b_{p r o c} $$

$$ b_{a c c}\gets\bigwedge_{j=1}^{k}\left(\varGamma_{I j}^{a_{I j}}=A_{j}\land\varDelta_{I j}^{b_{I j}}=B_{j}\right) $$

(1)

$$ b _ {p r o d} \leftarrow \bigwedge_ {j = 1} ^ {k} \left(\mathrm {P o P r o d} _ {2}. \mathrm {V} (\mathrm {c r s}, \left(A _ {j} \cdot B _ {j}, U _ {n}\right), \pi_ {\mathrm {p r o d}} ^ {(j)})\right) $$

(2)

? Remark 5.1. For more ecient verication, VC*:* Open can be changed to include 2k (non-interactive) proofs of exponentiation PoE (which using the PoKCR aggregation from [BBF19] add only k ele- ? ments of G). This reduces the exponentiations cost in VC*:* Ver. As noted in [BBF19], although the asymptotic complexity is the same, the operations are in Z₂2 instead of G, which concretely makes up an improvement.

$$ \ {\sf{V C}}.{{psf e n}}^{\times} $$

$$ \mathsf{V C.e r^{\star}} $$

$$ \mathbb{L}_{2^{2}}) $$

The correctness of the vector commitment scheme described above is obvious by inspection (assuming correctness of PoProd₂).

Incremental Aggregation. Here we show that our SVC scheme is incrementally aggregatable.

VC*:* Disagg(crs*;I;v*I;I;K)!K. Let L := I n K, and *v*Lbe the subvector of ~vIat positions in L. Then compute faLj;bLjgj2[k]PartndPrimeProd(L;~vL), and for each j 2 [k] set:

$$ I,\vec{v}{I},\pi{I},K)\rightarrow\pi_{K} $$

$$ \vec{v}_{I} $$

$$ L:=I\setminus K $$

$$ {\vec{v}}_{L} $$

$$ {a_{L j},b_{L j}}{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(L,\vec{v}{L}) $$

$$ j\in[k] $$

$$ \varGamma_{K j}\leftarrow\varGamma_{I j}^{a_{L j}},\quad\varDelta_{K j}\leftarrow\varDelta_{I j}^{b_{L j}} $$

and return $ \pi_{K} :={\pi_{K1},\dots,\pi_{Kk}}:={(\varGamma_{K1},\varDelta_{K1}),\dots,(\varGamma_{Kk},\varDelta_{Kk})} $

$$ \pi_{K}:={\pi_{K1},\dots,\pi_{K k}}:={(\varGamma_{K1},\varDelta_{K1}),\dots,(\varGamma_{K k},\varDelta_{K k})} $$

$$ \mathrm {V C}. \mathrm {A g g} (\mathrm {c r s}, (I, \vec {v} _ {I}, \pi_ {I}), (J, \vec {v} _ {J}, \pi_ {J})) \rightarrow \pi_ {K}: = \left{\left(\Gamma_ {K 1}, \Delta_ {K 1}\right), \dots , \left(\Gamma_ {K k}, \Delta_ {K k}\right)\right}. $$

I I J J K K1 K1 Kk Kk 1.Let L := I \J. If L 6=;, set I⁰ := I nL and computeI0 VC*:* Disagg(crs*;I;~vI;I;I⁰*); otherwise letI0 =I.

$$ L:=I\ \cap J.\ operatorname I f f\ L\neq\emptyset $$

$$ I^{\prime}:=I\backslash L $$

$$ \pi_{I^{\prime}}\gets V C.D i s a g g(c\mathsf{c r s},I,\vec{v}{I},\pi{I},I^{\prime}) $$

$$ \pi_{I^{\prime}}=\pi_{I} $$

2.Compute faI0j;bI0jgj2[k]PartndPrimeProd(I;~vI0) and faJj;bJjgj2[k]PartndPrimeProd(J;~vJ).

$$ \operatorname{t e};{a_{I^{\prime}j},b_{I^{\prime}j}}{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\vec{v}{I^{\prime}});\mathtt{a n} $$

$$ {a_{J j},b_{J j}}{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(J,\vec{\upsilon}{J}) $$

k k 3.ParseI0 := (I0j;I0j),J:= f(Jj;Jj)g, and for all j 2 [k], compute j=1 j=1

$$ \boldsymbol{{\pi}}{I^{\prime}}:=\big{\ \ \big(\varGamma{I^{\prime}j},\varDelta_{I^{\prime}j}\big)\big}{j=1}^{k},,\pi{J}:=\big{\big(\varGamma_{J j},\varDelta_{J j}\big)\big}_{j=1}^{k} $$

$$ j\in[k] $$

$$ \Gamma_ {K j} \leftarrow \mathbf {S h a m i r T r i c k} \left(\Gamma_ {I ^ {\prime} j}, \Gamma_ {J j}, a _ {I ^ {\prime} j}, a _ {J j}\right), \quad \Delta_ {K j} \leftarrow \mathbf {S h a m i r T r i c k} \left(\Delta_ {I ^ {\prime} j}, \Delta_ {J j}, b _ {I ^ {\prime} j}, b _ {J j}\right). $$

Note that our algorithms above can work directly with the universal CRS crs, and do not need the specialized one crsn.

Aggregation Correctness. The second property of aggregation correctness (the one about VC*:* Disagg) is straightforward by construction:

$$ \mathsf{c r S}_{n} $$

aIj if we let faKj;bKjgj2[k]PartndPrimeProd(K;~vK), then aIj= aLjaKj, and thus Aj= = Ij aLjaKjaKj = (and similarly forKj). Ij Kj

$$ {a_{K j},b_{K j}}{j\in[k]}:\longleftarrow\:\mathsf{P r r t n d P P r i m e P r o d}(K,\vec{v}{K})\ \mathrm{{{\ t{h e n}\ }}}a_{I j}:=:a_{L j}\cdot a_{K j} $$

$$ A_{j}=mathitGammaGamma_{I j}^{a_{I j}}= $$

$$ \varGamma_{I j}^{a_{L j}\cdot a_{K j}}=\varGamma_{K j}^{a_{K j}} $$

$$ \varDelta_{K j}) $$


The rst property instead follows from the correctness of Shamir’s trick if the integer values provided as input are coprime; however since I⁰\ J =;, aI0jand aJj(resp. bI0jand bJj) are coprime unless a collision occurs in PrimeGen.

$$ I^{\prime}\cap J=\emptyset,,a_{I^{\prime}j} $$

$$ a_{J j},(\mathrm{r e s p.},b_{I^{\prime}j} $$

$$ b_{J j}) $$

Eciency. We summarize the eciency of our construction in terms of both the computational cost of the algorithms and the communication (CRS, commitment and openings size). For this analysis we consider an instantiation of PrimeGen with a deterministic function that maps every integer in [n] into a unique prime number, which can be of = logn bits.

Our scheme is presented in order to support vectors of length n of k-bits-long strings. We summarize eciency in terms of k and n. However, we note that k is actually only a parameter and our scheme can work with any setting of vectors ~v of length N of ‘-bits long strings. In this case, it ‘ is sucient to x an arbitrary k that divides ‘ and to spread each vi2f0*;* 1g over ‘=k positions. For example, for k = 1 with have n = N‘ and thus the prime size is = log(N‘).

$$ \vec{v} $$

$$ v_{i}\in{0,1}^{\ell} $$

$$ \ell/k $$

$$ \alpha=\log(N\ell) $$

$$ n=N\ell $$

Setup. In terms of computation, VC*:* Setup generates the group description and samples 3 generators, while VC*:* Specialize computes one exponentiation in G with an (n)-long integer. The CRS consists of 3 elements of G, and the specialized CRS (for any n) is one group element.

$$ \mathbb{G} $$

k n Committing. Committing to a vector ~v 2 (f0*;* 1g) requires about k exponentiations with an (n)-long integer each. A commitment consists of 4k elements of G and 2k integers in Z₂2.

$$ \ {vec v\in({0,1}^{k})^{n}} $$

$$ \mathbb{Z}_{2^{2}\lambda} $$

Opening. Creating an opening for a set I of m positions has about the same cost of committing, and the opening consists of 2k group elements. Using the PoE to make verication more ecient (see Remark5.1) would (naively) result to 4k elements. However, as described in [BBF19], many PoE’s for coprime exponents can be aggregated into a single group element. In our case, applying this optimization would result to k group elements for all the PoE’s, which totally gives 3k group elements for an opening.

Verification. Verifying an opening for set I requires about k exponentiations with (m)- bit integers (resp. 4k exponentiations with-bit integers, 2k multiplications in G and O(km) multiplications in Z₂2, when using PoE) to check equation (1), plus 5k exponentiations with 2-bit integers and 3k multiplications in G to verify PoProd₂ proofs in equation (2).

$$ (m\cdot\alpha). $$

$$ \mathbb{Z}_{2^{2}\lambda} $$

Aggregation and Disaggregation. Disaggregation requires 2k exponentiations with ((jIj jKj))-bit integers, while aggregation requires 2k computations of ShamirTrick that amount to O(k(jIj+jJ j)) operations in G. From this, we obtain that VC*:* AggManyToOne and VC*:* DisaggOneToMany take time O(ksmlogm) G and O(kmlog(m=B)) G, respectively.

$$ ((|I|\ - $$

$$ |K|)\alpha, $$

$$ O \left(k \left(| I | + | J |\right) \alpha\right) $$

$$ O(k m\log(m/B)\alpha);\mathbb{G} $$

Commitment and Opening with Precomputation. Finally, let us summarize the costs of committing and opening with preprocessing obtained by instantiating our method of Section4.2. The preprocessing VC*:* PPCom takes time O(knlog(n=B)). The opening requires computing at most jSj m disaggregation, each taking time O(k(jPjjjIjj)), for a total of O(k(jSjB jIj)), followed by the aggregation step that counts O(kjSjlog jSj). So, in the worst case VC*:* FastOpen takes O(k m (log(m) + B 1)) operations of G.

$$ O(k n\alpha\log(n/B)) $$

$$ |S|\leq m $$

$$ O(k\alpha(|P_{j}|-|I_{j}|)) $$

$$ O(k\alpha(|S|B-|I|)) $$

$$ O(k\cdot m\cdot\alpha(\log!m)+B-1), $$

Security. The security of our SVC scheme, i.e., position binding, can be reduced to the Strong RSA and Adaptive root assumptions in the hidden order group G used in the construction and to the knowledge extractability of PoProd₂.

$$ \mathbb{G} $$

$$ \mathsf{P o P r o d}_{2} $$

A bit more in detail the steps of the proof are as follows. Let an adversary to the position 0 binding output (C;I;y;;y⁰;). First from knowledge extractability of PoProd₂ it comes that

$$ (C,I,\vec{y},\pi,\vec{y}^{\prime},\pi^{\prime}) $$ ajbj a b u A B = g₁ g₂ and gj j= U = gn. However, this does not necessarily means that a b = u over j j n j j n the integers and to prove it we need the Low Order assumptions, under which it holds. Afterwards ajbj 0 we prove that since AjBj= g₁ g₂ no dierent proofs*;* for the same positions can pass the verication under the strong RSA assumption, which is the core of our proof. The main caveat of ajbjajbj the proof is that instead of knowing that Aj= g₁ and Bj= g₂ we know only that AjBj= g₁ g₂. The former case would directly reduce to RSA Accumulator’s security (strong RSA assumption). For this we rst need to prove an intermediate lemma (lemma5.5) which shows that specically ajbj for our case AjBj= g₁ g₂ is enough, since the choice of the primes piin the exponent is restricted to a polynomially bounded set.

$$ g^{a_{j}b_{j}}=U_{n}=g^{u_{n}} $$

$$ A_{j}B_{j}=g_{1}^{a_{j}}g_{2}^{b_{j}} $$

$$ a_{j}b_{j}=u_{n} $$

$$ A_{j}B_{j},=,g_{1}^{a_{j}}g_{2}^{b_{j}} $$

$$ \pi,\pi^{\prime} $$

$$ A_{j}=g_{1}^{a_{j}} $$

$$ B_{j}=g_{2}^{b_{j}} $$

$$ A_{j}B_{j}=g_{1}^{a_{j}}g_{2}^{b_{j}} $$

$$ A_{j}B_{j}=g_{1}^{a_{j}}g_{2}^{b_{j}} $$

$$ p_{i} $$

Theorem 5.2(Position-Binding). Let Ggen be the generator of hidden order groups where the Strong RSA and Low Order assumptions hold, and let PoProd₂ be an argument of knowledge for RPoProd2. Then the subVector Commitment scheme dened above is position binding.

$$ R_{\mathsf{P o P r o d_{2}}} $$

Proof To prove the theorem we use a hybrid argument. We start by dening the game G₀ as the actual position binding game of Denition3.2, and our goal is to prove that for any PPT A, Pr[G₀ = 1] 2 negl().

$$ G_{0} $$

$$ \operatorname*{P r}[G_{0}=1]\in{\mathsf{n e g l}}(\lambda) $$

Game G₀:

$$ G_{0}; $$

$$ G_{0}=\mathsf{P o s B i n d_{V C}^{A}}(\lambda) $$

$$ \ {sf{c r s}}\leftarrow{\sf{V C}}.{\sf{S e t u p}}(1^{\lambda},\mathcal{M}) $$

$$ (C,I,{\vec{y}},\pi,{\vec{y}}^{\prime},\pi^{\prime})\leftarrow\ \ {mathcal A A}(\mathsf{c r s}) $$

$$ b\gets\mathsf{V C,V e r}(\mathsf{c r s},C,I,\vec{y},\pi)=1\land\vec{y}\neq\vec{y}^{\prime}\land\mathsf{V C,V e r}(\mathsf{c r s},C,I,\vec{y}^{\prime},\pi^{\prime})=1 $$

Lemma 5.1. For any PPT A in game G₀ there exists an algorithm E and an experiment G₁ such that

$$ G_{0} $$

$$ \mathcal{E} $$

$$ G_{1} $$

$$ \operatorname*{P r}[G_{0}{\ =\ }1]{\ \ \leq\ }\operatorname*{P r}[G_{1}{\ =\ }1]+\ \mathsf{n e g l}(\lambda) $$

Proof By construction of VC*:* Com, the commitment C returned by the adversary A in game G₀ contains k proofs of PoProd₂, and by construction of VC*:* Ver if G₀ returns 1 all these proofs verify. It is not hard to argue that for any adversary A playing in game G₀ there is an extractor E that outputs the k witnesses faj;bjgj2[k].

$$ G_{0} $$

$$ G_{0} $$

$$ G_{0} $$

$$ {a_{j},b_{j}}_{j\in[k]} $$

$$ \mathcal{E} $$

Game G₁: is the same as G₀ except that we also execute E, which outputs faj;bjgj2[k], and we ajbj additionally check that Un= g for all j 2 [k]. Below is a detailed description of G₁ in which we \open the box" of the VC algorithms.

$$ G_{1}: $$

$$ G_{0} $$

$$ {\mathcal{E}}, $$

$$ {a_{j},b_{j}}_{j\in[k]} $$

$$ U_{n}=g^{a_{j}b_{j}} $$

$$ j\in[k] $$

$$ G_{1} $$


$$ G_{1} $$

$$ \mathrm {c r s} \leftarrow \mathrm {V C}. \mathrm {S e t u p} \left(1 ^ {\lambda}, \mathcal {M}\right); \mathrm {b a d} _ {1} \leftarrow \mathrm {f a l s e} $$

$$ ({A_{j},B_{j}\pi_{\mathsf{g r o d}}^{(j)}}{j\in[k]},n),I,\vec{y},{\varGamma{I j},\varDelta_{I j}}{j\in[k]},\vec{y}^{\prime},{\varGamma{I j}^{\prime},\varDelta_{I j}^{\prime}}_{j\in[k]})\leftarrow\mathcal{A}(\mathsf{c r s}) $$

$$ {a_{j},b_{j}}_{j\in[k]}\leftarrow\mathcal{E}(\mathsf{c r s}) $$

$$ u_{n}\gets\mathsf{P r i m e P r o d}(n);U_{n}\gets g^{u_{n}} $$

$$ b_{p r o d}\leftarrow\bigwedge_{j=1}^{k}\Big(\mathsf{P o P r o d_{2}.V}(\mathsf{c r s},(A_{j}\cdot B_{j},U_{n}),\pi_{\mathsf{p r o d}}^{(j)})\Big) $$

$$ b_{w i t}\leftarrow\bigwedge_{j=1}^{k}A_{j}\cdot B_{j}=g_{0}^{a_{j}}g_{j}^{b_{j}}\wedge U_{n}=g^{a_{j}\cdot b_{j}} $$

$$ \mathbf{i f}\ b_{p r o d}=1\wedge b_{w i t}=0\ \mathbf{t h e n}\ \ \mathsf{b a d}_{1}\leftarrow\mathsf{t r u e} $$

$$ {a_{I j},b_{I j}}{j\in{k}}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\bar{y});\ {\mathbf{a}{\ell j}^{\prime},b_{\ell j}^{\prime}}_{j\in{k}}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\bar{y}^{\prime}) $$

$$ b\leftarrow b_{\mathrm{}{p r o d}}\wedge\bigwedge_{j=1}^{k}\left(\varGamma_{I j}{}^{a_{I j}}=A_{j}\wedge\varDelta_{I j}{}^{b_{I j}}=B_{j}\right)\wedge\vec{y}\neq\vec{y}^{\prime}\wedge $$

$$ \bigwedge_{j=1}^{k}\Big({\varGamma_{I j}^{\prime}}^{a_{I j}^{\prime}}=A_{j}\wedge{\varDelta_{I j}^{\prime}}^{b_{I j}^{\prime}}=B_{j}\Big) $$

if bad₁ = true then b 0

return b

$$ b\gets0 $$

Clearly, the games G₀ and G₁ are identical except if the ag bad₁ is raised true, i.e., Pr[G₀ = 1] Pr[G₁ = 1] Pr[bad₁ = true]. However, the event in which bad₁ is set true is the event in which one of the witnesses returned by the extractor is not correct. By the knowledge extractability of PoProd₂ we immediately get that Pr[bad₁ = true] 2 negl().

$$ G_{0} $$

$$ G_{1} $$

$$ \mathtt{b a d}_{1} $$

$$ \mathrm{P r}[G_{0}= $$

$$ 1]-\operatorname*{P r}[G_{1}=1]\leq\operatorname*{P r}[\mathsf{b a d}_{1}=\mathsf{t r u e}] $$

$$ \ \mathrm{b a d}_{1} $$

$$ \mathsf{P o P r o d}_{2} $$

$$ \operatorname*{P r}[{\mathsf{b a d}}_{1}={\mathsf{t r u e}}]\in{\mathsf{n e g l}}(\lambda) $$

ajbj Game G₂: is the same as G₁ except that G₂ outputs 0 if there is an index j such that Un= g but un6= ajbj. Precisely, if this happens a ag bad₂ is set true and the outcome of the experiment is 0. See below for the detailed description of G₂.

$$ G_{2}. $$

$$ G_{1} $$

$$ G_{2} $$

$$ j $$

$$ U_{n}=g^{a_{j}\cdot b_{j}} $$

$$ u_{n}\neq a_{j}\cdot b_{j} $$

$$ {\tt{b a d}}_{2} $$

$$ G_{2} $$


$$ G_{2} $$

$$ \mathsf{c r s}\leftarrow\mathsf{V C.S e t u p}(1^{\lambda},\mathcal{M});\mathsf{b a d}{1},\mathsf{b a d}{2}\leftarrow\mathsf{f a l s e} $$

$$ ({A_{j},B_{j}\pi_{\mathsf{p r o d}}^{(j)}}{j\in[k]},n),I,\vec{y},{\varGamma{I j},\varDelta_{I j}}{j\in[k]},\vec{y}^{\prime},{\varGamma{I j}^{\prime},\varDelta_{I j}^{\prime}}_{j\in[k]})\leftarrow\mathcal{A}(\mathsf{c r s}) $$

$$ {a_{j},b_{j}}_{j\in[k]}\leftarrow\mathcal{E}(\mathsf{c r s}) $$

$$ u_{n}\gets\mathsf{P r i n e P r o d}(n);U_{n}\gets g^{u_{n}} $$

$$ b_{p r o d}\leftarrow\bigwedge_{j=1}^{k}\Big(\mathsf{P o P r o d_{2}.V}(\mathsf{c r s},(A_{j}\cdot B_{j},U_{n}),\pi_{\mathsf{p r o d}}^{(j)})\Big) $$

$$ b_{w i t}\leftarrow\bigwedge_{j=1}^{k}A_{j}\cdot B_{j}=g_{0}^{a_{j}}g_{j}^{b_{j}}\wedge U_{n}=g^{a_{j}\cdot b_{j}} $$

$$ \textbf {i f} b _ {p r o d} = 1 \wedge b _ {w i t} = 0 \textbf {t h e n} \mathrm {b a d} _ {1} \leftarrow \mathrm {t r u e} $$

$$ b_{c o l}\leftarrow\bigwedge_{j=1}^{k}u_{n}=a_{j}\cdot b_{j} $$

$$ \mathbf{i f}\ b_{r o o}=1\wedge b_{o l}=0\ \mathbf{t h e n}\ \ \mathsf{b a d}_{2}\leftarrow\mathsf{t r u e} $$

$$ {a_{l j},b_{l j}}{j\in[k]}\leftarrow\mathsf{P a r t n P r i m e P r o d}(I,\vec{y});;\left{a{l j}^{\prime},b_{l j}^{\prime}\right}_{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\vec{y}^{\prime}) $$

$$ \bigwedge_{j=1}^{k}\Big({\varGamma_{I j}^{\prime}}^{a_{I j}^{\prime}}=A_{j}\wedge{\varDelta_{I j}^{\prime}}^{b_{I j}^{\prime}}=B_{j}\Big) $$

$$ \ {\bf i f}\ {\sf b a d}{1}={\sf t r u e}\vee{\sf b a d}{2}={\sf t r u e}\ {\bf t h e n}\ \ b\leftarrow0 $$

return b

Lemma 5.2. If the Low Order assumption holds for Ggen*, then* Pr[G₁ = 1] Pr[G₂ = 1] negl().

$$ \operatorname*{P r}[G_{1}=1]-\operatorname*{P r}[G_{2}=1]\leq\mathsf{n e g l}(\lambda) $$

Proof Clearly, G₁ and G₂ proceed identically except if bad₂ is set true. We claim that Pr[bad₂ = true] is negligible for any A; E running in G₂. If this event happens, one indeed obtains an integer v poly() v = unajbjsuch that g = 12 G, where g 6= 1 and 1 < v < 2, and solves the Low Order problem.

$$ G_{1} $$

$$ G_{2} $$

$$ \ \mathrm{b a d}_{2} $$

$$ \mathrm{P r}[\mathfrak{b a d}_{2}= $$

$$ \mathcal{A},\mathcal{E} $$

$$ G_{2} $$

$$ v=u_{n}-a_{j}\cdot b_{j} $$

$$ g^{v}=1\in\mathbb{G} $$

$$ g\neq1 $$

$$ 1<v<2^{\mathsf{p o l y}(\lambda)} $$

Game G₃: is an experiment that can be seen as a simplication of G₂. G₃

$$ G_{3:} $$

$$ G_{2} $$

$$ G_{3} $$

$$ \ {sf c c r}\leftarrow\ {sf V C}.{\sf e t u p}(1^{\lambda},\mathcal{M}) $$

$$ \left{a_{j},b_{j}\right}_{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}([n],\vec{v}) $$

$$ {a_{I j},b_{I j}}{j\in[k]}\leftarrow\mathsf{P a r t n P r i m e P r o d}(I,\vec{y});;\left{a{I j}^{\prime},b_{I j}^{\prime}\right}_{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\vec{y}^{\prime}) $$

$$ b\leftarrow\bigwedge_{j=1}^{k}(A_{j}\cdot B_{j}=g_{0}^{a_{j}}\cdot g_{1}^{b_{j}})\bigwedge_{j=1}^{k}\left(\varGamma_{I j}{}^{a_{I j}}=A_{j}\wedge\varDelta_{I j}{}^{b_{I j}}=B_{j}\right)\wedge\vec{y}\neq\vec{y}^{\prime}\wedge $$

$$ \bigwedge_{j=1}^{k}\Big({\varGamma_{I j}^{\prime}}^{a_{I j}^{\prime}}=A_{j}\wedge{\varDelta_{I j}^{\prime}}^{b_{I j}^{\prime}}=B_{j}\Big) $$

return b

First, we show the following lemma that relates the probability of winning in G₃ with that of winning in G₂.

$$ G_{3} $$

$$ G_{2} $$


Lemma 5.3. For any (A; E) running in G₂ there is an A⁰ running in G₃ such that Pr[G₂ = 1] = Pr[G₃ = 1].

$$ G_{2} $$

$$ \operatorname*{P r}[G_{2}=1]= $$

$$ (\mathcal{A},\mathcal{E}) $$

$$ G_{3} $$

$$ \operatorname*{P r}[G_{3}=1] $$

Proof We build A⁰ from (A; E) as follows. On input crs, A⁰ executes

$$ (\mathcal{A},\mathcal{E}) $$

(j) 0 0 0Ij (fAj;Bj; gj2[k];n);I;~y; fIj;Ijgj2[k];~y; f; gj2[k]) A (crs) and faj;bjgj2[k] E (crs). prod Ij k n Next, A⁰ reconstructs a vector ~v 2 (f0*;* 1g) from the set faj;bjgj2[k]. This can be done by setting vij= 0 if pij ajand vij= 1 if pij bj, where piPrimeGen(i) (in case both or neither cases occur, abort). Finally, A⁰ runs all the checks as in game G₂, and if G₂ would output 1, then A⁰ outputs 0 0Ij (~v; fAj;Bjgj2[k];I;~y; fIj;Ijgj2[k];~y⁰; f; gj2[k]), otherwise A⁰ aborts. Ij

$$ ({A_{j},B_{j},\pi_{\mathsf{w r d d}}^{(j)}}{j\in[k]},n),I,\vec{y},{\varGamma{I j},\varDelta_{I j}}{j\in[k]},\vec{y}^\prime,{\varGamma{I j}^{\prime},\varDelta_{I j}^{\prime}}_{j\in[k]})\leftarrow\mathcal{A}(\mathsf{c r s}) $$

$$ {a_{j},b_{j}}_{j\in[k]}\leftarrow\mathcal{E}(\mathsf{c r s}) $$

$$ \mathrm{N e x t},{\mathcal{A}}^{\prime} $$

$$ \vec{v}\in({0,1}^{k})^{n} $$

$$ p_{i}\gets\mathsf{P r i m e G e n}(i) $$

$$ v_{i j}=0 $$

$$ {a_{j},b_{j}}_{j\in[k]} $$

$$ p_{i}\mid a_{j} $$

$$ p_{i}\mid b_{j} $$

$$ v_{i j}=1 $$

$$ G_{2}. $$

$$ G_{2} $$

$$ \mathcal{A}^{\prime} $$

$$ (\vec {v}, \left{A _ {j}, B _ {j} \right} _ {j \in [ k ]}, I, \vec {y}, \left{\Gamma_ {I j}, \Delta_ {I j} \right} _ {j \in [ k ]}, \vec {y} ^ {\prime}, \left{\Gamma_ {I j} ^ {\prime}, \Delta_ {I j} ^ {\prime} \right} _ {j \in [ k ]}) $$

$$ \mathcal{A}^{\prime} $$

To claim that Pr[G₂ = 1] = Pr[G₃ = 1], we observe that whenever G₂ returns 1 it is the case Q n 0 that ajbj= un= pifor all j 2 [k]; therefore A never aborts. i=1

$$ \Pr [ G _ {2} = 1 ] = \Pr [ G _ {3} = 1 ] $$

$$ G_{2} $$

$$ a_{j}\cdot b_{j}=u_{n}=\prod_{i=1}^{n}p_{i} $$

$$ j\in[k] $$

Game G₄: this is the same as game G₃ except that the game outputs 0 if during any computation of lines 3 and 4 it happens that PrimeGen(i) = PrimeGen(i⁰) for distinct i 6= i⁰. It is straightforward to show that the probability of this event is bounded by the probability of nding collisions in PrimeGen, i.e., that under the collision resistance of PrimeGen it holds Pr[G₃] Pr[G₄] 2 negl().

$$ G_{3} $$

$$ G_{4}; $$

$$ P r_e e G e n(i)=P r i m e G e n(i^{\prime}) $$

$$ i\neq i^{\prime} $$

$$ \operatorname*{P r}[G_{3}]-\operatorname*{P r}[G_{4}]\in\mathsf{n e g l}(\lambda) $$

To conclude the proof of our Theorem, we prove that any PPT adversary can win in G₄ with only negligible probability assuming that the strong RSA assumption holds in G.

$$ G_{4} $$

Lemma 5.4. If the strong RSA assumption holds for Ggen*, then for every PPT adversary A⁰* running in game G₄ we have that Pr[G₄ = 1] 2 negl().

$$ G_{4} $$

$$ P r[G_{4}=1]\in{\mathsf{n e g l}}(\lambda) $$

Proof For the proof, we rely on the following lemma that denes a computational problem that we prove it is implied by the Strong RSA assumption.

Lemma 5.5. Let Ggen be a hidden order group generation algorithm where the strong RSA assumption holds and PrimeGen a deterministic collision resistant function that maps integers to primes. Then for any PPT adversary A and any n = poly(), the probability below is negligible:

$$ n=\ \mathsf{p o l y}(\lambda) $$

$$ \Pr \left[ \begin{array}{c c} u ^ {p} = g _ {0} ^ {a} \cdot g _ {1} ^ {b} & \mathbb {G} \leftarrow \operatorname {G e n e n} (\lambda) \ \wedge (p \nmid a \vee p \nmid b) & g _ {0}, g _ {1} \leftarrow \mathbb {G} \ \wedge u \in \mathbb {G} \wedge (a, b) \in \mathbb {Z} ^ {2} \wedge p \in S & S = \left{p _ {i} \leftarrow \operatorname {P r i m e G e n} (i)\right} _ {i=1} ^ {n} \ & (u, p, a, b) \leftarrow \mathcal {A} \left(\mathbb {G}, g _ {0}, g _ {1}, S\right) \end{array} \right] \in \operatorname {n e g l} (\lambda) $$

We proceed assuming that the lemma holds; its proof is deferred to the end.

Suppose by contradiction the existence of a PPT adversary A⁰ such that Pr[G₄] = with non-negligible. Below we show how to construct an adversary B that uses A⁰ in order to solve the problem of Lemma5.5with probability.

$$ \operatorname*{P r}|G_{4}|,=,\epsilon $$

{ B(G*;g₀;g₁*) samples a random g $ G, determines a PrimeGen as in VC*:* Setup, sets crs (G*;g;g₀;g₁;*PrimeGen), and runs A on input crs.

$$ g\leftarrow\S\mathbb{G} $$

$$

0 { A(crs) responds with a tuple (~v; fAj;Bjgj2[k];I;y;;y⁰;).

$$ \left(\vec{v},{A_{j},B_{j}}_{j\in[k]},I,\vec{y},\pi,\vec{y}^{\prime},\pi^{\prime}\right) $$

{ B computes faj;bjg PartndPrimeProd([n];~v), j2[k] faIj;bIjg PartndPrimeProd(I;~y) and j2[k] 0Ij 0Ij fa;b gj2[k]PartndPrimeProd(I;~y⁰) as in game G₃.

$$ \left{a _ {j}, b _ {j} \right} _ {j \in [ k ]} \leftarrow \operatorname {P a r t n d P r i m e P r o d} ([ n ], \vec {v}). $$

$$ \left{a_{I j},b_{I j}\right}_{j\in[k]}\leftarrow $$

$$ {a_{I j}^{\prime},b_{I j}^{\prime}}_{j\in[k]}\leftarrow $$

$$ G_{3} $$


{ If A⁰ wins the game then we have that all the following conditions holds:

$$ \vec {y} \neq \vec {y} ^ {\prime}, \bigwedge_ {j = 1} ^ {k} \left(\Gamma_ {I j} ^ {a _ {I j}} = A _ {j} \wedge \Delta_ {I j} ^ {b _ {I j}} = B _ {j}\right) = 1, \bigwedge_ {j = 1} ^ {k} \left(\Gamma_ {I j} ^ {\prime a _ {I j} ^ {\prime}} = A _ {j} \wedge \Delta_ {I j} ^ {\prime b _ {I j} ^ {\prime}} = B _ {j}\right) = 1 $$

$$ \bigwedge_{j=1}^{k}(A_{j}\cdot B_{j}=g_{0}^{a_{j}}\cdot g_{1}^{b_{j}}). $$

0 From ~y 6= ~y⁰ we get that there is at least one pair of indices l 2 [m] and j 2 [k] such that ylj6= y. lj 0 Say wlog that ylj= 0 and y = 1. Also, if we parse I = fi₁;:::;img, we let i = il2 [m]. So we lj x these indices i and j, and let pi= PrimeGen(i) be the corresponding prime.

$$ \vec{y}\neq\vec{y} $$

$$ l\in[m] $$

$$ j\in[k] $$

$$ y_{l j}=0 $$

$$ y _ {l j} ^ {\prime} = 1 $$

$$ y_{l j}\neq y_{l j}^{\prime} $$

$$ I={i_{1},\dots,i_{m}} $$

$$ i=i_{l}\in[m] $$

$$ j, $$

$$ p_{i}=\mathsf{P r i m e G e n}(i) $$

Notice that by construction of PartndPrimeProd (and since we assumed no collision occurs in PrimeGen) we have that either pi-ajor pi-bjholds. Additionally, by our assumption that 0 0Ij 0Ij ylj= 0 and y = 1, the following holds: pij aIj, pi-bIj, pi-a, pij b. lj

$$ p_{i}\nmid a_{j} $$

$$ p_{i}\nmid b_{j} $$

$$ y_{l j}=0 $$

$$ y_{l j}^{\prime}=1 $$

$$ p_{i}:|:a_{I j},p_{i}:|:b_{I j},p_{i}:|:a_{I j}^{\prime},p_{i}:|:b_{I j}^{\prime} $$

$$ \hat{}GammaGamma,\hat{\Delta} $$

$$ \hat{\varGamma}^{p_{i}}=A_{i} $$

$$ \hat{\Delta}^{p_{i}}=B_{i} $$

From the other condition on the validity of the proofs, B can compute two group elements*;*^ ^ ^pi ^pi such that = Ajand = Bj.

ajbj p ajbj Combining this with the condition A B = g₀ g₁, we have that ( ^ ^) i= g₀ g₁. j j

$$ A_{j}\cdot B_{j}=g_{0}^{a_{j}}\cdot g_{1}^{b_{j}} $$

$$ (\hat{\boldsymbol{\Gamma}}\cdot\hat{\boldsymbol{\Delta}})^{p_{i}}=g_{0}^{a_{j}}\cdot g_{1}^{b_{j}}. $$

{ B sets w = ^ ^ and outputs the tuple (w;p;a;b). i j j

$$ w=\hat{\varGamma}\cdot\hat{\varDelta} $$

$$ (w,p_{i},a_{j},b_{j}) $$

From all the above observations, if A⁰ makes game G₄ return 1, then the tuple returned by B is a suitable solution for the problem of Lemma5.5, which in turn reduces to the Strong RSA assumption.

$$ G_{4} $$

By combining all the lemmas we have that any PPT adversary has at most negligible probability of breaking the position binding of our SVC scheme.

Proof [Proof of Lemma5.5] Suppose that for a PPT adversary A the above probability is a non-negligible value. We will construct an adversary B that breaks strong RSA assumption with a non-negligible probability. B takes as input (G*;g*). We denote as GAthe game dened in lemma (parametrized by an adversary A). We dene two dierent reductions:

$$ G_{A} $$

Reduction 1. In reduction 1 the adversary B breaks strong RSA assumption only in case where the adversary A outputs a tuple (u;p;a;b) such that p j a (and thus from assumption p-b) and fails otherwise. B proceeds as follows.

$$ (u,p,a,b) $$

$$ p\mid a $$

$$ p\nmid b) $$

B(G*;g*) samples $ [1*;2 ordmax], where ordmaxis the upper bound of the order of G outputted by Ggen(1 ) (see section2.1), and sets g₀ g;g₁ g. B runs A on input (G;g₀;g₁*). is sampled from a large enough domain so that g is statistically close to a uniformly distributed g₀ from G hence g₀;g₁ are indistinguishable to two uniformly random elements of G. A(G*;g₀;g₁;S*) responds with a tuple (u;p;a;b) and sends it to B. We condition our analysis on the event p j a, meaning that B stops in case p-a.

$$ \mathcal{B}(\mathbb{G},g) $$

$$ \gamma\gets\ [,22^{\lambda}\mathsf{o r d}_{m a x}] $$

$$ \mathsf{o r d}_{m a x} $$

$$ \mathsf{G g e n}(1^{\lambda}) $$

$$ g_{0}\leftarrow g^{\gamma},g_{1}\leftarrow g.,k $$

$$ (\mathbb{G},g_{0},g_{1}).,\gamma $$

$$ g^{\gamma} $$

$$ g_{0} $$

$$ g_{0},g_{1} $$

$$ \mathbb{G}.\ \mathcal{A}(\mathbb{G},g_{0},g_{1},S) $$

$$ (u,p,a,b) $$

$$ p\ |\ a. $$

$$ p\nmid a $$

p a b Assume that u = g₀ g₁ ^ (p j a ^ p-b) ^ u 2 G ^ (a;b) 2 Z² ^ p 2 S then we will show that B can break the strong RSA assumption. We argue that p j a leads to gcd(p;a + b) = 1. Let gcd(p;a + b) 6= 1, meaning that gcd(p;a + b) = p, then p j a + b ) a + b = 0 (mod p). However, p j a ) a = 0 (mod p). From the two previous facts we infer that b = 0 (mod p)) p j b, hence p j a ^ p j b, which is a contradiction. Therefore, assuming that gcd(p;a + b) = 1, B uses

$$ u^{p},=,g_{0}^{a},\cdot,g_{1}^{b},\wedge,(p,\mid,a,\wedge,p,\dag\ b),\wedge,u,\in,\mathbb{G},\wedge,(a,,b),\in,\mathbb{Z}^{2},\wedge,p,\in,S $$

$$ \operatorname{l}(p,\gamma a+b)=1 $$

$$ \operatorname*{g c d}(p,\gamma a+b)\neq1 $$

$$ ptextit{||c} $$

$$ \ !(p,\gamma a+b)=p. $$

$$ p\mid\gamma a+b\Rightarrow\gamma a+b=0 $$

$$ p) $$

$$ p\mid a\Rightarrow a=0 $$

$$ b=0 $$

$$ p)\Rightarrow p,\vert|,b $$

$$ p\ |\ a\wedge p\ |\ b $$ the extended Euclidean algorithm to compute (;) such that p + (a + b) = 1. We know that a+b p+ (a+b)=1 a+b p a b a+b =p + u = g₀g₁ = g) u = gphence it follows that g¹ = gp= gp= g u. Finally, B outputs (g u;p) which is a valid strong-RSA solution.

$$ (\alpha,\beta) $$

$$ \alpha p+\beta(a\gamma+b)=1 $$

$$ u^{p}=g_{0}^{a}g_{1}^{b}=g^{a\gamma+b}\Rightarrow u=g^{\frac{a\gamma+b}{p}} $$

$$ g^{1/p}=g^{\frac{\alpha p+\beta(a\gamma+b)=1}{p}}=g^{\alpha+\beta\frac{a\gamma+b}{p}}=g^{\alpha}\cdot u^{\beta}. $$

$$ (g^{\alpha}\cdot u^{\beta},p) $$

Reduction 2. In reduction 2 the adversary B breaks strong RSA assumption only in case where the adversary A outputs a tuple (u;p;a;b) such that p-a and fails otherwise.

B(G*;g*) samples $ [1*;2 ordmax], where ordmaxis the upper bound of the order of G outputted Q n n by Ggen(1 ) (see section2.1), denes S := fpiPrimeGen(i)g and prod piand sets i=1 i=1 prod g₀ g;g₁ g. B sends (G;g₀;g₁*) to A. is sampled from a large enough domain so that g is statistically close to a uniformly distributed g₁ from G hence g₀;g₁ are indistinguishable to two uniformly random elements of G. A(G*;g₀;g₁;S*) responds with a tuple (u;p;a;b) and sends it to B. We condition our analysis on the event p-a, meaning that B stops in case p j a.

$$ (u,p,a,b) $$

$$ \mathcal{B}(\mathbb{G},g) $$

$$ \gamma\gets\ [1,2^{\lambda}\mathsf{o r d}_{m a x}] $$

$$ \mathsf{G g e n}(1^{\lambda}) $$

$$ \ S=={{p_{i}\leftarrow\mathsf{P r i m e G e n}(i)}}_{i=1}^{n} $$

$$ g_{0}\leftarrow g,g_{1}\leftarrow g^{\gamma\cdot\mathsf{p r o d}} $$

$$ \textstyle\leftarrow\prod_{i=1}^{n}p_{i} $$

$$ A.\gamma $$

$$ (\mathbb{G},\mathfrak{g}{0},\mathfrak{g}{1}) $$

$$ g^{\gamma} $$

$$ g_{1} $$

$$ \mathbb{G} $$

$$ g_{0},g_{1} $$

$$ (u,p,a,b) $$

$$ \mathbb{G}.\ \mathcal{A}(\mathbb{G},g_{0},g_{1},S) $$

$$ p\mid a. $$

$$ p\nmid a $$

p a b Assume that u = g₀ g₁ ^ p-a ^ u 2 G ^ (a;b) 2 Z² ^ p 2 S then we will show that B can break the strong RSA assumption. We argue that gcd(p;a + bprod) = 1. Let gcd(p;a + bprod) 6= 1, meaning that gcd(p;a+ bprod) = p, then p j a+ bprod*) a*+ bprod = 0 (mod p). However, prod includes p (p 2 S) we know that p j bprod*) bprod = 0 (mod p). From the two previous facts we infer that a = 0 (mod p)) p j a* which is a contradiction. B uses the extended Euclidean algorithm p a b a+bprod to compute (;) such that p + (a + bprod) = 1. We know that u = g₀g₁ = g) u = a+bprod p+ (a+bprod)=1 a+bprod =p + gphence it follows that g¹ = gp= gp= g u. Finally, B outputs (g u;p) which is a valid strong-RSA solution.

$$ u^{p}=g_{0}^{a}\cdot g_{1}^{b}\wedge p\nmid a\wedge u\in\mathbb{G}\wedge(a,b)\in\mathbb{Z}^{2}\wedge p\in S $$

$$ (p,a+b\gamma\mathsf{p r o d})=1 $$

$$ \mathtt{I}(p,a+b\gamma\mathsf{p r o d})\neq1 $$

$$ (p,a+b\gamma\mathsf{p r o d})=p $$

$$ p\mid a+b\gamma\mathsf{p r o d}\Rightarrow a+b\gamma $$

$$ p\left(p\in S\right) $$

$$ p,big vert,b\gamma\mathsf{p r o d}\Rightarrow b\gamma\mathsf{p r o d}=0 $$

$$ a=0 $$

$$ p)\Rightarrow p, $$

$$ \alpha p+\beta(a+b\gamma\mathsf{p r o d})=1 $$

$$ u^{p}=g_{0}^{a}g_{1}^{b}=g^{a+b\gamma{\tt r o o}{\tt d}}\Rightarrow u= $$

$$ (\alpha,\beta) $$

$$ g^{\ ;\ ;} $$

$$ g^{1/p}=g^{\frac{\alpha p+\beta(a+b\gamma\mathsf{p r o d})=1}{p}}=g^{\alpha+\beta\ \frac{a+b\gamma\mathsf{p r o d}}{p}}=g^{\alpha}\cdot u^{\beta} $$

$$ \left(\boldsymbol{g}^{\alpha}\cdot\boldsymbol{u}^{\beta},\boldsymbol{p}\right) $$

To conclude the proof, notice that:

$$ \begin{aligned}{\operatorname*{P r}[G_{\mathcal{A}}=1]}&{{}=\operatorname*{P r}[G_{\mathcal{A}}=1|p\mid a]\operatorname*{P r}[p\mid a]+\operatorname*{P r}[G_{\mathcal{A}}=1|p\nmid a]\operatorname*{P r}[p\nmid a]}\ {}&{{}\leq\operatorname*{P r}[G_{\mathcal{A}}=1|p\mid a]+\operatorname*{P r}[G_{\mathcal{A}}=1|p\nmid a]}\ \end{aligned} $$

The reductions 1 and 2 described above show that under the strong RSA assumption Pr[GA= 1jp j a] and Pr[GA= 1jp-a] respectively are negligible. Hence, we have that Pr[GA= 1] 2 negl(), which concludes the proof.

$$ \mathrm{P r}[G_{\mathcal{A}}= $$

$$ 1|p\mid a] $$

$$ \mathrm{P r}[G_{\mathcal{A}}=1|p\nmid a] $$

$$ \operatorname*{P r}[G_{\mathcal{A}}=1]\in{\mathsf{n e g l}}(\lambda) $$

On concrete instantiation. Our SVC construction is described generically from a hidden order group G, an AoK PoProd₂, and a mapping to primes PrimeGen. The concrete scheme we analyze is the one where PoProd₂ is instantiated with the non-interactive version of the PoProd₂ protocol described in Sec.5.1. The non-interactive version needs a hash-to-prime function Hprime. We note that the same function can be used to instantiate PrimeGen, though for the sake of PrimeGen we do not need its randomness properties. One can choose a dierent mapping to primes for PrimeGen and even just a bijective mapping (which is inherently collision resistant) would be enough: this is actually the instantiation we consider in our eciency analysis. Finally, see Section2.1for a discussion on possible instantiations of G.

$$ \mathsf{P o P r o d}_{2} $$

$$ \mathsf{P o P r o d}_{2} $$

$$ \mathsf{H}_{\mathsf{p r i m e}} $$

We note that by using the specic PoProd₂ protocol given in Sec.5.1we are assuming adversaries that are generic with respect to the group G. Therefore, our SVC is ultimately position binding in the generic group model.

5.2 Our Second SVC Construction

In this section we propose another SVC scheme with constant-size parameters and incremental aggregation. This scheme builds on the SVC of [LM19] based on the RSA assumption, which in turn extends the VC of [CF13] to support subvector openings. Our technical contribution is twofold. First, we show that the SVC of [CF13,LM19] can be modied in order to have public parameters and verication time independent of the vector’s length. Second, we propose new algorithms for (incremental) aggregation and disaggregation for this SVC.

Our second SVC Construction. Let us start by giving a brief overview of the [CF13] VC scheme and of the basic idea to turn it into one with succinct parameters and verication time. In brief, inQ v1 vn j2[n]nfigej [CF13] a commitment to a vector ~v is C = S₁ Sn, where each Si:= g with g 2 G a random generator and ejbeing distinct prime numbers (which can be deterministically generated eii i using a suitable map-to-primes). The opening for position i is an elementisuch that S = C iv and the key idea is that suchiis an ei-th root that can be publicly computed as long as one does it for the correct position i and value vi. Also, as it can be seen, the element Siis necessary to verify an opening of position i, and thus (S₁;:::;Sn) were included in the public parameters. Catalano and Fiore observed that it might be possible to remove the Si-s from crs if the verier opts for recomputing Siat verication time at the price of linear-time verication.

$$ \vec{v} $$

$$ C=S_{1}^{v_{1}}\cdots S_{n}^{v_{n}} $$

$$ S_{i}:=g^{\prod_{j\in[n]\setminus{i}}e e_{j}} $$

$$ g\in\mathbb{G} $$

$$ e_{j} $$

$$ \Lambda_ {i} $$

$$ \Lambda_ {i} $$

$$ \varLambda_{i}^{e_{i}}\cdot S_{i}^{v_{i}}=C $$

$$ e_{i^{-}\mathrm{t h}} $$

$$ v_{i} $$

$$ S_{i} $$

$$ i, $$

$$ (S_{1},\ldots,S_{n}) $$

$$ S_{i\ \mathrm{S}} $$

$$ S_{i} $$

Our goal is to obtain constant-size parameters and constant-time verication. To do that we let the prover compute Siand include it in the opening for positionQi. To prevent adversaries from i2[n]ei providing false Si’s, we store in the public parameters Un= g (i.e., an accumulator to all i positions) so that the verier can verify the correctness of Siin constant-time by checking S = Un. ie This technique easily generalizes to subvector openings.

$$ S_{i} $$

$$ S _ {i} ^ {\prime} \mathrm {s} $$

$$ \ {U{n}=g}{\prod_{i\in[n]}e_{i}} $$

$$ S_{i}^{e_{i}}=U_{n} $$

$$ S_{i} $$

In the following, we describe the scheme in details and then propose our incremental aggregation algorithms. To simplify our exposition, we use the following notation: for a set of indices I [n], Q eI:= eidenotes the product of all primes corresponding to the elements of I, and SI:= Q i2I ei e 1=eI gi2[n]nI= g[n]nI= U (which is a generalization of the former S), where, we recall, the e ’s n i i are dened from the crs.

$$ I\subseteq[n] $$

$$ \textstyle{e_{I}:=\prod_{i\in I}e_{i}} $$

$$ S_{I}\ = $$

$$ S_{i}) $$

$$ {e e{}}_i{\ }^{?} $$

VC*:* Setup(1*;‘;n*)! crs generates a hidden order group G Ggen(1 ) and samples a generator g $ G. It also determines a deterministic collision resistant function PrimeGen that maps integers to primes.

$$ {\mathsf{S e t u p}}(1^{\lambda},\ell,n)\to{\mathsf{c r s}} $$

$$ g\leftarrow\mathfrak{s}\mathbb{G} $$

$$ \mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda}) $$

Returns crs = (G*;g;* PrimeGen)

$$ {\mathsf{c r s}}=(\mathbb{G},g,{\mathsf{P r i m e G e n}}) $$

VC*:* Specialize(crs*;n*)! crsncomputes n (‘ + 1)-bit primes e₁;:::;en, eiPrimeGen(i) for each e[n] i 2 [n], and Un= g and returns crsn(crs*;U*n). One can think of Unas an accumulator to the set [n].

$$ n\ (\ell+1){\mathrm{-b i t}} $$

$$ e_{1},\ldots,e_{n},:e_{i}\leftarrow $$

$$ i\in[n] $$

$$ U_{n}=\mathfrak{g}^{\mathfrak{e}[n]} $$

$$ \mathsf{c r s}{n}\leftarrow(\mathsf{c r s},U{n}) $$

$$ U_{n} $$

$$ [n] $$

e[n]nfigv1 vn VC*:* Com(crs*;~v*)! (C; aux)Computes for each i 2 [n], Sig and then C S₁ :::Snand aux (v₁;:::;vn).

$$ \mathsf{C o m}(\mathsf{c r s},{\vec{v}})\to\big({\mathcal{C}},\mathsf{a u x}\big) $$

$$ i\in[n],,S_{i}\leftarrow g^{e_{[n]\setminus{i}}} $$

$$ C\leftarrow S_{1}^{v_{1}}\ldots S_{n}^{v_{n}} $$

$$ \leftarrow(v_{1},\ldots,v_{n}) $$

1=eI e e VC*:* Open(crs*;I;~y;* aux)! Computes for each j 2 [n] n I, S g[n]n(I[fjg)and S g[n]nI I j I and then 0 11=e I

$$ \ \ cdot mathsf O P p\ !(\mathsf{c r s},I,\vec{y},\mathsf{a l x}\ \ )\to\pi_{I} $$

$$ j\in[n]\setminus I,,S_{j}^{1/e_{I}}\leftarrow g^{e_{[n]\setminus((I\cup{j})}} $$

$$ S_{I}\leftarrow g^{e_{[n]\setminus I}} $$

$$ \varLambda_{I}\leftarrow\prod_{j=1,j\notin I}^{n}\left(S_{j}^{1/e_{I}}\right)^{y_{j}}=\left(\prod_{j=1,j\notin I}^{n}S_{j}^{y_{j}}\right)^{1/\epsilon} $$

$$ \pi_{I}:=(S_{I},\varLambda_{I}) $$

ReturnsI:= (SI;I)

eInfig 1=ei VC*:* Ver(crs*;C;I;~y;I)! b* ParseI:= (SI;I), and compute Si= S = Unfor every i 2 I. I Return 1 (accept) if both the following checks hold, and 0 (reject) otherwise: Y

$$ \ {sf V V C r}({\sf c r s},{\mathcal{C}},I,\vec{y},\pi_{I})\to b $$

$$ S_{i}=S_{I}^{e_{I\setminus{i}}}=U_{n}^{1/e_{i}} $$

$$ \pi_{I}:=(S_{I},\varLambda_{I}) $$

$$ i\in I $$

$$ S_{I}^{e_{I}}=U_{n};\wedge;C=\varLambda_{I}^{e_{I}}\prod_{i\in I}S_{i}^{y_{i}} $$


The correctness of the above construction holds essentially the same as the one of the SVC of [CF13,LM19] with the addition of the SIelements of the openings, whose correctness can be seen by inspection (and is the same as for RSA accumulators).

$$ S_{I} $$

Incremental Aggregation. Let us now show that the SVC above has incremental aggregation. Note that our algorithms also implicitly show that the RSA-based SVC of [LM19] is incrementally aggregatable.

eInK VC*:* Disagg(crs*;I;~v*I;I;K)!KParseI:= (SI;I). First compute SKfrom SI, SKS, I 1=ejeIn(K[fjg) and then, for every j 2 I n K,j= S, e.g., by computingjS. K I ReturnK:= (SK*;K*) where Y e v

$$ \mathfrak{g}(\mathsf{c r s},I,\vec{v}{I},\pi{I},K)\to\pi_{K} $$

$$ \pi_{I}:=\left(S_{I},\varLambda_{I}\right) $$

$$ S_{K} $$

$$ S_{I},,S_{K}\gets S_{I}^{e_{I\setminus K}} $$

$$ j\in I\setminus K,,\chi_{j}=S_{K}^{1/e_{j}},,{mathrm{e.g}} $$

$$ \chi_{j}\leftarrow S_{I}^{e_{I\setminus(K\cup{j})}} $$

$$ \pi_{K}:=\big(S_{K},\varLambda_{K}\big) $$

$$ \varLambda_{K}\leftarrow\varLambda_{I}^{e_{I\setminus K}}\cdot\prod_{j\in I\setminus K}\chi_{j}^{v_{j}} $$

VC*:* Agg(crs*;* (I;~vI;I); (J;~vJ;J))!KParseI:= (SI;I) and similarlyJ. Also, let K = I [ J, and assume for simplicity that I \ J =; (if this is not the case, one could simply disaggregateI (orJ) toInJ(orJ nI)).

$$ \check{\cdot}.\mathsf{A g g}(\mathsf{c r s},(I,\vec{v}{I},\pi{I}),(J,\vec{v}{J},\pi{J}))\to\pi_{K} $$

$$ \pi_{I}:=(S_{I},\varLambda_{I}) $$

$$ \pi J $$

$$ K=I\cup J. $$

$$ I\cap J=\emptyset $$

$$ \pi\ !I{} $$

$$ \pi_{J}) $$

$$ \pi_{I\setminus J}\ \ \bigl(\mathrm{o r}\ \pi_{J\setminus I}\bigr)_{!}^{!} $$

eJ nfjg 1=ej First, compute SKShamirTrick(SI;SJ;eI;eJ). Next, computejS = S for every K I eInfig 1=ei j 2 J, and similarlyiS = S for every i 2 I. Then compute K J

$$ S_{K}\leftarrow\mathbf{S h a m i r T r i c k}(S_{I},S_{J},e_{I},e_{J}) $$

$$ \phi_{j}\gets S_{K}^{e_{J\setminus{j}}}=S_{I}^{1/e_{j}} $$

$$ j\in J $$

$$ \psi_{i}\gets S_{K}^{e_{I\setminus{i}}}=S_{J}^{1/e_{i}} $$

$$ i\in I $$

$$ \rho_{I}\leftarrow\frac{\varLambda_{I}}{\prod_{j\in J}\phi_{j}^{v_{j}}}\qquad\mathrm{}{a n d}\qquad\sigma_{J}\leftarrow\frac{\varLambda_{J}}{\prod_{i\in I}\psi_{i}^{v_{i}}} $$

ReturnK:= (SK;K) whereKShamirTrick(I;J;eI;eJ).

$$ \pi_{K}:=\big(S_{K},\varLambda_{K}\big) $$

$$ \varLambda_{K}\leftarrow\mathbf{S h a m i r T r i c k}(\rho_{I},\sigma_{J},e_{I},e_{J}) $$

Aggregation Correctness. It follows from the correctness of Shamir’s trick and by construction. In Aggregation and disaggregation SK’s correctness is straightforward, so we emphasize onK. For the disaggregation algorithm:

$$ S_{K}^{^{\ }} $$

$$ \Lambda_{K} $$

$$ \begin{aligned}{\varLambda_{K}:=\varLambda_{I}^{e_{I\setminus K}}\cdot\prod_{j\in I\setminus K}\chi_{j}^{v_{j}}}&{{}=\left(\prod_{j=1,j\notin K}^{n}S_{j}^{v_{j}}\right)^{\frac{1}{e_{I}}e_{I\setminus K}}\cdot\prod_{j\in I\setminus K}\left(S_{j}^{1/e_{K}}\right)^{v_{j}}}\ {}&{{}=\left(\prod_{j=1,j\notin K}^{n}S_{j}^{v_{j}}\right)^{\frac{1}{e_{K}}}\cdot\left(\prod_{j\in I\setminus K}S_{j}^{v_{j}}\right)^{1/e_{K}}}\ {}&{{}=\left(\prod_{j=1,j\notin K}^{n}S_{j}^{v_{j}}\right)^{1/e_{K}}}\ \end{aligned} $$

which is a valid opening for the K-subvector. And for the aggregation algorithm:

$$ \rho_{I}:=\frac{A_{I}}{\prod_{j\in J}\phi_{j}^{v_{j}}}=\left(\prod_{j=1,j\notin I\cup J}^{n}S_{j}^{v_{j}}\right)^{1/e_{I}}\ operatorname{n n d}\ \sigma_{J}:=\frac{A_{J}}{\prod_{j\in I}\psi_{j}^{v_{j}}}=\left(\prod_{j=1,j\notin J\cup I}^{n}S_{j}^{v_{j}}\right)^{1/e_{J}} $$


$$ \begin{aligned}{\varLambda_{K}}&{{}:=\mathbf{S h a m i r T i c c k}(\rho_{I},\sigma_{J},e_{I},e_{J})}\ {}&{{}=\mathbf{S h a m i r r i c c}\left(\left(\prod_{j=1,j\notin I\cup J}^{n}S_{j}^{v_{j}}\right)^{1/e_{I}},\left(\prod_{j=1,j\notin I\cup I}^{n}S_{j}^{v_{j}}\right)^{1/e_{J}},e_{I},e_{J}\right)}\ {}&{{}=\left(\prod_{j=1,j\notin I\cup J}^{n}S_{j}^{v_{j}}\right)^{\overrightarrow{e_{I}I_{J}}}=\left(\prod_{j=1,j\notin I\cup J}^{n}S_{j}^{v_{j}}\right)^{\overrightarrow{e_{I}I_{J\cup J}}}}\ \end{aligned} $$

which is a valid opening for the (I[J)-subvector.

Eciency. We summarize the eciency of this construction in terms of both the computational cost of each algorithm and the communication. For the analysis we consider an instantiation of PrimeGen with a deterministic function that maps every integers in [n] into an ‘-bit prime number. Also, we observe that the algorithms described above may have dierent implementations: while straightforward instantiations may lead to a complexity quadratic in the (sub)vector’s length, in what follows we discuss more ecient ways that keeps the complexity quasilinear. For this, we often rely on the MultiExp algorithm described in [BBF19]. On input an integer n, and two n n vectors ~ 2 G and ~x 2 Z, MultiExp(n;;x) is a divide-and-conquer algorithm that computes Qx =xQ n i n 2 where x = xi, and it does it in time O(nlogn), instead of a naive O(n). i=1 i i=1

$$ \vec{\alpha}\in\mathbb{G}^{n} $$

$$ \vec{x}\in\mathbb{Z}^{n} $$

$$ O(n^{2}) $$

$$ \textstyle\prod_{i=1}^{n}\alpha_{i}^{x^{*}/x_{i}} $$

$$ \textstyle{x^{*}=\prod_{i=1}^{n}x_{i}} $$

Setup. VC*:* Setup generates a group description and samples one random group element, while VC*:* Specialize computes one exponentiation with an (‘ n)-bits integer. Both the universal and the specialized CRS consist each of 1 element of G.

‘ n Committing. Committing to a vector ~v 2 (f0*;* 1g) can be done in time O(‘ nlogn) by using vi the MultiExp algorithm from [BBF19], i.e., C MultiExp(n;;e) wherei= g and ei= PrimeGen(i). The commitment is a single element of G.

$$ \vec{v},\in,({0,1}^{\ell})^{n} $$

$$ \ {\bf[B B F19],\ i i.e.,\ C;\leftarrow;M u l t i E x p}(n,\vec{\alpha},\vec{e}) $$

$$ \alpha_{i}=g^{v_{i}} $$

$$ e_{i},= $$

Opening. An opening for a set I of m positions consists of two group elements, and it can be come[n]nI puted as follows. First, compute SIthrough the exponentiation g which requires O(‘(n m)) group operations, and then computeIin a way similar to committing, i.e.,IMultiExp(n⁰;;x), vj where n⁰ = n m, ~ = (g)j2[n]nI, ~x = (ej)j2[n]nI, which takes time O(‘(n m) log(n m)).

$$ S_{I} $$

$$ g^{e_{[n]}\setminus I} $$

$$ O(\ell(n-m)) $$

$$ \varLambda_{I} $$

$$ \Lambda_ {I} \leftarrow \operatorname {M u l t i E x p} \left(n ^ {\prime}, \vec {\alpha}, \vec {x}\right) $$

$$ n^{\prime}=n-m,:\vec{\alpha}=(g^{v_{j}}){j\in[n]\setminus I},:\vec{x}=(e{j})_{j\in[n]\setminus I} $$

$$ O(\ell(n-m)\log(n-m)) $$

Verification. Verifying an opening for I of size m requires two exponentiations with an (‘m)-bits Qy eIeI i long integer (S and), and the computation of S can be done in time O(‘mlogm) by I I i2I i y1ym running MultiExp(m;;x) with ~ = (S;:::;S) and ~x = (ei)i2I. I I

$$ (S_{I}^{e_{I}} $$

$$ \Lambda_{I}^{e_{I}}) $$

$$ \textstyle\prod_{i\in I}S_{i}^{y_{i}} $$

$$ \vec {\alpha} = \left(S _ {I} ^ {y _ {1}}, \dots , S _ {I} ^ {y _ {m}}\right) $$

$$ \vec {x} = \left(e _ {i}\right) _ {i \in I} $$

Aggregation and Disaggregation. Disaggregation can be computed in time O(‘(jIjjKj) log(jIj jKj)) in a way similar to verication: two exponentiations with an ‘(jIjjKj)-bits long integer vj each, and an invocation of MultiExp((jIjjKj);;x), with ~ = (S)j2InKand ~x = (ej)j2InK, to I QeIn(K[fjg)vj compute S. j2InK I

$$ O(\ell(|I|-|K|)\log(|I|- $$

$$ \ell(|I|-|K|) $$

$$ \ K|)) $$

$$ \mathrm{W u l t i E x p}(\left|||-\left|K\right|\right),{\vec{\alpha}},{\vec{x}}) $$

$$ \vec{\alpha}=(S_{I}^{v_{j}})_{j\in I\backslash K} $$

$$ \textstyle\prod_{j\in I\setminus K}S_{I}^{e_{I\setminus(K\cup{j})}\cdot v_{j}} $$

$$ \vec{x}=(e_{j})_{j\in I\setminus K} $$

Aggregation can be computed in time O(‘mlogm) where m = max(jIj; jJ j) as follows. Two invocations of ShamirTrick, each requiring two exponentiations with (‘m)-bits long integers, QvQ j i to compute SKandK, and two invocations of MultiExp to compute and j2J j i2I iv respectively. From this, we obtain that VC: AggManyToOne and VC*:* DisaggOneToMany take time O(‘mlog² m) G and O(‘mlogmlog(m=B)) G, respectively.

$$ m=\operatorname*{m a x}(|I|,|J|) $$

$$ O(\ell m\log m) $$

$$ S_{K} $$

$$ \Lambda_{K} $$

$$ \textstyle\prod_{j\in J}\phi_{j}^{v_{j}} $$

$$ \textstyle\prod_{i\in I}\psi_{i}^{v_{i}} $$

$$ O(\ell m\log^{2}m)\ \mathbb{G} $$

$$ O(\ell m\log m\log(m{}/{B})),\mathbb{G} $$

Commitment and Opening with Precomputation. Finally, let us summarize the costs of committing and opening with preprocessing obtained by instantiating our method of Section4.2.


The preprocessing VC*:* PPCom, with parameter B, requires O(‘nlognlog(n=B)) operations of G and produces a storage advice of 2n=B group elements. The opening requires computing at most jSj m disaggregation, each taking time O(‘(jPjjjIjj) log((jPjjjIjj))), for a total of O(‘(jSjB jIj) log(jSj)), followed by the aggregation step that counts O(‘jSjlog² jSj). So, in the worst case VC*:* FastOpen takes O(‘ m (log²(m) + B 1)) operations of G.

$$ n\log(n/B)) $$

$$ 2n/B $$

$$ |S|\leq m $$

$$ O(\ell(\ P_{j}|\ ||,,|I_{j}|,)\log(\left|{{j}}|,|,|I{j}|,\right\rangle)) $$

$$ |I|)\operatorname{l o g}(|S|)) $$

$$ O(\ell(|S|B- $$

$$ O(\ell|S|\log^{2}|S|) $$

$$ O(\ell\cdot m\cdot(\log^{2}(m)+B-1). $$

Security. For the security of the above SVC scheme we observe that the dierence with the corresponding [LM19] lies in the generation of Si’s. In [LM19] they are generated in the trusted setup phase, thus they are considered \well-formed" in the security proof. In our case, the Si’s are reconstructed during verication time from the SIthat comes in the openingIwhich can (possibly) eI be generated in an adversarial way. However, in the verication it is checked that S = U, where I e[n] U = g is computed in the trusted setup. So under the Low Order assumption we get that SIhas e[n]=eIe[n]nI the correct form, SI= g = g, with overwhelming probability. Except for this change, the rest reduces to the position binding of the [LM19] SVC.

$$ S_{i}^{\ }, $$

$$ {5{_{i}}^{\prime}\mathrm{{S}}} $$

$$ \pi\ !I $$

$$ S_{I} $$

$$ S_{I}^{e_{I}}=U $$

$$ U=g^{e_{[n]}} $$

$$ S_{I} $$

$$ S_{I}=g^{e_{[n]}/e_{I}}=g^{e_{[n]\setminus I}} $$

Theorem 5.3(Position-Binding). Let Ggen be the generator of hidden order groups where the Low Order assumption holds and the [LM19] SVC is position binding. Then the SVC scheme dened above is position binding.

Proof We start by dening the game G₀ as the actual position binding game of Denition3.2, and our goal is to prove that for any PPT A, Pr[G₀ = 1] 2 negl():

$$ G_{0} $$

$$ \mathcal{A},\operatorname*{P r}[G_{0}=1]\in\mathsf{n e g l}(\lambda) $$

Game G₀: G₀ = PosBind

$$ G_{0}; $$

$$ G_{0}=\sf{P o s B i n d_{V C}^{A}}(\lambda) $$

$$ \mathsf{c r s}\leftarrow\mathsf{V C}.\mathsf{S e t u p}(1^{\lambda},\mathcal{M}) $$

$$ (\mathcal{C},I,\vec{y},\pi,\vec{y}^{\prime},\pi^{\prime})\leftarrow\mathcal{A}(\mathsf{c r s}) $$

$$ b\leftarrow\mathsf{V C.V e r}(\mathsf{c r s},C,I,\vec{y},\pi)=\mathbf{1}\wedge\vec{y}\not\ \neq\vec{y}^{\prime}\wedge\mathsf{V C.V e r}(\mathsf{c r s},C,I,\vec{y}^{\prime},\pi^{\prime})=\mathbf{1} $$

0 0I More specically crs := (G*;g;* PrimeGen), := (SI;I), := (S;) and I0 Y

$$ \mathrm {c r s} := (\mathbb {G}, g, \mathrm {P r i m e G e n}), \pi := \left(S _ {I}, A _ {I}\right), \pi^ {\prime}: = \left(S _ {I} ^ {\prime}, A _ {I} ^ {\prime}\right) $$

$$ b=S_{I}^{e_{I}}=U_{n}\wedge C=\varLambda_{I}^{e_{I}}\prod_{i\in I}S_{i}^{y_{i}}\wedge\vec{y}=\vec{y}^{\prime}\wedge S_{I}^{\prime e_{I}}=U_{n}\wedge C=\varLambda_{I}^{\prime e_{I}}\prod_{i\in I}S_{i}^{y_{i}^{\prime\prime}} $$

eInfig0eInfig where Si= S and S = S for each i 2 I. I i0 I

$$ \ \ S{}{i}=S{I}^{e_{I\setminus{i}}} $$

$$ S_{i}^{\prime}=S_{I}^{\prime e_{I\setminus{i}}} $$

$$ i\in I $$

Now let G₁ be the same as above except for the outputted by the adversary SIand S it holds I0 e[n]nIeI0eI that SI= g = S. The S = Un= S checks are not done in the verication (as they are I0 I I redundant):

$$ G_{1} $$

$$ S_{I} $$

$$ S_{I}^{\prime} $$

$$ S_{I}=g^{e_{[n]\setminus I}}=S_{I}^{\prime} $$

$$ S_{I}^{e_{I}}=U_{n}=S_{I}^{\prime e_{I}} $$

$$ G_{1}, $$

Game G₁: G₁

$$ \begin{array}{l} G _ {1} \ \mathrm {c r s} \leftarrow \mathrm {V C}. \mathrm {S e t u p} \left(1 ^ {\lambda}, \mathcal {M}\right) \ \left(C, I, \vec {y}, \left(S _ {I}, \Lambda_ {I}\right), \vec {y} ^ {\prime}, \left(S _ {I} ^ {\prime}, \Lambda_ {I} ^ {\prime}\right)\right) \leftarrow \mathcal {A} (\mathrm {c r s}) \ \mathrm {i f} S _ {I} \neq g ^ {e [ n ] \backslash I} \text {o r} S _ {I} ^ {\prime} \neq g ^ {e [ n ] \backslash I} \mathrm {t h e n a b o r t} \ b \leftarrow C = \Lambda_ {I} ^ {e _ {I}} \prod_ {i \in I} \left(S _ {I} ^ {e _ {I} \setminus {i}}\right) ^ {y _ {i}} \wedge \vec {y} = \vec {y} ^ {\prime} \wedge C = \Lambda_ {I} ^ {\prime e _ {I}} \prod_ {i \in I} \left(S _ {I} ^ {\prime e _ {I} \setminus {i}}\right) ^ {y _ {i} ^ {\prime}} \ \end{array} $$

return b

eI eIeI Then Pr[G₀ = 1] Pr[G₁ = 1] + negl(). In G₀, S = Un= g. Assume that SI6= g then I e eIeI 1 eIpoly() g[n]nI= S, hence S = S) S S = 1. Since S is eciently computable and e < 2 I I I I I I I

$$ \operatorname*{P r}[G_{0},=,1],\leq,\operatorname*{P r}[G_{1},=,1],+,\mathsf n e g l(\lambda) $$

$$ G_{0},,S_{I}^{e_{I}}=U_{n}=g^{e_{I}} $$

$$ \beta_{I}\neq g^{e_{I}} $$

$$ g^{e_{[n]\setminus I}}=S_{I}^{*} $$

$$ S_{I}^{e_{I}}=S_{I}^{e_{I}}\Rightarrow\left(S_{I}^{-1}S_{I}^{}\right)^{e_{I}}=1 $$

$$ S_{I}^{*} $$

$$ e_{I}<2^{\mathsf{p o l y}(\lambda)} $$ this constitutes a solution to the Low Order problem for the hidden order group. The previous happens only with negligible probability under the Low Order assumption. The same holds for S. I0 e[n]nfig Notice that it follows that Si= S = g. i0

$$ S_{i}=S_{i}^{\prime}=g^{e_{[n]}setminus{{\\ \ }}} $$

e[n]nfig Let G₂ be the same as above except the adversary receives eiPrimeGen(i) and Si= g for each i 2 [n], together with the parameters:

$$ S_{I}^{\prime} $$

$$ G_{2} $$

$$ e_{i}\leftarrow{\mathsf r i m e G e n}(i) $$

$$ S_{i}=g^{e_{[n]\setminus{i}}} $$

$$ i\in[n] $$

Game G₂:

$$ G_{2}, $$

G₂ (G;g; PrimeGen) VC*:* Setup(1*; M*) Q i2[n]nfigei ei PrimeGen(i);Si = g for each i 2 [n] 0I (C;I;y;I;y⁰;) A G*;g;* PrimeGen*; fSigi2[n] Y Y e 0 0IeI y0 b C =IISiyi^ y* = *y ^ C* = Si i i2I i2I

$$ (\mathbb{G},\mathfrak{g},\mathsf{P r i m e G e n})\leftarrow\mathbb{V C}.\mathsf{S e t u p}(\ {{1}}^{\lambda},\mathcal{M}) $$

$$ e_{i}\leftarrow\mathsf{P r i m e G e n}(i);S_{i}=g^{\prod_{i\in{n}\setminus{i}}e{{}_{i}}}\mathrm{}{f o re a c hi\in[n]} $$

$$ (C,I,\vec{y},\varLambda_{I},\vec{y}^{\prime},\varLambda_{I}^{\prime})\leftarrow\mathcal{A}\left(\mathbb{G},g,\mathsf{P r i m e G e n},{S_{i}}_{i\in[n]}\right) $$

$$ b\gets C=\varLambda_{I}^{e_{I}}\prod_{i\in I}S_{i}^{y_{i}}\wedge\vec{y}=\vec{y}^{\prime}\wedge C=\varLambda_{I}^{\prime e_{I}}\prod_{i\in I}S_{i}^{y_{i}^{\prime}} $$

return b

It is straightforward that Pr[G₁ = 1] = Pr[G₂ = 1] and furthermore G₂ is identical to the position binding game of the [LM19] SVC scheme and according to the hypothesis Pr[G₂ = 1] = negl().

$$ \operatorname*{P r}[G_{1}!=!1]=\operatorname*{P r}[G_{2}!=!1] $$

$$ G_{2} $$

$$ \operatorname*r P![left[G_{2}=1]=\ \mathsf{n e g l!(\lambda)}.,subset $$

As showed in [LM19], their SVC is position binding under the strong Distinct-Prime-Product Root assumption in the standard model. We conclude that the above SVC is position binding in hidden order groups where the Low Order and the Strong Distinct-Prime-Product Root assumptions hold.

5.3 Comparison with Related Work

We compare our two SVC schemes with the recent scheme proposed by Boneh et al. [BBF19] and 18 the one by Lai and Malavolta [LM19], which extends [CF13] to support subvector openings. We present a detailed comparison in Table1, considering to work with vectors of length N of ‘-bit elements and security parameter. In particular we consider an instantiation of our rst SVC with k = 1 (and thus n = N ‘).

$$ k=1 $$

$$ n=N\cdot\ell) $$

Setup Model. [BBF19] works with a fully universal CRS, whereas our schemes have both a universal CRS with deterministic specialization, which however, in comparison to [CF13,LM19], outputs constant-size parameters instead of linear.

Aggregation. The VC of [BBF19] supports aggregation only on openings created by VC*:* Open (i.e., it is one-hop) and does not have disaggregatable proofs (unless in a dierent model where one works linearly in the length of the vector or knows the full vector). In contrast, we show the rst schemes that satisfy incremental aggregation (also, our second one immediately yields a method for the incremental aggregation of [LM19]). As we mention later, incremental aggregation can be very useful to precompute openings for a certain number of vector blocks allowing for interesting time-space tradeos that can speedup the running time of VC*:* Open.

Efficiency. From the table, one can see that our rst SVC has: slightly worse commitments size than all the other schemes, computational asymptotic performances similar to [BBF19], and opening size slightly better than [BBF19]. Our second SVC is the most ecient among the schemes with constant-size parameters; in particular, it has faster asymptotics than our rst SVC and [BBF19]

18 We refer to [BBF19] to see how these schemes compare with Merkle trees.


for having a smaller logarithmic factor (e.g., log(N m) vs. log(‘N)), which is due to the avoidance of using one prime per bit of the vector. In some cases, [CF13,LM19] is slightly better, but this is essentially a benet of the linear-size parameters, namely the improvement is due to having the Si’s elements already precomputed.

$$ (\mathrm {e . g .}, \log (N - m) $$

$$ S _ {i} ^ {\prime} \mathrm {s} $$

When considering applications in which a user creates the commitment to a vector and (at some later points in time) is requested to produce openings for various subvectors, our incremental aggregation property leads to use preprocessing to achieve more favorable time and memory costs. In a nutshell, The idea of preprocessing is that one can precompute and store information that allows to speedup the generation of openings, in particular by making opening time less dependent on the total length of the vector. Our method in Section4.2works generically for any SVC that has incremental aggregation. A similar preprocessing solution can also be designed for the SVC of [BBF19] by using its one-hop aggregation; we provide a detailed description of the method in AppendixB. The preprocessing for [BBF19] however has no exibility in choosing how much auxiliary storage can be used, and one must store (a portion of) a non-membership witness for every bit of the vector.

Even in the simplest case of B = 1 (shown in Table1) both our SVCs save a factor ‘ in storage, which concretely turns into 3 less storage.

Furthermore we support exible choices of B thus allowing to tune the amount of auxiliary p p storage. For instance, we can choose B = N so as to get 2 N jGj bits of storage, and opening time p p 2 about O(‘mlogn( n+ logm)) and O(m( n+ log m)) in the rst and second scheme respectively. Our exibility may also allow one to choose the buckets size B and their distribution according to applications-dependent heuristics; investigating its benet may be an interesting direction for future work.

$$ B=\sqrt{N} $$

$$ 2\sqrt{N}|\mathbb{G}| $$

$$ n{\big(}{\sqrt{n}}+\log m\big), $$

$$ O(m{\bigl(}{\sqrt{n}}+{log^{2}}m{\bigr)}) $$

Metric Our First SVC Our Second SVC [BBF19] [CF13,LM19]
Setup
VC.Setup O(1) O(1) O(1) O(1)
crs 3 G
VC.Specialize O(ℓ·N·log(ℓN))G O(ℓ·N)G - O(ℓ·N·logN)G
crs_N 1 G
Commit a vector $\vec{v}\in({0,1}^{\ell})^{N}$
VC.Com O(ℓ·N·log(ℓN))G O(ℓ·N·logN)G O(ℓ·N·log(ℓN))G O(ℓ·N)G
C 4 G
Opening and Verification for $\vec{v}_{I}$ with $ I =m$
VC.Open O(ℓ·(N-m)·log(ℓN))G O(ℓ·(N-m)·log(N-m))G O(ℓ·(N-m)·log(ℓN))G O(ℓ·(N-m)·m log m)G
π_I 3 G
VC.Ver O(ℓ·m·log(ℓN))Z_{22λ}+O(\lambda)G O(ℓ·m log m) G
Commitment and Opening with Precomputation
VC.Com O(ℓ·N·log(ℓ·N)·log(N))G O(ℓ·N log^2(N))G O(ℓ·N·log(ℓ·N)·log(N))G O(ℓ·N log^2(N))
aux 2N G
VC.Open O(m·ℓ·log(m) log(ℓN))G O(ℓ·m log^2m)G O(m·ℓ·log(m) log(ℓN))G O(m·ℓ·log^2(m))G
Aggregation Incremental Incremental One-hop Incremental
Disaggregation Yes Yes No Yes

$$ O(\ell\cdot N\cdot\operatorname{l o g}(\ell N));\mathbb{G} $$

$$ O(\ell\cdot N)\ \mathbb{G} $$

$$ O(\ell\cdot N\cdot\operatorname{l o g}N)\ mathbb G; $$

$$ \vec{v}\in({0,1}^{\ell})^{N} $$

$$ O(\ell\cdot N\cdot\operatorname{l o g}N);\mathbb{G} $$

$$ \overline{{O(\ell\cdot N\cdot\operatorname{l o g}(\ell N))\ \mathbb{G}}} $$

$$ \overline{{O(\ell\cdot N),\mathbb{G}}} $$

$$ O(\ell\cdot N\cdot\operatorname{l o g}(\ell N));\mathbb{G} $$

$$ 4\ |\mathbb{G}|+2\ |\mathbb{Z}_{2^{2\lambda}}| $$

$$ O(\ell\cdot(N-m)\cdot\log(\ell N)),\mathbb{G} $$

$$ \left|O(\ell\cdot(N-m)\cdot\operatorname{l o g}(N-m)\right)\mathbb{G} $$

$$ O(\ell\cdot(N-m)\cdot\log(\ell N));\mathbb{G} $$

$$ \overline{{\left|O(\ell\cdot(N-m)\cdot m\operatorname{l o g}m\right)\mathbb{G}}} $$

$$ 2\left|\mathbb{G}\right| $$

$$ 5\ |\mathbb{G}|+1\ |\mathbb{Z}_{2^{2\lambda}}| $$

$$ O \left(\ell \cdot m \cdot \log (\ell N)\right) \mathbb {Z} _ {2 ^ {2 \lambda}} + O (\lambda) \mathbb {G} $$

$$ O(\ell\cdot m\operatorname{l o g}m);|\mathbb{G}| $$

$$ 0(m\cdot\ell\cdot\log(N))\mathbb{I}_{2^{2\lambda}}+O(\lambda)\mathbb{G} $$

$$ \overline{{O(\ell\cdot N\cdot\log(\ell\cdot N)\cdot\log(N))\mathbb{G}}} $$

$$ O(\ell\cdot N\operatorname{l o g}^{2}(N));\mathbb{G} $$

$$ {\overline{{O(\ell\cdot N\cdot\log(\ell\cdot N)\cdot\log(N))\ \mathbb{G}}}} $$

$$ \overline{{O(\ell\cdot N\operatorname{l o g}^{2}(N))}} $$

$$ 2N\left|\mathbb{G}\right| $$

$$ 2N,|\mathbb{G}|+O(\ell\cdot N\log(\ell N)) $$

$$ 2N\left|\mathbb{G}\right| $$

$$ O(m\cdot\ell\cdot\log(m)\log(\ell N)),\mathbb{G} $$

$$ 2N\left|\mathbb{G}\right| $$

$$ O(\ell\cdot m\operatorname{l o g}^{2}m);mathbb $$

$$ O(m\cdot\ell\cdot\log(m)\log(\ell N));\mathbb{G} $$

$$ O(m\cdot\ell\cdot\operatorname{l o g}^{2}(m));\mathbb{G} $$

Table 1. Comparison between the SVC’s of [BBF19], [LM19] and this work; our contributions are highlighted in gray. ‘ N We consider committing to a vector ~v 2 (f0*;* 1g) of length N, and opening and verifying for a set I of m positions. By ‘O(x) G’ we mean O(x) group operations in G; jGj denotes the bit length of an element of G. An alternative algorithm for VC*:* Open in [LM19] costs O(‘ (N m) log(N m)). Our precomputation is for B = 1.

$$ \vec{v}\in({0,1}^{\ell})^{N} $$

$$ {mathfrak}O{({\boldsymbol{x}})}\ \mathbb{G}^{\ } $$

$$ O(x) $$

$$ \mathbb{G}, $$

$$ O(\ell\cdot(N-m)\cdot\log(N-m)) $$

$$ B=1 $$


Setup(1) : run G $ Ggen(1), g $ G, set crs := (G*;g*). Prover’s input: (crs*;* (A;B;C;;); (a;b)). Verier’s input: (crs*;* (A;B;C;;)). V! P: h $ G a b P! V: z := (za;zb) computed as za h;zbh V! P: ‘ $ Primes() and $ [0*;* 2) P! V: := ((QA;QB;QC);ra;rb) computed as follows { (qa;qb;qab) (ba=‘c; bb=‘c; bab=‘c) { (ra;rb) (a mod ‘;b mod ‘) qa qa qb qb qab { (QA;QB;QC) := ( h; h;g) V(crs; (A;B;C);za;zb;‘;;): { Compute rc ra rbmod ‘ ‘ ra ra ‘ rb rb ‘ rc { Output 1 i ra;rb2 [‘] ^ QAh = Aza^ QBh = Bzb^ QCg = C

$$ {\underline{{\mathsf{V}}}}\to{\underline{{\mathsf{P}}}}\colon h\leftarrow{\mathfrak{S}},{\mathbb{G}} $$

$$ \underline{{\mathsf{P}\to\mathcal{V}}};\ z z:=\left(z_{a},z_{b}\right) $$

$$ \underline {{\mathrm {V} \rightarrow \mathrm {P}}}: \ell \leftarrow $ \operatorname {P r i m e s} (\lambda) $$

$$ z_{a}\leftarrow h^{a},z_{b}\leftarrow h^{b} $$

$$ \alpha\leftarrow\ [,22^{\lambda}) $$

$$ \underline {{\mathrm {P} \rightarrow \mathrm {V}}}: \pi := \left(\left(Q _ {A}, Q _ {B}, Q _ {C}\right), r _ {a}, r _ {b}\right) $$

$$ -\ (q_{a},q_{b},q_{a b})\leftarrow(\ a/c\ ,\ b/c,\ \ a a//c/)) $$

$$ -\ (r_{a},r_{b})\leftarrow(a $$

$$ -\ (Q_{A},Q_{B},Q_{C}):=(\varGamma^{q_{a}}h^{\alpha q_{a}},\varDelta^{q_{b}}h^{\alpha q_{b}},g^{q_{a b}}) $$

$$ \mathsf{V}(\mathsf{c r s},(A,B,C),z_{a},z_{b},\ell,\alpha,\pi) $$

$$ r_{c}\leftarrow r_{a}\cdot r_{b} $$

Fig. 4. PoProd protocol

6 Arguments of Knowledge for Our First SVC

We propose three Arguments of Knowledge (AoK) related to our vector commitment scheme presented in section5.1. More specically, the rst AoK allows one to prove knowledge of an opening of a subvector. The second AoK, is a direct outcome of the rst and allows one to prove that two given commitments share a common subvector. Finally, the third protocol allows one to commit to a prex-subvector of a vector and prove the knowledge of it succinctly.

Similarly to section5.1, our protocols build on the techniques for succinct proofs in groups of unknown order from [BBF19]. Furthermore, these arguments of knowledge are not zero knowledge and they serve eciency purposes. Interestingly, one can prove knowledge of a portion of a vector committed without having to send the actual vector values. The proofs are constant-size which leads to an improvement of communication complexity linear in the size of the opening.

6.1 Building block: A Stronger Proof of Product

Before proceeding to describing the main protocols, we introduce another one that is used as building block. This is an argument of knowledge, called PoProd , for the relation RPoProddescribed below, which uses a common reference string consisting of a hidden order group G Ggen(1 ) and a random generator g 2 G:

$$ R_{\mathsf{P o P r o d^{*}}} $$

$$ \mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda}) $$

$$ g\in\mathbb{G} $$

$$ R _ {\mathrm {P o P r o d} ^ {*}} = \left{\left((A, B, C, \Gamma , \Delta), (a, b)\right) \in \mathbb {G} ^ {5} \times \mathbb {Z} ^ {2}: A = \Gamma^ {a} \wedge B = \Delta^ {b} \wedge C = g ^ {a \cdot b} \right} $$

The relation RPoProdis similar to RPoProddened in Section5.1with the dierence that now the rst two bases and are not part of the common reference string, but part of the statement instead. As argued in [BBF19] the PoKE protocol is not secure anymore for adversarially chosen bases, therefore we cannot use PoProd protocol which assumes knowledge extractability of PoKE . To deal with this problem, we thus modify the protocol by using the protocol PoKE2, which is secure for arbitrary bases. This comes with some cost: in our PoProd a proof consists of 5 group elements and 2 eld elements, that is 2 group elements more comparing to proofs of PoProd. The protocol is in Fig.6.1.

$$ R_{\mathsf{P o P r o d^{*}}} $$

$$ R_{\mathsf P o p r o d} $$

$$ \Delta $$

Theorem 6.1. The PoProd protocol in Fig.6.1is an argument of knowledge for RPoProdin the generic group model.

$$ R_{\mathsf{P o P r o d^{*}}} $$


The proof of the theorem above is similar to the proof of Theorem5.1, except that we use the extractor EPoKE2of the protocol PoKE2 from [BBF19] in order to extract integers a and b and EPoKEin order to extract the exponent of C.

$$ \mathcal{E}_{\mathsf{P o K E E2}} $$

$$ \mathcal{E}_{\mathsf{P o K E}^{*}} $$

6.2 A Succinct AoK of Opening for our VC Construction

We show an argument of knowledge of an I-opening with respect to a commitment C to a vector, where I is a set of positions. We emphasize that the goal of this protocol is not to keep the opening secret (i.e., the protocol is not zero knowledge, also our vector commitment scheme is not hiding). The goal is to reduce the communication complexity of an opening by proving knowledge of the subvector at positions I without having to actually send the values ~vI. Even though the argument of knowledge itself adds an overhead it is independent of the number of the positions. Hence, the protocol makes more sense for large sets of positions I as for a small number of positions the overhead of the AoK would exceed the size of the opening values.

$$ {vec{v}}_{I} $$

Let VC = (VC*:* Setup*;VC:* Specialize*;VC:* Com*;VC:* Open*;VC:* Ver) be our SVC scheme from Section 5.1, and let us dene the following relation

$$ R_{\mathsf{P o K O O e e n}}={(:(C,I),:(\vec{y},\pi_{I}):):\mathsf{V C.V e r}(\mathsf{c r s},C,I,\vec{y},\pi_{I})=1} $$

that is parametrized by a CRS crs VC*:* Setup(1*; M*), and where the statement consists of a jIj commitment C and a set of indices I [n], and the witness consists of a vector ~y 2M and an openingI.

$$ \leftarrow\ {mathsf V C C}u t{\mathsf{u p}}(1^{\lambda},{\mathcal{M}}) $$

$$ I\subseteq[n] $$

$$ \vec{y}\in\mathcal{M}^{|I|} $$

$$ \pi I $$

For simplicity we present a protocol PoKOpen for the case when k = 1 in our VC (see section5.1); extension to larger k is immediate. The idea of our protocol is that, given a commitment C := ((A;B);prod) and a set of indices I, the prover, holdingI:= (I;I), rst sendsIto the verier aIbI aIbIuI and then provides an AoK of (aI;bI) such that = A ^ = B ^ g = UI, where UIg I I with uIPrimeProd(I). This can be proven by using the PoProd protocol presented above. Finally the verier should also verify theprodproof as in the normal verication of an opening algorithm.

$$ C:= $$

$$ \pi_{I}:=\left(\varGamma_{I},\varDelta_{I}\right) $$

$$ ((A,B),\pi_{\mathsf{p r o d}}) $$

$$ \pi I $$

$$ \varGamma_{I}^{a_{I}}=A\wedge\varDelta_{I}^{b_{I}}=B\wedge g^{a_{I}\cdot b_{I}}=U_{I} $$

$$ (a_{I},b_{I}) $$

$$ U_{I}\leftarrow g^{u_{I}} $$

$$ u_{I}\gets\mathsf{P r i m e P r o d}(I) $$

$$ \pi_{\mathsf{p r o d}} $$

We state the following theorem.

Theorem 6.2. If PoProd is a succinct argument of knowledge for RPoProd, then protocol PoKOpen is a succinct argument of knowledge for relation RPoKOpenwith respect to algorithm VC*:* Ver of our construction of Section5.1.

$$ R_{\mathsf{P o P r o d^{*}}} $$

$$ R_{\mathsf P o o Q O p n} $$

Proof Let A be an adversary of the Knowledge Extractability of PoKOpen such that: ((C;I);state) A₀(pp), A₁(pp; (C;I);state) executes with V(pp; (C;I)) the protocol PoKOpen and the verier accepts with a non-negligible probability. We will construct an extractor E that having access to the internal state of A₁ and on input (pp, (C;I);state), outputs a witness (~y;I) of RPoKOpenwith overwhelming probability and runs in (expected) polynomial time.

$$ ((C,I),\mathsf{s t a t e})\leftarrow $$

$$ \mathcal{A}{0}(\mathsf{p p}),\thinspace\mathcal{A}{1}(\mathsf{p p},(C,I) $$

$$ \mathsf{V}(\mathsf{p p},(C C,I)) $$

$$ \mathcal{E} $$

$$ \mathcal{A}_{1} $$

$$ (\vec{y},\pi_{I}) $$

$$ R_{\mathsf P o o Q O p n} $$

To prove knowledge extractability of PoKOpen we rely on the knowledge extractability of PoProd . More precisely, given a PoKOpen execution between A and V, (I*;I; 0*), E con- PoProd structs an adversary A⁰ = (A⁰0; A⁰1) of PoProd Knowledge Extractability and, by using the input and internal state of A₁, simulates an execution between A⁰ and V: A⁰0outputs (((G*;g*); (A;B;UI; *I;I));*state), A⁰1outputs tuple

$$ \mathsf{P o P r o d}^{*} $$

$$ \mathcal{A}^{\prime}=(\mathcal{A}{0}^{\prime},\mathcal{A}{1}^{\prime}) $$

$$ \mathsf{V},:(\varGamma_{I},\varDelta_{I},\pi_{\mathsf{P_{0}P P o d^{\prime}}}),:\mathcal{E} $$

$$ \mathcal{A} $$

$$ \Gamma_ {I}, \Delta_ {I}) $$

$$ \mathrm {V}: \mathcal {A} _ {0} ^ {\prime} $$

$$ \ {\cal A}_{1}. $$

$$ \mathcal{A}_{1}^{\prime} $$

$$ \mathcal{A}^{\prime} $$

$$ (((\mathbb{G},g),(A,B,U_{I} $$

(za;zb; (QA;QB;QC);ra;rb). It is obvious that if the initial execution is accepted by V so is the PoProd execution. From Knowledge Extractability of PoProd we know that there exists an extrac- 0 0 aIbI aIbI tor E corresponding to A₁ that outputs (aI;bI) such that A = ^ B = ^ UI= g. Since I I

$$ (z_{a},z_{b},(Q_{A},Q_{B},Q_{C}),r_{a},r_{b}) $$

$$ \mathsf{P o P r o d}^{*} $$

$$ \ mathcal E{{}}^prime{} $$

$$ \mathcal{A}_{1}^{\prime} $$

$$ A=\varGamma_{\it I}^{a_{I}}\wedge B=\varDelta_{\it I}^{b_{I}}\wedge U_{I}=g^{a_{I}\cdot b_{I}} $$

$$ (a_{I},b_{I}) $$


PoKOpen protocol Prover’s input: (crs*;* (C;I); (~y;I). Verier’s input: (crs*;* (C;I)). uI V Compute uI PrimeProd(I) and then UI g. un Similarly compute un PrimeProd([n]) and then Un g P: Parse crs := (G*;g;g₀;g₁;PrimeGen;Un*), C := (fA;Bg;prod), I := ( I;I). Compute (aI;bI) uI PartndPrimeProd(I;~y) and then uI PrimeProd(I) and UI g. P! V: ( I;I) Finally a PoProd protocol (with an additional check of the commitment) between P((G;g); (A;B;UI;I;I); (aI;bI)) and V((G*;g*); (A;B;UI;I;I)) is executed: V! P: h $ G aI bI P! V: z := (za;zb) computed as za h;zbh V! P: ‘ $ Primes() and $ [0*;* 2) P! V: := ((QA;QB;QC);ra;rb) computed as follows { (qa;qb;qab) (baI=‘c; bbI=‘c; baI bI=‘c) { (ra;rb) (aI mod ‘;bI mod ‘) qa q qb qab { (QA;QB;QC) := (Iqah;Ibh;g) V: Parse crs := (G*;g;g₀;g₁;PrimeGen;Un*) and C := (fA;Bg;prod). { Compute rc ra rbmod ‘ ‘ ra ‘ r rb ‘ rc { Output 1 i ra;rb2 [‘] ^ QA Irah = Aza*^ QB Ibh* = Bzb*^ Q*Cg = UI ^ PoProd₂*:* V(crs*;* (A B;Un);prod)

$$ U_{I}\gets g^{u_{I}} $$

$$ (\mathsf{c r s},(C,I),(\vec{y},\pi_{I}) $$

$$ \ \ (\mathsf{c r s},(\mathcal{C},I)) $$

$$ u_{I}\leftarrow\mathsf{P r i m e P r d}(I) $$

$$ U_{n}\leftarrow g^{u_{n}} $$

$$ u_{n}\leftarrow\mathsf{P r i m e P r o d}([n]) $$

$$ \begin{array}{r c l c l l l}{\ \mathsf{c r s}}&{:=}&{(\mathbb{G},g,g_{0},g_{1},\mathsf{P r i m e G e n},U_{n}),;;C}&{:=}&{({A,B},\pi_{\mathsf{p r o d}}),;;\pi_{I}}&{:=}&{(\varGamma_{I},\varDelta_{I})}\ \end{array} $$

$$ \ a(a_{I},b_{I}),\leftarrow, $$

$$ U_{I}\leftarrow g^{u_{I}} $$

$$ \mathsf{P}((\mathbb{G},g),(A,B,U_{I},\varGamma_{I},\varDelta_{I}),(a_{I},b_{I})\big) $$

$$ \underline{{\mathsf{{P}}}}\to\underline{{\mathsf{{V}}}}\ {\mathrm:{{{}}}}\ (\ \varGamma_{I},\varDelta_{I}) $$

$$ \mathsf{V}((\mathbb{G},g),(A,B,U_{I},\varGamma_{I},\varDelta_{I})) $$

$$ {\underline{{\mathsf{V}}}}\to{\underline{{\mathsf{P}}}}\colon h\leftarrow{\mathfrak{s}},{\mathbb{G}} $$

$$ {\underline{{\mathsf{P}}}}\to{\underline{{\mathsf{V}}}};z:=\left(z_{a},z_{b}\right) $$

$$ z_{a}\leftarrow h^{a_{I}},z_{b}\leftarrow h^{b_{I}} $$

$$ \underline{{\mathsf{{V}}}}\to\mathsf{{P}}:\ell\leftarrow\sharp\mathsf{{P r i m e s}}(\lambda) $$

$$ \alpha \leftarrow \mathbb {s} [ 0, 2 ^ {\lambda}) $$

$$ \underline{{\mathcal{P}\to\mathcal{V}}};\pi:=((\mathcal{Q}{A},\mathcal{Q}{B},\mathcal{Q}{C}),r{a},r_{b}) $$

$$ -\ (mathit q_{{a}},\mathit{{{}}}\ \mathit{q}{{{a b}}})\leftarrow(\lfloor\mathit{a_{I}}/\ell\rfloor,\lfloor\mathit{b_{I}}/\ell\rfloor,\lfloor\mathit{a_{I}}{b_{I}}/\ell\rfloor) $$

$$ -\ (r_{a},r_{b})\leftarrow(a_{I} $$

$$ \ell,b_{I} $$

$$ -\ (Q_{A},Q_{B},Q_{C}):=(\varGamma_{I}^{q_{a}}h^{\alpha q_{a}},\varDelta_{I}^{q_{b}}h^{\alpha q_{b}},g^{q_{a b}}) $$

$$ C:=({A,B},\pi_{\mathsf{p r o d}}) $$

$$ U_{n}) $$

$$ \mathrm{-C o m p u t e}r_{c}\gets r_{a}\cdot r_{b} $$

$$

$$ B,U_{n}),\pi_{\mathsf{p r o d}}) $$

Fig. 5. PoKOpen protocol

uI UIis also computed from V it holds that UI= g, unless with a negligible probability that A⁰ x uI can nd an x 6= uIsuch that g = UI= g (which implies nding a multiple of the order of G). uIaIbI Therefore g = UI= g and using the same argument we know that uI= aIbI(unless with negligible probability).

$$ U_{I} $$

$$ \mathcal{A}^{\prime} $$

$$ U_{I}=y^{u_{I}} $$

$$ x\neq u_{I} $$

$$ g^{x}=U_{I}=g^{u_{I}} $$

$$ g^{u_{I}}=U_{I}=g^{a_{I}\cdot b_{I}} $$

$$ u_{I}=a_{I}\cdot b_{I} $$

0 aIbI aIbI So, E uses E and gets a (aI;bI) such that A = ^ B = ^ UI= g. Then computes I I uIPrimeProd(I) and works as follows: for each i 2 I computes piPrimeGen(i) and if pij aI then sets yi= 0, otherwise if pij aIthen sets yi= 1. It is clear that pidivides exactly one of Q Q aI;bIsince aIbI= uI= pi:= PrimeGen(i) (unless with a negligible probability that i2I i2I a collision happened in PrimeGen). Finally sets the subvector ~y = (yi)i2IandI= (I;I). As aIbI stated above = A ^ = B and also since V veries the PoKOpen protocol it holds that I I PoProd₂*:* V(pp*;* (A B;Un);prod) which means that VC*:* Ver(pp*;C;I;~y;*I) = 1.

$$ \mathcal{E}^{\prime} $$

$$ (a_{I},b_{I}) $$

$$ u_{I}\leftarrow{mathsf{P r i m e P r d d}}(I) $$

$$ A,=,\
$$

$$ i\in I $$

$$ p_{i}\gets\mathsf{P r i m e G e n}(i) $$

$$ p_{i}\mid a_{I} $$

$$ y_{i},=,0 $$

$$ p_{i}\mid a_{I} $$

$$ y_{i}=1 $$

$$ p_{i} $$

$$ a_{I},b_{I} $$

$$ a_{I}\cdot b_{I}=u_{I}=\prod_{i\in I}p_{i}:=\prod_{i\in I} $$

$$ \pi_{I}=(\varGamma_{I},\varDelta_{I}) $$

$$ \varGamma_{I}^{a_{I}}=A\wedge\varDelta_{I}^{b_{I}}=B $$

$$ \mathrm {P o P r o d} _ {2}. \mathrm {V} (\mathrm {p p}, (A \cdot B, U _ {n}), \pi_ {\mathrm {p r o d}}) $$

$$ \mathsf{V C.V e r}(\mathsf{p p},\mathcal{C},I,\vec{y},\pi_{I})=1 $$

As one can see, the expected running time of E is the (expected) time to obtain a successful execution of the protocol plus the running time to obtain ~y plus the running time of E⁰. To obtain ~y it will need to make jIj divisibility checks which takes time O(jIj) plus jIj calls of PrimeGen, which 1( takes poly() time. So overall the expected time is + tE0 + O jIj) + poly() = poly().

$$ \vec{y} $$

$$ \mathcal{E}^{\prime} $$

$$ \ddot{O}(|I|) $$

$$ \vec{y} $$

$$ \frac{1}{\epsilon}+t_{\mathcal{E}{'}}+\tilde{O}(|I|)+\mathsf{p o l y}(\lambda)=\mathsf{p o l y}(\lambda) $$

Non-interactive PoKOpen. A non-interactive version of the protocol PoKOpen after applying the generalized Fiat-Shamir transform [BCS16] is shortly presented below:

PoKOpen*:* P(crs*;* (C;I); (~y;I))! : Parse crs := (G*;g;g₀;g₁;PrimeGen;U*n), C := (fA;Bg;prod), I:= (I*;I). Compute (aI;bI) PartndPrimeProd(I;~y) and then uIPrimeProd(I) and uI UIg. Finally compute a proofPoProdPoProd : P((G;g*); (A;B;UI;I;I); (aI;bI)).

$$ \mathsf{P}(\mathsf{c r s},(\mathcal{C},I),(\vec{y},\pi_{I}))\to\pi; $$

$$ \mathtt{c r s}:{=};(\mathbb{G},g,g_{0},g_{1},\mathsf{P r i m e G e n},U_{n}),;C:{=};({A,B},\pi_{\mathsf{p r o d}}) $$

$$ \pi_{I}\ :=\ (\varGamma_{I},\varDelta_{I}) $$

$$ (a_{I},b_{I});\leftarrow;\mathsf{P a r t n d P r i m e P r o d}(I,\vec{y}) $$

$$ u_{I}\leftarrow{mathsf P r r i p}d({\cal I}) $$

$$ U_{I}\gets g^{u_{I}} $$

$$ \pi_ {\mathrm {P o P r o d} ^ {}} \leftarrow \mathrm {P o P r o d} ^ {}. \mathrm {P} \left(\left(\mathbb {G}, g\right), \left(A, B, U _ {I}, \Gamma_ {I}, \Delta_ {I}\right), \left(a _ {I}, b _ {I}\right)\right) $$


Return (I;I;PoProd)

$$ \pi\gets(\varGamma_{I},\varDelta_{I},\pi_{\mathsf{P}{0}\mathsf{P}{\mathsf{r o d}^{*}}}) $$

PoKOpen*:* V(crs*;* (C;I);PoProd)! b: Parse crs := (G*;g;g₀;g₁;PrimeGen;U*n), C := (fA;Bg;prod) uI and := (I;I;PoProd). Compute uIPrimeProd(I) and then UIg. Return 1 if both PoProd₂*:* V(crs*;* (A B;Un);prod) and

$$ \mathrm {V} \left(\operatorname {c r s}, (C, I), \pi_ {\mathrm {P o P r o d} ^ {*}}\right)\rightarrow b $$

$$ \mathsf{c r s}:=(\mathbb{G},g,g_{0},g_{1} $$

$$ U_{n}),,\mathcal{C}:=({A,B},\pi_{\mathsf{p r o d}}) $$

$$ \pi:=(\varGamma_{I},\varDelta_{I},\pi_{\mathsf{P}{0}\mathsf{P}{\mathsf{P r}0\mathsf{d}^{*}}}) $$

$$ U_{I}\gets g^{u_{I}} $$

$$ \text {b o t h} \mathrm {P o P r o d} _ {2}. \mathrm {V} (\mathrm {c r s}, (A \cdot B, U _ {n}), \pi_ {\mathrm {p r o d}}) $$

PoProd : V((G*;g*); (A;B;I;I;UI);PoProd) output 1, and 0 otherwise.

$$ \mathsf{P o P r o d}^{}.\mathsf{V}((\mathbb{G},g),(A,B,\varGamma_{I},\varDelta_{I},U_{I}),\pi_{\mathsf{P o P r o d}^{}}) $$

Remark 6.1(Achieving sub-linear verication time). For ease of exposition we presented the case of k = 1 in the above. For the case of arbitrary k one should prove knowledge of (aIj;bIj) such VaVb k Ij k Ij aIjbIjuI that = Aj= B ^ g = UI, where UIg and uIPrimeProd(I). Using j=1 Ij j=1 Ij the same technique as above the size of the AoK is O(k) (as is the commitment and the opening proof). However, since the UIis the same for each j, the verication is done in O(jIj=k+ k) time. p p Interestingly, if k = jIj the verication time gets O( jIj), which is sublinear in the size of the opening. Essentially, in cases where the opening queries are (approximately) xed, one can trade a p larger commitment size O( jIj) in order to achieve an argument of knowledge of subvectors that p has sublinear size and sublinear verication time O( jIj).

$$ (a_{I j},b_{I j}) $$

$$ \bigwedge_{j=1}^{k}\varGamma_{I j}^{a_{I j}}=A_{j}\bigwedge_{j=1}^{k}\varDelta_{I j}^{b_{I j}}=B\wedge g^{a_{I j}\cdot b_{I j}}=U_{I} $$

$$ U_{I}\leftarrow g^{u_{I}} $$

$$ u_{I}\gets\mathsf{P r i m e P r d}(I) $$

$$ O(k) $$

$$ U_{I} $$

$$ j $$

$$ k=\sqrt{|left|I|} $$

$$ O\big(|I|/k!+!\lambda!\cdot!k\big) $$

$$ O(\sqrt{|I|}) $$

$$ O(\sqrt{|I|}) $$

$$ O(\sqrt{|I|}) $$

Applications to Compact Proofs of Storage. We observe that the protocol PoKOpen for our VC immediately implies a keyless proof of storage, or more precisely a proof of retrievable commitment (PoRC) [Fis18] with non-black-box extraction. In a nutshell, a PoRC is a proof of retrievability [JK07] of a committed le. In [Fis18] Fisch denes PoRC and proposes a construction based on vector commitments { called VC-PoRC { which abstracts away a classical proof of retrievability based on Merkle trees. A bit more in detail, in the VC-PoRC scheme the prover uses a VC to commit to a le (seen as a vector of blocks); then at every audit the verier chooses a challenge by picking a set ofposrandomly chosen positions I = fi $ [n]g, and the prover responds by sending the subvector ~vIand an openingI. Hereposis a statistical parameter that governs the probability of catching an adversary that deletes (or corrupts) a fraction of the le. For example, if the le is rst encoded using an erasure code with constant rate (i.e., one where a-fraction of 1 blocks suces to decode and such that the encoded le has size roughly jF j), then an erasing adversary has probability at mostposof passing an audit.

$$ I,=,{i\leftarrow,[n]} $$

$$ \lambda_{\mathsf{p o s}} $$

$$ \pi I $$

$$ {vec v,}_I $$

$$ \lambda_{\mathsf{p o s}} $$

$$ \mu $$

$$ \mu^{-1}\cdot|F|) $$

$$ \mu^{\lambda_{\mathsf{p o s}}} $$

Our PoRC scheme is obtained by modifying the VC-PoRC of [Fis18] in such a way that the VC opening is replaced by a PoKOpen AoK. This change saves the cost of sending theposvector values, which gives us proofs of xed size, 7 elements of G and 2 values of Z₂2. As drawback, our scheme is not black-box extractable; strictly speaking, this means it is not a PoR in the sense of 19 [JK07] since the extractor does not exist in the real world.

$$ \lambda_{\mathsf{p o s}} $$

$$ \mathbb{Z}_{2^{2}\lambda} $$

We note that another solution with xed-size proofs can be achieved by using a SNARK to prove knowledge of the VC openings so that the VC-PoRC verier would accept. For the Merkle tree VC, this means proving knowledge ofposMerkle tree openings, which amounts to proving 20 correctness of aboutposlogn hash computations. On a le of 2 bits with 128 spot-checks, this solution would reduce proof size from 80KB to less than 1KB. But its concrete proving costs are high (more than 20 minutes and hundreds of GB of RAM).

$$ \lambda_{\mathsf{p o s}} $$

$$ \lambda_{\mathsf{p o s}} $$

$$ 2^{20} $$

In contrast we can estimate our AoK to be generated in less than 20 seconds and of size roughly 2KB.

19 + The notion of PoR with non-black-box extractability is close to that of robust proof of data possession [ABC 07, + ABC 11].

$$ \mathrm{[A B C^{+}07.} $$

$$ \mathrm{A B C^{+}11} $$


Since our PoRC scheme is a straightforward modication of Fisch’s VC-PoRC construction, a complete description is omitted. We stress that our technical contribution here is the design of the AoK.

Finally, we note that we can apply the observation of the previous remark in order to also achieve verication time sub-linear in the size jIj of the challenged subvector at the expense of p slightly larger commitments (of size jIj).

$$ \sqrt{|I|}) $$

6.3 An AoK for commitments with common subvector

We note that a simple AND composition of two PoKOpen arguments of knowledge on two dierent vector commitments can serve as a protocol proving knowledge of a common subvector of the two vectors committed. More specically given two vector commitments, C₁;C₂ on two dierent vector v₁;v₂ respectively, one can prove knowledge of a common subvector ~vIwith a succinct (constant sized) argument without having to send the actual subvector. The two commitments should share the same CRS crs VC*:* Setup(1*; M*) though they can have distinct specialized CRSs crsn1and crsn2respectively (i.e., ~v₁ and ~v₂ may have dierent length). The underlying relation is:

$$ \vec{v}{1},\vec{v}{2} $$

$$ C_{1},C_{2} $$

$$ {\vec{v}}_{I} $$

$$ \leftarrow\ {mathsf V C C}u t{\mathsf{u p}}(1^{\lambda},{\mathcal{M}}) $$

$$ \mathsf{c r s}{n{1}} $$

$$ (\mathrm{i.e.,\ \vec{v}}_{1} $$

$$ \mathsf{c r S}{n{2}} $$

$$ \ {\vec{v}}_{2} $$

$$ \begin{aligned}{R_{\mathsf{P o K C o m S u b}}={&}{}}{{}&{{}(\ C_{1},C_{2},I),(\vec{v}{I},\pi{I,1},\pi_{I,2})\ :\mathsf{V C}\mathsf{V e r}^{}(\mathsf{c r s}{n{1}},C_{1},I,\vec{v}{I},\pi{I,1})=1}\ {}&{{}\wedge\mathsf{V C}\mathsf{V e r}^{}(\mathsf{c r s}{n{2}},C_{2},I,\vec{v}{I},\pi{I,2})=1}}\ \end{aligned} $$

As mentioned above, it is straightforward to show that an AND composition of PoKOpen on dierent vector commitments C₁ and C₂ is a protocol for the above relation. That is the prover, holdingI;1:= (I;1;I;1) andI;2:= (I;2;I;2), rst sendsI;1;I;2to the verier and then aIbI aIbIaI provides an argument of knowledge of (aI;bI) such that = A₁^ = B₁ ^ g = UI^ = I;1 I;1 I;2 bI uI A₂ ^ = B₂, where UIg and uIPrimeProd(I). I;2

$$ C_{1} $$

$$ C_{2} $$

$$ \pi_ {I, 1} := \left(\Gamma_ {I, 1}, \Delta_ {I, 1}\right) $$

$$ \pi_{I,2}:=\big(\varGamma_{I,2},\varDelta_{I,2}\big) $$

$$ \pi_{I,1},\pi_{I,2} $$

$$ (a_{I},b_{I}) $$

$$ A_{2}\wedge\varDelta_{I,2}^{b_{I}}=B_{2} $$

$$ U_{I}\leftarrow g^{u_{I}} $$

$$ u_{I}\gets\mathsf{P r i m e P r o d}(I) $$

6.4 A Succinct AoK for Commitment on Subvector

Here we present a protocol which succinctly proves that a commitment C⁰ opens to an I-subvector ~vIof the opening ~v of another commitment C. Since C⁰ is a vector commitment ~vIshould be a normal vector instead of a general subvector, i.e. I should be a set of consecutive positions starting from 1, I = f1*;:::;n⁰g* for some n⁰ 2 N. We note though that both commitments should share the same crs (but not the same specialized CRS). Below is the relation of the AoK that is parametrized by the two specialized CRSs crsnVC*:* Specialize(crs*;n*) and crsn0 VC*:* Specialize(crs*;n⁰*) where crs VC*:* Setup(1*; M*) is common.

$$ \vec{v} $$

$$ C^{\prime} $$

$$ {\vec{v}}_{I} $$

$$ C^{\prime} $$

$$ {vec v,}_I $$

$$ I={1,\ldots,n^{\prime}} $$

$$ n^{\prime}\in\mathbb{N} $$

$$ C s s_{n}\leftarrow V C.S p e c i d i l e(c r s,n) $$

$$ \ s_{n^{\prime}}\leftarrow V C.S p e c i d l i z e(c r s,n^{\prime}) $$

$$ \mathsf{c r s}\leftarrow\mathsf{V C}.\mathsf{S e t u p}(1^{\lambda},\mathcal{M}) $$

$$ \begin{aligned}{R_{\mathsf{P o K S u b V}}=\ }&{{}({\ (C,C^{\prime},I),(\vec{v}{I},\pi{I},\pi_{I}^{\prime})}):{\mathsf{V C}}.\mathsf{V e r}^{}(\mathsf{c r s}{n},C,I,\vec{v}{I},\pi_{I})=1}\ {}&{{}\wedge{mathsf{V C}V e r}^{}(\mathsf{c r s}{n^{\prime}},C^{\prime},I,\vec{v}{I},\pi_{I}^{\prime})=1\wedge|\vec{v}_{I}|=n^{\prime}}}\ \end{aligned} $$

The idea of our protocol is that since the opening ~vIis the I-subvector of ~v one can provide a succinct proof of knowledge of the opening at these positions using the PoKOpen protocol presented above. However this is not enough as one should bind the opening proof with C⁰. This concretely can happen if one embeds a proof of product for the two components, A⁰ and B⁰, of C⁰ inside the proof of opening. More specically the prover provides an opening proofI:= (I;I) then computes aI 0 bI 0 aIbIaI (aI;bI) PartndPrimeProd(I;~vI) and proves that g₀ = A ^ g₁ = B ^ Un0 = g ^ = I bI A ^ = B. Notice that the last three equalities correspond to the proof of opening protocol I

$$ {\vec{v}}_{I} $$

$$ \vec{v} $$

$$ C^{\prime} $$

$$ B^{\prime} $$

$$ \pi_{I}:=\left(\varGamma_{I},\varDelta_{I}\right) $$

$$ C^{\prime} $$

$$ (a_{I},b_{I});\leftarrow;\mathsf{P a r t n d P r i m e P r o d}(I,\vec{v}_{I}) $$

$$ g_{0}^{a_{I}}:=:A^{\prime}{\ \wedge\ }g_{1}^{b_{I}}:=:B^{\prime}{\ \wedge\ }U_{n^{\prime}}:=:g^{a_{I}\cdot b_{I}}{\ \wedge\ }\varGamma_{I}^{a_{I}}:= $$

$$ A\wedge\varDelta_{I}^{b_{I}},=,B $$ and the rst three to the proof of product. So a conjunction of PoKOpen and PoProd protocol is sucient. Lastly g;g₀;g₁ and Un0 are part of crsn0 and (A;B), (A⁰;B⁰) part of the C and C⁰ commitments respectively.

$$ g,g_{0},g_{1} $$

$$ U_{n^{\prime}} $$

$$ \mathsf{c r s}_{n^{\prime}} $$

$$ (A,B),,(A^{\prime},B^{\prime}) $$

$$ C^{\prime} $$

Fig. 6. PoKSubV protocol

Prover input: ((crsn;crsn0); (C;C⁰;I); (~vI;I). Verier input: ((crsn;crsn0); (C;C⁰;I)).

P! V: I := ( I;I)

A conjuction of PoProd and PoKOpen protocols between P(crsn;crsn0; (C;C⁰;I); (~vI;I)) and V(crsn;crsn0; (C;C⁰;I))

is executed: V! P: h $ G aI bI P! V: z := (za;zb) computed as za h;zbh V! P: ‘ $ Primes() and $ [0*;* 2) 0A 0B P! V: := ((QA;QB;Q;Q;QC);ra;rb) computed as follows { (qa;qb;qab) (baI=‘c; bbI=‘c; baI bI=‘c) { (ra;rb) (aI mod ‘;bI mod ‘) qa qb qa q qb qab { (QA0;QB0;QA;QB;QC) := (*g₀;g₁;*Iqah;Ibh;g)

V: Parse crsn := (G*;g;g₀;g₁;PrimeGen;Un*), crsn0:= (G*;g;g₀;g₁;PrimeGen;U*n0) and C := (*fA;Bg;*prod).

{ Compute rc ra rbmod ‘

‘ ra ‘ rb ‘ ra ‘ r rb ‘ rc { Output 1 i ra;rb2 [‘] ^ QA0g₀ = A⁰ ^ QB0g₁ = B⁰ ^ QA Irah = Aza^ QB Ibh = Bzb^ QCg =

Un0 ^ PoProd₂: V(pp; (A B;Un);prod)

$$ \left((\mathsf{c r s}{n},\mathsf{c r s}{n^{\prime}}),(C,C^{\prime},I)\right) $$

$$ (big(\mathsf{c r s}{n},\mathsf{c r s}{n^{\prime}}\big),(\mathcal{C},\mathcal{C}^{\prime},I),(\vec{v}{I},\pi{I}\big) $$

$$ \underline{{\mathsf{P}\to\mathbb{V}}}:\pi_{I}:=\left(\varGamma_{I},\varDelta_{I}\right) $$

$$ \mathsf{V}(\mathsf{c r s}{n},\mathsf{c r s}{n^{\prime}},(C,C^{\prime},I)) $$

$$ {\sf P}({\sf c r s}{n},{\sf c r s}{n^{\prime}},({\mathcal C C},{\mathcal C}^{\prime},I),(\vec{v}{I},\pi{I})) $$

$$ {\underline{{\mathsf{V}}}}\to{\mathsf{P}}\colon h\leftarrow\ \ \ \ \ \ $$

$$ z_{a}\leftarrow h^{a_{I}},z_{b}\leftarrow h^{b_{I}} $$

$$ \underline {{\mathrm {P} \rightarrow \mathrm {V}}}: z := \left(z _ {a}, z _ {b}\right) $$

$$ \underline{{\mathsf{{V}}}}\to\mathsf{{P}}:\ell\leftarrow\sharp\mathsf{{P r i m e s}}(\lambda) $$

$$ \alpha\leftarrow\ [,2^{\lambda}) $$

$$ \underline {{\mathrm {P} \rightarrow \mathrm {V}}}: \pi := \left(\left(Q _ {A}, Q _ {B}, Q _ {A} ^ {\prime}, Q _ {B} ^ {\prime}, Q _ {C}\right), r _ {a}, r _ {b}\right) $$

$$ -\ {q_{a},q_{b},q_{a b}})\leftarrow(\lfloor a{a_I}\mathord\rfloor/\lfloor{b_{I}\ \ell}\rfloor,\lfloor{a_{I}b_{I}/\ell}\rfloor) $$

$$ -\ \big(r_{a},r_{b}\big)\leftarrow\big(a_{I} $$

$$ -\ (Q_{A^{\prime}},Q_{B^{\prime}},Q_{A},Q_{B},Q_{C}):=(g_{0}^{q_{\alpha}},g_{1}^{q_{b}},\varGamma_{I}^{q_{\alpha}}h^{\alpha q_{\alpha}},\varDelta_{I}^{q_{b}}h^{\alpha q_{b}},g^{q_{a b}}) $$

$$ \mathsf{Y}{!}\ \mathsf{P a r n e}\ \mathsf{e r n}{n}:=(\mathsf{G},g,g_{0},g_{1},\mathsf{P r i m e G e n},U_{n}),\ \mathsf{e r n}{n^{\prime}}:=(\mathsf{G},g,g{0},g_{1},\mathsf{P r i m e G e n},U_{n^{\prime}})\ \operatorname{a n d}\ C:=({A,B},\pi_{\pi\neq\ } $$

$$ r_{c}\leftarrow r_{a}\cdot r_{b} $$

$$ -\ {\mathrm{O u t p a t1i f}}r_{a},r_{b}\in[\ell]{,\wedge,\ },,Q_{A^{\prime}}^{\ell}g_{5}^{r_{5}}=A^{\prime}{,\wedge,},Q{B^{\prime}}^{}g_{1}^{r_{5}}=B^{\prime}{,\wedge,\ ,}Q_{A}^{\ell}I_{I}^{r_{5}}h^{_{7}}_a={,A,},\wedge,,,,,,, $$

$$ U_{n^{\prime}}\land\mathsf P_r o o\mathsf{r o d_{2}}\ V(\mathsf p\ ,(A\cdot B,U_{n}),\pi_{\mathfrak p00}) $$

We state the following theorem for the security of the protocol above.

Theorem 6.3. If PoProd and PoKOpen are succinct arguments of knowledge for RPoProdand RPoKOpen, then protocol PoKSubV in Fig.6is a succinct argument of knowledge for relation RPoKSubV with respect to algorithm VC*:* Ver of our construction of Section5.1.

$$ R_{\mathsf{P o P r o d^{*}}} $$

$$ R_{\mathsf P o o Q O p n} $$

$$ R_{\mathsf P o o K S u b V} $$

The intuition of the proof is that one proves knowledge of an opening I for C, namely that ~vI is an I-subvector of C, where (aI;bI) PartndPrimeProd(I;~vI), with a normal proof of subvector ? opening. This is equivalent to VC*:* Ver (crsn;C;I;~vI;I) = 1. Then in the same proof proves that the accumulators of C⁰ are composed by the same (aI;bI) which results to proving that C⁰ commits ? to ~vI. The last point is equivalent to VC*:* Ver (crsn0;C⁰;I;~vI;) = 1 ^j~vIj = n⁰. I0

$$ \ {vec v}_{I} $$

$$ C $$

$$ (a_{I},b_{I})\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\vec{v}_{I}) $$

$$ \mathrm {V C}. \operatorname {V e r} ^ {\star} \left(\mathrm {c r s} _ {n}, C, I, \vec {v} _ {I}, \pi_ {I}\right) = 1 $$

$$ C^{\prime} $$

$$ (a_{I},b_{I}) $$

$$ C^{\prime} $$

$$ \vec{v}_{I} $$

$$ \mathsf{V C}V_{}{\mathsf{V e r}}^{\star}(\mathsf{c r s}{n^{\prime}},C^{\prime},I,\vec{v}{I},\pi_{I}^{\prime})=1\wedge|\vec{v}_{I}|=n^{\prime} $$

7 Veriable Decentralized Storage

In this section we introduce veriable decentralized storage (VDS). We recall that in VDS there are two types of parties (called nodes): the generic client nodes and the more specialized storage nodes (a storage node can also act as a client node). The main goal of client nodes is to retrieve some blocks (i.e., a portion) of a given le. The role of a storage node is instead to store a portion of a le (or more les) and to answer to the retrieval queries of clients that are relevant to the portion it stores. In terms of security, VDS guarantees that malicious storage nodes cannot send to the clients blocks of the le that have been tampered with.

We refer the reader to Section1.2for a discussion on the motivation and requirements of VDS. In Table2we summarize the main roles/capabilities of VDS nodes.


ALL PARTICIPATING NODES
STORAGE NODES
Store current digest.
Can retrieve blocks of the file and verify responses.
Can aggregate proofs they received.
Can update the digest following updates from other nodes Store a portion of the file.
Can answer and certify retrievals of subportions.
Can produce and publish updates to their view.
Can apply updates from other nodes efficiently.

Table 2. Roles in a decentralized veriable database.

7.1 Syntax

Here we introduce the syntax of VDS. A VDS scheme is dened by a collection of algorithms that are to be executed by either storage nodes or client nodes. The only exception is the Bootstrap algorithm that is used to bootstrap the entire system and is assumed to be executed by a trusted party, or to be implemented in a distributed fashion (which is easy if it is public coin).

The syntax of VDS reects its goal: guaranteeing data integrity in a highly dynamic and decentralized setting (the le can change and expend/shrink often and no single node stores it all). In VDS we create both parameters and an initial commitment for an empty le at the beginning (through the probabilistic Bootstrap algorithm, which requires a trusted execution). From then on this commitment is changed through incremental updates (of arbitrary size). Updating is divided in two parts. A node can carry out an update it and \push" it to all the other nodes, i.e. providing auxiliary information (that we call \update hint") other nodes can use to update their local certicates (if aected by the change) and a new digest²⁰. These operations are done respectively trough StrgNode*:* PushUpdate and StrgNode*:* ApplyUpdate. Opening and verifying are where VC (with incremental aggregation) and VDS share the same mechanism. To respond to a query, a storage node can produce (possibly partial) proofs of opening, nodes can use algorithm StrgNode*:* Retrieve. If these proofs needs to be aggregated, any node can use algorithm AggregateCerticates. Anyone can verify a proof through ClntNode*:* VerRetrieve.

In VDS we model the les to be stored as vectors in some message space M (e.g., M = f0*;* 1g ‘ or f0*;* 1g), i.e., F = (F₁*;:::;*FN). Given a le F, we dene a portion of it as a pair (*I;*FI) where FI is essentially the I-subvector of F.

$$ {0,1}^{\ell}),\ \mathrm{i.e.,}\ \mathsf{F}=\left(\mathsf{F}{1},\dots,\mathsf{F}{N}\right) $$

$$ (\mathrm{e.g.},,\mathcal{M}={0,1} $$

$$ (I,\mathsf{F}_{I}) $$

$$ \ {mathsf F}_{I} $$

Denition 7.1(Veriable Decentralized Storage).

Algorithm to bootstrap the system:

Bootstrap(1 )! (pp*;0;st₀) Given the security parameter, the probabilistic bootstrap algorithm outputs public parameters pp, initial digest*0and state st₀*.*0and st₀ correspond to the digest and storage node’s local state respectively for an empty le.

$$ {\mathsf{B o o t s t r a p}}(1^{\lambda})\to({\mathsf{p p}},\delta_{0},{\mathsf{s t}}_{0}) $$

All the algorithms below implicitly take as input the public parameters pp*.*

The algorithms for storage nodes are:

StrgNode*:* AddStorage(;n; st*;I;FI;Q;FQ;Q)!* (st⁰*;J;FJ) This algorithm allows a storage node to add more blocks of a given le F to its local storage. Its rst inputs are the local view of the storage node that is dened by a digest, a length n, a state st, and a le portion* (I;FI). Then it takes

$$ (\delta,n,\mathsf{s t},I,\mathsf{F}{I},Q,\mathsf{F}{Q},\pi_{Q})\to(\mathsf{s t}^{\prime},J,\mathsf{F}_{J}) $$

$$ n, $$

$$ (I,\mathsf{F}_{I}) $$

20 One can also see this update hint as a certicate to check that a new digest is consistent with some changes. This issue does not arise in our context as all but the Bootstrap algorithms are deterministic.


as input a le subportion (Q;FQ) together with a valid retrieval certicateQ. The output is an updated view of the storage node, that is a new state st⁰ and le portion (*J;*FJ) := (I;FI)[(Q;FQ). Note that this algorithm can be used to enable anyone who holds a valid retrieval certicate for a le portion FQto become a storage node of such portion.

$$ (Q,\mathsf{F}_{Q}) $$

$$ \pi_{Q} $$

$$ \left(J,\mathsf{F}{J}\right):=\left(I,\mathsf{F}{I}\right){\cup}(Q(,,\mathsf{F}_{Q}) $$

$$ \mathrm {F} _ {Q} $$

StrgNode*:* RmvStorage(;n; st*;I;FI;K*)! (st⁰*;J;FJ) This algorithm allows a storage node to remove blocks of a given le F from its local storage. Its rst inputs are the local view of the storage node that is dened by a digest, a length n, a state st, and a le portion* (I;FI). Then it takes as input a set of positions K I, and the output is an updated view of the storage node, that is a new state st⁰ and le portion (*J;*FJ) := (I;FI) n (K;).

$$ \left(\delta,n,\mathsf{s t},I,\mathsf{F}{I},K\right)\to\left(\mathsf{s t}^{I},J,\mathsf{F}{J}\right) $$

$$ n, $$

$$ (I,\mathsf{F}_{I}) $$

$$ K\subseteq I $$

$$ s mathsf{t}^{\prime} $$

$$ \left(J,\mathsf{F}{J}\right):=\left(I,\mathsf{F}{I}\right)\setminus\left(K,\cdot\right) $$

0 StrgNode*:* CreateFrom(;n; st*;I;FI;J*)! (;n⁰;st⁰;J;FJ;J) This algorithm allows a storage node for a le subportion FIto create a new le containing only a subset FJof FIalong with the 0 corresponding digest and length n⁰ and a hint to help other nodes generate their own digest. The algorithm takes as input the local view of the storage node, i.e., digest, length n, local state 0 st and le portion (I;FI), and a set of indices J I. The algorithm returns a new digest, length n⁰, a local state st⁰*, a le portion* (J;FJ) and an advice. This advice can be used by a 0 client holding only the former digest to obtain the new digest, by using the ClntNode: GetCreate algorithm described below.

$$ (\delta , n, \mathsf {s t}, I, \mathsf {F} _ {I}, J) \rightarrow \left(\delta^ {\prime}, n ^ {\prime}, \mathsf {s t} ^ {\prime}, J, \mathsf {F} _ {J}, \Upsilon_ {J}\right) $$

$$ \mathrm {F} _ {I} $$

$$ \mathrm {F} _ {J} $$

$$ \delta^{\prime} $$

$$ \mathrm {F} _ {I} $$

$$ J\subseteq I $$

$$ (I,\mathsf{F}_{I}) $$

$$ n^{\prime} $$

$$ \delta^{\prime}, $$

$$ (J,\mathsf{F}_{J}) $$

$$ \delta^{\prime} $$

0 0J StrgNode*:* PushUpdate(;n; st*;I;FI;op;)!* (;n⁰;st⁰;J;F;) This algorithm allow a storage node of a le subportion FIto perform an update on the le and to generate a corresponding digest, length and local view, along with a hint other nodes can use to accordingly update their digests and local views. The inputs include the local view of the storage node, i.e., digest, length n, local state st and le portion (I;FI), an update operation op 2fmod*;add;delg and an update description.* 0 0J The outputs are a new digest and length n⁰, a new local state st⁰*, an updated le portion* (J;F) 0K and an update hint. If op = mod, then contains a le portion (K;F) such that K I and 0K 0K F represents the new content to be written in positions K. If op = add, it is also = (K;F) except that K is a set of new (sequential) positions K \ I =; that start from n + 1 (and end to n + jKj). If op = del*, then only contains a set of positions K I, which are the ones to be* deleted (and are ought to be the jKj last sequential positions). The proof can be used by client 0 nodes holding in order to check the validity of the new digest, and by other storage nodes, holding additionally the length n, in order to check the validity of the changes and to update their local views accordingly.

$$ (\delta , n, \mathsf {s t}, I, \mathsf {F} _ {I}, \mathsf {o p}, \Delta) \rightarrow (\delta^ {\prime}, n ^ {\prime}, \mathsf {s t} ^ {\prime}, J, \mathsf {F} _ {J} ^ {\prime}, \Upsilon_ {\Delta}) $$

$$ \mathrm {F} _ {I} $$

$$ (I,\mathsf{F}_{I}) $$

$$ \in{{\mathsf o m d},{\mathsf a d d},{\mathsf d e} $$

$$ \Delta $$

$$ \delta^{\prime} $$

$$ (J,\mathsf{F}_{J}^{\prime}) $$

$$ n^{\prime} $$

$$ s mathsf\ell t^{\prime} $$

$$ Y_{\Delta} $$

$$ K\subseteq I $$

$$ \Delta $$

$$ (K,\mathsf{F}_{K}^{\prime}) $$

$$ F_{K}^{\prime} $$

$$ \varDelta=(K,\mathsf{F}_{K}^{\prime}) $$

$$ \bigcap\cap I=\emptyset $$

$$ n+1 $$

$$ n+|K|) $$

$$ \Delta $$

$$ K\subseteq I $$

$$ |K| $$

$$ T_{\Delta} $$

$$ \delta^{\prime} $$

$$ n, $$

0 0J StrgNode*:* ApplyUpdate(;n; st*;I;FI;op;;)!* (b;;n⁰;st⁰;J;F) This algorithm allows a stor- age node to incorporate changes in a le pushed by another node. The inputs include the local view of the storage node, i.e., digest, length n, local state st and le portion (I;FI), an update operation op 2fmod;add;delg, an update description and an update hint. The algorithm 0 returns a bit b (to accept/reject the update) and (if b = 1*) a new digest, a new length n⁰, a new* 0J (local) state st⁰ and an updated le subportion (J;F). If op 2fmod*;addg we have that J* = I, i.e., the node keeps storing the same indices; if op = del then J is I minus the deleted indices.

$$ (\delta,n,\mathsf{s t},I,\mathsf{F}{I},\mathsf{o p},\varDelta,\varUpsilon{\varDelta})\to(b,\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{J}^{\prime}) $$

$$ (I,\mathsf{F}_{I}) $$

$$ \mathsf{o p}\in $$

$$ \bigtriangleup $$

$$ T_{\Delta} $$

$$ (i f,b=1) $$

$$ \delta^{\prime} $$

$$ (J,\mathsf{F}_{J}^{\prime}) $$

$$ {\mathsf{o p}}\in{{\mathsf{m o d}} $$

$$ n^{\prime} $$

$$ J=I $$

StrgNode*:* Retrieve(;n; st*;I;FI;Q*)! (FQ;Q) This algorithm allows a storage node to answer a retrieval query for blocks with indices in Q and to create a certicate vouching for the correctness of the returned blocks. The inputs include the local view of the storage node, i.e., digest, length n local state st and le portion (I;FI), and a set of indices Q. The output is a le portion FQand a retrieval certicateQ.

$$ (\delta , n, \mathsf {s t}, I, \mathsf {F} _ {I}, Q) \rightarrow (\mathsf {F} _ {Q}, \pi_ {Q}) $$

$$ Q $$

$$ (I,\mathsf{F}_{I}) $$

$$ Q. $$

$$ \pi_{Q} $$

$$ \mathrm {F} _ {Q} $$

The algorithms for clients nodes are:


0 ClntNode*:* GetCreate(;J;J)! (b;) On input a digest, a set of indices J and a creation advice 0 J, this algorithm returns a bit b (to accept/reject) and (if b = 1*) a new digest that corresponds* to a le F⁰ that is the prex with indices J of the le represented by digest.

$$ T_{J} $$

$$ (i f,b=1) $$

$$ \delta^{\prime} $$

0 ClntNode*:* ApplyUpdate(;op;;)! (b;) On input a digest, an update operation op 2 fmod*;add;delg, an update description and an update hint, it returns a bit b (to* 0 accept/reject update) and (if b = 1*) a new digest.*

$$ \mathrm {A p p l y U p d a t e} (\delta , \mathrm {o p}, \Delta , Y _ {\Delta}) \rightarrow (b, \delta^ {\prime}) $$

$$ \textsf{o p}\in $$

$$ \bigtriangleup $$

$$ \delta^{\prime} $$

$$ (i f,b=1) $$

$$ T_{\Delta} $$

ClntNode*:* VerRetrieve(;Q;FQ;Q)! b On input a digest, a le portion (Q;FQ) and a certicate Q, this algorithm accepts (i.e. it outputs 1) only ifQis a valid proof that corresponds to a le F with length n of which FQis the portion corresponding to indices Q.

$$ (left(\delta,Q,\mathsf{F}{Q},\pi{Q})\to b $$

AggregateCerticates(; (I;FI;I); (J;FJ;J))!KOn input a digest and two certicated re- trieval outputs (I;FI;I) and (J;FJ;J), this algorithm aggregates their certicates into a single certicateK(with K := I[J). In a running VDS system, this algorithm can be used by any node to aggregate two (or more) incoming certied data blocks into a single certied data block.

$$ \big(\emptyset,\big(I,\mathsf{F}{I},\pi{I}\big),\big(J,\mathsf{F}{J},\pi{J}\big)\big)\to\pi_{K} $$

$$ (I,\mathsf{F}{I},\pi{I}) $$

$$ (J,\mathsf{F}{J},\pi{J}) $$

$$ \pi_{K} $$

$$ K:=I\cup J, $$

Remark 7.1(On CreateFrom). For completeness, our VDS syntax also includes the functionalitis (StrgNode*:* CreateFrom*;ClntNode:* GetCreate) that allow a storage node to initialize storage (and corresponding digest) for a new le that is a subset of an existing one, and a client node to verify such resulting digest. Although this feature can be interesting in some application scenarios (see the Introduction), we still see it as an extra feature that may or may not be satised by a VDS construction.

7.2 Correctness and Eciency of VDS

Intuitively, we say that a VDS scheme is ecient if running VDS has a \small" overhead in terms of the storage required by all the nodes and the bandwidth to transmit certicates. More formally, a VDS scheme is said ecient if there is a xed polynomial p( ) such that p(;logn) (with the security parameter and n the length of the le) is a bound for all certicates and advices generated by the VDS algorithms as well as for digests and the local state st of storage nodes. Note that combining this bound with the requirement that all algorithms are polynomial time in their input, we also get that no VDS algorithm can run linearly in the size of the le (except in the trivial case that the le is processed in one shot, e.g., in the rst StrgNode*:* AddStorage).

$$ p(\lambda,\log n) $$

Eciency essentially models that running VDS is cost-eective for all the nodes in the sense that it does not require them to store signicantly more data then they would have to store without. Notice that by requiring certicates to have a xed size implies that they do not grow with aggregation.

For correctness, intuitively speaking, we want that for any (valid) evolution of the system in which the VDS algorithms are honestly executed we get that any storage node storing a portion of a le F can successfully convince a client holding a digest of F about retrieval of any portion of F. And such (intuitive notion of) correctness is also preserved when updates, aggregations, or creations of new les are done.

Turning this intuition into a formal correctness denition turned out to be nontrivial. This is due to the distributed nature of this primitive and the fact that there could be many possible ways in which, at the time of answering a retrieval query, a storage node may have reached its state starting from the empty node state. The basic idea of our denition is that an empty node is \valid", and then any \valid" storage node that runs StrgNode*:* PushUpdate \transfers" such validity to both itself and to other nodes that apply such update. A bit more precisely, we model \validity"


as the ability to correctly certify retrievals of any subsets of the stored portion. A formal denition correctness follows. To begin with, we dene the notion of validity for the view of a storage node.

Denition 7.2(Validity of storage node’s view). Let pp be public parameters as generated by Bootstrap*. We say that a local view* (;n; st*;I;*FI) of a storage node is valid if 8Q I:

$$ (\delta,n,\mathsf{s t},I,\mathsf{F}_{I}) $$

$$ i f#Q\subseteq I. $$

$$ \mathsf{C I n t N o d e.V e r R e t r i e v e}(\delta,Q,\mathsf{F}{Q},\pi{Q})=\mathtt{1} $$

where (FQ;Q) StrgNode*:* Retrieve(;n; st*;I;FI;Q*)

$$ :(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},Q) $$

Remark 7.2. By Denition7.2the output of a bootstrapping algorithm (pp*;0;st₀) Bootstrap(1 ) is always such that (pp;0;* 0*;st₀;;;;*) is valid. This provides a \base case" for Denition7.4.

$$ (\mathsf{p p},\delta_{0},\mathsf{s t}_{0})\leftarrow\mathsf{B o o t s t a p}(1^{\lambda}) $$

$$ (\mathsf{p p},\delta_{0},0,\mathsf{s t}_{0},\emptyset,\emptyset) $$

Second, we dene the notion of admissible update, which intuitively models when a given update can be meaningfully processed, locally, by a storage node.

Denition 7.3(Admissible Update). An update (op*;*) is admissible for (*n;I;*FI) if:

$$ (mathsf o o p,\varDelta) $$

0K 0K { for op = mod*, K I and j*F j = jKj, where := (K;F).

$$ {\it f o r}\left(n,I,\mathsf{F}_{I}\right),j $$

$$ K\subseteq I $$

$$ |\mathsf{F}_{K}^{\prime}|=|K| $$

$$ \varDelta:=(K,\mathsf{F}_{K}^{\prime}) $$

0K 0K { for op = add*, K \ I* =; and jF j = jKj and K = fn+1*;n*+2*;:::;n*+jKjg, where := (K;F). { for op = del*, K I and K* = fn jKj + 1*;:::;ng, where* := K.

$$ \left|\mathbb{F}_{K}^{\prime}\right|=\left|K\right| $$

$$ \varDelta:=(K,\mathsf{F}_{K}^{\prime}) $$

$$

In words, the above denition formalizes that: to push a modication at positions K, the storage node must store those positions; to push an addition, the new positions K must extend the currently stored length of the le; to push a deletion of position K, the storage node must store data of the positions to be deleted and those positions must also be the last jKj positions of the currently stored le (i.e., the le length is reduced).

Denition 7.4(Correctness of VDS). A VDS scheme VDS is correct if for all honestly gen- erated parameters (pp*;0;st₀) Bootstrap(1 ) and any storage node’s local view (;n;* st*;I;*FI) that is valid, the following conditions hold.

$$ (\mathfrak{p p},\delta_{0},\mathfrak{s t}_{0})\leftarrow\mathsf{B o o t s t r p p}(1^{\lambda}) $$

$$ (\delta,n,\mathsf{s t},I,\mathsf{F}_{I}) $$

0 Update Correctness. For any update (op*;) that is admissible for (n;I;FI) and for any (;n⁰; 0J st⁰;J;F;) StrgNode:* PushUpdate(;n; st*;I;FI;op;):*

$$ (mathsf o o p,\varDelta) $$

$$ (n,I,\mathsf{F}_{I}) $$

$$ (\delta^{\prime},n^{\prime} $$

$$ \mathrm {s t} ^ {\prime}, J, \mathrm {F} _ {J} ^ {\prime}, \gamma_ {\Delta}) \leftarrow \operatorname {S t r g} $$

$$ (\delta,n,\ \ {mathsf s}\mathsf{t},I,\mathsf{F}_{I},\ {\mathsf{o p}},\varDelta) $$

0 0J 1. (pp*;;n⁰;st⁰;J;*F) is valid;

$$ (\mathsf{p p},\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{I}^{\prime}) $$

0s 0s 2.for any valid (;n; sts;Is; FIs), if (bs;s0;n⁰;st;Is0; F) StrgNode*:* ApplyUpdate(;n; sts;Is; FIs;op; 0 0s 0s 0s 0s ;) then we have: bs= 1*,s0=, n* = n⁰, and (s0;n;st;Is0; F) is valid; 0 3.if (bc;c0) ClntNode*:* ApplyUpdate(;op;;), thenc0= and bc= 1*.*

$$ \left(\delta , n, \mathrm {s t} _ {s}, I _ {s}, \mathrm {F} _ {I _ {s}}\right), i f \left(b _ {s}, \delta_ {s} ^ {\prime}, n ^ {\prime}, \mathrm {s t} _ {s} ^ {\prime}, I _ {s} ^ {\prime}, \mathrm {F} _ {s} ^ {\prime}\right) \leftarrow \operatorname {S t r g N o d e}. \operatorname {A p p l y U p d a t e} \left(\delta , n, \mathrm {s t} _ {s}, I _ {s}, \mathrm {F} _ {I _ {s}}, \mathrm {o p},\right. $$

$$ \varDelta,Y_{\varDelta}) $$

$$ b_{s}=1,,\delta_{s}^{\prime}=\delta^{\prime},,n_{s}^{\prime}=n^{\prime} $$

$$ \boldsymbol{\cdot}(\delta,\mathsf{o p},\varDelta,\varUpsilon_{\varDelta}) $$

$$ \delta_{c}^{\prime}=\delta^{\prime} $$

$$ b_{c}=1 $$

Add-Storage Correctness. For any (Q;FQ;Q) such that

$$ (Q,\mathsf{F}{Q},\pi{Q}) $$

ClntNode*:* VerRetrieve(;Q;FQ;Q) = 1*, if* (st⁰*;J;FJ) StrgNode:* AddStorage(;st;I;F;Q;FQ;Q) then (;n; st⁰*;J;*FJ) is valid.

$$ (\delta,Q,\mathsf{F}{Q},\pi{Q}):=:1,::\mathit{i f}:(\mathsf{s t}^{\prime},J,\mathsf{F}_{J}):\leftarrow:\mathsf{S t r} $$

$$ (\delta,n,\mathsf{s t}^{\prime},J,\mathsf{F}_{J}) $$

$$ K\subseteq I, $$

Remove-Storage Correctness. For any K I,

if (st⁰*;J;FJ) StrgNode:* RmvStorage(;st;I;F;K) then (;n; st⁰*;J;*FJ) is valid.

$$ (\delta,n,\mathsf{s t}^{\prime},J,\mathsf{F}_{J}) $$

$$ J\subseteq I,,i f\left(\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}}{J},\mathsf{\check{T}}{J}\right) $$

0 Create Correctness. For any J I, if (;n⁰;st⁰;J;FJ;J) is output of

$$ \mathsf{r o m}(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},J) $$

$$ |J|,,\delta^{\prime\prime}=\delta^{\prime} $$

00 StrgNode*:* CreateFrom(;n; st*;I;FI;J*) and (b;) ClntNode*:* GetCreate(;J;J), then b = 1*, n⁰* = 00 0 0 jJ j, = and (pp*;;n⁰;st⁰;J;*FJ) is valid.

$$ (b,\delta^{\prime\prime}):\leftarrow:\mathsf{C I n t N o d e}.\mathsf{G e t C r e a t e}(\delta,J,\varUpsilon_{J}) $$

$$ n^{\prime}= $$

$$ (\mathsf{p p},\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{J}) $$

Aggregate Correctness. For any pair of triples (I;FI;I) and (J;FJ;J) such that

$$ (I,\mathsf{F}{I},\pi{I}) $$

$$ (J,\mathsf{F}{J},\pi{J}) $$

ClntNode: VerRetrieve(;I;FI;I) = 1 and ClntNode: VerRetrieve(;J;FJ;J) = 1, ifKAggregateCerticates((I;FI;I); (J;FJ;J)) and (K;FK) := (I;FI) [ (J;FJ), then ClntNode: VerRetrieve(;K;FK;K) = 1*.*

$$ \left{\left(\delta,I,\mathsf{F}{I},\pi{I}\right)=1\ \ \right. $$

$$ \sharp(\delta,J,\mathsf{F}{J},\pi{J})=1 $$

$$ {{}^{}},\pi_{K}\leftarrow{\sf A g g r e g a t e} $$

$$ \mathsf{s}\big((I,\mathsf{F}{I},\pi{I}),(J,\mathsf{F}{J},\pi{J})\big) $$

$$ \left(K,\mathsf{F}{K}\right):=\left(I,\mathsf{F}{I}\right)\cup\left(J,\mathsf{F}_{J}\right) $$

$$ \left(\delta,K,\mathsf{F}{K},\pi{K}\right)=1 $$


Remark 7.3(Relation with Updatable VCs). Our notion of VDS is very close to the notion of updatable VCs [CF13] extended to support subvector openings and incremental aggregation. On a syntactical level, in comparison to updatable VCs, our VDS notion makes more evident the decentralized nature of the primitive, which is reected in the denition of our algorithms where for example it is clear that no one ever needs to store/know the entire le. One major dierence is that in VDS the public parameters must necessarily be short since no node can run linearly in the size of the le (nor it can aord such storage), whereas in VCs this may not be necessarily the case. Another dierence is that in updatable VCs [CF13] updates can be received without any hint, which is instead the case in VDS. Finally, it is interesting to note that, as of today, there exists no VC scheme that is updatable, incrementally aggregatable and with subvector openings, that enjoys short parameters and has the required short verication time. So, in a way, our two VDS realizations show how to bypass this barrier of updatable VC by moving to a slightly dierent (and practically motivated) model.

7.3 Security of VDS

In this section we dene the security of VDS schemes. Intuitively speaking, we require that a malicious storage node (or a coalition of them) cannot convince a client of a false data block in a retrieval query. To formalize this, we let the adversary fully choose a history of the VDS system that starts from the empty state and consists of a sequence of steps, where each step is either an update (addition, deletion, modication) or a creation (from an existing le) and is accompanied by an advice. A client’s digest is updated following such history and using the adversarial advices, and similarly one gets a le F corresponding to such digest. At this point, the adversary’s goal is to provide a tuple (Q;Q; F) that is accepted by a client with digest but where F 6= FQ. Q Q

$$ \mathsf{F}{Q}^{*}\neq\mathsf{F}{Q} $$

$$ (Q,\pi_{Q},\mathsf{F}_{Q}^{*}) $$

Denition 7.5(History for Decentralized Storage). Let VDS be a veriable decentralized i i i i storage scheme. A history for VDS is a sequence H = (op*;;)i2[‘]of tuples, where op is either i in fmod;add;delg (i.e., it is an update of the le), or* op = cfrom (i.e., it is the creation of a new i le related to the current one), in which case is a set of indices. In order to dene valid histories we dene the function EvalHistory(pp*;0;st₀; H*) as follows

EvalHistory(pp;0;st₀; H) F₀ ;; b 1 for i 2 [‘] i i Fi FileChange(Fi 1*;op;) i if op 2fmod;add;delg* then

FileChange(F;op;) 0K if op 2fmod*;addg parse* = (K;F) 0i 8i 2 K : FiF;8i 2 [jFj] n K : FiFi; elseif op = del parse = K 8i 2 [jFj] n K : FiFi;

i i i elseif op = cfrom parse = K (bi;i) ClntNode*:* ApplyUpdate( i 1*;op;;*)

i elseif op = cfrom then i i (bi*;i) ClntNode:* GetCreate( i 1*;;) endif b b ^ bi endfor return (b;‘; F‘*)

8i 2 K : FiFi; endif return F

We say that a history H is valid w.r.t. public parameters pp and initial digest0and state st₀ if EvalHistory(pp*;0;st₀; H*) returns bit b = 1*.*

$$ \mathcal{H}=(\mathfrak{o p}^{i},\varDelta^{i},\varUpsilon_{\varDelta}^{i})_{i\in[\ell]} $$

$$ \mathbf{o p}^{i} $$

$$ {\mathsf{o p p}}^{i}= $$

$$ \Delta^{i} $$

$$ (\mathsf{p p},\delta_{0},\mathsf{s t}_{0},\mathcal{H}) $$

$$ \mathsf{F}_{0}\leftarrow\emptyset;b\leftarrow1 $$

$$ (\mathsf{F},{\mathsf{o p}},\varDelta) $$

$$ i\in[\ell] $$

$$ \mathsf{o p}\in\left{\mathsf{m o d},\mathsf{a d d}\right}\mathrm{p a r s e}\varDelta=(K,\mathsf{F}_{K}^{\prime}) $$

$$ \mathsf{F}{i}\leftarrow\mathsf{F i l e C h a n g e}(\mathsf{F}{i-1},\mathfrak{o p}^{i},\varDelta^{i}) $$

$$ \forall i\in K:\mathsf{F}{i}^{*}\leftarrow\mathsf{F}{i}^{\prime};\forall i\in[[\mathsf{F}]]\setminus K:\mathsf{F}{i}^{*}\leftarrow\mathsf{F}{i}, $$

$$ \mathsf{o p}^{i}\in{\mathsf{m o d},\mathsf{a d d},\mathsf{d e l}} $$

$$ \varDelta=K $$

$$ \forall i\in[\mathsf{F}]\setminus K:\mathsf{F}{i}^{*}\leftarrow\mathsf{F}{i}, $$

$$ (\delta_{i-1},\mathsf{o p}^{i},\varDelta^{i},\varUpsilon_{\varDelta}^{i}) $$

$$ \forall i\in K:\mathsf{F}{i}^{*}\leftarrow\mathsf{F}{i}, $$

$$ (b_{i},\delta_{i})\leftarrow\mathsf{C l n t N o d e.G e t C r e a t e}(\delta_{i-1},\varDelta^{i},\varUpsilon_{\varDelta}^{i}) $$

$$ \ {\sf F}^{*} $$

$$ b\gets b\land b_{i} $$

$$ (b,\delta_{\ell},\mathsf{F}_{\ell}) $$

$$ \delta_{0} $$

$$ {\sf S}{\sf t}_{0} $$

$$ (\mathsf{p p},\delta_{0},\mathsf{s t}_{0},\mathcal{H}) $$


Denition 7.6(Security for Veriable Decentralized Storage). Consider the experiment A VDS*-SecurityVDS() below. Then we say that a VDS scheme VDS is secure if for all PPT A we A have Pr[VDS-SecurityVDS() = 1] 2 negl().*

$$ \operatorname{P r}[\sf{V D S\ S e e c u r i t y}_{\sf{D S}}^{\cal{A}}(\lambda)=1]\in\sf{n e g l}(\lambda) $$

A VDS-SecurityVDS() (pp*;0;st₀) Bootstrap(1) (H;Q;FQ;) A (pp;0;st₀) (b;; F) EvalHistory(pp;0;st₀; H*) b b ^ FQ6= FQ^ ClntNode*:* VerRetrieve(pp*;;Q;FQ;*) return b

$$ b\gets b\land\mathsf{F}{Q}^{*}\neq\mathsf{F}{Q}\land $$

VDS Proof of Storage. As an additional security mechanism we consider the possibility to ensure a client that a given le is stored by the network at a certain point of time without having to retrieve it. To this end, we extend the VDS notion to provide a proof of storage mechanism in + the form of a proof of retrievability (PoR) [JK07] or a proof of data possession (PDP) [ABC 07]. Our proof of storage model for VDS is such that proofs are publicly veriable given the le’s digest. Also, in order to support the decentralized and open nature of DSNs, the entire proof mechanism should not use any secret, and proofs should be generatable in a distributed fashion (this is a main distinguishing feature compared to existing PoRs/PDPs) while staying compact. The formalization of this property is in AppendixD.

$$ [\mathrm{A B C}^{+}07] $$

8 Our Realizations of VDS in Hidden-Order Groups

In this section, we present two constructions of VDS that work in hidden-order groups. The two schemes are presented in Sections8.1and8.2respectively, and we discuss a comparison in Section 8.3.

8.1 Our First VDS Construction

We build our rst scheme by extending the techniques used to construct our rst SVC scheme from Section5.1. In particular, we start from a modied version of our SVC that achieves a weaker position binding property (in which the adversary reveals the full vector, yet its goal is to nd two distinct openings for the same position) and then show how to make this scheme dynamic (i.e., to change vector values or its length) and fully distributed (i.e., updates can be performed without knowing the entire vector).

Preliminaries. We begin by describing the simplied version of our SVC, considering the case of k = 1, which ts best our VDS construction, regarding eciency and communication complexity. For convenience of the reader we describe again shortly the algorithms and functions (and variations of them) from sections5.1and5.1that are used in the scheme (for more details we refer to the corresponding section):

{ PrimeGen, a deterministic collision resistant function that maps integers to primes.

{ PartndPrimeProd(I;~y)! (aI;bI): given a set of indices I = fi₁;:::;img [n] and a vector Q Q m m m ~y 2M, the function computes (aI;bI) := pi; pi, where piPrimeGen(i) l=1: yl=0 l l=1: yl=1 l for all i 2 N.

$$ \ I,\vec{y},\rightarrow,(a_{I},b_{I}) $$

$$ I,=,\left{i_{1},\ldots,i_{m}\right},\subseteq,[n] $$

$$ \vec{y}\in\mathcal{M}^{m} $$

$$ (left\ a_{I},b_{I}):=(\prod_{l=1:y_{l}=0}^{m}p_{i_{l}},\prod_{l=1:y_{l}=1}^{m}p_{i_{l}}) $$

$$ p_{i}\gets\mathsf{P r i m e G e n}(i) $$

$$ i\in\mathbb{N} $$


VC*:* Com⁰(crs*;v*)! C compute (a;b) PartndPrimeProd([n]*;v*), where n j~vj; next compute A = a b? g₀ and B = g₁. Return C := (C;n) := ((A;B); j~vj).

$$ \ {{{\sf~t e t u p}}({{\sf^{\lambda}}},{0,1}^{k})}\to{{\sf r r s}};:=({{\mathbb G}},g,g_{0},g_{1},{{{\sf P r P m e e e n}}}) $$

$$ .mathsf C C o^{{\prime}}(\mathsf{c r s},{\vec{v}})\to C $$

$$ n\gets|\vec{v}|. $$

$$ (a,b)\leftarrow\mathsf{P a t n d P r n n e P o d d}([n],\vec{v}) $$

$$ A= $$

$$ g_{0}^{a} $$

$$ B=g_{1}^{b} $$

$$ \mathcal{C}:=\left(\mathcal{C}^{\star},n\right):=\left((A,B),\left|\vec{v}\right|\right) $$

VC*:* Ver⁰(crs*;C;I;y;I)! b* compute (aI;bI) PartndPrimeProd(*I;y*), and then parseI:= (I;I) aIbI and return b ( = A) ^ ( = B). I I

$$ (a_{I},b_{I})\leftarrow\sf P a I t n d P r m e P r o d(I,\vec{y}) $$

$$ \pi_ {I} := \left(\Gamma_ {I}, \Delta_ {I}\right) $$

VC*:* Disagg⁰(crs*;I;v*I;I;K)!Klet L := I n K, and *v*Lbe the subvector of ~vIat positions in L. Then compute aL;bLPartndPrimeProd(L;~vL) parseI:= (I;I) and set (K;K) aLbL (;). ReturnK(K;K). I I VC: Agg⁰(crs; (I;v;); (J;v;))! :

$$ b\gets\big(\ \ Gamma_{I}^{a_{I}}=A\big)\wedge\big(\Delta_{I}^{b_{I}}=B\big) $$

$$ \mathrm {V C}. \operatorname {D i s a g g} ^ {\prime} (\mathrm {c r s}, I, \vec {v} _ {I}, \pi_ {I}, K) \rightarrow \pi_ {K} \text {l e t} L := I \setminus K $$

$$ {\vec{v}}_{L} $$

$$ \ {\vec{v}}_{I} $$

$$ L. $$

$$ a_{L},b_{L}\gets $$

$$ (L,\vec{v}_{L}) $$

$$ \pi_{I}:=,(\varGamma_{I},\varDelta_{I}) $$

$$ (\varGamma_{K},\varDelta_{K})\leftarrow $$

$$ (\varGamma_{I}^{a_{L}},\varDelta_{I}^{b_{L}}) $$

$$ \pi_{K}\leftarrow(\varGamma_{K},\varDelta_{K}) $$

$$ \ .{\sf A g g}^{\prime}({\sf c r s},(I,\vec{v}{I},\pi{I}),(J,\vec{v}{J},\pi{J}))\to\pi_{K} $$

1.Let L := I \J. If L 6=;, set I⁰ := I nL and computeI0 VC*:* Disagg(crs*;I;~vI;I;I⁰*); otherwise letI0 =I.

$$ L:=I\cap J $$

$$ L\neq\emptyset $$

$$ I^{\prime}!:=I\backslash!L $$

$$ \pi_{I^{\prime}}\gets V\ .mathsf C i D s a g e(\mathsf{c r s},I,\vec{v}{I},\pi{I},I^{\prime}) $$

$$ \pi_{I^{\prime}}=\pi_{I} $$

$$ (I,\vec{v}_{I^{\prime}}) $$

2.Compute (aI0;bI0) PartndPrimeProd(I;~vI0) and faJ;bJg PartndPrimeProd(J;~vJ).

$$ {a_{J},b_{J}}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(J,\vec{v}_{J}) $$

3.ParseI0 := (I0;I0),J:= (J;J) and computeKShamirTrick(I0;J;aI0;aJ) and KShamirTrick(I0;J;bI0;bJ)

$$ \pi_{I^{\prime}}:=(\varGamma_{I^{\prime}},\varDelta_{I^{\prime}}),\pi_{J}:=(\varGamma_{J},\varDelta_{J}) $$

$$ \varGamma_{K}\leftarrow\mathbf{S h a m i r T r i c k}(\varGamma_{I^{\prime}},\varGamma_{J},a_{I^{\prime}},a_{J}) $$

$$ (\varDelta_{I^{\prime}},\varDelta_{J},b_{I^{\prime}},b_{J}) $$

$$ \pi_{K}\leftarrow(big var_Gamma K,\varDelta_{K} $$

4.ReturnK(K;K)

Finally, let PoKSubV⁰ be the same protocol as in section6but adjusted according to the above algorithms. That is the CRS of is simply crs instead of the two specialized CRSs. Furthermore, since C is not accompanied with PoProd₂ the verier does not have to check the validity of it. The rest of the protocol remains the same and the underlying relation is:

$$ \mathsf{P o P r o d}_{2} $$

$$ \begin{aligned}{R_{\mathsf{P o k S u b V}^{\prime}}={(}&{{}\ C,C^{\prime},I),(\vec{v}{I},\pi{I},\pi_{I}^{\prime})\ :\ \ \ {\sf V C,N e r^{\prime}}(\mathsf{c r s},C,I,\vec{v}{I},\pi{I})=1}\ {}&{{}\wedge\ \ {\sf V C,V e r^{\prime}}(\mathsf{c r s s},C^{\prime},I,\vec{v}{I},\pi{I}^{\prime})=1\wedge|\vec{v}_{I}|=n^{\prime}}}\ \end{aligned} $$

Finally, we note that for simplicity in the following we abuse the notation for Shamir’s trick 0I a0b0 by writing e.g. (;) ShamirTrick(I;K; FI; FK)K; ShamirTrick(I;K; FI; FK)K I0 instead of writing, more precisely,

$$ (\varGamma_{}^{\prime},\varDelta_{\ I}^{\prime});\leftarrow;(\mathbf{S h a m i r T r i c k}(\varGamma_{I},\varGamma_{K},\mathsf{F}{I},\mathsf{F}{K})^{a_{K}^{\prime}}} $$

$$ \ \cdot $$

$$ \left(\Gamma_ {I} ^ {\prime}, \Delta_ {I} ^ {\prime}\right) \leftarrow \left(\mathbf {S h a m i r T rick} \left(\Gamma_ {I}, \Gamma_ {K}, a _ {I}, a _ {K}\right) ^ {a _ {K} ^ {\prime}}, \mathbf {S h a m i r T rick} \left(\Delta_ {I}, \Delta_ {K}, b _ {I}, b _ {K}\right) ^ {b _ {K} ^ {\prime}}\right). $$

21 Our scheme VDS₁. The algorithms of the VDS scheme VDS₁ are the following:

$$ \mathsf{V D S_{1}} $$

$$ \mathsf{V D S_{1}} $$

k Bootstrap(1 )! (pp*;0;n₀;st₀)Execute VC:* Setup(1*; f0;* 1g) and get pp := (G*;g;g₀;g₁;PrimeGen). Set n₀ 0,0((g₀;g₁);n₀*) and st₀ (g₀;g₁).

$$ {\mathsf{r a p}}(1^{\lambda})\to({\mathsf{p p}},\delta_{0},n_{0},{\mathsf{s t}}_{0}) $$

$$ \mathsf{V C.S e t u p}(1^{\lambda},{0,1}^{k}) $$

$$ {\mathfrak{p p}}:=({\mathfrak{G}},{\mathfrak{g}},{\mathfrak{g}}{0},{\mathfrak{g}}{1},{\sf{P r i m e G e n}}) $$

$$ n_{0}\leftarrow0,\delta_{0}\leftarrow((g_{0},g_{1}),n_{0}) $$

$$ \mathsf{s t}{0}\leftarrow(g{0},g_{1}) $$

The algorithms for storage nodes are:

StrgNode*:* AddStorage(;n; st*;I;FI;Q;FQ;Q)!* (st⁰*;J;FJ)If I =;* then set st⁰Q, otherwise st :=I. Then compute st⁰ VC*:* Agg⁰(pp*;* (I;FI;I); (Q;FQ;Q)). The computation of J and FJ is straightforward: (*J;*FJ) (I [ Q;FI[ FQ).

$$ \ \cdot $$

$$ {mathfrak s t t}^{\prime}\leftarrow\pi_{Q} $$

$$ \mathsf{s t}:=\pi_{I} $$

$$ I=\emptyset $$

$$ \mathrm {s} ^ {\prime} \leftarrow \mathrm {V C}. \mathrm {A g g} ^ {\prime} (\mathrm {p p}, (I, \mathrm {F} _ {I}, \pi_ {I}) , (Q, \mathrm {F} _ {Q}, \pi_ {Q})) $$

$$ (J,\mathsf{F}{J})\leftarrow(I\cup Q,\mathsf{F}{I}\cup\mathsf{F}_{Q}) $$

$$ \mathrm {F} _ {J} $$

$$ J\gets,I\setminus K $$

StrgNode*:* RmvStorage(;n; st*;I;FI;K*)! (st⁰*;J;FJ)Compute J I n K and the corresponding FJ. ThenJVC:* Disagg⁰(pp*;I;FI;I;J*) and set st⁰J.

$$ \digamma J $$

$$ \pi_{J}\gets V\ .mathsf.D i s a\mathsf{g o}^{I}(\mathsf{p p},I,\mathsf{F}{I},\pi{I},J) $$

$$ smathfrak{t}^{\prime}\leftarrow\pi_{J} $$

21 Since the scheme has several parts in common with the above VC algorithms, we use those algorithms as shorthands in the description.


0 0 StrgNode*:* CreateFrom(;n; st*;I;FI;J*)! (;n⁰;st⁰;J;FJ;J)The new digest of FJis computed 0 with the commitment algorithm VC*:* Com⁰(pp*;* FJ). The new length gets n⁰ j J j. The previous local state is st =Iand the new local state gets st⁰ VC*:* Disagg(pp*;I;FI;I;J*). Finally, forJit computes an argument of knowledge of subvector (see section6), 0 PoKSubV 0 0 PoKSubV⁰*:* P(pp*;* (;;J); (~vJ;I)) and setsJ(; 0). PoKSubV

$$ (\delta,n,\mathsf{s t},I,\mathsf{F}{I},J)\to(\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}{J},\varUpsilon_{J}) $$

$$ \delta^{\prime} $$

$$ \mathrm {F} _ {J} $$

$$ \delta^{\prime}\leftarrow\mathsf{V C.C o m^{\prime}(p p,F_{J})} $$

$$ \boldsymbol{n}^{\prime}\gets|\boldsymbol{J}| $$

$$ {\mathfrak{s t}},=,\pi_{I} $$

$$ \mathsf{s t}^{\prime};\leftarrow;\mathsf{V C}D i s a g g(\mathsf{p p},I,\mathsf{F}{I},\pi{I},J) $$

$$ T_{J} $$

$$ \pi_{\mathsf{P o K S u b V}^{\prime}}\xleftarrow{{}} $$

$$ \varUpsilon_{J}\gets(\delta^{\prime},\pi_{\mathsf{P o K S u b V}^{\prime}}) $$

0 0J StrgNode*:* PushUpdate(;n; st*;I;FI;op;)!* (;n⁰;st⁰;J;F;)The algorithm works according to the type of update operation op:

$$ .\mathsf{P u s h U p d a t e}(\delta,n,\mathsf{s t},I,\mathsf{F}{I},\mathsf{o p},\varDelta)\to(\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}{J}^{\prime},\varUpsilon_{\varDelta}) $$

0K { op = mod: parse := (K;F) and st :=I. ExecuteKVC: Disagg⁰(pp*;I;FI;I;K*) 0K 0K 0K 0 and parseK:= (K;K). Then compute (a;b) PartndPrimeProd(K;F) and set a0b0 K K 0 0 ((;);n) (i.e., n = n remains the same). st is the new opening of I,I, which K K I0 is the same so the local state does not change st⁰ st. Since it is a modication operation 0J 0I 0I 0I 0K (*J;*F) (I;F), where F is simply the modied le F = (FIn FK) [ F. Finally, set (FK;K).

$$ -{\mathrm{\ o}}{\mathrm{,,}}{=\mathrm{\ m o d}} $$

$$ \varDelta,:=,(K,\mathsf{F}_{K}^{\prime}) $$

$$ :=\ \pi_{I} $$

$$ \pi_{K};\leftarrow;\mathsf{V C}.\mathsf{D i s a g g}^{\prime}(\mathsf{p p},I,\mathsf{F}{I},\pi{I},K) $$

$$ \pi_ {K} := \left(\Gamma_ {K}, \Delta_ {K}\right) $$

$$ (K,\mathsf{F}_{K}^{\prime}) $$

$$ \delta^{\prime}\leftarrow $$

$$ ((\varGamma_{K}^{a_{K}^{\prime}},\varDelta_{K}^{b_{K}^{\prime}}),n)\ (\mathrm{i.e.,,},,n^{\prime}=,n $$

$$ s mathsf t{{'}} $$

$$ I,,\pi_{I}^{\prime}\leftarrow\pi_{I} $$

$$ \ {mathfrak s t}^{\prime}\leftarrow{\mathfrak s t} $$

$$ (J,\mathsf{F}{J}^{\prime})\leftarrow(I,\mathsf{F}{I}^{\prime}) $$

$$ (\mathsf{F}{K},\pi{K}) $$

$$ {\mathsf{F}}{I}^{\prime}=({\mathsf{F}}{I}\setminus{\mathsf{F}}{K})\cup{\mathsf{F}}{K}^{\prime} $$

$$ \mathrm {F} _ {I} ^ {\prime} $$

$$ T_{\varDelta}\leftarrow $$

0K { op = add: parse := (K;F), st :=I, and the old digest := ((A;B);n). Then compute 0K 0K 0K 0 a0b00 0 (a;b) PartndPrimeProd(K;F) and the new digest gets ((AK;BK);n) where n 0J 0 n + jKj. The new state refers to the new le subportion (*J;*F) (I [ K;FI[ FK), st⁰ :=, J 0 and is the same as the old one st⁰ st sinceI=. Finally, set?. J

$$ \varDelta:=(K,\mathsf{F}_{K}^{\prime}) $$

$$ :=,\pi_{I} $$

$$ \delta:=((A,B),n) $$

$$ (a_{K}^{\prime},b_{K}^{\prime})\leftarrow\mathsf{P a r t n d P r i m e P r o d}(K,\mathsf{F}_{K}^{\prime}) $$

$$ \delta^{\prime}\leftarrow((A^{a_{K}^{\prime}},B^{b_{K}^{\prime}}),n^{\prime}) $$

$$ n^{\prime}\gets $$

$$ n+|K| $$

$$ (J,\mathsf{F}{,J}^{\prime});\leftarrow;(I\cup K,\mathsf{F}{,I}\cup\mathsf{F}{K}),;\mathsf{s t}^{\prime}:=\pi{,J}^{\prime}, $$

$$ \pi_{I}=\pi_{,J}^{\prime} $$

$$ T_{\Delta}\gets\otimes $$

$$ \mathsf{s t}^{\prime}\gets\mathsf{s t} $$

{ op = del: parse := K and st :=I. ExecuteKVC*:* Disagg⁰(pp*;I;FI;I;K*) and parse 0 K:= (K*;K). Then the new digest is ((K;K);n⁰*) where n⁰ n jKj. The new 0J state refers to the new le subportion (*J;*F) (I n K;FIn FK)) and is the same as the old one 0 st⁰ st sinceI=. Finally set (FK;K). J

$$ -\circ!, $$

$$ \varDelta:=K $$

$$ :=\ \pi_{I} $$

$$ \pi_{K}\leftarrow\mathsf{V C.D i s a g g}^{\prime}(\mathsf{p p},I,\mathsf{F}{I},\pi{I},K) $$

$$ \pi_{K}:=\big(\varGamma_{K},\varDelta_{K}\big) $$

$$ \boldsymbol{\delta}^{\prime}\gets((\boldsymbol{\Gamma}{K},\boldsymbol{\Delta}{K}),n^{\prime}) $$

$$ n^{\prime}\leftarrow n-|K| $$

$$ (J,\mathsf{F}{J}^{\prime})\leftarrow(I\setminus K,\mathsf{F}{I}\setminus\mathsf{F}_{K}), $$

$$ \mathsf{s t}^{\prime}\leftarrow\mathsf{s t} $$

$$ \pi_{I}=\pi_{J}^{\prime} $$

$$ \varUpsilon_{\varDelta}\gets\left(\mathsf{F}{K},\pi{K}\right) $$

0 0J StrgNode*:* ApplyUpdate(;n; st*;I;FI;op;;)!* (*b;;n⁰;st⁰;J;*F)Again, it works according to the type of update operation op:

0K { op = mod: parse := (K;F), st :=Iand := (FK;K). Compute acceptance bit 0K 0K b VC*:* Ver⁰(pp*;;K;FK;K). Then, if b = 1 parseK:= (K;K), compute (a;b) a0b0 0K 0 K K 0 0 PartndPrimeProd(K;F) and set ((;);n*) where n n. It is clear that in the case K K 0J 0I 0I 0I 0K of a modify operation (*J;*F) (I;F), where F is simply the modied le F = (FIn FK) [ F. For the new local state st⁰ that we discern three cases: I\K =;: then compute

$$ \varDelta,:=,(K,\mathsf{F}_{K}^{\prime}) $$

$$ :=\ \pi_{I} $$

$$ \gamma_ {\Delta} := \left(\mathrm {F} _ {K}, \pi_ {K}\right) $$

$$ b,=,1 $$

$$ b\gets\mathsf{V C.V e r^{\prime}}(\mathsf{p p},\emptyset,K,\mathsf{F}{K},\pi{K}) $$

$$ \pi_{K},:=,\big(\varGamma_{K},\varDelta_{K}\big) $$

$$ (a_{K}^{\prime},b_{K}^{\prime})\leftarrow $$

$$ (K,\mathsf{F}_{K}^{\prime}) $$

$$ \delta^{\prime}\gets((\varGamma_{K}^{a_{K}^{\prime}},\varDelta_{K}^{b_{K}^{\prime}}),n^{\prime}) $$

$$ n^{\prime}\gets n $$

$$ (J,\mathsf{F}{J}^{\prime})\leftarrow(I,\mathsf{F}{I}^{\prime}) $$

$$ \ {\sf F^{\prime}} $$

$$ {\mathsf{F}}{I}^{\prime}=\big({\mathsf{F}}{I}\backslash{\mathsf{F}}{K}\big){\cup}{\mathsf{F}}{K}^{\prime} $$

$$ s mathsf{t}^{\prime} $$

$$ I\cap K=\emptyset: $$

0I a0b00 (;) ShamirTrick(I;K; FI; FK)K; ShamirTrick(I;K; FI; FK)Kand set st I0 0 0 0 := (;). I I I

$$ (T_{I}^{\prime},\varDelta_{I}^{\prime})\leftarrow $$

$$ (\varGamma_{I},\varGamma_{K},\mathsf{F}{I},\mathsf{F}{K})^{a_{K}^{\prime}} $$

$$ \left(\varDelta_{I},\varDelta_{K},\mathsf F_{I},\mathsf F_{K})^{b_{K}^{\prime}}\right) $$

$$ \mathsf{s t^{\prime}\ }leftarrow $$

$$ \pi_{I}^{\prime}:=(\varGamma_{I}^{\prime},\varDelta_{I}^{\prime}) $$

$$ (\varGamma_{I}^{\prime},\varDelta_{I}^{\prime})\leftarrow(\varGamma_{I},\varDelta_{I}) $$

$$ I\cap K=K $$

0I 0I I\K = K: compute (;) (I;I) and set st⁰ := (;). I0 I0 I0

$$ \mathsf{s t}^{\prime}\leftarrow\pi_{I}^{\prime}:=(\varGamma_{I}^{\prime},\varDelta_{I}^{\prime}) $$

For the case where neither I\K =; nor I\K = K, i.e. I\K = L =2fK;;g we partition K as K = L[L and apply two sequential updates toI, one with L⁰ (s.t. I\L =;) 0L 0L 0L and one with L (s.t. I \ L = L). That is, compute (a;b) PartndPrimeProd(L;F) and then a0b0 0IL L00 (;) ShamirTrick(I;L; FI; FL); ShamirTrick(I;L; FI; FL). Then (;) I0 I00 I 0I 00 (;). Finally, set st⁰ (;). Essentially, since the case of I \ L = L doesn’t cause any I0 I00 I change to the state, computationally it is as a single update.

$$ I\cap K=\emptyset $$

$$ I\cap K=L\notin{K,\emptyset} $$

$$ I\cap K=K $$

$$ K=L\cup\bar{L} $$

$$ L ^ {\prime} \left(\mathrm {s . t .} I \cap \bar {L} = \emptyset\right) $$

$$ \pi\ I $$

$$ L,{\mathrm{(s.t.}},I\ \ \cap L=L $$

$$ \big(a_{\bar{L}}^{\prime},b_{\bar{L}}^{\prime}\big)\leftarrow\mathsf{P a r t n d P r i m e P r o d}(\bar{L},\mathsf{F}_{\bar{L}}^{\prime}) $$

$$ (T_{I}^{\prime\prime},\varDelta_{I}^{\prime\prime})\xleftarrow{} $$

$$ \cdot(\varDelta_{I},\varDelta_{\bar{L}},\mathsf F_{I},\mathsf F_{\bar{L}})^{b_{\bar{L}}^{\prime}}\Big) $$

$$ (\varGamma_{I}^{\prime},\varDelta_{I}^{\prime}) $$

$$ \mathsf{t}^{\prime}\gets(\varGamma_{I}^{\prime\prime},\varDelta_{I}^{\prime\prime}) $$

$$ \ \ (\varGamma_{I}^{\prime},\varDelta_{I}^{\prime})\leftarrow\big(\mathtt{S h a m i r T r i c k}(\varGamma_{I},\varGamma_{\bar{L}},\mathsf{F}{I},\mathsf{F}{\bar{L}})^{a_{\bar{L}}^{\prime}} $$

$$ I\cap L=L $$

$$ \varDelta:=(K,\mathsf{F}_{K}^{\prime}) $$

0K { op = add: parse := (K;F), st :=Iand the old digest as := ((A;B);n). Set b = 1 i 0K 0K 0K K = fn + 1*;:::;n* + jKjg. Then if b = 1 compute (a;b) PartndPrimeProd(K;F) and the 0 a0b00 0 new digest becomes ((AK;BK);n) where n n + jKj. For the new local state, rst a0b0 0 K K parse the old one st :=I:= (I;I) and the new one gets st where (;). I0 I0 I I 0J Finally set (*J;*F) (*I;*FI), i.e., the le remains unchanged.

$$ :=\pi_{I} $$

$$ \delta:=((A,B),n) $$

$$ K=\left{n+1,\ldots,n+\left|K\right|\right} $$

$$ b=1 $$

$$ b=1 $$

$$ (a_{K}^{\prime},b_{K}^{\prime})\leftarrow $$

$$ \delta^{\prime},\dot{\leftarrow},((A^{a_{K}^{\prime}},B^{b_{K}^{\prime}}),n^{\prime}) $$

$$ (K,\mathsf{F}_{K}^{\prime}) $$

$$ n^{\prime}\leftarrow n+|K| $$

$$ \mathfrak{I}:=\pi_{I}:=\left(\varGamma_{I},\varDelta_{I}\right) $$

$$ \mathsf{s t}^{\prime}\gets\pi_{I}^{\prime} $$

$$ \pi_{I}^{\prime}\leftarrow(\varGamma_{I}^{a_{K}^{\prime}},\varDelta_{I}^{b_{K}^{\prime}}) $$

$$ (J,\mathsf{F}{J}^{\prime})\leftarrow(I,\mathsf{F}{I}) $$


{ op = del: parse := K, st :=I, and := (FK;K). Set b = 1 i K = fn jKj + 1*;:::;ng^* 0 VC*:* Ver⁰(pp*;;K;FK;K) = 1. Then if b = 1 sets ((K;K);n⁰*) where n⁰ n jKj. For the new local state, similarly to the modify operation, we discern three cases. If I \ K =; then 0I (;) (ShamirTrick(I;K; FI; FK); ShamirTrick(I;K; FI; FK)) and set st⁰K:= I0 0I (;); else if I\K = K st⁰ = st, else if I\K = L then (let L = K n L) I0 0I (;) (ShamirTrick(I;L; FI; FL); ShamirTrick(I;L; FI; FL)) and set st⁰I:= I0 0I 0J (;) (similarly to the op = mod case). Finally (*J;*F) (*I n L;*FIn FL). I0

$$ \varUpsilon_{\varDelta}:=(\mathsf{F}{K},\pi{K}) $$

$$ \varDelta:=K $$

$$ \tilde{K}=\left{n-\left|\tilde{K}\right|!+!,\ 1,,\ldots,n\right}\Lambda $$

$$ b=1 $$

$$ {=}\pi_{I} $$

$$ \delta^{\prime}\gets((\varGamma_{K},\varDelta_{K}),n^{\prime}) $$

$$ b=1 $$

$$ \mathsf{V C.V e r}^{\prime}(\mathsf{p p},\delta,K,\mathsf{F}{K},\pi{K})=1 $$

$$ n^{\prime}\leftarrow n-|K| $$

$$ I\cap K=\emptyset $$

$$ (\varGamma_{I}^{\prime},\varDelta_{I}^{\prime})\leftarrow $$

$$ (Gamma_{I},\varGamma_{K},\mathsf F{{}}{I},\mathsf F{K}) $$

$$ \varDelta_{I},\varDelta_{K},\mathsf F_{I},\mathsf F_{K}), $$

$$ \mathsf{s t}^{\prime}\leftarrow\pi_{K}:= $$

$$ I\cap K=K;{\mathsf{s t}}^{\prime}={\mathsf{s t}} $$

$$ (\varGamma_{I}^{\prime},\varDelta_{I}^{\prime}) $$

$$ I\cap K=L $$

$$ \bar{L}=K\setminus L) $$

$$ (T_{I}^{\prime},\varDelta_{I}^{\prime})\leftarrow $$

$$ (\varGamma_{I},\varGamma_{\bar{L}},\mathsf F_{I},\mathsf F_{\bar{L}}) $$

$$ (\varGamma_{I}^{\prime},\varDelta_{I}^{\prime}) $$

$$ (\varDelta_{I},\varDelta_{\bar{L}},\mathsf F{{}}{I},\mathsf F{\bar{L}})) $$

$$ (J,\mathsf{F}{J}^{\prime})\gets(I\setminus L,\mathsf{F}{I}\setminus\mathsf{F}_{L}) $$

$$ \mathsf{s t}^{\prime}\leftarrow\pi_{I}:= $$

StrgNode*:* Retrieve(;n; st*;I;FI;Q*)! (FQ;Q)Compute both portion FQFIas well as proof 0 QVC*:* Disagg (pp*;I;FI;st;Q*).

$$ (\delta,n,\mathsf{s t},I,\mathsf{F}{I},Q)\to(\mathsf{F}{Q},\pi_{Q}) $$

$$ \mathsf{F}{Q}\subseteq\mathsf{F}{I} $$

$$ \pi_{Q}\leftarrow\mathsf{V C.D i s a g g}^{\prime}(\mathsf{p p},I,\mathsf{F}_{I},\mathsf{s t},Q). $$

The algorithms for client nodes are:

0 0 ClntNode*:* GetCreate(;J;J)! (b;)ParseJ:= (; 0), set n⁰ = jJ j and output b PoKSubV 0 0 PoKSubV⁰*:* V(pp*;* (;;J);J) ^ J = f1*;:::; jJ jg* and.

$$ \ {sf L I t t N o d e.G e t C r e a t e}(\delta,J,\varUpsilon_{J})\to(b,\delta^{\prime}) $$

$$ \ {itUpsilon}{J},:=,(\delta^{\prime},\pi{\sf P o K S u b V^{\prime}}) $$

$$ n^{\prime},=,|J| $$

$$ b\leftarrow $$

$$ \mathsf{P o K S u b V^{\prime}.V}(\mathsf{p p},(\delta,\delta^{\prime},J),\pi_{J})\wedge J={1,\dots,|J|} $$

$$ \delta^{\prime} $$

ClntNode*:* VerRetrieve(;Q;FQ;Q)! b Output b VC*:* Ver⁰(pp*;;Q;FQ;*Q)

$$ \left(\delta,Q,\mathsf{F}{Q},\pi{Q}\right)\to b $$

0 ClntNode*:* ApplyUpdate(;op;;)! (b;)This algorithm is almost identical to the rst part of the Storage Node algorithm StrgNode*:* ApplyUpdate(;n; st*;I;FI;op;;*). The dierence is that it executes only the parts that are related to the output of b and.

$$ (\delta,{\mathfrak{o p}},\varDelta,\varUpsilon_{\varDelta}right)\to(b,\delta^{\prime}) $$

$$ (\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, \mathrm {o p}, \Delta , Y _ {\Delta}) $$

AggregateCerticates(; (I;FI;I); (J;FJ;J))!K

$$ \left(\emptyset,(I,\mathsf{F}{I},\pi{I}),(J,\mathsf{F}{J},\pi{J})\right)\to\pi_{K} $$

ReturnKVC*:* Agg⁰(pp*;* (I; ~FI;I); (J; ~FJ;J)).

$$ \pi_{K}\leftarrow\mathsf{V C.A g g}^{\prime}(\mathsf{p p},(I,\mathsf{F}{I},\pi{I}),(J,\mathsf{F}{J},\pi{J})). $$

Correctness. Here we state and prove the correctness of VDS₁.

$$ \mathsf{V D S}_{1} $$

Theorem 8.1. The scheme VDS₁ presented above is a correct veriable decentralized storage scheme.

$$ \mathsf{V D S}_{1} $$

? Proof In the following we will always assume that st := (st₁*;st₂) and := (;n*) := ((1;2);n). Furthermore, whenever (aI;bI) appear, we assume that they are the outputs of PartndPrimeProd(I;FI), for each set of indices I. Finally for each set of indices I we assumeI:= (I;I).

$$ \delta:=\left(\delta^{\star},n\right):=\left((\delta_{1},\delta_{2}),n\right) $$

$$ :=(\mathsf{s t}{1},\mathsf{s t}{2}) $$

$$ (a_{I},b_{I}) $$

$$ |(I,\mathsf{F}_{I}) $$

$$ \pi_ {I} := \left(\Gamma_ {I}, \Delta_ {I}\right) $$

First we note that in our construction it is sucient for a local view (pp*;;n;* st*;I;*FI) of a storage node to be valid that

$$ (\mathsf{p p},\delta,n,\mathsf{s t},I,\mathsf{F}_{I}) $$

ClntNode*:* VerRetrieve(;I; StrgNode*:* Retrieve(;n; st*;I;FI;I*)) = 1 holds. More concretely this transaIbI0aQ0bQ lates to st₁ =1^st₂ =2and due to the correctness of disaggregation property st₁ =1^st₂ = 2holds where st⁰ StrgNode: Retrieve(;n; st*;I;FI;Q*) for each Q I. To put things clear, a local aIbI view of a storage node (pp*;;n;* st*;I;FI) is valid if st₁ =1^ st₂ =2. Let (pp;;n;* st*;I;*F) be a valid local view of a storage node:

$$ (\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, I)) = 1 $$

$$ \mathsf{s t}{1}^{a{I}}=\delta_{1}{\wedge}\mathsf{s t}{2}^{b{I}}=\delta_{2} $$

$$ {mathsf\mathsf s t}{1}^{\prime a{Q}}=\delta_{1}{\wedge}\mathsf{s t}{2}^{\prime b{Q}}= $$

$$ \delta_{2} $$

$$ (\delta,n,\mathsf{s t},I,\mathsf{F}_{I},Q) $$

$$ Q\subseteq I $$

$$ \mathsf{s t}{1}^{a{I}}=\delta_{1}\wedge\mathsf{s t}{2}^{b{I}}=\delta_{2} $$

$$ (\mathsf{p p},\delta,n,\mathsf{s t},I,\mathsf{F}_{I}) $$

I 0 0J Update Correctness. Let (op*;) be an admissible update for (I;FI;n) and (;n⁰;st⁰;J;F;) be the output of StrgNode:* PushUpdate(;n; st*;I;FI;op;*). We discern three cases depending on the type of update:

$$ (I,\mathsf{F}_{I},n) $$

$$ \left(\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}{J}^{\prime},\varUpsilon{\varDelta}\right) $$

$$ (mathsf o o p,\varDelta) $$

$$ \mathrm {P u s h U p d a t e} (\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, \mathrm {o p}, \Delta) $$

{ op = mod:

$$ \boldsymbol{\delta}^{\star}=(\boldsymbol{\Gamma}{K}^{a{K}^{\prime}},\boldsymbol{\Delta}{K}^{b{K}^{\prime}}) $$

0 a0b0 ? K K 1.According to our construction = (;), where K K

a b a 0K b 0K a b a b InK InK a IK b IK 0 0a IK b IK (K;K) = (;) = (st₁*;st₂) (due to VC:* Disagg). So = (st₁*;*st₂). Fur- I I thermore st⁰ = st and J = I, so

$$ (\varGamma_{K},\varDelta_{K})=(\varGamma_{I}^{a_{I\setminus K}},\varDelta_{I}^{b_{I\setminus K}})=(\mathsf{s t}{1}^{\frac{a{I}}{a_{K}}},\mathsf{s t}{2}^{\frac{b{I}}{b_{K}}}) $$

$$ \delta^{\prime}=(\mathsf{s t}{1}^{\frac{a{I}}{a_{K}}a_{K}^{\prime}},\mathsf{s t}{2}^{\frac{b{I}}{b_{K}}b_{K}^{\prime}}) $$

$$ J=I. $$

$$ \mathsf{s t}^{\prime}=\mathsf{s t} $$

$$ (\mathsf{s t}{1}^{\prime a{J}^{\prime}},\mathsf{s t}{1}^{\prime b{J}^{\prime}})=(\mathsf{s t}{1}^{\frac{a{I}}{a_{K}}a_{K}^{\prime}},\mathsf{s t}{2}^{\frac{b{I}}{b_{K}}b_{K}^{\prime}})=(\delta_{1}^{\prime},\delta_{2}^{\prime}) $$


0s 0s 0J 2.Let (;n; sts;Is; FIs) be valid and (bs;s0;n;st;Js; F) be the output of s 0 0s StrgNode*:* ApplyUpdate(;n; st*;I;FI;op;;). bs= 1,s0= and n = n⁰ come from inspection. If I\K =;* then 0s; 0s; a0b0 (st*;st) ShamirTrick(sts;1;K; FI;* FK)K; ShamirTrick(sts;2;K; FI; FK)K= 1 2 a0K b0K aK bK 0I 0I = (st*;st) and (a;b) = (aI;b*I) remains the same. So s;1 s;2

$$ (\delta,n,\mathsf{s t}{s},I{s},\mathsf{F}{I{s}}) $$

$$ (b_{s},\delta_{s}^{\prime},n_{s}^{\prime},\mathsf{s t}{s}^{\prime},J{s},\mathsf{F}{J{s}}^{\prime}) $$

$$ \operatorname {S t r g N o d e}. \operatorname {A p l y U p d a t e} (\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, \mathrm {o p}, \Delta , Y _ {\Delta}). b _ {s} = 1, \delta_ {s} ^ {\prime} = \delta^ {\prime} \text {a n d} n _ {s} ^ {\prime} = n ^ {\prime} \text {c o m e f r o m i n s p e c t i o n}. $$

$$ I\cap K=\emptyset $$

$$ (\mathsf{s t}{s,1}^{\prime},\mathsf{s t}{s,2}^{\prime})\leftarrow\Big(\mathbf{S h a m i r T r i c k}(\mathsf{s t}{s,1},\varGamma{K},\mathsf{F}{I},\mathsf{F}{K})^{\mathsf{d}{K}^{\prime}}:,\mathbf{S h a m i r T r i c k}(\mathsf{s t}{s,2},\varDelta_{K},\varDelta{\ \ {K}},\mathsf{F}{K})^{\mathsf{d}_{K}^{\prime}}\Big)= $$

$$ =\big(\mathsf{s t}{s,1}^{\frac{a{K}^{\prime}}{a_{K}}},\mathsf{s t}{s,2}^{\frac{b{K}^{\prime}}{b_{K}^{}}}\big)} $$

$$ (a_{I}^{\prime},b_{I}^{\prime})=(a_{I},b_{I}) $$

$$ (\mathsf{s t}{s,1}^{\prime a{I}^{\prime}},\mathsf{s t}{s,2}^{\prime})=(\mathsf{s t}{s,1}^{a_{K}^a_{I}},a_{I},\mathsf{s t}{s,2}^{b{K}}b_{I})=(\delta_{s,1},\delta_{s,2}) $$

0I 0I aI 0K bI 0K If I\K = K then stsdoesn’t change and (a;b) = ( a; b), hence aKbK

$$ I\cap K=K $$

$$ {\sf{S}}{\sf{t}}_{s} $$

$$ \left(a_{I}^{\prime},b_{I}^{\prime}\right)=\left(\frac{a_{I}}{a_{K}}a_{K}^{\prime},\frac{b_{I}}{b_{K}}b_{K}^{\prime}\right) $$

$$ \left(\mathrm {s t} _ {s, 1} ^ {\prime a _ {I} ^ {\prime}} \mathrm {s t} _ {s, 2} ^ {\prime b _ {I} ^ {\prime}}\right) = \left(\delta_ {s, 1} ^ {\prime}, \delta_ {s, 2} ^ {\prime}\right) $$

0s 0s 0J The validity of (pp*;s0;n;st;J*s; F) in the case of I \ K = L =2f;;Kg is covered by the above s two, since it essentially is a sequence of the two above cases.

$$ (\mathsf{p p},\delta_{s}^{\prime},n_{s}^{\prime},\mathsf{s t}{s}^{\prime},J{s},\mathsf{F}{J{s}}^{\prime}) $$

$$ I\cap K=L\notin{\emptyset,K} $$

3.Let (bc;c) be the output of ClntNode*:* ApplyUpdate(;op;;). It follows directly from the denition of ClntNode*:* ApplyUpdate (and its similarity with StrgNode*:* ApplyUpdate) that bc= 0 bs= 1 andc0=s0=.

$$ (b_{c},\delta_{c}) $$

$$ (\delta , \mathrm {o p}, \Delta , Y _ {\Delta}) $$

$$ {_b{c}}= $$

$$ b_{s}=1 $$

$$ \delta_{c}^{\prime}=\delta_{s}^{\prime}=\delta^{\prime} $$

{ op = add:

0 a0b0 ? K K 0 0J 0J 1.According to our construction = (;) and st = st. Also, J = I[K and (a;b) = 1 2 0K 0K (aIa;bIb) and so

$$ \delta^{\star^{\prime}}=(\delta_{1}^{a_{K}^{\prime}},\delta_{2}^{b_{K}^{\prime}}) $$

$$ \mathsf{s t}^{\prime}=\mathsf{s t} $$

$$ (a_{J}^{\prime},b_{J}^{\prime})= $$

$$ (a_{I}a_{K}^{\prime},b_{I}b_{K}^{\prime}) $$

$$ (\mathsf{s t}{1}^{\prime a{J}^{\prime}},\mathsf{s t}{1}^{\prime b{J}^{\prime}})=(\mathsf{s t}{1}^{a{I}a_{K}^{\prime}},\mathsf{s t}{2}^{b{I}b_{K}^{\prime}})=(\delta_{1}^{a_{K}^{\prime}},\delta_{2}^{b_{K}^{\prime}})=(\delta_{1}^{\prime},\delta_{2}^{\prime}) $$

0s 0s 0J 2.Let (;n; sts;Is; FIs) be valid and (bs;s0;n;st;Js; F) be the output of s 0 0s StrgNode*:* ApplyUpdate(;n; st*;I;FI;op;;). bs= 1,s0= and n = n⁰ come from inspection. a0b0 0 a0b0 0J 0J 0 K K? K K Also J = I so (a;b) = (aI;b*I). st = (st₁*;st₂) and = (;*) so 1 2

$$ (\delta,n,\mathsf{s t}{s},I{s},\mathsf{F}{I{s}}) $$

$$ (b_{s},\delta_{s}^{\prime},n_{s}^{\prime},\mathsf{s t}{s}^{\prime},J{s},\mathsf{F}{J{s}}^{\prime}) $$

$$ \mathtt{t r g N o d e.A p p l y V D a t e e}(\delta,n,\mathtt{s t},\mathtt{I},\mathtt{F}{},\mathtt{o p},\mathtt DeltaDelta,\mathtt{T}{\Delta}).;b_{s}=1,\bar{\delta}{s}^{\prime}=\delta^{\prime}\operatorname{a n d}n{s}^{\prime}=n^{\prime} $$

$$ J=I;{\mathrm{s o}};(a_{J}^{\prime},b_{J}^{\prime})=(a_{I},b_{I}).;{\mathfrak{s t}}^{\prime}=({\mathfrak{s t}}{1}^{a{K}^{\prime}},{\mathfrak{s t}}{2}^{b{K}^{\prime}}) $$

$$ \delta^{\star}=(\delta_{1}^{a_{K}^{\prime}},\delta_{2}^{b_{K}^{\prime}}) $$

$$ (\mathsf{s t}{1}^{\prime a{J}^{\prime}},\mathsf{s t}{1}^{\prime b{J}^{\prime}})=(\mathsf{s t}{1}^{a{K}^{\prime}a_{I}},\mathsf{s t}{2}^{b{K}^{\prime}b_{I}})=(\delta_{1}^{\prime},\delta_{1}^{\prime}) $$

3.Let (bc;c) be the output of ClntNode*:* ApplyUpdate(;op;;). Again correctness comes directly from the denition of ClntNode*:* ApplyUpdate. { op = del:

$$ (b_{c},\delta_{c}) $$

$$ (\delta,\mathsf{o p},\varDelta,\varUpsilon_{\varDelta}) $$

$$ -{\mathrm{\ o}}{\mathsf{p p}}={\mathsf{d e l}}!, $$

1 1 0 0aK bK 0 1.According to our construction (1;2)=(K;K)=(;), st = st and J = I n K. 1 2 0J 0J aIbI Furthermore, (a;b) = (;) aKbK

$$ (\delta_{1}^{\prime},\delta_{2}^{\prime}):=:(\varGamma_{K},\varDelta_{K}):=:(\delta_{1}^{\frac{1}{_{K}}},\delta_{2}^{\frac{1}{\delta_{K}}}),:\mathsf{s t}^{\prime}:=:\mathsf{s t}:\mathrm{a n d}::J:=:I:\setminus K $$

$$ \left(a_{J}^{\prime},b_{J}^{\prime}\right)=\left(\frac{a_{I}}{a_{K}},\frac{b_{I}}{b_{K}}\right) $$

$$ (\mathsf{s t}{1}^{\prime mathsf a{J}^{\prime}},\mathsf{s t}{1}^{\prime b{J}^{\prime}})=(\mathsf{s t}{1}^{\frac{a{I}}{a_{K}}},\mathsf{s t}{2}^{\frac{b{I}}{b_{K}}})=(\delta_{1}^{\frac{1}{a_{K}}},\delta_{2}^{\frac{1}{b_{K}}})=(\delta_{1}^{\prime},\delta_{2}^{\prime}) $$

0s 0s 0J 2.Let (;n; sts;Is; FIs) be valid and (bs;s0;n;st;Js; F) be the output of s 0 0s StrgNode*:* ApplyUpdate(;n; st*;I;FI;op;;*). bs= 1,s0= and n = n⁰ come from inspection. Also let L = I\K then J = I n L and if L = K n L then

$$ (\delta,n,\mathsf{s t}{s},I{s},\mathsf{F}{I{s}}) $$

$$ (b_{s},\delta_{s}^{\prime},n_{s}^{\prime},\mathsf{s t}{s}^{\prime},J{s},\mathsf{F}{J{s}}^{\prime}) $$

$$ \ \mathbf\ {\mathrm{p p l y J p d a t e}}(\delta,n,\mathtt{s t},\mathtt I\{{F}}{I},\mathtt{o p},\mathtt\ Delta\ ,\varUpsilon{\varDelta}).\ b_{s}=\ ,\tilde{1},\delta_{s}^{\prime}=\delta^{\prime}\operatorname{a n d}n_{s}^{\prime}=n^{\prime} $$

$$ {\bar{L}}=K\setminus L $$

$$ L=I\cap K $$

$$ J=I\setminus L $$

1 1 0 0aL bL (st₁*;st₂) (ShamirTrick(st₁;L;* FI; FL); ShamirTrick(st₂*;L;* FI; FL)) = (st₁;st₂)

$$ (\mathsf{s t}{1}^{\prime},\mathsf{s t}{2}^{\prime})\leftarrow(\mathbf{S h a m i r r T r c c}(\mathsf{s t}{1},\mathit{\Gamma}{\bar{L}},\mathit{\Gamma}{\bar{L}},\mathit{\Gamma}{},\mathit{\Gamma}_{\bar{L}})\nonumber} $$

$$ \cdot(\mathsf{s t}{2},\varDelta{\bar{L}},\mathsf{F}{I},\mathsf{F}{\bar{L}}))=(\mathsf{s t}{1}^{\frac{1}{a{\bar{L}}}},\mathsf{s t}{2}^{\frac{1}{b{\bar{L}}}}) $$

$$ (\mathbf{s t}{1}^{\prime prime alpha{{J}^{\prime}}},\mathbf{s t}{1}^{b{J}^{\prime}})=(\mathbf{s t}{1}^{\frac{a{J}}{a_{L}}},\mathbf{s t}{2}^{\frac{b{J}}{b_{L}^{\prime}}})=(\mathbf{s t}{1}^{\frac{a{J}/a_{L}}{a_{L}/a_{L}}},\mathbf{s t}{1}^{\frac{b{J}/b_{L}}{b_{K}/b_{L}}})=(\delta_{1}^{\frac{1}{a_{K}}},\delta_{2}^{\frac{1}{b_{K}}})=(\delta_{1}^{\prime},\delta_{2}^{\prime}) $$


0 3.Let (bc;c) be the output of ClntNode*:* ApplyUpdate(;op;;). bc= bs= 1 andc0=s0= from inspection.

$$ (b_{c},\delta_{c}) $$

$$ \delta_{c}^{\prime}=\delta_{s}^{\prime}=\delta^{\prime} $$

$$ (\delta , \mathrm {o p}, \Delta , Y _ {\Delta}). b _ {c} = b _ {s} = 1 $$

Add Storage Correctness. It comes directly from aggregation correctness of VC*:* Agg⁰ (see section5.1).

$$ \mathsf{V C.A g g^{\prime}} $$

Remove Storage Correctness. It comes directly from disaggregation correctness of VC*:* Disagg⁰ (see section5.1).

$$ J\subseteq I $$

0 Create Correctness. Let J I and (;n⁰;st⁰;J;FJ;J) be the output of 00 StrgNode*:* CreateFrom(;n; st*;I;FI;J*) and (b;) the output of ClntNode*:* GetCreate(;J;J), then 00 0 n⁰ = jJ j comes from inspection of StrgNode*:* CreateFrom, = comes from inspection of 0 ClntNode*:* GetCreate algorithm and validity of (pp*;;n⁰;st⁰;J;FJ) comes from correctness of VC:* Com⁰ and VC*:* Agg. Finally, b = 1 comes from correctness of PoKSubV⁰ protocol.

$$ (\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}{J},\mathsf{T}{J}) $$

$$ (\delta,n,\mathsf{s t},I,\mathsf{F}_{I},J) $$

$$ (b,\delta^{\prime\prime}) $$

$$ e. \operatorname {G e t C r e a t e} (\delta , J, Y _ {J}) $$

$$ n^{\prime},=,|J| $$

$$ \delta^{\prime\prime};=;\delta^{\prime} $$

$$ \ \ (\mathsf{p p},\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{J}) $$

$$ \mathsf{V C}o o\mathsf{N} $$

$$ b=1 $$

Aggregate Correctness. It comes directly from aggregation correctness of VC*:* Agg⁰ (see section5.1).

Security. Below we state and prove the security of our VDS₁ scheme.

$$ \mathsf{V D S}_{1} $$

Theorem 8.2(Security). Let G Ggen(1 ) be a hidden order group where the strong RSA assumption holds, then the scheme VDS₁ presented above is a secure Veriable Decentralized Storage scheme in the generic group model.

$$ \mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda}) $$

Proof First we observe that in our scheme, for every valid history H, with Bootstrap(1 )! (pp*;0;st₀) := ((G;g;g₀;g₁;PrimeGen);* ((g₀;g₁);0); (g₀;g₁)), the digest that arises is the same as a commitment of the le with VC*:* Com⁰. Concretely, let (b;; F) EvalHistory(pp*;0;st₀; H*) ? a b then if b = 1 it holds that = VC*:* Com⁰(pp*;F) or = (1;2) = (g₀;g₁), where (a;b) PartndPrimeProd([jFj*]*;*F). Particularly this is central to our construction and one can validate that it holds by inspecting all the algorithms that alter the digest.

$$ (\mathsf{p p},\delta_{0},\mathsf{s t}{0});:=;((\mathbb{G},g,g{0},g_{1},\mathsf{P r i m e G G n)):};((g_{0},g_{1}),0):,;(g_{0},g_{1}). $$

$$ \mathsf{B o o t s t r a p}(1^{\lambda})\to $$

$$ (b,\delta,\mathsf{F})\ \leftarrow\ \mathsf{E v a l H i s t o r y}(\mathsf{p p},\delta_{0},\mathsf{s t}_{0},\mathcal{H}) $$

$$ \delta,=,\mathsf{V C.C o m^{\prime}(p p,F)} $$

$$ \delta^{\star};=;\big(\delta_{1},\delta_{2}\big);=;\big(g_{0}^{a},g_{1}^{b}\big) $$

$$ (a,b)\leftarrow $$

To prove the theorem we use a hybrid argument. We start by dening the game G₀ as the actual VDS security game of Denition7.6, and our goal is to prove that for any PPT A, Pr[G₀ = 1] 2 negl().

$$ G_{0} $$

$$ \mathcal{A},,\operatorname*{P r}[G_{0}=1]\in $$

$$ G{{}_{0}}; $$

$G_{0}=\mathrm{VDS-Security}_{\mathrm{VDS}}^{\mathcal{A}}(\lambda)$ EvalHistory(pp, $\delta_{0}$, st0,H)
(pp,$\delta_{0}$,st0) $ \leftarrow $ Bootstrap($1^{\lambda}$) F0 $ \leftarrow $ ∅;b $ \leftarrow $ 1
(H,Q,F${Q}^{}$,$\pi^{}$) $ \leftarrow $ A(pp,$\delta{0}$,st0) for i∈[ℓ]
(b,$\delta$,F) $ \leftarrow $ EvalHistory(pp,$\delta_{0}$,st0,H) Fi $ \leftarrow $ FileChange(Fi-1,opi,$\Delta^{i}$)
b $ \leftarrow $ b $ \wedge $ F${Q}^{*} \neq F{Q}\wedge$ if opi $ \in $ {mod,add,del} then
ClntNode.VerRetrieve(pp,$\delta$,Q,F$_{Q}^{}$,$\pi^{}$) (bi,$\delta_{i}$) $ \leftarrow $ ClntNode.ApplyUpdate($\delta_{i-1}$,opi,$\Delta^{i}$,Y$_{\Delta}^{i}$)
return b elseif opi $ = $ cfrom then
(bi,$\delta_{i}$) $ \leftarrow $ ClntNode.GetCreate($\delta_{i-1}$,$\Delta^{i}$,Y$_{\Delta}^{i}$)
endif b $ \leftarrow $ b $ \wedge $ bi
endfor return(b,$\delta_{\ell}$,F$\ell$)

$$ G_{0}=\mathsf{V D S-S e c u r i t y_{V D S}^{A}}(\lambda) $$

$$ (\mathsf{p p},\delta_{0},\mathsf{s t}_{0})\leftarrow\mathsf{B o o t s t r a p(1}{}^{\lambda}) $$

$$ \mathsf{F}_{0}\leftarrow\emptyset;b\leftarrow1 $$

$$ (\mathcal{H},\mathcal{Q},\mathsf{F}{Q}^{},\pi^{})\leftarrow\mathcal{A}(\mathsf{p p},\emptyset{0},\mathsf{s t}_{0}) $$

$$ (b, \delta , F) \leftarrow \operatorname {E v a l H i s t o r y} (\mathrm {p p}, \delta_ {0}, \mathrm {s t} _ {0}, \mathcal {H}) $$

$$ i\in[\ell] $$

$$ \mathsf{F}{i}\leftarrow\mathsf{F i l e C h a n g e}(\mathsf{F}{i-1},\mathfrak{o p}^{i},\varDelta^{i}) $$

$$ b\gets b\land\mathsf{F}{Q}^{*}\neq\mathsf{F}{Q}\land $$

$$ \cdot\mathsf{o p}^{i}\in{\mathsf{m o d},\mathsf{a d d},\mathsf{d e l}} $$

$$ \mathsf{C I n t N o d e.V e r R e t r i e v e}(\mathsf{p p},\delta,,,\mathsf{Q},\mathsf{F}_{Q}^{},\pi^{}) $$

$$ \left(b _ {i}, \delta_ {i}\right) \leftarrow \mathrm {C l n t N o d e . A p p l y U p d a t e} \left(\delta_ {i - 1}, \mathrm {o p} ^ {i}, \Delta^ {i}, \gamma_ {\Delta} ^ {i}\right) $$

$$ \ \mathsf{o p}^{i}=\mathsf{c f r o m\ t\ e t{n n}} $$

$$ \left(b _ {i}, \delta_ {i}\right) \leftarrow \mathrm {C l n t N o d e . G e t C r e a t e} \left(\delta_ {i - 1}, \Delta^ {i}, \Upsilon_ {\Delta} ^ {i}\right) $$

$$ b\gets b\land b_{i} $$

$$ (b,\delta_{\ell},\mathsf{F}_{\ell}) $$

i i i Recall that H = (op*;;*)i2[‘]where:

$$ \mathcal{H}=(\mathfrak{o p}^{i},\varDelta^{i},\varUpsilon_{\varDelta}^{i})_{i\in[\ell]} $$


$$ -\mathrm{f o r}\mathfrak{o p}^{i}=\mathsf{m o d}\colon\Delta^{i}:=(K^{i},\mathsf{F}{K^{i}}^{i}),{\underline{{\Delta}}}^{i}:=(\mathsf{F}{K^{i}}^{i-1},\pi{K^{i}}^{i-1})\mathrm{a n d}\mathsf{C i n t h o d e}\mathsf{A p p y f D p d a t e}(\delta^{i-1},\mathsf{o p}^{i},\Delta^{i},T_{\underline{{\Delta}}}^{i}) $$

i i i iK i iK 1 i 1 i 1 i i i { for op = mod: := (K; Fi), := (Fi;i) and ClntNode*:* ApplyUpdate(;op;;) K i 0 i 1 i iK 1 i 1 aKi i 1 bKii i 1 outputs b = 1 if VC*:* Ver (pp*;;K;* Fi;i) = 1 or (i=) ^ ( =). K K 1 K 2

$$ \text {o u t p u t s} b ^ {i} = 1 \text {i f} \mathrm {V C}. \operatorname {V e r} ^ {\prime} \left(\mathrm {p p}, \delta^ {i - 1}, K ^ {i}, \mathrm {F} _ {K ^ {i}} ^ {i - 1}, \pi_ {K ^ {i}} ^ {i - 1}\right) = 1 \text {o r} \left(\Gamma_ {K ^ {i}} ^ {a _ {K ^ {i}}} = \delta_ {1} ^ {i - 1}\right) \wedge \left(\Delta_ {K ^ {i}} ^ {b _ {K ^ {i}}} = \delta_ {2} ^ {i - 1}\right). $$

i i iK i i 1 i i i { for op = add: := (K;Fi), := ? and ClntNode: ApplyUpdate(;op;;) outputs i i i 1 i 1 i b = 1 if K = fn + 1;:::;n + jK jg.

$$ \ cdot{\bf o o\ o{\o o\o o}}^{i},=,{\bf a\ do{\o d}}\ \colon:=,(K,\mathsf{F}{K^{i}}^{i}),,\var_Upsilon{\Delta}^{i},:=,\varnothing $$

$$ \mathsf{N o d e.A p p l y U p d a t e}(\delta^{i-1},\mathsf{o p}^{i},\varDelta^{i},\varUpsilon^{i}) $$

$$ b^{i}={\mathbf{1}}{\mathrm{i f}}K^{i}={n^{i-1}+{\mathbf{1}},{\ldots,\ \overset{\ \ }{n^{i-1}}+\ \overset\rightarrow\vert,overset\\rightarrow vert\,}}} $$

i i i i iK 1 i 1 i 1 i i i { op = del: := K, := (Fi;i) and ClntNode*:* ApplyUpdate(;op;;) outputs K i i i 1 i i 1 i 1 i 1 iK 1 i 1 i i 1 b = 1 if (K = fn jK j+ 1;:::;n g) ^VC: Ver⁰(pp*;;K;* Fi;i)) or (K = fn K i i 1 aKi i 1 bKii i 1 jK j + 1;:::;n g^ ( =) ^ ( =).

$$ -\ {\bf\sf o p}^{i};=;{\bf\sf d e l}\ \colon\varDelta^{i};:=;K^{i},\ \varUpsilon_{\Delta}^{i};:=;({\sf F}{K^{i}}^{i-1},\pi{K^{i}}^{i-1}) $$

$$ \ ^{t}=,1,\mathrm{i f}(K^{t}=,{n^{t-1}-|K^{t}|+1,,\dots,n^{t-1}}),\land\mathsf{V C}e^{\prime}(\mathbf{p p},\theta^{t-1},K^{t-1},\mathbf{P}{\mathcal{K}^{t}}^{t-1},\mathbf{P}{\mathcal{K}^{t}}^{t-1},\pi_{\mathcal{K}^{t}}^{t-1}),\mathrm{o r}(\mathsf{K}^{t}={\ n^{t-1}-\ \ ,\dots,n^{t-1}}),. $$

$$ \ K^{i}|+1,\ldots,n^{i-1}\big}\wedge(\varGamma_{K^{i}}^{a_{K^{i}}}=\delta_{1}^{i-1})\wedge(\varDelta_{K^{i}}^{b_{K^{i}}}=\delta_{2}^{i-1}). $$

i i i i i i i 1 i i i { op = cfrom: := K, := (;0) and ClntNode*:* GetCreate(;;) outputs b = 1 PoKSubV i 1 i i i i if PoKSubV⁰*:* V(pp*;* (;; jK j;K);i) = 1. K

$$

$$ \operatorname {G e t C r e a t e} \left(\delta^ {i - 1}, \Delta^ {i}, Y _ {\Delta} ^ {i}\right) $$

$$ b^{i}=1 $$

$$ \text {i f} \mathrm {P o K S u b V} ^ {\prime}. \mathrm {V} (\mathrm {p p}, \left(\delta^ {i - 1}, \delta^ {i}, \left| K ^ {i} \right|, K ^ {i}\right), \pi_ {K ^ {i}} ^ {i}) = 1 $$

Game Gi: dene Gibe the same as Gi 1except for the update i:

$$ G_{i}: $$

$$ G_{i-1} $$

$$ G_{i} $$

i i i iK i iK 1 i 1 i { if op = mod: := (K; Fi), := (Fi;i) but in the i-th step of EvalHistory b is instead K output of: i b (a ja) ^ (b jb)

$$ -\ \ \ \mathrm{i f}\ \ \mathsf{o p}^{i}=\mathsf{m o d}\ :\ Delta^{i}:=(K^{i},\mathsf{F}{K^{i}}^{i}),,Upsilon{\varDelta}^{i}:=(\mathsf{F}{K^{i}}^{i-1},\pi{K^{i}}^{i-1}) $$

$$ b^{i} $$

$$ b^{i}\leftarrow(a_{K^{i}}|a)\wedge(b_{K^{i}}|b) $$

$$ (\mathit{a},\mathit{b})\leftarrow\mathsf{P a r t n d P r i m e P r o d}([|\mathsf{F}^{i-1}|],\mathsf{F}^{i-1}) $$

i i In case b = 0 aborts (aborti). Otherwise is computed normally from

$$ b^{i}=0 $$

$$ \delta^{i} $$

i 1 i i i ClntNode*:* ApplyUpdate(;op;;).

i i iK i i i { for op = add: := (K;Fi), := ? and everything is the same as in Gi 1. I.e. (b;) is the i 1 i i i output of ClntNode: ApplyUpdate(;op;;).

$$ \mathrm {o p} ^ {i} = \mathrm {a d d}: \Delta^ {i} := (K, \mathrm {F} _ {K ^ {i}} ^ {i}), Y _ {\Lambda} ^ {i} := \varnothing $$

$$ G_{i-1} $$

$$ (b^{i},\delta^{i}) $$

$$ (\delta^{i-1},{\mathfrak{o p}}^{i},\varDelta^{i},\varUpsilon_{\varDelta}^{i}) $$

i i i i iK 1 i 1 i { op = del: := K, := (Fi;i). Similarly to the mod case b is the output of: K

$$

$$ b^{i} $$

$$ b^{i}\leftarrow(a_{K^{i}}|a)\wedge(b_{K^{i}}|b)\wedge(K^{i}={n^{i-1}-|K^{i}|+1,\ldots,n^{i-1}}) $$

i 1 i 1 where (a;b) PartndPrimeProd([jF j]; F)

$$ ([|\mathsf{F}^{i-1}|],\mathsf{F}^{i-1}) $$

i i In case b = 0 aborts (aborti). Otherwise is computed normally from

$$ b^{i}=0 $$

$$ \delta^{i} $$

i 1 i i i ClntNode*:* ApplyUpdate(;op;;).

$$ (\delta^{i-1},{\mathfrak{o p}}^{i},\varDelta^{i},\varUpsilon_{\varDelta}^{i}) $$

i i i i i i i { op = cfrom: := K, := (;0) but in the i-th step of EvalHistory b is instead: PoKSubV

$$ b^{i} $$

$$ b^{i}\gets(\mathsf{F}{K^{i}}^{i-1}\subseteq\mathsf{F}^{i-1})\wedge\delta^{i}=\mathsf{V C}C o m^{\prime}(\mathsf{p p},\mathsf{F}{K^{i}}^{i-1})\wedge J={1,\dots,|J|} $$

i In case b = 0 aborts (aborti).

$$ b^{i}=0 $$

i Lemma 8.1. Let op = mod then if the strong RSA assumption holds for Ggen*,* Pr[Gi 1= 1] Pr[Gi= 1] + negl().

$$ {\mathfrak{o p}}^{i}= $$

$$ \operatorname*{P r}[G_{i-1}=1]\leq $$

$$ \operatorname*{P r}[G_{i}=1]+{mathsf{n e g l}}(\lambda) $$

Proof It is straightforward that the only dierence between Gi 1and Giis in the computation i i aKi i 1 bKii i 1 i of b inside the EvalHistory. That is in Gi 1: b = (i=) ^ ( =) and in Gi: b = K 1 K 2 (aKija) ^ (bKijb). Since abort₁*;abort₂;:::;* aborti 2have not happen, from correctness of the VDS i 1 i 1 a b i 1 i 1 scheme it comes that (;) = (g₀;g₁), where (a;b) PartndPrimeProd([jF j]; F). 1 2

$$ G_{i-1} $$

$$ G_{i} $$

$$ G_{i-1}:b^{i}=(\varGamma_{K^{i}}^{a_{K^{i}}}=\delta_{1}^{i-1})\wedge(\varDelta_{K^{i}}^{b_{K^{i}}}=\delta_{2}^{i-1}) $$

$$ b^{i} $$

$$ (a_{K^{i}}|a)\wedge(b_{K^{i}}|b) $$

$$ G_{i}:b^{i}= $$

$$ \left(\delta_{1}^{i-1},\delta_{2}^{i-1}\right)=\left(g_{0}^{a},g_{1}^{b}\right) $$

$$ (\mathbf{\mathit{a}},\mathbf{\mathit{b}})\leftarrow\mathsf{P a r t n d P r i m e P r o d}([\lfloor\mathsf{\mathit{F}}^{i-1}\vert],\mathsf{\mathit{F}}^{i-1}) $$

$$ \left| \Pr \left[ G _ {i - 1} = 1 \right] - \Pr \left[ G _ {i} = 1 \right] \right| = P r \left[ \mathrm {a b o r t} _ {i} \right] = P r \left[ b ^ {i} = 0 \right] = P r \left[ \left(a _ {K ^ {i}} | a\right) \wedge \left(b _ {K ^ {i}} | b\right) \right] $$

i jPr[Gi 1= 1] Pr[Gi= 1]j = Pr[aborti] = Pr[b = 0] = Pr[(aKija) ^ (bKijb)]. But since aKi a bKii b aborti 1didn’t happen (i= g₀) ^ ( = g₁). Therefore it is straightforward to abortito K K the strong RSA assumption, i.e. Pr[aborti] = negl().

$$ \mathsf{a b o r t}_{i-1} $$

$$ \ \big({\mathit\Gamma}{K^{i}}^{a{K^{i}}},=,g_{0}^{a}\big)\wedge\big({\mathit\Delta}{K^{i}}^{b{K^{i}}},=,g_{1}^{b}\big) $$

$$ \ \mathrm{i.e.~}P r[\mathsf{a b o r t}_{i}]=\mathsf{n e g}|(\lambda) $$ i Lemma 8.2. Let op = del then if the strong RSA assumption holds for Ggen*,* Pr[Gi 1= 1] Pr[Gi= 1] + negl().

$$ {\mathsf{o p}}^{i},= $$

$$ \operatorname*{P r}[G_{i-1}=1]\leq $$

$$ \operatorname*{P r}[G_{i}=1]+{\mathsf{n e g l}}(\lambda) $$

i Proof The same as the above case of op = mod holds.

$$ {\mathfrak{o p}}^{i}={\mathsf{m o d\ h o l d s}} $$

i Lemma 8.3. Let op = add then Pr[Gi 1= 1] = Pr[Gi= 1].

$$ {\mathfrak{o p}}^{i}={\mathfrak{a}}d d\ , $$

$$ \operatorname*{P r}[G_{i-1}!=!1]=\operatorname*{P r}[G_{i}=1] $$

Proof Gi 1and Giare identical.

$$ G_{i-1} $$

$$ G_{i} $$

i Lemma 8.4. Let op = cfrom then for any PPT A in Githere exists an algorithm E such that Pr[Gi 1= 1] Pr[Gi= 1] + negl() of the strong RSA assumption holds.

$$ {\mathfrak{o p}}^{i}={\mathfrak{c f r o}}m $$

$$ G_{i} $$

$$ \mathcal{E} $$

$$ \operatorname*{P r}[G_{i-1}=1]\leq\operatorname*{P r}[G_{i}=1]+\mathsf{n e g l}(\lambda) $$

Proof Let E be the extractor of PoKSubV⁰ protocol that corresponds to A. Since PoKSubV⁰ iK 1 0 i 1 i iK 1 is knowledge sound, E outputs (Fi;Ki;i) such that VC*:* Ver⁰(pp*;;K; ~Fi;Ki) = 1 ^ K i i iK 1 0 iK 1 i?i i VC: Ver⁰(pp;;K;* ~Fi;i) = 1*^*jFij = n⁰, where = (;n). Since abort₁*;abort₂;:::;* aborti 2 K i 1 i 1 have not happen, from correctness of the VDS scheme it comes that = VC*:* Com⁰(pp*;* F). iK 1 i 1 From the rst verication equation above we get that under strong RSA assumption F F. i iK 1 i From the second verication equation above we get that F is an opening of. From the third i i iK 1 equation above we get that is a digest for a le of size jF j. From the last two points we get i i iK 1 that = VC*:* Com⁰(pp*;* Fi). So Pr[G = 1] Pr[G = 1] + negl().

$$ (\vec{\mathsf{F}}{K^{i}}^{i-1},\pi{K^{i}},\pi_{K^{i}}^{\prime}) $$

$$ \mathrm {V C}. \operatorname {V e r} ^ {\prime} \left(\mathrm {p p}, \delta^ {i - 1}, K ^ {i}, \vec {\mathrm {F}} _ {K ^ {i}} ^ {i - 1}, \pi_ {K ^ {i}}\right) = 1 \wedge $$

$$ \mathsf{V C.V e r}^{\prime}(\mathsf{p p},\delta^{i},K^{i},\vec{\mathsf{F}}{K^{i}}^{i-1},\pi{K^{i}}^{\prime})=1\wedge\ |vec\bar{{\mathsf{F}}}_{K^{i}}^{i-1}|=n^{\prime} $$

$$ \delta^{i}=(\delta^{\star i},n^{i}) $$

$$ :2,\cdots. $$

$$ \delta^{i-1}=\mathsf{V C.C o m}^{\prime}(\mathsf{p p},\mathsf{F}^{i-1}) $$

$$ \mathsf{F}{K{i}}^{i-1}\subseteq\mathsf{F}^{i-1} $$

$$ \mathsf{F}{K{i}}^{i-1} $$

$$ \delta^{i} $$

$$ \delta^{i} $$

$$ |\mathsf{F}{K{i}}^{i-1}| $$

$$ \delta^{i}=\mathsf{V C.C o m}^{\prime}(\mathsf{p p},\mathsf{F}_{K^{i}}^{i-1}) $$

$$ \operatorname*{P r}[G_{i-1}=1]\leq\operatorname*{P r}[G_{i}=1]+\mathsf{n e g l}(\lambda). $$

We conclude that in any case Pr[Gi 1= 1] Pr[Gi= 1] + negl(). Since jHj = ‘ = poly() with a hybrid argument we get that Pr[G₀ = 1] Pr[G‘= 1] + negl(). But clearly G‘= 0 always A (since no abort has happened), and thus Pr[VDS-SecurityVDS() = 1] = P [G₀ = 1] = negl().

$$ \operatorname*{P r}[G_{i-1},=,1],\leq,\operatorname*{P r}[G_{i},=,1],+,\mathsf{n e g l}(\lambda) $$

$$ |\mathcal{H}|=\ell=\ \ \mathsf{p o l y}(\lambda) $$

$$ \operatorname*{P r}[G_{0}=1]\leq\operatorname*{P r}[G_{\ell}=1]+\mathsf{n e g l}(\lambda) $$

$$ G_{\ell}=0 $$

$$ \operatorname*{P r}[\mathsf{V}S\mathsf{-}\mathsf{S e c u r i t y}{\mathsf{V D S}}^{\mathsf{A}}(\lambda)=1]=P[G{0}=1]{\ =\ }{\mathsf{n e g l}}(\lambda) $$

8.2 Our Second VDS Construction

To construct our second VDS scheme, denoted VDS₂, we build on our second SVC scheme from section5.2. The main diculty that we face in turning our SVC into a VDS is the specializtionQ i2[n]ei phase of the CRS, i.e. the trusted generation of U = g. Although VDS schemes can support a trusted setup phase, it can only be done once by the Bootstrap algorithm. However, U depends on the current size of the le (though not on its content), meaning that normally at each addition (or deletion) to the le it should be updated²². To solve this problem, we attach U to the VDS’s digest (together with n for technical reasons), = ((U;C);n).

$$ \mathsf{V D S_{2}} $$

$$ U=g^{\tilde{\prod_{i\in[n]}e_{i}}} $$

$$ \delta=((U,C),n) $$

Then, U can be built progressively while the le is extended or reduced. Namely, when adding new positions from the set K to the le, all ei’s in K are added to the accumulator, i.e. U⁰ Q i2Kei U. The denition of VDS security (def.7.6) ensures that the digest is evaluated honestly Q i2nei which ensures that U has the correct form U = g.

$$ Utextstyle\prod_{i\in K}e_{i} $$

$$ e_{i}^{3} $$

$$ U^{\prime}\leftarrow $$

$$ 7.6) $$

$$ U = g ^ {\prod_ {i \in n} e _ {i}} $$

Finally, we make use of the dynamic properties of the [CF13,LM19] scheme (in which our SVC builds) and the RSA Accumulator, to construct the VDS scheme. The latter is important if

22 Another solution would be to recompute it at the verication time, but it would require linear work, which contradicts VDS requirements.


Q Q i2[n]ei i2[n]nIei one notice that U = g;SI= g resemble an RSA Accumulator value and witness respectively.

$$ U,=,g^{\prod_{i\in[n]}e_{i}},S_{I},=,g^{\prod_{i\in[n]\setminus I}e_{i}} $$

Our scheme VDS₂. In the following := ((U;C);n), st :=I, whereI:= (SI;I). Also, each eiis computed as eiPrimeGen(i); so PrimeGen(i) is omitted for simplicity in the description. VC*:* Agg*;VC:* Disagg are the aggregation and disaaggregation algorithms dened in section5.2. We Q j2InJej highlight that possession of SIallows anyone to compute SJS for each J I, thus for I simplicity we omit explicitly refer to the procedure of computing any such SJ.

$$ \mathsf{V D S_{2}} $$

$$ \delta:=((U,C),n) $$

$$ {=}\pi_{I}. $$

$$ \pi_{I}:=\left(S_{I},\varLambda_{I}\right) $$

$$ e_{i} $$

$$ e_{i}\leftarrow{\mathsf r i m e G e n}(i) $$

$$ S_{I} $$

$$ J\subseteq I $$

$$ S_{J}\gets S_{I}^{\prod_{j\in I\setminus J}e_{j}} $$

$$ S J $$

Bootstrap(1*;‘)!* (pp*;0;n₀;st₀)generates a hidden order group G Ggen(1 ) and samples a generator g $ G. It also determines a deterministic collision resistant function PrimeGen that maps integers to primes of ‘ + 1 bits. Set n₀ 0,0((1;g*);n₀) and st₀ g.

$$ (1^{\lambda},\ell)\to(\mathsf{p p},\delta_{0},n_{0},\mathsf{s t}_{0}) $$

$$ \mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda}) $$

$$ g\leftarrow\S\mathbb{G} $$

$$ n_{0}\gets0,,\delta_{0}\gets((1,g),n_{0}) $$

$$ \mathrm {s t} _ {0} \leftarrow g $$

StrgNode*:* AddStorage(;n; st*;I;FI;Q;FQ;Q)!* (st⁰*;J;*FJ)aggregates the parameters and the opening proofs

$$ \therefore \mathrm {A d d S t o r a g e} (\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, Q, \mathrm {F} _ {Q}, \pi_ {Q}) \rightarrow \left(\mathrm {s t} ^ {\prime}, J, \mathrm {F} _ {J}\right) $$

$$ S_{I\cup Q}\leftarrow\mathbf{S h a m i r}\mathbf{T r i c k}(S_{I},S_{Q},\prod_{l\in I}e_{i},\prod_{l\in Q}e_{i})\ \mathrm{a n d}\ A_{I\cup Q}\leftarrow\mathsf{V C}A g g((S_{I},S_{J}),(I,\mathsf{F}{I},A{I}),(J,\mathsf{F}{J},A{J})) $$

StrgNode*:* RmvStorage(;n; st*;I;FI;K*)! (st⁰*;J;*FJ)disaggregates

$$ S_{J}\leftarrow S_{I}^{\prod_{i\in I\cap K}e_{i}}\ \ {\ {\mathrm{}{a n d}}}\ \varLambda_{J}\leftarrow{\ \ \mathsf{V C.D i s a g g}}(S_{J},I,\ \mathsf{F}{I},\varLambda{I},J) $$

0 0J StrgNode*:* PushUpdate(;n; st*;I;FI;op;)!* (;n⁰;st⁰;J;F;)the algorithm works according to the type of update operation op: 0K { op = mod: := (*K;*F).

$$ \flat,\mathsf{P u s h U p d a t e}(\delta,n,\mathsf{s t},I,\mathsf{F}{I},\mathsf{o p},\varDelta)\to(\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}{J}^{\prime},\varUpsilon_{\varDelta}) $$

$$

$$ C^{\prime}\leftarrow C\cdot\prod_{i\in K}s_{i}^{\mathsf{F}{i}^{\prime}-\mathsf{F}{i}},\qquad U^{\prime}\leftarrow U,\qquad\varLambda_{I}^{\prime}\leftarrow\varLambda_{I},\qquad S_{I}^{\prime}\leftarrow S_{I}\qquad\varUpsilon_{\varDelta}\leftarrow(\mathsf{F}{K},S{K}) $$

$$ -\ {\mathsf{o0p}}={\mathsf{a d d}}:\varDelta:=(big,K,\ \mathsf{F}_{K}^{\prime}\big). $$

$$ C ^ {\prime} \leftarrow C \cdot \prod_ {j \in K} S _ {j} ^ {\mathsf {F} _ {j}}, \quad U ^ {\prime} \leftarrow U ^ {\Pi_ {i \in K} e _ {i}}, \quad \Lambda_ {I} ^ {\prime} \leftarrow \Lambda_ {I}, \quad S _ {I} ^ {\prime} \leftarrow S _ {I}, \quad \Upsilon_ {\Delta} \leftarrow S _ {K} $$

$$

$$ C ^ {\prime} \leftarrow \frac {C}{\prod_ {j \in K} S _ {j} ^ {\mathsf {F} _ {j}}}, \quad U ^ {\prime} \leftarrow S _ {I} ^ {\prod_ {i \in I \backslash K} e _ {i}} = S _ {K}, \quad \Lambda_ {I} ^ {\prime} \leftarrow \Lambda_ {I} ^ {\prod_ {j \in K} e _ {j}}, \quad S _ {I} ^ {\prime} \leftarrow S _ {I}, \quad \gamma_ {\Delta} \leftarrow (\mathsf {F} _ {K}, S _ {K}) $$

0 0J StrgNode*:* ApplyUpdate(;n; st*;I;FI;op;;)!* (*b;;n⁰;st⁰;J;*F)Again, it works according to the type of update operation op: Q

$$ {\sf p l y U p d a t e}(\delta,n,{\sf s t},I,\mathsf{F}{I},{\sf o p},\varDelta,\varUpsilon{\varDelta})\to(b,\delta^{\prime},n^{\prime},{\sf s t}^{\prime},J,\mathsf{F}_{,J}^{\prime}) $$

j2Kej 0K { op = mod: := (*K;*F) and := SK. Compute b (S = U) and if b = 1: K

$$ b\gets(S_{K}^{\prod_{j\in K}e_{j}}=U) $$

$$ \varDelta:=(K,\mathsf{F}_{K}^{\prime}) $$

$$ \ T{\ }!:=\ S{}_{K} $$

$$ b=1 $$

$$ C^{\prime}\leftarrow C\cdot\prod_{i\in K}S_{i}^{\mathsf{F}{i}^{\prime}-\mathsf{F}{i}},\quad U^{\prime}\leftarrow U,\quad A_{I}^{\prime}\leftarrow\varLambda_{I}\cdot\prod_{j\in K\setminus I}\left(S_{j}^{1/\prod_{i\in I}e_{i}}\right)^{\mathsf{F}{j}^{\prime}-\mathsf{F}{j}},:S_{I}^{\prime}\leftarrow S_{I} $$


$$ -\mathrm{o p}=\mathsf{a d d}\ \varDelta:=(K,\mathsf{F}_{K}^{\prime}){\mathrm{a n d}}\varUpsilon_{A}:=S_{K}.\ {\mathrm{C o m p u t e}}b\leftarrow(S_{K}^{\prod_{j\in K}e_{j}}=U){\mathrm{a n di f~}}b=1. $$

$$ C ^ {\prime} \leftarrow C \cdot \prod_ {j \in K} S _ {j} ^ {\mathsf {F} _ {j}}, \quad U ^ {\prime} \leftarrow U ^ {\Pi_ {i \in K} e _ {i}}, \quad \Lambda_ {I} ^ {\prime} \leftarrow \Lambda_ {I} \cdot \prod_ {j \in K} \left(S _ {j} ^ {1 / \Pi_ {i \in I} e _ {i}}\right) ^ {\mathsf {F} _ {j}}, \quad S _ {I} ^ {\prime} \leftarrow S _ {I} ^ {\Pi_ {i \in K} e _ {i}} $$

Q 1= eiQ i2I where S = ShamirTrick(SI;Sj; ei;ej) for each j 2 K. j i2I Q e

$$ \begin{array}{l}{S_{j}^{1/\prod_{i\in I}e_{i}}=\mathbf{S h a m i r T r i c k}(S_{I},S_{j},\prod_{i\in I}e_{i},e_{j})}\ \end{array} $$

$$ j\in K $$

$$ -\mathrm{\sfo p}=\mathsf{d e l}\ \ varDeltaDelta:K K\ \mathrm an var\ var{}{\Delta}:=(\mathsf{F}{K},S_{K}).\ \mathrm{C o n p u t e}\ b\leftarrow(S_{K}^{\prod_j in K K}e_{j}=U)\ \mathrm{a n d~i f}\ b=1 $$

$$ \begin{aligned}{}&{{}C^{\prime}\leftarrow\frac{C}{\prod_{j\in K}s_{j}^{\mathsf{F}{j}}},\qquad U^{\prime}\leftarrow S{K},}\ {}&{{}A_{I}^{\prime}\leftarrow\frac{\Lambda_{I}^{\prod_{i\in K\cap I}e_{i}}}{\prod_{j\in K\cap I}\left(S_{j}^{1}\prod_{i\in K\cap I}e_{i}\right)^{\mathsf{F}{j}}},\qquad S{I}^{\prime}\leftarrow\mathbf{S h a m i r T r i c k}(S_{I},S_{K\setminus I},\prod_{i\in I}c_{i},\prod_{i\in K\backslash I}e_{i})}\ \end{aligned} $$

StrgNode*:* Retrieve(;n; st*;I;FI;Q*)! (FQ;Q)disaggregates

$$ (\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, Q) \rightarrow (\mathrm {F} _ {Q}, \pi_ {Q}) $$

$$ S_{Q}\leftarrow S_{I}^{\prod_{i\in I\setminus Q}e_{i}}\ \ {operatorname a n n}\ \varLambda_{Q}\leftarrow\ \mathsf{V C}D i s a g g(S_{Q},I,\mathsf{F}{I},\varLambda{I},Q) $$

The algorithms for client nodes are:

ClntNode*:* VerRetrieve(;Q;FQ;Q)! b output

$$ (left(\delta,Q,\mathsf{F}{Q},\pi{Q})\to b $$

$$ b\leftarrow\mathsf{V C.V e r}(\mathsf{p p},C,Q,\mathsf{F}{Q},\varLambda{Q})\wedge S_{Q}^{\prod_{i\in Q}e_{i}}=U $$

$$ (\delta,n,\mathsf{s t},I,\mathsf{F}{I},\mathsf{o p},\varDelta,\varUpsilon,\varUpsilon{\varDelta}) $$

AggregateCerticates(; (I;FI;I); (J;FJ;J))!Kreturn

$$ \left(\delta,(I,\mathsf{F}{I},\pi{I}),(J,\mathsf{F}{J},\pi{J})\right)\to\pi_{K} $$

$$ S _ {I \cup J} \leftarrow \operatorname {S h a m i r T rick} \left(S _ {I}, S _ {J}, \prod_ {i \in I} e _ {i}, \prod_ {i \in J} e _ {i}\right) \text {a n d} \Lambda_ {K} \leftarrow \mathrm {V C}. \mathrm {A g g} \left((S _ {I}, S _ {J}), (I, \vec {\mathbf {F}} _ {I}, \Lambda_ {I}), (J, \vec {\mathbf {F}} _ {J}, \Lambda_ {J})\right) $$

We note that we do not dene an ecient StrgNode*:* CreateFrom operation for the VDS₂ construction. While general-purpose SNARKs would work to achieve this result, they would be extremely expensive. We leave it as an open problem to nd an ecient arguments of knowledge of subvector opening for this scheme.

$$ \mathsf{V D S_{2}} $$

Theorem 8.3(VDS₂). Let G Ggen(1 ) be a hidden order group where the strong Distinct- Prime-Product Root and the Low Order assumptions hold. Then the VDS scheme presented above is a correct and secure Veriable Decentralized Storage scheme.

$$ \mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda}) $$

$$ (\mathsf{V D S}_{2}) $$

The intuition of the above theorem is as follows: the VDS scheme can be seen as preserving and updating a vector commitment C and an RSA Accumulator U. So correctness of VDS comes from correctness of the updatable vector commitment SVC and correctness of updates of the RSA Accumulator (see [BBF19]). Similarly, security comes from security of SVC and the RSA accumulator’s security, which in turn rely on the strong distinct-prime-product root assumption and the strong RSA assumption respectively. Note that strong Distinct-Prime-Product Root implies strong RSA (the opposite also holds in RSA groups).

Recall that U is an RSA accumulator of all ei’s and is used to verify SI’s. The RSA accumulator’s security demands that the accumulated value U is honestly computed, which is ensured in the VDS setting since we assume a valid history. So given a valid history one knows thatQU is of correct i2[n]ei form (i.e. U = g) and then can securely check that SIis of correct form (by checking Q i2Iei S = U), which is ensured from RSA Accumulator’s security. After checking the validity of I SIit all boils down to position binding of the vector commitment. To conclude, the gap between position binding of the original VC and security of our VDS construction is to ensure that SIis well formed, which in turn relies on the correct form of U.

$$ S_{I},^{\prime}\mathrm{S} $$

$$ e_{i} $$

$$ S_{I} $$

$$ U,=,g^{\prod_{i\in[n]}e_{i}}) $$

$$ S_{I}^{\prod_{i\in I}e_{i}}=U] $$

$$ S_{I} $$

$$ S_{I} $$

$$ U $$

8.3 Eciency and Comparison

In Table3we provide a detailed eciency analysis and comparison of the two VDS schemes, VDS₁ and VDS₂, proposed in the two earlier sections.

$$ \mathsf{V D S}_{1} $$

$$ \mathsf{V D S_{2}} $$

In terms of performances, the two schemes do similarly, though VDS₂ outperforms the rst one by a logarithmic factor. Its eciency advantage comes from the fact that operations are not bit-bybit as in the rst one. More in detail, in VDS₁ most of the operations require one exponentiation with an-bit prime for each bit and each position of the suble, roughly O(‘ jIj) group operations. In VDS₂, the main overhead is related to handling the distributed parameters fSig. In fact, computing Sifor each i 2 I, given SItakes O(I log jIj) exponentiations with (‘ + 1)-bit primes, roughly O(‘ jIj log jIj) group operations.

$$ \mathsf{V D S_{2}} $$

$$ \mathsf{V D S}_{1} $$

$$ O(\ell,\cdot,|I|,\cdot,\alpha) $$

$$ \mathrm {V D S} _ {2} $$

$$ \left{S_{i}\right} $$

$$ i\in I $$

$$ S_{I} $$

$$ O(I\log|I|) $$

$$ O(\ell\cdot|left|I|\cdot\log|I|) $$

To compare the two methods, recall that is at least log(‘n) (since we need at least ‘n distinct primes), which means that VDS₁ has a (logarithmic) dependence on the size of the le. On the other hand, VDS₂’s cost depends only on the size of the suble that is processed. Hence, since > log(‘n) > log(n) log(jIj) the VDS₂ always outperforms VDS₁ (see Table3).

$$ \alpha $$

$$ \log(\ell n) $$

$$ \mathsf{V D S_{1}} $$

$$ \mathsf{V D S_{2}} $$

$$ a>\log(\ n)>\log(n)\geq\log(\ \ I $$

$$ \mathsf{V D S}_{1} $$

$$ \mathsf{V D S_{2}} $$

Another notable dierence regards the StrgNode*:* PushUpdate algorithm for op = mod. In VDS₂, the running time depends solely on the size of the update, whereas in VDS₁ it depends on the size of the entire suble stored locally. This can be a huge dierence for nodes that decide to store large portions, and it constitutes a major theoretical (and practical) improvement of VDS₂ over VDS₁.

$$ {\mathsf{o p}}={\mathsf{m o d}} $$

$$ \mathsf{V D S_{2}} $$

$$ \mathsf{V D S_{1}} $$

$$ \mathsf{V D S_{2}} $$

$$ \mathsf{V D S_{1}} $$

In terms of security, VDS₁ is based on a weaker assumption, over groups of unknown order, than VDS₂ (although for the specic case of RSA groups the two assumptions are equivalent). Finally, in terms of functionality, VDS₁ is the only scheme that supports eciently the StrgNode*:* CreateFrom functionality and the (compact) Proofs of Data Possession; this is thanks to its compatibility with the ecient succinct arguments of knowledge that we propose in section6.

$$ \mathsf{V D S}_{1} $$

$$ \mathsf{V D S_{2}} $$

$$ \mathsf{V D S_{1}} $$


Metric VDS1 VDS2
Bootstrap O(1) O(1)
pp
Digest δ
Storage Node storing(I,FI)
State stI
StrgNode.AddStorage(K) O(λ·α·( I
StrgNode.RmvStorage(K) O(λ·α· K
StrgNode.CreateFrom(J) O(λ·α· I
YJ
mod O(λ·α· I
add O(λ·α· Δ
del O(λ·α·( I
YΔ
mod,del ∅ 1
add O(λ·α·( I
mod O(λ·α·( I
add O(λ·α·( I
del O(λ·α·( I
StrgNode.Retrieve(Q) O(λ·α·( I
πQ
Client Node
CIntNode.GetCreate(J) O(λ·α· J
CIntNode.VerRetrieve(Q) O(λ·α· Q
CIntNode.ApplyUpdate(Δ)(mod,add,del) O(λ·α· Δ
AggregateCertificates(I,J) O(λ·α·( I
PoR yes yes
PDP yes no1

$$ \mathsf{V D S_{1}} $$

$$ \mathsf{V D S_{2}} $$

$$ O(1) $$

$$ O(1) $$

$$ 3\mid mathbb G $$

$$ 1\mid mathbb G $$

$$ 2\ |\mathbb{G}|+\log|\mathsf{F}| $$

$$ 2\ |\mathbb{G}|+\log|\mathbb{F}| $$

$$ (I,\mathsf{F}_{I}) $$

$$ 2\mid|\mathbb{G}| $$

$$ 2\mid mathbb G $$

$$ O\big(\ell\cdot\alpha\cdot(|I|+|K|)\big) $$

$$ O(\ell\cdot\ (|I|\log|I|+|K|\log|K|),) $$

$$ O(\ell\cdot\alpha\cdot|K|) $$

$$ O(\ell\cdot|K|\log|K|) $$

$$ O(\ell\cdot\alpha\cdot|I|) $$

$$ |T_{J}| $$

$$ 9\ |\mathbb{G}|+2\ |\mathbb{Z}_{2^{\lambda}}| $$

$$ \mathrm {n o} ^ {1} $$

$$ O(\ell\cdot\alpha\cdot|I|) $$

$$ O \left(\ell \cdot | \Delta | \log | \Delta |\right) $$

$$ O(\ell\cdot\alpha\cdot|\varDelta|) $$

$$ O(\ell\cdot|\varDelta|\log|\varDelta)| $$

$$ O \left(\ell \cdot \alpha \cdot \left(| I | - | \Delta |\right)\right) $$

$$ O \left(\ell \cdot \left(| I | - | \Delta | + | \Delta | \log | \Delta |\right)\right) $$

$$ O(|\varDelta|)+2\cdot|\mathbb{G}| $$

$$ O(|\varDelta|)+1\cdot|\mathbb{G}| $$

$$ \left| \gamma_ {\Delta} \right| $$

$$ O \left(\ell \cdot \alpha \cdot \left(| I | + | \Delta |\right)\right) $$

$$ \overline{{O(\ell\cdot(|I|+|\varDelta|\log|\varDelta|)}}) $$

$$ O(\ell\cdot\alpha\cdot|\varDelta|) $$

$$ O(\ell\cdot(|I|+|\varDelta|\log|\varDelta|)) $$

$$ O \left(\ell \cdot \alpha \cdot \left(| I | + | \Delta |\right)\right) $$

$$ O \left(\ell \cdot \left(| I | + | \Delta | \log | \Delta |\right)\right) $$

$$ O\big(\ell\cdot\alpha\cdot\big( vert I|\ -\vert Q\vert\big)\big) $$

$$ O(\ell\cdot\ (left|{I}|-|{Q}|)\log\bigl(|{I}|-|{Q}|)\bigr) $$

$$ \mathrm{no~}^{1} $$

$$ O(\ell\cdot\alpha\cdot|J|) $$

$$ O(\ell\cdot\alpha\cdot|Q|) $$

$$ O(\ell\cdot|Q|\operatorname{l o g}|Q|) $$

$$ O(\ell\cdot\alpha\cdot|\varDelta|) $$

$$ O(\ell\cdot|\varDelta|\operatorname{l o g}|\varDelta|) $$

$$ O\big(\ell\cdot\alpha\cdot\ (|I|+|J|)\big) $$

$$ O(\ell\cdot\left(\left|I\right|!{0}!{!}^{!{\mathfrak{g}}}\left|I\right|+\left|J\right|!{0}!{!}{!{\mathfrak{g}}}\left|J\right|\right)) $$

$$ \mathrm{y e s} $$

$$ \mathrm{no~}^{1} $$

Table 3. Comparison between our two VDS schemes. The running time is expressed in number of G-group operations. Notation for the sets of positions: I are the ones held by the storage node, K the ones added or removed from local storage by the storage node, J the ones used to create the le in StrgNode*:* CreateFrom, the updated ones, and Q the ones of a retrieval query. In VDS₁, denotes the size of the primes (returned by PrimeGen); so ‘ n log(n‘) where n is the size of the le and ‘ the bit-size of each position (i.e. F 2 (f0*;* 1g)).

$$ \ \mathsf{V D S_{1}}. $$

$$ \alpha\geq\log(n\ell) $$

$$ \mathsf{F}\in({0,1}^{\ell})^{n}) $$

1 Such a protocol exists but it is either inecient for the prover (SNARKs) or it has a large overhead in communication complexity (-protocols or PoKE -based ones).

9 Experimental Evaluation

We have implemented in Rust our new SVC scheme of section5.1(with and without preprocessing) and the recent SVC of [BBF19] (referred as BBF in what follows). Here we discuss an experimen-


23 tal evaluation of these three schemes. Below is a summary of the comparison, details of the experiments are in AppendixF.

{ Our SVC construction is faster in opening and verication than BBF (up to 2*:* 5 and 2*:* 3 faster respectively), but at the cost of a slower commitment stage (up to 6 slower). These dierences tend to atten for larger vectors and opening sizes.

{ Our SVC construction with preprocessing allows for extremely fast opening times compared to non-preprocessing constructions. Namely, it can reduce the running time by several orders of magnitude for various choices of vector and opening sizes, allowing to obtain practical opening times|of the order of seconds|that would be impossible without preprocessing|of the order of 20 hundred of seconds. In a le of 1 Mibit (2 bits), preprocessing reduces the time to open 2048 bits from one hour to less than 5 seconds! This ecient opening, however, comes at the cost of a one-time preprocessing (during commitment) and higher storage requirements. We discuss how to mitigate these space requirements by trading for opening time and/or communication complexity later in this section. We stress that it is thanks to the incremental aggregation property of our construction that allows these tradeos (they are not possible in BBF with preprocessing).

$$ \ 2^{20} $$

{ Although our SVC construction with preprocessing has an expensive commitment stage, this tends to be amortized throughout very few openings²⁴, as few as 30 (see Figure9in AppendixF). These eects are particularly signicant over a higher number of openings: over 1000 openings our SVC construction with preprocessing has an amortized cost of less than 6 seconds, while our SVC construction and BBF have amortized openings above 90 seconds.

Mitigating Space Requirements for Preprocessing Construction The experiments illustrated so far show the benet of using preprocessing to speedup opening time. This comes at the cost of storing an auxiliary information|N openings|which, in spite of being much smaller than in BBF, can still be quite large. Here we discuss two ways to mitigate this storage cost, which can be used either separately or together.

{Hashing in blocks. Let us recall that by selecting a block size ‘ = 2 (e.g., 256) one can combine our VC with a collision-resistant hash function and support larger vectors at virtually the same cost. Concretely, given a vector ~v of N blocks, each of ‘Hbits, one can obtain a vector ‘ N ~v⁰ 2 (f0*;* 1g) by hashing each ‘H-bits block into a ‘-bits one. The downside of this approach is that subvector openings with respect to the original vector ~v are less ne grained. On the good side, though, one gets that the eciency of a VC for a vector of size N ‘His virtually the same²⁵ as the one for a VC for a vector of size N 2. For example, by selecting ‘H= 2 Kibit our timings for a vector of 262 144 bits would work for one of 1 Mibit. This would yield a committing/preprocessing time of roughly 10 minutes. These advantages also translate opening times: for example, if we 11 expect openings of roughly M = 2 bits we can expect a virtually instantaneous opening time 14 (as we just need to look up a cached precomputed proof). A larger opening size such as M = 2 17 (resp. M = 2) bits, would yield a running time of roughly 4 seconds (resp. 70 seconds).

$$ \ell_{H} $$

$$ \vec{v}^{\prime}\in({0,1}^{\ell})^{N} $$

$$ \ell_{H} $$

$$ \vec{v} $$

$$ N!\cdot!\ell_{H} $$

$$ \ell_{H}=2;\mathrm{K i b i t} $$

$$ M=2^{11} $$

$$ M=2^{14} $$

$$ M=2^{17}) $$

23 We did not include BBF with precomputation in our experimental evaluation because this scheme has worse performances than our preprocessing construction in terms of both required storage and running time. We elaborate on this in AppendixF

24 Amortized opening time roughly represents how computationally expensive a scheme is \in total" throughout all its operations. Amortized opening time for m openings is the cost of one commitment plus the cost of m openings, all averaged over the m openings.

25 This is because the cost of hashing is negligible compared to group operations.


{Selecting larger precomputed chunks. Another possibility to reduce storage is to precompute less openings by storing more aggregated openings, namely instead of an opening for every chunk of ‘ bits, store one opening for every chunk of B ‘ bits. This technique requires a bit more computation in order to compute disaggregations|about m(B 1) G operations in the worst case for m positions (cf. SectionB)|but opens the way to various tradeos to be explored. For instance, one could use certain application-dependent heuristics to choose which positions to precompute aggregated. As an example in the VC application to proofs of space and replication [Fis19] one opens a set of randomly chosen positions, and for each of them, also a set of 26 predetermined positions.

predetermined positions. 26

Acknowledgements

We thank Ben Fisch for valuable clarications about the notions of Proof of Retrievable Commitment and Proof of Replication, and Justin Drake for pointing out the need (due to the attack discussed in [BBF18]) of using a hash function mapping into Primes(2) in the Fiat-Shamir transformation when making our succinct arguments of knowledge non-interactive.

Research leading to these results has been partially supported by the Spanish Government under projects SCUM (ref. RTI2018-102043-B-I00), CRYPTOEPIC (refs. ERC2018-092822, EUR2019- 103816), and SECURITAS (ref. RED2018-102321-T), by the Madrid Regional Government under project BLOQUES (ref. S2018/TCS-4339), and by research gifts from Protocol Labs.

References

+ ABC 07.G. Ateniese, R. C. Burns, R. Curtmola, J. Herring, L. Kissner, Z. N. J. Peterson, and D. Song. Provable data possession at untrusted stores. In P. Ning, S. De Capitani di Vimercati, and P. F. Syverson, editors, ACM CCS 2007, pages 598{609. ACM Press, October 2007. + ABC 11.G. Ateniese, R. Burns, R. Curtmola, J. Herring, O. Khan, L. Kissner, Z. Peterson, and D. Song. Remote Data Checking Using Provable Data Possession. ACM Trans. Inf. Syst. Secur., 14(1):12:1{12:34, June 2011. BBF18.D. Boneh, B. Bunz, and B. Fisch. A Survey of Two Veriable Delay Functions. Cryptology ePrint Archive, Report 2018/712, 2018. https://eprint.iacr.org/2018/712. BBF19.D. Boneh, B. Bunz, and B. Fisch. Batching Techniques for Accumulators with Applications to IOPs and Stateless Blockchains. In A. Boldyreva and D. Micciancio, editors, CRYPTO 2019, Part I, volume 11692 of LNCS, pages 561{586. Springer, Heidelberg, August 2019. BCS16.E. Ben-Sasson, A. Chiesa, and N. Spooner. Interactive Oracle Proofs. In M. Hirt and A. D. Smith, editors, TCC 2016-B, Part II, volume 9986 of LNCS, pages 31{60. Springer, Heidelberg, October / November 2016. Bd94.J. C. Benaloh and M. de Mare. One-Way Accumulators: A Decentralized Alternative to Digital Sinatures (Extended Abstract). In T. Helleseth, editor, EUROCRYPT’93, volume 765 of LNCS, pages 274{285. Springer, Heidelberg, May 1994. BGR12.K. Brogle, S. Goldberg, and L. Reyzin. Sequential Aggregate Signatures with Lazy Verication from Trapdoor Permutations - (Extended Abstract). In X. Wang and K. Sako, editors, ASIACRYPT 2012, volume 7658 of LNCS, pages 644{662. Springer, Heidelberg, December 2012. BGV11.S. Benabbas, R. Gennaro, and Y. Vahlis. Veriable Delegation of Computation over Large Datasets. In P. Rogaway, editor, CRYPTO 2011, volume 6841 of LNCS, pages 111{131. Springer, Heidelberg, August 2011. BH01.J. Buchmann and S. Hamdy. A Survey on fIQg Cryptography, 2001. BP97.N. Bari and B. Ptzmann. Collision-Free Accumulators and Fail-Stop Signature Schemes Without Trees. In W. Fumy, editor, EUROCRYPT’97, volume 1233 of LNCS, pages 480{494. Springer, Heidelberg, May 1997. 26 There, each vector entry is the node of a DAG and one opens a set of randomly chosen nodes and for each of them

a given number of parents.


CF13.D. Catalano and D. Fiore. Vector Commitments and Their Applications. In K. Kurosawa and G. Hanaoka, editors, PKC 2013, volume 7778 of LNCS, pages 55{72. Springer, Heidelberg, February / March 2013. CL02.J. Camenisch and A. Lysyanskaya. Dynamic Accumulators and Application to Ecient Revocation of Anonymous Credentials. In M. Yung, editor, CRYPTO 2002, volume 2442 of LNCS, pages 61{76. Springer, Heidelberg, August 2002. CMS99.C. Cachin, S. Micali, and M. Stadler. Computationally Private Information Retrieval with Polylogarithmic Communication. In J. Stern, editor, EUROCRYPT’99, volume 1592 of LNCS, pages 402{414. Springer, Heidelberg, May 1999. CS99.R. Cramer and V. Shoup. Signature Schemes Based on the Strong RSA Assumption. In J. Motiwalla and G. Tsudik, editors, ACM CCS 99, pages 46{51. ACM Press, November 1999. CSWH01.I. Clarke, O. Sandberg, B. Wiley, and T. W. Hong. Freenet: A Distributed Anonymous Information Storage and Retrieval System, pages 46{66. Springer Berlin Heidelberg, Berlin, Heidelberg, 2001. DG20.S. Dobson and S. D. Galbraith. Trustless Groups of Unknown Order with Hyperelliptic Curves. Cryptology ePrint Archive, Report 2020/196, 2020. https://eprint.iacr.org/2020/196. DK02.I. Damgard and M. Koprowski. Generic Lower Bounds for Root Extraction and Signature Schemes in General Groups. In L. R. Knudsen, editor, EUROCRYPT 2002, volume 2332 of LNCS, pages 256{271. Springer, Heidelberg, April / May 2002. Fis18.B. Fisch. PoReps: Proofs of Space on Useful Data. Cryptology ePrint Archive, Report 2018/678, 2018. https://eprint.iacr.org/2018/678. Fis19.B. Fisch. Tight Proofs of Space and Replication. In Y. Ishai and V. Rijmen, editors, EUROCRYPT 2019, Part II, volume 11477 of LNCS, pages 324{348. Springer, Heidelberg, May 2019. FS87.A. Fiat and A. Shamir. How to Prove Yourself: Practical Solutions to Identication and Signature Problems. In A. M. Odlyzko, editor, CRYPTO’86, volume 263 of LNCS, pages 186{194. Springer, Heidelberg, August 1987. GHR99.R. Gennaro, S. Halevi, and T. Rabin. Secure Hash-and-Sign Signatures Without the Random Oracle. In J. Stern, editor, EUROCRYPT’99, volume 1592 of LNCS, pages 123{139. Springer, Heidelberg, May 1999. + GKM 18.J. Groth, M. Kohlweiss, M. Maller, S. Meiklejohn, and I. Miers. Updatable and Universal Common Reference Strings with Applications to zk-SNARKs. In H. Shacham and A. Boldyreva, editors, CRYPTO 2018, Part III, volume 10993 of LNCS, pages 698{728. Springer, Heidelberg, August 2018. GRWZ20.S. Gorbunov, L. Reyzin, H. Wee, and Z. Zhang. Pointproofs: Aggregating Proofs for Multiple Vector Commitments. Cryptology ePrint Archive, Report 2020/419, 2020. https://eprint.iacr.org/2020/419. JK07.A. Juels and B. S. Kaliski Jr. Pors: proofs of retrievability for large les. In P. Ning, S. De Capitani di Vimercati, and P. F. Syverson, editors, ACM CCS 2007, pages 584{597. ACM Press, October 2007. KZG10.A. Kate, G. M. Zaverucha, and I. Goldberg. Constant-Size Commitments to Polynomials and Their Applications. In M. Abe, editor, ASIACRYPT 2010, volume 6477 of LNCS, pages 177{194. Springer, Heidelberg, December 2010. Lab17.P. Labs. Filecoin: A Decentralized Storage Network, 2017. https://filecoin.io/filecoin.pdf. Lip12.H. Lipmaa. Secure Accumulators from Euclidean Rings without Trusted Setup. In F. Bao, P. Samarati, and J. Zhou, editors, ACNS 12, volume 7341 of LNCS, pages 224{240. Springer, Heidelberg, June 2012. LM19.R. W. F. Lai and G. Malavolta. Subvector Commitments with Application to Succinct Arguments. In A. Boldyreva and D. Micciancio, editors, CRYPTO 2019, Part I, volume 11692 of LNCS, pages 530{560. Springer, Heidelberg, August 2019. LMRS04.A. Lysyanskaya, S. Micali, L. Reyzin, and H. Shacham. Sequential Aggregate Signatures from Trapdoor Permutations. In C. Cachin and J. Camenisch, editors, EUROCRYPT 2004, volume 3027 of LNCS, pages 74{90. Springer, Heidelberg, May 2004. LRY16.B. Libert, S. C. Ramanna, and M. Yung. Functional Commitment Schemes: From Polynomial Commitments to Pairing-Based Accumulators from Simple Assumptions. In I. Chatzigiannakis, M. Mitzenmacher, Y. Rabani, and D. Sangiorgi, editors, ICALP 2016, volume 55 of LIPIcs, pages 30:1{30:14. Schloss Dagstuhl, July 2016. LY10.B. Libert and M. Yung. Concise Mercurial Vector Commitments and Independent Zero-Knowledge Sets with Short Proofs. In D. Micciancio, editor, TCC 2010, volume 5978 of LNCS, pages 499{517. Springer, Heidelberg, February 2010. Mer88.R. C. Merkle. A Digital Signature Based on a Conventional Encryption Function. In C. Pomerance, editor, CRYPTO’87, volume 293 of LNCS, pages 369{378. Springer, Heidelberg, August 1988. OWB19.A. Ozdemir, R. S. Wahby, and D. Boneh. Scaling Veriable Computation Using Ecient Set Accumulators. Cryptology ePrint Archive, Report 2019/1494, 2019. https://eprint.iacr.org/2019/1494.


Sha83.A. Shamir. On the Generation of Cryptographically Strong Pseudorandom Sequences. ACM Trans. Comput. Syst., 1(1):38{44, 1983. STY01.T. Sander, A. Ta-Shma, and M. Yung. Blind, Auditable Membership Proofs. In Y. Frankel, editor, FC 2000, volume 1962 of LNCS, pages 53{71. Springer, Heidelberg, February 2001. + TAB 20.A. Tomescu, I. Abraham, V. Buterin, J. Drake, D. Feist, and D. Khovratovich. Aggregatable Subvector Commitments for Stateless Cryptocurrencies. Cryptology ePrint Archive, Report 2020/527, 2020. https: //eprint.iacr.org/2020/527. Tam03.R. Tamassia. Authenticated Data Structures. In G. Di Battista and U. Zwick, editors, Algorithms - ESA 2003, pages 2{5, Berlin, Heidelberg, 2003. Springer Berlin Heidelberg. Wes18.B. Wesolowski. Ecient veriable delay functions. Cryptology ePrint Archive, Report 2018/623, 2018. https://eprint.iacr.org/2018/623.

A PoProd protocol for Union of RSA Accumulators

Let G be a an hidden order group as generated by Ggen, and let g₁;g₂;g₃ 2 G be three honestly sampled random generators. A more straightforward succinct argument of knowledge for the union of RSA Accumulators is for the following relation

$$ g_{1},g_{2},g_{3}\in\mathbb{G} $$

$$ R_{\mathsf{P o P r o d}}=\left{((A,B,C),(a,b))\in\mathbb{G}^{3}\times\mathbb{Z}^{2}:::A=g_{1}^{a}\wedge B=g_{2}^{b}\wedge C=g_{3}^{a\cdot b}::\right} $$

Our protocol PoProd is described below.

PoProd protocol

Setup(1 ) : run G $ Ggen(1 ), g₁;g₂;g₃ $ G, set crs := (G*;g₁;g₂;g₃*). Prover’s input: (crs*;* (A;B;C); (a;b)). Verier’s input: (crs*;* (A;B;C)). V! P: ‘ $ Primes() P! V: := ((QA;QB;QC);ra;rb) computed as follows { (qa;qb;qc) (ba=‘c; bb=‘c; bab=‘c) { (ra;rb) (a mod ‘;b mod ‘) qa qbqc { (QA;QB;QC) := (g₁;g₂;g₃) V(crs; (A;B;C);‘;): { Compute rcrarbmod ‘ ‘ ra ‘ rb ‘ rc { Output 1 i ra;rb2 [‘] ^ Q g₁ = A ^ Q g₂ = B ^ Q g₃ = C A B C

$$ \mathtt{S e t u p}(1^{\lambda})\ \colon{\tt r u n}\ \mathbb{G}\hookleftarrow\mathtt{G g e n}(1^{\lambda}),;g_{1},g_{2},g_{3}\hookleftarrow\mathtt{G},;{\tt s e t}\ {\tt c r s}:=(\mathbb{G},g_{1},g_{2},g_{3}). $$

$$ (\mathsf{c r s},(A,B,C),(a,b)) $$

$$ (mathsf c r r,(A,B,C)) $$

$$ \underline{{\mathsf{V}}\to\mathsf{P}}:\ell\leftarrow\mathfrak{S}P\ m e s(\lambda) $$

$$ \underline {{\mathrm {P} \rightarrow \mathrm {V}}}: \pi := \left(\left(Q _ {A}, Q _ {B}, Q _ {C}\right), r _ {a}, r _ {b}\right) $$

$$ -\ (q_{a},q_{b},q_{c})\leftarrow(\lfloor a/\ell\rfloor,\lfloor b/\ell\rfloor,\lfloor a b/\ell\rfloor) $$

$$

$$ -\ (Q_{A},Q_{B},Q_{C}):=(g_{1}^{q_{a}},g_{2}^{q_{b}},g_{3}^{q_{c}}) $$

$$ \mathsf{V}(\mathsf{c r s},(A,B,C),\ell,\pi) $$

$$

To prove the security of our protocol we rely on the adaptive root assumption and, in a nonblack-box way, on the knowledge extractability of the PoKE protocol from [BBF19]. The latter is proven in the generic group model for hidden order groups (where also the adaptive root assumption holds).

$$ \mathsf{P o K E}^{*} $$

Theorem A.1. The PoProd protocol is an argument of knowledge for RPoProdin the generic group model.

$$ R_{\mathsf P o\mathsf P r d} $$

The proof is quite similar to the one of theorem5.1only instead of using the extractor if PoKRep a b protocol we use the extractors of two PoKE protocols (one for g₁ = A and one for g₂ = B).

$$ \mathsf{P o K E}^{*} $$

$$ g_{1}^{a}=A $$

$$ g_{2}^{b}=B boldsymbol{} $$


B Committing and Opening with Precomputation for the [BBF19] SVC

We discuss how the preprocessing technique can also be applied to the SVC scheme of [BBF19] (instantiated for binary vectors of length n = N‘). In this case, however, we will not use the incremental disaggregation and aggregation but only one-hop aggregation. Q

$$ n,=,N\ell,) $$

n b Let us recall that in [BBF19] a commitment to ~v 2f0*;* 1g is Acc = g with b = pj. j2[n];vj=1 When asked for opening of some positions in the set I, the vector owner has to provide a batched membership proof for all fpj: j = (i 1)‘ +l;i 2 I;l 2 [‘];vj= 1g and a batched non-membership proof for all fpj: j = (i 1)‘ + l;i 2 I;l 2 [‘];vj= 0g.

$$ \vec{v}\in{0,1}^{n} $$

$$ A c c=g^{b} $$

$$ b=\prod_{j\in[n],v_{j}=1}p_{j}. $$

$$ {p_{j}:j=(i-1)\ell+l,i\in I,l\in[\ell],v_{j}=1} $$

$$ {p_{j}:j=(i-1)\ell+\mathfrak{l},i\in I,l\in[\ell],v_{j}=0} $$

For the membership proofs, we can use ideas similar to the ones discussed earlier. In the com- Q b=bi mitment phase one can precompute fWi= g : i 2 [N]g where bi= p(i 1)‘+l, which l2[‘];vil=1 can be done in time O(N logN ‘log(‘N)) using the RootFactor algorithm from [STY01,BBF19]. This adds at most N elements of G to the advice information. Next, in the opening phase, in order to compute a membership witness for a set of positions I one can use the aggregation property to compute a witness WIfrom all Wiwith i 2 I, which is doable in time O(mlogm).

$$ \left{W _ {i} = g ^ {b / b _ {i}}: i \in [ N ] \right} $$

$$ b_{i}=\prod_{l\in[\ell|,v_{i l}=1}p_{(i-1)\ell+l} $$

$$ O(N\log N{\cdot}\ell\log(\ell N)) $$

$$ W_{I} $$

$$ i\in I $$

$$ W_{i} $$

For the non-membership proof, there are instead two options:

$$ O(m\log m) $$

1.Compute the batch-nonmembership witness from scratch

2.Precompute and store (unbatched) non-membership witnesses for all 0’s of the vector and then aggregate the necessary ones to provide the opening asked.

We argue that an intermediate solution of precomputing a fraction of non-membership witnesses and computing the rest from scratch does not provide any benet since even if a single non-membership witness needs to be computed, it requires the whole vector and computing the corresponding product of primes. So, in the end the intermediate solution will be more costly than both the above ones.

  1. Compute non-membership witness from scratch. To compute a non-membership witness one needs the product b of all the primes in the accumulator (i.e., all primes that correspond to 1’s in ~v). There are in turn two possible ways to deal with this:

{ Precompute and store b, which requires O(log(N‘) N ‘) computation and jbj = O(N ‘ log(N‘)) bits of storage.

$$ |b|={(}{{{N}}{\cdot}{\ell}{\cdot}{\log}({{N}{\ell}})) $$

{ Compute b online from all pi’s, which requires O(log(N‘) N ‘) computing power.

$$ {{p p_{i}}^{\ }}\mathrm{S} $$

$$ O(\log(N\ell)\cdot N\cdot\ell) $$

The computations needed to obtain a single non-membership witness is proportional to the size of b, which is O(‘ N log(‘N)) G. Hence, virtually there is no big improvement in the opening time by precomputing b, since the group exponentiations are more costly (although concretely it saves the online computation of it). Furthermore, keeping jbj = O(N ‘ log(N‘)) bits of storage may get impractical for big N.

$$ O(\ell\cdot N\cdot\log{(\ell N)})\ \mathbb{G} $$

$$ |b|=O(N\cdot\ell\cdot\log(N\ell)) $$

  1. Precompute non-membership witnesses and then aggregate. The idea is similar to the aggregation technique mentioned above for membership witnesses. However, a crucial dierence is that, as stated in [BBF19], for non-membership witnesses one has only one-hop aggregation. This means one must precompute and store non-membership witnesses for each block of the vector. However these non-membership witnesses have size proportional to the number of bits of each block (plus one group element).

This technique requires storage of O(N) group elements plus O(N ‘log(N‘)) eld elements on average. Precisely, the size of a non-membeship witness for each block is jGj + log(N‘) #f0-bits in the blockg, hence the total size of non-membership witnesses is N jGj + N‘ log(N‘) in the worst case and N jGj + N‘ log(N‘)=2 in an average case where half of the bits of the vector are 0. To conclude, with the VC of [BBF19], one would need, on average, to precompute and store 2N jGj + N‘ log(N‘)*=*2 bits.

$$ O(N\cdot\ell\operatorname{l o g}(N\ell)) $$

$$ O(N) $$

$$ |\mathbb{G}|+\log(N\ell)\times $$

$$ N|\mathbb{G}|+N\ell\log(N\ell) $$

$$ N|\mathbb{G}|+N\ell\log(N\ell)/2 $$

$$ 2N|\mathbb{G}|+N\ell\log(N\ell)/2 $$

Comparison. To conclude, even if we consider the case B = 1, both our solutions require much less storage than in [BBF19]: 2N jGj vs. 2N jGj+N‘ log(N‘)*=*2 bits. In terms of computing time, the preprocessing has roughly the same complexity in all three solutions, although our second scheme is slightly less favorable due to the log² m factor in the opening. Comparing [BBF19] and our rst scheme, in [BBF19] the computing time for an opening of m blocks requires at least 50% more time than in our rst scheme due to the handling of non-membership witnesses (which leads to 25% more time in the average case).

$$ B=1 $$

$$ 2N\ \ {mathbb G\ {}}N\ell\log(N\ell)/2 $$

$$ \mathrm{l o g}^{2} $$

C Succinct Arguments of Knowledge for VDS

All the protocols below are for simplicity presented for the case of k = 1.

$$ k=1 $$

AoK of correct change (

$$ R _ {\mathrm {P o K C h a n g e}} = \left{ \begin{array}{c} \left(\left(C, C ^ {\prime}, I\right), \left(\pi_ {I}, \vec {v} _ {I}, \vec {v} _ {I} ^ {\prime}\right)\right): \mathrm {V C . V e r U p d a t e} (\mathrm {c r s}, C, \left(I, \pi_ {I}, \vec {v} _ {I}, \vec {v} _ {I} ^ {\prime}\right)) = 1 \ \wedge C ^ {\prime} = \mathrm {V C . C o m U p d a t e} (\mathrm {c r s}, C, \left(I, \pi_ {I}, \vec {v} _ {I}, \vec {v} _ {I} ^ {\prime}\right)) \end{array} \right} $$

0 0 0 bIaI In case of an update the new commitment is normally C := (A;B) = (;). Therefore the I I prover rst sends the proofI:= (I;I) to the verier. Then provides knowledge of the opening of bI 0 aI 0 positions I with respect to C and further that = A ^ = B. Putting all together the prover I I aIbI aIbIbI 0 aI 0 proves knowledge of (aI;bI) such that = A ^ = B ^ g = UI^ = A ^ = B, I I I I uI where UIg and uIPrimeProd(I).

$$ \mathcal{C}^{\prime}:=\left(A^{\prime},B^{\prime}\right)=\left(\varGamma_{I}^{b_{I}},\varDelta_{I}^{a_{I}}\right) $$

$$ \pi_ {I} := \left(\Gamma_ {I}, \Delta_ {I}\right) $$

$$ \Gamma_ {I} ^ {b _ {I}} = A ^ {\prime} \wedge \Delta_ {I} ^ {a _ {I}} = B ^ {\prime} $$

$$ (a_{I},b_{I}) $$

$$ \ Gamma_{I}^{a_{I}}=A\wedge\ \ !{\it}{I}^{b{I}}=B\wedge g^{a_{I}\cdot b_{I}}=U_{I}\wedge\ !\ !{I}^{b{I}}=A^{\prime}\wedge\ \ !\ I{{}}{}{I}=B^{\prime} $$

$$ U_{I}\leftarrow g^{u_{I}} $$

$$ u_{I}\leftarrow\mathsf{P r i m e P r o d}(I) $$

AoK of correct add

$$ R_{\mathsf{P o l A A d d}}=\left{\begin{matrix}{(:(C,C^{\prime},I),\vec{v}{I}^{\prime}:):}&{\mathsf{V C}V e r U p d a t e(\mathsf{c r s},C,(I,\varnothing,\varnothing,\vec{v}{I}^{\prime}))=1}\ {\wedge}&{\mathrm C{'}=\mathsf{V C}.C o m J y d a t e(\mathsf{c r s},C,(I,\varnothing,\varnothing,\vec{v}_{I}^{\prime}))}\ \end{matrix}\right} $$

0I 0I a00 b00 a b The prover provides an argument of knowledge of (a;b) such that AI= A ^BI= B ^gI I= uI UI, where UIg and uIPrimeProd(I). Also, C := (A;B) and C⁰ = (A⁰;B⁰) are part of the statement.

$$ (a_{I}^{\prime},b_{I}^{\prime}) $$

$$ A^{a_{I}^{\prime}}=A^{\prime}\wedge B^{b_{I}^{\prime}}=B^{\prime}\wedge g^{a_{I}\cdot b_{I}}= $$

$$ U_{I} $$

$$ U_{I}\leftarrow g^{u_{I}} $$

$$ u_{I}\gets\mathsf{P r i m e P r o d}(I) $$

$$ C:=(A,B) $$

$$ C^{\prime}=(A^{\prime},B^{\prime}) $$

AoK of correct delete (

$$ R _ {\mathrm {P o K D e l e t e}} = \left{ \begin{array}{c} \left(\left(C, C ^ {\prime}, I\right), \left(\pi_ {I}, \vec {v} _ {I}\right)\right): \mathrm {V C . V e r U p d a t e} (\mathrm {c r s}, C, \left(I, \pi_ {I}, \vec {v} _ {I}, \emptyset\right)) = 1 \ \wedge C ^ {\prime} = \mathrm {V C . C o m U p d a t e} (\mathrm {c r s}, C, \left(I, \pi_ {I}, \vec {v} _ {I}, \emptyset\right)) \end{array} \right} $$

Recall that in case of deletion the new commitment C⁰ is simply the proofIof the subvector deleted. So the prover has only to provide an argument of knowledge of opening in the deleted 0aI0bIaIbIuI positions I. That is (aI;bI) such that A = A^B = B ^ g = UI, where UIg and uIPrimeProd(I). Also, C := (A;B) and C⁰ = (A⁰;B⁰) are part of the statement.

$$ C^{\prime} $$

$$ \pi\ I $$

$$ (a_{I},b_{I}) $$

$$ A^{\prime a_{I}},=,A,\wedge,B^{\prime b_{I}},=,B,\wedge,g^{a_{I}\cdot b_{I}},=,U_{I} $$

$$ U_{I}\gets g^{u_{I}} $$

$$ u_{I}\leftarrow\mathsf{P r i m e P r o d}(I) $$

$$ C:=(A,B) $$

$$ C^{\prime}=(A^{\prime},B^{\prime}) $$


D VDS Proof of Storage

For a VDS scheme we additionally consider the possibility to ensure a client that a given le is stored by the network at a certain point of time without having to retrieve it. To this end, we extend the VDS notion to provide a proof of storage mechanism in the form of a proof of + retrievability (PoR) [JK07] or a proof of data possession (PDP) [ABC 07]. Our proof of storage model for VDS is such that proofs are publicly veriable given the le’s digest. Also, in order to support the decentralized and open nature of DSNs, the entire proof mechanism should not use any secret. Finally, a main distinguishing feature compared to existing PoRs/PDPs is that proofs are generated in a distributed fashion by a collection of storage nodes and remain compact regardless of the number of nodes involved in the their generation.

$$ [\mathrm{A B C^{+}07}] $$

Below we begin by dening the syntax and correctness of proof of storage for a VDS scheme; these are dened the same for modeling both retrievability and data possession. The dierence between the two is only in the security notion.

A VDS scheme VDS as in Denition7.1admits proofs of storage if there exist algorithms (StrgNode*:* PoS-Challenge*;StrgNode:* PoS-Prove*;ClntNode:* PoS-Ver) that work as follows.

StrgNode*:* PoS-Challenge( )! r This is a probabilistic algorithm that, given a le’s digest, outputs a challenge r.

$$ :(\delta)\to r $$

$$ \delta, $$

StrgNode*:* PoS-Prove(;n; st*;I;FI;r*)!rThis algorithm allows a storage node to (partially) answer a PoS challenge r. The inputs include the local view of the storage node, i.e., digest, length n local state st and le portion (*I;*FI), and a challenge r 2C. The output is a proofr.

$$ P S\ \ \mathsf P{r o v e}(\emptyset,n,\mathsf{s t},I,\mathsf{F}{I},r)\to\pi{r} $$

$$ r\in{\mathcal{C}}. $$

$$ (I,\mathsf{F}_{I}) $$

$$ \pi_{r} $$

StrgNode*:* PoS-Aggregate(;r;r;1;r;2)! (b;r)On input a digest, a challenge r 2 C and two partial proofsr;1;r;2, this algorithm outputs an aggregated proofrand a bit b such that b = 1 iris a \complete" proof for challenge r (i.e., it can be veried).

$$ \delta, $$

$$ r\in{\mathcal{C}} $$

$$ \left(\delta,r,\pi_{r,1},\pi_{r,2}\right)\rightarrow\left(b,\pi_{r}\right) $$

$$ \pi_{r} $$

$$ \pi_{r,1},\pi_{r,2} $$

$$ b=1 $$

$$ \pi_{r} $$

ClntNode*:* PoS-Ver(;r;r)! b On input a digest, a challenge r 2C and a \complete" proofr, this algorithm accepts (outputs 1) or rejects (outputs 0).

$$ \mathsf{P o S-V e r}(\delta,r,\pi_{r})\to b $$

$$ \pi_{r} $$

$$ r\in{\mathcal{C}} $$

Denition D.1(Correctness of VDS PoS). A VDS scheme VDS has a correct PoS mechanism if VDS is correct and if for all honestly generated parameters (pp*;0;st₀) Bootstrap(1 ), any le* F S ‘ of length n and any set of ‘ valid storage node’s local views (;n; stj;Ij; FIj) such that (Ij; FIj) = j=1 ([n];F), the following holds:

$$ (\sf{p p},\delta_{0},\sf{s t}_{0})\leftarrow\sf{B o o t s t a p}(1^{\lambda}) $$

$$ (\delta,n,\mathsf{s t}{j},I{j},\mathsf{F}{I{j}}) $$

$$ \textstyle\bigcup_{j=1}^{\ell}(I_{j},\mathsf{F}{I{j}})= $$

if r $ StrgNode*:* PoS*-Challenge( ),r;jStrgNode:* PoS*-Prove(;n;* stj*;Ij;* FIj*;r*) for all j 2 [‘], andris obtained by aggregating fr;jgj2[‘]in an arbitrary order using repeated usage of StrgNode*:* PoS*-Aggregate until getting b = 1, then* ClntNode*:* PoS*-Ver(;r;r) = 1.*

$$ \pi_{r,j}\gets $$

$$ \pi_{r} $$

$$ (\delta,n,\mathsf{s t}{j},I{j},\mathsf{F}{I{j}},r) $$

$$ j \in $$

$$ {\pi_{r,j}}_{j\in[\ell]} $$

$$ \mathsf{P o S-V e r}(\delta,r,\pi_{r})=1 $$

PoS Security. Here we dene two security properties for the above PoS mechanism: retrievability + and data possession. Similarly to [JK07,ABC 07], the idea is to ask that from any adversary, controlling all storage nodes, who creates a proofrthat is accepted with suciently high probability it is possible to extract the entire le. In the retrievability case, this is formalized through requiring the existence of an extractor that extracts the le by interacting multiple times with such prover (via rewinding). In the data possession case, it is the same except that the extractor is non-blackbox, i.e., we assume that for any adversary there is an extractor; in other words, the extractor is a cryptographic one that does not exist in the real world, and for this reason the data possession notion is weaker than retrievability.

$$ \mathrm{[J K07,A B C^{+}07]} $$

$$ \pi_{r} $$


We build our denitions inspired to the one of Proof of Retrievable commitment (PoRC) soundness in [Fis18]. To this end, we dene the following two experiments.

$$ \begin{array}{l l}{\frac{\mathsf{V D S P S S A d d}{\mathsf{C S S}}^{\mathcal{A}}(\lambda)}{(mathsf{p s},\delta{0},\mathbf{s t}_{0})\sim\mathsf{D o o t t r a p}(\delta^{1})}}&{\mathsf{V D S P S S e x t e}}\\ (\mathsf{P e}^{*},\delta{\mathsf{s}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}\end{array} $$

n 0 n0 Above, given two les F 2M and F 2M and a parameter 2 [0*;*1] we say that F agrees 0i on a-fraction with F⁰, denoted F F⁰, if and only if n = n⁰ and jfi 2 [n] : Fi= F gj n.

$$ \ {\mathsf{F}}\in{\mathcal{M}}^{n} $$

$$ {\mathsf{F}}^{\prime}\in{\mathcal{M}}^{n^{\prime}} $$

$$ \mu\in[0,1] $$

$$ \mathsf{F}^{\prime} $$

$$ \ {\sf F\equiv_{\mu}\sf{F}^{\prime}} $$

$$ n=n^{\prime} $$

$$ |{i\in\ n]:\mathsf{F}{i}=\mathsf{F}{i}^{\prime}}|\geq\mu\cdot n $$

A The experiment VDSPoSAdmVDS() is parametrized by a two-stage adversary A = (A₁; A₂) and models the interaction between an adversarial prover that creates a (valid) VDS history which results into a digest and then replies to one honestly generated challenge. This experiment is used to formalize the notion of-admissible adversaries, which in brief are adversaries that in this game answer successfully to the challenge with probability at least. The second experiment A;E VDSPoSExtr () is again parametrized by a two-stage adversary A = (A₁; A₂), and additionally VDS by an extractor E having oracle access to A₂. The goal of the extractor is to return a le Fb which agrees on a-fraction of indices with the le F implicitly returned by A₁.

$$ \mathsf{V D S P o S A d m}_{\mathsf{V D S}}^{\mathcal{A}}(\lambda) $$

$$ \mathcal {A} = \left(\mathcal {A} _ {1}, \mathcal {A} _ {2}\right) $$

$$ \delta^{*} $$

$$ \mathsf{V D S P o S E x t r}_{\mathsf{V D S}}^{\mathcal{A},\mathcal{E}}(\lambda) $$

$$ \mathcal{A}=(\mathcal{A}{1},\mathcal{A}{2}) $$

$$ \mathcal{E} $$

$$ \mathcal{A}_{2} $$

$$ \widehat{F} $$

$$ \mu\mathrm{r a a t t i i l!} $$

$$ \mathcal{A}_{1} $$

Denition D.2(Admissible VDS PoS Adversary). A VDS adversary A = (A₁; A₂) is- A admissible if and only if the experiment VDSPoRAdmVDS() does not abort with probability 1 A negl() and Pr[VDSPoRAdmVDS(;F) = 1].

$$ \mathcal{A}=(\mathcal{A}{1},\mathcal{A}{2}) $$

$$ \mathsf{V D S P o R A d m}_{\mathsf{V D S}}^{\mathcal{A}}(\lambda) $$

$$ 11- $$

$$ \operatorname{P r}[\sf{V D S P o R A d m}_{V D S}^{A}(\lambda,F)=1]\geq\epsilon $$

Denition D.3(Retrievability for VDS). A VDS scheme VDS is (;)-retrievable if it is se- cure and for some;2 O(log*=log) and every > ;there exists an extractor E that runs in A;E time poly(;n;1=) such that for any adversary A which is-admissible we have Pr[VDSPoSExtr () = VDS 1] 2 negl().*

$$ (\mu,\epsilon) $$

$$ \lambda_{\epsilon,\mu}\in O(\log\epsilon/\log\mu) $$

$$ \lambda>\lambda_{\epsilon,\mu} $$

$$ \ \left(\lambda,n,1/\epsilon\right) $$

$$ \operatorname{P r}[\mathsf{V D S P o S E x t r}_{\mathsf{V D S}}^{\mathcal{A},\mathcal{E}}(\lambda)= $$

$$ 1]\in\mathsf{n e g l}(\lambda) $$

Denition D.4(Data Possession for VDS). A VDS scheme VDS has-data-possession if it is secure and for some;2 O(log*=log) and every > ;and every adversary A which is- A;E admissible there is an extractor E that runs in time poly(;n;1=) such that Pr[VDSPoSExtr () = VDS 1] 2 negl().*

$$ \lambda_{\epsilon,\mu}\in O(\log\epsilon/\log\mu) $$

$$ \lambda>\lambda_{\epsilon,\mu} $$

$$ \epsilon- $$

$$ \operatorname{P r}[\mathsf{V D S P o S E x t r}_{\mathsf{V D S}}^{\mathcal{A},\mathcal{E}}(\lambda)= $$

$$ 1]\in\mathsf{n e g l}(\lambda) $$

$$ \ \left(\lambda,n,1/\epsilon\right) $$

$$ \mathcal{E} $$

Parallel Proof of Storage. We extend our PoS notion for VDS to a setting where one can simultaneously check storage of k dierent les of the same length with a single challenge. The syntactical change we do is to assume that one can generate a challenge by only knowing the length of the les. Informally, the parallel version of retrievability (resp. data possession) is a parallel repetition of the protocol, and then from any adversary that answers successfully for all les it is possible to extract les so that each is consistent with at least a-fraction of the original one.

The parallel security experiments are as follows.


$$ \vee\ \ S P P o S!P $$

$$ \mathsf{V D S P o S-P a r-x x t r}_{\mathsf{V D S}}^{mathcal A\mathcal{E}}(\lambda) $$

$$ (\mathrm {p p}, \delta_ {0}, \mathrm {s t} _ {0}) \leftarrow \operatorname {B o o t s t r a p} \left(1 ^ {\lambda}\right) $$

$$ {\big(\mathcal{H}{i}^{*},\alpha{i}^{*}\big)}{i=1}^{k}\leftarrow\mathcal{A}{1}\big(\mathfrak{p p},\delta_{0},\mathfrak{s t}_{0}\big) $$

$$ {(b_{i}^{},\delta_{i}^{},\mathsf{F}{i}^{*})\leftarrow\mathsf{E v a l H i s t o r y}(\mathsf{p p},\delta{0},\mathsf{s t}{0},\mathcal{H}{i}^{*})}_{i=1}^{k} $$

$$ {\big(\mathcal{H}{i}^{*},\alpha{i}^{*}\big)}{i=1}^{k}\leftarrow\mathcal{A}{1}\big(\mathsf{p p},\delta_{0},\mathsf{s t}_{0}\big) $$

$$ \exists i\in[k]:b_{i}^{}=\mathbf{0}\lor\neg(\wedge_{i\in[k-1]}|\mathsf{F}_{i}^{}|=|\mathsf{F}_{i+1}^{*}|) $$

if 9i 2 [k] : bi= 0 _:(^i2[k 1]jFij = jFi+1j) abort*;*

$$ {(b_{i}^{},\delta_{i}^{},\mathsf{F}{i}^{*})\xleftarrow{}\mathsf{E v a l H i s t o r y}(\mathsf{p p},\delta{0},\mathsf{s t}{0},\mathcal{H}{i}^{*})}_{i=1}^{k} $$

else r $ StrgNode*:* PoS-Challenge(jF₁j); k k

$$ {\pi_{r,i}^{}}{i=1}^{k}\leftarrow\mathcal{A}{2}(\mathsf{p p},\delta_{0},\mathsf{s t}{0},{\delta{i}^{},\alpha_{i}^{*}}_{i=1}^{k},r) $$

$$ {\widehat{\mathtt{F}}{i}}{i=1}^{k}\xleftarrow{}\mathcal{E}^{\mathcal{A}{2}(\mathtt{p p},\delta{0},\mathtt{s t}{0},\delta{i}^{},\alpha_{i}^{},\cdot)}(\mathtt{p p},\delta_{0},\mathtt{s t}{0},{\delta{i}^{*}}_{i=1}^{k}) $$

return 1 i 8i 2 [k] : Fb 6=?^9j 2 [k] : F 6 Fb i j j

return 1 i ClntNode*:* PoS-Ver(i;r;r;i) 8i 2 [k]

$$ \mathrm {i f f} \forall i \in [ k ]: \widehat {\mathbf {F}} _ {i} \neq \perp \wedge \exists j \in [ k ]: \mathbf {F} _ {j} ^ {*} \neq \delta \widehat {\mathbf {F}} _ {j} $$

Denition D.5(Admissible VDS PoS Parallel Adversary). A VDS adversary A = (A₁; A₂) A is parallel-admissible if and only if the experiment VDSPoS*-Par-AdmVDS() does not abort with probability 1 negl() and A Pr[VDSPoS-Par-Adm (;F) = 1].*

$$ \mathcal{A}=(\mathcal{A}{1},\mathcal{A}{2}) $$

$$ \vee D S P o S\cdot P\mathrm{A r}d M\cdot{\ S}({\lambda}) $$

$$ 1-\mathsf{n e g}(\lambda) $$

$$ \bf{P r}[\sf{V D S P o S\ P a r\ A A m m}_{D S}(\lambda,F)=1]\geq\epsilon. $$

Denition D.6(Parallel Retrievability for VDS). A VDS scheme VDS is parallel (;)- retrievable if it is secure and for some;2 O(log*=log) and every > ;there exists an extractor E that runs in time poly(;n;1=) such that for any adversary A which is parallel- admissible we have A;E Pr[VDSPoS-Par-Extr () = 1] 2 negl().*

$$ (\mu,\epsilon). $$

$$ \lambda_{\epsilon,\mu},\in,O(\log\epsilon/\log\mu) $$

$$ \lambda>\lambda_{\epsilon,\mu} $$

$$ \mathcal{E} $$

$$ \left\langle\lambda,n,1/\epsilon\right\rangle $$

$$ \bf{P r}[\sf{V D S P o S\ P a r_E x t r}_{V Osf}S^{A,E}(\lambda){\ =\ }1]\in n e g l(\lambda). $$

Denition D.7(Parallel Data Possession for VDS). A VDS scheme VDS has parallel- data-possession if it is secure and for some;2 O(log*=log) and every > ;and every adversary A which is-admissible there is an extractor E that runs in time poly(;n;1=) such that A;E Pr[VDSPoS-Par-Extr () = 1] 2 negl().* VDS

$$ \epsilon- $$

$$ \lambda_{\epsilon,\mu},\in,O(\log\epsilon/\log\mu) $$

$$ \lambda>\lambda_{\epsilon,\mu} $$

$$ \mathcal{E} $$

$$ \operatorname{P r}[\mathsf{V D S P o S_P a r_E x t r}_{\mathsf{V D S}}^{\mathcal{A},\varepsilon}(\lambda)=1]\in\mathsf{n e g l}(\lambda) $$

$$ \ \left(\lambda,n,1\ \epsilon\right) $$

With the following theorem we show that it is enough to prove security in the (nonparallel) setting. The idea of the proof is that one can construct an extractor for the parallel game by running k extractors of the nonparallel game. The analysis of this reduction is rather simple and is therefore omitted.

Theorem D.1. A VDS scheme that has (;)-retrievability (resp. data possession) also achieves parallel (;)-retrievability (resp. data possession).

$$ (\mu,\epsilon) $$

D.1 Proof of Storage for our rst VDS

In this section we show that our rst VDS scheme from Section8.1admits both a PoR and a PDP mechanism, while our second VDS scheme from Section8.2admits a PoR.

Retrievability. In the case of PoR we can describe the algorithms generically from the VDS algorithms. Namely, any VDS always admits a PoR.

StrgNode*:* PoS-Challenge(n)! r samplesposintegers r₁;:::;rpos $ [n] and dene r = fr₁;:::;rposg StrgNode*:* PoS-Prove(;n; st*;I;FI;r*)!rParse r := fr₁;:::;rposg and let Q := I \ r, compute (FQ;Q) StrgNode*:* Retrieve(;n; st*;I;FI;Q*) and returnr;Q:= (Q;FQ;Q;Q).

$$ P O S-C h a l l e n g e(n)\rightarrow r $$

$$ \lambda_{\mathsf{p o s}} $$

$$ r_{1},\ldots,r_{\lambda_{\mathsf p o s}}\leftarrow_{\mathfrak S}\ n $$

$$ r=\left{r_{1},\ldots,r_{\lambda_{\mathsf{p o s}}}\right} $$

$$ \ \ \\ \\ \\ \\ \\ \\ \\ \ \ \ {\ mathcal S}-{\sf P r o v e}(\partial,n,\mathfrak{s t},I,\mathfrak{F}{I},r)\to\pi{r} $$

$$ Q:=I\cap r $$

$$ \pi_{r,Q}:=\left(Q,\mathsf{F}{Q},\pi{Q},Q\right) $$

StrgNode*:* PoS-Aggregate(;r;r;1;r;2)! (b;r)Parser;1:= (Q₁; FQ1;Q1) andr;2:= (Q₂; FQ2;Q2).

$$ (\mathsf{F}{Q},\pi{Q})\leftarrow\mathsf{S t r g N o d e}.\mathsf{R e t r i e v e}(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},Q) $$

$$ \pi_{r,1}:=\left(Q_{1},\mathsf{F}{Q{1}},\pi_{Q_{1}}\right) $$

$$ {\sf{t e}}(\delta,r,\pi_{r,1},\pi_{r,2})\rightarrow\ b,\pi_{r,1} $$

$$ \exists i\in{1,2} $$

$$ Q_{i}=r;\ *{\sec}b:=1 $$

If 9i 2f1*;* 2g such that Qi= r set b := 1 andr:=r;i.

$$ \pi_{r}:=\pi_{r,i}. $$

Otherwise, compute (*Q;*FQ) := (Q₁; FQ1) [ (Q₂; FQ2) and

$$ (\mathcal{Q},\mathsf{F}{\mathcal{Q}}):=(\mathcal{Q}{1},\mathsf{F}{\mathcal{Q}{1}})\cup(\mathcal{Q}{2},\mathsf{F}{\mathcal{Q}_{2}}) $$

QAggregateCerticates(; (Q₁; FQ1*;Q1);* (Q₂; FQ2*;Q*2)), and setr:= (*Q;FQ;*Q). If Q = r, set b := 1, otherwise set b := 0.

$$ \left(\delta,(Q_{1},\mathsf{F}{Q{1}},\pi_{Q_{1}}),(Q_{2},\mathsf{F}{Q{2}},\pi_{Q_{2}})\right) $$

$$ \pi_{r}:=\left(Q,\mathsf{F}{Q},\pi{Q}\right) $$

$$ Q=r $$

$$ b:=1 $$

$$ b:=0 $$

Return (b;r)

$$ (b,\pi_{r}) $$


$$ \pi_{r}:=\left(Q,\mathsf{F}{Q},\pi{Q}\right) $$

$$ \mathsf{P o S-V e r}(\delta,r,\pi_{r})\to b $$

ClntNode*:* PoS-Ver(;r;r)! b parser:= (Q;FQ;Q) and return 1 i Q = r and ClntNode*:* VerRetrieve(; Q;FQ;Q) = 1.

$$ Q,\mathsf{F}{Q},\pi{Q})=1 $$

Correctness is easy by inspection and by the correctness of VDS.

For security we state the following theorem. The proof is omitted since it is almost identical to the proof of the VC-PoRC construction in [Fis18]; the only dierence is that instead of reducing to 27 the position binding of the VC we reduce to the security of the VDS scheme.

Theorem D.2. If the VDS scheme VDS from Section8.1is secure then its extension with the PoS algorithms described above is a (;)-retrievable VDS for any > 0 such thatposis non-negligible in.

$$ a\ (\mu,\epsilon) $$

$$ \epsilon-\mu^{\lambda_{\mathsf{p o s}}} $$

Data Possession. The PDP for our VDS is almost the same as the PoR described above except that the last step of aggregation \compacts" the proof by generating an AoK of opening (see Section 6). More precisely, let PoKOpen⁰ be the same as protocol PoKOpen but adjusted for the simpler version of our VC scheme given in Section8.1. Namely, the one where the commitment is (A;B) and the verication is the VC*:* Ver⁰ algorithm. So, the relation proven by PoKOpen⁰ is:

$$ R_{\mathsf{P o K O O p e}{^\prime}}={(:(C,I),:(\vec{y},\pi_{I}):):\mathsf{V C.V e r}^{\prime}(\mathsf{p p},C,I,\vec{y},\pi_{I}):} $$

Then, the PDP aggregation algorithm works as follows.

StrgNode*:* PoS-Aggregate(;r;r;1;r;2)! (b;r)Parser;1:= (Q₁; FQ1;Q1) andr;2:= (Q₂; FQ2;Q2). If 9i 2f1*;* 2g such that Qi= r set b := 1 and (Q;FQ;Q) :=r;i. Otherwise, compute (Q;FQ) := (Q₁; FQ1) [ (Q₂; FQ2) and QAggregateCerticates(; (Q₁; FQ1*;Q1);* (Q₂; FQ2*;*Q2)).

$$ \left(\hat{\delta},r,\pi_{r,1},\pi_{r,2}\right)\rightarrow\left(b,\pi_{r}\right) $$

$$ \pi_{r,1}:=\left(Q_{1},\mathsf{F}{Q{1}},\pi_{Q_{1}}\right) $$

$$ \pi_{r,2}:=\left(Q_{2},\mathsf{F}{Q{2}},\pi_{Q_{2}}\right) $$

$$ \exists\dot{i}\in{1,2} $$

$$ b:=1 $$

$$ Q_{i}=r $$

$$ (Q,\mathsf{F}{Q},\pi{Q}):=\pi_{r,i} $$

$$ (\mathcal{Q},\mathsf{F}{\mathcal{Q}}):=(\mathcal{Q}{1},\mathsf{F}{\mathcal{Q}{1}})\cup(\mathcal{Q}{2},\mathsf{F}{\mathcal{Q}_{2}}) $$

$$ \left(\emptyset,(Q_{1},\mathsf{F}{Q{1}},\pi_{Q_{1}}),(Q_{2},\mathsf{F}{Q{2}},\pi_{Q_{2}})\right) $$

If Q 6= r, setr:= (Q;FQ;Q) and return (0*;r). Otherwise, proceed to compute an AoK of opening, i.e., computerPoKOpen⁰:* P((;Q);(FQ;Q)), and then return (1*;*r)

$$ Q\neq r. $$

$$ \left(0,\pi_{r}\right) $$

$$ \pi_{r}:=\left(Q,\mathsf{F}{Q},\pi{Q}\right) $$

$$ \pi_{r}\leftarrow\mathsf{P o K O p e n}^{\prime}.\mathsf{P}((\delta,Q),(\mathsf{F}{Q},\pi{Q})) $$

$$ (1,\pi_{r}) $$

ClntNode*:* PoS-Ver(;r;r)! b return PoKOpen⁰*:* V((;r);r).

$$ \mathsf{P o S-V e r}(\delta,r,\pi_{r})\to b $$

$$ \mathsf{P o K O p e n}^{\prime}.\mathsf{V}((\delta,r),\pi_{r}) $$

Correctness is easy by inspection and by the correctness of VDS.

For security we state the following theorem. The proof is essentially the same as the one for retrievability except that in this case we dene a non-black-box extractor which is build from the extractor for PoKOpen⁰.

Theorem D.3. If PoKOpen⁰ is a secure AoK for relation R 0 and the VDS scheme VDS from PoKOpen Section8.1is secure, then its extension with the PoS algorithms described above satises (;)-data possession for any > 0 such thatposis non-negligible in.

$$ \ {sf P P k V O p n}^{\prime} $$

$$ R_{\mathsf{P o k O p e n}^{\prime}} $$

$$ \epsilon>0 $$

$$ \epsilon-\mu^{\lambda_{\mathtt{p o s}}} $$

$$ \lambda $$

Parallel PDP. We observe that in the case of executing the PDP protocol in parallel for k dierent digests, our construction has an interesting eciency property. While verifying one PDP takes time ur O(pos) due to the computation of the group element Ur:= g with ur:= PrimeProd(r), in the case of verifying k PDPs with the same challenge the element Urcan be reused. This yields a total verication time O(pos+ k) instead of O(kpos).

$$ U_{r}:=g^{u_{r}} $$

$$ O(\lambda_{\mathsf{p o s}}) $$

$$ u_{r}:=\mathsf{P r i m e P r o d}(r) $$

$$ U_{r} $$

$$ O(\lambda_{\mathsf p{o o s}}+k) $$

$$ O(k\cdot\lambda_{\mathtt{p o s}}) $$

27 For this we also observe that Fisch’s proof could go through even assuming a weaker notion of position binding in which the adversary declares the whole committed vector in addition to the two discording openings for one position.


E A Variant VDS Construction with Strong Security

We dene a stronger notion of security for VDS schemes where the digest is chosen adversarially, namely without having the verier need to check the corresponding history. Also, we show that a variant of our second VDS construction can be proven secure under this strong notion; this however comes at the price of dropping one of the eciency requirements as now the verier may sometimes run in time linear in the size of the le (still all proofs remain short).

E.1 Strong Security

In this notion the digest can diverge from a valid history, meaning that the VDS scheme is secure independently of the corresponding history: an adversary cannot convince a client of a false data block in a retrieval query for any arbitrary digest (that is possibly not an EvalHistory). This notion is analogous to the position binding of vector commitments. This allows a client that has not followed the complete history of the VDS to make certain that for the given digest no invalid retrieval answers can be given.

Denition E.1(Strong Security for Veriable Decentralized Storage). Consider the ex- A periment VDS*-strongSecurityVDS() below. Then we say that a VDS scheme VDS is strongly-secure A if for all PPT A we have Pr[VDS-strongSecurityVDS() = 1] 2 negl().* A VDS-strongSecurityVDS() (pp*;0;st₀) Bootstrap(1) 0Q 0 (;Q;FQ;;F;) A (pp;0;st₀) 0Q 0 b ClntNode:* VerRetrieve(pp*;;Q;F;)^* 0Q ClntNode*:* VerRetrieve(pp*;;Q;FQ;) ^ F 6= FQ* return b

$$ y_{\mathsf{V D S}}^{\mathcal{A}}(\lambda)=1]\in\mathsf{n e g l}(\lambda) $$

$$ (\delta^{*},\mathcal{Q},\mathsf{F}{Q},\pi,\mathsf{F}{Q}^{\prime},\pi^{\prime})\leftarrow\mathcal{A}(\mathfrak{p p},\delta_{0},\mathfrak{s t}_{0}) $$

$$ \delta^{*},Q,\mathsf{F}_{Q}^{\prime},\pi^{\prime})\wedge $$

$$ \delta^{*},Q,\mathsf{F}{Q},\pi)\wedge\mathsf{F}{Q}^{\prime}\neq\mathsf{F}_{Q} $$

E.2 A VDS Construction with Strong Security

Our second VDS scheme from Section8.2is built upon the [CF13,LM19] SVC. This scheme is not strongly secure although it inherits the standard position binding of VC (dierently from our other construction). This property states that, even for adversarially chosen C’s, which possibly do not 0 come from a valid history, no PPT adversary can provide openingsQ; for dierent subles. Q

$$ \pi_{Q},\pi_{Q}^{\prime} $$

What prevents our VDS scheme to be strongly secure is theQU-part of the digest. For U it must i2[n]ei be ensured that it has the correct form U g. There are two ways to ensure this, either one follows the history of the VDS or it computes it from scratch when necessary. The rst case leads to the VDS scheme of Section8.2, while the second one leads to a strongly-secure VDS scheme, let us call it VDS⁰, that however has the drawback of having linear-time (in the size of the le) verication of a retrieval.

$$ U\leftarrow g^{\prod_{i\in[n]}e_{i}} $$

We note that in practice a client may not need to check U at each retrieval. Observe that it only depends on the size of the le and not on its context, meaning that only addition and deletionQ i2[n]ei updates aect it. So one may keep Un= g stored and at the time of the query verication update it with the new le length n⁰. This gives an O(jn n⁰j) computational cost for verication at the cost of storing a single group element, U.

$$ U_{n}=g^{\prod_{i\in[n]}e_{i}} $$

$$ O(|n-n^{\prime}|) $$

$$ n^{\prime} $$

Let the alternative verication algorithm be:


Q 0i2[n]ei ClntNode*:* VerRetrieve (;Q;FQ;Q)! b compute U g and output acceptance bit Q i2Qei b VC*:* Ver(pp*;C;Q;FQ;*Q) ^ S = U Q

$$ U\leftarrow g^{\prod_{i\in[n]}e_{i}} $$

$$ (left(\delta,Q,\mathsf{F}{Q},\pi{Q})\to b $$

$$ b\leftarrow\mathsf{V C.V e r}(\mathsf{p p},C,Q,\mathsf{F}{Q},\pi{Q})\wedge S_{Q}^{\prod_{i\in Q}e_{i}}=U $$

and the corresponding VDS scheme be the same as the one in Section8.2except for the verication of retrieval query algorithm, i.e.,

VDS⁰ = (Bootstrap*;StrgNode:* AddStorage*;StrgNode:* RmvStorage*;StrgNode:* PushUpdate*;* StrgNode*:* ApplyUpdate*;StrgNode:* Retrieve*;ClntNode:* VerRetrieve⁰*;ClntNode:* ApplyUpdate*;* AggregateCerticates)

Theorem E.1(Security). Let G Ggen(1 ) be a hidden order group where the Strong Distinct- Prime-Product Root assumption, then the VDS⁰ scheme presented above is a strongly-secure Veri- able Decentralized Storage scheme in the standard model.

$$ \mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda}) $$

The proof is almost the same to the one of Theorem8.3and is omitted.

F Experimental Results

In this section we include complete tables and plots for our benchmarks.

In some of the tables and plots we show only results for openings of size at most 25% of the vector size as this is often the case in practice. We remark that the timings for verication of our SVC construction and BBF do not use proofs of knowledge of exponent, thus both timings can in practice be reduced through the use of this technique. Finally, although we show amortized openings (Figure9) for only openings of size 2048 bits, we stress that dierent choices of le and opening size show very similar patterns.

We exclude BBF with precomputation from our experiments as its storage requirements and running times dominate those of our construction with preprocessing. In terms of storage it is linear in the number of the bits in the vector. For our choice of security parameters and block size, it would require 3 more memory independently of the size of the vector. In terms of time, the running times of BBF with preprocessing always dominate those of our preprocessing scheme. Concretely opening and verication of each zero bit requires one more group exponentiation. Finally, the lack of incremental aggregation makes this scheme less exible than ours as it does not allow to choose dierent tradeos in terms of memory/running time.

The Experimental Setting We implemented our VC, its preprocessing variant and BBF²⁸ in Rust. We executed our experiments on a virtual machine running Debian GNU/Linux with 8 Xeon Gold 6154 cores and 30 GB of RAM.

$$ \mathrm{B B F^{28}} $$

We measured running times for the commitment stage (including or not a preprocessing), opening and verication for dierent choices of vector length (N) and subvector openings (m). Vectors have blocks of ‘ = 256 bits (which is representative of vectors where blocks are hash outputs) and 29 their total size n = N‘ range from 16 kibibit (Kibit) to 1 mebibit (Mibit). For preprocessing we considered the basic case in which we precompute one proof per block, i.e., a total of n=‘ proofs is precomputed. We chose m, the opening size to be of 1, 8 or 64 blocks (i.e. 256, 2048 or 16536 bits). On security parameters: our experiments always used an RSA modulus of 2048 bits and primes of 64 bits for accumulation.

$$ n=N\ell $$

$$ n/\ell $$

28 https://github.com/nicola/rust-yinyan

29 10 10 1 Kibit = 2 bits; 1 Mibit = 2 Kibit. We choose powers of two for convenience.

$$ 1;\mathrm{K i b i t}=2^{10} $$

$$ =2^{10} $$


n(file size in bits) Running Time
16384 52s
32768 1m56s
64536 4m23s
131072 10m7s
262144 24m5s
524288 1h1m
1048576 2h54m

Table 4. Commitment times for our preprocessing construction (block size ‘ = 256).

n(size in bits) This work BBF
16384 18s 3s
32768 37s 8s
64536 1m19s 18s
131072 3m0s 45s
262144 7m22s 2m29s
524288 20m12s 7m8s
1048576 1h10m 29m54s

Table 5. Commitment Times (no preprocessing)

n(size in bits) This work(precomp.) This work BBF
16384 $2\cdot10^{-4}$ 5.56 5.86
32768 $2\cdot10^{-4}$ 11.17 11.69
64536 $2\cdot10^{-4}$ 22.44 23.26
131072 $2\cdot10^{-4}$ 44.68 45.49
262144 $2\cdot10^{-4}$ 88.98 90.72
524288 $2\cdot10^{-4}$ 178.94 184.86
1048576 $2\cdot10^{-4}$ 357.50 370.82

$$ \overline{{2\cdot10^{-4}}} $$

$$ 2\cdot10^{-4} $$

$$ 2\cdot10^{-4} $$

$$ 2\cdot10^{-4} $$

$$ 2\cdot{10}^{-4} $$

$$ 2\cdot10^{-4} $$

$$ 2\cdot{10}^{-4} $$

Table 6. Opening Times (in s) for openings of 256 bits

n(size in bits) This work(precomp.) This work BBF
16384 4.27 5.70 7.96
32768 4.27 11.34 14.75
64536 4.27 22.84 28.10
131072 4.27 45.44 54.17
262144 4.27 91.45 108.69
524288 4.27 182.29 222.47
1048576 4.27 362.50 453.28

Table 7. Opening Times (in s) for openings of 2048 bits

n(size in bits) This work(precomp.) This work BBF
64536 73.57 25.96 66.16
131072 73.57 52.42 122.68
262144 73.57 104.63 238.07
524288 73.57 210.40 521.89
1048576 73.57 423.48 1100.10

Table 8. Opening Times (in s) for openings of 16384 bits


m·l(opening in bits) This work BBF
256 3.31 7.72
2048 8.97 13.28
16384 309.82 314.28

Table 9. Verication Times (in ms)

Fig. 7. Commitment Experiments


Fig. 8. Opening Experiments


Fig. 9. Amortized Opening Experiments for a le of size 128 Kibib.