# Vector Commitment Techniques and Applications to Veriable Decentralized Storage

;2
Matteo Campanelli¹, Dario Fiore¹, Nicola Greco³, Dimitris Kolonelos¹, and Luca Nizzardo³

<sup>1</sup>
IMDEA Software Institute, Madrid, Spain
*f*matteo.campanelli,dario.fiore,dimitris.kolonelos*g*@imdea.org
<sup>2</sup>
Universidad Politecnica de Madrid, Spain
<sup>3</sup>
Protocol Labs
*f*nicola,luca*g*@protocol.ai

independent of both the vector’s length and the number of opened positions.
We continue the study of SVC with two goals in mind: improving their eciency and making them more
suitable to decentralized settings. We address both problems by proposing a new notion for VC that
we call *incremental aggregation* and that allows one to merge openings in a succinct way an unbounded
number of times. We show two applications of this property. The rst one is immediate and is a method
to generate openings in a distributed way. For the second one, we use incremental aggregation to design
an algorithm for faster generation of openings via preprocessing.

We then proceed to realize SVC with incremental aggregation. We provide two constructions in groups
of unknown order that, similarly to that of Boneh et al. (which supports only one-hop aggregation),
have constant-size public parameters, commitments and openings. As an additional feature, for the rst
construction we propose ecient arguments of knowledge of subvector openings which immediately
yields a keyless proof of storage with compact proofs.

Finally, we address a problem closely related to that of SVC: storing a le eciently in completely
decentralized networks. We introduce and construct *veriable decentralized storage* (VDS), a cryptographic primitive that allows to check the integrity of a le stored by a network of nodes in a distributed
and decentralized way. Our VDS constructions rely on our new vector commitment techniques.

---

## Table of Contents

1 **Introduction** 4
    1.1 A new notion for SVCs: incremental aggregation 4
    1.2 Verifiable Decentralized Storage 7
    1.3 Concurrent Work 10

2 **Preliminaries** 10
    2.1 Groups of Unknown Order and Computational Assumptions 11
    2.2 Arguments of Knowledge 12

3 **Vector Commitments with Incremental Aggregation** 13
    3.1 Vector Commitments with Subvector Openings 13
    3.2 Incrementally Aggregatable Subvector Openings 15

4 **Applications of Incremental Aggregation** 17
    4.1 Divide-and-Conquer Extensions of Aggregation and Disaggregation 17
    4.2 Committing and Opening with Precomputation 18

5 **Our Realizations of Incrementally Aggregatable Vector Commitments** 20
    5.1 Our First SVC Construction 20
    5.2 Our Second SVC Construction 31
    5.3 Comparison with Related Work 36

6 **Arguments of Knowledge for Our First SVC** 38
    6.1 Building block: A Stronger Proof of Product 38
    6.2 A Succinct AoK of Opening for our VC Construction 39
    6.3 An AoK for commitments with common subvector 42
    6.4 A Succinct AoK for Commitment on Subvector 42

7 **Verifiable Decentralized Storage** 43
    7.1 Syntax 44
    7.2 Correctness and Efficiency of VDS 46
    7.3 Security of VDS 48

8 **Our Realizations of VDS in Hidden-Order Groups** 49
    8.1 Our First VDS Construction 49
    8.2 Our Second VDS Construction 56
    8.3 Efficiency and Comparison 59

9 **Experimental Evaluation** 60

A PoProd protocol for Union of RSA Accumulators 64

B Committing and Opening with Precomputation for the [BBF19] SVC 65

C Succinct Arguments of Knowledge for VDS 66

D VDS Proof of Storage 67
    D.1 Proof of Storage for our first VDS 69

E A Variant VDS Construction with Strong Security 71
    E.1 Strong Security 71
    E.2 A VDS Construction with Strong Security 71

7 Veriable Decentralized Storage43

---

F Experimental Results72

---

## 1 Introduction

Commitment schemes are one of the most fundamental cryptographic primitives. They can be seen
as the digital equivalent of a sealed envelop: committing to a message *m* is akin to putting *m* in the
envelop; opening the commitment is like opening the envelop and revealing the value inside. They
have two basic properties. *Hiding* guarantees that a commitment reveals no information about the
underlying message. *Binding* instead ensures that one cannot change its mind about the committed
message; namely, it is not possible to open a commitment to two distinct values *m 6*= *m⁰*.

$$
\neq m^{\prime}
$$

Vector commitments (VC) [LY10,CF13] are a special class of commitment schemes in which
one can commit to a vector *~v* of length *n* and to later open the commitment at any position *i 2* [*n*].
The distinguishing feature of VCs is that both the commitment and an opening for a position *i*
have size independent of *n*. In terms of security, VCs should be *position binding*, i.e., one cannot
open a commitment at position *i* to two distinct values *v*<sub>i</sub>6= *v*.
<sub>i0</sub>

$$
i\in[n]
$$

$$
v_{i}\neq v_{i}^{\prime}.
$$

VCs were formalized by Catalano and Fiore [CF13] who also proposed two constructions based
on the CDH assumption in bilinear groups and the RSA assumption respectively. Both schemes
have constant-size commitments and openings but suer from large public parameters that are
*O*(*n²*) and *O*(*n*) for the CDH- and RSA-based scheme respectively. Noteworthy is that Merkle
trees [Mer88] are VCs with *O*(log*n*)-size openings.

$$
O(n^{2})
$$

$$
O(n)
$$

Two recent works [BBF19,LM19] proposed new constructions of vector commitments that enjoy a new property called *subvector openings* (also called *batch openings* in [BBF19]). A VC with
subvector openings (called SVC, for short) allows one to open a commitment at a collection of positions *I* = *fi₁;:::;i*<sub>m</sub>*g* with a constant-size proof, namely of size independent of the vector’s length
*n* and the subvector length *m*. This property has been shown useful for reducing communication
complexity in several applications, such as PCP/IOP-based succinct arguments [LM19,BBF19]
and keyless Proofs of Retrievability (PoR) [Fis18].

$$
I=\left\{i_{1},\ldots,i_{m}\right\}
$$

In this work we continue the study of VCs with subvector openings with two main goals: (1)
improving their eciency, and (2) enabling their use in decentralized systems.

With respect to eciency, although the most attractive feature of SVCs is the constant size
of their opening proofs, a drawback of all constructions is that generating each opening takes at
least time *O*(*n*) (i.e., as much as committing). This is costly and may harm the use of SVCs in
applications such as the ones mentioned above.

$$
O(n)
$$

When it comes to decentralization, VCs have been proposed as a solution for integrity of a
distributed ledger (e.g., blockchains in the account model [BBF19]): the commitment is a succinct
representation of the ledger, and a user responsible for the *i*-th entry can hold the corresponding
opening and use it to prove validity of *v*<sub>i</sub>. In this case, though, it is not obvious how to create a
succinct subvector opening for, say, *m* positions held by *dierent* users each responsible *only* of its
own position/s in the vector. We elaborate more on the motivation around this problem in Section
1.2.

$$
v_{i}
$$

## 1.1 A new notion for SVCs: incremental aggregation

To address these concerns, we dene and investigate a new property of vector commitments with
subvector openings called *incremental aggregation*. In a nutshell, aggregation means that dierent
subvector openings (say, for sets of positions *I* and *J*) can be merged together into a single *concise*
(i.e., constant-size) opening (for positions *I [J*). This operation must be doable *without* knowing the entire committed vector. Moreover, aggregation is incremental if aggregated proofs can be further
aggregated (e.g., two openings for *I[J* and *K* can be merged into one for *I[J[K*, and so on
an unbounded number of times) and disaggregated (i.e., given an opening for set *I* one can create
one for any *K I*).

$$
I\cup J\cup K
$$

$$
K\subset I)
$$

While a form of aggregation is already present in the VC of Boneh et al. [BBF19], in [BBF19]
this can be performed only once. In contrast, *we dene (and construct) the rst VC schemes where*
*openings can be aggregated an unbounded number of times*. This incremental property is key to
address eciency and decentralized applications of SVCs, as we detail below.

Incremental aggregation for eciency. To overcome the barrier of generating each opening in
linear time⁴ *O* (*n*), we propose an alternative preprocessing-based method. The idea is to precompute at commitment time an auxiliary information consisting of *n=B* openings, one for each batch
of *B* positions of the vector. Next, to generate an opening for an arbitrary subset of *m* positions, one
uses incremental aggregation in order to disaggregate the relevant subsets of precomputed openings,
and then further aggregate for the *m* positions. Concretely, with this method, in our construction
we can do the preprocessing in time *O* (*n*log*n*) and generate an opening for *m* positions in time
roughly *O* (*mB* log*n*).

$$
\operatorname{t i m e}^{4}\,O_{\lambda}(n)
$$

$$
n/B
$$

$$
O_{\lambda}(n\log n)
$$

$$
O_{\lambda}(m B\log n)
$$

With the VC of [BBF19], a limited version of this approach is also viable: one precomputes an
opening for each bit of the vector in *O* (*n*log*n*) time; and then, at opening time, one uses their onehop aggregation to aggregate relevant openings in time roughly *O* (*m*log*n*). This however comes
with a huge drawback: one must store one opening (of size *p*() = poly() where is the security
parameter) for every bit of the vector, which causes a prohibitive storage overhead, i.e., *p*() *n*
bits in addition to storing the vector *~v* itself.

$$
O_{\lambda}(n\log n)
$$

$$
O_{\lambda}(m\log n)
$$

$$
\lambda
$$

$$
p(\lambda)={\mathsf{p o l y}}(\lambda)
$$

$$
p(\lambda)\cdot n
$$

$$
\vec{v}
$$

With incremental aggregation, we can instead tune the chunk size *B* to obtain exible time-
*p p p*
memory tradeos. For example, with *B* = *n* one can use *p*() *n* bits of storage to get *O* (*m n*log*n*)
opening time. Or, by setting *B* = *p*() as the size of one opening, we can obtain a storage overhead
of exactly *n* bits and opening time *O* (*m*log*n*).

$$
B={\sqrt{n}}
$$

$$
p(\lambda){\sqrt{n}}
$$

$$
O_{\lambda}(m{\sqrt{n}}\log n)
$$

$$
B=p(\lambda)
$$

$$
O_{\lambda}(m\log n)
$$

Incremental aggregation for decentralization. Essentially, by its denition, incremental aggregation enables generating subvector openings in a distributed fashion. Namely, consider a scenario
where dierent parties each hold an opening of some subvector; using aggregation they can create
an opening for the union of their subvectors, moreover the incremental property allows them to
perform this operation in a non-coordinated and asynchronous manner, i.e. without the need of
a central aggregator. We found this application of incrementally aggregatable SVCs to decentralized systems worth exploring in more detail. To fully address this application, we propose a new
cryptographic primitive called veriable decentralized storage which we discuss in Section1.2.

Constructing VCs with incremental aggregation. Turning to realizing SVC schemes with
our new incremental aggregation property, we propose two SVC constructions that work in hiddenorder groups [DK02] (instantiatable using classical RSA groups, class groups [BH01] or the recently
proposed groups from Hyperelliptic Curves [DG20]).

Our rst SVC has constant-size public parameters and constant-size subvector openings, and its
security relies on the Strong RSA assumption and an argument of knowledge in the generic group
model. Asymptotically, its eciency is similar to the SVC of Boneh et al. [BBF19], but concretely

<sup>4</sup>
We use the notation *O* ( ) to include the factor depending on the security parameter. Writing \*O* (*t*)" essentially
means \*O*(*t*) cryptographic operations".

$$
O_{\lambda}(\cdot)
$$

$$
“ O _ {\lambda} (t)”
$$

$$
^(O(t)
$$ we outperform [BBF19]. We implement⁵ our new SVC and show it can obtain very fast opening
times thanks to the preprocessing method described earlier: opening time reduces by several orders
of magnitude for various choices of vector and opening sizes, allowing us to obtain practical opening
times|of the order of seconds|that would be impossible without preprocessing|of the order of
20
hundred of seconds. In a le of 1 Mibit (2 bits), preprocessing reduces the time to open 2048 bits
from one hour to less than 5 seconds!

$$
\ 2^{20}\mathrm{\ b i t s})
$$

For the second construction, we show how to modify the RSA-based SVC of [LM19] (which in
turn extends the one of [CF13] to support subvector openings) in order to make it with *constant-*
*size* parameters and to achieve incremental aggregation. Compared to the rst construction, it is
more ecient and based on more standard assumptions, in the standard model.

Ecient Arguments of Knowledge of Subvector Opening. As an additional result, we
propose ecient arguments of knowledge (AoK) with constant-size proofs for our rst VC. The rst
AoK can prove knowledge of the subvector that opens a commitment at a public set of positions,
and it extends to proving that two commitments share a common subvector. The second AoK is
similar except that the subvector one proves knowledge of is also committed; essentially one can
create two vector commitments *C* and *C⁰* together with a short proof that *C⁰* is a commitment to
a subvector of the vector committed in *C*.

$$
C^{\prime}
$$

$$
C^{\prime}
$$

An immediate application of our rst AoK is a *keyless proof of storage* (PoS) protocol with
compact proofs. PoS allows a client to verify that a server is storing intactly a le via a shortcommunication challenge-response protocol. A PoS is said *keyless* if no secret key is needed by
clients, a property useful in open systems where the client is a set of distrustful parties (e.g.,
veriers in a blockchain) and the server may even be one of these clients. A classical keyless PoS
is based on Merkle trees and random spot-checks [JK07], recently generalized to work with vector
commitments [Fis18]. A drawback of this construction is that proofs grow with the number of spotchecks (and the size of the tree) and become undesirably large in some applications, e.g., if need
to be stored in a blockchain. With our AoK we can obtain openings of xed size, as short as 2KB,
which is 40x shorter than those based on Merkle trees in a representative setting without relying
6
on SNARKs (that would be unfeasible in terms of time and memory).

From Updatable VCs to Veriable Decentralized Storage. In their seminal work on VCs,
Catalano and Fiore [CF13] also dened updatable VCs. This means that if one changes the *i*-th
value of a vector from *v*<sub>i</sub>to *v* it is possible to update: a commitment *C* to *~v* into a commitment
i0
*C⁰* to *~v⁰*, a valid opening for *C* (at any position) into a valid opening for *C⁰*. And importantly,
these updates can be done without knowing the entire vector and in time that depends only on the
number of modied positions. As an application, in [CF13] it is shown how updatable VCs can be
used to realize veriable databases (VDB) [BGV11], a primitive that enables a client to outsource
a database to an untrusted server in such a way that the client can retrieve (and update) a DB
record and be assured that it has not been tampered with by the server.

$$
v_{i}
$$

$$
C^{\prime}
$$

$$
v_{i}^{\prime}
$$

$$
\vec{v}
$$

$$
\vec{v}^{\ j}
$$

$$
C^{\prime}
$$

In this work we study how to extend this model to a scenario where storage is distributed
across dierent nodes of a decentralized network. This problem is motivated by the emerging trend
of *decentralized storage networks* (DSNs), a decentralized and open alternative to traditional cloud

5
Code publicly available at https://github.com/nicola/rust-yinyan

<sup>6</sup>
We provide further details in Section6 storage and hosting services. Filecoin (which is built on top of IPFS), Storj, Dat, Freenet and
general-purpose blockchains like Ethereum⁷ are some emerging projects in this space.

Our contribution is to put forward a new cryptographic primitive called *veriable decentralized*
*storage* (VDS) that can be used to obtain data integrity guarantees in DSNs. We propose a denition
of VDS and a construction obtained by extending the techniques of our VC scheme; in particular,
both incremental aggregation and the arguments of knowledge are key ingredients for building a
cost-eective VDS solution.

In the following section we elaborate on the VDS problem: we begin by discussing the requirements imposed by DSNs, and then give a description of our VDS primitive and realization.

## 1.2 Veriable Decentralized Storage

Decentralized Storage Networks. *Openness* and *decentralization* are the main characteristics of
DSNs: anyone can enter the system (and participate as either a service provider or a consumer) and
the system works without any central management or trusted parties. Abstracting from the details
of each system, a DSN consists of participants called *nodes* that can be either a storage provider (aka
*storage node*) or a *client node*. Akin to centralized cloud storage, a client can outsource the storage
of large data; the key dierence of DSN however is that storage is provided by, and distributed
across, a collection of nodes that can enter and leave the system at their wish. Also, DSNs can have
some reward mechanism to economically incentivize storage nodes.

The openness and the presence of economic incentives raise a number of security questions that
need to be solved in order to make these systems viable. In this work, we focus on the basic problem
of ensuring that the storage nodes of the DSN are doing their job properly, namely:

## How can any client node check that the whole DSN is storing correctly its data (in a distributed fashion)?

While this question is well studied in the centralized setting where the storage provider is a single
server, for decentralized systems the situation is less satisfactory. In what follows we elaborate on
the problem and the desired requirements, and then on our solution.

The Problem of Veriable Decentralized Storage. Consider a client who outsources the
storage of a large le *F*, consisting of blocks (*F₁;:::;F*<sub>N</sub>), to a collection of storage nodes. A
storage node can store a portion of *F* and the network is assumed to be designed in order to
self-coordinate so that the whole *F* is stored, and to be fault-resistant (e.g., by having the same
data block stored on multiple nodes). Once the le is stored, clients can request to the network to
retrieve or modify a data block *F*<sub>i</sub>(or more), as well as to append (resp. delete) blocks to (resp.
from) the le.

$$
(F_{1},\ldots,F_{N})
$$

$$
F_{i}
$$

In this scenario, our goal is to formalize a cryptographic primitive that can provide clients with
the guarantee of *integrity of the outsourced data and its modications*. The basic idea of VDS is
that: (i) the client retains a short *digest*<sub>F</sub>that \uniquely" points to the le *F*; (ii) any operation
performed by the network, be it a retrieval or a le modication, can be proven by generating a
short *certicate* that is publicly veriable given<sub>F</sub>.

$$
\delta_{F}
$$

This problem is similar in scope to the one addressed by authenticated data structures (ADS)
[Tam03]. But while ADS is centralized, VDS is not. In VDS nodes act as storage in a distributed

$$
\delta_{F}
$$

<sup>7</sup>
https://filecoin.io, https://storj.io, https://datproject.org, https://freenetproject.org, https://
www.ethereum.org and uncoordinated fashion. This is more challenging as VDS needs to preserve some basic properties
of the DSN:

*Highly Local.* The le is stored across multiple nodes and no node is required to hold the entire *F* :
in VDS every node should function with only its own local view of the system, which should be
much smaller than the whole *F*, e.g., logarithmic or constant in the size of *F*. Another challenge is
dynamic les: in VDS both the digest and the local view must be *locally* updatable, possibly with
the help of a short and publicly veriable update advice that can be generated by the node who
holds the modied data blocks.

*Decentralized Keyless Clients.* In a decentralized system the notion of a client who outsources the
storage of a le is blurry. It may for example be a set of mutually distrustful parties (even the
entire DSN in the most extreme case, e.g., the le is a blockchain), or a collection of storage
nodes themselves that decide to make some data available to the network. This comes with two
implications:

1. *VDS must work without any secret key* on the clients side, so that everyone in the network can
delegate and verify storage. This *keyless* setting captures not only clients requiring no coordination, but also a stronger security model. Here the attacker may control both the storage node and
the client, yet it must not be able to cheat when proving correctness of its storage. The latter is
crucial in DSNs with economic rewards to well-behaving storage nodes⁸.

2. *In VDS a le F exists as long as some storage nodes provide its storage* and a pointer to the le
is known to the network through its digest. When a le *F* is modied into *F⁰* and its digest<sub>F</sub>
is updated intoF*0*, both versions of the le may coexist. Forks are possible and it is left to each
client (or the application) to choose which digest to track: the old one, the new one, or both.

$$
F^{\prime}
$$

$$
\delta_{F}
$$

$$
\delta_{F^{\prime}}
$$

*Non-Coordinated Certicates Generation.* There are multiple ways in which data retrieval queries
can be answered in a DSN. In some cases, e.g., IPFS, after executing a P2P protocol to discover
the storage nodes holding the desired data blocks, one gets such blocks from these nodes. In other
cases (e.g., Freenet [CSWH01] or the original Gnutella protocol), data retrieval is also answered in
a peer-to-peer non-coordinated fashion. When a query for blocks *i₁;:::;i*<sub>m</sub>propagates through the
network, every storage node replies with the blocks that it owns and these answers are aggregated
and propagated in the network until they reach the client who asked for them. Notably, data
9
aggregation and propagation may follow dierent strategies. To accommodate exible aggregation
strategies, in VDS we consider the incremental aggregation of query certicates in an arbitrary
and bandwidth-ecient fashion. For example, short certicates for le blocks *F*<sub>i</sub>and *F*<sub>j</sub>should
be mergeable into a *short* certicate for (*F*<sub>i</sub>*;F*<sub>j</sub>) and this aggregation process should be carried
on and on. Noteworthy that having certicates that stay short after each aggregation keeps the
10
communication overhead of the VDS integrity mechanism at a minimum.

$$
i_{1},\ldots,i_{m}
$$

$$
F_{i}
$$

$$
(F_{i},F_{j})
$$

$$
F_{j}
$$

Dening VDS. We dene VDS as a collection of algorithms that capture all the properties above;
these are the algorithms that can be executed by clients and storage nodes to maintain the system.
A client for a le *F* is anyone who holds a digest<sub>F</sub>with which it can: verify retrieval queries,
verify and apply updates of *F* (that result in forks ofFinto some otherF*0*). A storage node for

$$
\delta_{F}
$$

$$
\delta_{F^{\prime}}
$$

$$
\delta_{F}
$$

<sup>8</sup>
Since in a decentralized system a storage node may also be a client, an attacker could \delegate storage to itself"
and use the client’s secret key to cheat in the proof in order to steal rewards (akin to the so-called \generation
attack" in Filecoin [Lab17]).

<sup>9</sup>
E.g., in Freenet data is sent back along the same route the query came through, with the goal of providing
anonymity between who requests and who delivers data.

<sup>10</sup>
The motivation of this property is similar to that of sequential aggregate signatures, see e.g., [LMRS04,BGR12].

---

some blocks *F*<sub>I</sub>= *fF*<sub>i</sub>*g*<sub>i2I</sub>of a le *F* is anyone that in addition to *F*<sub>I</sub>stores the digest<sub>F</sub>and a
local state st<sub>F</sub>with which it can: answer and certify retrieval queries for any subset of *F*<sub>I</sub>; push
I
and certify updates of *F* that involve blocks in *F*<sub>I</sub>; verify and apply updates of *F* from other nodes.
Finally, any node can aggregate retrieval certicates for dierent blocks of the same le.

$$
F_{I}=\{F_{i}\}_{i\in I}
$$

$$
F_{I}
$$

$$
F
$$

$$
\delta_{F}
$$

$$
\cdot_{F}I
$$

$$
F_{I}^{\cdot}
$$

$$
F_{I}
$$

In our VDS notion, an update of *F* can be: (i) a modication of some blocks, (ii) appending
new blocks, or (iii) deleting some blocks (from the end). In all cases, an update of *F* results into a
le *F⁰* and a new digestF*0*.

$$
F^{\prime}
$$

$$
\delta_{F^{\prime}}
$$

In terms of eciency, in VDS the digests and every certicate (for both retrieval queries or
modications) are required to be of size at most *O*(log *jF j*); similarly, the storage node’s local state
st<sub>F</sub>has size at most *O*(*jF*<sub>I</sub>*j* + log *jF j*). In a nutshell, no node should run linearly in the size of the
I
le (unless it is explicitly storing it in full).

$$
O(\log{|F|})
$$

$$
\mathrm{s t}_{F_{I}}
$$

$$
O(|F_{I}|+\log|F|)
$$

The main security property of a VDS scheme intuitively requires that no ecient adversary
can create a certicate for falsied data blocks (or updates) that passes verication. As an extra
security property, we also consider the possibility that anyone holding a digest<sub>F</sub>can check if
the DSN is storing correctly *F* without having to retrieve it. Namely, we let VDS provide a Proof
of Storage mechanism, which we dene similarly to Proof of Retrievability [JK07] and Proof of
+
Data Possession [ABC 07]. Similarly to the case of data retrieval queries, the creation of these
proofs of storage must be possible while preserving the aforementioned properties of locality and
no-central-coordination.

$$
\delta_{F}
$$

$$
[\mathrm{A B C^{+}07}]
$$

Constructing VDS. We propose two constructions of VDS in hidden-order groups. Both our
VDS schemes are obtained by extending our rst and second SVC scheme respectively, in order to
handle updates and to ensure that all such update operations can be performed locally. In particular
we show crucial use of the new properties of our construction: subvector openings, incremental
aggregation and disaggregation, and arguments of knowledge for sub-vector commitments (the
latter for the rst scheme only).

Our two VDS schemes are based on the Strong RSA [BP97] and Strong distinct-prime-product
root [LM19], and Low Order [BBF18] assumptions and have similar performances. The second
scheme has the interesting property that the storage node can perform and propagate updates by
running in time that is independent of even its total local storage. Our rst scheme instead supports
an additional type of update that we call \CreateFrom". In it, a storage node holding a prex *F⁰*
of a le *F* can publish a new digestF*0* corresponding to *F⁰* as a new le *and* convince any client
11
about its correctness *without the need for the client to know neither F nor F⁰*. As a potential
use case for this feature, consider a network that is supposed to store the entire editing history of
some data (e.g., one or more les of a Git project); namely the *i*-th block of the VDS le contains
the data value after the *i*-th edit (e.g., the *i*-th Git commit). Then \CreateFrom" can be used to
veriably create a digest of any past version of the data (e.g., of a fork at any point in the past).
Finally, our approach is not limited to a prex of the le but to whatever subset of indices we want
to create the new le from.

$$
F^{\prime}
$$

$$
\delta_{F^{\prime}}
$$

$$
F^{\prime}
$$

$$
{F^{\prime}.^{11}}
$$

It is worth noting that by abstracting the ideas of our constructions, other VDS schemes can be
12
obtained using Merkle trees or RSA accumulators. Compared to a Merkle-tree based solution, we
can achieve constant-size certicates for every operation as well as to (eciently) support compact

<sup>11</sup>
This can be seen as a deletion that can be performed without holding the blocks to be deleted and is more ecient
to verify when the prex *F⁰* is much smaller than *F*.

$$
F^{\prime}
$$

<sup>12</sup>
In fact, a similar idea from RSA accumulators was discussed in [BBF19].

---

proofs of storage without expensive SNARKs¹³. Compared to RSA Accumulators, our rst VDS
scheme takes advantage of our AoK thanks to which it supports CreateFrom updates and compact
proofs of storage.

$$
\mathrm{S N A R K s^{13}}
$$

Finally, we note that VDS shares similarities with the notion of updatable VCs [CF13] extended
with incrementally aggregatable subvector openings. There are two main dierences. First, in VDS
updates can be applied with the help of a short advice created by the party who created the update,
whereas in updatable VC this is possible having only the update’s description. The second dierence
is that in VDS the public parameters must be short, otherwise nodes could not aord storing them.
This is not necessarily the case in VCs and in fact, to the best of our knowledge, there exists no
VC construction with short parameters that is updatable (according to the updatability notion of
[CF13]) and has incrementally aggregatable subvector openings. We believe this is an interesting
open problem.

## 1.3 Concurrent Work

+
In very recent concurrent works, Gorbunov et al. [GRWZ20] and Tomescu et al. [TAB 20] study sim-
+
ilar problems related to aggregation properties of vector commitments. In [TAB 20], Tomescu et al.
study a vector commitment scheme based on the Kate et al. polynomial commitment [KZG10]: they
show how it can be made both updatable and aggregatable, and propose an ecient Stateless Cryptocurrency based on it. In Pointproofs [GRWZ20] they propose the notion of Cross-Commitment
Aggregation, which enables aggregating opening proofs for dierent commitments, and show how
+
this notion is relevant to blockchain applications. The VC schemes in both [TAB 20] and [GRWZ20]
work in bilinear groups and have linear-size public parameters. Also, these constructions do not support incremental aggregation or disaggregation. In contrast, our VCs work in hidden-order groups,
which likely makes them concretely less ecient, but they have constant-size parameters, and they
support incremental aggregation and disaggregation. Finally, we note that by using techniques similar to [GRWZ20] we can extend our constructions to support cross-commitment aggregation; we
leave formalizing this extension for future work.

$$
\mathrm{[T A B^{+}20]}
$$

$$
\mathrm{[T A B^{+}20]}
$$

$$
\mathrm{[T A B^{+}20]}
$$

## 2 Preliminaries

In this section we describe notation and denitions used throughout the paper.

Notation. We denote the security parameter by and the set of all polynomial functions by
poly(). A function () is said *negligible* { denoted () *2* negl() { if it vanishes faster than the
inverse of any polynomial. An algorithm *A* is said PPT if it is modeled as a probabilistic Turing
machine that runs in time poly(). We denote by *y  A* (*x*) the process of running *A* on input *x*
and assigning the output to *y*. For a set *S*, *jSj* denotes its cardinality, and *x* $ *S* denotes selecting
*x* uniformly at random over *S*. For a positive integer *n 2* N we let [*n*] := *f*1*;:::;ng*. We denote
n
vectors *~v* in bold, and for *~v 2M v*<sub>i</sub>is its entry at position *i*. We let Primes() be the set of all
prime integers less than 2.

$$
\epsilon(\lambda)
$$

$$
\epsilon (\lambda) \in \operatorname {n e g l} (\lambda) - \mathrm {i f}
$$

$$
y\gets\mathcal{A}(x)
$$

$$
x\gets\natural S
$$

$$
_x
$$

$$
n\in\mathbb{N}
$$

$$
\vec{v}
$$

$$
\vec{v}\in\mathcal{M}^{n}\ v_{i}
$$

$$
[n]:=\{1,\ldots,n\}
$$

$$
2^{\lambda}
$$

<sup>13</sup>
In Merkle trees certicates depend logarithmically on the le size and linearly on the number of blocks (since they
are not aggregatable).

---

## 2.1 Groups of Unknown Order and Computational Assumptions

Our constructions use a group G of unknown (aka hidden) order, in which the Low Order assumption [BBF18] and the Strong RSA assumption [BP97] or the Strong Distinct-Prime-Product Root
assumption [LM19] (dened below) hold.

$$
\mathbb{G}
$$

We let Ggen(1 ) be a probabilistic algorithm that generates such a group G with order in a
1
specic range [ord<sub>min</sub>*;*ord<sub>max</sub>] such that*;; 2* negl().
ord1minord1max ordmax ordmin

$$
\left(1 ^ {\lambda}\right)
$$

$$
\mathbb{G}
$$

$$
\frac{1}{\mathsf{o r d}_{imathrm{}{m i n}}},\frac{1}{\mathsf{o r d}_{\mathrm{}{m a x}}},\frac{1}{\mathsf{o r d}_{\mathrm{}{m a x}}\mathsf{-d r}_{\mathrm{}{m i n}}}\in\mathsf{n e g l}(\lambda)
$$

$$
[\mathsf{o r d}_{m i n},\mathsf{o r d}_{m a x}]
$$

Denition 2.1(Low Order Assumption [BBF18]). *We say that the* low order assumption
*holds for* Ggen *if for any PPT adversary A:*
2 3

$$
\Pr \left[ \begin{array}{c c} u ^ {\ell} = 1 \\ \wedge u \neq 1 \\ \wedge 1 < \ell < 2 ^ {\mathrm {p o l y} (\lambda)} & : \mathbb {G} \leftarrow \operatorname {G g e n} (\lambda) \\ & (u, \ell) \leftarrow \mathcal {A} (\mathbb {G}) \end{array} \right] = \operatorname {n e g l} (\lambda)
$$

*Remark 2.1.* The Low Order Assumption is implied by the more commonly known Adaptive Root
assumption, which is dened below. For the reduction we refer to [BBF18]. We also notice that
the denition of the Low Order assumption given in [BBF18] is for smaller ‘, 1 < ‘ < 2 , which
was sucient for the application in the paper, whereas ours is for any polynomial-size *‘*. We note
that the same reduction to the Adaptive Root assumption described in [BBF18] also holds for our
denition of the problem.

$$
\ell,\,1<\ell<2^{\lambda}
$$

Denition 2.2(Adaptive Root Assumption [Wes18]). *We say that the* adaptive root assumption *holds for* Ggen *if for any PPT adversary* (*A₁; A₂*)*:*
2 3

$$
(\mathcal{A}_{1},\mathcal{A}_{2})
$$

$$
\Pr \left[ \begin{array}{c c} u ^ {\ell} = w & \mathbb {G} \leftarrow \operatorname {G g e n} (\lambda) \\ \wedge w \neq 1 & : (w, \mathrm {s t a t e}) \leftarrow \mathcal {A} _ {1} (\mathbb {G}) \\ & \ell \leftarrow \$ \mathrm {P r i m e s} (\lambda) \\ & u \leftarrow \mathcal {A} _ {2} (\ell , \mathrm {s t a t e}) \end{array} \right] = \operatorname {n e g l} (\lambda)
$$

Denition 2.3(Strong-RSA Assumption [BP97]). *We say that the* strong RSA assumption
*holds for* Ggen *if for any PPT adversary A:*
2 3

$$
\Pr \left[ \begin{array}{c c} u ^ {e} = g & \mathbb {G} \leftarrow \mathrm {G g e n} (\lambda) \\ \wedge e i s p r i m e & : g \leftarrow \$ \mathbb {G} \\ & (u, e) \leftarrow \mathcal {A} (\mathbb {G}, g) \end{array} \right] = \mathrm {n e g l} (\lambda)
$$

Denition 2.4(Strong Distinct-Prime-Product Root assumption [LM19]). *We say that*
*the* Strong Distinct-Prime-Product Root assumption *holds for* Ggen *if for any PPT adversary A:*
2 3

$$
\operatorname*{P r}\left[\begin{matrix}{u\prod_{i\in S}e_{i}=g}&{\mathbb{G}\leftarrow\mathsf{G g e n}(\lambda)}\\ {\wedge\forall i\:e_{i}\in\mathsf{P r i m e s}(\lambda)\;:\;g\leftarrow\ \ \ \&\ \ }\\ {\wedge\forall i\neq j,e_{i}\neq e_{j}\;\;\;\;\;\;\;\;\ u(\{e_{i}\}_{i\in S})\leftarrow\mathcal{A}(\mathbb{G},g)}\\ \end{matrix}\right]=\mathsf{n e g l}(\lambda)
$$

The assumption is implied by the strong RSA assumption over RSA groups.

As discussed in [BBF18,BBF19,LM19], two concrete instantiations of G are class groups [BH01]
and the quotient group Z *=f*1*;* 1*g* of an RSA group [Wes18]. The reason why we cannot directly
N

$$
\mathbb{D}_{N}^{*}/\{1,-1\}
$$ use the RSA group is that the order of 1*2* Z is known, and thus the adaptive root assumption
N
does not hold. In the quotient group, *f*1*;* 1*g* is the identity element; hence, knowing the order of
1 does not help in nding a root for a non-identity element and thus solving the adaptive root
assumption.

$$
-1\in\mathbb{D}_{N}^{*}
$$

$$
\{-1,1\}
$$

Shamir’s Trick. Informally speaking, Shamir’s trick [Sha83] is a way to compute an *xy*-root of a
group element *g* given an *x*-root and a *y*-root of it in groups of unknown order, when *x* and *y* are
1 1
co-prime. That is, given = *gx*, = *g*<sub>y</sub>, *x* and *y*, one can compute *a;b* st *ax* + *by* = 1 using
x y
1 ax+by a b
+ a bx
the extended gcd algorithm. Then *g*<sup>xy</sup>= *g*<sup>xy</sup>= *g*<sup>y</sup> <sup>x</sup>=. More formally, we recall the
y
following algorithm:

$$
a,b
$$

$$
y,
$$

$$
\rho_{x}=g^{\frac{1}{x}},\,\rho_{y}=g^{\frac{1}{y}}
$$

$$
a x+b y=1
$$

$$
g^{{\frac{1}{x y}}}\,=\,g^{{\frac{a x+b y}{x y}}}\,=\,g^{{\frac{a}{y}}+{\frac{b}{x}}}\,=\,\rho_{y}^{a}\cdot\rho_{x}^{b}
$$

ShamirTrick(<sub>x</sub>*;*<sub>y</sub>*;x;y*)
x y
if<sup>x</sup>6=<sup>y</sup>then return*?*
Use the extended Euclidean Algorithm to compute *a;b;d* s.t. *ax* + *by* = *d* = gcd(*x;y*)
if *d 6*= 1 then return*?*
b a
return<sub>x</sub> <sub>y</sub>

$$
(\rho_{x},\rho_{y},x,y)
$$

$$
\rho_{x}^{x}\neq\rho_{y}^{y}
$$

$$
a x+b y=d=\operatorname*{g c d}(x,y)
$$

$$
\rho_{x}^{b}\rho_{y}^{a}
$$

## 2.2 Arguments of Knowledge

Let *R* : *X W ! f*0*;* 1*g* be an NP relation for a language *L* = *fx* : *9w* s.t. *R*(*x;w*) = 1*g*. An
argument system for *R* is a triple of algorithms (Setup*;* P*;*V) such that: Setup(1 ) takes as input a
security parameter and outputs a common reference string crs; the prover P(crs*;x;w*) takes as
input the crs, the statement *x* and witness *w*; the verier V(crs*;x*) takes in the crs, the statement
*x*, and after interacting with the prover outputs 0 (reject) or 1 (accept). An execution between the
prover and verier is denoted with *h*P(crs*;x;w*)*;*V(crs*;x*)*i* = *b*, where *b 2f*0*;* 1*g* is the output of the
verier. If V uses only public randomness, we say that the protocol is public coin.

$$
R:\mathcal{X}\times\mathcal{W}\rightarrow\{0,1\}
$$

$$
\mathcal {L} = \left\{x: \exists w \text {s . t .} R (x, w) = 1 \right\}
$$

$$
\mathsf{S e t u p}(1^{\lambda})
$$

$$
\lambda
$$

$$
\mathsf{P}(\mathsf{c r s},x,w)
$$

$$
w,
$$

$$
x cdot
$$

$$
\mathsf{V}(\mathsf{c r s},x)
$$

$$
\langle\mathsf{P}(\mathsf{c r s},x,w),\mathsf{V}(\mathsf{c r s},x)\rangle=b
$$

$$
b \in \{0, 1 \}
$$

Denition 2.5(Completeness). *We say that an argument system* (Setup*;* P*;*V) *for a relation*
*R* : *XW!f*0*;* 1*g is complete if, for all* (*x;w*) *2XW such that R*(*x;w*) = 1 *we have*

$$
R:\mathcal{X}\times\mathcal{W}\rightarrow\{0,1\}
$$

$$
(x,w)\in\mathcal{X}\times\mathcal{W}
$$

$$
R(x,w)=1
$$

$$
\operatorname*{P r}\left[\langle\mathsf{P}(\mathsf{c r s},x,w),\mathsf{V}(\mathsf{c r s},x)\rangle=1:\mathsf{c r s}\leftarrow\mathsf{S e t u p}(1^{\lambda})\right]=1.
$$

Consider an adversary *A* = (*A₀; A₁*) modeled as a pair of algorithms such that *A₀*(crs)*!*
(*x;* state) (i.e. outputs an instance *x 2X* after crs Setup() is run) and *A₁*(crs*;x;* state) interacts
with a honest verier. We want an argument of knowledge to satisfy the following properties:

$$
\mathcal{A}\,=\,(\mathcal{A}_{0},\mathcal{A}_{1})
$$

$$
\mathcal{A}_{0}(\mathsf{c r s})\;\rightarrow
$$

$$
x\in\mathcal{X}
$$

$$
{mathsf c r r}\leftarrow{\mathsf S{e e t u p}}(\lambda)
$$

$$
\mathcal{A}_{1}(\mathsf{c r s},x
$$

Soundness. We say that an argument (Setup*;* P*;*V) is sound if for all PPT adversaries *A* = (*A₀; A₁*)
we have

$$
\mathcal{A}=(\mathcal{A}_{0},\mathcal{A}_{1})
$$

$$
\operatorname*{P r}\left[\begin{matrix}{\langle\mathcal{A}_{1}(\mathsf{c r s},x,\mathsf{s t a t e}),\mathsf{V}(\mathsf{c r s},x)\rangle=1}&{\mathsf{c r s}\leftarrow\mathsf{S e t u p}(\lambda)}\\ {\mathrm{~a n d~}\nexists{}}&{R{R}(x,w)=1}&{(x,\mathsf{s t a t e})\leftarrow\mathcal{A}_{0}(\mathsf{c r s})}\\ \end{matrix}\right]\in\mathsf{n e g l}(\lambda).
$$

Knowledge Extractability. We say that (Setup*;* P*;*V) is an *argument of knowledge* if for all
polynomial time adversaries *A₁* there exists an extractor *E* running in polynomial time such that,
for all adversaries *A₀* it holds
2 3

$$
\mathcal{A}_{1}
$$

$$
\mathcal{A}_{0}
$$

$$
\operatorname*{P r}\left[\begin{matrix}{\langle\mathcal{A}_{1}(\mathsf{c r s},x,\mathsf{s t a t e}),\mathsf{V}(\mathsf{c r s},x)\rangle=1}&{\mathsf{c r s}\leftarrow\mathsf{S e t a p}(\lambda)}\\ {\operatorname{a n d}\ (x,w^{\prime})\notin\mathcal{R}}&{w x\leftarrow\mathcal{A}_{0}(\mathsf{c r s})}\\ {\operatorname{a n d}\ (x,w^{\prime})\notin\mathcal{R}}&{w w^{\prime}\leftarrow\mathcal{E}(\mathsf{c r s},x,\mathsf{s t a t e})}\\ \end{matrix}\right]\in\mathsf{n e g l}(\lambda).
$$

---

Succinctness. Finally we informally recall the notion of succinct arguments, which requires the
communication and verier’s running time in a protocol execution to be independent of the witness
length.

Succinct Arguments of Knowledge for Hidden Order Groups. We recall two succinct
AoK protocols for the exponentiation relation in groups of unknown order that have been recently
proposed by Boneh et. al. [BBF19]. Both protocols work for a hidden order group G generated by
Ggen in which the adaptive root assumption holds. Also, they are public-coin protocols that can
be made non-interactive in the random oracle model using the Fiat-Shamir [FS87] heuristic and its
generalization to multi-round protocols [BCS16].

1.<u>Protocol PoE</u>: is an argument system for the following relation:

$$
R_{\mathsf{P o E}}=\{((u,w,x)\in\mathbb{G}^{2}\times\mathbb{Z},\varnothing)\,:\,u^{x}=w\in\mathbb{G}\,\,\,right,
$$

PoE is a sound argument system under the adaptive root assumption for Ggen. It is neither zeroknowledge nor knowledge sound. Its main feature is *succinctness*, as the verier can get convinced
x
about *u* = *w* without having to execute the exponentiation herself. Moreover the information
14
sent by the prover is only 1 group element.

$$
\boldsymbol{u}^{x}=\boldsymbol{w}
$$

2.<u>Protocol PoKE</u> : is an argument of knowledge for the following relation, parametrized by a generator *g 2* G:
x
*R* = (*w;x*) *2* G Z : *g* = *w 2* G

$$
g\in\mathbb{G}
$$

$$
R_{\mathsf{P o K E}^{*}}=\left\{\ w,x\ \in\mathbb{G}\times\mathbb{Z}\,:\,g^{x}=w\in\mathbb{G}\,\,\,\,\right\}
$$

PoKE is an argument of knowledge that in [BBF19] is proven secure in the generic group model
for hidden order groups [DK02]. This protocol is also succinct consisting of only 1 group element
and 1 eld element in Z₂.

$$
\mathbb{Z}_{2^{\lambda}}
$$

3.<u>Protocol PoKE2</u>: is an argument of knowledge for the following relation, parametrized by a generator *g 2* G:
x
*R* = ((*w;u*) *2* G²*;x 2* Z) : *u* = *w 2* G

$$
g\in\mathbb{G}
$$

$$
R _ {\mathrm {P o K E 2}} = \left\{\left((w, u) \in \mathbb {G} ^ {2}, x \in \mathbb {Z}\right): u ^ {x} = w \in \mathbb {G} \quad \right\}
$$

PoKE2 is similar to PoKE but it is secure for arbitrary bases *u* chosen by the adversary, instead
of bases randomly sampled a priori as in PoKE . Similarly, it is an argument of knowledge in the
generic group model for hidden order groups and is also succinct, with a proof consisting of 2
group elements and 1 element of Z₂.

$$
\mathbb{Z}_{2^{\lambda}}
$$

## 3 Vector Commitments with Incremental Aggregation

In this section, we recall the notion of vector commitment with subvector openings [CF13,LM19,
BBF19] and then we formally dene our new incremental aggregation property.

## 3.1 Vector Commitments with Subvector Openings

A vector commitment (VC) [LY10,CF13] is a primitive that allows one to commit to a vector
*~v* of length *n* in such a way that it can later open the commitment at any position *i 2* [*n*]. For

$$
i\in[n]
$$

<sup>14</sup>
Technically, this protocol is not succinct as there is no witness and the verier must read and process the exponent
*x*; however, verication is still more ecient than running the full exponentiation.

$$
x;
$$ security, a VC should be *position binding* in the sense that it is not possible to open a commitment
to two dierent values at the same position. Also, what makes VC interesting is *conciseness*, which
requires commitment and openings to be of xed size, independent of the vector’s length.

In our work we consider a generalization of vector commitments proposed by Lai and Malavolta
15
[LM19] that is called *VCs with subvector openings*, which is in turn a specialization of the notion
of *functional vector commitments* by Libert et al. [LRY16]. In a nutshell, a functional VC is like
a VC with the additional possibility of opening the commitment to a function of the committed
vector, i.e., *f* (*~v*). Subvector openings are a specic class of functions in which one can open the
commitment to an ordered collection of positions (with a short proof).

In this section we recall this generalization of vector commitments with subvector openings
(that for brevity we call SVC). It is easy to see that the original notion of Catalano and Fiore
[CF13] is a special case when the opened subvector includes one position only.

We begin by recalling the notion of subvectors from [LM19].

Denition 3.1(Subvectors [LM19]). *Let M be a set, n 2* N *be a positive integer and I* =
n
*fi₁;:::;i*<sub>jIj</sub>*g* [*n*] *be an ordered index set. For a vector ~v 2 M, the I-subvector of ~v is ~v*<sub>I</sub>:=
(*v*<sub>i</sub><sub>1</sub>*;:::;v*<sub>i</sub>)*.*
<sub>jIj</sub>

$$
n\in\mathbb{N}
$$

$$
I=
$$

$$
\left\{i_{1},\ldots,i_{|I|}\right\}\subseteq\left[n\right]
$$

$$
\vec{v}\in\mathcal{M}^{n}
$$

$$
\vec{v}
$$

$$
{\vec{v}}_{I}\ :=
$$

$$
\ v_{i_{1}},\ldots,v_{i_{|I|}})
$$

n
Let *I;J* [*n*] be two sets, and let *~v*<sub>I</sub>*;~v*<sub>J</sub>be two subvectors of some vector *~v 2M*. The *ordered*
*union* of *~v*<sub>I</sub>and *~v*<sub>J</sub>is the subvector *~v*<sub>I[J</sub>:= (*v*<sub>k</sub><sub>1</sub>*;:::;v*<sub>k</sub><sub>m</sub>), where *I [ J* = *fk₁;:::;k*<sub>m</sub>*g* is the ordered
sets union of *I* and *J*.

$$
I,J\subseteq[n]
$$

$$
\vec{v}_{I},\vec{v}_{J}
$$

$$
\vec{v}\in\mathcal{M}^{n}
$$

$$
\ {\vec{v}}_{I}
$$

$$
\vec{v}_{I\cup J}:=\left(v_{k_{1}},\ldots,v_{k_{m}}\right)
$$

$$
{vec v,}
$$

$$
I\cup J=\left\{k_{1},\ldots,k_{m}\right\}
$$

Denition 3.2(Vector Commitments with Subvector Openings). *A vector commitment*
*scheme with subvector openings (SVC) is a tuple of algorithms* VC = (VC*:* Setup*;*VC*:* Com*;*VC*:* Open*;*
VC*:* Ver) *that work as follows and satisfy* correctness*,* position binding *and* conciseness *dened below.*

VC*:* Setup(1*; M*)*!* crs *Given the security parameter, and description of a message space M for*
*the vector components, the probabilistic setup algorithm outputs a common reference string* crs*.*

$$
{\mathfrak{S e t u p}}(1^{\lambda},{\mathcal{M}})\to{\mathfrak{t}}
$$

n
VC*:* Com(crs*;~v*)*!* (*C;* aux) *On input* crs *and a vector ~v 2M, the committing algorithm outputs a*
*commitment C and an auxiliary information* aux*.*

$$
\mathsf{V C.C o m(c r s,\vec{v})}\to\left(\mathcal{C}\right)
$$

$$
\vec{v}\in\mathcal{M}^{n}
$$

m
VC*:* Open(crs*;I;~y;* aux)*!*<sub>I</sub>*On input the CRS* crs*, a vector ~y 2M, an ordered index set I* N
*and auxiliary information* aux*, the opening algorithm outputs a proof*<sub>I</sub>*that ~y is the I-subvector*
*of the committed message.*

$$
\ \vec{y}\in\mathcal{M}^{m}
$$

$$
I\subset\mathbb{N}
$$

VC*:* Ver(crs*;C;I;~y;*<sub>I</sub>)*! b 2f*0*;* 1*g On input the CRS* crs*, a commitment C, an ordered set of in-*
m
*dices I* N*, a vector ~y 2M and a proof*<sub>I</sub>*, the verication algorithm accepts (i.e., it outputs*
*1) only if*<sub>I</sub>*is a valid proof that C was created to a vector ~v* = (*v₁;:::;v*<sub>n</sub>) *such that ~y* = *~v*<sub>I</sub>*.*

$$
\mathcal{C},I,\vec{y},\pi_{I})\rightarrow b\in\left\{0,1\right\}
$$

$$
I\subset\mathbb{N}
$$

$$
\vec{y}\in\mathcal{M}^{m}
$$

$$
\pi_{I}.
$$

$$
i f\,\pi_{I}
$$

$$
{\vec{v}}=(v_{1},\ldots,v_{n})
$$

$$
{\vec{y}}={\vec{v}}_{I}
$$

Correctness. *A SVC scheme* VC *is (perfectly)* correct *if for all 2* N*, any vector length n any*
n
*ordered set of indices I* [*n*]*, and any ~v 2M, we have:*

$$
I\subseteq[n]
$$

$$
\lambda\in\mathbb{N}
$$

$$
\ {vec v\in{\mathcal{M}}^{n}}
$$

$$
\operatorname*{P r}\left[\mathsf{V C}V e r(\mathsf{c r s},C,I,\vec{v}_{I},\pi_{I})=1\right.\quad\begin{array}{c}{\mathsf{c r s}\leftarrow\mathsf{V C}.\mathsf{S e t u p}(1^{\lambda},\mathcal{M})}\\ {(C,\mathsf{a u x})\leftarrow\mathsf{V C}.\mathsf{C o m}(\mathsf{c r s},\vec{v})}\\ {\pi_{I}\leftarrow\mathsf{V C}.\mathsf{O p e n}(\mathsf{c r s},I,\vec{v}_{I},\mathsf{a u x})}\\ \end{array}
$$

<sup>15</sup>
This is also called VCs with batchable openings in an independent work by Boneh et al. [BBF19].

---

Position Binding. *A SVC scheme* VC *satises position binding if for all PPT adversaries A we*
*have:* 2 3
VC*:* Ver(crs*;C;I;~y;*) = 1

$$
\operatorname*{P r}\left[\begin{matrix}{\mathsf{V C}\mathsf{V e r}(\mathsf{c r s},C,I,\vec{y},\pi)=1}\\ {\wedge\ \vec{y}\neq\vec{y}^{\prime}\wedge}\\ {\mathsf{V C}\mathsf{V e r}(\mathsf{c r s},C,I,\vec{y}^{\prime},\pi^{\prime})=1}\\ \end{matrix}:\begin{matrix}{\mathsf{c r s}\leftarrow\mathsf{V C}\mathsf{S e t u p}(1^{\lambda},\mathcal{M})}\\ {(C,I,\vec{y},\pi,\vec{y}^{\prime},\pi^{\prime})\leftarrow\mathcal{A}(\mathsf{c r s})}\\ \end{matrix}\right]\in\mathsf{n e g l}(\lambda)
$$

Conciseness. *A vector commitment is* concise *if there is a xed polynomial p*() *in the security*
*parameter such that the size of the commitment C and the outputs of* VC*:* Open *are both bounded by*
*p*()*, i.e., they are independent of n.*

$$
p(\lambda)
$$

$$
p(\lambda)
$$

Vector Commitments with Specializable Universal CRS. The notion of VCs dened above
slightly generalizes the previous ones in which the generation of public parameters (aka common
reference string) depends on a bound *n* on the length of the committed vectors. In contrast, in our
notion VC*:* Setup is length-independent. To highlight this property, we also call this primitive *vector*
*commitments with universal CRS*.

Here we formalize a class of VC schemes that lies in between VCs with universal CRS (as
dened above) and VCs with length-specic CRS (as dened in [CF13]). Inspired by the recent
+
work of Groth et al. [GKM 18], we call these schemes VCs with *Specializable* (Universal) CRS. In
a nutshell, these are schemes in which the algorithms VC*:* Com*;*VC*:* Open and VC*:* Ver work on input
a length-specic CRS crs<sub>n</sub>. However, this crs<sub>n</sub>is generated in two steps: (i) a *length-independent,*
*probabilistic* setup crs VC*:* Setup(1*; M*), and (ii) a *length-dependent, deterministic* specialization
crs<sub>n</sub>VC*:* Specialize(crs*;n*). The advantage of this model is that, being VC*:* Specialize deterministic,
it can be executed by anyone, and it allows to re-use the same crs for multiple vectors lengths.

$$
[\mathrm{G K M^{+}18}]
$$

$$
\mathsf{c r s}_{n}
$$

$$
\mathsf{c r s}_{n}
$$

$$
\leftarrow\mathsf{V C.S e t u p(1^{\lambda},M)}
$$

$$
\mathsf{c r s}_{n}\leftarrow\mathsf V C.\mathsf{S p e c i a l i z e}(\mathsf{c r s},n)
$$

Denition 3.3(VCs with Specializable CRS). *A VC scheme* VC *has a specializable CRS if*
*there exists a DPT algorithm* VC*:* Specialize(crs*;n*) *that, on input a (universal) CRS* crs *generated*
*by* VC*:* Setup(1*; M*) *and an integer n* = poly()*, produces a specialized CRS* crs<sub>n</sub>*such that the*
??
*algorithms* VC*:* Com*,* VC*:* Open *and* VC*:* Ver *can be dened in terms of algorithms* VC*:* Com*,* VC*:* Open
<sup>?</sup>
*and* VC*:* Ver *as follows:*

$$
\mathsf{V C.S p e c i a l i z e(\mathsf{c r s},n)}
$$

$$
\mathsf{V C.S e t u p}(1^{\lambda},\mathcal{M})
$$

$$
n\,=\,\ \mathsf{p o l y}(\lambda)
$$

$$
\mathit{C R S6c\ s{}}_{n}
$$

$$
\ {vee!.}{\mathsf{C o m}}^{\ }
$$

$$
\ {\sf{V C}}.{{psf e n}}^{\star}
$$

???
{ VC*:* Com(crs*;~v*) *sets n* := *j~vj, runs* crs<sub>n</sub>VC*:* Specialize(crs*;n*) *and* (*C;*aux) VC*:* Com (crs<sub>n</sub>*;~v*)*,*
??
*and returns C* := (*C;n*) *and* aux := (aux*;n*)*.*

$$
.mathsf C C o(\mathsf{c r s},\vec{v})
$$

$$
n:=|\vec{v}|
$$

$$
\mathsf{c r s}_{n}\leftarrow\mathsf V C.\mathsf{S p e c i a l i z e}(\mathsf{c r s},n)
$$

$$
(\hat{C}^{\star},\mathsf{a t x}^{\star})\leftarrow\mathsf{V c m}^{\star}(\mathsf{c t s}_{n},\vec{v})
$$

$$
C:=(C^{\star},n)
$$

$$
\mathsf{a u x}:=\left(\mathsf{a u x}^{\star},n\right)
$$

?
{ VC*:* Open(crs*;I;~y;* aux) *parses* aux := (aux*;n*)*, runs* crs<sub>n</sub>VC*:* Specialize(crs*;n*) *and returns*
??
*I*VC*:* Open (crsn*;I;~y;* aux )*.*

$$
:\!=\;(\mathsf{a u x}^{\star},n)
$$

$$
c s_{n}\leftarrow V c.S p e c d i/e(l r s,n)
$$

$$
\pi_{I}\leftarrow V C.O D e n^{\star}(\sf{c r S}_{n},I,\vec{y},a lsf^{{\ }!l}{x}^{{\star}})
$$

?
{ VC*:* Ver(crs*;C;I;~y;*<sup>I</sup>) *parses C* := (*C;n*)*, runs* crs<sub>n</sub>VC*:* Specialize(crs*;n*) *and returns*
??
VC*:* Ver (crs<sub>n</sub>*;C;I;~y;*<sub>I</sub>)*.*

$$
-mathsf V C C,\mathsf{V e r}(\mathsf{c r s},\mathcal{C},I,\vec{y},\pi_{I})
$$

$$
C:=(C^{\star},n)
$$

$$
C s_{n}\leftarrow V C.S D e c i d l i z e(C1,)nonumber
$$

$$
\mathsf{V C.V e r}^{\star}(\mathsf{c r s}_{n},\mathcal{C}^{\star},I,\vec{y},\pi_{I})
$$

Basically, for a VC with specializable CRS it is sucient to describe the algorithms VC*:* Setup*;*
???
VC*:* Specialize*;*VC*:* Com*;*VC*:* Open and VC*:* Ver. Furthermore, a concrete advantage is that when
working on multiple commitments, openings and verications that involve the same length *n*, one
can execute crs<sub>n</sub>VC*:* Specialize(crs*;n*) only once.

$$
\mathsf{V C.e r^{\star}}
$$

$$
\mathsf{V C.C o m}^{\star},\mathsf{V C.0p e n}^{\star}
$$

$$
n,
$$

## 3.2 Incrementally Aggregatable Subvector Openings

$$
C s_{n}\leftarrow..5!p_a c e a d i e e(c1s,n)
$$

In a nutshell, aggregation means that dierent proofs of dierent subvector openings can be merged
together into a single *short* proof which can be created *without* knowing the entire committed vector.

---

Moreover, this aggregation is composable, namely aggregated proofs can be further aggregated.
Following a terminology similar to that of aggregate signatures, we call this property *incremental*
*aggregation* (but can also be called *multi-hop aggregation*). In addition to aggregating openings, we
also consider the possibility to \disaggregate" them, namely from an opening of positions in the
set *I* one can create an opening for positions in a set *K I*.

$$
K\subset I
$$

We stress on the two main requirements that make aggregation and disaggregation non-trivial:
all openings must remain short (independently of the number of positions that are being opened),
and aggregation (resp. disaggregation) must be computable locally, i.e., without knowing the whole
committed vector. Without such requirements, one could achieve this property by simply concatenating openings of single positions.

Denition 3.4(Aggregatable Subvector Openings). *A vector commitment scheme* VC *with*
*subvector openings is called* aggregatable *if there exists algorithms* VC*:* Agg*,* VC*:* Disagg *working as*
*follows:*

VC*:* Agg(crs*;* (*I;~v*<sub>I</sub>*;*<sub>I</sub>)*;* (*J;~v*<sub>J</sub>*;*<sub>J</sub>))*!*<sub>K</sub>*takes as input two triples* (*I;~v*<sub>I</sub>*;*<sub>I</sub>)*;* (*J;~v*<sub>J</sub>*;*<sub>J</sub>) *where I*
jIj jJ j
*and J are sets of indices, ~v*<sub>I</sub>*2M and ~v*<sub>J</sub>*2M are subvectors, and*<sub>I</sub>*and*<sub>J</sub>*are opening*
*proofs. It outputs a proof*<sub>K</sub>*that is supposed to prove opening of values in positions K* = *I [ J.*

$$
\ \ cdot\mathsf{A g g}(\mathsf{c r s},(I,\vec{v}_{I},\pi_{I}),(J,\vec{v}_{J},\pi_{J}))\to\pi_{K}
$$

$$
(I,\vec{v}_{I},\pi_{I}),(J,\vec{v}_{J},\pi_{J})
$$

$$
\vec{v}_{I}\,\in\,\mathcal{M}^{|I|}
$$

$$
\vec{v}_{J}\in\mathcal{M}^{|J|}
$$

$$
\pi I
$$

$$
\pi J
$$

$$
\pi_{K}
$$

$$
K=I\cup J
$$

VC*:* Disagg(crs*;I;~v*<sub>I</sub>*;*<sub>I</sub>*;K*)*!*<sub>K</sub>*takes as input a triple* (*I;~v*<sub>I</sub>*;*<sub>I</sub>) *and a set of indices K I, and*
*it outputs a proof*<sub>K</sub>*that is supposed to prove opening of values in positions K.*

$$
I,\vec{v}_{I},\pi_{I},K)\rightarrow\pi_{K}
$$

$$
(I,\vec{v}_{I},\pi_{I})
$$

$$
K\subset I
$$

$$
\pi_{K}
$$

$$
K
$$

*The aggregation algorithm* VC*:* Agg *must guarantee the following two properties:*

Aggregation Correctness. *Aggregation is (perfectly) correct if for all 2* N*, all honestly gener-*
*ated* crs VC*:* Setup(1*; M*)*, any commitment C and triple* (*I;~v*<sub>I</sub>*;*<sub>I</sub>) *s.t.* VC*:* Ver(crs*;C;I;~v*<sub>I</sub>*;*<sub>I</sub>) =
1*, the following two properties hold:*

$$
\lambda\in\mathbb{N},
$$

$$
\leftarrow\ {mathsf V C C}.{\mathsf{S e t u p}}(1^{\lambda},{\mathcal{M}})
$$

$$
(I,\vec{v}_{I},\pi_{I})
$$

$$
\ \mathsf V V e(\mathsf{c r s},mathcal{C},I,\vec{v}_{I},\pi_{I})=
$$

*1.for any triple* (*J;~v*<sub>J</sub>*;*<sub>J</sub>) *such that* VC*:* Ver(crs*;C;J;~v*<sub>J</sub>*;*<sub>J</sub>) = 1*,*

$$
\mathsf{r}(\mathsf{c r s},C,J,\ \ \vec{v}_{J},\pi_{J})=1
$$

$$
(J,\vec{v}_{J},\pi_{J})
$$

$$
\Pr \left[ \mathrm {V C}. \operatorname {V e r} \left(\mathrm {c r s}, C, K, \vec {v} _ {K}, \pi_ {K}\right) = 1: \pi_ {K} \leftarrow \mathrm {V C}. \operatorname {A g g} \left(\mathrm {c r s}, \left(I, \vec {v} _ {I}, \pi_ {I}\right), \left(J, \vec {v} _ {J}, \pi_ {J}\right)\right) \right] = 1
$$

*where K* = *I[J and ~v*<sub>K</sub>*is the ordered union ~v*<sub>I[J</sub>*of ~v*<sub>I</sub>*and ~v*<sub>J</sub>*;*

$$
K=I\cup J
$$

$$
\vec{v}_{K}
$$

$$
\ {\vec{v}}_{I\cup J}
$$

$$
\vec{v}_{I}
$$

$$
\ {\vec{v}}_{J}
$$

*2.for any subset of indices K I,*

$$
K\subset I
$$

$$
\operatorname*{P r}\left[\mathsf{V C,V e r}(\mathsf{c r s},C,K,\vec{v}_{K},\pi_{K})=1\,:\,\pi_{K}\gets\mathsf{V C.D i s a g g}(\mathsf{c r s},I,\vec{v}_{I},\pi_{I},K)\right]=1
$$

$$
\vec{v}_{K}=(v_{i_{l}})_{i_{l}\in K}
$$

*where ~v*<sub>K</sub>= (*v*<sub>i</sub>)<sub>i</sub> <sub>2K</sub>*, for ~v*<sub>I</sub>= (*v*<sub>i</sub><sub>1</sub>*;:::;v*<sub>i</sub>)*.*
l l <sub>jIj</sub>

$$
{\vec{v}}_{I}=(v_{i_{1}},\ldots,v_{i_{|I|}})
$$

Aggregation Conciseness. *There exists a xed polynomial p*( ) *in the security parameter such*
*that all openings produced by* VC*:* Agg *and* VC*:* Disagg *have length bounded by p*()*.*

$$
p(\cdot)
$$

$$
p(\lambda)
$$

We remark that the notion of specializable CRS can apply to aggregatable VCs as well. In this
??
case, we let VC*:* Agg (resp. VC*:* Disagg) be the algorithm that works on input the specialized crs<sub>n</sub>
instead of crs.

$$
\mathsf{V C.A g g}^{\star}
$$

$$
\mathsf{c r s}_{n}
$$

---

## 4 Applications of Incremental Aggregation

We discuss two general applications of the incremental aggregation property of vector commitments.

One application is generating subvector openings in a distributed and decentralized way. Namely,
assume a set of parties hold each an opening of some subvector. Then it is possible to create
a (concise) opening for the union of their subvectors by using the VC*:* Agg algorithm. Moreover,
the incremental (aka multi-hop) aggregation allows these users to perform this operation in an
arbitrary order, hence no coordination or a central aggregator party are needed. This application
is particularly useful in our extension to veriable decentralized storage.

The second application is to generate openings in a faster way via preprocessing. As we mentioned in the introduction, this technique is useful in the scenario where a user commits to a vector
and then must generate openings for various subvectors, which is for example the use case when
the VC is used for proofs of retrievability and IOPs [BBF19].

So, here the goal is to achieve a method for computing subvector openings in time sub-linear
in the total size of the vector, which is the barrier in all existing constructions. To obtain this
speedup, the basic idea is to (A) compute and store openings for all the position at commitment
time, and then (B) use the aggregation property to create an opening for a specic set of positions.
In order to obtain eciency using this approach it is important that both steps (A) and (B) can be
computed eciently. In particular, step (A) is challenging since typically computing one opening
takes linear time, hence computing all of them would take quadratic time.

In this section, we show how steps (A) and (B) can benet from disaggregation and aggregation
respectively. As a preliminary for this technique, we begin by describing two generic extensions of
(incremental) aggregation (resp. disaggregation) that support many inputs (resp. outputs). Then we
show how these extended algorithms can be used for committing and opening with preprocessing.

## 4.1 Divide-and-Conquer Extensions of Aggregation and Disaggregation

We discuss how the incremental property of our aggregation and disaggregation can be used to
dene two extended versions of these algorithms. The rst one is an algorithm that can aggregate
many openings for dierent sets of positions into a single opening for their union. The second one
does the opposite, namely it disaggregates one opening for a set *I* into many openings for partitions
of *I*.

Aggregating Many Openings We consider the problem of aggregating several openings for
S
n
sets of positions *I₁;:::;I*<sub>m</sub>into a single openi<sub>n</sub>g for *I*<sub>j</sub>. Our syntax in Denition3.4only
j=1
considers pairwise aggregation. This can be used to handle many aggregations by executing the
pairwise aggregation in a sequential (or arbitrary order) fashion. Sequential aggregation might
however be costly since it would require executing VC*:* Agg on increasingly growing sets. If *f*<sub>a</sub>(*k*) is
the complexity of VC: Agg on two sets of total size *k*, then the total complexity of the sequential
P Pj 1
m
method is f ( <sub>j</sub>I<sub>l</sub>j + jIj<sub>j</sub>), which *f*or example is quadratic in *m*, for *f*<sub>a</sub>(*k*) = (*k*).
*j*=2 l=1

$$
I_{1},\ldots,I_{m}
$$

$$
\cup_{j=1}^{n}I_{j}
$$

$$
f_{a}(k)
$$

$$
\textstyle\sum_{j=2}^{m}f\bigl(\sum_{l=1}^{j-1}\left|I_{l}\right|+\left|I_{j}\right|\bigr)
$$

$$
m,
$$

$$
f_{a}(k)=\theta(k)
$$

In Fig.1, we show an algorithm, VC*:* AggManyToOne, that is a nearly optimal solution for
aggregating *m* openings based on a divide-and-conquer methodology. Assuming for simplicity that
all *I*<sub>j</sub>’s have size bounded by some *s*, then the complexity of VC*:* AggManyToOne is given by the
following recurrence relation:
<u>m</u>

$$
I _ {j} \mathrm {' s}
$$

$$
T(m)=2T\left({frac{m}{2}}\right)+f_{a}(s\cdot m)
$$

---

<u>VC</u><u>:</u> <u>AggManyToOne(crs</u><u>;</u> <u>(</u><u>Ij;~vIj;j</u><u>)</u><sub>j2</sub><sub>[</sub><sub>m</sub><sub>]</sub><u>)</u>
1 : if *m* = 1 return 1
2 : *m⁰ m=*2
m0m
3 : *L  [*j=1Ij; *R  [j*=*m0*+1*Ij;*

<u>VC</u><u>:</u> <u>DisaggOneToMany(crs</u><u>;B;I;~vI;I</u><u>)</u>
1 : if *n* = *jIj* = *B* return *I*
2 : *n⁰ n=*2
*n0*m
3 : *L  [j*=1*ij; R  [j*=*n0*+1*ij;*

0
4 : *L* VC*:* AggManyToOne(crs*;* (*Ij;~vIj;j*)<sub>j</sub><sub>=1</sub><sub>;:::;m0</sub>) 4 :<sub>L</sub>VC*:* Disagg(crs*;I;~vI;I;L*)
0
5 : *R* VC*:* AggManyToOne(crs*;* (*Ij;~vIj;j*)<sub>j</sub><sub>=</sub><sub>m0</sub><sub>+1</sub><sub>;:::;m</sub>) 5 :<sub>R</sub>VC*:* Disagg(crs*;I;~vI;I;R*)
0
6 : *L[R* VC*:* Agg(crs*;* (*L;~vL;L*)*;* (*R;~vR;R*)) 6 : *~L* VC*:* DisaggOneToMany(crs*;B;L;~vL;*<sub>L</sub>)

7 : return *L[R*

0
7 : *~R* VC*:* DisaggOneToMany(crs*;B;R;~vR;*<sub>R</sub>)
8 : return *~Ljj~R*

$$
n^{\prime}\leftarrow n/2
$$

$$
m^{\prime}\leftarrow m/2
$$

$$
L\leftarrow\cup_{j=1}^{m^{\prime}}I_{j},\;\;\;R\leftarrow\cup_{j=m^{\prime}+1}^{m}I_{j},
$$

$$
\pi_{L}\leftarrow\mathsf{V C.A g g M a n y T o O n e}(\mathsf{c r s},(I_{j},\vec{v}_{I_{j}},\pi_{j})_{j=1,\dots,m^{\prime}})
$$

$$
\pi_{L}^{\prime}\leftarrow\mathsf{V C.D i s a g g}(\mathsf{c r s},I,\vec{v}_{I},\pi_{I},L)
$$

$$
\pi_{R}^{\prime}\leftarrow\mathsf{V C.D i s a g g}(\mathsf{c r s},I,\vec{v}_{I},\pi_{I},R)
$$

$$
\pi_{R}\leftarrow\mathsf{V C.A g g M a n y T o O n e}(\mathsf{c r s},(I_{j},\vec{v}_{I_{j}},\pi_{j})_{j=m^{\prime}+1,\dots,m})
$$

$$
L\leftarrow\cup_{j=1}^{n^{\prime}}i_{j},\;\;\;R\leftarrow\cup_{j=n^{\prime}+1}^{m}i_{j},
$$

$$
\vec {\pi} _ {L} \leftarrow \mathrm {V C}. \mathrm {D i s a g g O n e T o M a n y} (\mathrm {c r s}, B, L, \vec {v} _ {L}, \pi_ {L} ^ {\prime})
$$

$$
\pi_{L\cup R}\leftarrow\mathsf{V C.A g g}(\mathsf{c r s},(L,\vec{v}_{L},\pi_{L}),(R,\vec{v}_{R},\pi_{R}))
$$

Fig. 1. Extensions of Aggregation and Disaggregation

which for example solves to (*s m*log*m*) if *f*<sub>a</sub>(*n*) *2* (*n*), or to (*s m*log(*sm*) log*m*) if *f*<sub>a</sub>(*n*) *2*
(*n*log*n*).

$$
\Theta (s \cdot m \log m)
$$

$$
f_{a}(n)\in\Theta(n)
$$

$$
\varTheta(s\cdot m\log(s m)\log m){\mathrm{~i f~}}f_{a}(n)\in
$$

$$
\theta(n\log n)
$$

Disaggregating from One to Many Openings We consider the problem that is dual of the one
above, namely how to disaggregate an opening for a set *I* into several openings for sets *I₁;:::;I*<sub>m</sub>
that form a partition of *I*. Our syntax in Denition3.4only considers disaggregation from one set *I*
to one subset *K* of *I*. Similarly to the aggregation case, disaggregating from one set to many subsets
can be trivially obtained via a sequential application of VC*:* Disagg on all pairs (*I;I*<sub>j</sub>). This however
can be costly if the number of partitions approaches the size of *I*, e.g., if we want to disaggregate
to all the elements of *I*.

$$
I_{1},\ldots,I_{m}
$$

$$
(I,I_{j})
$$

In Fig.1, we show an algorithm, VC*:* DisaggOneToMany, we show a divide-and-conquer algorithm
for disaggregating an opening for a set *I* of size *m* into *m⁰* = *m=B* openings, each for a partition of
size *B*. For simplicity, we assume that *m* is a power of 2, and *B j m*.

$$
m^{\prime}=m/B
$$

$$
B\mid m.
$$

Let *f*<sub>d</sub>(*jIj*) be the complexity of VC*:* Disagg. Then the complexity of VC*:* DisaggOneToMany is
given by the following recurrence relation:

$$
f_{d}(|I|)
$$

$$
T(m)=2T\left(\frac{m}{2}\right)+2f_{d}(m/2)
$$

which for example solves to (*m*log(*m=B*)) if *f*<sub>d</sub>(*n*) *2* (*n*), or to (*m*log*m*log(*m=B*)) if *f*<sub>d</sub>(*n*) *2*
(*n*log*n*).

$$
\theta(m{mathrm l o o}(m/B)){\mathrm{~i f~}}f_{d}(n)\in\theta(n)
$$

$$
f_{d}(n)\in
$$

## 4.2 Committing and Opening with Precomputation

Our preprocessing method works with a exible choice of a parameter *B* that allows for dierent
time-memory tradeos. In a nutshell, ranging from 1 to *n*, a larger *B* reduces memory but increases
opening time while a smaller *B* (e.g., *B* = 1) requires larger storage overhead but gives the fastest
opening time.

$$
B\ (\mathrm{e.g.},\,B=1)
$$

Let *B* be an integer that divides *n*, and let *n⁰* = *n=B:* The core of our idea is that, during
the commitment stage, one can create openings for *n⁰* = *n=B* subvectors of *~v* that cover the all
vector (e.g., *B* contiguous positions). Let<sub>P</sub><sub>1</sub>*;:::;*<sub>P</sub>be such openings; these elements are stored
n0
as advice information.

$$
n^{\prime}\,=\,n/B
$$

$$
n^{\prime}\,=\,n/B
$$

$$
\pi_{P_{1}},\ldots,\pi_{P_{n^{\prime}}}
$$

---

Next, in the opening phase, in order to compute the opening for a subvector *~v*<sub>I</sub>of *m* positions,
one should: (i) fetch the subset of openings<sub>P</sub><sub>j</sub>such that, for some *S*, *I [*<sub>j2S</sub>*P*<sub>j</sub>, (ii) possibly
disaggregate some of them and then aggregate in order to compute<sub>I</sub>.
To give a very general example of the above process, assume one has stored and

$$
\pi_{P}{}_{j}
$$

$$
S,\,I\subseteq\cup_{j\in S}P_{j}
$$

$$
{\vec{v}}_{I}
$$

$$
\pi I
$$

| To give a very general example of the above process, assume one has stored $\pi_{\{1,2\}}$ and $\pi_{\{3,4,5\}}$ and is asked for $\pi_{\{2,3\}}$, then she has to compute first $\pi_{2}$ and $\pi_{3}$ by disaggregating $\pi_{\{1,2\}}$ and $\pi_{\{3,4,5\}}$ respectively, and then aggregate them to $\pi_{\{2,3\}}$. Below are two more examples in picture: |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| B=2 | $\vec{v}_{1}$ |  |  |  | $\vec{v}_{2}$ |  |  |  | $\vec{v}_{3}$ |  |  |  | $\vec{v}_{4}$ |  |  |  | $\vec{v}_{5}$ |  |  |  |
| B=2 | 1 | 0 | 0 | 0 | 1 | 1 | 1 | 0 | 1 | 1 | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0 |  |
| $\pi_{\{1,2\}}$ |  |  |  |  |  |  |  |  |  |  |  |  | $\pi_{\{3,4\}}$ |  |  |  | $\pi_{\{5\}}$ |  |  |  |
| $\approx p(\lambda)\cdot n/2$ bits in opening advice |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |  |
| B=n | $\vec{v}_{1}$ |  |  |  | $\vec{v}_{2}$ |  |  |  | $\vec{v}_{3}$ |  |  |  | $\vec{v}_{4}$ |  |  |  | $\vec{v}_{5}$ |  |  |  |
| B=n | 1 | 0 | 0 | 0 | 1 | 1 | 1 | 0 | 1 | 1 | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0 |  |

$$
\pi_{\{1,2\}}
$$

$$
\pi_{2}
$$

$$
\pi_{\{2,3\}}
$$

$$
\pi_{\{3,4,5\}}
$$

$$
\pi_{3}
$$

$$
\pi_{\{1,2\}}
$$

$$
\pi_{\{2,3\}}
$$

$$
\vec{v}_{1}
$$

$$
\ {\vec{v}}_{2}
$$

$$
\vec{v}_{3}
$$

$$
{\vec{v}}_{4}
$$

$$
\vec{v}_{5}
$$

$$
\pi_{{\{5\}}}
$$

$$
\approx p(\lambda)\cdot n/2
$$

$$
\vec{v}_{1}
$$

$$
{vec v}_{2}
$$

$$
\vec{v}_{3}
$$

$$
\ {\vec{v}}_{4}
$$

$$
\vec{v}_{5}
$$

*p*() bits in opening advice

The two algorithms are described in detail in Fig.2.

$$
(C, \mathrm {a u x}) \leftarrow \mathrm {V C}. \operatorname {C o m} (\mathrm {c r s}, \vec {v})
$$

<u>VC</u><u>:</u> <u>PPCom(crs</u><u>;B;~v</u><u>)</u>
1 : (*C;* aux) VC*:* Com(crs*;~v*)

<u>VC</u><u>:</u> <u>FastOpen(crs</u><u>;B;</u> <u>aux</u><u>;I</u><u>)</u>
1 : Let *Pj* := *f*(*j* 1)*B* + *i* : *i 2* [*B*]*g; 8j 2* [*n⁰*]

2 : VC*:* Open(crs*;* [*n*]*;~v;* aux) 2 : Let *I* := *fi₁;:::;i*<sup>m</sup>*g*
[
3 : *~* VC*:* DisaggOneToMany(crs*;B;*[*n*]*;~v;*) 3 : Let *S* minimal set s.t. *P* I
*j*

4 : aux := ( 1*;:::;*<sub>n0</sub>*;~v*)
5 : return *C;* aux

*j2S*
4 : for *j 2 S* do :
5 : *Ij I\Pj*
6 :j0VC*:* Disagg(crs*;Pj;~vPj;j;Ij*)
7 : endfor
8 : *I* VC*:* AggManyToOne(crs*;*((*Ij;~vIj;*<sub>j0</sub>))*j2S*)
9 : return *I*

$$
P_{j}\ :==\{(j-1)B+i\ :\:i\in\:[B]\},\forall j\:\in\:[n^{\prime}]
$$

$$
\pi^{*}\leftarrow\mathsf{V C.O0e n n}(\mathsf{c r s},[n],\vec{v},\mathsf{a u x})
$$

$$
I:=\{i_{1},\ldots,i_{m}\}
$$

$$
\vec{\pi}\leftarrow\mathsf{V C.D i s a g g O n e T o M a n y}(\mathsf{c r s},B,[n],\vec{\upsilon},\pi^{*})
$$

$$
\bigcup P_{j}\supseteq I
$$

$$
\mathsf{a u x}^{*}:=\left(\pi_{1},\ldots,\pi_{n^{\prime}},\vec{v}\right)
$$

$$
j\in S
$$

$$
I_{j}\leftarrow I\cap P_{j}
$$

$$
\pi_{j}^{\prime}\leftarrow\mathsf{V C.D i s a g g}(\mathsf{c r s},P_{j},\vec{v}_{P_{j}},\pi_{j},I_{j})
$$

$$
\pi_{I}\leftarrow\mathsf{V C.A g g M a n y T o O n e(\ c r s,\:((I_{j},\:\vec{\upsilon}_{I_{j}},:\:pi\__j{j}^{\prime}))_{j\in S})}
$$

Fig. 2. Generic algorithms for committing and opening with precomputation.

In terms of auxiliary storage, in addition to the vector *~v* itself, one needs at most (*n=B*)*p*()
bits, where *p*() is the polynomial bounding the conciseness of the SVC scheme. In terms of time
complexity, VC*:* PPCom requires one execution of VC*:* Com, one execution of VC*:* Open, and one execution of VC*:* DisaggOneToMany, which in turn depends on the complexity of VC*:* Disagg; VC*:* FastOpen
16
requires to perform *jSj* disaggregations (each with a set *jIj*j such that their sum is *jIj*), and one
execution of VC*:* AggManyToOne on *jSj* openings. Note that VC*:* FastOpen’s running time depends
only on the size *m* of the set *I* and size *B* of the buckets *P*<sub>j</sub>, and thus oers various tradeos by
adjusting *B*.

$$
\vec{v}
$$

$$
(n/B)p(\lambda)
$$

$$
p(\lambda)
$$

$$
|I_{j}|
$$

$$
|I||)^{16}
$$

$$
P_{j}
$$

More specic running times depend on the complexity of VC*:* Com*;*VC*:* Open*;*VC*:* Agg, and VC*:* Disagg
of the given SVC scheme. See AppendixBfor these results for our construction.

<sup>16</sup>
Note that for *B* = 1 the disaggregation step can be skipped.

---

## 5 Our Realizations of Incrementally Aggregatable Vector Commitments

In this section we describe our new SVC realizations.

## 5.1 Our First SVC Construction

An overview of our techniques. The basic idea underlying our VC can be described as a generic
construction from any accumulator with union proofs. Consider a vector of bits *~v* = (*v₁;:::;v*<sub>n</sub>) *2*
n
*f*0*;* 1*g*. I<sup>n</sup> order to commit to this vector we produce two accumulator, Acc₀ and Acc₁, on two
partitions of the set *S* = *f*1*;:::;ng*. Each accumulator Acc<sub>b</sub>compresses the set of positions *i* such
that *v*<sub>i</sub>= *b*. In other words, Acc<sub>b</sub>compresses the set *S*<sub>=</sub><sub>b</sub>:= *fi 2 S* : *v*<sub>i</sub>= *bg* with *b 2f*0*;* 1*g*. In order
to open to bit *b* at position *i*, one can create an accumulator membership proof for the statement
*i 2 S*~ where we denote <sub>b</sub>y *S*~ the alleged set of positions that have value *b*.
b b

$$
{\vec{v}}=\left(v_{1},\ldots,v_{n}\right)\in
$$

$$
\{0,1\}^{n}
$$

$$
\ \mathrm{A c c}_{0}
$$

$$
\ \mathsf{A c c}_{1}
$$

$$
S=\{1,\ldots,n\}
$$

$$
\mathsf{A c c}_{b}
$$

$$
\ \mathrm{A c c}_{b}
$$

$$
v_{i}=b
$$

$$
S_{=b}:=\left\{i\in S:v_{i}=b\right\}
$$

$$
i,
$$

$$
b \in \{0, 1 \}
$$

$$
i\in\tilde{S}_{b}
$$

$$
\tilde{S}_{b}
$$

However, if the commitment to *~v* is simply the pair of accumulators (Acc₀*;*Acc₁) we do not
achieve position binding as an adversary could for example include the same element *i* in both
accumulators. To solve this issue we set the commitment to be the pair of accumulators plus a
succinct non-interactive proof that the two sets *S*~*; S*~ they compress constitute together a
S 0 1
*partition* of *S*. Notably, this proof guarantees that each index *i* is in either *S*~ or *S*~, and thus
S 0 1
prevents an adversary from also opening the position *i* to the complement bit 1 *b*.

$$
\vec{v}
$$

$$
(\mathsf{A c c}_{0},\mathsf{A c c}_{1})
$$

$$
\pi\ {cal S S}
$$

$$
\tilde{S}_{0},\tilde{S}_{1}
$$

$$
\tilde{S}_{0}
$$

$$
{tilde\mathcal S}_{1}
$$

$$
1-b
$$

The construction described above could be instantiated with any accumulator scheme that
admits an ecient and succinct proof of union. We, though, directly present an ecient construction
based on RSA accumulators [Bd94,BP97,CL02,Lip12,BBF19] as this is ecient and has some
nice extra properties like aggregation and constant-size parameters. Also, part of our technical
contribution to construct this VC scheme is the construction of ecient and succinct protocols for
proving the union of two RSA accumulators built with dierent generators.

Succinct AoK Protocols for Union of RSA Accumulators Let G be a an hidden order
group as generated by Ggen, and let *g₁;g₂;g₃ 2* G be three honestly sampled random generators.
We propose a succinct argument of knowledge for the following relation

$$
g_{1},g_{2},g_{3}\in\mathbb{G}
$$

$$
R_{\mathsf{P o P r o d}_{2}}=\left\{\left((Y,C),(a,b)\right)\in\mathbb{G}^{2}\times\mathbb{Z}^{2}\::\:Y=g_{1}^{a}g_{2}^{b}\wedge C=g_{3}^{a\cdot b}\:\:\:\right\}
$$

Our protocol (described in Fig.3) is inspired by a similar protocol of Boneh et al. [BBF19], PoDDH,
for a similar relation in which there is only one generator (i.e., *g₁* = *g₂* = *g₃*, namely for DDH tuples
a b <sup>a</sup><sup>b</sup>
(*g;g;g*)). Their protocol has a proof consisting of 3 groups elements and 2 integers of bits.

$$
(\mathrm{i.e.,}\,g_{1}=g_{2}=g_{3}
$$

$$
\left(g ^ {a}, g ^ {b}, g ^ {a b}\right)
$$

As we argue later PoProd₂ is still sucient for our construction, i.e., for the goal of proving
c
that *C* = *g₃* is an accumulator to a set that is the union of sets represented by two accumulators
a b
*A* = *g₁* <sup>a</sup>nd *B* = *g₂* respectively. The idea is to invoke PoProd₂ on (*Y;C*) with *Y* = *A B*.

$$
\mathsf{P o P r o d}_{2}
$$

$$
C=g_{3}^{c}
$$

$$
B=g_{2}^{b}
$$

$$
\mathsf{P o P r o d}_{2}
$$

$$
A=g_{1}^{a}
$$

$$
(Y,C)
$$

$$
Y=A\cdot B
$$

To prove the security of our protocol we rely on the adaptive root assumption and, in a nonblack-box way, on the knowledge extractability of the PoKRep and PoKE protocols from [BBF19].
The latter is proven in the generic group model for hidden order groups (where also the adaptive
root assumption holds), therefore we state the following theorem.

Theorem 5.1. *The* PoProd₂ *protocol is an argument of knowledge for R*<sub>PoProd</sub><sub>2</sub>*in the generic group*
*model.*

$$
R_{\mathsf{P o P r o d_{2}}}
$$

---

Setup(1) : run G $ Ggen(1), *g₁;g₂;g₃* $ G, set crs := (G*;g₁;g₂;g₃*).
<u>Prover’s input:</u> (crs*;* (*Y;C*)*;* (*a;b*<u>)). Verier’s input:</u> (crs*;* (*Y;C*)).
<u>V</u><u>!</u> <u>P</u>: *‘* $ Primes()
<u>P</u><u>!</u> <u>V</u>: := ((*QY;QC*)*;ra;rb*) computed as follows
{ (*qa;qb;qc*) (*ba=‘c; bb=‘c; bab=‘c*)
{ (*ra;rb*) (*a* mod *‘;b* mod *‘*)
qa qb qc
{ (*QY;QC*) := (*g₁ g₂;g₃*)
<u>V(crs</u><u>;</u> <u>(</u><u>Y;C</u><u>)</u><u>;‘;</u><u>):</u>
{ Compute *rc ra rb*mod *‘*
‘ ra rb ‘ rc
<u>{ Output 1 i</u> <u>r</u>*a*<u>;r</u>*b*<u>2</u> <u>[</u><u>‘</u><u>]</u> <u>^ Q</u>Y<u>g₁ g₂</u> <u>=</u> <u>Y ^ Q</u>C<u>g₃</u> <u>=</u> <u>C</u>

$$
\mathtt{S e t u p}(1^{\lambda}):\;{\tt r u n}\;\mathbb{G}\leftarrow\mathtt{G g e n}(1^{\lambda}),\;g_{1},g_{2},g_{3}\leftarrow\mathfrak{s}\mathbb{G},\;\operatorname{s e t}\;{\tt c r s}:=(\mathbb{G},g_{1},g_{2},g_{3})
$$

$$
\underline{{\mathsf{{V}}}}\to\mathsf{{}}\ {mathsf{{{P}}}}\colon\ell\leftarrow\ \mathsf{{P P g i m e s}}(\lambda)
$$

$$
\underline{{\mathcal{P}\to\mathcal{V}}}:\pi:=((Q_{Y},Q_{C}),r_{a},r_{b})
$$

$$
-\ (q_{a},q_{b},q_{c})\leftarrow(\vert a/vert\vert,\vert b/vert\vert\,vert a b/vert\vert/\vert))
$$

$$
-\ (r_{a},r_{b})\leftarrow(a
$$

$$
\mathsf{V}(\mathsf{c r s},(Y,C),\ell,\pi)
$$

$$
-((_{{Y}},_{{}Q{}_{C}}):=(g_{1}^{q_{a}}g_{2}^{q_{b}},g_{3}^{q_{c}})
$$

$$
r_{c}\leftarrow r_{a}\cdot r_{b}
$$

$$
r _ {a}, r _ {b} \in [ \ell ] \wedge Q _ {Y} ^ {\ell} g _ {1} ^ {r _ {a}} g _ {2} ^ {r _ {b}} = Y \wedge Q _ {C} ^ {\ell} g _ {3} ^ {r _ {c}} = C
$$

Fig. 3. PoProd₂ protocol

Proof For ease of exposition we show a security proof for a slight variant of the protocol PoProd₂.
Then, towards the end of this proof we show that security of this variant implies security for our
0
protocol. We let PoProd₂ be the same protocol as PoProd₂ with only dierence that the prover
computes also *r*<sub>c</sub>*r*<sub>a</sub>*r*<sub>b</sub>(mod *‘*) and sends *r*<sub>c</sub>in the proof, and the verier V checks in the
verication if *r*<sub>c</sub>= *r*<sub>a</sub>*r*<sub>b</sub>(mod *‘*).

$$
\mathsf{P o P r o d}_{2}{}^{\prime}
$$

$$
r_{c}\gets r_{a}\cdot r_{b}
$$

$$
r_{c}
$$

$$
rboldsymbol{}_{c}=\boldsymbol{r}_{a}\cdot\boldsymbol{r}_{b}
$$

0
Let *A⁰* = (*A⁰*<sub>0</sub>*; A⁰*<sub>1</sub>) be an adversary of the Knowledge Extractability of PoProd₂ such that:
0 0
((*Y;C*)*;*state) *A*<sub>0</sub>(crs), *A⁰*<sub>1</sub>(crs*;* (*Y;C*)*;*state) executes with V(crs*;* (*Y;C*)) the protocol PoProd₂
and the verier accepts with a non-negligible probability. We will construct an extractor *E⁰* that
having access to the internal state of *A⁰*<sub>1</sub>and on input (crs, (*Y;C*)*;*state), outputs a witness (*a;b*)
of *R 0* with overwhelming probability and runs in (expected) polynomial time.
PoProd2

$$
\mathcal{A}^{\prime}\,=\,(\mathcal{A}_{0}^{\prime},\mathcal{A}_{1}^{\prime})
$$

$$
\ ((Y,C),\mathsf{s t a t e})\;\leftarrow\;\mathcal{A}_{0}^{\prime}(\mathsf{c r s}),\;\mathcal{A}_{1}^{\prime}(\mathsf{c r s},(Y,C),\mathsf{s t a}
$$

$$
\mathsf{V}(\mathsf{c r s},(Y,C))
$$

$$
\mathcal{E}^{\prime}
$$

$$
\mathcal{A}_{1}^{\prime}
$$

$$
R_{\sf{P o P r o d}^{\prime}}
$$

0
To prove knowledge extractability of PoProd₂ we rely on the knowledge extractability of the
protocol PoKRep from [BBF19], which is indeed implicit in our protocol. More precisely, given
0
a PoProd₂ execution between *A⁰* and V, (*‘;Q*<sub>Y</sub>*;Q*<sub>C</sub>*;r*<sub>a</sub>*;r*<sub>b</sub>*;r*<sub>c</sub>), *E⁰* constructs an adversary *A*<sub>Y</sub>=
(*A*<sub>Y;</sub><sub>0</sub>*; A*<sub>Y;</sub><sub>1</sub>) of PoKRep Knowledge Extractability and, by using the input and internal state of *A⁰*<sub>1</sub>,
simulates an execution between *A*<sub>Y</sub>and V: *A*<sub>Y;</sub><sub>0</sub>outputs (crs<sub>Y</sub>*;Y;* state) := ((G*;g₁;g₂*)*;Y;* state), *A*<sub>Y;</sub><sub>1</sub>
outputs (*Q*<sub>Y</sub>*;r*<sub>a</sub>*;r*<sub>b</sub>). It is obvious that if the initial execution is accepted by V so is the PoKRep
execution. From Knowledge Extractability of PoKRep we know that there exists an extractor *E*<sub>Y</sub>
a b
corresponding to *A*<sub>Y;</sub><sub>1</sub>that outputs (*a;b*) such th<sup>a</sup>t *g₁g₂* = *Y*. Additionally, it is implicit from the
extraction that *a* = *r*<sub>a</sub>(mod *‘*) and *b* = *r*<sub>b</sub>(mod *‘*) (for more details we refer to the Knowledge
Extractability proof of PoKRep in [BBF19]). So, *E⁰* uses *E*<sub>Y</sub>and gets (*a;b*). Similarly, it simulates
c
PoKE for *g₃* = *C*, uses the extractor *E*<sub>c</sub>and gets *c*.

$$
\mathrm {P o P r o d} _ {2} ^ {\prime}
$$

$$
\mathcal{A}^{\prime}
$$

$$
\mathsf{P}_{0}\mathsf{P r r}_{0}{\ d_{2}}^{\prime}
$$

$$
{\mathcal{A}}_{Y}\,=
$$

$$
\mathsf{V},(\ell,Q_{Y},Q_{\mathcal{C}},r_{a},r_{b},r_{c}),\,\xi^{\prime}
$$

$$
(\mathcal{A}_{Y,0},\mathcal{A}_{Y,1})
$$

$$
\mathcal{A}_{Y}
$$

$$
\ {\mathcal{A}}_{Y,0}
$$

$$
(\mathsf{c r s}_{Y},Y,\mathsf{s t a t e}):=((\mathbb{G},g_{1},g_{2}),Y,\mathsf{s t a t e}),\mathcal{A}_{Y,1}
$$

$$
(Q_{Y},r_{a},r_{b})
$$

$$
\mathcal{E}_{Y}
$$

$$
\mathcal{A}_{Y,1}
$$

$$
(a,b)
$$

$$
g_{1}^{a}g_{2}^{b}=Y
$$

$$
a=r_{a}
$$

$$
b=r_{b}
$$

$$
\ell)
$$

$$
{\mathcal{E}}^{\prime}
$$

$$
\mathcal{E}_{Y}
$$

$$
(a,b)
$$

$$
g_{3}^{c}=C
$$

$$
\mathcal{E}_{c}
$$

As one can see, the expected running time of *E⁰* is the (expected) time to obtain a successful
1
execution of the protocol plus the running time of the 2 extractors: + *t*<sub>E</sub>+ *t*<sub>E</sub><sub>c</sub>= poly().
Y

$$
{\mathcal{E}}^{\prime}
$$

$$
\frac{1}{\epsilon}+t\pm_{Y}+t\pmb{\varepsilon}_{c}=\mathsf{p o l y}(\lambda)
$$

Now what is left to prove to conclude our theorem is to show that the extracted *a;b;c* are such
that *a b* = *c* with all but negligible probability. To this end, we observe that we could run *E⁰*
0
a second time using a dierent random challenge *‘*; by using again *E*<sup>Y</sup>*; E*<sup>c</sup>(after simulating the
0 0 0 a0b0a b
corresponding PoKRep and PoKE executions) we would get *a;b;c* such th<sub>a</sub>t *g₁ g₂* = *Y* = *g₁g₂*,
c0c 0 0 <sup>0</sup>
*g₃* = *C* = *g₃*. We argue that *a* = *a*, *b* = *b* and *c* = *c* holds over the integers with overwhelming
probability under the assumption that computing a multiple of the order of the group G is hard
(such assumption is in turn implied by the adaptive root assumption). If such event does not hold
one can make a straightforward reduction to this problem. Therefore, we proceed by assuming that
from the two executions we have *a* = *a⁰*, *b* = *b⁰*, and *c* = *c⁰* over the integers. Moreover, since both

$$
\mathcal{E}^{\prime}
$$

$$
\mathcal{E}_{Y},\mathcal{E}_{c}
$$

$$
\ell;
$$

$$
g_{1}^{a^{\prime}}g_{2}^{b^{\prime}}=Y=g_{1}^{a}g_{2}^{b}
$$

$$
g_{3}^{c^{\prime}}=C=g_{3}^{c}
$$

$$
a^{\prime},b^{\prime},c^{\prime}
$$

$$
c=c^{\prime}
$$

$$
a=a^{\prime},\,b=b^{\prime}
$$

$$
a=a^{\prime},\,b=b^{\prime}
$$

$$
c=c^{\prime}
$$

---

0 0 0 0
executions are accepted we have *r*<sup>c0</sup>= *r*<sup>a</sup>*r* (mod *‘*)*) c⁰* = *a⁰ b⁰* (mod *‘*)*) c* = *a b* (mod *‘*),
b<sup>0</sup>
<sub>0</sub>
but *‘* was sampled uniformly at random from Primes() after *a;b;c* were determined. So *a b* = *c*
#f<u>factors of</u> ab cg poly()
over the integers, unless with a negligible probability = negl().
jPrimes()j jPrimes()j

$$
\boldsymbol{r}_{c}^{\prime}=\boldsymbol{r}_{a}^{\prime}\cdot\boldsymbol{r}_{b}^{\prime}
$$

$$
\ell^{\prime})\Rightarrow c^{\prime}=a^{\prime}\cdot b^{\prime}
$$

$$
\ell^{\prime})\Rightarrow c=a\cdot b
$$

$$
\ell^{\prime})
$$

$$
\ell^{\prime}
$$

$$
a,b,c
$$

$$
a\cdot b=c
$$

$$
\leq \frac {\# \left\{\text {f a c t o r s o f} a b - c \right\}}{\left| \operatorname {P r i m e s} (\lambda) \right|} \leq \frac {\operatorname {p o l y} (\lambda)}{\left| \operatorname {P r i m e s} (\lambda) \right|} = \operatorname {n e g l} (\lambda)
$$

Finally, it is trivial to reduce the Knowledge Extractability of PoProd₂ to Knowledge Ex-
0
tractability of PoProd₂. Let a generic adversary *A* against the Knowledge Extractability of protocol
PoProd₂ such that the verier accepts with a non-negligible probability, we can construct a generic
0
adversary *A⁰* against Knowledge Extractability of PoProd₂, so that the verier accepts with the
same probability. *A⁰* runs the crs Setup(1 ) algorithm and sends crs to *A*. The adversary *A*
outputs ((*Y;C*)*;*state) *A*<sup>0</sup>(crs) and sends it to *A⁰*<sub>0</sub>, which outputs as it is. Then *A⁰*<sub>1</sub>interacts with
0
V in the protocol PoProd₂ (as a prover<sup>)</sup> and at the same time with *A₁* in PoProd₂ (as a verier).
After receiving *‘* from V it forwards it to *A₁*. *A₁* answers with := ((*Q*<sup>Y</sup>*;Q*<sup>C</sup>)*;r*<sup>a</sup>*;r*<sup>b</sup>). *A⁰* computes
1
0 0
*r*<sub>c</sub>*r*<sub>a</sub>*r*<sub>b</sub>mod *‘* and sends := ((*Q*<sub>Y</sub>*;Q*<sub>C</sub>)*;r*<sub>a</sub>*;r*<sub>b</sub>*;r*<sub>c</sub>) to V. The verier V accepts with the
same probability that a verier of PoProd₂ would accept since *r*<sup>c</sup>= *r*<sup>a</sup>*r*<sup>b</sup>mod *‘* in both cases.
0
From Knowledge Extractability of PoProd₂ we know that there is an extractor *E⁰* that outputs a
witness (*a;b*). Then *E* = *E⁰* is a valid extractor for PoProd₂.

$$
\mathsf{P o P r o d}_{2}{}^{\prime}
$$

$$
\mathsf{P o P r o d}_{2}
$$

$$
\epsilon_{,}
$$

$$
\mathcal{A}^{\prime}
$$

$$
\mathsf{P o P r o d}_{2}{}^{\prime}
$$

$$
\mathcal{A}^{\prime}
$$

$$
\leftarrow\mathsf{S e t u p}(1^{\lambda})
$$

$$
\mathcal{A}.
$$

$$
((Y,C)
$$

$$
\leftarrow\mathcal{A}_{0}(\mathsf{c r s})
$$

$$
\mathcal{A}_{0}^{\prime}
$$

$$
\ {\mathcal A}_{1}^{\prime}
$$

$$
\mathcal{A}_{1}
$$

$$
\mathsf{P}_{0}\mathsf{P r r}_{0}{\ d_{2}}^{\prime}
$$

$$
\mathcal{A}_{1},\,\mathcal{A}_{1}
$$

$$
\pi:=((\mathcal{Q}_{Y},\mathcal{Q}_{\mathcal{C}}),r_{a},r_{b}).\mathcal{A}_{1}^{I}
$$

$$
r_{c}\gets r_{a}r_{b}
$$

$$
\pi^{\prime}:=((Q_{Y},Q_{\mathcal{C}}),r_{a},r_{b},r_{c})
$$

$$
\pi^{\prime}
$$

$$
\mathsf{P o P r o d}_{2}
$$

$$
\pi
$$

$$
r_{c}=r_{a}r_{b}
$$

$$
\mathrm {P o P r o d} _ {2} ^ {\prime}
$$

$$
\ {\mathcal{E}}={\mathcal{E}}^{\prime}
$$

$$
{\mathcal{E}}^{\prime}
$$

$$
\mathsf{P o P r o d}_{2}
$$

a b a b
In AppendixAwe give a protocol PoProd that proves *g₁* = *A ^ g₂* = *B* inste<sup>a</sup>d of *g₁g₂* = *Y* (i.e.,
a version of PoDDH with dierent generators). Despite being conceptually simpler, it is slightly less
ecient than PoProd₂, and thus use the latter in our VC construction.

$$
g_{1}^{a}=A\wedge g_{2}^{b}=B
$$

$$
g_{1}^{a}g_{2}^{b}=Y
$$

$$
\mathsf{P o P r o d}_{2}
$$

Hash to prime function and non-interactive PoProd₂. Our protocols can be made noninteractive by applying the Fiat-Shamir transform. For this we need an hash function that can
be modeled as a random oracle and that maps arbitrary strings to prime numbers, i.e., H<sub>prime</sub>:
17
*f*0*;* 1*g!* Primes(2). A simple way to achieve such a function is to apply a standard hash
function H : *f*0*;* 1*g! f*0*;* 1*g²* to an input *~y* together with a counter *i*, and if *p*<sub>y;i</sub>= H(*~y;i*) is
prime then output *p*<sub>y;i</sub>, otherwise continue to H(*~y;i* + 1) and so on, until a prime is found. Due to
the distribution of primes, the expected running time of this method is *O*(), assuming that H’s
outputs are uniformly distributed. We do not insist, though, in the previous or any other specic
instantiation of H<sub>prime</sub>in this work. For more discussion on hash-to-prime functions we refer to
[GHR99,CMS99,CS99,BBF19,OWB19].

$$
\mathsf{H}_{\mathsf{p r i m e}}
$$

$$
\{0,1\}^{*}\,\to\,\mathsf{P r m e s}(2\lambda)^{17}
$$

$$
\ {mathsf H::\{{0,1\}}^{*}}\rightarrow\{{0,1\}^{2\lambda}}
$$

$$
\vec{y}
$$

$$
i,
$$

$$
p_{y,i}\,=\,\mathsf{H}(\vec{y},i)
$$

$$
p_{y,i}
$$

$$
\mathsf{H}(\vec{y},i+1)
$$

$$
O(\lambda)
$$

$$
\mathsf{H}_{\mathsf{p r i m e}}
$$

Our First SVC Construction Now we are ready to describe our SVC scheme. For an intuition
we refer the reader to the beginning of this section. Also, we note that while the intuition was given
for the case of committing to a vector of bits, our actual VC construction generalizes this idea to
vectors where each item is a *block of k bits*. This is done by creating 2*k* accumulators, each of them
holding sets of indices *i* for specic positions inside each block *v*<sub>j</sub>.

$$
v_{j}
$$

Notation and Building Blocks. To describe our scheme we use the notation below:

k n
{ Our message space is *M* = *f*0*;* 1*g*. Then for a vector *~v 2M*, we de<sup>n</sup>ote with *i 2* [*n*] the vector’s
position, i.e., *v*<sub>i</sub>*2M*, and with *j 2* [*k*] the position of its *j*’th bit. So *v*<sub>ij</sub>denotes the *j*-th bit in
position *i*.

$$
\mathcal{M}=\{0,1\}^{k}
$$

$$
\vec{v}\in\mathcal{M}^{n}
$$

$$
i\in[n]
$$

$$
\mathrm{i.e.,}\ v v_{i}\in\mathcal{M}
$$

$$
j\in[k]
$$

$$
j^{\ }
$$

$$
v_{i j}
$$

$$
j-\mathrm{t h}
$$

<sup>17</sup>
As pointed out in [BBF18], although for the interactive version of such protocols the prime can be of size, the
non-interactive version requires at least a double-sized prime 2, as an explicit square root attack was presented.
=2
Notably, even in the interactive version a <sup>2</sup>-attacker would still be able to succeed in breaking knowledge-
=2
soundness with <sup>2</sup> probability, with a-sized prime.

$$
\lambda,
$$

$$
2\lambda,
$$

$$
2^{\lambda/2}
$$

$$
2^{-\lambda/2}
$$

---

{ We make use of a deterministic collision resistant function PrimeGen that maps integers to primes.
In our construction we do not need its outputs to be random (see e.g., [BBF19] for possible
instantiations).

{ As a building block, we use the PoProd₂ AoK from the previous section.

$$
\mathsf{P}_{0}\mathsf{P P r}_{0}\mathsf{d}_{2}
$$

{ PartndPrimeProd(*I;~y*)*!* ((*a*<sub>I</sub><sub>1</sub>*;b*<sub>I</sub><sub>1</sub>)*;:::;*(*a*<sub>Ik</sub>*;b*<sub>Ik</sub>)): given a set of indices *I* = *fi₁;:::;i*<sub>m</sub>*g* [*n*]
m
and a vector *~y 2M*, this function computes
0 1

$$
(I,\vec{y})\ \to{}\ ((a_{I1},b_{I1}),\dots,(a_{I k},b_{I k}))
$$

$$
\vec{y}\in\mathcal{M}^{m}
$$

$$
I=\left\{i_{1},\ldots,i_{m}\right\}\subseteq[n]
$$

$$
(a_{I j},b_{I j}):=\left(\prod_{l=1:y_{l j}=0}^{m}p_{i_{l}},\prod_{l=1:y_{l j}=1}^{m}p_{i_{l}}\right)\quad\mathrm{~f o r~}j=1,\ldots,k
$$

where *p*<sub>i</sub>PrimeGen(*i*) for all *i*.

$$
p_{i}\gets{\mathsf{P r i m e G e n}}(i)
$$

Basically, for every bit position *j 2* [*k*], the function computes the products of primes that
correspond to, respectively, 0-bits and 1-bits.

$$
j\,\in\,[k]
$$

In the special case where *I* = [*n*], we omit the set of indices from the notation of the outputs, i.e.,
PartndPrimeProd([*n*]*;~v*) outputs *a*<sub>j</sub>and *b*<sub>j</sub>.

$$
I=[n]
$$

$$
([n],\vec{v})
$$

$$
b_{j}
$$

$$
a_{j}
$$

{ PrimeProd(*I*)*! u*I: given a set of indices *I*, this function outputs the product of all primes
Q
corresponding to indices in *I*. Namely, it returns *u*<sub>I</sub>:= *p*<sub>i</sub>. In the special case *I* = [*n*], we
i2I
denote the output of PrimeProd([*n*]) as *u*<sub>n</sub>.

$$
-{\sf P r P m e P r d}(I)\,\to\,u_{I}:
$$

$$
\textstyle u_{I}:=\prod_{i\in I}p_{i}
$$

$$
I=[n]
$$

$$
u_{n}
$$

$$
\mathsf{P r i m e P r o d}([n])
$$

Notice that by construction, for any *I* and *~y*, it always holds *a*<sub>Ij</sub>*b*<sub>Ij</sub>= *u*<sub>I</sub>.

$$
a_{I j}\cdot b_{I j}=u_{I}
$$

$$
\vec{y}
$$

SVC Scheme. Below we describe our SVC scheme and then we show its incremental aggregation.

k
VC*:* Setup(1*; f*0*;* 1*g*)*!* crs generates a hidden order group G Ggen(1 ) and samples three generators *g;g₀;g₁* G. It also determines a deterministic collision resistant function PrimeGen that
maps integers to primes.
Returns crs = (G*;g;g₀;g₁;*PrimeGen)

$$
\mathsf{V C.S e t u p}(1^{\lambda},\{0,1\}^{k})\rightarrow
$$

$$
\mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda})
$$

$$
g,g_{0},g_{1}\leftarrow\mathbb{G}
$$

$$
\ mathrm\ {\mathit{R e t u r n s~c r s}}=(\mathbb{G},g,g_{0},g_{1},\mathsf{P r i m e G e n})
$$

u
VC*:* Specialize(crs*;n*)*!* crs<sub>n</sub>computes *u*<sub>n</sub>PrimeProd([*n*]) and *U*<sub>n</sub>= *g*, and returns crs<sub>n</sub>
(crs*;U*<sub>n</sub>). One can think of *U*<sub>n</sub>as an accumulator to the set [*n*].

$$
u_{n}\:\leftarrow\:\mathsf{P r i m e P r o d}([n])
$$

$$
U_{n}\,=\,g^{u}
$$

$$
{mathsf\mathsf c{r s}}_{n}\gets
$$

$$
\ {mathsf c c r},U_{n})
$$

$$
U_{n}
$$

???
VC*:* Com (crs<sub>n</sub>*;~v*)*!* (*C;*aux)does the following:

$$
\mathsf{V C.C o n}^{\star}(\mathsf{c r s}_{n},{\vec{v}})\to\left({\check{C}}^{\star},\mathsf{a l x}^{\star}\right)
$$

$$
\ {{1bf.\ }}o m p u t e\ ((a_{1},b_{1}),\ldots,(a_{k},b_{k}))\leftarrow{{sf P a r t n d P r i m e P r o d}}([n],\vec{v});\;{{\bf2n e x t}},
$$

$$
{\mathrm{f o r~a l l~}}j\in[k]{\mathrm{o c m u u t e~}}A_{j}=g_{0}^{a_{j}}{\mathrm{~a n d~}}B_{j}=g_{1}^{b_{j}}
$$

One can think of each (*A*<sub>j</sub>*;B*<sub>j</sub>) as a pair of RSA accumulators for two sets that constitute a
partition of [*n*] done according to the bits of *v₁*<sub>j</sub>*;:::;v*<sub>nj</sub>. Namely *A*<sub>j</sub>and *B*<sub>j</sub>accumulate the
sets *fi 2* [*n*] : *v*<sub>ij</sub>= 0*g* and *fi 2* [*n*] : *v*<sub>ij</sub>= 1*g* respectively.

$$
(A_{j},B_{j})
$$

$$
v_{1j},\ldots,v_{n j}
$$

$$
\{i\in[n]:v_{i j}=0\}
$$

$$
A_{j}
$$

$$
B_{j}
$$

$$
\{i\in[n]:v_{i j}=1\}
$$

(j)
2.For all *j 2* [*k*], compute *C*<sup>j</sup>= *A*<sup>j</sup>*B*<sup>j</sup>*2* G and a proof PoProd₂*:* P(crs*;* (*C*<sup>j</sup>*;U*<sup>n</sup>)*;* (*a*<sup>j</sup>*;b*<sup>j</sup>)).
prod
Such proof ensures that the sets represented by *A*<sub>j</sub>and *B*<sub>j</sub>are a partition of the set represented
by *U*<sub>n</sub>. Since *U*<sub>n</sub>is part of the CRS (i.e., it is trusted), this ensures the well-formedness of *A*<sub>j</sub>
and *B*<sub>j</sub>.
n o

$$
C_{j}=A_{j}\cdotp\boldsymbol{B}_{j}\in\mathbb{G}
$$

$$
j\in[k]
$$

$$
\pi_{\mathsf{p r o d}}^{(j)}\leftarrow\mathsf{P o P r o d_{2}.P}(\mathsf{c r s},(C_{j},U_{n}),(a_{j},b_{j}))
$$

$$
B_{j}
$$

$$
A_{j}
$$

$$
U_{n}
$$

$$
U_{n}
$$

$$
A_{j}
$$

$$
B_{j}
$$

$$
\ {operatorname r n n}\ C^{\star}:=\left(\left\{A_{1},B_{1},\ldots,A_{k},B_{k}\right\},\left\{\pi_{\mathsf{p r o d}}^{(1)},...,\pi_{\mathsf{p r o d}}^{(k)}\right\}\right)\mathrm{}{~a n d~}{\mathsf{a u x}}^{\star}:=\vec{v}.
$$

??
VC*:* Open (crs<sub>n</sub>*;I;~y;* aux)*!*<sub>I</sub>proceeds as follows:

$$
\ {sf V C.p e e}^{\star}({\sf{C r S}}_{n},I,\vec{y},{\sf{a l x}}^{\star})\to\pi_{I}
$$

$$
-\ {\mathrm{l e t}}\ J=[n]\setminus I\ {\mathrm{a n d}}\ {\mathrm{c o m p u t e}}\ ((a_{J1},b_{J1}),\ldots ldots,a_{J\ },b_{J\ }))\leftarrow{\bf P a r t e d r i m e{P r o d}}(J,U_{J});
$$

---

{ for all *j 2* [*k*] compute

$$
j\in[k]
$$

$$
\varGamma_{I j}:=g_{0}^{a_{J j}}\ \mathrm{a n d}\ \varDelta_{I j}=g_{1}^{b_{J j}}
$$

Notice that *a*<sub>Jj</sub>= *a*<sub>j</sub>*=a*<sub>Ij</sub>and *b*<sub>Jj</sub>= *b*<sub>j</sub>*=b*<sub>Ij</sub>. Also<sub>Ij</sub>is a membership witness for the set *fi*<sub>l</sub>*2 I* :
*y*<sub>lj</sub>= 0*g* in the accumulator *A*<sub>j</sub>, and similarly for<sub>Ij</sub>.

$$
a_{J j}=a_{j}/a_{I j}
$$

$$
b_{J j}=b_{j}/b_{I j}
$$

$$
P_{I j}
$$

$$
\{i_{l}\in I
$$

$$
A_{j}
$$

Return<sub>I</sub>:= *f*<sub>I</sub><sub>1</sub>*;:::;*<sub>Ik</sub>*g f* (<sub>I</sub><sub>1</sub>*;*<sub>I</sub><sub>1</sub>)*;:::;*(<sub>Ik</sub>*;*<sub>Ik</sub>)*g*

$$
\varDelta_{I j}
$$

$$
y_{l j}=0\}
$$

$$
\pi_{I}:=\{\pi_{I1},\dots,\pi_{I k}\}\leftarrow\{(\varGamma_{I1},\varDelta_{I1}),\dots,(\varGamma_{I k},\varDelta_{I k})\}
$$

??
VC*:* Ver (crs<sub>n</sub>*;C;I;~y;*<sub>I</sub>)*! b* computes ((*a*<sub>I</sub><sub>1</sub>*;b*<sub>I</sub><sub>1</sub>)*;:::;*(*a*<sub>Ik</sub>*;b*<sub>Ik</sub>)) using

$$
\ {mathsf I C C},{\mathsf{V e r}}^{\star}({\mathsf{c r s}}_{n},{\mathcal{C}}^{\star},I,{\vec{y}},\pi_{I})\to b
$$

$$
((a_{I1},b_{I1}),\ldots,(a_{I k},b_{I k}))
$$

PartndPrimeProd(*I;~y*), and then returns *b b*<sub>acc</sub>*^ b*<sub>prod</sub>where:

$$
b\gets b_{a c c}\land b_{p r o c}
$$

$$
b_{a c c}\gets\bigwedge_{j=1}^{k}\left(\varGamma_{I j}^{a_{I j}}=A_{j}\land\varDelta_{I j}^{b_{I j}}=B_{j}\right)
$$

(1)

$$
b _ {p r o d} \leftarrow \bigwedge_ {j = 1} ^ {k} \left(\mathrm {P o P r o d} _ {2}. \mathrm {V} (\mathrm {c r s}, \left(A _ {j} \cdot B _ {j}, U _ {n}\right), \pi_ {\mathrm {p r o d}} ^ {(j)})\right)
$$

(2)

?
*Remark 5.1.* For more ecient verication, VC*:* Open can be changed to include 2*k* (non-interactive)
proofs of exponentiation PoE (which using the PoKCR aggregation from [BBF19] add only *k* ele-
?
ments of G). This reduces the exponentiations cost in VC*:* Ver. As noted in [BBF19], although the
asymptotic complexity is the same, the operations are in Z₂2 instead of G, which concretely makes
up an improvement.

$$
\ {\sf{V C}}.{{psf e n}}^{\times}
$$

$$
\mathsf{V C.e r^{\star}}
$$

$$
\mathbb{L}_{2^{2}})
$$

The correctness of the vector commitment scheme described above is obvious by inspection
(assuming correctness of PoProd₂).

Incremental Aggregation. Here we show that our SVC scheme is incrementally aggregatable.

VC*:* Disagg(crs*;I;~v*<sub>I</sub>*;*<sub>I</sub>*;K*)*!*<sub>K</sub>. Let *L* := *I n K*, and *~v*<sub>L</sub>be the subvector of *~v*<sub>I</sub>at positions in *L*.
Then compute *fa*<sub>Lj</sub>*;b*<sub>Lj</sub>*g*<sub>j2</sub><sub>[</sub><sub>k</sub><sub>]</sub>PartndPrimeProd(*L;~v*<sub>L</sub>), and for each *j 2* [*k*] set:

$$
I,\vec{v}_{I},\pi_{I},K)\rightarrow\pi_{K}
$$

$$
\vec{v}_{I}
$$

$$
L:=I\setminus K
$$

$$
{\vec{v}}_{L}
$$

$$
\{a_{L j},b_{L j}\}_{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(L,\vec{v}_{L})
$$

$$
j\in[k]
$$

$$
\varGamma_{K j}\leftarrow\varGamma_{I j}^{a_{L j}},\quad\varDelta_{K j}\leftarrow\varDelta_{I j}^{b_{L j}}
$$

and return $ \pi_{K} :=\{\pi_{K1},\dots,\pi_{Kk}\}:=\{(\varGamma_{K1},\varDelta_{K1}),\dots,(\varGamma_{Kk},\varDelta_{Kk})\} $

$$
\pi_{K}:=\{\pi_{K1},\dots,\pi_{K k}\}:=\{(\varGamma_{K1},\varDelta_{K1}),\dots,(\varGamma_{K k},\varDelta_{K k})\}
$$

$$
\mathrm {V C}. \mathrm {A g g} (\mathrm {c r s}, (I, \vec {v} _ {I}, \pi_ {I}), (J, \vec {v} _ {J}, \pi_ {J})) \rightarrow \pi_ {K}: = \left\{\left(\Gamma_ {K 1}, \Delta_ {K 1}\right), \dots , \left(\Gamma_ {K k}, \Delta_ {K k}\right)\right\}.
$$

I I J J K K1 K1 Kk Kk
1.Let *L* := *I \J*. If *L 6*=*;*, set *I⁰* := *I nL* and computeI*0* VC*:* Disagg(crs*;I;~v*I*;*I*;I⁰*); otherwise
letI*0* =I.

$$
L:=I\ \cap J.\ operatorname I f f\ L\neq\emptyset
$$

$$
I^{\prime}:=I\backslash L
$$

$$
\pi_{I^{\prime}}\gets V C.D i s a g g(c\mathsf{c r s},I,\vec{v}_{I},\pi_{I},I^{\prime})
$$

$$
\pi_{I^{\prime}}=\pi_{I}
$$

2.Compute *fa*<sub>I</sub>*0*<sub>j</sub>*;b*<sub>I</sub>*0*<sub>j</sub>*g*<sub>j2</sub><sub>[</sub><sub>k</sub><sub>]</sub>PartndPrimeProd(*I;~v*<sub>I</sub>*0*) and *fa*<sub>Jj</sub>*;b*<sub>Jj</sub>*g*<sub>j2</sub><sub>[</sub><sub>k</sub><sub>]</sub>PartndPrimeProd(*J;~v*J).

$$
\operatorname{t e}\;\{a_{I^{\prime}j},b_{I^{\prime}j}\}_{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\vec{v}_{I^{\prime}})\;\mathtt{a n}
$$

$$
\{a_{J j},b_{J j}\}_{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(J,\vec{\upsilon}_{J})
$$

k k
3.ParseI0 := (<sub>I</sub>*0*j;<sub>I</sub>*0*<sub>j</sub>),<sub>J</sub>:= f(<sub>Jj</sub>*;*<sub>Jj</sub>)g, and *f*or all *j 2* [*k*], compute
j=1 j=1

$$
\boldsymbol{{\pi}}_{I^{\prime}}:=\big\{\ \ \big(\varGamma_{I^{\prime}j},\varDelta_{I^{\prime}j}\big)\big\}_{j=1}^{k},\,\pi_{J}:=\big\{\big(\varGamma_{J j},\varDelta_{J j}\big)\big\}_{j=1}^{k}
$$

$$
j\in[k]
$$

$$
\Gamma_ {K j} \leftarrow \mathbf {S h a m i r T r i c k} \left(\Gamma_ {I ^ {\prime} j}, \Gamma_ {J j}, a _ {I ^ {\prime} j}, a _ {J j}\right), \quad \Delta_ {K j} \leftarrow \mathbf {S h a m i r T r i c k} \left(\Delta_ {I ^ {\prime} j}, \Delta_ {J j}, b _ {I ^ {\prime} j}, b _ {J j}\right).
$$

Note that our algorithms above can work directly with the universal CRS crs, and do not need the
specialized one crs<sub>n</sub>.

Aggregation Correctness. The second property of aggregation correctness (the one about VC*:* Disagg)
is straightforward by construction:

$$
\mathsf{c r S}_{n}
$$

aIj
if we let *fa*<sub>Kj</sub>;b<sup>Kj</sup>*g*<sub>j2</sub><sup>[</sup><sup>k</sup><sup>]</sup>PartndPrimeProd(*K;~v*<sub>K</sub>), then *a*<sub>Ij</sub>= *a*<sub>Lj</sub>*a*<sub>Kj</sub>, and thus *A*<sub>j</sub>= =
<sub>Ij</sub>
<sup>a</sup><sub>Lj</sub><sub>a</sub><sub>Kj</sub><sub>a</sub><sub>Kj</sub>
= (<sub>a</sub>nd similarly for<sub>Kj</sub>).
Ij Kj

$$
\{a_{K j},b_{K j}\}_{j\in[k]}\:\longleftarrow\\:\\mathsf{P r r t n d P P r i m e P r o d}(K,\vec{v}_{K})\ \mathrm{{{\ t{h e n}\ }}}a_{I j}\:=\:a_{L j}\cdot a_{K j}
$$

$$
A_{j}=mathitGammaGamma_{I j}^{a_{I j}}=
$$

$$
\varGamma_{I j}^{a_{L j}\cdot a_{K j}}=\varGamma_{K j}^{a_{K j}}
$$

$$
\varDelta_{K j})
$$

---

The rst property instead follows from the correctness of Shamir’s trick if the integer values
provided as input are coprime; however since *I⁰\ J* =*;*, *a*<sub>I</sub>*0*<sub>j</sub>and *a*<sub>Jj</sub>(resp. *b*<sub>I</sub>*0*<sub>j</sub>and *b*<sub>Jj</sub>) are coprime
unless a collision occurs in PrimeGen.

$$
I^{\prime}\cap J=\emptyset,\,a_{I^{\prime}j}
$$

$$
a_{J j}\,(\mathrm{r e s p.}\,b_{I^{\prime}j}
$$

$$
b_{J j})
$$

Eciency. We summarize the eciency of our construction in terms of both the computational
cost of the algorithms and the communication (CRS, commitment and openings size). For this
analysis we consider an instantiation of PrimeGen with a deterministic function that maps every
integer in [*n*] into a unique prime number, which can be of = log*n* bits.

Our scheme is presented in order to support vectors of length *n* of *k*-bits-long strings. We
summarize eciency in terms of *k* and *n*. However, we note that *k* is actually only a parameter and
our scheme can work with any setting of vectors *~v* of length *N* of *‘*-bits long strings. In this case, it
‘
is sucient to x an arbitrary *k* that divides *‘* and to spread each *v*<sub>i</sub>*2f*0*;* 1*g* over *‘=k* positions.
For example, for *k* = 1 with have *n* = *N‘* and thus the prime size is = log(*N‘*).

$$
\vec{v}
$$

$$
v_{i}\in\{0,1\}^{\ell}
$$

$$
\ell/k
$$

$$
\alpha=\log(N\ell)
$$

$$
n=N\ell
$$

Setup. In terms of computation, VC*:* Setup generates the group description and samples 3 generators, while VC*:* Specialize computes one exponentiation in G with an (*n*)-long integer. The CRS
consists of 3 elements of G, and the specialized CRS (for any *n*) is one group element.

$$
\mathbb{G}
$$

k n
Committing. Committing to a vector *~v 2* (*f*0*;* 1*g*) requires about *k* exponentiations with an
(*n*)-long integer each. A commitment consists of 4*k* elements of G and 2*k* integers in Z₂2.

$$
\ {vec v\in(\{0,1\}^{k})^{n}}
$$

$$
\mathbb{Z}_{2^{2}\lambda}
$$

Opening. Creating an opening for a set *I* of *m* positions has about the same cost of committing,
and the opening consists of 2*k* group elements. Using the PoE to make verication more ecient
(see Remark5.1) would (naively) result to 4*k* elements. However, as described in [BBF19], many
PoE’s for coprime exponents can be aggregated into a single group element. In our case, applying
this optimization would result to *k* group elements for all the PoE’s, which totally gives 3*k* group
elements for an opening.

Verification. Verifying an opening for set *I* requires about *k* exponentiations with (*m*)-
bit integers (resp. 4*k* exponentiations with-bit integers, 2*k* multiplications in G and *O*(*km*)
multiplications in Z₂2, when using PoE) to check equation (1), plus 5*k* exponentiations with 2-bit
integers and 3*k* multiplications in G to verify PoProd₂ proofs in equation (2).

$$
(m\cdot\alpha).
$$

$$
\mathbb{Z}_{2^{2}\lambda}
$$

Aggregation and Disaggregation. Disaggregation requires 2*k* exponentiations with ((*jIj*
*jKj*))-bit integers, while aggregation requires 2*k* computations of ShamirTrick that amount to
*O*(*k*(*jIj*+*jJ j*)) operations in G. From this, we obtain that VC*:* AggManyToOne and VC*:* DisaggOneToMany
take time *O*(*ksm*log*m*) G and *O*(*km*log(*m=B*)) G, respectively.

$$
((|I|\ -
$$

$$
|K|)\alpha,
$$

$$
O \left(k \left(| I | + | J |\right) \alpha\right)
$$

$$
O(k m\log(m/B)\alpha)\;\mathbb{G}
$$

Commitment and Opening with Precomputation. Finally, let us summarize the costs of
committing and opening with preprocessing obtained by instantiating our method of Section4.2.
The preprocessing VC*:* PPCom takes time *O*(*kn*log(*n=B*)). The opening requires computing at
most *jSj m* disaggregation, each taking time *O*(*k*(*jP*<sub>j</sub>*jjIj*j)), for a total of *O*(*k*(*jSjB jIj*)),
followed by the aggregation step that counts *O*(*kjSj*log *jSj*). So, in the worst case VC*:* FastOpen
takes *O*(*k m* (log(*m*) + *B* 1)) operations of G.

$$
O(k n\alpha\log(n/B))
$$

$$
|S|\leq m
$$

$$
O(k\alpha(|P_{j}|-|I_{j}|))
$$

$$
O(k\alpha(|S|B-|I|))
$$

$$
O(k\cdot m\cdot\alpha(\log\!m)+B-1),
$$

Security. The security of our SVC scheme, i.e., position binding, can be reduced to the Strong
RSA and Adaptive root assumptions in the hidden order group G used in the construction and to
the knowledge extractability of PoProd₂.

$$
\mathbb{G}
$$

$$
\mathsf{P o P r o d}_{2}
$$

A bit more in detail the steps of the proof are as follows. Let an adversary to the position
0
binding output (*C;I;~y;;~y⁰;*). First from knowledge extractability of PoProd₂ it comes that

$$
(C,I,\vec{y},\pi,\vec{y}^{\prime},\pi^{\prime})
$$ ajbj a b u
*A B* = *g₁ g₂* <sup>a</sup>nd *g*<sup>j</sup> <sup>j</sup>= *U* = *g*<sub>n</sub>. However, this does not necessarily means that *a b* = *u* over
j j n j j n
the integers and to prove it we need the Low Order assumptions, under which it holds. Afterwards
ajbj 0
we prove that since *A*<sub>j</sub>*B*<sub>j</sub>= *g₁ g₂* no dierent proofs*;* for the same positions can pass the
verication under the strong RSA assumption, which is the core of our proof. The main caveat of
ajbjajbj
the proof is that instead of knowing that *A*<sub>j</sub>= *g₁* <sup>a</sup>nd *B*<sup>j</sup>= *g₂* we know only that *A*<sub>j</sub>*B*<sub>j</sub>= *g₁ g₂*.
The former case would directly reduce to RSA Accumulator’s security (strong RSA assumption).
For this we rst need to prove an intermediate lemma (lemma5.5) which shows that specically
ajbj
for our case *A*<sub>j</sub>*B*<sub>j</sub>= *g₁ g₂* is enough, since the choice of the primes *p*<sub>i</sub>in the exponent is restricted
to a polynomially bounded set.

$$
g^{a_{j}b_{j}}=U_{n}=g^{u_{n}}
$$

$$
A_{j}B_{j}=g_{1}^{a_{j}}g_{2}^{b_{j}}
$$

$$
a_{j}b_{j}=u_{n}
$$

$$
A_{j}B_{j}\,=\,g_{1}^{a_{j}}g_{2}^{b_{j}}
$$

$$
\pi,\pi^{\prime}
$$

$$
A_{j}=g_{1}^{a_{j}}
$$

$$
B_{j}=g_{2}^{b_{j}}
$$

$$
A_{j}B_{j}=g_{1}^{a_{j}}g_{2}^{b_{j}}
$$

$$
A_{j}B_{j}=g_{1}^{a_{j}}g_{2}^{b_{j}}
$$

$$
p_{i}
$$

Theorem 5.2(Position-Binding). *Let* Ggen *be the generator of hidden order groups where the*
*Strong RSA and Low Order assumptions hold, and let* PoProd₂ *be an argument of knowledge for*
*R*<sub>PoProd</sub><sub>2</sub>*. Then the subVector Commitment scheme dened above is position binding.*

$$
R_{\mathsf{P o P r o d_{2}}}
$$

Proof To prove the theorem we use a hybrid argument. We start by dening the game *G₀* as
the actual position binding game of Denition3.2, and our goal is to prove that for any PPT *A*,
Pr[*G₀* = 1] *2* negl().

$$
G_{0}
$$

$$
\operatorname*{P r}[G_{0}=1]\in{\mathsf{n e g l}}(\lambda)
$$

Game *G₀*:

$$
G_{0};
$$

$$
G_{0}=\mathsf{P o s B i n d_{V C}^{A}}(\lambda)
$$

$$
\ {sf{c r s}}\leftarrow{\sf{V C}}.{\sf{S e t u p}}(1^{\lambda},\mathcal{M})
$$

$$
(C,I,{\vec{y}},\pi,{\vec{y}}^{\prime},\pi^{\prime})\leftarrow\ \ {mathcal A A}(\mathsf{c r s})
$$

$$
b\gets\mathsf{V C,V e r}(\mathsf{c r s},C,I,\vec{y},\pi)=1\land\vec{y}\neq\vec{y}^{\prime}\land\mathsf{V C,V e r}(\mathsf{c r s},C,I,\vec{y}^{\prime},\pi^{\prime})=1
$$

Lemma 5.1. *For any PPT A in game G₀ there exists an algorithm E and an experiment G₁ such*
*that*

$$
G_{0}
$$

$$
\mathcal{E}
$$

$$
G_{1}
$$

$$
\operatorname*{P r}[G_{0}{\ =\ }1]{\ \ \leq\ }\operatorname*{P r}[G_{1}{\ =\ }1]+\ \mathsf{n e g l}(\lambda)
$$

Proof By construction of VC*:* Com, the commitment *C* returned by the adversary *A* in game *G₀*
contains *k* proofs of PoProd₂, and by construction of VC*:* Ver if *G₀* returns 1 all these proofs verify.
It is not hard to argue that for any adversary *A* playing in game *G₀* there is an extractor *E* that
outputs the *k* witnesses *fa*<sub>j</sub>*;b*<sub>j</sub>*g*<sub>j2</sub><sub>[</sub><sub>k</sub><sub>]</sub>.

$$
G_{0}
$$

$$
G_{0}
$$

$$
G_{0}
$$

$$
\{a_{j},b_{j}\}_{j\in[k]}
$$

$$
\mathcal{E}
$$

Game *G₁*: is the same as *G₀* except that we also execute *E*, which outputs *fa*<sub>j</sub>*;b*<sub>j</sub>*g*<sub>j2</sub><sub>[</sub><sub>k</sub><sub>]</sub>, and we
ajbj
additionally check that *U*<sub>n</sub>= *g* for <sup>a</sup>ll *j 2* [*k*]. Below is a detailed description of *G₁* in which we
\open the box" of the VC algorithms.

$$
G_{1}:
$$

$$
G_{0}
$$

$$
{\mathcal{E}},
$$

$$
\{a_{j},b_{j}\}_{j\in[k]}
$$

$$
U_{n}=g^{a_{j}b_{j}}
$$

$$
j\in[k]
$$

$$
G_{1}
$$

---

$$
G_{1}
$$

$$
\mathrm {c r s} \leftarrow \mathrm {V C}. \mathrm {S e t u p} \left(1 ^ {\lambda}, \mathcal {M}\right); \mathrm {b a d} _ {1} \leftarrow \mathrm {f a l s e}
$$

$$
(\{A_{j},B_{j}\pi_{\mathsf{g r o d}}^{(j)}\}_{j\in[k]},n),I,\vec{y},\{\varGamma_{I j},\varDelta_{I j}\}_{j\in[k]},\vec{y}^{\prime},\{\varGamma_{I j}^{\prime},\varDelta_{I j}^{\prime}\}_{j\in[k]})\leftarrow\mathcal{A}(\mathsf{c r s})
$$

$$
\{a_{j},b_{j}\}_{j\in[k]}\leftarrow\mathcal{E}(\mathsf{c r s})
$$

$$
u_{n}\gets\mathsf{P r i m e P r o d}(n);U_{n}\gets g^{u_{n}}
$$

$$
b_{p r o d}\leftarrow\bigwedge_{j=1}^{k}\Big(\mathsf{P o P r o d_{2}.V}(\mathsf{c r s},(A_{j}\cdot B_{j},U_{n}),\pi_{\mathsf{p r o d}}^{(j)})\Big)
$$

$$
b_{w i t}\leftarrow\bigwedge_{j=1}^{k}A_{j}\cdot B_{j}=g_{0}^{a_{j}}g_{j}^{b_{j}}\wedge U_{n}=g^{a_{j}\cdot b_{j}}
$$

$$
\mathbf{i f}\ b_{p r o d}=1\wedge b_{w i t}=0\ \mathbf{t h e n}\ \ \mathsf{b a d}_{1}\leftarrow\mathsf{t r u e}
$$

$$
\{a_{I j},b_{I j}\}_{j\in\{k\}}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\bar{y});\ \{\mathbf{a}_{\ell j}^{\prime},b_{\ell j}^{\prime}\}_{j\in\{k\}}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\bar{y}^{\prime})
$$

$$
b\leftarrow b_{\mathrm{}{p r o d}}\wedge\bigwedge_{j=1}^{k}\left(\varGamma_{I j}{}^{a_{I j}}=A_{j}\wedge\varDelta_{I j}{}^{b_{I j}}=B_{j}\right)\wedge\vec{y}\neq\vec{y}^{\prime}\wedge
$$

$$
\bigwedge_{j=1}^{k}\Big({\varGamma_{I j}^{\prime}}^{a_{I j}^{\prime}}=A_{j}\wedge{\varDelta_{I j}^{\prime}}^{b_{I j}^{\prime}}=B_{j}\Big)
$$

if bad₁ = true then *b* 0

return *b*

$$
b\gets0
$$

Clearly, the games *G₀* and *G₁* are identical except if the ag bad₁ is raised true, i.e., Pr[*G₀* =
1] Pr[*G₁* = 1] Pr[bad₁ = true]. However, the event in which bad₁ is set true is the event in which
one of the witnesses returned by the extractor is not correct. By the knowledge extractability of
PoProd₂ we immediately get that Pr[bad₁ = true] *2* negl().

$$
G_{0}
$$

$$
G_{1}
$$

$$
\mathtt{b a d}_{1}
$$

$$
\mathrm{P r}[G_{0}=
$$

$$
1]-\operatorname*{P r}[G_{1}=1]\leq\operatorname*{P r}[\mathsf{b a d}_{1}=\mathsf{t r u e}]
$$

$$
\ \mathrm{b a d}_{1}
$$

$$
\mathsf{P o P r o d}_{2}
$$

$$
\operatorname*{P r}[{\mathsf{b a d}}_{1}={\mathsf{t r u e}}]\in{\mathsf{n e g l}}(\lambda)
$$

ajbj
Game *G₂*: is the same as *G₁* except that *G₂* outputs 0 if there is an index *j* such that *U*<sub>n</sub>= *g*
<sup>b</sup>ut *u*<sub>n</sub>6= *a*<sub>j</sub>*b*<sub>j</sub>. Precisely, if this happens a ag bad₂ is set true and the outcome of the experiment
is 0. See below for the detailed description of *G₂*.

$$
G_{2}.
$$

$$
G_{1}
$$

$$
G_{2}
$$

$$
j
$$

$$
U_{n}=g^{a_{j}\cdot b_{j}}
$$

$$
u_{n}\neq a_{j}\cdot b_{j}
$$

$$
{\tt{b a d}}_{2}
$$

$$
G_{2}
$$

---

$$
G_{2}
$$

$$
\mathsf{c r s}\leftarrow\mathsf{V C.S e t u p}(1^{\lambda},\mathcal{M});\mathsf{b a d}_{1},\mathsf{b a d}_{2}\leftarrow\mathsf{f a l s e}
$$

$$
(\{A_{j},B_{j}\pi_{\mathsf{p r o d}}^{(j)}\}_{j\in[k]},n),I,\vec{y},\{\varGamma_{I j},\varDelta_{I j}\}_{j\in[k]},\vec{y}^{\prime},\{\varGamma_{I j}^{\prime},\varDelta_{I j}^{\prime}\}_{j\in[k]})\leftarrow\mathcal{A}(\mathsf{c r s})
$$

$$
\{a_{j},b_{j}\}_{j\in[k]}\leftarrow\mathcal{E}(\mathsf{c r s})
$$

$$
u_{n}\gets\mathsf{P r i n e P r o d}(n);U_{n}\gets g^{u_{n}}
$$

$$
b_{p r o d}\leftarrow\bigwedge_{j=1}^{k}\Big(\mathsf{P o P r o d_{2}.V}(\mathsf{c r s},(A_{j}\cdot B_{j},U_{n}),\pi_{\mathsf{p r o d}}^{(j)})\Big)
$$

$$
b_{w i t}\leftarrow\bigwedge_{j=1}^{k}A_{j}\cdot B_{j}=g_{0}^{a_{j}}g_{j}^{b_{j}}\wedge U_{n}=g^{a_{j}\cdot b_{j}}
$$

$$
\textbf {i f} b _ {p r o d} = 1 \wedge b _ {w i t} = 0 \textbf {t h e n} \mathrm {b a d} _ {1} \leftarrow \mathrm {t r u e}
$$

$$
b_{c o l}\leftarrow\bigwedge_{j=1}^{k}u_{n}=a_{j}\cdot b_{j}
$$

$$
\mathbf{i f}\ b_{r o o}=1\wedge b_{o l}=0\ \mathbf{t h e n}\ \ \mathsf{b a d}_{2}\leftarrow\mathsf{t r u e}
$$

$$
\{a_{l j},b_{l j}\}_{j\in[k]}\leftarrow\mathsf{P a r t n P r i m e P r o d}(I,\vec{y});\;\left\{a_{l j}^{\prime},b_{l j}^{\prime}\right\}_{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\vec{y}^{\prime})
$$

$$
\bigwedge_{j=1}^{k}\Big({\varGamma_{I j}^{\prime}}^{a_{I j}^{\prime}}=A_{j}\wedge{\varDelta_{I j}^{\prime}}^{b_{I j}^{\prime}}=B_{j}\Big)
$$

$$
\ {\bf i f}\ {\sf b a d}_{1}={\sf t r u e}\vee{\sf b a d}_{2}={\sf t r u e}\ {\bf t h e n}\ \ b\leftarrow0
$$

return *b*

Lemma 5.2. *If the Low Order assumption holds for* Ggen*, then* Pr[*G₁* = 1] Pr[*G₂* = 1] negl()*.*

$$
\operatorname*{P r}[G_{1}=1]-\operatorname*{P r}[G_{2}=1]\leq\mathsf{n e g l}(\lambda)
$$

Proof Clearly, *G₁* and *G₂* proceed identically except if bad₂ is set true. We claim that Pr[bad₂ =
true] is negligible for any *A; E* running in *G₂*. If this event happens, one indeed obtains an integer
*v* poly()
v = unajbjsuch that g = 12 G, where g 6= 1 and 1 < v < 2, and solves the Low Order
problem.

$$
G_{1}
$$

$$
G_{2}
$$

$$
\ \mathrm{b a d}_{2}
$$

$$
\mathrm{P r}[\mathfrak{b a d}_{2}=
$$

$$
\mathcal{A},\mathcal{E}
$$

$$
G_{2}
$$

$$
v=u_{n}-a_{j}\cdot b_{j}
$$

$$
g^{v}=1\in\mathbb{G}
$$

$$
g\neq1
$$

$$
1<v<2^{\mathsf{p o l y}(\lambda)}
$$

Game *G₃*: is an experiment that can be seen as a simplication of *G₂*.
<u>G₃</u>

$$
G_{3:}
$$

$$
G_{2}
$$

$$
G_{3}
$$

$$
\ {sf c c r}\leftarrow\ {sf V C}.{\sf e t u p}(1^{\lambda},\mathcal{M})
$$

$$
\left\{a_{j},b_{j}\right\}_{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}([n],\vec{v})
$$

$$
\{a_{I j},b_{I j}\}_{j\in[k]}\leftarrow\mathsf{P a r t n P r i m e P r o d}(I,\vec{y});\;\left\{a_{I j}^{\prime},b_{I j}^{\prime}\right\}_{j\in[k]}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\vec{y}^{\prime})
$$

$$
b\leftarrow\bigwedge_{j=1}^{k}(A_{j}\cdot B_{j}=g_{0}^{a_{j}}\cdot g_{1}^{b_{j}})\bigwedge_{j=1}^{k}\left(\varGamma_{I j}{}^{a_{I j}}=A_{j}\wedge\varDelta_{I j}{}^{b_{I j}}=B_{j}\right)\wedge\vec{y}\neq\vec{y}^{\prime}\wedge
$$

$$
\bigwedge_{j=1}^{k}\Big({\varGamma_{I j}^{\prime}}^{a_{I j}^{\prime}}=A_{j}\wedge{\varDelta_{I j}^{\prime}}^{b_{I j}^{\prime}}=B_{j}\Big)
$$

return *b*

First, we show the following lemma that relates the probability of winning in *G₃* with that of
winning in *G₂*.

$$
G_{3}
$$

$$
G_{2}
$$

---

Lemma 5.3. *For any* (*A; E*) *running in G₂ there is an A⁰ running in G₃ such that* Pr[*G₂* = 1] =
Pr[*G₃* = 1]*.*

$$
G_{2}
$$

$$
\operatorname*{P r}[G_{2}=1]=
$$

$$
(\mathcal{A},\mathcal{E})
$$

$$
G_{3}
$$

$$
\operatorname*{P r}[G_{3}=1]
$$

Proof We build *A⁰* from (*A; E*) as follows. On input crs, *A⁰* executes

$$
(\mathcal{A},\mathcal{E})
$$

(j) 0 0 0Ij
(*fA*<sub>j</sub>*;B*<sub>j</sub>*;* g<sup>j</sup>2[k]*;n*<sup>)</sup>*;I;~y; f*<sub>Ij</sub>*;*<sub>Ij</sub>*g*<sub>j2</sub><sub>[</sub><sub>k</sub><sub>]</sub>*;~y; f; g*<sub>j2</sub><sub>[</sub><sub>k</sub><sub>]</sub>) A (crs) and *fa*<sub>j</sub>*;b*<sub>j</sub>*g*<sub>j2</sub><sub>[</sub><sub>k</sub><sub>]</sub> *E* (crs).
prod Ij
k n
Next, *A⁰* reconstructs a vector *~v 2* (*f*0*;* 1*g*) from the set *fa*<sub>j</sub>*;b*<sub>j</sub>*g*<sub>j2</sub><sub>[</sub><sub>k</sub><sub>]</sub>. This can be done by setting
*v*<sub>ij</sub>= 0 if *p*<sub>i</sub>*j a*<sub>j</sub>and *v*<sub>ij</sub>= 1 if *p*<sub>i</sub>*j b*<sub>j</sub>, where *p*<sub>i</sub>PrimeGen(*i*) (in case both or neither cases occur,
abort). Finally, *A⁰* runs all the checks as in game *G₂*, and if *G₂* would output 1, then *A⁰* outputs
0 0Ij
(*~v; fA*<sup>j</sup>*;B*<sup>j</sup>*g*<sup>j2</sup><sup>[</sup><sup>k</sup><sup>]</sup>*;I;~y; f*<sup>Ij</sup>*;*<sup>Ij</sup>*g*<sup>j2</sup><sup>[</sup><sup>k</sup><sup>]</sup>*;~y⁰; f; g*<sup>j2</sup><sup>[</sup><sup>k</sup><sup>]</sup>), otherwise *A⁰* aborts.
Ij

$$
(\{A_{j},B_{j},\pi_{\mathsf{w r d d}}^{(j)}\}_{j\in[k]},n),I,\vec{y},\{\varGamma_{I j},\varDelta_{I j}\}_{j\in[k]},\vec{y}^\prime,\{\varGamma_{I j}^{\prime},\varDelta_{I j}^{\prime}\}_{j\in[k]})\leftarrow\mathcal{A}(\mathsf{c r s})
$$

$$
\{a_{j},b_{j}\}_{j\in[k]}\leftarrow\mathcal{E}(\mathsf{c r s})
$$

$$
\mathrm{N e x t},{\mathcal{A}}^{\prime}
$$

$$
\vec{v}\in(\{0,1\}^{k})^{n}
$$

$$
p_{i}\gets\mathsf{P r i m e G e n}(i)
$$

$$
v_{i j}=0
$$

$$
\{a_{j},b_{j}\}_{j\in[k]}
$$

$$
p_{i}\mid a_{j}
$$

$$
p_{i}\mid b_{j}
$$

$$
v_{i j}=1
$$

$$
G_{2}.
$$

$$
G_{2}
$$

$$
\mathcal{A}^{\prime}
$$

$$
(\vec {v}, \left\{A _ {j}, B _ {j} \right\} _ {j \in [ k ]}, I, \vec {y}, \left\{\Gamma_ {I j}, \Delta_ {I j} \right\} _ {j \in [ k ]}, \vec {y} ^ {\prime}, \left\{\Gamma_ {I j} ^ {\prime}, \Delta_ {I j} ^ {\prime} \right\} _ {j \in [ k ]})
$$

$$
\mathcal{A}^{\prime}
$$

To claim that Pr[G₂ = 1] = Pr[*G₃* = 1], we observe that whenever *G₂* returns 1 it is the case
Q
n 0
that *a*<sub>j</sub>*b*<sub>j</sub>= *u*<sub>n</sub>= *p*<sub>i</sub>for all *j 2* [*k*]; therefore *A* never aborts.
i=1

$$
\Pr [ G _ {2} = 1 ] = \Pr [ G _ {3} = 1 ]
$$

$$
G_{2}
$$

$$
a_{j}\cdot b_{j}=u_{n}=\prod_{i=1}^{n}p_{i}
$$

$$
j\in[k]
$$

Game *G₄*: this is the same as game *G₃* except that the game outputs 0 if during any computation
of lines 3 and 4 it happens that PrimeGen(*i*) = PrimeGen(*i⁰*) for distinct *i 6*= *i⁰*. It is straightforward
to show that the probability of this event is bounded by the probability of nding collisions in
PrimeGen, i.e., that under the collision resistance of PrimeGen it holds Pr[*G₃*] Pr[*G₄*] *2* negl().

$$
G_{3}
$$

$$
G_{4};
$$

$$
P r_e e G e n(i)=P r i m e G e n(i^{\prime})
$$

$$
i\neq i^{\prime}
$$

$$
\operatorname*{P r}[G_{3}]-\operatorname*{P r}[G_{4}]\in\mathsf{n e g l}(\lambda)
$$

To conclude the proof of our Theorem, we prove that any PPT adversary can win in *G₄* with
only negligible probability assuming that the strong RSA assumption holds in G.

$$
G_{4}
$$

Lemma 5.4. *If the* strong RSA assumption *holds for* Ggen*, then for every PPT adversary A⁰*
*running in game G₄ we have that Pr*[*G₄* = 1] *2* negl()*.*

$$
G_{4}
$$

$$
P r[G_{4}=1]\in{\mathsf{n e g l}}(\lambda)
$$

Proof For the proof, we rely on the following lemma that denes a computational problem that
we prove it is implied by the Strong RSA assumption.

Lemma 5.5. *Let* Ggen *be a hidden order group generation algorithm where the* strong RSA assumption *holds and* PrimeGen *a deterministic collision resistant function that maps integers to*
*primes. Then for any PPT adversary A and any n* = poly()*, the probability below is negligible:*

$$
n=\ \mathsf{p o l y}(\lambda)
$$

$$
\Pr \left[ \begin{array}{c c} u ^ {p} = g _ {0} ^ {a} \cdot g _ {1} ^ {b} & \mathbb {G} \leftarrow \operatorname {G e n e n} (\lambda) \\ \wedge (p \nmid a \vee p \nmid b) & g _ {0}, g _ {1} \leftarrow \mathbb {G} \\ \wedge u \in \mathbb {G} \wedge (a, b) \in \mathbb {Z} ^ {2} \wedge p \in S & S = \left\{p _ {i} \leftarrow \operatorname {P r i m e G e n} (i)\right\} _ {i=1} ^ {n} \\ & (u, p, a, b) \leftarrow \mathcal {A} \left(\mathbb {G}, g _ {0}, g _ {1}, S\right) \end{array} \right] \in \operatorname {n e g l} (\lambda)
$$

We proceed assuming that the lemma holds; its proof is deferred to the end.

Suppose by contradiction the existence of a PPT adversary *A⁰* such that Pr[*G₄*] = with
non-negligible. Below we show how to construct an adversary *B* that uses *A⁰* in order to solve the
problem of Lemma5.5with probability.

$$
\operatorname*{P r}|G_{4}|\,=\,\epsilon
$$

{ *B*(G*;g₀;g₁*) samples a random *g* $ G, determines a PrimeGen as in VC*:* Setup, sets
crs (G*;g;g₀;g₁;*PrimeGen), and runs *A* on input crs.

$$
g\leftarrow\S\mathbb{G}
$$

$$
- \mathcal {B} \left(\mathbb {G}, g _ {0}, g _ {1}\right)
$$

0
{ *A*(crs) responds with a tuple (*~v; fA*<sub>j</sub>*;B*<sub>j</sub>*g*<sub>j2</sub><sub>[</sub><sub>k</sub><sub>]</sub>*;I;~y;;~y⁰;*).

$$
\left(\vec{v},\{A_{j},B_{j}\}_{j\in[k]},I,\vec{y},\pi,\vec{y}^{\prime},\pi^{\prime}\right)
$$

{ *B* computes *fa*<sub>j</sub>*;b*<sub>j</sub>*g* PartndPrimeProd([*n*]*;~v*),
j2[k]
*fa*<sup>Ij</sup>*;b*<sup>Ij</sup>*g* PartndPrimeProd(*I;~y*) and
j2[k]
0Ij <sup>0Ij</sup>
*fa;b g*<sub>j2</sub><sub>[</sub><sub>k</sub><sub>]</sub>PartndPrimeProd(*I;~y⁰*) as in game *G₃*.

$$
\left\{a _ {j}, b _ {j} \right\} _ {j \in [ k ]} \leftarrow \operatorname {P a r t n d P r i m e P r o d} ([ n ], \vec {v}).
$$

$$
\left\{a_{I j},b_{I j}\right\}_{j\in[k]}\leftarrow
$$

$$
\{a_{I j}^{\prime},b_{I j}^{\prime}\}_{j\in[k]}\leftarrow
$$

$$
G_{3}
$$

---

{ If *A⁰* wins the game then we have that all the following conditions holds:

$$
\vec {y} \neq \vec {y} ^ {\prime}, \bigwedge_ {j = 1} ^ {k} \left(\Gamma_ {I j} ^ {a _ {I j}} = A _ {j} \wedge \Delta_ {I j} ^ {b _ {I j}} = B _ {j}\right) = 1, \bigwedge_ {j = 1} ^ {k} \left(\Gamma_ {I j} ^ {\prime a _ {I j} ^ {\prime}} = A _ {j} \wedge \Delta_ {I j} ^ {\prime b _ {I j} ^ {\prime}} = B _ {j}\right) = 1
$$

$$
\bigwedge_{j=1}^{k}(A_{j}\cdot B_{j}=g_{0}^{a_{j}}\cdot g_{1}^{b_{j}}).
$$

0
From *~y 6*= *~y⁰* we get that there is at least one pair of indices *l 2* [*m*] and *j 2* [*k*] such that *y*<sup>lj</sup>6= *y*.
<sup>lj</sup>
<sup>0</sup>
Say wlog that *y*<sub>lj</sub>= <sub>0</sub> and *y* = 1. Also, if we parse *I* = *fi₁;:::;i*<sub>m</sub>*g*, we let *i* = *i*<sub>l</sub>*2* [*m*]. So we
lj
x these indices *i* and *j*, and let *p*<sub>i</sub>= PrimeGen(*i*) be the corresponding prime.

$$
\vec{y}\neq\vec{y}
$$

$$
l\in[m]
$$

$$
j\in[k]
$$

$$
y_{l j}=0
$$

$$
y _ {l j} ^ {\prime} = 1
$$

$$
y_{l j}\neq y_{l j}^{\prime}
$$

$$
I=\{i_{1},\dots,i_{m}\}
$$

$$
i=i_{l}\in[m]
$$

$$
j,
$$

$$
p_{i}=\mathsf{P r i m e G e n}(i)
$$

Notice that by construction of PartndPrimeProd (and since we assumed no collision occurs in
PrimeGen) we have that either *p*<sub>i</sub>-*a*<sub>j</sub>or *p*<sub>i</sub>-*b*<sub>j</sub>holds. Additionally, by our assumption that
0 0Ij 0Ij
*y*<sup>lj</sup>= <sup>0</sup> and *y* = 1, the following holds: *p*<sup>i</sup>*j a*<sup>Ij</sup>, *p*<sup>i</sup>-*b*<sup>Ij</sup>, *p*<sup>i</sup>-*a*, *p*<sup>i</sup>*j b*.
lj

$$
p_{i}\nmid a_{j}
$$

$$
p_{i}\nmid b_{j}
$$

$$
y_{l j}=0
$$

$$
y_{l j}^{\prime}=1
$$

$$
p_{i}\:|\:a_{I j},p_{i}\:|\:b_{I j},p_{i}\:|\:a_{I j}^{\prime},p_{i}\:|\:b_{I j}^{\prime}
$$

$$
\hat{}GammaGamma,\hat{\Delta}
$$

$$
\hat{\varGamma}^{p_{i}}=A_{i}
$$

$$
\hat{\Delta}^{p_{i}}=B_{i}
$$

From the other condition on the validity of the proofs, *B* can compute two group elements*;*^ ^
^pi ^pi
such that = *A*<sub>j</sub>and = *B*<sub>j</sub>.

ajbj p ajbj
Combining this with the condition *A* B = g₀ g₁, we have that ( ^ ^) <sup>i</sup>= *g₀ g₁*.
j j

$$
A_{j}\cdot B_{j}=g_{0}^{a_{j}}\cdot g_{1}^{b_{j}}
$$

$$
(\hat{\boldsymbol{\Gamma}}\cdot\hat{\boldsymbol{\Delta}})^{p_{i}}=g_{0}^{a_{j}}\cdot g_{1}^{b_{j}}.
$$

{ *B* sets *w* = ^ ^ and outputs the tuple (*w;p;a;b*).
<sub>i</sub> <sub>j</sub> j

$$
w=\hat{\varGamma}\cdot\hat{\varDelta}
$$

$$
(w,p_{i},a_{j},b_{j})
$$

From all the above observations, if *A⁰* makes game *G₄* return 1, then the tuple returned by *B*
is a suitable solution for the problem of Lemma5.5, which in turn reduces to the Strong RSA
assumption.

$$
G_{4}
$$

By combining all the lemmas we have that any PPT adversary has at most negligible probability
of breaking the position binding of our SVC scheme.

Proof [Proof of Lemma5.5] Suppose that for a PPT adversary *A* the above probability is a
non-negligible value. We will construct an adversary *B* that breaks strong RSA assumption with
a non-negligible probability. *B* takes as input (G*;g*). We denote as *G*<sub>A</sub>the game dened in lemma
(parametrized by an adversary *A*). We dene two dierent reductions:

$$
G_{A}
$$

Reduction 1. In reduction 1 the adversary *B* breaks strong RSA assumption only in case where
the adversary *A* outputs a tuple (*u;p;a;b*) such that *p j a* (and thus from assumption *p*-*b*) and
fails otherwise. *B* proceeds as follows.

$$
(u,p,a,b)
$$

$$
p\mid a
$$

$$
p\nmid b)
$$

*B*(G*;g*) samples $ [1*;*2 ordmax], where ordmaxis the upper bound of the order of G outputted
by Ggen(1 ) (see section2.1), and sets *g₀ g;g₁ g*. *B* runs *A* on input (G*;g₀;g₁*). is sampled
from a large enough domain so that *g* is statistically close to a uniformly distributed *g₀* from G
hence *g₀;g₁* are indistinguishable to two uniformly random elements of G. *A*(G*;g₀;g₁;S*) responds
with a tuple (*u;p;a;b*) and sends it to *B*. We condition our analysis on the event *p j a*, meaning
that *B* stops in case *p*-*a*.

$$
\mathcal{B}(\mathbb{G},g)
$$

$$
\gamma\gets\ [,22^{\lambda}\mathsf{o r d}_{m a x}]
$$

$$
\mathsf{o r d}_{m a x}
$$

$$
\mathsf{G g e n}(1^{\lambda})
$$

$$
g_{0}\leftarrow g^{\gamma},g_{1}\leftarrow g.\,k
$$

$$
(\mathbb{G},g_{0},g_{1}).\,\gamma
$$

$$
g^{\gamma}
$$

$$
g_{0}
$$

$$
g_{0},g_{1}
$$

$$
\mathbb{G}.\ \mathcal{A}(\mathbb{G},g_{0},g_{1},S)
$$

$$
(u,p,a,b)
$$

$$
p\ |\ a.
$$

$$
p\nmid a
$$

p a b
Assume that *u* = *g₀ g₁ ^* (*p j a ^ p*-*b*) *^ u 2* G *^* (*a;b*) *2* Z² *^ p 2 S* then we will show
that *B* can break the strong RSA assumption. We argue that *p j a* leads to gcd(*p;a* + *b*) = 1.
Let gcd(*p;a* + *b*) 6= 1, meaning that gcd(*p;a* + *b*) = *p*, then *p j a* + *b ) a* + *b* = 0 (mod *p*).
However, *p j a ) a* = 0 (mod *p*). From the two previous facts we infer that *b* = 0 (mod *p*)*) p j b*,
hence *p j a ^ p j b*, which is a contradiction. Therefore, assuming that gcd(*p;a* + *b*) = 1, *B* uses

$$
u^{p}\,=\,g_{0}^{a}\,\cdot\,g_{1}^{b}\,\wedge\,(p\,\mid\,a\,\wedge\,p\,\dag\ b)\,\wedge\,u\,\in\,\mathbb{G}\,\wedge\,(a,\,b)\,\in\,\mathbb{Z}^{2}\,\wedge\,p\,\in\,S
$$

$$
\operatorname{l}(p,\gamma a+b)=1
$$

$$
\operatorname*{g c d}(p,\gamma a+b)\neq1
$$

$$
ptextit{||c}
$$

$$
\ !(p,\gamma a+b)=p.
$$

$$
p\mid\gamma a+b\Rightarrow\gamma a+b=0
$$

$$
p)
$$

$$
p\mid a\Rightarrow a=0
$$

$$
b=0
$$

$$
p)\Rightarrow p\,\vert|\,b
$$

$$
p\ |\ a\wedge p\ |\ b
$$ the extended Euclidean algorithm to compute (*;*) such that *p* + (*a* + *b*) = 1. We know that
a+b p+ (a+b)=1 a+b
p a b a+b =<sup>p</sup> +
*u* = *g₀g₁* = *g) u* = *g*<sup>p</sup>hence it follows that *g¹* = *g*<sup>p</sup>= *g*<sup>p</sup>= *g u*.
Finally, *B* outputs (*g u;p*) which is a valid strong-RSA solution.

$$
(\alpha,\beta)
$$

$$
\alpha p+\beta(a\gamma+b)=1
$$

$$
u^{p}=g_{0}^{a}g_{1}^{b}=g^{a\gamma+b}\Rightarrow u=g^{\frac{a\gamma+b}{p}}
$$

$$
g^{1/p}=g^{\frac{\alpha p+\beta(a\gamma+b)=1}{p}}=g^{\alpha+\beta\frac{a\gamma+b}{p}}=g^{\alpha}\cdot u^{\beta}.
$$

$$
(g^{\alpha}\cdot u^{\beta},p)
$$

Reduction 2. In reduction 2 the adversary *B* breaks strong RSA assumption only in case where
the adversary *A* outputs a tuple (*u;p;a;b*) such that *p*-*a* and fails otherwise.

*B*(G*;g*) samples <sup>$</sup> [1*;*2 ordmax], where ordmaxis the upper bound of the order of G outputted
Q
n n
by Ggen(1 ) (see section2.1), denes *S* := *fp*<sub>i</sub>PrimeGen(*i*)*g* a<sub>n</sub>d prod *p*<sub>i</sub>a<sub>n</sub>d sets
i=1 i=1
prod
*g₀ g;g₁ g*. *B* sends (G*;g₀;g₁*) to *A*. is sampled from a large enough domain so that *g*
is statistically close to a uniformly distributed *g₁* from G hence *g₀;g₁* are indistinguishable to two
uniformly random elements of G. *A*(G*;g₀;g₁;S*) responds with a tuple (*u;p;a;b*) and sends it to
*B*. We condition our analysis on the event *p*-*a*, meaning that *B* stops in case *p j a*.

$$
(u,p,a,b)
$$

$$
\mathcal{B}(\mathbb{G},g)
$$

$$
\gamma\gets\ [1,2^{\lambda}\mathsf{o r d}_{m a x}]
$$

$$
\mathsf{G g e n}(1^{\lambda})
$$

$$
\ S==\{{p_{i}\leftarrow\mathsf{P r i m e G e n}(i)}\}_{i=1}^{n}
$$

$$
g_{0}\leftarrow g,g_{1}\leftarrow g^{\gamma\cdot\mathsf{p r o d}}
$$

$$
\textstyle\leftarrow\prod_{i=1}^{n}p_{i}
$$

$$
A.\gamma
$$

$$
(\mathbb{G},\mathfrak{g}_{0},\mathfrak{g}_{1})
$$

$$
g^{\gamma}
$$

$$
g_{1}
$$

$$
\mathbb{G}
$$

$$
g_{0},g_{1}
$$

$$
(u,p,a,b)
$$

$$
\mathbb{G}.\ \mathcal{A}(\mathbb{G},g_{0},g_{1},S)
$$

$$
p\mid a.
$$

$$
p\nmid a
$$

p a b
Assume that *u* = *g₀ g₁ ^ p*-*a ^ u 2* G *^* (*a;b*) *2* Z² *^ p 2 S* then we will show that *B* can break
the strong RSA assumption. We argue that gcd(*p;a* + *b*prod) = 1. Let gcd(*p;a* + *b*prod) 6= 1,
meaning that gcd(*p;a*+ *b*prod) = *p*, then *p j a*+ *b*prod*) a*+ *b*prod = 0 (mod *p*). However, prod
includes *p* (*p 2 S*) we know that *p j b*prod*) b*prod = 0 (mod *p*). From the two previous facts we
infer that *a* = 0 (mod *p*)*) p j a* which is a contradiction. *B* uses the extended Euclidean algorithm
p a b a+bprod
to compute (*;*) such that *p* + (*a* + *b*prod) = 1. We know th<sup>a</sup>t *u* = *g₀g₁* = *g) u* =
<sup>a</sup><sup>+</sup><sup>b</sup><sup>prod</sup> p+ (a+bprod)=1 a+b<sup>prod</sup>
=p <sup>+</sup>
*g*<sup>p</sup>hence it follows that *g¹* = *g*<sup>p</sup>= *g*<sup>p</sup>= *g u*. Finally, *B* outputs
(*g u;p*) which is a valid strong-RSA solution.

$$
u^{p}=g_{0}^{a}\cdot g_{1}^{b}\wedge p\nmid a\wedge u\in\mathbb{G}\wedge(a,b)\in\mathbb{Z}^{2}\wedge p\in S
$$

$$
(p,a+b\gamma\mathsf{p r o d})=1
$$

$$
\mathtt{I}(p,a+b\gamma\mathsf{p r o d})\neq1
$$

$$
(p,a+b\gamma\mathsf{p r o d})=p
$$

$$
p\mid a+b\gamma\mathsf{p r o d}\Rightarrow a+b\gamma
$$

$$
p\left(p\in S\right)
$$

$$
p\,big vert\,b\gamma\mathsf{p r o d}\Rightarrow b\gamma\mathsf{p r o d}=0
$$

$$
a=0
$$

$$
p)\Rightarrow p\,
$$

$$
\alpha p+\beta(a+b\gamma\mathsf{p r o d})=1
$$

$$
u^{p}=g_{0}^{a}g_{1}^{b}=g^{a+b\gamma{\tt r o o}{\tt d}}\Rightarrow u=
$$

$$
(\alpha,\beta)
$$

$$
g^{\ ;\ ;}
$$

$$
g^{1/p}=g^{\frac{\alpha p+\beta(a+b\gamma\mathsf{p r o d})=1}{p}}=g^{\alpha+\beta\ \frac{a+b\gamma\mathsf{p r o d}}{p}}=g^{\alpha}\cdot u^{\beta}
$$

$$
\left(\boldsymbol{g}^{\alpha}\cdot\boldsymbol{u}^{\beta},\boldsymbol{p}\right)
$$

To conclude the proof, notice that:

$$
\begin{aligned}{\operatorname*{P r}[G_{\mathcal{A}}=1]}&{{}=\operatorname*{P r}[G_{\mathcal{A}}=1|p\mid a]\operatorname*{P r}[p\mid a]+\operatorname*{P r}[G_{\mathcal{A}}=1|p\nmid a]\operatorname*{P r}[p\nmid a]}\\ {}&{{}\leq\operatorname*{P r}[G_{\mathcal{A}}=1|p\mid a]+\operatorname*{P r}[G_{\mathcal{A}}=1|p\nmid a]}\\ \end{aligned}
$$

The reductions 1 and 2 described above show that under the strong RSA assumption Pr[*G*<sub>A</sub>=
1*jp j a*] and Pr[*G*<sub>A</sub>= 1*jp*-*a*] respectively are negligible. Hence, we have that Pr[*G*<sub>A</sub>= 1] *2* negl(),
which concludes the proof.

$$
\mathrm{P r}[G_{\mathcal{A}}=
$$

$$
1|p\mid a]
$$

$$
\mathrm{P r}[G_{\mathcal{A}}=1|p\nmid a]
$$

$$
\operatorname*{P r}[G_{\mathcal{A}}=1]\in{\mathsf{n e g l}}(\lambda)
$$

On concrete instantiation. Our SVC construction is described generically from a hidden order
group G, an AoK PoProd₂, and a mapping to primes PrimeGen. The concrete scheme we analyze
is the one where PoProd₂ is instantiated with the non-interactive version of the PoProd₂ protocol
described in Sec.5.1. The non-interactive version needs a hash-to-prime function H<sub>prime</sub>. We note
that the same function can be used to instantiate PrimeGen, though for the sake of PrimeGen we
do not need its randomness properties. One can choose a dierent mapping to primes for PrimeGen
and even just a bijective mapping (which is inherently collision resistant) would be enough: this
is actually the instantiation we consider in our eciency analysis. Finally, see Section2.1for a
discussion on possible instantiations of G.

$$
\mathsf{P o P r o d}_{2}
$$

$$
\mathsf{P o P r o d}_{2}
$$

$$
\mathsf{H}_{\mathsf{p r i m e}}
$$

We note that by using the specic PoProd₂ protocol given in Sec.5.1we are assuming adversaries
that are generic with respect to the group G. Therefore, our SVC is ultimately position binding in
the generic group model.

## 5.2 Our Second SVC Construction

In this section we propose another SVC scheme with constant-size parameters and incremental
aggregation. This scheme builds on the SVC of [LM19] based on the RSA assumption, which in turn extends the VC of [CF13] to support subvector openings. Our technical contribution is twofold.
First, we show that the SVC of [CF13,LM19] can be modied in order to have public parameters
and verication time independent of the vector’s length. Second, we propose new algorithms for
(incremental) aggregation and disaggregation for this SVC.

Our second SVC Construction. Let us start by giving a brief overview of the [CF13] VC scheme
and of the basic idea to turn it into one with succinct parameters and verication time. In brief, inQ
v1 vn j2[n]nfigej
[CF13] a commitment to a vector *~v* is *C* = *S₁ S*<sub>n</sub>, where each *S*<sub>i</sub>:= *g* with *g 2* G a
random generator and *e*<sup>j</sup>being distinct prime numbers (which can be deterministically generated
eii i
using a suitable map-to-primes). The opening for position *i* is an element<sub>i</sub>such that *S* = *C*
<sub>i</sub>v
and the key idea is that such<sub>i</sub>is an *e*<sub>i</sub>-th root that can be publicly computed as long as one
does it for the correct position *i* and value *v*<sub>i</sub>. Also, as it can be seen, the element *S*<sub>i</sub>is necessary
to verify an opening of position *i*, and thus (*S₁;:::;S*<sub>n</sub>) were included in the public parameters.
Catalano and Fiore observed that it might be possible to remove the *S*<sub>i</sub>-s from crs if the verier
opts for recomputing *S*<sub>i</sub>at verication time *at the price of linear-time verication*.

$$
\vec{v}
$$

$$
C=S_{1}^{v_{1}}\cdots S_{n}^{v_{n}}
$$

$$
S_{i}:=g^{\prod_{j\in[n]\setminus\{i\}}e e_{j}}
$$

$$
g\in\mathbb{G}
$$

$$
e_{j}
$$

$$
\Lambda_ {i}
$$

$$
\Lambda_ {i}
$$

$$
\varLambda_{i}^{e_{i}}\cdot S_{i}^{v_{i}}=C
$$

$$
e_{i^{-}\mathrm{t h}}
$$

$$
v_{i}
$$

$$
S_{i}
$$

$$
i,
$$

$$
(S_{1},\ldots,S_{n})
$$

$$
S_{i\ \mathrm{S}}
$$

$$
S_{i}
$$

Our goal is to obtain constant-size parameters *and* constant-time verication. To do that we
let the prover compute *S*<sup>i</sup>and include it in the opening for position<sub>Q</sub>*i*. To prevent adversaries from
i2[n]ei
providing false *S*<sub>i</sub>’s, we store in the public parameters *U*<sub>n</sub>= *g* (i.<sub>e</sub>., an accumulator to all
i
positions) so that the verier can verify the correctness of *S*<sub>i</sub>in constant-time by checking *S* = *U*<sub>n</sub>.
<sub>ie</sub>
Th<sup>i</sup>s technique easily generalizes to subvector openings.

$$
S_{i}
$$

$$
S _ {i} ^ {\prime} \mathrm {s}
$$

$$
\ _{U_{n}=g}{\prod_{i\in[n]}e_{i}}
$$

$$
S_{i}^{e_{i}}=U_{n}
$$

$$
S_{i}
$$

In the following, we describe the scheme in details and then propose our incremental aggregation
algorithms. To simplify our exposition, we use the following notation: for a set of indices I [n],
Q
e*I*:= eidenotes the product of all primes corresponding to the elements of *I*, and *S*<sup>I</sup>:=
Q i2I
ei e 1=eI
*g*<sub>i2</sub><sub>[</sub>*n*<sub>]</sub><sub>nI</sub>= *g*<sub>[</sub><sub>n</sub><sub>]</sub><sub>nI</sub>= *U* (which is a g*e*n*e*ral<sub>i</sub>zation of the former *S*), where, we recall, the *e* ’s
n <sub>i</sub> i
are dened from the crs.

$$
I\subseteq[n]
$$

$$
\textstyle{e_{I}:=\prod_{i\in I}e_{i}}
$$

$$
S_{I}\ =
$$

$$
S_{i})
$$

$$
{e e{}}_i{\ }^{?}
$$

VC*:* Setup(1*;‘;n*)*!* crs generates a hidden order group G Ggen(1 ) and samples a generator
*g* $ G. It also determines a deterministic collision resistant function PrimeGen that maps integers
to primes.

$$
{\mathsf{S e t u p}}(1^{\lambda},\ell,n)\to{\mathsf{c r s}}
$$

$$
g\leftarrow\mathfrak{s}\mathbb{G}
$$

$$
\mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda})
$$

Returns crs = (G*;g;* PrimeGen)

$$
{\mathsf{c r s}}=(\mathbb{G},g,{\mathsf{P r i m e G e n}})
$$

VC*:* Specialize(crs*;n*)*!* crs<sub>n</sub>computes *n* (*‘* + 1)-bit primes *e₁;:::;e*<sub>n</sub>, *e*<sub>i</sub>PrimeGen(*i*) for each
e[n]
*i 2* [*n*], and *U*<sub>n</sub>= *g* and r<sup>e</sup>tur<sup>n</sup>s crs<sub>n</sub>(crs*;U*<sub>n</sub>). One can think of *U*<sub>n</sub>as an accumulator to
the set [*n*].

$$
n\ (\ell+1){\mathrm{-b i t}}
$$

$$
e_{1},\ldots,e_{n},\:e_{i}\leftarrow
$$

$$
i\in[n]
$$

$$
U_{n}=\mathfrak{g}^{\mathfrak{e}[n]}
$$

$$
\mathsf{c r s}_{n}\leftarrow(\mathsf{c r s},U_{n})
$$

$$
U_{n}
$$

$$
[n]
$$

e[n]nfigv1 vn
VC*:* Com(crs*;~v*)*!* (*C;* aux)Computes for each *i 2* <sup>[</sup>*n*<sup>]</sup>, *S*<sub>i</sub>*g* and th<sup>e</sup>n *C S₁ :::S*<sub>n</sub>a<sup>n</sup>d
aux (*v₁;:::;v*<sub>n</sub>).

$$
\mathsf{C o m}(\mathsf{c r s},{\vec{v}})\to\big({\mathcal{C}},\mathsf{a u x}\big)
$$

$$
i\in[n],\,S_{i}\leftarrow g^{e_{[n]\setminus\{i\}}}
$$

$$
C\leftarrow S_{1}^{v_{1}}\ldots S_{n}^{v_{n}}
$$

$$
\leftarrow(v_{1},\ldots,v_{n})
$$

1=eI e e
VC*:* Open(crs*;I;~y;* aux)*!* Computes for each *j 2* [*n*] *n I*, *S g*<sup>[</sup><sup>n</sup><sup>]</sup><sup>n</sup><sup>(</sup><sup>I</sup>[fjg<sup>)</sup>and *S g*<sup>[</sup><sup>n</sup><sup>]</sup><sup>nI</sup>
I j I
and then
0 1<sub>1</sub><sub>=e</sub>
<sub>I</sub>

$$
\ \ cdot mathsf O P p\ \!(\mathsf{c r s},I,\vec{y},\mathsf{a l x}\ \\ )\to\pi_{I}
$$

$$
j\in[n]\setminus I,\,S_{j}^{1/e_{I}}\leftarrow g^{e_{[n]\setminus((I\cup\{j\})}}
$$

$$
S_{I}\leftarrow g^{e_{[n]\setminus I}}
$$

$$
\varLambda_{I}\leftarrow\prod_{j=1,j\notin I}^{n}\left(S_{j}^{1/e_{I}}\right)^{y_{j}}=\left(\prod_{j=1,j\notin I}^{n}S_{j}^{y_{j}}\right)^{1/\epsilon}
$$

$$
\pi_{I}:=(S_{I},\varLambda_{I})
$$

Returns<sub>I</sub>:= (*S*<sub>I</sub>*;*<sub>I</sub>)

eInfig 1=ei
VC*:* Ver(crs*;C;I;~y;*<sup>I</sup>)*! b* Parse<sup>I</sup>:= (*S*<sup>I</sup>*;*<sup>I</sup>), and comput<sup>e</sup> *S*<sup>i</sup>= S = *U*<sub>n</sub>for every *i 2 I*.
I
Return 1 (accept) if both the following checks hold, and 0 (reject) otherwise:
Y

$$
\ {sf V V C r}({\sf c r s},{\mathcal{C}},I,\vec{y},\pi_{I})\to b
$$

$$
S_{i}=S_{I}^{e_{I\setminus\{i\}}}=U_{n}^{1/e_{i}}
$$

$$
\pi_{I}:=(S_{I},\varLambda_{I})
$$

$$
i\in I
$$

$$
S_{I}^{e_{I}}=U_{n}\;\wedge\;C=\varLambda_{I}^{e_{I}}\prod_{i\in I}S_{i}^{y_{i}}
$$

---

The correctness of the above construction holds essentially the same as the one of the SVC of
[CF13,LM19] with the addition of the *S*<sub>I</sub>elements of the openings, whose correctness can be
seen by inspection (and is the same as for RSA accumulators).

$$
S_{I}
$$

Incremental Aggregation. Let us now show that the SVC above has incremental aggregation.
Note that our algorithms also implicitly show that the RSA-based SVC of [LM19] is incrementally
aggregatable.

eInK
VC*:* Disagg(crs*;I;~v*<sup>I</sup>*;*<sup>I</sup>;K)!<sup>K</sup>Parse<sup>I</sup>:= (*S*<sup>I</sup>*;*<sup>I</sup>). First compute S<sub>K</sub>from *S*<sub>I</sub>, *S*<sub>K</sub>S,
<sub>I</sub>
1=<sup>e</sup>jeIn(K[fjg)
and then, for every *j 2 I n K*,<sub>j</sub>= S, e.g., by computing<sub>j</sub>*S*.
K <sub>I</sub>
R<sub>e</sub>turnK:= <sub>(</sub>*S*K*;K*<sub>)</sub> where
Y
e v

$$
\mathfrak{g}(\mathsf{c r s},I,\vec{v}_{I},\pi_{I},K)\to\pi_{K}
$$

$$
\pi_{I}:=\left(S_{I},\varLambda_{I}\right)
$$

$$
S_{K}
$$

$$
S_{I},\,S_{K}\gets S_{I}^{e_{I\setminus K}}
$$

$$
j\in I\setminus K,\,\chi_{j}=S_{K}^{1/e_{j}},\,{mathrm{e.g}}
$$

$$
\chi_{j}\leftarrow S_{I}^{e_{I\setminus(K\cup\{j\})}}
$$

$$
\pi_{K}:=\big(S_{K},\varLambda_{K}\big)
$$

$$
\varLambda_{K}\leftarrow\varLambda_{I}^{e_{I\setminus K}}\cdot\prod_{j\in I\setminus K}\chi_{j}^{v_{j}}
$$

VC*:* Agg(crs*;* (*I;~v*<sub>I</sub>*;*<sub>I</sub>)*;* (*J;~v*<sub>J</sub>*;*<sub>J</sub>))*!*<sub>K</sub>Parse<sub>I</sub>:= (*S*<sub>I</sub>*;*<sub>I</sub>) and similarly<sub>J</sub>. Also, let *K* = *I [ J*,
and assume for simplicity that *I \ J* =*;* (if this is not the case, one could simply disaggregate<sub>I</sub>
(or<sub>J</sub>) to<sub>InJ</sub>(or<sub>J nI</sub>)).

$$
\check{\cdot}.\mathsf{A g g}(\mathsf{c r s},(I,\vec{v}_{I},\pi_{I}),(J,\vec{v}_{J},\pi_{J}))\to\pi_{K}
$$

$$
\pi_{I}:=(S_{I},\varLambda_{I})
$$

$$
\pi J
$$

$$
K=I\cup J.
$$

$$
I\cap J=\emptyset
$$

$$
\pi\ \!I{}
$$

$$
\pi_{J})
$$

$$
\pi_{I\setminus J}\ \ \bigl(\mathrm{o r}\ \pi_{J\setminus I}\bigr)_{\!}^{\!}
$$

eJ nfjg 1=ej
First, compute *S*<sup>K</sup>ShamirTrick(*S*<sub>I</sub>*;S*<sup>J</sup>;e<sup>I</sup>;e<sup>J</sup>). Next, comput<sup>e</sup><sup>j</sup>*S* = *S* for every
K I
eInfig 1=ei
*j 2 J*, and similarly<sub>i</sub>*S* = *S* for every *i 2 I*. Then compute
K J

$$
S_{K}\leftarrow\mathbf{S h a m i r T r i c k}(S_{I},S_{J},e_{I},e_{J})
$$

$$
\phi_{j}\gets S_{K}^{e_{J\setminus\{j\}}}=S_{I}^{1/e_{j}}
$$

$$
j\in J
$$

$$
\psi_{i}\gets S_{K}^{e_{I\setminus\{i\}}}=S_{J}^{1/e_{i}}
$$

$$
i\in I
$$

$$
\rho_{I}\leftarrow\frac{\varLambda_{I}}{\prod_{j\in J}\phi_{j}^{v_{j}}}\qquad\mathrm{}{~a n d~}\qquad\sigma_{J}\leftarrow\frac{\varLambda_{J}}{\prod_{i\in I}\psi_{i}^{v_{i}}}
$$

Return<sub>K</sub>:= (*S*<sub>K</sub>*;*<sub>K</sub>) where<sub>K</sub>ShamirTrick(<sub>I</sub>*;*<sub>J</sub>*;e*<sub>I</sub>*;e*<sub>J</sub>).

$$
\pi_{K}:=\big(S_{K},\varLambda_{K}\big)
$$

$$
\varLambda_{K}\leftarrow\mathbf{S h a m i r T r i c k}(\rho_{I},\sigma_{J},e_{I},e_{J})
$$

Aggregation Correctness. It follows from the correctness of Shamir’s trick and by construction.
In Aggregation and disaggregation *S*<sub>K</sub>’s correctness is straightforward, so we emphasize on<sub>K</sub>.
For the disaggregation algorithm:

$$
S_{K}^{^{\ }}
$$

$$
\Lambda_{K}
$$

$$
\begin{aligned}{\varLambda_{K}:=\varLambda_{I}^{e_{I\setminus K}}\cdot\prod_{j\in I\setminus K}\chi_{j}^{v_{j}}}&{{}=\left(\prod_{j=1,j\notin K}^{n}S_{j}^{v_{j}}\right)^{\frac{1}{e_{I}}e_{I\setminus K}}\cdot\prod_{j\in I\setminus K}\left(S_{j}^{1/e_{K}}\right)^{v_{j}}}\\ {}&{{}=\left(\prod_{j=1,j\notin K}^{n}S_{j}^{v_{j}}\right)^{\frac{1}{e_{K}}}\cdot\left(\prod_{j\in I\setminus K}S_{j}^{v_{j}}\right)^{1/e_{K}}}\\ {}&{{}=\left(\prod_{j=1,j\notin K}^{n}S_{j}^{v_{j}}\right)^{1/e_{K}}}\\ \end{aligned}
$$

which is a valid opening for the *K*-subvector. And for the aggregation algorithm:

$$
\rho_{I}:=\frac{A_{I}}{\prod_{j\in J}\phi_{j}^{v_{j}}}=\left(\prod_{j=1,j\notin I\cup J}^{n}S_{j}^{v_{j}}\right)^{1/e_{I}}\ operatorname{n n d}\ \sigma_{J}:=\frac{A_{J}}{\prod_{j\in I}\psi_{j}^{v_{j}}}=\left(\prod_{j=1,j\notin J\cup I}^{n}S_{j}^{v_{j}}\right)^{1/e_{J}}
$$

---

$$
\begin{aligned}{\varLambda_{K}}&{{}:=\mathbf{S h a m i r T i c c k}(\rho_{I},\sigma_{J},e_{I},e_{J})}\\ {}&{{}=\mathbf{S h a m i r r i c c}\left(\left(\prod_{j=1,j\notin I\cup J}^{n}S_{j}^{v_{j}}\right)^{1/e_{I}},\left(\prod_{j=1,j\notin I\cup I}^{n}S_{j}^{v_{j}}\right)^{1/e_{J}},e_{I},e_{J}\right)}\\ {}&{{}=\left(\prod_{j=1,j\notin I\cup J}^{n}S_{j}^{v_{j}}\right)^{\overrightarrow{e_{I}I_{J}}}=\left(\prod_{j=1,j\notin I\cup J}^{n}S_{j}^{v_{j}}\right)^{\overrightarrow{e_{I}I_{J\cup J}}}}\\ \end{aligned}
$$

which is a valid opening for the (*I[J*)-subvector.

Eciency. We summarize the eciency of this construction in terms of both the computational
cost of each algorithm and the communication. For the analysis we consider an instantiation of
PrimeGen with a deterministic function that maps every integers in [*n*] into an *‘*-bit prime number.
Also, we observe that the algorithms described above may have dierent implementations: while
straightforward instantiations may lead to a complexity quadratic in the (sub)vector’s length, in
what follows we discuss more ecient ways that keeps the complexity quasilinear. For this, we
often rely on the MultiExp algorithm described in [BBF19]. On input an integer *n*, and two
n n
vectors *~ 2* G a<sup>n</sup>d *~x 2* Z, MultiExp(*n;~;~x*) is a divide-and-conquer algorithm that computes
Q<sub>x</sub> <sub>=x</sub>Q
n <sub>i</sub> <sub>n</sub> 2
where *x* = *x*<sub>i</sub>, a<sub>n</sub>d it does it in time *O*(*n*log*n*), instead of a naive *O*(*n*).
i=1 i i=1

$$
\vec{\alpha}\in\mathbb{G}^{n}
$$

$$
\vec{x}\in\mathbb{Z}^{n}
$$

$$
O(n^{2})
$$

$$
\textstyle\prod_{i=1}^{n}\alpha_{i}^{x^{*}/x_{i}}
$$

$$
\textstyle{x^{*}=\prod_{i=1}^{n}x_{i}}
$$

Setup. VC*:* Setup generates a group description and samples one random group element, while
VC*:* Specialize computes one exponentiation with an (*‘ n*)-bits integer. Both the universal and the
specialized CRS consist each of 1 element of G.

‘ n
Committing. Committing to a vector *~v 2* (*f*0*;* 1*g*) ca<sup>n</sup> be done in time *O*(*‘ n*log*n*) by using
vi
the MultiExp algorithm from [BBF19], i.e., *C* MultiExp(*n;~;~e*) where<sub>i</sub>= *g* and *e*<sup>i</sup>=
PrimeGen(*i*). The commitment is a single element of G.

$$
\vec{v}\,\in\,(\{0,1\}^{\ell})^{n}
$$

$$
\ {\bf[B B F19],\ i i.e.,\ C\;\leftarrow\;M u l t i E x p}(n,\vec{\alpha},\vec{e})
$$

$$
\alpha_{i}=g^{v_{i}}
$$

$$
e_{i}\,=
$$

Opening. An opening for a set *I* of *m* positions consists of two group elements, and it can be come[n]nI
puted as follows. First, compute *S*<sub>I</sub>through the exponentiatio<sup>n</sup> *g* which r<sup>e</sup>quires *O*(*‘*(*n m*))
group operations, and then compute<sub>I</sub>in a way similar to committing, i.e.,<sub>I</sub>MultiExp(*n⁰;~;~x*),
vj
where *n⁰* = *n m*, *~* = (*g*)<sup>j</sup>2<sub>[</sub><sub>n</sub><sub>]</sub><sub>nI</sub>, *~x* = (*e*<sub>j</sub>)<sub>j2</sub><sub>[</sub><sub>n</sub><sub>]</sub><sub>nI</sub>, which takes time *O*(*‘*(*n m*) log(*n m*)).

$$
S_{I}
$$

$$
g^{e_{[n]}\setminus I}
$$

$$
O(\ell(n-m))
$$

$$
\varLambda_{I}
$$

$$
\Lambda_ {I} \leftarrow \operatorname {M u l t i E x p} \left(n ^ {\prime}, \vec {\alpha}, \vec {x}\right)
$$

$$
n^{\prime}=n-m,\:\vec{\alpha}=(g^{v_{j}})_{j\in[n]\setminus I},\:\vec{x}=(e_{j})_{j\in[n]\setminus I}
$$

$$
O(\ell(n-m)\log(n-m))
$$

Verification. Verifying an opening for *I* of size *m* requires two exponentiations with an (*‘m*)-bits
Qy
eIeI i
long integ<sub>e</sub>r (*S* and), and the computat<sub>i</sub>on of *S* can be done in time *O*(*‘m*log*m*) by
I I i2I i
y1ym
running MultiExp(*m;~;~x*) with *~* = (*S;:::;S*) and *~x* = (*e*<sub>i</sub>)<sub>i2I</sub>.
I I

$$
(S_{I}^{e_{I}}
$$

$$
\Lambda_{I}^{e_{I}})
$$

$$
\textstyle\prod_{i\in I}S_{i}^{y_{i}}
$$

$$
\vec {\alpha} = \left(S _ {I} ^ {y _ {1}}, \dots , S _ {I} ^ {y _ {m}}\right)
$$

$$
\vec {x} = \left(e _ {i}\right) _ {i \in I}
$$

Aggregation and Disaggregation. Disaggregation can be computed in time *O*(*‘*(*jIjjKj*) log(*jIj*
*jKj*)) in a way similar to verication: two exponentiations with an *‘*(*jIjjKj*)-bits long integer
vj
each, and an invocation of MultiExp((*jIjjKj*)*;~;~x*), with *~* = (*S*)<sub>j</sub>2InKand *~x* = (*e*<sub>j</sub>)<sub>j2InK</sub>, to
I
QeIn(K[fjg)vj
compute *S*.
<sub>j2InK</sub> I

$$
O(\ell(|I|-|K|)\log(|I|-
$$

$$
\ell(|I|-|K|)
$$

$$
\ K|))
$$

$$
\mathrm{W u l t i E x p}(\left\||\|-\left|K\right|\right),{\vec{\alpha}},{\vec{x}})
$$

$$
\vec{\alpha}=(S_{I}^{v_{j}})_{j\in I\backslash K}
$$

$$
\textstyle\prod_{j\in I\setminus K}S_{I}^{e_{I\setminus(K\cup\{j\})}\cdot v_{j}}
$$

$$
\vec{x}=(e_{j})_{j\in I\setminus K}
$$

Aggregation can be computed in time *O*(*‘m*log*m*) where *m* = max(*jIj; jJ j*) as follows. Two
invocations of ShamirTrick, each requiring two exponentiations with (*‘m*)-bits long integers,
Q<sub>v</sub>Q
j i
to compute *S*<sub>K</sub>and<sub>K</sub>, and two invocations of MultiExp to compute and
<sub>j2J</sub> <sub>j</sub> i2I iv
respectively. From this, we obtain that VC: AggManyToOne and VC*:* D<sub>i</sub>saggOneToMany take time
*O*(*‘m*log² *m*) G and *O*(*‘m*log*m*log(*m=B*)) G, respectively.

$$
m=\operatorname*{m a x}(|I|,|J|)
$$

$$
O(\ell m\log m)
$$

$$
S_{K}
$$

$$
\Lambda_{K}
$$

$$
\textstyle\prod_{j\in J}\phi_{j}^{v_{j}}
$$

$$
\textstyle\prod_{i\in I}\psi_{i}^{v_{i}}
$$

$$
O(\ell m\log^{2}m)\ \mathbb{G}
$$

$$
O(\ell m\log m\log(m{}/{B}))\,\mathbb{G}
$$

Commitment and Opening with Precomputation. Finally, let us summarize the costs of
committing and opening with preprocessing obtained by instantiating our method of Section4.2.

---

The preprocessing VC*:* PPCom, with parameter *B*, requires *O*(*‘n*log*n*log(*n=B*)) operations of G
and produces a storage advice of 2*n=B* group elements. The opening requires computing at most
*jSj m* disaggregation, each taking time *O*(*‘*(*jP*<sub>j</sub>*jjIj*j) log((*jP*<sub>j</sub>*jjIj*j))), for a total of *O*(*‘*(*jSjB*
*jIj*) log(*jSj*)), followed by the aggregation step that counts *O*(*‘jSj*log² *jSj*). So, in the worst case
VC*:* FastOpen takes *O*(*‘ m* (log²(*m*) + *B* 1)) operations of G.

$$
n\log(n/B))
$$

$$
2n/B
$$

$$
|S|\leq m
$$

$$
O(\ell(\ P_{j}|\ ||\,,|I_{j}|\,)\log(\left|_{{j}}|\,|\,|I_{j}|\,\right\rangle))
$$

$$
|I|)\operatorname{l o g}(|S|))
$$

$$
O(\ell(|S|B-
$$

$$
O(\ell|S|\log^{2}|S|)
$$

$$
O(\ell\cdot m\cdot(\log^{2}(m)+B-1).
$$

Security. For the security of the above SVC scheme we observe that the dierence with the
corresponding [LM19] lies in the generation of *S*<sub>i</sub>’s. In [LM19] they are generated in the trusted
setup phase, thus they are considered \well-formed" in the security proof. In our case, the *S*<sub>i</sub>’s are
reconstructed during verication time from the *S*<sup>I</sup>that comes in the opening<sup>I</sup>which can (possibly)
eI
be generated in an adversarial way. However, in the verication it is checked that *S* = *U*, wh<sub>e</sub>re
<sub>I</sub>
e[<sub>n</sub><sub>]</sub>
*U* = *g* is computed in the trusted setup. So under the Low Order assumption we get that *S*<sub>I</sub>has
e[n]=eIe[n]nI
the correct form, *S*<sub>I</sub>= *g* = *g*, with overwhelming probability. Except for this change, the
rest reduces to the position binding of the [LM19] SVC.

$$
S_{i}^{\ }\,
$$

$$
{5{_{i}}^{\prime}\mathrm{{S}}}
$$

$$
\pi\ \!I
$$

$$
S_{I}
$$

$$
S_{I}^{e_{I}}=U
$$

$$
U=g^{e_{[n]}}
$$

$$
S_{I}
$$

$$
S_{I}=g^{e_{[n]}/e_{I}}=g^{e_{[n]\setminus I}}
$$

Theorem 5.3(Position-Binding). *Let* Ggen *be the generator of hidden order groups where the*
*Low Order assumption holds and the [LM19] SVC is position binding. Then the SVC scheme dened*
*above is position binding.*

Proof We start by dening the game *G₀* as the actual position binding game of Denition3.2,
and our goal is to prove that for any PPT *A*, Pr[*G₀* = 1] *2* negl():

$$
G_{0}
$$

$$
\mathcal{A},\operatorname*{P r}[G_{0}=1]\in\mathsf{n e g l}(\lambda)
$$

Game *G₀*:
G₀ = PosBind

$$
G_{0};
$$

$$
G_{0}=\sf{P o s B i n d_{V C}^{A}}(\lambda)
$$

$$
\mathsf{c r s}\leftarrow\mathsf{V C}.\mathsf{S e t u p}(1^{\lambda},\mathcal{M})
$$

$$
(\mathcal{C},I,\vec{y},\pi,\vec{y}^{\prime},\pi^{\prime})\leftarrow\mathcal{A}(\mathsf{c r s})
$$

$$
b\leftarrow\mathsf{V C.V e r}(\mathsf{c r s},C,I,\vec{y},\pi)=\mathbf{1}\wedge\vec{y}\not\ \neq\vec{y}^{\prime}\wedge\mathsf{V C.V e r}(\mathsf{c r s},C,I,\vec{y}^{\prime},\pi^{\prime})=\mathbf{1}
$$

0 0I
More specically crs := (G*;g;* PrimeGen), := (*S*<sub>I</sub>*;*<sub>I</sub>), := (*S;*) and
<sub>I0</sub>
Y

$$
\mathrm {c r s} := (\mathbb {G}, g, \mathrm {P r i m e G e n}), \pi := \left(S _ {I}, A _ {I}\right), \pi^ {\prime}: = \left(S _ {I} ^ {\prime}, A _ {I} ^ {\prime}\right)
$$

$$
b=S_{I}^{e_{I}}=U_{n}\wedge C=\varLambda_{I}^{e_{I}}\prod_{i\in I}S_{i}^{y_{i}}\wedge\vec{y}=\vec{y}^{\prime}\wedge S_{I}^{\prime e_{I}}=U_{n}\wedge C=\varLambda_{I}^{\prime e_{I}}\prod_{i\in I}S_{i}^{y_{i}^{\prime\prime}}
$$

eInfig0eInfig
where *S*<sup>i</sup>= *S* and *S* = *S* for each *i 2 I*.
I i0 I

$$
\ \ S{}_{i}=S_{I}^{e_{I\setminus\{i\}}}
$$

$$
S_{i}^{\prime}=S_{I}^{\prime e_{I\setminus\{i\}}}
$$

$$
i\in I
$$

Now let *G₁* be the same as above except for the outputted by the adversary *S*<sup>I</sup>and *S* it holds
I0
e[n]nIeI0eI
that *S*<sub>I</sub>= *g* = *S*. Th<sub>e</sub> *S* = *U*<sub>n</sub>= *S* checks are not done in the verication (as they are
I0 I I
redundant):

$$
G_{1}
$$

$$
S_{I}
$$

$$
S_{I}^{\prime}
$$

$$
S_{I}=g^{e_{[n]\setminus I}}=S_{I}^{\prime}
$$

$$
S_{I}^{e_{I}}=U_{n}=S_{I}^{\prime e_{I}}
$$

$$
G_{1},
$$

Game *G₁*:
G₁

$$
\begin{array}{l} G _ {1} \\ \mathrm {c r s} \leftarrow \mathrm {V C}. \mathrm {S e t u p} \left(1 ^ {\lambda}, \mathcal {M}\right) \\ \left(C, I, \vec {y}, \left(S _ {I}, \Lambda_ {I}\right), \vec {y} ^ {\prime}, \left(S _ {I} ^ {\prime}, \Lambda_ {I} ^ {\prime}\right)\right) \leftarrow \mathcal {A} (\mathrm {c r s}) \\ \mathrm {i f} S _ {I} \neq g ^ {e [ n ] \backslash I} \text {o r} S _ {I} ^ {\prime} \neq g ^ {e [ n ] \backslash I} \mathrm {t h e n a b o r t} \\ b \leftarrow C = \Lambda_ {I} ^ {e _ {I}} \prod_ {i \in I} \left(S _ {I} ^ {e _ {I} \setminus \{i\}}\right) ^ {y _ {i}} \wedge \vec {y} = \vec {y} ^ {\prime} \wedge C = \Lambda_ {I} ^ {\prime e _ {I}} \prod_ {i \in I} \left(S _ {I} ^ {\prime e _ {I} \setminus \{i\}}\right) ^ {y _ {i} ^ {\prime}} \\ \end{array}
$$

return *b*

eI eIeI
Then Pr[*G₀* = 1] Pr[*G₁* = 1] + negl(). <sup>I</sup>n *G₀*, *S* = *U*<sup>n</sup>= *g*. Assum<sup>e</sup> that *S*<sup>I</sup>6= *g* th<sup>e</sup>n
<sup>I</sup>
e eIeI 1 eIpoly()
g[n]nI= S, hence S = S) S S = 1. Since S is eciently computable and e < 2
<sub>I</sub> I I I I I I

$$
\operatorname*{P r}[G_{0}\,=\,1]\,\leq\,\operatorname*{P r}[G_{1}\,=\,1]\,+\,\mathsf n e g l(\lambda)
$$

$$
G_{0},\,S_{I}^{e_{I}}=U_{n}=g^{e_{I}}
$$

$$
\beta_{I}\neq g^{e_{I}}
$$

$$
g^{e_{[n]\setminus I}}=S_{I}^{*}
$$

$$
S_{I}^{e_{I}}=S_{I}^{*e_{I}}\Rightarrow\left(S_{I}^{-1}S_{I}^{*}\right)^{e_{I}}=1
$$

$$
S_{I}^{*}
$$

$$
e_{I}<2^{\mathsf{p o l y}(\lambda)}
$$ this constitutes a solution to the Low Order problem for the hidden order group. The previous
happens only with negligible probability under the Low Order assumption. The same holds for *S*.
<sub>I0</sub>
e[n]nfig
Notice that it follows that *S*<sub>i</sub>= *S* = *g*.
*i*0

$$
S_{i}=S_{i}^{\prime}=g^{e_{[n]}setminus\{{\\\ \ \}}}
$$

e[n]nfig
Let *G₂* be the same as above except the adversary receives *e*<sub>i</sub>PrimeGen(*i*) and *S*<sub>i</sub>= *g*
for <sup>e</sup>ach *i 2* <sup>[</sup>*n*<sup>]</sup>, together with the parameters:

$$
S_{I}^{\prime}
$$

$$
G_{2}
$$

$$
e_{i}\leftarrow{\mathsf r i m e G e n}(i)
$$

$$
S_{i}=g^{e_{[n]\setminus\{i\}}}
$$

$$
i\in[n]
$$

Game *G₂*:

$$
G_{2},
$$

*G₂*
(G;g; PrimeGen) VC*:* Setup(1*; M*)
Q
i2[n]nfig*ei*
ei PrimeGen(*i*);*Si* = *g* for each *i 2* [*n*]
0I
(*C;I;~y;I;~y⁰;*) *A* G*;g;* PrimeGen*; fS*i*g*i2[n]
Y Y
e 0 0IeI y0
*b C* =<sub>II</sub>*S*<sub>iyi</sub>*^ ~y* = *~y ^ C* = *S*<sub>i i</sub>
*i2I i2I*

$$
(\mathbb{G},\mathfrak{g},\mathsf{P r i m e G e n})\leftarrow\mathbb{V C}.\mathsf{S e t u p}(\ {{1}}^{\lambda},\mathcal{M})
$$

$$
e_{i}\leftarrow\mathsf{P r i m e G e n}(i);S_{i}=g^{\prod_{i\in\{n\}\setminus\{i\}}e{{}_{i}}}\mathrm{}{~f o r~e a c h~i~\in~[n]~}
$$

$$
(C,I,\vec{y},\varLambda_{I},\vec{y}^{\prime},\varLambda_{I}^{\prime})\leftarrow\mathcal{A}\left(\mathbb{G},g,\mathsf{P r i m e G e n},\{S_{i}\}_{i\in[n]}\right)
$$

$$
b\gets C=\varLambda_{I}^{e_{I}}\prod_{i\in I}S_{i}^{y_{i}}\wedge\vec{y}=\vec{y}^{\prime}\wedge C=\varLambda_{I}^{\prime e_{I}}\prod_{i\in I}S_{i}^{y_{i}^{\prime}}
$$

return *b*

It is straightforward that Pr[*G₁* = 1] = Pr[*G₂* = 1] and furthermore *G₂* is identical to the position
binding game of the [LM19] SVC scheme and according to the hypothesis Pr[*G₂* = 1] = negl().

$$
\operatorname*{P r}[G_{1}\!=\!1]=\operatorname*{P r}[G_{2}\!=\!1]
$$

$$
G_{2}
$$

$$
\operatorname*r P\![left[G_{2}=1]=\ \mathsf{n e g l!(\lambda)}.\,subset
$$

As showed in [LM19], their SVC is position binding under the strong Distinct-Prime-Product
Root assumption in the standard model. We conclude that the above SVC is position binding in
hidden order groups where the Low Order and the Strong Distinct-Prime-Product Root assumptions
hold.

## 5.3 Comparison with Related Work

We compare our two SVC schemes with the recent scheme proposed by Boneh et al. [BBF19] and
18
the one by Lai and Malavolta [LM19], which extends [CF13] to support subvector openings. We
present a detailed comparison in Table1, considering to work with vectors of length *N* of *‘*-bit
elements and security parameter. In particular we consider an instantiation of our rst SVC with
*k* = 1 (and thus *n* = *N ‘*).

$$
k=1
$$

$$
n=N\cdot\ell)
$$

Setup Model. [BBF19] works with a fully universal CRS, whereas our schemes have both a
universal CRS with deterministic specialization, which however, in comparison to [CF13,LM19],
outputs *constant-size* parameters instead of linear.

Aggregation. The VC of [BBF19] supports aggregation only on openings created by VC*:* Open
(i.e., it is one-hop) and does not have disaggregatable proofs (unless in a dierent model where one
works linearly in the length of the vector or knows the full vector). In contrast, we show the rst
schemes that satisfy incremental aggregation (also, our second one immediately yields a method
for the incremental aggregation of [LM19]). As we mention later, incremental aggregation can be
very useful to precompute openings for a certain number of vector blocks allowing for interesting
time-space tradeos that can speedup the running time of VC*:* Open.

Efficiency. From the table, one can see that our rst SVC has: slightly worse commitments size
than all the other schemes, computational asymptotic performances similar to [BBF19], and opening
size slightly better than [BBF19]. Our second SVC is the most ecient among the schemes with
constant-size parameters; in particular, it has faster asymptotics than our rst SVC and [BBF19]

<sup>18</sup>
We refer to [BBF19] to see how these schemes compare with Merkle trees.

---

for having a smaller logarithmic factor (e.g., log(*N m*) vs. log(*‘N*)), which is due to the avoidance
of using one prime per bit of the vector. In some cases, [CF13,LM19] is slightly better, but this
is essentially a benet of the linear-size parameters, namely the improvement is due to having the
*S*<sub>i</sub>’s elements already precomputed.

$$
(\mathrm {e . g .}, \log (N - m)
$$

$$
S _ {i} ^ {\prime} \mathrm {s}
$$

When considering applications in which a user creates the commitment to a vector and (at
some later points in time) is requested to produce openings for various subvectors, *our incremental*
*aggregation property leads to use preprocessing to achieve more favorable time and memory costs*.
In a nutshell, The idea of preprocessing is that one can precompute and store information that
allows to speedup the generation of openings, in particular by making opening time less dependent
on the total length of the vector. Our method in Section4.2works generically for any SVC that
has incremental aggregation. A similar preprocessing solution can also be designed for the SVC
of [BBF19] by using its one-hop aggregation; we provide a detailed description of the method
in AppendixB. The preprocessing for [BBF19] however has no exibility in choosing how much
auxiliary storage can be used, and one must store (a portion of) a non-membership witness *for*
*every bit* of the vector.

Even in the simplest case of *B* = 1 (shown in Table1) both our SVCs save a factor *‘* in storage,
which concretely turns into 3 less storage.

Furthermore we support exible choices of B thus allowing to tune the amount of auxiliary
*p* p
storage. For instance, we can choose *B* = <u>N</u> so as to get 2 *N j*G*j* bits of storage, and opening time
*p p*
2
about *O*(*‘m*log*n*( *n*+ log*m*)) and *O*(*m*( *n*+ log *m*)) in the rst and second scheme respectively.
Our exibility may also allow one to choose the buckets size *B* and their distribution according
to applications-dependent heuristics; investigating its benet may be an interesting direction for
future work.

$$
B=\sqrt{N}
$$

$$
2\sqrt{N}|\mathbb{G}|
$$

$$
n{\big(}{\sqrt{n}}+\log m\big),
$$

$$
O(m{\bigl(}{\sqrt{n}}+{log^{2}}m{\bigr)})
$$

| Metric | Our First SVC | Our Second SVC | [BBF19] | [CF13,LM19] |
| --- | --- | --- | --- | --- |
| Setup |  |  |  |  |
| VC.Setup | O(1) | O(1) | O(1) | O(1) |
| |crs| | 3|G| | 1|G| | 1|G| | 1|G| |
| VC.Specialize | O(ℓ·N·log(ℓN))G | O(ℓ·N)G | - | O(ℓ·N·logN)G |
| |crs_N| | 1|G| | 1|G| | - | N|G| |
| Commit a vector $\vec{v}\in(\{0,1\}^{\ell})^{N}$ |  |  |  |  |
| VC.Com | O(ℓ·N·log(ℓN))G | O(ℓ·N·logN)G | O(ℓ·N·log(ℓN))G | O(ℓ·N)G |
| |C| | 4|G|+2|Z_{22λ}| | 1|G| | 1|G| | 1|G| |
| Opening and Verification for $\vec{v}_{I}$ with $|I|=m$ |  |  |  |  |
| VC.Open | O(ℓ·(N-m)·log(ℓN))G | O(ℓ·(N-m)·log(N-m))G | O(ℓ·(N-m)·log(ℓN))G | O(ℓ·(N-m)·m log m)G |
| |π_I| | 3|G| | 2|G| | 5|G|+1|Z_{22λ}| | 1|G| |
| VC.Ver | O(ℓ·m·log(ℓN))Z_{22λ}+O(\lambda)G | O(ℓ·m log m)|G| | O(m·ℓ·log(ℓN))Z_{22λ}+O(\lambda)G | O(ℓ·m)G |
| Commitment and Opening with Precomputation |  |  |  |  |
| VC.Com | O(ℓ·N·log(ℓ·N)·log(N))G | O(ℓ·N log^2(N))G | O(ℓ·N·log(ℓ·N)·log(N))G | O(ℓ·N log^2(N)) |
| |aux| | 2N|G| | 2N|G| | 2N|G|+O(ℓ·N log(ℓN)) | 2N|G| |
| VC.Open | O(m·ℓ·log(m) log(ℓN))G | O(ℓ·m log^2m)G | O(m·ℓ·log(m) log(ℓN))G | O(m·ℓ·log^2(m))G |
| Aggregation | Incremental | Incremental | One-hop | Incremental |
| Disaggregation | Yes | Yes | No | Yes |

$$
O(\ell\cdot N\cdot\operatorname{l o g}(\ell N))\;\mathbb{G}
$$

$$
O(\ell\cdot N)\ \mathbb{G}
$$

$$
O(\ell\cdot N\cdot\operatorname{l o g}N)\ mathbb G;
$$

$$
\vec{v}\in(\{0,1\}^{\ell})^{N}
$$

$$
O(\ell\cdot N\cdot\operatorname{l o g}N)\;\mathbb{G}
$$

$$
\overline{{O(\ell\cdot N\cdot\operatorname{l o g}(\ell N))\ \mathbb{G}}}
$$

$$
\overline{{O(\ell\cdot N)\,\mathbb{G}}}
$$

$$
O(\ell\cdot N\cdot\operatorname{l o g}(\ell N))\;\mathbb{G}
$$

$$
4\ |\mathbb{G}|+2\ |\mathbb{Z}_{2^{2\lambda}}|
$$

$$
O(\ell\cdot(N-m)\cdot\log(\ell N))\,\mathbb{G}
$$

$$
\left|O(\ell\cdot(N-m)\cdot\operatorname{l o g}(N-m)\right)\mathbb{G}
$$

$$
O(\ell\cdot(N-m)\cdot\log(\ell N))\;\mathbb{G}
$$

$$
\overline{{\left|O(\ell\cdot(N-m)\cdot m\operatorname{l o g}m\right)\mathbb{G}}}
$$

$$
2\left|\mathbb{G}\right|
$$

$$
5\ |\mathbb{G}|+1\ |\mathbb{Z}_{2^{2\lambda}}|
$$

$$
O \left(\ell \cdot m \cdot \log (\ell N)\right) \mathbb {Z} _ {2 ^ {2 \lambda}} + O (\lambda) \mathbb {G}
$$

$$
O(\ell\cdot m\operatorname{l o g}m)\;|\mathbb{G}|
$$

$$
0(m\cdot\ell\cdot\log(N))\mathbb{I}_{2^{2\lambda}}+O(\lambda)\mathbb{G}
$$

$$
\overline{{O(\ell\cdot N\cdot\log(\ell\cdot N)\cdot\log(N))\mathbb{G}}}
$$

$$
O(\ell\cdot N\operatorname{l o g}^{2}(N))\;\mathbb{G}
$$

$$
{\overline{{O(\ell\cdot N\cdot\log(\ell\cdot N)\cdot\log(N))\ \mathbb{G}}}}
$$

$$
\overline{{O(\ell\cdot N\operatorname{l o g}^{2}(N))}}
$$

$$
2N\left|\mathbb{G}\right|
$$

$$
2N\,|\mathbb{G}|+O(\ell\cdot N\log(\ell N))
$$

$$
2N\left|\mathbb{G}\right|
$$

$$
O(m\cdot\ell\cdot\log(m)\log(\ell N))\,\mathbb{G}
$$

$$
2N\left|\mathbb{G}\right|
$$

$$
O(\ell\cdot m\operatorname{l o g}^{2}m)\;mathbb
$$

$$
O(m\cdot\ell\cdot\log(m)\log(\ell N))\;\mathbb{G}
$$

$$
O(m\cdot\ell\cdot\operatorname{l o g}^{2}(m))\;\mathbb{G}
$$

Table 1. Comparison between the SVC’s of [BBF19], [LM19] and this work; our contributions are highlighted in gray.
‘ N
We consider committing to a vector *~v 2* (*f*0*;* 1*g*) of length *N*, and opening and verifying for a set *I* of *m* positions.
By ‘*O*(*x*) G’ we mean *O*(*x*) group operations in G; *j*G*j* denotes the bit length of an element of G. An alternative
algorithm for VC*:* Open in [LM19] costs *O*(*‘* (*N m*) log(*N m*)). Our precomputation is for *B* = 1.

$$
\vec{v}\in(\{0,1\}^{\ell})^{N}
$$

$$
{mathfrak}O{({\boldsymbol{x}})}\ \mathbb{G}^{\ }
$$

$$
O(x)
$$

$$
\mathbb{G},
$$

$$
O(\ell\cdot(N-m)\cdot\log(N-m))
$$

$$
B=1
$$

---

Setup(1) : run G $ Ggen(1), *g* $ G, set crs := (G*;g*).
<u>Prover’s input:</u> (crs*;* (*A;B;C;;*)*;* (*a;b*<u>)). Verier’s input:</u> (crs*;* (*A;B;C;;*)).
<u>V</u><u>!</u> <u>P</u>: *h* $ G
a b
<u>P</u><u>!</u> <u>V</u>: *z* := (*za;zb*) computed as *za h;zbh*
<u>V</u><u>!</u> <u>P</u>: *‘* $ Primes() and $ [0*;* 2)
<u>P</u><u>!</u> <u>V</u>: := ((*QA;QB;QC*)*;ra;rb*) computed as follows
{ (*qa;qb;qab*) (*ba=‘c; bb=‘c; bab=‘c*)
{ (*ra;rb*) (*a* mod *‘;b* mod *‘*)
qa qa qb qb qab
{ (*QA;QB;QC*) := ( *h; h;g*)
<u>V(crs</u><u>;</u> <u>(</u><u>A;B;C</u><u>)</u><u>;za;zb;‘;;</u><u>):</u>
{ Compute *rc ra rb*mod *‘*
‘ ra ra ‘ rb rb ‘ rc
<u>{ Output 1 i</u> <u>r</u>*a*<u>;r</u>*b*<u>2</u> <u>[</u><u>‘</u><u>]</u> <u>^ Q</u>A<u>h</u> <u>=</u> <u>Az</u>a<u>^ Q</u>B<u>h</u> <u>=</u> <u>Bz</u>b<u>^ Q</u>C<u>g</u> <u>=</u> <u>C</u>

$$
{\underline{{\mathsf{V}}}}\to{\underline{{\mathsf{P}}}}\colon h\leftarrow{\mathfrak{S}}\,{\mathbb{G}}
$$

$$
\underline{{\mathsf{P}\to\mathcal{V}}};\ z z:=\left(z_{a},z_{b}\right)
$$

$$
\underline {{\mathrm {V} \rightarrow \mathrm {P}}}: \ell \leftarrow \$ \operatorname {P r i m e s} (\lambda)
$$

$$
z_{a}\leftarrow h^{a},z_{b}\leftarrow h^{b}
$$

$$
\alpha\leftarrow\ [,22^{\lambda})
$$

$$
\underline {{\mathrm {P} \rightarrow \mathrm {V}}}: \pi := \left(\left(Q _ {A}, Q _ {B}, Q _ {C}\right), r _ {a}, r _ {b}\right)
$$

$$
-\ (q_{a},q_{b},q_{a b})\leftarrow(\ a/c\ ,\ b/c\,\ \ a a//c/))
$$

$$
-\ (r_{a},r_{b})\leftarrow(a
$$

$$
-\ (Q_{A},Q_{B},Q_{C}):=(\varGamma^{q_{a}}h^{\alpha q_{a}},\varDelta^{q_{b}}h^{\alpha q_{b}},g^{q_{a b}})
$$

$$
\mathsf{V}(\mathsf{c r s},(A,B,C),z_{a},z_{b},\ell,\alpha,\pi)
$$

$$
r_{c}\leftarrow r_{a}\cdot r_{b}
$$

Fig. 4. PoProd protocol

## 6 Arguments of Knowledge for Our First SVC

We propose three Arguments of Knowledge (AoK) related to our vector commitment scheme presented in section5.1. More specically, the rst AoK allows one to prove knowledge of an opening
of a subvector. The second AoK, is a direct outcome of the rst and allows one to prove that two
given commitments share a common subvector. Finally, the third protocol allows one to commit to
a prex-subvector of a vector and prove the knowledge of it succinctly.

Similarly to section5.1, our protocols build on the techniques for succinct proofs in groups of
unknown order from [BBF19]. Furthermore, these arguments of knowledge are not zero knowledge
and they serve eciency purposes. Interestingly, one can prove knowledge of a portion of a vector
committed *without having to send the actual vector values*. The proofs are constant-size which leads
to an improvement of communication complexity linear in the size of the opening.

## 6.1 Building block: A Stronger Proof of Product

Before proceeding to describing the main protocols, we introduce another one that is used as
building block. This is an argument of knowledge, called PoProd , for the relation *R*<sub>PoProd</sub>described
below, which uses a common reference string consisting of a hidden order group G Ggen(1 ) and
a random generator *g 2* G:

$$
R_{\mathsf{P o P r o d^{*}}}
$$

$$
\mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda})
$$

$$
g\in\mathbb{G}
$$

$$
R _ {\mathrm {P o P r o d} ^ {*}} = \left\{\left((A, B, C, \Gamma , \Delta), (a, b)\right) \in \mathbb {G} ^ {5} \times \mathbb {Z} ^ {2}: A = \Gamma^ {a} \wedge B = \Delta^ {b} \wedge C = g ^ {a \cdot b} \right\}
$$

The relation *R*<sub>PoProd</sub>is similar to *R*<sub>PoProd</sub>dened in Section5.1with the dierence that now
the rst two bases and are not part of the common reference string, but part of the statement
instead. As argued in [BBF19] the PoKE protocol is not secure anymore for adversarially chosen
bases, therefore we cannot use PoProd protocol which assumes knowledge extractability of PoKE .
To deal with this problem, we thus modify the protocol by using the protocol PoKE2, which is
secure for arbitrary bases. This comes with some cost: in our PoProd a proof consists of 5 group
elements and 2 eld elements, that is 2 group elements more comparing to proofs of PoProd. The
protocol is in Fig.6.1.

$$
R_{\mathsf{P o P r o d^{*}}}
$$

$$
R_{\mathsf P o p r o d}
$$

$$
\Delta
$$

Theorem 6.1. *The* PoProd *protocol in Fig.6.1is an argument of knowledge for R*<sub>PoProd</sub>*in the*
*generic group model.*

$$
R_{\mathsf{P o P r o d^{*}}}
$$

---

The proof of the theorem above is similar to the proof of Theorem5.1, except that we use
the extractor *E*<sub>PoKE2</sub>of the protocol PoKE2 from [BBF19] in order to extract integers *a* and *b* and
*E*<sub>PoKE</sub>in order to extract the exponent of *C*.

$$
\mathcal{E}_{\mathsf{P o K E E2}}
$$

$$
\mathcal{E}_{\mathsf{P o K E}^{*}}
$$

## 6.2 A Succinct AoK of Opening for our VC Construction

We show an argument of knowledge of an *I*-opening with respect to a commitment *C* to a vector,
where *I* is a set of positions. We emphasize that the goal of this protocol is not to keep the opening
secret (i.e., the protocol is not zero knowledge, also our vector commitment scheme is not hiding).
The goal is to reduce the communication complexity of an opening by proving knowledge of the
subvector at positions *I* without having to actually send the values *~v*<sub>I</sub>. Even though the argument
of knowledge itself adds an overhead it is independent of the number of the positions. Hence, the
protocol makes more sense for large sets of positions *I* as for a small number of positions the
overhead of the AoK would exceed the size of the opening values.

$$
{vec{v}}_{I}
$$

Let VC = (VC*:* Setup*;*VC*:* Specialize*;*VC*:* Com*;*VC*:* Open*;*VC*:* Ver) be our SVC scheme from Section
5.1, and let us dene the following relation

$$
R_{\mathsf{P o K O O e e n}}=\{(\:(C,I),\:(\vec{y},\pi_{I})\:):\mathsf{V C.V e r}(\mathsf{c r s},C,I,\vec{y},\pi_{I})=1\}
$$

that is parametrized by a CRS crs VC*:* Setup(1*; M*), and where the statement consists of a
jIj
commitment *C* and a set of indices *I* [*n*], and the witness consists of a vector *~y 2M* and an
opening<sub>I</sub>.

$$
\leftarrow\ {mathsf V C C}u t{\mathsf{u p}}(1^{\lambda},{\mathcal{M}})
$$

$$
I\subseteq[n]
$$

$$
\vec{y}\in\mathcal{M}^{|I|}
$$

$$
\pi I
$$

For simplicity we present a protocol PoKOpen for the case when *k* = 1 in our VC (see section5.1);
extension to larger *k* is immediate. The idea of our protocol is that, given a commitment *C* :=
((*A;B*)*;*<sub>prod</sub>) and a set of indices *I*, the prover, holding<sub>I</sub>:= (<sub>I</sub>*;*<sub>I</sub>), rst sends<sub>I</sub>to the verier
aIbI aIbIuI
and then provides an AoK of (*a*<sup>I</sup>*;b*<sup>I</sup>) such th<sup>a</sup>t = *A ^* = *B ^ g* = *U*<sup>I</sup>, where *U*<sup>I</sup>*g*
<sup>I</sup> I
with *u*<sub>I</sub>PrimeProd(*I*). This can be proven by using the PoProd protocol presented above.
Finally the verier should also verify the<sub>prod</sub>proof as in the normal verication of an opening
algorithm.

$$
C:=
$$

$$
\pi_{I}:=\left(\varGamma_{I},\varDelta_{I}\right)
$$

$$
((A,B),\pi_{\mathsf{p r o d}})
$$

$$
\pi I
$$

$$
\varGamma_{I}^{a_{I}}=A\wedge\varDelta_{I}^{b_{I}}=B\wedge g^{a_{I}\cdot b_{I}}=U_{I}
$$

$$
(a_{I},b_{I})
$$

$$
U_{I}\leftarrow g^{u_{I}}
$$

$$
u_{I}\gets\mathsf{P r i m e P r o d}(I)
$$

$$
\pi_{\mathsf{p r o d}}
$$

We state the following theorem.

Theorem 6.2. *If* PoProd *is a succinct argument of knowledge for R*<sub>PoProd</sub>*, then protocol* PoKOpen
*is a succinct argument of knowledge for relation R*<sub>PoKOpen</sub>*with respect to algorithm* VC*:* Ver *of our*
*construction of Section5.1.*

$$
R_{\mathsf{P o P r o d^{*}}}
$$

$$
R_{\mathsf P o o Q O p n}
$$

Proof Let *A* be an adversary of the Knowledge Extractability of PoKOpen such that: ((*C;I*)*;*state)
*A₀*(pp), *A₁*(pp*;* (*C;I*)*;*state) executes with V(pp*;* (*C;I*)) the protocol PoKOpen and the verier accepts with a non-negligible probability. We will construct an extractor *E* that having access to
the internal state of *A₁* and on input (pp, (*C;I*)*;*state), outputs a witness (*~y;*<sub>I</sub>) of *R*<sub>PoKOpen</sub>with
overwhelming probability and runs in (expected) polynomial time.

$$
((C,I),\mathsf{s t a t e})\leftarrow
$$

$$
\mathcal{A}_{0}(\mathsf{p p}),\thinspace\mathcal{A}_{1}(\mathsf{p p},(C,I)
$$

$$
\mathsf{V}(\mathsf{p p},(C C,I))
$$

$$
\mathcal{E}
$$

$$
\mathcal{A}_{1}
$$

$$
(\vec{y},\pi_{I})
$$

$$
R_{\mathsf P o o Q O p n}
$$

To prove knowledge extractability of PoKOpen we rely on the knowledge extractability of
PoProd . More precisely, given a PoKOpen execution between *A* and V, (I*;*I*; 0*), *E* con-
PoProd
structs an adversary *A⁰* = (*A⁰*<sub>0</sub>*; A⁰*<sub>1</sub>) of PoProd Knowledge Extractability and, by using the input
and internal state of *A₁*, simulates an execution between *A⁰* and V: *A⁰*<sub>0</sub>outputs (((G*;g*)*;* (*A;B;U*<sub>I</sub>*;*
*I;*I))*;*state), *A⁰*1outputs tuple

$$
\mathsf{P o P r o d}^{*}
$$

$$
\mathcal{A}^{\prime}=(\mathcal{A}_{0}^{\prime},\mathcal{A}_{1}^{\prime})
$$

$$
\mathsf{V},\:(\varGamma_{I},\varDelta_{I},\pi_{\mathsf{P_{0}P P o d^{\prime}}}),\:\mathcal{E}
$$

$$
\mathcal{A}
$$

$$
\Gamma_ {I}, \Delta_ {I})
$$

$$
\mathrm {V}: \mathcal {A} _ {0} ^ {\prime}
$$

$$
\ {\cal A}_{1}.
$$

$$
\mathcal{A}_{1}^{\prime}
$$

$$
\mathcal{A}^{\prime}
$$

$$
(((\mathbb{G},g),(A,B,U_{I}
$$

(*z*<sub>a</sub>*;z*<sub>b</sub>*;* (*Q*<sub>A</sub>*;Q*<sub>B</sub>*;Q*<sub>C</sub>)*;r*<sub>a</sub>*;r*<sub>b</sub>). It is obvious that if the initial execution is accepted by V so is the
PoProd execution. From Knowledge Extractability of PoProd we know that there exists an extrac-
0 0 aIbI aIbI
tor *E* corresponding to *A₁* that outputs (*a*<sub>I</sub>*;b*<sub>I</sub>) such th<sup>a</sup>t *A* = *^ B* = *^ U*<sub>I</sub>= *g*. Since
<sup>I</sup> <sup>I</sup>

$$
(z_{a},z_{b},(Q_{A},Q_{B},Q_{C}),r_{a},r_{b})
$$

$$
\mathsf{P o P r o d}^{*}
$$

$$
\ mathcal E{{}}^prime{}
$$

$$
\mathcal{A}_{1}^{\prime}
$$

$$
A=\varGamma_{\it I}^{a_{I}}\wedge B=\varDelta_{\it I}^{b_{I}}\wedge U_{I}=g^{a_{I}\cdot b_{I}}
$$

$$
(a_{I},b_{I})
$$

---

PoKOpen protocol
<u>Prover’s input:</u> (crs*;* (*C;I*)*;* (*~y;I*<u>). Verier’s input:</u> (crs*;* (*C;I*)).
uI
<u>V</u> Compute *uI* PrimeProd(*I*) and then *UI g*.
un
Similarly compute *un* PrimeProd([*n*]) and then *Un g*
<u>P</u>: Parse crs := (G*;g;g₀;g₁;*PrimeGen*;Un*), *C* := (*fA;Bg;*prod), *I* := ( *I;I*). Compute (*aI;bI*)
uI
PartndPrimeProd(*I;~y*) and then *uI* PrimeProd(*I*) and *UI g*.
<u>P</u><u>!</u> <u>V</u>: ( *I;I*)
Finally a PoProd protocol (with an additional check of the commitment) between P((G*;g*)*;* (*A;B;UI;I;I*)*;* (*aI;bI*))
and V((G*;g*)*;* (*A;B;UI;I;I*)) is executed:
<u>V</u><u>!</u> <u>P</u>: *h* $ G
aI bI
<u>P</u><u>!</u> <u>V</u>: *z* := (*za;zb*) computed as *za h;zbh*
<u>V</u><u>!</u> <u>P</u>: *‘* $ Primes() and $ [0*;* 2)
<u>P</u><u>!</u> <u>V</u>: := ((*QA;QB;QC*)*;ra;rb*) computed as follows
{ (*qa;qb;qab*) (*baI=‘c; bbI=‘c; baI bI=‘c*)
{ (*ra;rb*) (*aI* mod *‘;bI* mod *‘*)
qa q qb qab
{ (*QA;QB;QC*) := (<sub>Iqa</sub>*h;*<sub>Ib</sub>*h;g*)
V: Parse crs := (G*;g;g₀;g₁;*PrimeGen*;Un*) and *C* := (*fA;Bg;*prod).
{ Compute *rc ra rb*mod *‘*
‘ ra ‘ r rb ‘ rc
{ Output 1 i *ra;rb2* [*‘*] *^ Q*A I<sup>ra</sup>*h* = *Az*a*^ Q*B Ib*h* = *Bz*b*^ Q*<sub>C</sub>*g* = *UI ^* PoProd₂*:* V(crs*;* (*A*
<u>B;U</u><sub>n</sub><u>)</u><u>;</u><sub>prod</sub><u>)</u>

$$
U_{I}\gets g^{u_{I}}
$$

$$
(\mathsf{c r s},(C,I),(\vec{y},\pi_{I})
$$

$$
\ \ (\mathsf{c r s},(\mathcal{C},I))
$$

$$
u_{I}\leftarrow\mathsf{P r i m e P r d}(I)
$$

$$
U_{n}\leftarrow g^{u_{n}}
$$

$$
u_{n}\leftarrow\mathsf{P r i m e P r o d}([n])
$$

$$
\begin{array}{r c l c l l l}{\ \mathsf{c r s}}&{:=}&{(\mathbb{G},g,g_{0},g_{1},\mathsf{P r i m e G e n},U_{n}),\;\;C}&{:=}&{(\{A,B\},\pi_{\mathsf{p r o d}}),\;\;\pi_{I}}&{:=}&{(\varGamma_{I},\varDelta_{I})}\\ \end{array}
$$

$$
\ a(a_{I},b_{I})\,\leftarrow\,
$$

$$
U_{I}\leftarrow g^{u_{I}}
$$

$$
\mathsf{P}((\mathbb{G},g),(A,B,U_{I},\varGamma_{I},\varDelta_{I}),(a_{I},b_{I})\big)
$$

$$
\underline{{\mathsf{{P}}}}\to\underline{{\mathsf{{V}}}}\ {\mathrm:{{{}}}}\ (\ \varGamma_{I},\varDelta_{I})
$$

$$
\mathsf{V}((\mathbb{G},g),(A,B,U_{I},\varGamma_{I},\varDelta_{I}))
$$

$$
{\underline{{\mathsf{V}}}}\to{\underline{{\mathsf{P}}}}\colon h\leftarrow{\mathfrak{s}}\,{\mathbb{G}}
$$

$$
{\underline{{\mathsf{P}}}}\to{\underline{{\mathsf{V}}}};z:=\left(z_{a},z_{b}\right)
$$

$$
z_{a}\leftarrow h^{a_{I}},z_{b}\leftarrow h^{b_{I}}
$$

$$
\underline{{\mathsf{{V}}}}\to\mathsf{{P}}:\ell\leftarrow\sharp\mathsf{{P r i m e s}}(\lambda)
$$

$$
\alpha \leftarrow \mathbb {s} [ 0, 2 ^ {\lambda})
$$

$$
\underline{{\mathcal{P}\to\mathcal{V}}};\pi:=((\mathcal{Q}_{A},\mathcal{Q}_{B},\mathcal{Q}_{C}),r_{a},r_{b})
$$

$$
-\ (mathit q_{{a}},\mathit{_{{}}}\ \mathit{q}{_{{a b}}})\leftarrow(\lfloor\mathit{a_{I}}/\ell\rfloor,\lfloor\mathit{b_{I}}/\ell\rfloor,\lfloor\mathit{a_{I}}{b_{I}}/\ell\rfloor)
$$

$$
-\ (r_{a},r_{b})\leftarrow(a_{I}
$$

$$
\ell,b_{I}
$$

$$
-\ (Q_{A},Q_{B},Q_{C}):=(\varGamma_{I}^{q_{a}}h^{\alpha q_{a}},\varDelta_{I}^{q_{b}}h^{\alpha q_{b}},g^{q_{a b}})
$$

$$
C:=(\{A,B\},\pi_{\mathsf{p r o d}})
$$

$$
U_{n})
$$

$$
\mathrm{-~C o m p u t e~}r_{c}\gets r_{a}\cdot r_{b}
$$

$$
- \text {O u t p u t} 1 \mathrm {i f f} r _ {a}, r _ {b} \in [ \ell ] \wedge Q _ {A} ^ {\ell} \Gamma_ {I} ^ {r _ {a}} h ^ {\alpha r _ {a}} = A z _ {a} ^ {\alpha} \wedge Q _ {B} ^ {\ell} \Delta_ {I} ^ {r _ {b}} h ^ {\alpha r _ {b}} = B z _ {b} ^ {\alpha} \wedge Q _ {C} ^ {\ell} g ^ {r _ {c}} = U _ {I} \wedge \operatorname {P o P r o d} _ {2}. \mathrm {V} (\mathrm {c r s}, (A \cdot
$$

$$
B,U_{n}),\pi_{\mathsf{p r o d}})
$$

Fig. 5. PoKOpen protocol

uI
*U*<sub>I</sub>is also computed from V it holds that *U*<sub>I</sub>= *g*, <sup>u</sup>nless with a negligible probability that *A⁰*
x uI
can nd an *x 6*= *u*<sub>I</sub>such that *g* = *U*<sub>I</sub>= *g* (which implies nding a multiple of the order of G).
uIaIbI
Therefore *g* = *U*<sup>I</sup>= *g* <sup>a</sup>nd using the same argument we know that *u*<sub>I</sub>= *a*<sub>I</sub>*b*<sub>I</sub>(unless with
negligible probability).

$$
U_{I}
$$

$$
\mathcal{A}^{\prime}
$$

$$
U_{I}=y^{u_{I}}
$$

$$
x\neq u_{I}
$$

$$
g^{x}=U_{I}=g^{u_{I}}
$$

$$
g^{u_{I}}=U_{I}=g^{a_{I}\cdot b_{I}}
$$

$$
u_{I}=a_{I}\cdot b_{I}
$$

0 aIbI aIbI
So, *E* uses *E* and gets a (*a*<sup>I</sup>*;b*<sup>I</sup>) such th<sup>a</sup>t *A* = *^ B* = *^ U*<sup>I</sup>= *g*. Then computes
I I
*u*<sub>I</sub>PrimeProd(*I*) and works as follows: for each *i 2 I* computes *p*<sub>i</sub>PrimeGen(*i*) and if *p*<sub>i</sub>*j a*<sub>I</sub>
then sets *y*i= 0, otherwise if pij aIthen sets yi= 1. It is clear that *p*idivides exactly one of
Q Q
*a*<sub>I</sub>*;b*<sub>I</sub>since *a*<sub>I</sub>*b*<sub>I</sub>= *u*<sub>I</sub>= *p*<sub>i</sub>:= PrimeGen(*i*) (unless with a negligible probabilit*y* that
i2I i2I
a collision happened in PrimeGen). Finally sets the subvector *~y* = (*y*<sub>i</sub>)<sub>i2I</sub>and<sub>I</sub>= (<sub>I</sub>*;*<sub>I</sub>). As
aIbI
stated <sub>a</sub>bove = *A ^* = *B* and also since V veries the PoKOpen protocol it holds that
I I
PoProd₂*:* V(pp*;* (*A B;U*<sub>n</sub>)*;*<sub>prod</sub>) which means that VC*:* Ver(pp*;C;I;~y;*<sub>I</sub>) = 1.

$$
\mathcal{E}^{\prime}
$$

$$
(a_{I},b_{I})
$$

$$
u_{I}\leftarrow{mathsf{P r i m e P r d d}}(I)
$$

$$
A\,=\,\ \
$$

$$
i\in I
$$

$$
p_{i}\gets\mathsf{P r i m e G e n}(i)
$$

$$
p_{i}\mid a_{I}
$$

$$
y_{i}\,=\,0
$$

$$
p_{i}\mid a_{I}
$$

$$
y_{i}=1
$$

$$
p_{i}
$$

$$
a_{I},b_{I}
$$

$$
a_{I}\cdot b_{I}=u_{I}=\prod_{i\in I}p_{i}:=\prod_{i\in I}
$$

$$
\pi_{I}=(\varGamma_{I},\varDelta_{I})
$$

$$
\varGamma_{I}^{a_{I}}=A\wedge\varDelta_{I}^{b_{I}}=B
$$

$$
\mathrm {P o P r o d} _ {2}. \mathrm {V} (\mathrm {p p}, (A \cdot B, U _ {n}), \pi_ {\mathrm {p r o d}})
$$

$$
\mathsf{V C.V e r}(\mathsf{p p},\mathcal{C},I,\vec{y},\pi_{I})=1
$$

As one can see, the expected running time of *E* is the (expected) time to obtain a successful
execution of the protocol plus the running time to obtain *~y* plus the running time of *E⁰*. To obtain *~y*
it will need to make *jIj* divisibility checks which takes time *O*~(*jIj*) plus *jIj* calls of PrimeGen, which
1~(
takes poly() time. So overall the expected time is + *t*E*0* + *O jIj*) + poly() = poly().

$$
\vec{y}
$$

$$
\mathcal{E}^{\prime}
$$

$$
\ddot{O}(|I|)
$$

$$
\vec{y}
$$

$$
\frac{1}{\epsilon}+t_{\mathcal{E}{'}}+\tilde{O}(|I|)+\mathsf{p o l y}(\lambda)=\mathsf{p o l y}(\lambda)
$$

Non-interactive PoKOpen. A non-interactive version of the protocol PoKOpen after applying the
generalized Fiat-Shamir transform [BCS16] is shortly presented below:

PoKOpen*:* P(crs*;* (*C;I*)*;* (*~y;*<sub>I</sub>))*!* : Parse crs := (G*;g;g₀;g₁;*PrimeGen*;U*<sub>n</sub>), *C* := (*fA;Bg;*<sub>prod</sub>),
*I*:= (I*;*I). Compute (*a*I*;b*I) PartndPrimeProd(*I;~y*) and then *u*IPrimeProd(*I*) and
<sup>u</sup><sup>I</sup>
*U*<sub>I</sub>*g*. Finally compute a proof<sub>PoProd</sub>PoProd *:* P((G*;g*)*;* (*A;B;U*<sub>I</sub>*;*<sub>I</sub>*;*<sub>I</sub>)*;* (*a*<sub>I</sub>*;b*<sub>I</sub>)).

$$
\mathsf{P}(\mathsf{c r s},(\mathcal{C},I),(\vec{y},\pi_{I}))\to\pi;
$$

$$
\mathtt{c r s}\:{=}\;(\mathbb{G},g,g_{0},g_{1},\mathsf{P r i m e G e n},U_{n}),\;C\:{=}\;(\{A,B\},\pi_{\mathsf{p r o d}})
$$

$$
\pi_{I}\ :=\ (\varGamma_{I},\varDelta_{I})
$$

$$
(a_{I},b_{I})\;\leftarrow\;\mathsf{P a r t n d P r i m e P r o d}(I,\vec{y})
$$

$$
u_{I}\leftarrow{mathsf P r r i p}d({\cal I})
$$

$$
U_{I}\gets g^{u_{I}}
$$

$$
\pi_ {\mathrm {P o P r o d} ^ {*}} \leftarrow \mathrm {P o P r o d} ^ {*}. \mathrm {P} \left(\left(\mathbb {G}, g\right), \left(A, B, U _ {I}, \Gamma_ {I}, \Delta_ {I}\right), \left(a _ {I}, b _ {I}\right)\right)
$$

---

Return (<sub>I</sub>*;*<sub>I</sub>*;*<sub>PoProd</sub>)

$$
\pi\gets(\varGamma_{I},\varDelta_{I},\pi_{\mathsf{P}_{0}\mathsf{P}_{\mathsf{r o d}^{*}}})
$$

PoKOpen*:* V(crs*;* (*C;I*)*;*<sub>PoProd</sub>)*! b*: Parse crs := (G*;g;g₀;g₁;*PrimeGen*;U*<sub>n</sub>), *C* := (*fA;Bg;*<sub>prod</sub>)
uI
and := (<sub>I</sub>*;*<sub>I</sub>*;*<sub>PoProd</sub>). Compute *u*<sub>I</sub>PrimeProd(*I*) and then *U*<sub>I</sub>*g*.
Ret<sup>u</sup>rn 1 if both PoProd₂*:* V(crs*;* (*A B;U*<sub>n</sub>)*;*<sub>prod</sub>) and

$$
\mathrm {V} \left(\operatorname {c r s}, (C, I), \pi_ {\mathrm {P o P r o d} ^ {*}}\right)\rightarrow b
$$

$$
\mathsf{c r s}:=(\mathbb{G},g,g_{0},g_{1}
$$

$$
U_{n}),\,\mathcal{C}:=(\{A,B\},\pi_{\mathsf{p r o d}})
$$

$$
\pi:=(\varGamma_{I},\varDelta_{I},\pi_{\mathsf{P}_{0}\mathsf{P}_{\mathsf{P r}0\mathsf{d}^{*}}})
$$

$$
U_{I}\gets g^{u_{I}}
$$

$$
\text {b o t h} \mathrm {P o P r o d} _ {2}. \mathrm {V} (\mathrm {c r s}, (A \cdot B, U _ {n}), \pi_ {\mathrm {p r o d}})
$$

PoProd *:* V((G*;g*)*;* (*A;B;*<sub>I</sub>*;*<sub>I</sub>*;U*<sub>I</sub>)*;*<sub>PoProd</sub>) output 1, and 0 otherwise.

$$
\mathsf{P o P r o d}^{*}.\mathsf{V}((\mathbb{G},g),(A,B,\varGamma_{I},\varDelta_{I},U_{I}),\pi_{\mathsf{P o P r o d}^{*}})
$$

*Remark 6.1(Achieving sub-linear verication time).* For ease of exposition we presented the case
of *k* = 1 in the above. For the case of arbitrary *k* one should prove knowledge of (*a*<sup>Ij</sup>*;b*<sup>Ij</sup>) such
V<sub>a</sub>V<sub>b</sub>
k Ij k Ij aIjb<sub>Ij</sub>uI
that = *A*<sub>j</sub>= *B ^ g* = *U*<sub>I</sub>, where UI*g* and <sub>u</sub><sub>I</sub>PrimeProd(*I*). Using
j=1 Ij j=1 Ij
the same technique as above the size of the AoK is *O*(*k*) (as is the commitment and the opening
proof). However, since the *U*<sub>I</sub>is the same for each *j*, the verication is done in O(*jIj=k*+ *k*) time.
p p
<sup>I</sup>nterestingly, if *k* = *jIj* the verication time gets *O*( *jIj*), which is sublinear in the size of the
opening. Essentially, in cases where the opening queries are (approximately) xed, one can trade a
p
larger commitment size *O*( *jIj*) in order to achieve an argument of knowledge of subvectors that
p
has sublinear size and s*u*blinear verication time *O*( *jIj*).

$$
(a_{I j},b_{I j})
$$

$$
\bigwedge_{j=1}^{k}\varGamma_{I j}^{a_{I j}}=A_{j}\bigwedge_{j=1}^{k}\varDelta_{I j}^{b_{I j}}=B\wedge g^{a_{I j}\cdot b_{I j}}=U_{I}
$$

$$
U_{I}\leftarrow g^{u_{I}}
$$

$$
u_{I}\gets\mathsf{P r i m e P r d}(I)
$$

$$
O(k)
$$

$$
U_{I}
$$

$$
j
$$

$$
k=\sqrt{|left|I|}
$$

$$
O\big(|I|/k\!+\!\lambda\!\cdot\!k\big)
$$

$$
O(\sqrt{|I|})
$$

$$
O(\sqrt{|I|})
$$

$$
O(\sqrt{|I|})
$$

Applications to Compact Proofs of Storage. We observe that the protocol PoKOpen for our
VC immediately implies a *keyless* proof of storage, or more precisely a proof of retrievable commitment (PoRC) [Fis18] with non-black-box extraction. In a nutshell, a PoRC is a proof of retrievability
[JK07] of a committed le. In [Fis18] Fisch denes PoRC and proposes a construction based on
vector commitments { called VC-PoRC { which abstracts away a classical proof of retrievability
based on Merkle trees. A bit more in detail, in the VC-PoRC scheme the prover uses a VC to
commit to a le (seen as a vector of blocks); then at every audit the verier chooses a challenge
by picking a set ofposrandomly chosen positions *I* = *fi* $ [*n*]*g*, and the prover responds by
sending the subvector *~v*<sub>I</sub>and an opening<sub>I</sub>. Here<sub>pos</sub>is a statistical parameter that governs the
probability of catching an adversary that deletes (or corrupts) a fraction of the le. For example, if
the le is rst encoded using an erasure code with constant rate (i.e., one where a-fraction of
1
blocks suces to decode and such that the encoded le has size roughly *jF j*), then an erasing
adversary has probability at most<sup>pos</sup>of passing an audit.

$$
I\,=\,\{i\leftarrow\,[n]\}
$$

$$
\lambda_{\mathsf{p o s}}
$$

$$
\pi I
$$

$$
{vec v,}_I
$$

$$
\lambda_{\mathsf{p o s}}
$$

$$
\mu
$$

$$
\mu^{-1}\cdot|F|)
$$

$$
\mu^{\lambda_{\mathsf{p o s}}}
$$

Our PoRC scheme is obtained by modifying the VC-PoRC of [Fis18] in such a way that the
VC opening is replaced by a PoKOpen AoK. This change saves the cost of sending the<sub>pos</sub>vector
values, which gives us *proofs of xed size*, 7 elements of G and 2 values of Z₂2. As drawback, our
scheme is not black-box extractable; strictly speaking, this means it is not a PoR in the sense of
19
[JK07] since the extractor does not exist in the real world.

$$
\lambda_{\mathsf{p o s}}
$$

$$
\mathbb{Z}_{2^{2}\lambda}
$$

We note that another solution with xed-size proofs can be achieved by using a SNARK to
prove knowledge of the VC openings so that the VC-PoRC verier would accept. For the Merkle
tree VC, this means proving knowledge of<sub>pos</sub>Merkle tree openings, which amounts to proving
20
correctness of about<sub>pos</sub>log*n* hash computations. On a le of 2 bits with 128 spot-checks, this
solution would reduce proof size from 80KB to less than 1KB. But its concrete proving costs are
high (more than 20 minutes and hundreds of GB of RAM).

$$
\lambda_{\mathsf{p o s}}
$$

$$
\lambda_{\mathsf{p o s}}
$$

$$
2^{20}
$$

In contrast we can estimate our AoK to be generated in less than 20 seconds and of size roughly
2KB.

<sup>19</sup> +
The notion of PoR with non-black-box extractability is close to that of robust proof of data possession [ABC 07,
<sup>+</sup>
ABC 11].

$$
\mathrm{[A B C^{+}07.}
$$

$$
\mathrm{A B C^{+}11}
$$

---

Since our PoRC scheme is a straightforward modication of Fisch’s VC-PoRC construction, a
complete description is omitted. We stress that our technical contribution here is the design of the
AoK.

Finally, we note that we can apply the observation of the previous remark in order to also
achieve verication time sub-linear in the size jIj of the challenged subvector at the expense of
p
slightly larger commitments (of size *jIj*).

$$
\sqrt{|I|})
$$

## 6.3 An AoK for commitments with common subvector

We note that a simple AND composition of two PoKOpen arguments of knowledge on two dierent
vector commitments can serve as a protocol proving knowledge of a common subvector of the two
vectors committed. More specically given two vector commitments, *C₁;C₂* on two dierent vector
*~v₁;~v₂* respectively, one can prove knowledge of a common subvector *~v*<sub>I</sub>with a succinct (constant
sized) argument without having to send the actual subvector. The two commitments should share
the same CRS crs VC*:* Setup(1*; M*) though they can have distinct specialized CRSs crs<sub>n</sub><sub>1</sub>and
crs<sub>n</sub><sub>2</sub>respectively (i.e., *~v₁* and *~v₂* may have dierent length). The underlying relation is:

$$
\vec{v}_{1},\vec{v}_{2}
$$

$$
C_{1},C_{2}
$$

$$
{\vec{v}}_{I}
$$

$$
\leftarrow\ {mathsf V C C}u t{\mathsf{u p}}(1^{\lambda},{\mathcal{M}})
$$

$$
\mathsf{c r s}_{n_{1}}
$$

$$
(\mathrm{i.e.,\ \vec{v}}_{1}
$$

$$
\mathsf{c r S}_{n_{2}}
$$

$$
\ {\vec{v}}_{2}
$$

$$
\begin{aligned}{R_{\mathsf{P o K C o m S u b}}=\{&}{}}{\{}&{{}(\ C_{1},C_{2},I),(\vec{v}_{I},\pi_{I,1},\pi_{I,2})\ :\mathsf{V C}\mathsf{V e r}^{*}(\mathsf{c r s}_{n_{1}},C_{1},I,\vec{v}_{I},\pi_{I,1})=1}\\ {}&{{}\wedge\mathsf{V C}\mathsf{V e r}^{*}(\mathsf{c r s}_{n_{2}},C_{2},I,\vec{v}_{I},\pi_{I,2})=1\}}\\ \end{aligned}
$$

As mentioned above, it is straightforward to show that an AND composition of PoKOpen on
dierent vector commitments *C₁* and *C₂* is a protocol for the above relation. That is the prover,
holding<sub>I;</sub><sub>1</sub>:= (<sub>I;</sub><sub>1</sub>;<sub>I;</sub><sub>1</sub>) and<sub>I;</sub><sub>2</sub>:= (<sub>I;</sub><sub>2</sub>;<sub>I;</sub><sub>2</sub>), rst sends<sub>I;</sub><sub>1</sub>;<sub>I;</sub><sub>2</sub>to the verier and then
aIbI aIbIaI
provides an argument of knowledge of (*a*<sub>I</sub>*;b*<sub>I</sub>) such th<sup>a</sup>t = *A₁^* = *B₁ ^ g* = *U*<sup>I</sup>*^* =
<sup>I</sup>;1 <sup>I</sup>;1 I;<sub>2</sub>
bI u<sup>I</sup>
*A₂ ^* = *B₂*, where *U*<sub>I</sub>*g* and *uI*PrimeProd(I).
I;2

$$
C_{1}
$$

$$
C_{2}
$$

$$
\pi_ {I, 1} := \left(\Gamma_ {I, 1}, \Delta_ {I, 1}\right)
$$

$$
\pi_{I,2}:=\big(\varGamma_{I,2},\varDelta_{I,2}\big)
$$

$$
\pi_{I,1},\pi_{I,2}
$$

$$
(a_{I},b_{I})
$$

$$
A_{2}\wedge\varDelta_{I,2}^{b_{I}}=B_{2}
$$

$$
U_{I}\leftarrow g^{u_{I}}
$$

$$
u_{I}\gets\mathsf{P r i m e P r o d}(I)
$$

## 6.4 A Succinct AoK for Commitment on Subvector

Here we present a protocol which succinctly proves that a commitment *C⁰* opens to an *I*-subvector
*~v*<sub>I</sub>of the opening *~v* of another commitment *C*. Since *C⁰* is a vector commitment *~v*<sub>I</sub>should be a
normal vector instead of a general subvector, i.e. *I* should be a set of consecutive positions starting
from 1, *I* = *f*1*;:::;n⁰g* for some *n⁰ 2* N. We note though that both commitments should share the
same crs (but not the same specialized CRS). Below is the relation of the AoK that is parametrized
by the two specialized CRSs crsnVC*:* Specialize(crs*;n*) and crsn*0* VC*:* Specialize(crs*;n⁰*) where
crs VC*:* Setup(1*; M*) is common.

$$
\vec{v}
$$

$$
C^{\prime}
$$

$$
{\vec{v}}_{I}
$$

$$
C^{\prime}
$$

$$
{vec v,}_I
$$

$$
I=\{1,\ldots,n^{\prime}\}
$$

$$
n^{\prime}\in\mathbb{N}
$$

$$
C s s_{n}\leftarrow V C.S p e c i d i l e(c r s,n)
$$

$$
\ s_{n^{\prime}}\leftarrow V C.S p e c i d l i z e(c r s,n^{\prime})
$$

$$
\mathsf{c r s}\leftarrow\mathsf{V C}.\mathsf{S e t u p}(1^{\lambda},\mathcal{M})
$$

$$
\begin{aligned}{R_{\mathsf{P o K S u b V}}=\ }&{{}({\ (C,C^{\prime},I),(\vec{v}_{I},\pi_{I},\pi_{I}^{\prime})}):{\mathsf{V C}}.\mathsf{V e r}^{*}(\mathsf{c r s}_{n},C,I,\vec{v}_{I},\pi_{I})=1}\\ {}&{{}\wedge{mathsf{V C}V e r}^{*}(\mathsf{c r s}_{n^{\prime}},C^{\prime},I,\vec{v}_{I},\pi_{I}^{\prime})=1\wedge|\vec{v}_{I}|=n^{\prime}\}}\\ \end{aligned}
$$

The idea of our protocol is that since the opening *~v*<sub>I</sub>is the *I*-subvector of *~v* one can provide a
succinct proof of knowledge of the opening at these positions using the PoKOpen protocol presented
above. However this is not enough as one should bind the opening proof with *C⁰*. This concretely can
happen if one embeds a proof of product for the two components, *A⁰* and *B⁰*, of *C⁰* inside the proof
of opening. More specically the prover provides an opening proof<sup>I</sup>:= (<sup>I</sup>*;*<sup>I</sup>) then computes
aI 0 bI 0 aIbIaI
(*a*<sub>I</sub>*;b*<sub>I</sub>) PartndPrimeProd(*I;~v*<sub>I</sub>) and proves th<sub>a</sub>t *g₀* = *A ^ g₁* = *B ^ U*<sub>n</sub><sub>0</sub> = *g ^* =
<sub>I</sub>
<sub>b</sub><sub>I</sub>
*A ^* = *B*. Notice that the last three equalities correspond to the proof of opening protocol
I

$$
{\vec{v}}_{I}
$$

$$
\vec{v}
$$

$$
C^{\prime}
$$

$$
B^{\prime}
$$

$$
\pi_{I}:=\left(\varGamma_{I},\varDelta_{I}\right)
$$

$$
C^{\prime}
$$

$$
(a_{I},b_{I})\;\leftarrow\;\mathsf{P a r t n d P r i m e P r o d}(I,\vec{v}_{I})
$$

$$
g_{0}^{a_{I}}\:=\:A^{\prime}{\ \wedge\ }g_{1}^{b_{I}}\:=\:B^{\prime}{\ \wedge\ }U_{n^{\prime}}\:=\:g^{a_{I}\cdot b_{I}}{\ \wedge\ }\varGamma_{I}^{a_{I}}\:=
$$

$$
A\wedge\varDelta_{I}^{b_{I}}\,=\,B
$$ and the rst three to the proof of product. So a conjunction of PoKOpen and PoProd protocol
is sucient. Lastly *g;g₀;g₁* and *U*<sub>n</sub>*0* are part of crs<sub>n</sub>*0* and (*A;B*), (*A⁰;B⁰*) part of the *C* and *C⁰*
commitments respectively.

$$
g,g_{0},g_{1}
$$

$$
U_{n^{\prime}}
$$

$$
\mathsf{c r s}_{n^{\prime}}
$$

$$
(A,B),\,(A^{\prime},B^{\prime})
$$

$$
C^{\prime}
$$

<u>Fig. 6. PoKSubV protocol</u>

<u>Prover input:</u> ((crs*n;*crs<sub>n0</sub>)*;* (*C;C⁰;I*)*;* (*~vI;I*<u>). Verier input:</u> ((crs*n;*crs<sub>n0</sub>)*;* (*C;C⁰;I*)).

<u>P</u><u>!</u> <u>V</u>: *I* := ( *I;I*)

A conjuction of PoProd and PoKOpen protocols between P(crs*n;*crs<sub>n0</sub>*;* (*C;C⁰;I*)*;* (*~vI;I*)) and V(crs*n;*crs<sub>n0</sub>*;* (*C;C⁰;I*))

is executed:
<u>V</u><u>!</u> <u>P</u>: *h* $ G
aI bI
<u>P</u><u>!</u> <u>V</u>: *z* := (*za;zb*) computed as *za h;zbh*
<u>V</u><u>!</u> <u>P</u>: *‘* $ Primes() and $ [0*;* 2)
0A 0B
<u>P</u><u>!</u> <u>V</u>: := ((*QA;QB;Q;Q;QC*)*;ra;rb*) computed as follows
{ (*qa;qb;qab*) (*baI=‘c; bbI=‘c; baI bI=‘c*)
{ (*ra;rb*) (*aI* mod *‘;bI* mod *‘*)
qa qb qa q qb qab
{ (*Q*<sub>A0</sub>*;Q*<sub>B0</sub>*;QA;QB;QC*) := (*g₀;g₁;*I<sup>qa</sup>*h;*Ib*h;g*)

V: Parse crs*n* := (G*;g;g₀;g₁;*PrimeGen*;Un*), crs<sub>n0</sub>:= (G*;g;g₀;g₁;*PrimeGen*;U*n0) and *C* := (*fA;Bg;*prod).

{ Compute *rc ra rb*mod *‘*

‘ ra ‘ rb ‘ ra ‘ r rb ‘ rc
{ Output 1 i *r*<sup>a</sup>*;r*<sup>b</sup>*2* [*‘*] *^ Q*<sup>A0</sup>*g₀* = *A⁰ ^ Q*<sub>B0</sub>*g₁* = *B⁰ ^ Q*<sub>A</sub> <sub>Ira</sub>*h* = *Az*<sub>a</sub>*^ Q*<sub>B</sub> <sub>Ib</sub>*h* = *Bz*<sub>b</sub>*^ Q*<sub>C</sub>*g* =

<u>U</u><sub>n</sub>*0* <u>^</u> <u>PoProd₂</u><u>:</u> <u>V(pp</u><u>;</u> <u>(</u><u>A B;U</u>*n*<u>)</u><u>;</u>prod<u>)</u>

$$
\left((\mathsf{c r s}_{n},\mathsf{c r s}_{n^{\prime}}),(C,C^{\prime},I)\right)
$$

$$
(big(\mathsf{c r s}_{n},\mathsf{c r s}_{n^{\prime}}\big),(\mathcal{C},\mathcal{C}^{\prime},I),(\vec{v}_{I},\pi_{I}\big)
$$

$$
\underline{{\mathsf{P}\to\mathbb{V}}}:\pi_{I}:=\left(\varGamma_{I},\varDelta_{I}\right)
$$

$$
\mathsf{V}(\mathsf{c r s}_{n},\mathsf{c r s}_{n^{\prime}},(C,C^{\prime},I))
$$

$$
{\sf P}({\sf c r s}_{n},{\sf c r s}_{n^{\prime}},({\mathcal C C},{\mathcal C}^{\prime},I),(\vec{v}_{I},\pi_{I}))
$$

$$
{\underline{{\mathsf{V}}}}\to{\mathsf{P}}\colon h\leftarrow\ \ \ \ \ \\
$$

$$
z_{a}\leftarrow h^{a_{I}},z_{b}\leftarrow h^{b_{I}}
$$

$$
\underline {{\mathrm {P} \rightarrow \mathrm {V}}}: z := \left(z _ {a}, z _ {b}\right)
$$

$$
\underline{{\mathsf{{V}}}}\to\mathsf{{P}}:\ell\leftarrow\sharp\mathsf{{P r i m e s}}(\lambda)
$$

$$
\alpha\leftarrow\ [,2^{\lambda})
$$

$$
\underline {{\mathrm {P} \rightarrow \mathrm {V}}}: \pi := \left(\left(Q _ {A}, Q _ {B}, Q _ {A} ^ {\prime}, Q _ {B} ^ {\prime}, Q _ {C}\right), r _ {a}, r _ {b}\right)
$$

$$
-\ {q_{a},q_{b},q_{a b}})\leftarrow(\lfloor a{a_I}\mathord\rfloor/\lfloor{b_{I}\\ \ell}\rfloor,\lfloor{a_{I}b_{I}/\ell}\rfloor)
$$

$$
-\ \big(r_{a},r_{b}\big)\leftarrow\big(a_{I}
$$

$$
-\ (Q_{A^{\prime}},Q_{B^{\prime}},Q_{A},Q_{B},Q_{C}):=(g_{0}^{q_{\alpha}},g_{1}^{q_{b}},\varGamma_{I}^{q_{\alpha}}h^{\alpha q_{\alpha}},\varDelta_{I}^{q_{b}}h^{\alpha q_{b}},g^{q_{a b}})
$$

$$
\mathsf{Y}_{!}\ \mathsf{P a r n e}\ \mathsf{e r n}_{n}:=(\mathsf{G},g,g_{0},g_{1},\mathsf{P r i m e G e n},U_{n}),\ \mathsf{e r n}_{n^{\prime}}:=(\mathsf{G},g,g_{0},g_{1},\mathsf{P r i m e G e n},U_{n^{\prime}})\ \operatorname{a n d}\ C:=(\{A,B\},\pi_{\pi\neq\ }
$$

$$
r_{c}\leftarrow r_{a}\cdot r_{b}
$$

$$
-\ {\mathrm{O u t p a t~1~i f}}r_{a},r_{b}\in[\ell]{\,\wedge\,\ },,Q_{A^{\prime}}^{\ell}g_{5}^{r\__{5}}=A^{\prime}{\,\wedge\,}\,Q_{B^{\prime}}^{}g_{1}^{r_{5}}=B^{\prime}{\,\wedge\,\ \,}Q_{A}^{\ell}I_{I}^{r_{5}}h^{\_{7}}_a={\,A\,},\wedge,,,,,,,
$$

$$
U_{n^{\prime}}\land\mathsf P_r o o\mathsf{r o d_{2}}\ V(\mathsf p\ ,(A\cdot B,U_{n}),\pi_{\mathfrak p00})
$$

We state the following theorem for the security of the protocol above.

Theorem 6.3. *If* PoProd *and* PoKOpen *are succinct arguments of knowledge for R*<sub>PoProd</sub>*and*
*R*<sub>PoKOpen</sub>*, then protocol* PoKSubV *in Fig.6is a succinct argument of knowledge for relation R*<sub>PoKSubV</sub>
*with respect to algorithm* VC*:* Ver *of our construction of Section5.1.*

$$
R_{\mathsf{P o P r o d^{*}}}
$$

$$
R_{\mathsf P o o Q O p n}
$$

$$
R_{\mathsf P o o K S u b V}
$$

The intuition of the proof is that one proves knowledge of an opening *I* for *C*, namely that *~v*<sub>I</sub>
is an *I*-subvector of *C*, where (*a*<sup>I</sup>*;b*<sup>I</sup>) PartndPrimeProd(*I;~v*<sup>I</sup>), with a normal proof of subvector
?
opening. This is equivalent to VC*:* Ver (crs<sub>n</sub>*;C;I;~v*<sub>I</sub>*;*<sub>I</sub>) = 1. Then in the same proof proves that
the accumulators of *C⁰* are composed by the same (*a*<sup>I</sup>*;b*<sup>I</sup>) which results to proving that *C⁰* commits
?
to *~v*<sub>I</sub>. The last point is equivalent to VC*:* Ver (crs<sub>n</sub><sub>0</sub>*;C⁰;I;~v*<sub>I</sub>*;*) = 1 *^j~v*<sub>I</sub>*j* = *n⁰*.
I0

$$
\ {vec v}_{I}
$$

$$
C
$$

$$
(a_{I},b_{I})\leftarrow\mathsf{P a r t n d P r i m e P r o d}(I,\vec{v}_{I})
$$

$$
\mathrm {V C}. \operatorname {V e r} ^ {\star} \left(\mathrm {c r s} _ {n}, C, I, \vec {v} _ {I}, \pi_ {I}\right) = 1
$$

$$
C^{\prime}
$$

$$
(a_{I},b_{I})
$$

$$
C^{\prime}
$$

$$
\vec{v}_{I}
$$

$$
\mathsf{V C}V_{}{\mathsf{V e r}}^{\star}(\mathsf{c r s}_{n^{\prime}},C^{\prime},I,\vec{v}_{I},\pi_{I}^{\prime})=1\wedge|\vec{v}_{I}|=n^{\prime}
$$

## 7 Veriable Decentralized Storage

In this section we introduce veriable decentralized storage (VDS). We recall that in VDS there
are two types of parties (called nodes): the generic *client nodes* and the more specialized *storage*
*nodes* (a storage node can also act as a client node). The main goal of client nodes is to retrieve
some blocks (i.e., a portion) of a given le. The role of a storage node is instead to store a portion
of a le (or more les) and to answer to the retrieval queries of clients that are relevant to the
portion it stores. In terms of security, VDS guarantees that malicious storage nodes cannot send to
the clients blocks of the le that have been tampered with.

We refer the reader to Section1.2for a discussion on the motivation and requirements of VDS.
In Table2we summarize the main roles/capabilities of VDS nodes.

---

| ALL PARTICIPATING NODES |  |
| --- | --- |
|  | STORAGE NODES |
| Store current digest.
Can retrieve blocks of the file and verify responses.
Can aggregate proofs they received.
Can update the digest following updates from other nodes | Store a portion of the file.
Can answer and certify retrievals of subportions.
Can produce and publish updates to their view.
Can apply updates from other nodes efficiently. |

Table 2. Roles in a decentralized veriable database.

## 7.1 Syntax

Here we introduce the syntax of VDS. A VDS scheme is dened by a collection of algorithms that
are to be executed by either storage nodes or client nodes. The only exception is the Bootstrap
algorithm that is used to bootstrap the entire system and is assumed to be executed by a trusted
party, or to be implemented in a distributed fashion (which is easy if it is public coin).

The syntax of VDS reects its goal: guaranteeing data integrity in a highly dynamic and decentralized setting (the le can change and expend/shrink often and no single node stores it all).
In VDS we create both parameters and an initial commitment for an empty le at the beginning
(through the probabilistic Bootstrap algorithm, which requires a trusted execution). From then on
this commitment is changed through incremental updates (of arbitrary size). Updating is divided
in two parts. A node can carry out an update it and \push" it to all the other nodes, i.e. providing
auxiliary information (that we call \update hint") other nodes can use to update their local certicates (if aected by the change) and a new digest²⁰. These operations are done respectively trough
StrgNode*:* PushUpdate and StrgNode*:* ApplyUpdate. Opening and verifying are where VC (with incremental aggregation) and VDS share the same mechanism. To respond to a query, a storage node
can produce (possibly partial) proofs of opening, nodes can use algorithm StrgNode*:* Retrieve. If
these proofs needs to be aggregated, any node can use algorithm AggregateCerticates. Anyone can
verify a proof through ClntNode*:* VerRetrieve.

In VDS we model the les to be stored as vectors in some message space *M* (e.g., *M* = *f*0*;* 1*g*
‘
or *f*0*;* 1*g*), i.e., F = (F₁*;:::;*F<sub>N</sub>). Given a le F, we dene a *portion* of it as a pair (*I;*F<sub>I</sub>) where F<sub>I</sub>
is essentially the *I*-subvector of F.

$$
\{0,1\}^{\ell}),\ \mathrm{i.e.,}\ \mathsf{F}=\left(\mathsf{F}_{1},\dots,\mathsf{F}_{N}\right)
$$

$$
(\mathrm{e.g.},\,\mathcal{M}=\{0,1\}
$$

$$
(I,\mathsf{F}_{I})
$$

$$
\ {mathsf F}_{I}
$$

## Denition 7.1(Veriable Decentralized Storage).

*Algorithm to bootstrap the system:*

Bootstrap(1 )*!* (pp*;*<sub>0</sub>*;*st₀) *Given the security parameter, the probabilistic bootstrap algorithm*
*outputs public parameters* pp*, initial digest*<sub>0</sub>*and state* st₀*.*<sub>0</sub>*and* st₀ *correspond to the digest*
*and storage node’s local state respectively for an empty le.*

$$
{\mathsf{B o o t s t r a p}}(1^{\lambda})\to({\mathsf{p p}},\delta_{0},{\mathsf{s t}}_{0})
$$

*All the algorithms below implicitly take as input the public parameters* pp*.*

*The algorithms for storage nodes are:*

StrgNode*:* AddStorage(*;n;* st*;I;*F<sub>I</sub>*;Q;*F<sub>Q</sub>*;*<sub>Q</sub>)*!* (st⁰*;J;*F<sub>J</sub>) *This algorithm allows a storage node to*
*add more blocks of a given le* F *to its local storage. Its rst inputs are the local view of the storage*
*node that is dened by a digest, a length n, a state* st*, and a le portion* (*I;*F<sub>I</sub>)*. Then it takes*

$$
(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},Q,\mathsf{F}_{Q},\pi_{Q})\to(\mathsf{s t}^{\prime},J,\mathsf{F}_{J})
$$

$$
n,
$$

$$
(I,\mathsf{F}_{I})
$$

<sup>20</sup>
One can also see this update hint as a certicate to check that a new digest is consistent with some changes. This
issue does not arise in our context as all but the Bootstrap algorithms are deterministic.

---

*as input a le subportion* (*Q;*F<sub>Q</sub>) *together with a valid retrieval certicate*<sub>Q</sub>*. The output is an*
*updated view of the storage node, that is a new state* st⁰ *and le portion* (*J;*F<sub>J</sub>) := (*I;*F<sub>I</sub>)*[*(*Q;*F<sub>Q</sub>)*.*
*Note that this algorithm can be used to enable anyone who holds a valid retrieval certicate for a*
*le portion* F<sub>Q</sub>*to become a storage node of such portion.*

$$
(Q,\mathsf{F}_{Q})
$$

$$
\pi_{Q}
$$

$$
\left(J,\mathsf{F}_{J}\right):=\left(I,\mathsf{F}_{I}\right){\cup}(Q(,,\mathsf{F}_{Q})
$$

$$
\mathrm {F} _ {Q}
$$

StrgNode*:* RmvStorage(*;n;* st*;I;*F<sub>I</sub>*;K*)*!* (st⁰*;J;*F<sub>J</sub>) *This algorithm allows a storage node to remove*
*blocks of a given le* F *from its local storage. Its rst inputs are the local view of the storage node*
*that is dened by a digest, a length n, a state* st*, and a le portion* (*I;*F<sub>I</sub>)*. Then it takes as*
*input a set of positions K I, and the output is an updated view of the storage node, that is a*
*new state* st⁰ *and le portion* (*J;*F<sub>J</sub>) := (*I;*F<sub>I</sub>) *n* (*K;*)*.*

$$
\left(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},K\right)\to\left(\mathsf{s t}^{I},J,\mathsf{F}_{J}\right)
$$

$$
n,
$$

$$
(I,\mathsf{F}_{I})
$$

$$
K\subseteq I
$$

$$
s mathsf{t}^{\prime}
$$

$$
\left(J,\mathsf{F}_{J}\right):=\left(I,\mathsf{F}_{I}\right)\setminus\left(K,\cdot\right)
$$

0
StrgNode*:* CreateFrom(*;n;* st*;I;*F<sub>I</sub>*;J*)*!* (*;n⁰;*st⁰*;J;*F<sub>J</sub>*;*<sub>J</sub>) *This algorithm allows a storage node*
*for a le subportion* F<sub>I</sub>*to create a new le containing only a subset* F<sub>J</sub>*of* F<sub>I</sub>*along with the*
0
*corresponding digest and length n⁰ and a hint to help other nodes generate their own digest.*
*The algorithm takes as input the local view of the storage node, i.e., digest, length n, local state*
0
st *and le portion* (*I;*F<sub>I</sub>)*, and a set of indices J I. The algorithm returns a new digest,*
*length n⁰, a local state* st⁰*, a le portion* (*J;*F<sub>J</sub>) *and an advice. This advice can be used by a*
0
*client holding only the former digest to obtain the new digest, by using the* ClntNode*:* GetCreate
*algorithm described below.*

$$
(\delta , n, \mathsf {s t}, I, \mathsf {F} _ {I}, J) \rightarrow \left(\delta^ {\prime}, n ^ {\prime}, \mathsf {s t} ^ {\prime}, J, \mathsf {F} _ {J}, \Upsilon_ {J}\right)
$$

$$
\mathrm {F} _ {I}
$$

$$
\mathrm {F} _ {J}
$$

$$
\delta^{\prime}
$$

$$
\mathrm {F} _ {I}
$$

$$
J\subseteq I
$$

$$
(I,\mathsf{F}_{I})
$$

$$
n^{\prime}
$$

$$
\delta^{\prime},
$$

$$
(J,\mathsf{F}_{J})
$$

$$
\delta^{\prime}
$$

0 0J
StrgNode*:* PushUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;*)*!* (*;n⁰;*st⁰*;J;*F*;*) *This algorithm allow a storage node*
*of a le subportion* F<sub>I</sub>*to perform an update on the le and to generate a corresponding digest,*
*length and local view, along with a hint other nodes can use to accordingly update their digests and*
*local views. The inputs include the local view of the storage node, i.e., digest, length n, local state*
st *and le portion* (*I;*F<sub>I</sub>)*, an update operation* op *2f*mod*;*add*;*del*g and an update description.*
0 0J
*The outputs are a new digest and length n⁰, a new local state* st⁰*, an updated le portion* (*J;*F)
0K
*and an update hint. If* op = mod*, then contains a le portion* (*K;*F) *such that K I and*
0K <sup>0K</sup>
F *represents the new content to be written in positions K. If* op = add*, it is also* = (*K;*F)
*except that K is a set of new (sequential) positions K \ I* =*; that start from n* + 1 *(and end to*
*n* + *jKj). If* op = del*, then only contains a set of positions K I, which are the ones to be*
*deleted (and are ought to be the jKj last sequential positions). The proof can be used by client*
0
*nodes holding in order to check the validity of the new digest, and by other storage nodes,*
*holding additionally the length n, in order to check the validity of the changes and to update their*
*local views accordingly.*

$$
(\delta , n, \mathsf {s t}, I, \mathsf {F} _ {I}, \mathsf {o p}, \Delta) \rightarrow (\delta^ {\prime}, n ^ {\prime}, \mathsf {s t} ^ {\prime}, J, \mathsf {F} _ {J} ^ {\prime}, \Upsilon_ {\Delta})
$$

$$
\mathrm {F} _ {I}
$$

$$
(I,\mathsf{F}_{I})
$$

$$
\in\{{\mathsf o m d},{\mathsf a d d},{\mathsf d e}
$$

$$
\Delta
$$

$$
\delta^{\prime}
$$

$$
(J,\mathsf{F}_{J}^{\prime})
$$

$$
n^{\prime}
$$

$$
s mathsf\ell t^{\prime}
$$

$$
Y_{\Delta}
$$

$$
K\subseteq I
$$

$$
\Delta
$$

$$
(K,\mathsf{F}_{K}^{\prime})
$$

$$
F_{K}^{\prime}
$$

$$
\varDelta=(K,\mathsf{F}_{K}^{\prime})
$$

$$
\bigcap\cap I=\emptyset
$$

$$
n+1
$$

$$
n+|K|)
$$

$$
\Delta
$$

$$
K\subseteq I
$$

$$
|K|
$$

$$
T_{\Delta}
$$

$$
\delta^{\prime}
$$

$$
n,
$$

0 0J
StrgNode*:* ApplyUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;;*)*!* (*b;;n⁰;*st⁰*;J;*F) *This algorithm allows a stor-*
*age node to incorporate changes in a le pushed by another node. The inputs include the local*
*view of the storage node, i.e., digest, length n, local state* st *and le portion* (*I;*F<sub>I</sub>)*, an update*
*operation* op *2f*mod*;*add*;*del*g, an update description and an update hint. The algorithm*
0
*returns a bit b (to accept/reject the update) and (if b* = 1*) a new digest, a new length n⁰, a new*
0J
*(local) state* st⁰ *and an updated le subportion* (*J;*F)*. If* op *2f*mod*;*add*g we have that J* = *I,*
*i.e., the node keeps storing the same indices; if* op = del *then J is I minus the deleted indices.*

$$
(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},\mathsf{o p},\varDelta,\varUpsilon_{\varDelta})\to(b,\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{J}^{\prime})
$$

$$
(I,\mathsf{F}_{I})
$$

$$
\mathsf{o p}\in
$$

$$
\bigtriangleup
$$

$$
T_{\Delta}
$$

$$
(i f\,b=1)
$$

$$
\delta^{\prime}
$$

$$
(J,\mathsf{F}_{J}^{\prime})
$$

$$
{\mathsf{o p}}\in\{{\mathsf{m o d}}
$$

$$
n^{\prime}
$$

$$
J=I
$$

StrgNode*:* Retrieve(*;n;* st*;I;*F<sub>I</sub>*;Q*)*!* (F<sub>Q</sub>*;*<sub>Q</sub>) *This algorithm allows a storage node to answer a*
*retrieval query for blocks with indices in Q and to create a certicate vouching for the correctness*
*of the returned blocks. The inputs include the local view of the storage node, i.e., digest, length*
*n local state* st *and le portion* (*I;*F<sub>I</sub>)*, and a set of indices Q. The output is a le portion* F<sub>Q</sub>*and*
*a retrieval certicate*<sub>Q</sub>*.*

$$
(\delta , n, \mathsf {s t}, I, \mathsf {F} _ {I}, Q) \rightarrow (\mathsf {F} _ {Q}, \pi_ {Q})
$$

$$
Q
$$

$$
(I,\mathsf{F}_{I})
$$

$$
Q.
$$

$$
\pi_{Q}
$$

$$
\mathrm {F} _ {Q}
$$

*The algorithms for clients nodes are:*

---

0
ClntNode*:* GetCreate(*;J;*<sub>J</sub>)*!* (*b;*) *On input a digest, a set of indices J and a creation advice*
0
*J, this algorithm returns a bit b (to accept/reject) and (if b* = 1*) a new digest that corresponds*
*to a le* F⁰ *that is the prex with indices J of the le represented by digest.*

$$
T_{J}
$$

$$
(i f\,b=1)
$$

$$
\delta^{\prime}
$$

0
ClntNode*:* ApplyUpdate(*;*op*;;*)*!* (*b;*) *On input a digest, an update operation*
op *2 f*mod*;*add*;*del*g, an update description and an update hint, it returns a bit b (to*
0
*accept/reject update) and (if b* = 1*) a new digest.*

$$
\mathrm {A p p l y U p d a t e} (\delta , \mathrm {o p}, \Delta , Y _ {\Delta}) \rightarrow (b, \delta^ {\prime})
$$

$$
\textsf{o p}\in
$$

$$
\bigtriangleup
$$

$$
\delta^{\prime}
$$

$$
(i f\,b=1)
$$

$$
T_{\Delta}
$$

ClntNode*:* VerRetrieve(*;Q;*F<sub>Q</sub>*;*<sub>Q</sub>)*! b On input a digest, a le portion* (*Q;*F<sub>Q</sub>) *and a certicate*
*Q, this algorithm accepts (i.e. it outputs 1) only if*Q*is a valid proof that corresponds to a*
*le* F *with length n of which* F<sub>Q</sub>*is the portion corresponding to indices Q.*

$$
(left(\delta,Q,\mathsf{F}_{Q},\pi_{Q})\to b
$$

AggregateCerticates(*;* (*I;*F<sub>I</sub>*;*<sub>I</sub>)*;* (*J;*F<sub>J</sub>*;*<sub>J</sub>))*!*<sub>K</sub>*On input a digest and two certicated re-*
*trieval outputs* (*I;*F<sub>I</sub>*;*<sub>I</sub>) *and* (*J;*F<sub>J</sub>*;*<sub>J</sub>)*, this algorithm aggregates their certicates into a single*
*certicate*<sub>K</sub>*(with K* := *I[J). In a running VDS system, this algorithm can be used by any*
*node to aggregate two (or more) incoming certied data blocks into a single certied data block.*

$$
\big(\emptyset,\big(I,\mathsf{F}_{I},\pi_{I}\big),\big(J,\mathsf{F}_{J},\pi_{J}\big)\big)\to\pi_{K}
$$

$$
(I,\mathsf{F}_{I},\pi_{I})
$$

$$
(J,\mathsf{F}_{J},\pi_{J})
$$

$$
\pi_{K}
$$

$$
K:=I\cup J,
$$

*Remark 7.1(On CreateFrom).* For completeness, our VDS syntax also includes the functionalitis
(StrgNode*:* CreateFrom*;*ClntNode*:* GetCreate) that allow a storage node to initialize storage (and corresponding digest) for a new le that is a subset of an existing one, and a client node to verify
such resulting digest. Although this feature can be interesting in some application scenarios (see
the Introduction), we still see it as an extra feature that may or may not be satised by a VDS
construction.

## 7.2 Correctness and Eciency of VDS

Intuitively, we say that a VDS scheme is *ecient* if running VDS has a \small" overhead in terms
of the storage required by all the nodes and the bandwidth to transmit certicates. More formally,
a VDS scheme is said ecient if there is a xed polynomial *p*( ) such that *p*(*;*log*n*) (with the
security parameter and *n* the length of the le) is a bound for all certicates and advices generated
by the VDS algorithms as well as for digests and the local state st of storage nodes. Note that
combining this bound with the requirement that all algorithms are polynomial time in their input,
we also get that no VDS algorithm can run linearly in the size of the le (except in the trivial case
that the le is processed in one shot, e.g., in the rst StrgNode*:* AddStorage).

$$
p(\lambda,\log n)
$$

Eciency essentially models that running VDS is cost-eective for all the nodes in the sense
that it does not require them to store signicantly more data then they would have to store
without. Notice that by requiring certicates to have a xed size implies that they do not grow
with aggregation.

For correctness, intuitively speaking, we want that for any (valid) evolution of the system in
which the VDS algorithms are honestly executed we get that any storage node storing a portion
of a le F can successfully convince a client holding a digest of F about retrieval of any portion
of F. And such (intuitive notion of) correctness is also preserved when updates, aggregations, or
creations of new les are done.

Turning this intuition into a formal correctness denition turned out to be nontrivial. This is
due to the distributed nature of this primitive and the fact that there could be many possible
ways in which, at the time of answering a retrieval query, a storage node may have reached its
state starting from the empty node state. The basic idea of our denition is that an empty node is
\valid", and then any \valid" storage node that runs StrgNode*:* PushUpdate \transfers" such validity
to both itself and to other nodes that apply such update. A bit more precisely, we model \validity"

---

as the ability to correctly certify retrievals of any subsets of the stored portion. A formal denition
correctness follows. To begin with, we dene the notion of validity for the view of a storage node.

Denition 7.2(Validity of storage node’s view). *Let* pp *be public parameters as generated*
*by* Bootstrap*. We say that a local view* (*;n;* st*;I;*F<sub>I</sub>) *of a storage node is* valid *if 8Q I:*

$$
(\delta,n,\mathsf{s t},I,\mathsf{F}_{I})
$$

$$
i f\#Q\subseteq I.
$$

$$
\mathsf{C I n t N o d e.V e r R e t r i e v e}(\delta,Q,\mathsf{F}_{Q},\pi_{Q})=\mathtt{1}
$$

*where* (F<sub>Q</sub>*;*<sub>Q</sub>) StrgNode*:* Retrieve(*;n;* st*;I;*F<sub>I</sub>*;Q*)

$$
:(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},Q)
$$

*Remark 7.2.* By Denition7.2the output of a bootstrapping algorithm (pp*;*<sub>0</sub>*;*st₀) Bootstrap(1 )
is always such that (pp*;*<sub>0</sub>*;* 0*;*st₀*;;;;*) is valid. This provides a \base case" for Denition7.4.

$$
(\mathsf{p p},\delta_{0},\mathsf{s t}_{0})\leftarrow\mathsf{B o o t s t a p}(1^{\lambda})
$$

$$
(\mathsf{p p},\delta_{0},0,\mathsf{s t}_{0},\emptyset,\emptyset)
$$

Second, we dene the notion of admissible update, which intuitively models when a given update
can be meaningfully processed, locally, by a storage node.

Denition 7.3(Admissible Update). *An update* (op*;*) *is* admissible *for* (*n;I;*F<sub>I</sub>) *if:*

$$
(mathsf o o p,\varDelta)
$$

0K 0K
{ *for* op = mod*, K I and j*F *j* = *jKj, where* := (*K;*F)*.*

$$
{\it f o r}\left(n,I,\mathsf{F}_{I}\right)\,j
$$

$$
K\subseteq I
$$

$$
|\mathsf{F}_{K}^{\prime}|=|K|
$$

$$
\varDelta:=(K,\mathsf{F}_{K}^{\prime})
$$

0K 0K
{ *for* op = add*, K \ I* =*; and j*F *j* = *jKj and K* = *fn*+1*;n*+2*;:::;n*+*jKjg, where* := (*K;*F)*.*
{ *for* op = del*, K I and K* = *fn jKj* + 1*;:::;ng, where* := *K.*

$$
\left|\mathbb{F}_{K}^{\prime}\right|=\left|K\right|
$$

$$
\varDelta:=(K,\mathsf{F}_{K}^{\prime})
$$

$$
- f o r \mathrm {o p} = \mathrm {d e l}, K \subseteq I a n d K = \{n - | K | + 1, \dots , n \}, w h e r e \Delta := K.
$$

In words, the above denition formalizes that: to push a modication at positions *K*, the storage
node must store those positions; to push an addition, the new positions *K* must extend the currently
stored length of the le; to push a deletion of position *K*, the storage node must store data of the
positions to be deleted and those positions must also be the last *jKj* positions of the currently
stored le (i.e., the le length is reduced).

Denition 7.4(Correctness of VDS). *A VDS scheme* VDS *is* correct *if for all honestly gen-*
*erated parameters* (pp*;*<sub>0</sub>*;*st₀) Bootstrap(1 ) *and any storage node’s local view* (*;n;* st*;I;*F<sub>I</sub>) *that*
*is valid, the following conditions hold.*

$$
(\mathfrak{p p},\delta_{0},\mathfrak{s t}_{0})\leftarrow\mathsf{B o o t s t r p p}(1^{\lambda})
$$

$$
(\delta,n,\mathsf{s t},I,\mathsf{F}_{I})
$$

0
Update Correctness. *For any update* (op*;*) *that is admissible for* (*n;I;*F<sub>I</sub>) *and for any* (*;n⁰;*
<sup>0</sup>J
st⁰*;J;*F*;*) StrgNode*:* PushUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;*)*:*

$$
(mathsf o o p,\varDelta)
$$

$$
(n,I,\mathsf{F}_{I})
$$

$$
(\delta^{\prime},n^{\prime}
$$

$$
\mathrm {s t} ^ {\prime}, J, \mathrm {F} _ {J} ^ {\prime}, \gamma_ {\Delta}) \leftarrow \operatorname {S t r g}
$$

$$
(\delta,n,\ \ {mathsf s}\mathsf{t},I,\mathsf{F}_{I},\ {\mathsf{o p}},\varDelta)
$$

0 0J
*1.* (pp*;;n⁰;*st⁰*;J;*F) *is valid;*

$$
(\mathsf{p p},\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{I}^{\prime})
$$

0s 0s
*2.for any valid* (*;n;* st<sup>s</sup>*;I*<sup>s</sup>*;* F<sup>I</sup><sup>s</sup>)*, if* (*b*<sub>s</sub>*;*<sup>s0</sup>*;n⁰;*st*;I*<sup>s0</sup>*;* F) StrgNode*:* ApplyUpdate(*;n;* st<sub>s</sub>*;I*<sub>s</sub>*;* F<sub>I</sub><sub>s</sub>*;*op*;*
0 0s 0s 0s 0s
*;*) *then we have: b*<sub>s</sub>= 1*,*<sub>s0</sub>=*, n* = *n⁰, and* (<sub>s0</sub>*;n;*st*;I*<sub>s0</sub>*;* F) *is valid;*
0
*3.if* (*b*<sub>c</sub>*;*<sub>c0</sub>) ClntNode*:* ApplyUpdate(*;*op*;;*)*, then*<sub>c0</sub>= *and b*<sub>c</sub>= 1*.*

$$
\left(\delta , n, \mathrm {s t} _ {s}, I _ {s}, \mathrm {F} _ {I _ {s}}\right), i f \left(b _ {s}, \delta_ {s} ^ {\prime}, n ^ {\prime}, \mathrm {s t} _ {s} ^ {\prime}, I _ {s} ^ {\prime}, \mathrm {F} _ {s} ^ {\prime}\right) \leftarrow \operatorname {S t r g N o d e}. \operatorname {A p p l y U p d a t e} \left(\delta , n, \mathrm {s t} _ {s}, I _ {s}, \mathrm {F} _ {I _ {s}}, \mathrm {o p},\right.
$$

$$
\varDelta,Y_{\varDelta})
$$

$$
b_{s}=1,\,\delta_{s}^{\prime}=\delta^{\prime},\,n_{s}^{\prime}=n^{\prime}
$$

$$
\boldsymbol{\cdot}(\delta,\mathsf{o p},\varDelta,\varUpsilon_{\varDelta})
$$

$$
\delta_{c}^{\prime}=\delta^{\prime}
$$

$$
b_{c}=1
$$

Add-Storage Correctness. *For any* (*Q;*F<sub>Q</sub>*;*<sub>Q</sub>) *such that*

$$
(Q,\mathsf{F}_{Q},\pi_{Q})
$$

ClntNode*:* VerRetrieve(*;Q;*F*Q;*<sub>Q</sub>) = 1*, if* (st⁰*;J;*F<sub>J</sub>) StrgNode*:* AddStorage(*;*st*;I;*F*;Q;*F<sub>Q</sub>*;*<sub>Q</sub>)
*then* (*;n;* st⁰*;J;*F<sub>J</sub>) *is valid.*

$$
(\delta,Q,\mathsf{F}_{Q},\pi_{Q})\:=\:1,\:\:\mathit{i f}\:(\mathsf{s t}^{\prime},J,\mathsf{F}_{J})\:\leftarrow\:\mathsf{S t r}
$$

$$
(\delta,n,\mathsf{s t}^{\prime},J,\mathsf{F}_{J})
$$

$$
K\subseteq I,
$$

Remove-Storage Correctness. *For any K I,*

*if* (st⁰*;J;*F<sub>J</sub>) StrgNode*:* RmvStorage(*;*st*;I;*F*;K*) *then* (*;n;* st⁰*;J;*F<sub>J</sub>) *is valid.*

$$
(\delta,n,\mathsf{s t}^{\prime},J,\mathsf{F}_{J})
$$

$$
J\subseteq I,\,i f\left(\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F\}}_{J},\mathsf{\check{T}}_{J}\right)
$$

0
Create Correctness. *For any J I, if* (*;n⁰;*st⁰*;J;*F<sub>J</sub>*;*<sub>J</sub>) *is output of*

$$
\mathsf{r o m}(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},J)
$$

$$
|J|,\,\delta^{\prime\prime}=\delta^{\prime}
$$

00
StrgNode*:* CreateFrom(*;n;* st*;I;*F<sub>I</sub>*;J*) *and* (*b;*) ClntNode*:* GetCreate(*;J;*<sub>J</sub>)*, then b* = 1*, n⁰* =
00 0 0
*jJ j,* = *and* (pp*;;n⁰;*st⁰*;J;*F<sub>J</sub>) *is valid.*

$$
(b,\delta^{\prime\prime})\:\leftarrow\:\mathsf{C I n t N o d e}.\mathsf{G e t C r e a t e}(\delta,J,\varUpsilon_{J})
$$

$$
n^{\prime}=
$$

$$
(\mathsf{p p},\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{J})
$$

Aggregate Correctness. *For any pair of triples* (*I;*F<sub>I</sub>*;*<sub>I</sub>) *and* (*J;*F<sub>J</sub>*;*<sub>J</sub>) *such that*

$$
(I,\mathsf{F}_{I},\pi_{I})
$$

$$
(J,\mathsf{F}_{J},\pi_{J})
$$

ClntNode: VerRetrieve(;*I*;F*I*;I) = 1 and ClntNode: VerRetrieve(;*J*;F*J*;J) = 1,
if<sub>K</sub>AggregateCerticates((*I;*F<sub>I</sub>*;*<sub>I</sub>)*;* (*J;*F<sub>J</sub>*;*<sub>J</sub>)) *and* (*K;*F<sub>K</sub>) := (*I;*F<sub>I</sub>) *[* (*J;*F<sub>J</sub>)*, then*
ClntNode*:* VerRetrieve(*;K;*F<sub>K</sub>*;*<sub>K</sub>) = 1*.*

$$
\left\{\left(\delta,I,\mathsf{F}_{I},\pi_{I}\right)=1\ \ \right.
$$

$$
\sharp(\delta,J,\mathsf{F}_{J},\pi_{J})=1
$$

$$
{{}^{}}\,\pi_{K}\leftarrow{\sf A g g r e g a t e}
$$

$$
\mathsf{s}\big((I,\mathsf{F}_{I},\pi_{I}),(J,\mathsf{F}_{J},\pi_{J})\big)
$$

$$
\left(K,\mathsf{F}_{K}\right):=\left(I,\mathsf{F}_{I}\right)\cup\left(J,\mathsf{F}_{J}\right)
$$

$$
\left(\delta,K,\mathsf{F}_{K},\pi_{K}\right)=1
$$

---

*Remark 7.3(Relation with Updatable VCs).* Our notion of VDS is very close to the notion of
updatable VCs [CF13] extended to support subvector openings and incremental aggregation. On
a syntactical level, in comparison to updatable VCs, our VDS notion makes more evident the
decentralized nature of the primitive, which is reected in the denition of our algorithms where
for example it is clear that no one ever needs to store/know the entire le. One major dierence
is that in VDS the public parameters must necessarily be *short* since no node can run linearly in
the size of the le (nor it can aord such storage), whereas in VCs this may not be necessarily
the case. Another dierence is that in updatable VCs [CF13] updates can be received without any
hint, which is instead the case in VDS. Finally, it is interesting to note that, as of today, there
exists no VC scheme that is updatable, incrementally aggregatable and with subvector openings,
that enjoys short parameters and has the required short verication time. So, in a way, our two
VDS realizations show how to bypass this barrier of updatable VC by moving to a slightly dierent
(and practically motivated) model.

## 7.3 Security of VDS

In this section we dene the security of VDS schemes. Intuitively speaking, we require that a
malicious storage node (or a coalition of them) cannot convince a client of a false data block in a
retrieval query. To formalize this, we let the adversary fully choose a *history* of the VDS system
that starts from the empty state and consists of a sequence of steps, where each step is either an
update (addition, deletion, modication) or a creation (from an existing le) and is accompanied
by an advice. A client’s digest is updated following such history and using the adversarial advices,
and similarly one gets a le F corresponding to such digest. At this point, the adversary’s goal is
to provide a tuple (*Q;*<sub>Q</sub>*;* F) that is accepted by a client with digest but where F 6= F<sub>Q</sub>.
Q Q

$$
\mathsf{F}_{Q}^{*}\neq\mathsf{F}_{Q}
$$

$$
(Q,\pi_{Q},\mathsf{F}_{Q}^{*})
$$

Denition 7.5(History for Decentralized Storage). *Let* VDS *be a veriable decentralized*
i i i i
*storage scheme. A history for* VDS *is a sequence H* = (op*;;*)<sup>i</sup>2<sup>[</sup><sup>‘</sup><sup>]</sup>*of tuples, where* op *is either*
i
*in f*mod*;*add*;*del*g (i.e., it is an update of the le), or* op = cfrom *(i.e., it is the creation of a new*
i
*le related to the current one), in which case is a set of indices. In order to dene valid histories*
*we dene the function* EvalHistory(pp*;*<sub>0</sub>*;*st₀*; H*) *as follows*

<u>EvalHistory(pp</u><u>;</u><sub>0</sub><u>;</u><u>st₀</u><u>; H</u><u>)</u>
F₀ *;*; *b* 1
for *i 2* [*‘*]
i i
F*i* FileChange(F*i* 1*;*op*;*)
<sup>i</sup>
<sup>i</sup>f op *2f*mod*;*add*;*del*g* then

<u>FileChange(F</u><u>;</u><u>op</u><u>;</u><u>)</u>
0K
if op *2f*mod*;*add*g parse* = (*K;*F)
0i
*8i 2 K* : FiF;*8i 2* [*j*F*j*] *n K* : FiF*i;*
elseif op = del *parse* = *K*
*8i 2* [*j*F*j*] *n K* : FiF*i;*

i i <sup>i</sup> else<sup>i</sup>f op = cfrom *parse* = *K*
(*bi;i*) ClntNode*:* ApplyUpdate( *i* 1*;*op*;;*)

*i*
else*i*f op = cfrom then
*i* i
(*b*i*;*i) ClntNode*:* GetCreate( i 1*;;*)
end*i*f
*b b ^ bi*
endfor
return (*b;‘;* F*‘*)

*8i 2 K* : FiF*i;*
endif return F

*We say that a history H is valid w.r.t. public parameters* pp *and initial digest*<sub>0</sub>*and state* st₀
*if* EvalHistory(pp*;*<sub>0</sub>*;*st₀*; H*) *returns bit b* = 1*.*

$$
\mathcal{H}=(\mathfrak{o p}^{i},\varDelta^{i},\varUpsilon_{\varDelta}^{i})_{i\in[\ell]}
$$

$$
\mathbf{o p}^{i}
$$

$$
{\mathsf{o p p}}^{i}=
$$

$$
\Delta^{i}
$$

$$
(\mathsf{p p},\delta_{0},\mathsf{s t}_{0},\mathcal{H})
$$

$$
\mathsf{F}_{0}\leftarrow\emptyset;b\leftarrow1
$$

$$
(\mathsf{F},{\mathsf{o p}},\varDelta)
$$

$$
i\in[\ell]
$$

$$
\mathsf{o p}\in\left\{\mathsf{m o d},\mathsf{a d d}\right\}\mathrm{~p a r s e~}\varDelta=(K,\mathsf{F}_{K}^{\prime})
$$

$$
\mathsf{F}_{i}\leftarrow\mathsf{F i l e C h a n g e}(\mathsf{F}_{i-1},\mathfrak{o p}^{i},\varDelta^{i})
$$

$$
\forall i\in K:\mathsf{F}_{i}^{*}\leftarrow\mathsf{F}_{i}^{\prime};\forall i\in[[\mathsf{F}]]\setminus K:\mathsf{F}_{i}^{*}\leftarrow\mathsf{F}_{i},
$$

$$
\mathsf{o p}^{i}\in\{\mathsf{m o d},\mathsf{a d d},\mathsf{d e l}\}
$$

$$
\varDelta=K
$$

$$
\forall i\in[\mathsf{F}]\setminus K:\mathsf{F}_{i}^{*}\leftarrow\mathsf{F}_{i},
$$

$$
(\delta_{i-1},\mathsf{o p}^{i},\varDelta^{i},\varUpsilon_{\varDelta}^{i})
$$

$$
\forall i\in K:\mathsf{F}_{i}^{*}\leftarrow\mathsf{F}_{i},
$$

$$
(b_{i},\delta_{i})\leftarrow\mathsf{C l n t N o d e.G e t C r e a t e}(\delta_{i-1},\varDelta^{i},\varUpsilon_{\varDelta}^{i})
$$

$$
\ {\sf F}^{*}
$$

$$
b\gets b\land b_{i}
$$

$$
(b,\delta_{\ell},\mathsf{F}_{\ell})
$$

$$
\delta_{0}
$$

$$
{\sf S}{\sf t}_{0}
$$

$$
(\mathsf{p p},\delta_{0},\mathsf{s t}_{0},\mathcal{H})
$$

---

Denition 7.6(Security for Veriable Decentralized Storage). *Consider the experiment*
A
VDS*-*Security<sup>VDS</sup>() *below. Then we say that a VDS scheme* VDS *is secure if for all PPT A we*
A
*have* Pr[VDS*-*Security<sub>VDS</sub>() = 1] *2* negl()*.*

$$
\operatorname{P r}[\sf{V D S\ S e e c u r i t y}_{\sf{D S}}^{\cal{A}}(\lambda)=1]\in\sf{n e g l}(\lambda)
$$

A
<u>VDS-Security</u><sub>VDS</sub><u>()</u>
(pp*;*0*;*st₀) Bootstrap(1)
(*H;Q;*FQ*;*) *A* (pp*;*0*;*st₀)
(*b;;* F) EvalHistory(pp*;*0*;*st₀*; H*)
*b b ^* FQ6= F*Q^*
ClntNode*:* VerRetrieve(pp*;;Q;*F<sub>Q</sub>*;*)
return *b*

$$
b\gets b\land\mathsf{F}_{Q}^{*}\neq\mathsf{F}_{Q}\land
$$

VDS Proof of Storage. As an additional security mechanism we consider the possibility to
ensure a client that a given le is stored by the network at a certain point of time without having
to retrieve it. To this end, we extend the VDS notion to provide a *proof of storage* mechanism in
+
the form of a proof of retrievability (PoR) [JK07] or a proof of data possession (PDP) [ABC 07].
Our proof of storage model for VDS is such that proofs are publicly veriable given the le’s digest.
Also, in order to support the decentralized and open nature of DSNs, the entire proof mechanism
should not use any secret, and proofs should be generatable in a distributed fashion (this is a main
distinguishing feature compared to existing PoRs/PDPs) while staying compact. The formalization
of this property is in AppendixD.

$$
[\mathrm{A B C}^{+}07]
$$

## 8 Our Realizations of VDS in Hidden-Order Groups

In this section, we present two constructions of VDS that work in hidden-order groups. The two
schemes are presented in Sections8.1and8.2respectively, and we discuss a comparison in Section
8.3.

## 8.1 Our First VDS Construction

We build our rst scheme by extending the techniques used to construct our rst SVC scheme
from Section5.1. In particular, we start from a modied version of our SVC that achieves a weaker
position binding property (in which the adversary reveals the full vector, yet its goal is to nd two
distinct openings for the same position) and then show how to make this scheme dynamic (i.e., to
change vector values or its length) and fully distributed (i.e., updates can be performed without
knowing the entire vector).

Preliminaries. We begin by describing the simplied version of our SVC, considering the case of
*k* = 1, which ts best our VDS construction, regarding eciency and communication complexity.
For convenience of the reader we describe again shortly the algorithms and functions (and variations
of them) from sections5.1and5.1that are used in the scheme (for more details we refer to the
corresponding section):

{ PrimeGen, a deterministic collision resistant function that maps integers to primes.

{ PartndPrimeProd(*I;~y*)*!* (*a*<sup>I</sup>*;b*<sup>I</sup>): given a set of indices *I* = *fi₁;:::;i*<sup>m</sup>*g* [*n*] and a vector
Q Q
m m <sub>m</sub>
*~y 2M*, the function computes (*a*<sub>I</sub>*;b*<sub>I</sub>) := *p*<sub>i</sub>; p<sub>i</sub>, where *p*<sub>i</sub>PrimeGen(*i*)
l=1: yl=0 l l=1: yl=1 l
for all *i 2* N.

$$
\ I,\vec{y}\,\rightarrow\,(a_{I},b_{I})
$$

$$
I\,=\,\left\{i_{1},\ldots,i_{m}\right\}\,\subseteq\,[n]
$$

$$
\vec{y}\in\mathcal{M}^{m}
$$

$$
(left\ a_{I},b_{I}):=(\prod_{l=1:y_{l}=0}^{m}p_{i_{l}},\prod_{l=1:y_{l}=1}^{m}p_{i_{l}})
$$

$$
p_{i}\gets\mathsf{P r i m e G e n}(i)
$$

$$
i\in\mathbb{N}
$$

---

VC*:* Com⁰(crs*;~v*)*! C* compute (*a;b*) PartndPrimeProd([*n*]*;~v*), where *n  j~vj*; next compute *A* =
<sup>a</sup> b?
*g₀* and *B* = *g₁*. Return *C* := (*C;n*) := ((*A;B*)*; j~vj*).

$$
\ {{{\sf~t e t u p}}({{\sf^{\lambda}}},\{0,1\}^{k})}\to{{\sf r r s}}\;:=({{\mathbb G}},g,g_{0},g_{1},{{{\sf P r P m e e e n}}})
$$

$$
.mathsf C C o^{{\prime}}(\mathsf{c r s},{\vec{v}})\to C
$$

$$
n\gets|\vec{v}|.
$$

$$
(a,b)\leftarrow\mathsf{P a t n d P r n n e P o d d}([n],\vec{v})
$$

$$
A=
$$

$$
g_{0}^{a}
$$

$$
B=g_{1}^{b}
$$

$$
\mathcal{C}:=\left(\mathcal{C}^{\star},n\right):=\left((A,B),\left|\vec{v}\right|\right)
$$

VC*:* Ver⁰(crs*;C;I;~y;*<sub>I</sub>)*! b* compute (*a*<sup>I</sup>*;b*<sub>I</sub>) PartndPrimeProd(*I;~y*), and then parse<sub>I</sub>:= (<sub>I</sub>*;*<sub>I</sub>)
aIbI
and return *b* ( = *A*) *^* ( = *B*).
<sub>I</sub> <sub>I</sub>

$$
(a_{I},b_{I})\leftarrow\sf P a I t n d P r m e P r o d(I,\vec{y})
$$

$$
\pi_ {I} := \left(\Gamma_ {I}, \Delta_ {I}\right)
$$

VC*:* Disagg⁰(crs*;I;~v*<sub>I</sub>*;*<sub>I</sub>*;K*)*!*<sub>K</sub>let *L* := *I n K*, and *~v*<sub>L</sub>be the subvector of *~v*<sub>I</sub>at positions in
*L*. Then compute *a*<sub>L</sub>*;b*<sub>L</sub>PartndPrimeProd(*L;~v*<sub>L</sub>) parse<sub>I</sub>:= (<sub>I</sub>*;*<sub>I</sub>) and set (<sub>K</sub>*;*<sub>K</sub>)
<sub>a</sub><sub>L</sub><sub>b</sub><sub>L</sub>
(*;*). Return<sub>K</sub>(<sub>K</sub>*;*<sub>K</sub>).
I I
VC: Agg⁰(crs; (I;~v;); (J;~v;))! :

$$
b\gets\big(\ \ Gamma_{I}^{a_{I}}=A\big)\wedge\big(\Delta_{I}^{b_{I}}=B\big)
$$

$$
\mathrm {V C}. \operatorname {D i s a g g} ^ {\prime} (\mathrm {c r s}, I, \vec {v} _ {I}, \pi_ {I}, K) \rightarrow \pi_ {K} \text {l e t} L := I \setminus K
$$

$$
{\vec{v}}_{L}
$$

$$
\ {\vec{v}}_{I}
$$

$$
L.
$$

$$
a_{L},b_{L}\gets
$$

$$
(L,\vec{v}_{L})
$$

$$
\pi_{I}:=\,(\varGamma_{I},\varDelta_{I})
$$

$$
(\varGamma_{K},\varDelta_{K})\leftarrow
$$

$$
(\varGamma_{I}^{a_{L}},\varDelta_{I}^{b_{L}})
$$

$$
\pi_{K}\leftarrow(\varGamma_{K},\varDelta_{K})
$$

$$
\ .{\sf A g g}^{\prime}({\sf c r s},(I,\vec{v}_{I},\pi_{I}),(J,\vec{v}_{J},\pi_{J}))\to\pi_{K}
$$

1.Let *L* := *I \J*. If *L 6*=*;*, set *I⁰* := *I nL* and computeI*0* VC*:* Disagg(crs*;I;~v*I*;*I*;I⁰*); otherwise
letI*0* =I.

$$
L:=I\cap J
$$

$$
L\neq\emptyset
$$

$$
I^{\prime}\!:=I\backslash\!L
$$

$$
\pi_{I^{\prime}}\gets V\ .mathsf C i D s a g e(\mathsf{c r s},I,\vec{v}_{I},\pi_{I},I^{\prime})
$$

$$
\pi_{I^{\prime}}=\pi_{I}
$$

$$
(I,\vec{v}_{I^{\prime}})
$$

2.Compute (*a*<sub>I</sub>*0;b*<sub>I</sub>*0*) PartndPrimeProd(*I;~v*<sub>I</sub>*0*) and *fa*<sub>J</sub>*;b*<sub>J</sub>*g* PartndPrimeProd(*J;~v*J).

$$
\{a_{J},b_{J}\}\leftarrow\mathsf{P a r t n d P r i m e P r o d}(J,\vec{v}_{J})
$$

3.Parse<sub>I</sub>*0* := (<sub>I</sub>*0;*<sub>I</sub>*0*),<sub>J</sub>:= (<sub>J</sub>*;*<sub>J</sub>) and computeKShamirTrick(<sub>I</sub>*0;*<sub>J</sub>*;a*<sub>I</sub>*0;a*<sub>J</sub>) and
*K*ShamirTrick(<sub>I</sub>*0;*<sub>J</sub>*;b*<sub>I</sub>*0;b*<sub>J</sub>)

$$
\pi_{I^{\prime}}:=(\varGamma_{I^{\prime}},\varDelta_{I^{\prime}}),\pi_{J}:=(\varGamma_{J},\varDelta_{J})
$$

$$
\varGamma_{K}\leftarrow\mathbf{S h a m i r T r i c k}(\varGamma_{I^{\prime}},\varGamma_{J},a_{I^{\prime}},a_{J})
$$

$$
(\varDelta_{I^{\prime}},\varDelta_{J},b_{I^{\prime}},b_{J})
$$

$$
\pi_{K}\leftarrow(big var\_Gamma K,\varDelta_{K}
$$

4.Return<sub>K</sub>(<sub>K</sub>*;*<sub>K</sub>)

Finally, let PoKSubV⁰ be the same protocol as in section6but adjusted according to the above
algorithms. That is the CRS of is simply crs instead of the two specialized CRSs. Furthermore,
since *C* is not accompanied with PoProd₂ the verier does not have to check the validity of it. The
rest of the protocol remains the same and the underlying relation is:

$$
\mathsf{P o P r o d}_{2}
$$

$$
\begin{aligned}{R_{\mathsf{P o k S u b V}^{\prime}}=\{(}&{{}\ C,C^{\prime},I),(\vec{v}_{I},\pi_{I},\pi_{I}^{\prime})\ :\ \ \ {\sf V C,N e r^{\prime}}(\mathsf{c r s},C,I,\vec{v}_{I},\pi_{I})=1}\\ {}&{{}\wedge\ \ {\sf V C,V e r^{\prime}}(\mathsf{c r s s},C^{\prime},I,\vec{v}_{I},\pi_{I}^{\prime})=1\wedge|\vec{v}_{I}|=n^{\prime}\}}\\ \end{aligned}
$$

Finally, we note that for simplicity in the following we abuse the notation for Shamir’s trick
0I a0b0
by writing e.g. (*;*) ShamirTrick(<sub>I</sub>*;*<sub>K</sub>*;* F<sub>I</sub>; F<sub>K</sub>)<sub>K</sub>*;* Sh<sup>a</sup>mirTrick(I;K; F<sub>I</sub>*;* F<sub>K</sub>)*K*
<sub>I</sub><sup>0</sup>
instead of writing, more precisely,

$$
(\varGamma_{\}^{\prime},\varDelta_{\ I}^{\prime})\;\leftarrow\;(\mathbf{S h a m i r T r i c k}(\varGamma_{I},\varGamma_{K},\mathsf{F}_{I},\mathsf{F}_{K})^{a_{K}^{\prime}}}
$$

$$
\ \cdot
$$

$$
\left(\Gamma_ {I} ^ {\prime}, \Delta_ {I} ^ {\prime}\right) \leftarrow \left(\mathbf {S h a m i r T rick} \left(\Gamma_ {I}, \Gamma_ {K}, a _ {I}, a _ {K}\right) ^ {a _ {K} ^ {\prime}}, \mathbf {S h a m i r T rick} \left(\Delta_ {I}, \Delta_ {K}, b _ {I}, b _ {K}\right) ^ {b _ {K} ^ {\prime}}\right).
$$

21
Our scheme VDS₁. The algorithms of the VDS scheme VDS₁ are the following:

$$
\mathsf{V D S_{1}}
$$

$$
\mathsf{V D S_{1}}
$$

k
Bootstrap(1 )*!* (pp*;*<sub>0</sub>*;n₀;*st₀)Execute VC*:* Setup(1*; f*0*;* 1*g*) and get pp := (G*;g;g₀;g₁;*PrimeGen).
Set *n₀* 0,<sub>0</sub>((*g₀;g₁*)*;n₀*) and st₀ (*g₀;g₁*).

$$
{\mathsf{r a p}}(1^{\lambda})\to({\mathsf{p p}},\delta_{0},n_{0},{\mathsf{s t}}_{0})
$$

$$
\mathsf{V C.S e t u p}(1^{\lambda},\{0,1\}^{k})
$$

$$
{\mathfrak{p p}}:=({\mathfrak{G}},{\mathfrak{g}},{\mathfrak{g}}_{0},{\mathfrak{g}}_{1},{\sf{P r i m e G e n}})
$$

$$
n_{0}\leftarrow0,\delta_{0}\leftarrow((g_{0},g_{1}),n_{0})
$$

$$
\mathsf{s t}_{0}\leftarrow(g_{0},g_{1})
$$

The algorithms for storage nodes are:

StrgNode*:* AddStorage(*;n;* st*;I;*F<sub>I</sub>*;Q;*F<sub>Q</sub>*;*<sub>Q</sub>)*!* (st⁰*;J;*F<sub>J</sub>)If *I* =*;* then set st⁰<sub>Q</sub>, otherwise
st :=<sub>I</sub>. Then compute st⁰ VC*:* Agg⁰(pp*;* (*I;*F<sub>I</sub>*;*<sub>I</sub>)*;* (*Q;*F<sub>Q</sub>*;*<sub>Q</sub>)). The computation of *J* and F<sub>J</sub>
is straightforward: (*J;*F<sub>J</sub>) (*I [ Q;*F<sub>I</sub>*[* F<sub>Q</sub>).

$$
\ \cdot
$$

$$
{mathfrak s t t}^{\prime}\leftarrow\pi_{Q}
$$

$$
\mathsf{s t}:=\pi_{I}
$$

$$
I=\emptyset
$$

$$
\mathrm {s} ^ {\prime} \leftarrow \mathrm {V C}. \mathrm {A g g} ^ {\prime} (\mathrm {p p}, (I, \mathrm {F} _ {I}, \pi_ {I}) , (Q, \mathrm {F} _ {Q}, \pi_ {Q}))
$$

$$
(J,\mathsf{F}_{J})\leftarrow(I\cup Q,\mathsf{F}_{I}\cup\mathsf{F}_{Q})
$$

$$
\mathrm {F} _ {J}
$$

$$
J\gets\,I\setminus K
$$

StrgNode*:* RmvStorage(*;n;* st*;I;*F<sub>I</sub>*;K*)*!* (st⁰*;J;*F<sub>J</sub>)Compute *J I n K* and the corresponding
F<sub>J</sub>. Then<sub>J</sub>VC*:* Disagg⁰(pp*;I;*F<sub>I</sub>*;*<sub>I</sub>*;J*) and set st⁰<sub>J</sub>.

$$
\digamma J
$$

$$
\pi_{J}\gets V\ .mathsf.D i s a\mathsf{g o}^{I}(\mathsf{p p},I,\mathsf{F}_{I},\pi_{I},J)
$$

$$
smathfrak{t}^{\prime}\leftarrow\pi_{J}
$$

<sup>21</sup>
Since the scheme has several parts in common with the above VC algorithms, we use those algorithms as shorthands
in the description.

---

0 0
StrgNode*:* CreateFrom(*;n;* st*;I;*F<sub>I</sub>*;J*)*!* (*;n⁰;*st⁰*;J;*F<sub>J</sub>*;*<sub>J</sub>)The new digest of F<sub>J</sub>is computed
0
with the commitment algorithm VC*:* Com⁰(pp*;* F<sub>J</sub>). The new length gets *n⁰ j J j*. The
previous local state is st =<sub>I</sub>and the new local state gets st⁰ VC*:* Disagg(pp*;I;*F<sub>I</sub>*;*<sub>I</sub>*;J*).
Finally, forJit computes an argument of knowledge of subvector (see section6), *0*
PoKSubV
0 0
PoKSubV⁰*:* P(pp*;* (*;;J*)*;* (*~v*<sub>J</sub>*;*<sub>I</sub>)) and sets<sub>J</sub>(*;* <sub>0</sub>).
<sub>PoKSubV</sub>

$$
(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},J)\to(\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{J},\varUpsilon_{J})
$$

$$
\delta^{\prime}
$$

$$
\mathrm {F} _ {J}
$$

$$
\delta^{\prime}\leftarrow\mathsf{V C.C o m^{\prime}(p p,F_{J})}
$$

$$
\boldsymbol{n}^{\prime}\gets|\boldsymbol{J}|
$$

$$
{\mathfrak{s t}}\,=\,\pi_{I}
$$

$$
\mathsf{s t}^{\prime}\;\leftarrow\;\mathsf{V C}D i s a g g(\mathsf{p p},I,\mathsf{F}_{I},\pi_{I},J)
$$

$$
T_{J}
$$

$$
\pi_{\mathsf{P o K S u b V}^{\prime}}\xleftarrow{{}}
$$

$$
\varUpsilon_{J}\gets(\delta^{\prime},\pi_{\mathsf{P o K S u b V}^{\prime}})
$$

0 0J
StrgNode*:* PushUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;*)*!* (*;n⁰;*st⁰*;J;*F*;*)The algorithm works according to
the type of update operation op:

$$
.\mathsf{P u s h U p d a t e}(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},\mathsf{o p},\varDelta)\to(\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{J}^{\prime},\varUpsilon_{\varDelta})
$$

0K
{ op = mod: parse := (*K;*F) and st :=<sub>I</sub>. Execute<sub>K</sub>VC*:* Disagg⁰(pp*;I;*F<sub>I</sub>*;*<sub>I</sub>*;K*)
0K 0K 0K 0
and parse<sub>K</sub>:= (<sub>K</sub>*;*<sub>K</sub>). Then compute (*a;b*) PartndPrimeProd(*K;*F) and set
a<sup>0</sup>b0
K <sup>K</sup> 0 <sup>0</sup>
((*;*)*;n*) (i.e., *n* = *n* remains the same). st is the new opening of *I*,<sup>I</sup>, which
K K I0
is the same so the local state does not change st⁰ st. Since it is a modication operation
0J 0I 0I 0I 0K
(*J;*F) (*I;*F), where F is simply the modied le F = (F<sub>I</sub>*n* F<sub>K</sub>) *[* F. Finally, set
(F<sub>K</sub>*;*<sub>K</sub>).

$$
-{\mathrm{\ o}}{\mathrm{\,,}}{=\mathrm{\ m o d}}
$$

$$
\varDelta\,:=\,(K,\mathsf{F}_{K}^{\prime})
$$

$$
:=\ \pi_{I}
$$

$$
\pi_{K}\;\leftarrow\;\mathsf{V C}.\mathsf{D i s a g g}^{\prime}(\mathsf{p p},I,\mathsf{F}_{I},\pi_{I},K)
$$

$$
\pi_ {K} := \left(\Gamma_ {K}, \Delta_ {K}\right)
$$

$$
(K,\mathsf{F}_{K}^{\prime})
$$

$$
\delta^{\prime}\leftarrow
$$

$$
((\varGamma_{K}^{a_{K}^{\prime}},\varDelta_{K}^{b_{K}^{\prime}}),n)\ (\mathrm{i.e.,,}\,\,n^{\prime}=\,n
$$

$$
s mathsf t{{'}}
$$

$$
I,\,\pi_{I}^{\prime}\leftarrow\pi_{I}
$$

$$
\ {mathfrak s t}^{\prime}\leftarrow{\mathfrak s t}
$$

$$
(J,\mathsf{F}_{J}^{\prime})\leftarrow(I,\mathsf{F}_{I}^{\prime})
$$

$$
(\mathsf{F}_{K},\pi_{K})
$$

$$
{\mathsf{F}}_{I}^{\prime}=({\mathsf{F}}_{I}\setminus{\mathsf{F}}_{K})\cup{\mathsf{F}}_{K}^{\prime}
$$

$$
\mathrm {F} _ {I} ^ {\prime}
$$

$$
T_{\varDelta}\leftarrow
$$

0K
{ op = add: parse := (*K;*F), st :=<sup>I</sup>, and the old digest := ((*A;B*)*;n*). Then compute
0K 0K 0K 0 a0b00 0
(*a;b*) PartndPrimeProd(*K;*F) and the new digest gets ((*A*<sub>K</sub>*;B*<sub>K</sub>)*;n*) where *n*
<sub>0</sub>J 0
*n* + *jKj*. The new state refers to the new le subportion (*J;*F) (*I [ K;*F<sub>I</sub>*[* F<sub>K</sub>), st⁰ :=,
<sub>J</sub>
<sup>0</sup>
and is the same as the old one st⁰ st since<sub>I</sub>=. Finally, set?.
J

$$
\varDelta:=(K,\mathsf{F}_{K}^{\prime})
$$

$$
:=\,\pi_{I}
$$

$$
\delta:=((A,B),n)
$$

$$
(a_{K}^{\prime},b_{K}^{\prime})\leftarrow\mathsf{P a r t n d P r i m e P r o d}(K,\mathsf{F}_{K}^{\prime})
$$

$$
\delta^{\prime}\leftarrow((A^{a_{K}^{\prime}},B^{b_{K}^{\prime}}),n^{\prime})
$$

$$
n^{\prime}\gets
$$

$$
n+|K|
$$

$$
(J,\mathsf{F}_{,J}^{\prime})\;\leftarrow\;(I\cup K,\mathsf{F}_{,I}\cup\mathsf{F}_{K}),\;\mathsf{s t}^{\prime}:=\pi_{,J}^{\prime},
$$

$$
\pi_{I}=\pi_{,J}^{\prime}
$$

$$
T_{\Delta}\gets\otimes
$$

$$
\mathsf{s t}^{\prime}\gets\mathsf{s t}
$$

{ op = del: parse := *K* and st :=<sub>I</sub>. Execute<sub>K</sub>VC*:* Disagg⁰(pp*;I;*F<sub>I</sub>*;*<sub>I</sub>*;K*) and parse
0
*K*:= (K*;*K). Then the new digest is ((K*;*K)*;n⁰*) where *n⁰ n jKj*. The new
0J
state refers to the new le subportion (*J;*F) (*I n K;*F<sub>I</sub>*n* F<sub>K</sub>)) and is the same as the old one
0
st⁰ st since<sub>I</sub>=. Finally set (F<sub>K</sub>*;*<sub>K</sub>).
J

$$
-\circ!,
$$

$$
\varDelta:=K
$$

$$
:=\ \pi_{I}
$$

$$
\pi_{K}\leftarrow\mathsf{V C.D i s a g g}^{\prime}(\mathsf{p p},I,\mathsf{F}_{I},\pi_{I},K)
$$

$$
\pi_{K}:=\big(\varGamma_{K},\varDelta_{K}\big)
$$

$$
\boldsymbol{\delta}^{\prime}\gets((\boldsymbol{\Gamma}_{K},\boldsymbol{\Delta}_{K}),n^{\prime})
$$

$$
n^{\prime}\leftarrow n-|K|
$$

$$
(J,\mathsf{F}_{J}^{\prime})\leftarrow(I\setminus K,\mathsf{F}_{I}\setminus\mathsf{F}_{K}),
$$

$$
\mathsf{s t}^{\prime}\leftarrow\mathsf{s t}
$$

$$
\pi_{I}=\pi_{J}^{\prime}
$$

$$
\varUpsilon_{\varDelta}\gets\left(\mathsf{F}_{K},\pi_{K}\right)
$$

0 0J
StrgNode*:* ApplyUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;;*)*!* (*b;;n⁰;*st⁰*;J;*F)Again, it works according to
the type of update operation op:

0K
{ op = mod: parse := (*K;*F), st :=<sub>I</sub>and := (F<sub>K</sub>*;*<sub>K</sub>). Compute acceptance bit
0K 0K
*b* VC*:* Ver⁰(pp*;;K;*F<sub>K</sub>*;*<sub>K</sub>). Then, if *b* = 1 parse<sub>K</sub>:= (<sub>K</sub>*;*<sub>K</sub>), compute (*a;b*)
a0b0
<sup>0K</sup> 0 K K 0 0
PartndPrimeProd(*K;*F) and set ((*;*)*;n*) where *n n*. It is clear that in the case
K K
0J 0I 0I 0I 0K
of a modify operation (*J;*F) (*I;*F), where F is simply the modied le F = (F<sub>I</sub>*n* F<sub>K</sub>) *[* F.
For the new local state st⁰ that we discern three cases:
*I\K* =*;*: then compute

$$
\varDelta\,:=\,(K,\mathsf{F}_{K}^{\prime})
$$

$$
:=\ \pi_{I}
$$

$$
\gamma_ {\Delta} := \left(\mathrm {F} _ {K}, \pi_ {K}\right)
$$

$$
b\,=\,1
$$

$$
b\gets\mathsf{V C.V e r^{\prime}}(\mathsf{p p},\emptyset,K,\mathsf{F}_{K},\pi_{K})
$$

$$
\pi_{K}\,:=\,\big(\varGamma_{K},\varDelta_{K}\big)
$$

$$
(a_{K}^{\prime},b_{K}^{\prime})\leftarrow
$$

$$
(K,\mathsf{F}_{K}^{\prime})
$$

$$
\delta^{\prime}\gets((\varGamma_{K}^{a_{K}^{\prime}},\varDelta_{K}^{b_{K}^{\prime}}),n^{\prime})
$$

$$
n^{\prime}\gets n
$$

$$
(J,\mathsf{F}_{J}^{\prime})\leftarrow(I,\mathsf{F}_{I}^{\prime})
$$

$$
\ {\sf F^{\prime}}
$$

$$
{\mathsf{F}}_{I}^{\prime}=\big({\mathsf{F}}_{I}\backslash{\mathsf{F}}_{K}\big){\cup}{\mathsf{F}}_{K}^{\prime}
$$

$$
s mathsf{t}^{\prime}
$$

$$
I\cap K=\emptyset:
$$

0I a0b00
(;) ShamirTrick(I;K; FI; FK)K; ShamirTrick(I;K; F<sub>I</sub>; F<sub>K</sub>)<sub>K</sub><sup>a</sup>nd set st
*I*<sup>0</sup>
0 0 <sup>0</sup>
:= (*;*).
<sub>I</sub> I I

$$
(T_{I}^{\prime},\varDelta_{I}^{\prime})\leftarrow
$$

$$
(\varGamma_{I},\varGamma_{K},\mathsf{F}_{I},\mathsf{F}_{K})^{a_{K}^{\prime}}
$$

$$
\left(\varDelta_{I},\varDelta_{K},\mathsf F_{I},\mathsf F_{K})^{b_{K}^{\prime}}\right)
$$

$$
\mathsf{s t^{\prime}\ }leftarrow
$$

$$
\pi_{I}^{\prime}:=(\varGamma_{I}^{\prime},\varDelta_{I}^{\prime})
$$

$$
(\varGamma_{I}^{\prime},\varDelta_{I}^{\prime})\leftarrow(\varGamma_{I},\varDelta_{I})
$$

$$
I\cap K=K
$$

0I 0I
*I\K* = *K*: compute (*;*) (<sub>I</sub>*;*<sub>I</sub>) and set st⁰ := (*;*).
<sub>I0</sub> I0 I0

$$
\mathsf{s t}^{\prime}\leftarrow\pi_{I}^{\prime}:=(\varGamma_{I}^{\prime},\varDelta_{I}^{\prime})
$$

For the case where neither *I\K* =*;* nor *I\K* = *K*, i.e. *I\K* = *L =2fK;;g* we partition *K* as *K* = *L[L* and apply two sequential updates to<sub>I</sub>, one with *L⁰* (s.t. *I\L* =*;*)
0L 0L 0L
and one with *L* (s.t. *I \ L* = *L*). That is, compute (*a;b*) PartndPrimeProd(*L;*F) and then
a0b0
<sup>0I</sup>L L00
(*;*) ShamirTrick(<sub>I</sub>*;*<sub>L</sub>*;* F<sub>I</sub>*;* F<sub>L</sub>); Sh<sup>a</sup>mirTrick(I;*L;* F<sub>I</sub>*;* F<sub>L</sub>). Then (*;*)
<sub>I</sub>0 <sub>I00</sub> I
<sup>0I</sup> 00
(*;*). Finally, set st⁰ (*;*). Essentially, since the case of *I \ L* = *L* doesn’t cause any
I0 I00 I
change to the state, computationally it is as a single update.

$$
I\cap K=\emptyset
$$

$$
I\cap K=L\notin\{K,\emptyset\}
$$

$$
I\cap K=K
$$

$$
K=L\cup\bar{L}
$$

$$
L ^ {\prime} \left(\mathrm {s . t .} I \cap \bar {L} = \emptyset\right)
$$

$$
\pi\ I
$$

$$
L\,{\mathrm{(s.t.}}\,I\ \ \cap L=L
$$

$$
\big(a_{\bar{L}}^{\prime},b_{\bar{L}}^{\prime}\big)\leftarrow\mathsf{P a r t n d P r i m e P r o d}(\bar{L},\mathsf{F}_{\bar{L}}^{\prime})
$$

$$
(T_{I}^{\prime\prime},\varDelta_{I}^{\prime\prime})\xleftarrow{}
$$

$$
\cdot(\varDelta_{I},\varDelta_{\bar{L}},\mathsf F_{I},\mathsf F_{\bar{L}})^{b_{\bar{L}}^{\prime}}\Big)
$$

$$
(\varGamma_{I}^{\prime},\varDelta_{I}^{\prime})
$$

$$
\mathsf{t}^{\prime}\gets(\varGamma_{I}^{\prime\prime},\varDelta_{I}^{\prime\prime})
$$

$$
\ \ (\varGamma_{I}^{\prime},\varDelta_{I}^{\prime})\leftarrow\big(\mathtt{S h a m i r T r i c k}(\varGamma_{I},\varGamma_{\bar{L}},\mathsf{F}_{I},\mathsf{F}_{\bar{L}})^{a_{\bar{L}}^{\prime}}
$$

$$
I\cap L=L
$$

$$
\varDelta:=(K,\mathsf{F}_{K}^{\prime})
$$

0K
{ op = add: parse := (*K;*F), st :=<sub>I</sub>and the old digest as := ((*A;B*)*;n*). Set *b* = 1 i
0*K* 0K 0K
K = *fn* + 1*;:::;n* + *jKjg*. Then if *b* = 1 compute (*a;b*) PartndPrimeProd(*K;*F) and the
0 a0b00 0
new digest becomes ((*AK;BK*)*;n*) where *n n* + *jKj*. For the new local state, rst
a0b0
0 K K
parse the old one st :=<sup>I</sup>:= (<sup>I</sup>*;*<sup>I</sup>) and the new one gets st where (*;*).
<sub>I0</sub> I0 I I
0J
Finally set (*J;*F) (*I;*F<sub>I</sub>), i.e., the le remains unchanged.

$$
:=\pi_{I}
$$

$$
\delta:=((A,B),n)
$$

$$
K=\left\{n+1,\ldots,n+\left|K\right|\right\}
$$

$$
b=1
$$

$$
b=1
$$

$$
(a_{K}^{\prime},b_{K}^{\prime})\leftarrow
$$

$$
\delta^{\prime}\,\dot{\leftarrow}\,((A^{a_{K}^{\prime}},B^{b_{K}^{\prime}}),n^{\prime})
$$

$$
(K,\mathsf{F}_{K}^{\prime})
$$

$$
n^{\prime}\leftarrow n+|K|
$$

$$
\mathfrak{I}:=\pi_{I}:=\left(\varGamma_{I},\varDelta_{I}\right)
$$

$$
\mathsf{s t}^{\prime}\gets\pi_{I}^{\prime}
$$

$$
\pi_{I}^{\prime}\leftarrow(\varGamma_{I}^{a_{K}^{\prime}},\varDelta_{I}^{b_{K}^{\prime}})
$$

$$
(J,\mathsf{F}_{J}^{\prime})\leftarrow(I,\mathsf{F}_{I})
$$

---

{ op = del: parse := *K*, st :=<sub>I</sub>, and := (F<sub>K</sub>*;*<sub>K</sub>). Set *b* = 1 i *K* = *fn jKj* + 1*;:::;ng^*
0
VC*:* Ver⁰(pp*;;K;*F<sub>K</sub>*;*<sub>K</sub>) = 1. Then if *b* = 1 sets ((<sub>K</sub>*;*<sub>K</sub>)*;n⁰*) where *n⁰ n jKj*. For
the new local state, similarly to the modify operation, we discern three cases. If *I \ K* =*;* then
<sup>0I</sup>
(*;*) (ShamirTrick(<sup>I</sup>*;*<sup>K</sup>*;* F<sup>I</sup>*;* F<sup>K</sup>)*;* ShamirTrick(<sup>I</sup>*;*<sup>K</sup>*;* F<sup>I</sup>*;* F<sup>K</sup>)) and set st⁰<sup>K</sup>:=
<sup>I0</sup>
<sub>0I</sub>
(*;*); else if *I\K* = *K* st⁰ = st, else if *I\K* = *L* then (let *L* = *K n L*)
<sup>I0</sup>
<sub>0I</sub>
(*;*) (ShamirTrick(<sub>I</sub>*;*<sub>L</sub>*;* F<sub>I</sub>*;* F<sub>L</sub>)*;* ShamirTrick(<sub>I</sub>*;*<sub>L</sub>*;* F<sub>I</sub>*;* F<sub>L</sub>)) and set st⁰<sub>I</sub>:=
<sub>I0</sub>
<sub>0I</sub> 0J
(*;*) (similarly to the op = mod case). Finally (*J;*F) (*I n L;*F<sub>I</sub>*n* F<sub>L</sub>).
I0

$$
\varUpsilon_{\varDelta}:=(\mathsf{F}_{K},\pi_{K})
$$

$$
\varDelta:=K
$$

$$
\tilde{K}=\left\{n-\left|\tilde{K}\right|\!+\!,\ 1\,,\ldots,n\right\}\Lambda
$$

$$
b=1
$$

$$
{=}\pi_{I}
$$

$$
\delta^{\prime}\gets((\varGamma_{K},\varDelta_{K}),n^{\prime})
$$

$$
b=1
$$

$$
\mathsf{V C.V e r}^{\prime}(\mathsf{p p},\delta,K,\mathsf{F}_{K},\pi_{K})=1
$$

$$
n^{\prime}\leftarrow n-|K|
$$

$$
I\cap K=\emptyset
$$

$$
(\varGamma_{I}^{\prime},\varDelta_{I}^{\prime})\leftarrow
$$

$$
(Gamma_{I},\varGamma_{K},\mathsf F{{}}_{I},\mathsf F_{K})
$$

$$
\varDelta_{I},\varDelta_{K},\mathsf F_{I},\mathsf F_{K}),
$$

$$
\mathsf{s t}^{\prime}\leftarrow\pi_{K}:=
$$

$$
I\cap K=K\;{\mathsf{s t}}^{\prime}={\mathsf{s t}}
$$

$$
(\varGamma_{I}^{\prime},\varDelta_{I}^{\prime})
$$

$$
I\cap K=L
$$

$$
\bar{L}=K\setminus L)
$$

$$
(T_{I}^{\prime},\varDelta_{I}^{\prime})\leftarrow
$$

$$
(\varGamma_{I},\varGamma_{\bar{L}},\mathsf F_{I},\mathsf F_{\bar{L}})
$$

$$
(\varGamma_{I}^{\prime},\varDelta_{I}^{\prime})
$$

$$
(\varDelta_{I},\varDelta_{\bar{L}},\mathsf F{{}}_{I},\mathsf F_{\bar{L}}))
$$

$$
(J,\mathsf{F}_{J}^{\prime})\gets(I\setminus L,\mathsf{F}_{I}\setminus\mathsf{F}_{L})
$$

$$
\mathsf{s t}^{\prime}\leftarrow\pi_{I}:=
$$

StrgNode*:* Retrieve(*;n;* st*;I;*F<sup>I</sup>*;Q*)*!* (F<sub>Q</sub>*;*<sub>Q</sub>)Compute both portion F<sub>Q</sub>F<sub>I</sub>as well as proof
0
<sub>Q</sub>VC*:* Disagg (pp*;I;*F<sub>I</sub>*;*st*;Q*).

$$
(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},Q)\to(\mathsf{F}_{Q},\pi_{Q})
$$

$$
\mathsf{F}_{Q}\subseteq\mathsf{F}_{I}
$$

$$
\pi_{Q}\leftarrow\mathsf{V C.D i s a g g}^{\prime}(\mathsf{p p},I,\mathsf{F}_{I},\mathsf{s t},Q).
$$

The algorithms for client nodes are:

0 0
ClntNode*:* GetCreate(*;J;*J)*!* (*b;*)ParseJ:= (*; 0*), set *n⁰* = *jJ j* and output *b*
PoKSubV
0 0
PoKSubV⁰*:* V(pp*;* (*;;J*)*;*<sub>J</sub>) *^ J* = *f*1*;:::; jJ jg* and.

$$
\ {sf L I t t N o d e.G e t C r e a t e}(\delta,J,\varUpsilon_{J})\to(b,\delta^{\prime})
$$

$$
\ {itUpsilon}_{J}\,:=\,(\delta^{\prime},\pi_{\sf P o K S u b V^{\prime}})
$$

$$
n^{\prime}\,=\,|J|
$$

$$
b\leftarrow
$$

$$
\mathsf{P o K S u b V^{\prime}.V}(\mathsf{p p},(\delta,\delta^{\prime},J),\pi_{J})\wedge J=\{1,\dots,|J|\}
$$

$$
\delta^{\prime}
$$

ClntNode*:* VerRetrieve(*;Q;*F<sub>Q</sub>*;*<sub>Q</sub>)*! b* Output *b* VC*:* Ver⁰(pp*;;Q;*F<sub>Q</sub>*;*<sub>Q</sub>)

$$
\left(\delta,Q,\mathsf{F}_{Q},\pi_{Q}\right)\to b
$$

0
ClntNode*:* ApplyUpdate(*;*op*;;*)*!* (*b;*)This algorithm is almost identical to the rst part of
the Storage Node algorithm StrgNode*:* ApplyUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;;*). The dierence is that
it executes only the parts that are related to the output of *b* and.

$$
(\delta,{\mathfrak{o p}},\varDelta,\varUpsilon_{\varDelta}right)\to(b,\delta^{\prime})
$$

$$
(\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, \mathrm {o p}, \Delta , Y _ {\Delta})
$$

AggregateCerticates(*;* (*I;*F<sub>I</sub>*;*<sub>I</sub>)*;* (*J;*F<sub>J</sub>*;*<sub>J</sub>))*!*<sub>K</sub>

$$
\left(\emptyset,(I,\mathsf{F}_{I},\pi_{I}),(J,\mathsf{F}_{J},\pi_{J})\right)\to\pi_{K}
$$

Return<sub>K</sub>VC*:* Agg⁰(pp*;* (*I; ~*F<sub>I</sub>*;*<sub>I</sub>)*;* (*J; ~*F<sub>J</sub>*;*<sub>J</sub>)).

$$
\pi_{K}\leftarrow\mathsf{V C.A g g}^{\prime}(\mathsf{p p},(I,\mathsf{F}_{I},\pi_{I}),(J,\mathsf{F}_{J},\pi_{J})).
$$

Correctness. Here we state and prove the correctness of VDS₁.

$$
\mathsf{V D S}_{1}
$$

Theorem 8.1. *The scheme* VDS₁ *presented above is a correct veriable decentralized storage scheme.*

$$
\mathsf{V D S}_{1}
$$

?
Proof In the following we will always assume that st := (st₁*;*st₂) and := (*;n*) := ((<sub>1</sub>*;*<sub>2</sub>)*;n*).
Furthermore, whenever (*a*<sub>I</sub>*;b*<sub>I</sub>) appear, we assume that they are the outputs of PartndPrimeProd(*I;*F<sub>I</sub>),
for each set of indices *I*. Finally for each set of indices *I* we assume<sub>I</sub>:= (<sub>I</sub>*;*<sub>I</sub>).

$$
\delta:=\left(\delta^{\star},n\right):=\left((\delta_{1},\delta_{2}),n\right)
$$

$$
:=(\mathsf{s t}_{1},\mathsf{s t}_{2})
$$

$$
(a_{I},b_{I})
$$

$$
|(I,\mathsf{F}_{I})
$$

$$
\pi_ {I} := \left(\Gamma_ {I}, \Delta_ {I}\right)
$$

First we note that in our construction it is sucient for a local view (pp*;;n;* st*;I;*F<sub>I</sub>) of a
storage node to be valid that

$$
(\mathsf{p p},\delta,n,\mathsf{s t},I,\mathsf{F}_{I})
$$

ClntNode*:* VerRetrieve(*;I;* StrgNode*:* Retrieve(*;n;* st*;I;*F<sub>I</sub>*;I*)) = 1 holds. More concretely this transaIbI0aQ0bQ
lates to st₁ =<sub>1</sub>*^*st₂ =<sub>2</sub>and due to the correctness of disaggregation property st₁ =<sub>1</sub>*^*st₂ =
<sup>2</sup>holds where st⁰ StrgNode*:* Retrieve(*;n;* st*;I;*F<sup>I</sup>*;Q*) for each *Q I*. To put things clear, a local
aIbI
view of a storage node (pp*;;n;* st*;I;*F<sub>I</sub>) is v<sub>a</sub>lid if st₁ =<sub>1</sub>^ st₂ =<sub>2</sub>.
Let (pp*;;n;* st*;I;*F) be a valid local view of a storage node:

$$
(\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, I)) = 1
$$

$$
\mathsf{s t}_{1}^{a_{I}}=\delta_{1}{\wedge}\mathsf{s t}_{2}^{b_{I}}=\delta_{2}
$$

$$
{mathsf\mathsf s t}_{1}^{\prime a_{Q}}=\delta_{1}{\wedge}\mathsf{s t}_{2}^{\prime b_{Q}}=
$$

$$
\delta_{2}
$$

$$
(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},Q)
$$

$$
Q\subseteq I
$$

$$
\mathsf{s t}_{1}^{a_{I}}=\delta_{1}\wedge\mathsf{s t}_{2}^{b_{I}}=\delta_{2}
$$

$$
(\mathsf{p p},\delta,n,\mathsf{s t},I,\mathsf{F}_{I})
$$

*I*
0 0J
Update Correctness. Let (op*;*) be an admissible update for (*I;*F<sub>I</sub>*;n*) and (*;n⁰;*st⁰*;J;*F*;*)
be the output of StrgNode*:* PushUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;*). We discern three cases depending on
the type of update:

$$
(I,\mathsf{F}_{I},n)
$$

$$
\left(\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{J}^{\prime},\varUpsilon_{\varDelta}\right)
$$

$$
(mathsf o o p,\varDelta)
$$

$$
\mathrm {P u s h U p d a t e} (\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, \mathrm {o p}, \Delta)
$$

{ op = mod:

$$
\boldsymbol{\delta}^{\star}=(\boldsymbol{\Gamma}_{K}^{a_{K}^{\prime}},\boldsymbol{\Delta}_{K}^{b_{K}^{\prime}})
$$

0 a0b0
? K K
1.According to our construction = (*;*), where
K K

a b a 0K b 0K
a b a b
InK InK a IK b IK 0 0a IK b IK
(<sup>K</sup>*;*<sup>K</sup>) = (*;*) = (st₁*;*st₂) (due to VC*:* Disagg). So = (st₁*;*st₂). Fur-
I I
thermore st⁰ = st and *J* = *I*, so

$$
(\varGamma_{K},\varDelta_{K})=(\varGamma_{I}^{a_{I\setminus K}},\varDelta_{I}^{b_{I\setminus K}})=(\mathsf{s t}_{1}^{\frac{a_{I}}{a_{K}}},\mathsf{s t}_{2}^{\frac{b_{I}}{b_{K}}})
$$

$$
\delta^{\prime}=(\mathsf{s t}_{1}^{\frac{a_{I}}{a_{K}}a_{K}^{\prime}},\mathsf{s t}_{2}^{\frac{b_{I}}{b_{K}}b_{K}^{\prime}})
$$

$$
J=I.
$$

$$
\mathsf{s t}^{\prime}=\mathsf{s t}
$$

$$
(\mathsf{s t}_{1}^{\prime a_{J}^{\prime}},\mathsf{s t}_{1}^{\prime b_{J}^{\prime}})=(\mathsf{s t}_{1}^{\frac{a_{I}}{a_{K}}a_{K}^{\prime}},\mathsf{s t}_{2}^{\frac{b_{I}}{b_{K}}b_{K}^{\prime}})=(\delta_{1}^{\prime},\delta_{2}^{\prime})
$$

---

0s 0s 0J
2.Let (*;n;* st<sup>s</sup>*;I*<sup>s</sup>*;* F<sup>I</sup><sup>s</sup>) be valid and (*b*<sup>s</sup>*;*<sup>s0</sup>*;n;*st*;J*<sup>s</sup>*;* F) be the output of
s
0 0s
StrgNode*:* ApplyUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;;*). *b*<sub>s</sub>= 1,<sub>s0</sub>= and *n* = *n⁰* come from inspection.
If *I\K* =*;* then
0s; 0s; a0b0
(st*;*st) ShamirTrick(st<sub>s;</sub><sub>1</sub>*;*<sub>K</sub>; F<sub>I</sub>*;* F<sub>K</sub>)*K;* Sh<sup>a</sup>mirTrick(st<sub>s;</sub><sub>2</sub>*;*<sub>K</sub>; F<sub>I</sub>*;* F<sub>K</sub>)*K*=
1 2
*a0K b0K*
aK bK 0I 0I
= (st*;*st) <sup>a</sup>nd (*a;b*) = (*a*<sub>I</sub>*;b*<sub>I</sub>) remains the same. So
s;1 s;2

$$
(\delta,n,\mathsf{s t}_{s},I_{s},\mathsf{F}_{I_{s}})
$$

$$
(b_{s},\delta_{s}^{\prime},n_{s}^{\prime},\mathsf{s t}_{s}^{\prime},J_{s},\mathsf{F}_{J_{s}}^{\prime})
$$

$$
\operatorname {S t r g N o d e}. \operatorname {A p l y U p d a t e} (\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, \mathrm {o p}, \Delta , Y _ {\Delta}). b _ {s} = 1, \delta_ {s} ^ {\prime} = \delta^ {\prime} \text {a n d} n _ {s} ^ {\prime} = n ^ {\prime} \text {c o m e f r o m i n s p e c t i o n}.
$$

$$
I\cap K=\emptyset
$$

$$
(\mathsf{s t}_{s,1}^{\prime},\mathsf{s t}_{s,2}^{\prime})\leftarrow\Big(\mathbf{S h a m i r T r i c k}(\mathsf{s t}_{s,1},\varGamma_{K},\mathsf{F}_{I},\mathsf{F}_{K})^{\mathsf{d}_{K}^{\prime}}\:,\mathbf{S h a m i r T r i c k}(\mathsf{s t}_{s,2},\varDelta_{K},\varDelta{\ \ _{K}},\mathsf{F}_{K})^{\mathsf{d}_{K}^{\prime}}\Big)=
$$

$$
=\big(\mathsf{s t}_{s,1}^{\frac{a_{K}^{\prime}}{a_{K}}},\mathsf{s t}_{s,2}^{\frac{b_{K}^{\prime}}{b_{K}^{\}}}\big)}
$$

$$
(a_{I}^{\prime},b_{I}^{\prime})=(a_{I},b_{I})
$$

$$
(\mathsf{s t}_{s,1}^{\prime a_{I}^{\prime}},\mathsf{s t}_{s,2}^{\prime})=(\mathsf{s t}_{s,1}^{a\_{K}^a_{I}},a_{I},\mathsf{s t}_{s,2}^{b_{K}}b_{I})=(\delta_{s,1},\delta_{s,2})
$$

0I 0I aI 0K bI 0K
If *I\K* = *K* then st<sub>s</sub>doesn’t change and (*a;b*) = ( *a; b*), hence
aKbK

$$
I\cap K=K
$$

$$
{\sf{S}}{\sf{t}}_{s}
$$

$$
\left(a_{I}^{\prime},b_{I}^{\prime}\right)=\left(\frac{a_{I}}{a_{K}}a_{K}^{\prime},\frac{b_{I}}{b_{K}}b_{K}^{\prime}\right)
$$

$$
\left(\mathrm {s t} _ {s, 1} ^ {\prime a _ {I} ^ {\prime}} \mathrm {s t} _ {s, 2} ^ {\prime b _ {I} ^ {\prime}}\right) = \left(\delta_ {s, 1} ^ {\prime}, \delta_ {s, 2} ^ {\prime}\right)
$$

0s 0s 0J
The validity of (pp*;*<sup>s0</sup>*;n;*st*;J*<sup>s</sup>*;* F) in the case of *I \ K* = *L =2f;;Kg* is covered by the above
s
two, since it essentially is a sequence of the two above cases.

$$
(\mathsf{p p},\delta_{s}^{\prime},n_{s}^{\prime},\mathsf{s t}_{s}^{\prime},J_{s},\mathsf{F}_{J_{s}}^{\prime})
$$

$$
I\cap K=L\notin\{\emptyset,K\}
$$

3.Let (*b*<sub>c</sub>*;*<sub>c</sub>) be the output of ClntNode*:* ApplyUpdate(*;*op*;;*). It follows directly from the
denition of ClntNode*:* ApplyUpdate (and its similarity with StrgNode*:* ApplyUpdate) that *b*<sub>c</sub>=
0
*b*<sub>s</sub>= 1 and<sub>c0</sub>=<sub>s0</sub>=.

$$
(b_{c},\delta_{c})
$$

$$
(\delta , \mathrm {o p}, \Delta , Y _ {\Delta})
$$

$$
{_b{c}}=
$$

$$
b_{s}=1
$$

$$
\delta_{c}^{\prime}=\delta_{s}^{\prime}=\delta^{\prime}
$$

{ op = add:

0 a0b0
? K K 0 0J 0J
1.According to our construction = (*;*) <sup>a</sup>nd st = st. Also, *J* = *I[K* and (*a;b*) =
1 2
0K <sub>0K</sub>
(*a*<sub>I</sub>*a;b*<sub>I</sub>*b*) and so

$$
\delta^{\star^{\prime}}=(\delta_{1}^{a_{K}^{\prime}},\delta_{2}^{b_{K}^{\prime}})
$$

$$
\mathsf{s t}^{\prime}=\mathsf{s t}
$$

$$
(a_{J}^{\prime},b_{J}^{\prime})=
$$

$$
(a_{I}a_{K}^{\prime},b_{I}b_{K}^{\prime})
$$

$$
(\mathsf{s t}_{1}^{\prime a_{J}^{\prime}},\mathsf{s t}_{1}^{\prime b_{J}^{\prime}})=(\mathsf{s t}_{1}^{a_{I}a_{K}^{\prime}},\mathsf{s t}_{2}^{b_{I}b_{K}^{\prime}})=(\delta_{1}^{a_{K}^{\prime}},\delta_{2}^{b_{K}^{\prime}})=(\delta_{1}^{\prime},\delta_{2}^{\prime})
$$

0s 0s 0J
2.Let (*;n;* st<sup>s</sup>*;I*<sup>s</sup>*;* F<sup>I</sup><sup>s</sup>) be valid and (*b*<sup>s</sup>*;*<sup>s0</sup>*;n;*st*;J*<sup>s</sup>*;* F) be the output of
s
0 0s
StrgNode*:* ApplyUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;;*). *b*<sub>s</sub>= 1,<sub>s0</sub>= and *n* = *n⁰* come from inspection.
a0b0 0 a0b0
0J 0J 0 K K? K K
Also *J* = *I* so (*a;b*) = (*a*<sub>I</sub>*;b*<sub>I</sub>). st = (st₁*;*st₂) <sub>a</sub>nd = (*;*) so
<sub>1</sub> <sub>2</sub>

$$
(\delta,n,\mathsf{s t}_{s},I_{s},\mathsf{F}_{I_{s}})
$$

$$
(b_{s},\delta_{s}^{\prime},n_{s}^{\prime},\mathsf{s t}_{s}^{\prime},J_{s},\mathsf{F}_{J_{s}}^{\prime})
$$

$$
\mathtt{t r g N o d e.A p p l y V D a t e e}(\delta,n,\mathtt{s t},\mathtt{I},\mathtt{F}_{},\mathtt{o p},\mathtt DeltaDelta\,\mathtt{T}_{\Delta}).\;b_{s}=1,\bar{\delta}_{s}^{\prime}=\delta^{\prime}\operatorname{a n d}n_{s}^{\prime}=n^{\prime}
$$

$$
J=I\;{\mathrm{s o}}\;(a_{J}^{\prime},b_{J}^{\prime})=(a_{I},b_{I}).\;{\mathfrak{s t}}^{\prime}=({\mathfrak{s t}}_{1}^{a_{K}^{\prime}},{\mathfrak{s t}}_{2}^{b_{K}^{\prime}})
$$

$$
\delta^{\star}=(\delta_{1}^{a_{K}^{\prime}},\delta_{2}^{b_{K}^{\prime}})
$$

$$
(\mathsf{s t}_{1}^{\prime a_{J}^{\prime}},\mathsf{s t}_{1}^{\prime b_{J}^{\prime}})=(\mathsf{s t}_{1}^{a_{K}^{\prime}a_{I}},\mathsf{s t}_{2}^{b_{K}^{\prime}b_{I}})=(\delta_{1}^{\prime},\delta_{1}^{\prime})
$$

3.Let (*b*<sub>c</sub>*;*<sub>c</sub>) be the output of ClntNode*:* ApplyUpdate(*;*op*;;*). Again correctness comes directly from the denition of ClntNode*:* ApplyUpdate.
{ op = del:

$$
(b_{c},\delta_{c})
$$

$$
(\delta,\mathsf{o p},\varDelta,\varUpsilon_{\varDelta})
$$

$$
-{\mathrm{\ o}}{\mathsf{p p}}={\mathsf{d e l}}!\,
$$

1 1
0 0aK bK 0
1.According to our construction (<sub>1</sub>*;*<sub>2</sub>)=(<sub>K</sub>*;*<sub>K</sub>)=(*;*), st = st and *J* = *I n K*.
1 2
0J 0J aIbI
Furthermore, (*a;b*) = (*;*)
<sub>a</sub><sub>K</sub><sub>b</sub><sub>K</sub>

$$
(\delta_{1}^{\prime},\delta_{2}^{\prime})\:=\:(\varGamma_{K},\varDelta_{K})\:=\:(\delta_{1}^{\frac{1}{\_{K}}},\delta_{2}^{\frac{1}{\delta_{K}}}),\:\mathsf{s t}^{\prime}\:=\:\mathsf{s t}\:\mathrm{a n d}\:\:J\:=\:I\:\setminus K
$$

$$
\left(a_{J}^{\prime},b_{J}^{\prime}\right)=\left(\frac{a_{I}}{a_{K}},\frac{b_{I}}{b_{K}}\right)
$$

$$
(\mathsf{s t}_{1}^{\prime mathsf a_{J}^{\prime}},\mathsf{s t}_{1}^{\prime b_{J}^{\prime}})=(\mathsf{s t}_{1}^{\frac{a_{I}}{a_{K}}},\mathsf{s t}_{2}^{\frac{b_{I}}{b_{K}}})=(\delta_{1}^{\frac{1}{a_{K}}},\delta_{2}^{\frac{1}{b_{K}}})=(\delta_{1}^{\prime},\delta_{2}^{\prime})
$$

0s 0s 0J
2.Let (*;n;* st<sup>s</sup>*;I*<sup>s</sup>*;* F<sup>I</sup><sup>s</sup>) be valid and (*b*<sup>s</sup>*;*<sup>s0</sup>*;n;*st*;J*<sup>s</sup>*;* F) be the output of
s
0 0s
StrgNode*:* ApplyUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;;*). *b*<sub>s</sub>= 1,<sub>s0</sub>= and *n* = *n⁰* come from inspection.
Also let *L* = *I\K* then *J* = *I n L* and if *L* = *K n L* then

$$
(\delta,n,\mathsf{s t}_{s},I_{s},\mathsf{F}_{I_{s}})
$$

$$
(b_{s},\delta_{s}^{\prime},n_{s}^{\prime},\mathsf{s t}_{s}^{\prime},J_{s},\mathsf{F}_{J_{s}}^{\prime})
$$

$$
\ \mathbf\ {\mathrm{p p l y J p d a t e}}(\delta,n,\mathtt{s t},\mathtt I\\{{F}}_{I},\mathtt{o p},\mathtt\ Delta\ ,\varUpsilon_{\varDelta}).\ b_{s}=\ ,\tilde{1},\delta_{s}^{\prime}=\delta^{\prime}\operatorname{a n d}n_{s}^{\prime}=n^{\prime}
$$

$$
{\bar{L}}=K\setminus L
$$

$$
L=I\cap K
$$

$$
J=I\setminus L
$$

<u>1 1</u>
0 0aL bL
(st₁*;*st₂) (ShamirTrick(st₁*;*<sub>L</sub>*;* F<sub>I</sub>*;* F<sub>L</sub>)*;* ShamirTrick(st₂*;*<sub>L</sub>*;* F<sub>I</sub>*;* F<sub>L</sub>)) = (st₁;st₂)

$$
(\mathsf{s t}_{1}^{\prime},\mathsf{s t}_{2}^{\prime})\leftarrow(\mathbf{S h a m i r r T r c c}(\mathsf{s t}_{1},\mathit{\Gamma}_{\bar{L}},\mathit{\Gamma}_{\bar{L}},\mathit{\Gamma}_{\},\mathit{\Gamma}_{\bar{L}})\nonumber}
$$

$$
\cdot(\mathsf{s t}_{2},\varDelta_{\bar{L}},\mathsf{F}_{I},\mathsf{F}_{\bar{L}}))=(\mathsf{s t}_{1}^{\frac{1}{a_{\bar{L}}}},\mathsf{s t}_{2}^{\frac{1}{b_{\bar{L}}}})
$$

$$
(\mathbf{s t}_{1}^{\prime prime alpha{_{J}^{\prime}}},\mathbf{s t}_{1}^{b_{J}^{\prime}})=(\mathbf{s t}_{1}^{\frac{a_{J}}{a_{L}}},\mathbf{s t}_{2}^{\frac{b_{J}}{b_{L}^{\prime}}})=(\mathbf{s t}_{1}^{\frac{a_{J}/a_{L}}{a_{L}/a_{L}}},\mathbf{s t}_{1}^{\frac{b_{J}/b_{L}}{b_{K}/b_{L}}})=(\delta_{1}^{\frac{1}{a_{K}}},\delta_{2}^{\frac{1}{b_{K}}})=(\delta_{1}^{\prime},\delta_{2}^{\prime})
$$

---

0
3.Let (*b*<sub>c</sub>*;*<sub>c</sub>) be the output of ClntNode*:* ApplyUpdate(*;*op*;;*). *b*<sub>c</sub>= *b*<sub>s</sub>= 1 and<sub>c0</sub>=<sub>s0</sub>=
from inspection.

$$
(b_{c},\delta_{c})
$$

$$
\delta_{c}^{\prime}=\delta_{s}^{\prime}=\delta^{\prime}
$$

$$
(\delta , \mathrm {o p}, \Delta , Y _ {\Delta}). b _ {c} = b _ {s} = 1
$$

Add Storage Correctness. It comes directly from aggregation correctness of VC*:* Agg⁰ (see
section5.1).

$$
\mathsf{V C.A g g^{\prime}}
$$

Remove Storage Correctness. It comes directly from disaggregation correctness of VC*:* Disagg⁰
(see section5.1).

$$
J\subseteq I
$$

0
Create Correctness. Let *J I* and (*;n⁰;*st⁰*;J;*F<sub>J</sub>*;*<sub>J</sub>) be the output of
00
StrgNode*:* CreateFrom(*;n;* st*;I;*F<sub>I</sub>*;J*) and (*b;*) the output of ClntNode*:* GetCreate(*;J;*<sub>J</sub>), then
00 0
*n⁰* = *jJ j* comes from inspection of StrgNode*:* CreateFrom, = comes from inspection of
0
ClntNode*:* GetCreate algorithm and validity of (pp*;;n⁰;*st⁰*;J;*F<sub>J</sub>) comes from correctness of VC*:* Com⁰
and VC*:* Agg. Finally, *b* = 1 comes from correctness of PoKSubV⁰ protocol.

$$
(\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{J},\mathsf{T}_{J})
$$

$$
(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},J)
$$

$$
(b,\delta^{\prime\prime})
$$

$$
e. \operatorname {G e t C r e a t e} (\delta , J, Y _ {J})
$$

$$
n^{\prime}\,=\,|J|
$$

$$
\delta^{\prime\prime}\;=\;\delta^{\prime}
$$

$$
\ \ (\mathsf{p p},\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{J})
$$

$$
\mathsf{V C}o o\mathsf{N}
$$

$$
b=1
$$

Aggregate Correctness. It comes directly from aggregation correctness of VC*:* Agg⁰ (see section5.1).

Security. Below we state and prove the security of our VDS₁ scheme.

$$
\mathsf{V D S}_{1}
$$

Theorem 8.2(Security). *Let* G Ggen(1 ) *be a hidden order group where the strong RSA*
*assumption holds, then the scheme* VDS₁ *presented above is a secure Veriable Decentralized Storage*
*scheme in the generic group model.*

$$
\mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda})
$$

Proof First we observe that in our scheme, for every valid history *H*, with Bootstrap(1 )*!*
(pp*;*<sub>0</sub>*;*st₀) := ((G*;g;g₀;g₁;*PrimeGen)*;* ((*g₀;g₁*)*;*0)*;* (*g₀;g₁*)), the digest that arises is the same
as a commitment of the le with VC*:* Com⁰. Concretely, let (*b;;* F) EvalHistory(pp*;*<sup>0</sup>*;*st₀*; H*)
? a b
then if *b* = 1 it holds that = VC*:* Com⁰(pp*;*F) or = (<sub>1</sub>*;*<sub>2</sub>) = (*g₀;g₁*), where (*a;b*)
PartndPrimeProd([*j*F*j*]*;*F). Particularly this is central to our construction and one can validate that
it holds by inspecting all the algorithms that alter the digest.

$$
(\mathsf{p p},\delta_{0},\mathsf{s t}_{0})\;:=\;((\mathbb{G},g,g_{0},g_{1},\mathsf{P r i m e G G n)):}\;((g_{0},g_{1}),0)\:,\;(g_{0},g_{1}).
$$

$$
\mathsf{B o o t s t r a p}(1^{\lambda})\to
$$

$$
(b,\delta,\mathsf{F})\ \leftarrow\ \mathsf{E v a l H i s t o r y}(\mathsf{p p},\delta_{0},\mathsf{s t}_{0},\mathcal{H})
$$

$$
\delta\,=\,\mathsf{V C.C o m^{\prime}(p p,F)}
$$

$$
\delta^{\star}\;=\;\big(\delta_{1},\delta_{2}\big)\;=\;\big(g_{0}^{a},g_{1}^{b}\big)
$$

$$
(a,b)\leftarrow
$$

To prove the theorem we use a hybrid argument. We start by dening the game *G₀* as the actual
*VDS* security game of Denition7.6, and our goal is to prove that for any PPT *A*, Pr[*G₀* = 1] *2*
negl().

$$
G_{0}
$$

$$
\mathcal{A},\,\operatorname*{P r}[G_{0}=1]\in
$$

$$
G{{}_{0}};
$$

| $G_{0}=\mathrm{VDS-Security}_{\mathrm{VDS}}^{\mathcal{A}}(\lambda)$ | EvalHistory(pp, $\delta_{0}$, st0,H) |
| --- | --- |
| (pp,$\delta_{0}$,st0) $ \leftarrow $ Bootstrap($1^{\lambda}$) | F0 $ \leftarrow $ ∅;b $ \leftarrow $ 1 |
| (H,Q,F$_{Q}^{*}$,$\pi^{*}$) $ \leftarrow $ A(pp,$\delta_{0}$,st0) | for i∈[ℓ] |
| (b,$\delta$,F) $ \leftarrow $ EvalHistory(pp,$\delta_{0}$,st0,H) | Fi $ \leftarrow $ FileChange(Fi-1,opi,$\Delta^{i}$) |
| b $ \leftarrow $ b $ \wedge $ F$_{Q}^{*} \neq F_{Q}\wedge$ | if opi $ \in $ {mod,add,del} then |
| ClntNode.VerRetrieve(pp,$\delta$,Q,F$_{Q}^{*}$,$\pi^{*}$) | (bi,$\delta_{i}$) $ \leftarrow $ ClntNode.ApplyUpdate($\delta_{i-1}$,opi,$\Delta^{i}$,Y$_{\Delta}^{i}$) |
| return b | elseif opi $ = $ cfrom then |
|  | (bi,$\delta_{i}$) $ \leftarrow $ ClntNode.GetCreate($\delta_{i-1}$,$\Delta^{i}$,Y$_{\Delta}^{i}$) |
| endif | b $ \leftarrow $ b $ \wedge $ bi |
| endfor | return(b,$\delta_{\ell}$,F$\ell$) |

$$
G_{0}=\mathsf{V D S-S e c u r i t y_{V D S}^{A}}(\lambda)
$$

$$
(\mathsf{p p},\delta_{0},\mathsf{s t}_{0})\leftarrow\mathsf{B o o t s t r a p(1}{}^{\lambda})
$$

$$
\mathsf{F}_{0}\leftarrow\emptyset;b\leftarrow1
$$

$$
(\mathcal{H},\mathcal{Q},\mathsf{F}_{Q}^{*},\pi^{*})\leftarrow\mathcal{A}(\mathsf{p p},\emptyset_{0},\mathsf{s t}_{0})
$$

$$
(b, \delta , F) \leftarrow \operatorname {E v a l H i s t o r y} (\mathrm {p p}, \delta_ {0}, \mathrm {s t} _ {0}, \mathcal {H})
$$

$$
i\in[\ell]
$$

$$
\mathsf{F}_{i}\leftarrow\mathsf{F i l e C h a n g e}(\mathsf{F}_{i-1},\mathfrak{o p}^{i},\varDelta^{i})
$$

$$
b\gets b\land\mathsf{F}_{Q}^{*}\neq\mathsf{F}_{Q}\land
$$

$$
\cdot\mathsf{o p}^{i}\in\{\mathsf{m o d},\mathsf{a d d},\mathsf{d e l}\}
$$

$$
\mathsf{C I n t N o d e.V e r R e t r i e v e}(\mathsf{p p},\delta,\,\,\mathsf{Q},\mathsf{F}_{Q}^{*},\pi^{*})
$$

$$
\left(b _ {i}, \delta_ {i}\right) \leftarrow \mathrm {C l n t N o d e . A p p l y U p d a t e} \left(\delta_ {i - 1}, \mathrm {o p} ^ {i}, \Delta^ {i}, \gamma_ {\Delta} ^ {i}\right)
$$

$$
\ \mathsf{o p}^{i}=\mathsf{c f r o m\ t\ e t{n n}}
$$

$$
\left(b _ {i}, \delta_ {i}\right) \leftarrow \mathrm {C l n t N o d e . G e t C r e a t e} \left(\delta_ {i - 1}, \Delta^ {i}, \Upsilon_ {\Delta} ^ {i}\right)
$$

$$
b\gets b\land b_{i}
$$

$$
(b,\delta_{\ell},\mathsf{F}_{\ell})
$$

i i i
Recall that *H* = (op*;;*)<sup>i</sup>2<sub>[</sub><sub>‘</sub><sub>]</sub>where:

$$
\mathcal{H}=(\mathfrak{o p}^{i},\varDelta^{i},\varUpsilon_{\varDelta}^{i})_{i\in[\ell]}
$$

---

$$
-\mathrm{~f o r~}\mathfrak{o p}^{i}=\mathsf{m o d}\colon\Delta^{i}:=(K^{i},\mathsf{F}_{K\^{i}}^{i}),_{\underline{{\Delta}}}^{i}:=(\mathsf{F}_{K^{i}}^{i-1},\pi_{K^{i}}^{i-1})\mathrm{~a n d~}\mathsf{C i n t h o d e}\mathsf{A p p y f D p d a t e}(\delta^{i-1},\mathsf{o p}^{i},\Delta^{i},T_{\underline{{\Delta}}}^{i})
$$

i i i iK i iK 1 i 1 i 1 i i i
{ for op = mod: := (*K;* F<sup>i</sup>), := (F<sup>i</sup>*;*<sup>i</sup>) and ClntNode*:* ApplyUpdate(*;*op*;;*)
K
<sup>i</sup> 0 i 1 i iK 1 i 1 aKi i 1 bKii i 1
outputs *b* = 1 <sub>i</sub>f VC*:* Ver (pp*;;K;* F<sup>i</sup>*;*<sup>i</sup>) = <sub>1</sub> or (<sub>i</sub>=) *^* ( =).
<sub>K</sub> K 1 K 2

$$
\text {o u t p u t s} b ^ {i} = 1 \text {i f} \mathrm {V C}. \operatorname {V e r} ^ {\prime} \left(\mathrm {p p}, \delta^ {i - 1}, K ^ {i}, \mathrm {F} _ {K ^ {i}} ^ {i - 1}, \pi_ {K ^ {i}} ^ {i - 1}\right) = 1 \text {o r} \left(\Gamma_ {K ^ {i}} ^ {a _ {K ^ {i}}} = \delta_ {1} ^ {i - 1}\right) \wedge \left(\Delta_ {K ^ {i}} ^ {b _ {K ^ {i}}} = \delta_ {2} ^ {i - 1}\right).
$$

i i iK i i 1 i i i
{ for op = add: := (*K;*F<sup>i</sup>), := ? and ClntNode*:* ApplyUpdate(*;*op*;;*) outputs
i i i 1 i 1 i
*b* = 1 <sup>i</sup>f *K* = *fn* + <sup>1</sup>*;:::;n* + *jK jg*.

$$
\ cdot{\\bf o o\ o{\o o\o o}}^{i}\,=\,{\bf a\ do{\o d}}\ \colon:=\,(K,\mathsf{F}_{K^{i}}^{i}),\,\var\_Upsilon_{\Delta}^{i}\,:=\,\varnothing
$$

$$
\mathsf{N o d e.A p p l y U p d a t e}(\delta^{i-1},\mathsf{o p}^{i},\varDelta^{i},\varUpsilon^{i})
$$

$$
b^{i}={\mathbf{1}}{\mathrm{~i f~}}K^{i}=\{n^{i-1}+{\mathbf{1}},{\ldots,\ \overset{\ \ }{n^{i-1}}+\ \overset\rightarrow\vert,overset\\\rightarrow vert\\,\}\}}
$$

i i i i iK 1 i 1 i 1 i i <sup>i</sup>
{ op = del: := *K*, := (F<sup>i</sup>*;*<sup>i</sup>) and ClntNode*:* ApplyUpdate(*;*op*;;*) outputs
K
i i i 1 i i 1 i 1 i 1 iK 1 i 1 i i 1
*b* = 1 <sub>i</sub>f (*K* = *fn jK j*+ <sub>1</sub>*;:::;n g*) *^*VC*:* Ver⁰(pp*;;K;* F<sub>i</sub>*;*<sup>i</sup>)) or (*K* = *fn*
K
<sub>i</sub> i <sub>1</sub> aKi i 1 bKii <sub>i</sub> 1
*jK j* + <sub>1</sub>*;:::;n g^* ( =) *^* ( =).

$$
-\ {\bf\sf o p}^{i}\;=\;{\bf\sf d e l}\ \colon\varDelta^{i}\;:=\;K^{i},\ \varUpsilon_{\Delta}^{i}\;:=\;({\sf F}_{K^{i}}^{i-1},\pi_{K^{i}}^{i-1})
$$

$$
\ ^{t}=\,1\,\mathrm{~i f~}(K^{t}=\,\{n^{t-1}-|K^{t}|+1\,,\dots,n^{t-1}\})\,\land\mathsf{V C}e^{\prime}(\mathbf{p p},\theta^{t-1},K^{t-1},\mathbf{P}_{\mathcal{K}^{t}}^{t-1},\mathbf{P}_{\mathcal{K}^{t}}^{t-1},\pi_{\mathcal{K}^{t}}^{t-1})\,\mathrm{~o r~}(\mathsf{K}^{t}=\{\ n^{t-1}-\ \ ,\dots,n^{t-1}\})\,.
$$

$$
\ K^{i}|+1,\ldots,n^{i-1}\big\}\wedge(\varGamma_{K^{i}}^{a_{K^{i}}}=\delta_{1}^{i-1})\wedge(\varDelta_{K^{i}}^{b_{K^{i}}}=\delta_{2}^{i-1}).
$$

i i i i i i i 1 i i <sup>i</sup>
{ op = cfrom: := *K*, := (*;*<sup>0</sup>) and ClntNode*:* GetCreate(*;;*) outputs *b* = 1
PoKSubV
i 1 i i i i
if PoKSubV⁰*:* V(pp*;* (*;; jK j;K*)*;*<sub>i</sub>) = 1.
<sub>K</sub>

$$
- \mathrm {o p} ^ {i} = \mathrm {c f r o m}: \Delta^ {i} := K ^ {i}, \Upsilon_ {\Delta} ^ {i} := \left(\delta^ {i}, \pi_ {\mathrm {P o K S u b V} ^ {\prime}} ^ {i}\right)
$$

$$
\operatorname {G e t C r e a t e} \left(\delta^ {i - 1}, \Delta^ {i}, Y _ {\Delta} ^ {i}\right)
$$

$$
b^{i}=1
$$

$$
\text {i f} \mathrm {P o K S u b V} ^ {\prime}. \mathrm {V} (\mathrm {p p}, \left(\delta^ {i - 1}, \delta^ {i}, \left| K ^ {i} \right|, K ^ {i}\right), \pi_ {K ^ {i}} ^ {i}) = 1
$$

Game *G*<sub>i</sub>: dene *G*<sub>i</sub>be the same as *G*<sub>i</sub> <sub>1</sub>except for the update *i*:

$$
G_{i}:
$$

$$
G_{i-1}
$$

$$
G_{i}
$$

i i i iK i iK 1 i 1 i
{ <sup>i</sup>f op = mod: := (*K;* F<sup>i</sup>), := (F<sup>i</sup>*;*<sup>i</sup>) but <sub>i</sub>n the *i*-th step of EvalHistory *b* <sup>i</sup>s instead
K
output of:
*i*
b (a ja) ^ (b jb)

$$
-\ \ \ \mathrm{i f}\ \ \mathsf{o p}^{i}=\mathsf{m o d}\ :\ Delta^{i}:=(K^{i},\mathsf{F}_{K^{i}}^{i}),\,Upsilon_{\varDelta}^{i}:=(\mathsf{F}_{K^{i}}^{i-1},\pi_{K^{i}}^{i-1})
$$

$$
b^{i}
$$

$$
b^{i}\leftarrow(a_{K^{i}}|a)\wedge(b_{K^{i}}|b)
$$

$$
(\mathit{a},\mathit{b})\leftarrow\mathsf{P a r t n d P r i m e P r o d}([|\mathsf{F}^{i-1}|],\mathsf{F}^{i-1})
$$

i i
In case *b* = 0 aborts (abort<sub>i</sub>). Otherwise <sup>i</sup>s computed normally from

$$
b^{i}=0
$$

$$
\delta^{i}
$$

i 1 i i i
ClntNode*:* ApplyUpdate(*;*op*;;*).

i i iK i i i
{ for op = add: := (*K;*F<sup>i</sup>), := ? and everything is the same as in *G*<sub>i</sub> <sub>1</sub>. I.e. (*b;*) <sup>i</sup>s the
i 1 i i i
output of ClntNode*:* ApplyUpdate(*;*op*;;*).

$$
\mathrm {o p} ^ {i} = \mathrm {a d d}: \Delta^ {i} := (K, \mathrm {F} _ {K ^ {i}} ^ {i}), Y _ {\Lambda} ^ {i} := \varnothing
$$

$$
G_{i-1}
$$

$$
(b^{i},\delta^{i})
$$

$$
(\delta^{i-1},{\mathfrak{o p}}^{i},\varDelta^{i},\varUpsilon_{\varDelta}^{i})
$$

i i i i iK 1 i 1 <sup>i</sup>
{ op = del: := *K*, := (F<sup>i</sup>*;*<sup>i</sup>). S<sub>i</sub>milarly to the mod case *b* <sup>i</sup>s the output of:
K

$$
- \mathrm {o p} ^ {i} = \mathrm {d e l}: \Delta^ {i} := K ^ {i}, \Upsilon_ {\Delta} ^ {i} := \left(\mathrm {F} _ {K ^ {i}} ^ {i - 1}, \pi_ {K ^ {i}} ^ {i - 1}\right)
$$

$$
b^{i}
$$

$$
b^{i}\leftarrow(a_{K^{i}}|a)\wedge(b_{K^{i}}|b)\wedge(K^{i}=\{n^{i-1}-|K^{i}|+1,\ldots,n^{i-1}\})
$$

i 1 i 1
where (*a;b*) PartndPrimeProd([*j*F *j*]*;* F)

$$
([|\mathsf{F}^{i-1}|],\mathsf{F}^{i-1})
$$

i i
In case *b* = 0 aborts (abort<sub>i</sub>). Otherwise <sup>i</sup>s computed normally from

$$
b^{i}=0
$$

$$
\delta^{i}
$$

i 1 i i i
ClntNode*:* ApplyUpdate(*;*op*;;*).

$$
(\delta^{i-1},{\mathfrak{o p}}^{i},\varDelta^{i},\varUpsilon_{\varDelta}^{i})
$$

i i i i i i <sup>i</sup>
{ op = cfrom: := *K*, := (*;0*) but <sup>i</sup>n the *i*-th step of EvalHistory *b* <sup>i</sup>s instead:
PoKSubV

$$
b^{i}
$$

$$
b^{i}\gets(\mathsf{F}_{K^{i}}^{i-1}\subseteq\mathsf{F}^{i-1})\wedge\delta^{i}=\mathsf{V C}C o m^{\prime}(\mathsf{p p},\mathsf{F}_{K^{i}}^{i-1})\wedge J=\{1,\dots,|J|\}
$$

i
In case *b* = 0 aborts (abort<sub>i</sub>).

$$
b^{i}=0
$$

i
Lemma 8.1. *Let* op = mod *then if the strong RSA assumption holds for* Ggen*,* Pr[*G*<sub>i</sub> <sub>1</sub>= 1]
Pr[*G*<sub>i</sub>= 1] + negl()*.*

$$
{\mathfrak{o p}}^{i}=
$$

$$
\operatorname*{P r}[G_{i-1}=1]\leq
$$

$$
\operatorname*{P r}[G_{i}=1]+{mathsf{n e g l}}(\lambda)
$$

Proof It is straightforward that the only dierence between *G*<sup>i</sup> <sup>1</sup>and *G*<sup>i</sup>is in the computation
i i aKi i 1 bKii i 1 i
of *b* <sub>i</sub>nside the EvalHistory. That is in *G*<sub>i</sub> <sub>1</sub>: *b* = (<sub>i</sub>=) ^ ( =) and <sub>i</sub>n *G*<sub>i</sub>: *b* =
K 1 K 2
(*a*<sub>K</sub><sub>i</sub>*ja*) *^* (*b*<sub>K</sub><sub>i</sub>*jb*). S<sub>i</sub>nce abort₁*;*abort₂*;:::;* abort<sub>i</sub> <sub>2</sub>have not happen, from correctness of the *VDS*
i 1 i 1 a b i 1 i 1
scheme it comes that (*;*) = (*g₀;g₁*), where (*a;b*) PartndPrimeProd([*j*F *j*]*;* F).
<sub>1</sub> 2

$$
G_{i-1}
$$

$$
G_{i}
$$

$$
G_{i-1}:b^{i}=(\varGamma_{K^{i}}^{a_{K^{i}}}=\delta_{1}^{i-1})\wedge(\varDelta_{K^{i}}^{b_{K^{i}}}=\delta_{2}^{i-1})
$$

$$
b^{i}
$$

$$
(a_{K^{i}}|a)\wedge(b_{K^{i}}|b)
$$

$$
G_{i}:b^{i}=
$$

$$
\left(\delta_{1}^{i-1},\delta_{2}^{i-1}\right)=\left(g_{0}^{a},g_{1}^{b}\right)
$$

$$
(\mathbf{\mathit{a}},\mathbf{\mathit{b}})\leftarrow\mathsf{P a r t n d P r i m e P r o d}([\lfloor\mathsf{\mathit{F}}^{i-1}\vert],\mathsf{\mathit{F}}^{i-1})
$$

$$
\left| \Pr \left[ G _ {i - 1} = 1 \right] - \Pr \left[ G _ {i} = 1 \right] \right| = P r \left[ \mathrm {a b o r t} _ {i} \right] = P r \left[ b ^ {i} = 0 \right] = P r \left[ \left(a _ {K ^ {i}} | a\right) \wedge \left(b _ {K ^ {i}} | b\right) \right]
$$

i
*j*Pr[*G*<sup>i</sup> <sup>1</sup>= 1] Pr[*G*<sup>i</sup>= <sup>1</sup>]*j* = *Pr*[abort<sup>i</sup>] = *Pr*[*b* = 0] = *Pr*[(*a*<sup>K</sup><sup>i</sup>*ja*) *^* (*b*<sup>K</sup><sup>i</sup>*jb*)]. But since
aKi a bKii b
abort<sub>i</sub> <sub>1</sub>didn’t h<sub>a</sub>ppen (<sub>i</sub>= *g₀*) *^* ( = *g₁*). Therefore it is straightforward to abort<sub>i</sub>to
K K
the strong RSA assumption, i.e. *Pr*[abort<sub>i</sub>] = negl().

$$
\mathsf{a b o r t}_{i-1}
$$

$$
\ \big({\mathit\Gamma}_{K^{i}}^{a_{K^{i}}}\,=\,g_{0}^{a}\big)\wedge\big({\mathit\Delta}_{K^{i}}^{b_{K^{i}}}\,=\,g_{1}^{b}\big)
$$

$$
\ \mathrm{i.e.~}P r[\mathsf{a b o r t}_{i}]=\mathsf{n e g}|(\lambda)
$$ i
Lemma 8.2. *Let* op = del *then if the strong RSA assumption holds for* Ggen*,* Pr[*G*<sub>i</sub> <sub>1</sub>= 1]
Pr[*G*<sub>i</sub>= 1] + negl()*.*

$$
{\mathsf{o p}}^{i}\,=
$$

$$
\operatorname*{P r}[G_{i-1}=1]\leq
$$

$$
\operatorname*{P r}[G_{i}=1]+{\mathsf{n e g l}}(\lambda)
$$

i
Proof The same as the above case of op = mod holds.

$$
{\mathfrak{o p}}^{i}={\mathsf{m o d\ h o l d s}}
$$

i
Lemma 8.3. *Let* op = add *then* Pr[*G*<sub>i</sub> <sub>1</sub>= 1] = Pr[*G*<sub>i</sub>= 1]*.*

$$
{\mathfrak{o p}}^{i}={\mathfrak{a}}d d\ \,
$$

$$
\operatorname*{P r}[G_{i-1}\!=\!1]=\operatorname*{P r}[G_{i}=1]
$$

Proof *G*<sub>i</sub> <sub>1</sub>and *G*<sub>i</sub>are identical.

$$
G_{i-1}
$$

$$
G_{i}
$$

i
Lemma 8.4. *Let* op = cfrom *then for any PPT A in G*<sub>i</sub>*there exists an algorithm E such that*
Pr[*G*<sub>i</sub> <sub>1</sub>= 1] Pr[*G*<sub>i</sub>= 1] + negl() *of the strong RSA assumption holds.*

$$
{\mathfrak{o p}}^{i}={\mathfrak{c f r o}}m
$$

$$
G_{i}
$$

$$
\mathcal{E}
$$

$$
\operatorname*{P r}[G_{i-1}=1]\leq\operatorname*{P r}[G_{i}=1]+\mathsf{n e g l}(\lambda)
$$

Proof Let *E* be the extractor of PoKSubV⁰ protocol that corresponds to *A*. Since PoKSubV⁰
~iK 1 0 i 1 i iK 1
is knowledge sound, *E* outputs (Fi;Ki;i) such that VC*:* Ver⁰(pp*;*;K*; ~*F<sup>i</sup>*;*<sup>K</sup><sup>i</sup>) = 1 ^
K
i i iK 1 0 iK 1 i?i i
VC: Ver⁰(pp*;;K;* ~F<sup>i</sup>;i) = 1*^*j~Fij = n⁰, where = (;n). Since abort₁*;*abort₂*;:::;* abort<sub>i</sub> <sub>2</sub>
K
i 1 i 1
have not happen, from correctness of the *VDS* scheme it comes that = VC*:* Com⁰(pp*;* F).
<sub>i</sub>K <sub>1</sub> <sub>i</sub> <sub>1</sub>
From the rst verication equation above we get that under strong RSA assumption F F.
<sup>i</sup>
<sup>iK</sup> <sup>1</sup> <sup>i</sup>
From the second verication equation above we get that F <sub>i</sub>s an open<sub>i</sub>ng of. From the third
i
i iK 1
equation above we get that <sub>i</sub>s a digest for a le of s<sub>i</sub>ze *j*F *j*. From the last two points we get
i
i iK 1
that = VC*:* Com⁰(pp*;* F<sub>i</sub>).
So Pr[*G* = 1] Pr[*G* = 1] + negl().

$$
(\vec{\mathsf{F}}_{K^{i}}^{i-1},\pi_{K^{i}},\pi_{K^{i}}^{\prime})
$$

$$
\mathrm {V C}. \operatorname {V e r} ^ {\prime} \left(\mathrm {p p}, \delta^ {i - 1}, K ^ {i}, \vec {\mathrm {F}} _ {K ^ {i}} ^ {i - 1}, \pi_ {K ^ {i}}\right) = 1 \wedge
$$

$$
\mathsf{V C.V e r}^{\prime}(\mathsf{p p},\delta^{i},K^{i},\vec{\mathsf{F}}_{K^{i}}^{i-1},\pi_{K^{i}}^{\prime})=1\wedge\ |vec\\bar{{\mathsf{F}}}_{K^{i}}^{i-1}|=n^{\prime}
$$

$$
\delta^{i}=(\delta^{\star i},n^{i})
$$

$$
:2,\cdots.
$$

$$
\delta^{i-1}=\mathsf{V C.C o m}^{\prime}(\mathsf{p p},\mathsf{F}^{i-1})
$$

$$
\mathsf{F}_{K_{i}}^{i-1}\subseteq\mathsf{F}^{i-1}
$$

$$
\mathsf{F}_{K_{i}}^{i-1}
$$

$$
\delta^{i}
$$

$$
\delta^{i}
$$

$$
|\mathsf{F}_{K_{i}}^{i-1}|
$$

$$
\delta^{i}=\mathsf{V C.C o m}^{\prime}(\mathsf{p p},\mathsf{F}_{K^{i}}^{i-1})
$$

$$
\operatorname*{P r}[G_{i-1}=1]\leq\operatorname*{P r}[G_{i}=1]+\mathsf{n e g l}(\lambda).
$$

We conclude that in any case Pr[*G*<sub>i</sub> <sub>1</sub>= 1] Pr[*G*<sub>i</sub>= 1] + negl(). Since *jHj* = *‘* = poly()
with a hybrid argument we get that Pr[*G₀* = 1] Pr[*G*<sup>‘</sup>= 1] + negl(). But clearly *G*<sup>‘</sup>= 0 always
A
(since no abort has happened), and thus Pr[VDS-Security<sub>VDS</sub>() = 1] = *P* [*G₀* = 1] = negl().

$$
\operatorname*{P r}[G_{i-1}\,=\,1]\,\leq\,\operatorname*{P r}[G_{i}\,=\,1]\,+\,\mathsf{n e g l}(\lambda)
$$

$$
|\mathcal{H}|=\ell=\ \ \mathsf{p o l y}(\lambda)
$$

$$
\operatorname*{P r}[G_{0}=1]\leq\operatorname*{P r}[G_{\ell}=1]+\mathsf{n e g l}(\lambda)
$$

$$
G_{\ell}=0
$$

$$
\operatorname*{P r}[\mathsf{V}S\mathsf{-}\mathsf{S e c u r i t y}_{\mathsf{V D S}}^{\mathsf{A}}(\lambda)=1]=P[G_{0}=1]{\ =\ }{\mathsf{n e g l}}(\lambda)
$$

## 8.2 Our Second VDS Construction

To construct our second VDS scheme, denoted VDS₂, we build on our second SVC scheme from
section5.2. The main diculty that we face in turning our SVC into a VDS is the specializtionQ
i2[n]ei
phase of the CRS, i.e. the trusted generation of *U* = *g*. Although VDS schemes can support
a trusted setup phase, it can only be done once by the Bootstrap algorithm. However, *U* depends
on the current size of the le (though not on its content), meaning that normally at each addition
(or deletion) to the le it should be updated²². To solve this problem, we attach *U* to the VDS’s
digest (together with *n* for technical reasons), = ((*U;C*)*;n*).

$$
\mathsf{V D S_{2}}
$$

$$
U=g^{\tilde{\prod_{i\in[n]}e_{i}}}
$$

$$
\delta=((U,C),n)
$$

Then, *U* can be built progressively while the le is extended or reduced. Namely, when adding
new positions from the set *K* to the le, all *e*<sup>i</sup>’s in *K* are added to the accumulator, i.e. *U⁰*
Q
<sub>i2K</sub><sub>e</sub><sub>i</sub>
*U*. The denition of VDS security (def.7.6) ensures that the digest is evaluated honestly
Q
i2nei
which ensures that *U* has the correct form *U* = *g*.

$$
Utextstyle\prod_{i\in K}e_{i}
$$

$$
e_{i}^{3}
$$

$$
U^{\prime}\leftarrow
$$

$$
7.6)
$$

$$
U = g ^ {\prod_ {i \in n} e _ {i}}
$$

Finally, we make use of the dynamic properties of the [CF13,LM19] scheme (in which our
SVC builds) and the RSA Accumulator, to construct the VDS scheme. The latter is important if

<sup>22</sup>
Another solution would be to recompute it at the verication time, but it would require linear work, which
contradicts VDS requirements.

---

Q Q
i2[n]ei i2[n]nIei
one notice that *U* = *g;S*<sub>I</sub>= *g* r<sup>e</sup>semble an RSA Accumulator value and witness
respectively.

$$
U\,=\,g^{\prod_{i\in[n]}e_{i}},S_{I}\,=\,g^{\prod_{i\in[n]\setminus I}e_{i}}
$$

Our scheme VDS₂. In the following := ((*U;C*)*;n*), st :=<sub>I</sub>, where<sub>I</sub>:= (*S*<sub>I</sub>*;*<sub>I</sub>). Also, each
*e*<sub>i</sub>is computed as *e*<sub>i</sub>PrimeGen(*i*); so PrimeGen(*i*) is omitted for simplicity in the description.
VC*:* Agg*;*VC*:* Disagg are the aggregation and disaaggregation algorithms dened in section5.2. We
Q
j2InJej
highlight that possession of *S*<sub>I</sub>allows anyone to compute *S*<sub>J</sub>*S* for <sub>e</sub>ach *J I*, thus for
I
simplicity we omit explicitly refer to the procedure of computing any such *S*<sub>J</sub>.

$$
\mathsf{V D S_{2}}
$$

$$
\delta:=((U,C),n)
$$

$$
{=}\pi_{I}.
$$

$$
\pi_{I}:=\left(S_{I},\varLambda_{I}\right)
$$

$$
e_{i}
$$

$$
e_{i}\leftarrow{\mathsf r i m e G e n}(i)
$$

$$
S_{I}
$$

$$
J\subseteq I
$$

$$
S_{J}\gets S_{I}^{\prod_{j\in I\setminus J}e_{j}}
$$

$$
S J
$$

Bootstrap(1*;‘*)*!* (pp*;*<sub>0</sub>*;n₀;*st₀)generates a hidden order group G Ggen(1 ) and samples a
generator *g* $ G. It also determines a deterministic collision resistant function PrimeGen that
maps integers to primes of *‘* + 1 bits. Set *n₀* 0,<sub>0</sub>((1*;g*)*;n₀*) and st₀ *g*.

$$
(1^{\lambda},\ell)\to(\mathsf{p p},\delta_{0},n_{0},\mathsf{s t}_{0})
$$

$$
\mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda})
$$

$$
g\leftarrow\S\mathbb{G}
$$

$$
n_{0}\gets0,\,\delta_{0}\gets((1,g),n_{0})
$$

$$
\mathrm {s t} _ {0} \leftarrow g
$$

StrgNode*:* AddStorage(*;n;* st*;I;*F<sub>I</sub>*;Q;*F<sub>Q</sub>*;*<sub>Q</sub>)*!* (st⁰*;J;*F<sub>J</sub>)aggregates the parameters and the opening proofs

$$
\therefore \mathrm {A d d S t o r a g e} (\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, Q, \mathrm {F} _ {Q}, \pi_ {Q}) \rightarrow \left(\mathrm {s t} ^ {\prime}, J, \mathrm {F} _ {J}\right)
$$

$$
S_{I\cup Q}\leftarrow\mathbf{S h a m i r}\mathbf{T r i c k}(S_{I},S_{Q},\prod_{l\in I}e_{i},\prod_{l\in Q}e_{i})\ \mathrm{a n d}\ A_{I\cup Q}\leftarrow\mathsf{V C}A g g((S_{I},S_{J}),(I,\mathsf{F}_{I},A_{I}),(J,\mathsf{F}_{J},A_{J}))
$$

StrgNode*:* RmvStorage(*;n;* st*;I;*F<sub>I</sub>*;K*)*!* (st⁰*;J;*F<sub>J</sub>)disaggregates

$$
S_{J}\leftarrow S_{I}^{\prod_{i\in I\cap K}e_{i}}\ \ {\ {\mathrm{}{a n d}}}\ \varLambda_{J}\leftarrow{\ \ \mathsf{V C.D i s a g g}}(S_{J},I,\ \mathsf{F}_{I},\varLambda_{I},J)
$$

0 0J
StrgNode*:* PushUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;*)*!* (*;n⁰;*st⁰*;J;*F*;*)the algorithm works according to
the type of update operation op:
0K
{ op = mod: := (*K;*F).

$$
\flat,\mathsf{P u s h U p d a t e}(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},\mathsf{o p},\varDelta)\to(\delta^{\prime},n^{\prime},\mathsf{s t}^{\prime},J,\mathsf{F}_{J}^{\prime},\varUpsilon_{\varDelta})
$$

$$
- \mathrm {o p} = \mathrm {m o d}: \Delta := \left(K, \mathrm {F} _ {K} ^ {\prime}\right).
$$

$$
C^{\prime}\leftarrow C\cdot\prod_{i\in K}s_{i}^{\mathsf{F}_{i}^{\prime}-\mathsf{F}_{i}},\qquad U^{\prime}\leftarrow U,\qquad\varLambda_{I}^{\prime}\leftarrow\varLambda_{I},\qquad S_{I}^{\prime}\leftarrow S_{I}\qquad\varUpsilon_{\varDelta}\leftarrow(\mathsf{F}_{K},S_{K})
$$

$$
-\ {\mathsf{o0p}}={\mathsf{a d d}}:\varDelta:=(big,K,\ \mathsf{F}_{K}^{\prime}\big).
$$

$$
C ^ {\prime} \leftarrow C \cdot \prod_ {j \in K} S _ {j} ^ {\mathsf {F} _ {j}}, \quad U ^ {\prime} \leftarrow U ^ {\Pi_ {i \in K} e _ {i}}, \quad \Lambda_ {I} ^ {\prime} \leftarrow \Lambda_ {I}, \quad S _ {I} ^ {\prime} \leftarrow S _ {I}, \quad \Upsilon_ {\Delta} \leftarrow S _ {K}
$$

$$
- \mathrm {o p} = \mathrm {d e l}: \Delta := K.
$$

$$
C ^ {\prime} \leftarrow \frac {C}{\prod_ {j \in K} S _ {j} ^ {\mathsf {F} _ {j}}}, \quad U ^ {\prime} \leftarrow S _ {I} ^ {\prod_ {i \in I \backslash K} e _ {i}} = S _ {K}, \quad \Lambda_ {I} ^ {\prime} \leftarrow \Lambda_ {I} ^ {\prod_ {j \in K} e _ {j}}, \quad S _ {I} ^ {\prime} \leftarrow S _ {I}, \quad \gamma_ {\Delta} \leftarrow (\mathsf {F} _ {K}, S _ {K})
$$

0 0J
StrgNode*:* ApplyUpdate(*;n;* st*;I;*F<sub>I</sub>*;*op*;;*)*!* (*b;;n⁰;*st⁰*;J;*F)Again, it works according to
the type of update operation op:
<sub>Q</sub>

$$
{\sf p l y U p d a t e}(\delta,n,{\sf s t},I,\mathsf{F}_{I},{\sf o p},\varDelta,\varUpsilon_{\varDelta})\to(b,\delta^{\prime},n^{\prime},{\sf s t}^{\prime},J,\mathsf{F}_{,J}^{\prime})
$$

j2Kej
0K
{ op = mod: := (*K;*F) and := *S*<sub>K</sub>. Comput<sup>e</sup> *b* (*S* = *U*) and if *b* = 1:
K

$$
b\gets(S_{K}^{\prod_{j\in K}e_{j}}=U)
$$

$$
\varDelta:=(K,\mathsf{F}_{K}^{\prime})
$$

$$
\ T{\ }\!:=\ S{}_{K}
$$

$$
b=1
$$

$$
C^{\prime}\leftarrow C\cdot\prod_{i\in K}S_{i}^{\mathsf{F}_{i}^{\prime}-\mathsf{F}_{i}},\quad U^{\prime}\leftarrow U,\quad A_{I}^{\prime}\leftarrow\varLambda_{I}\cdot\prod_{j\in K\setminus I}\left(S_{j}^{1/\prod_{i\in I}e_{i}}\right)^{\mathsf{F}_{j}^{\prime}-\mathsf{F}_{j}},\:S_{I}^{\prime}\leftarrow S_{I}
$$

---

$$
-\mathrm{~o p}=\mathsf{a d d}\ \varDelta:=(K,\mathsf{F}_{K}^{\prime}){\mathrm{~a n d~}}\varUpsilon_{A}:=S_{K}.\ {\mathrm{C o m p u t e~}}b\leftarrow(S_{K}^{\prod_{j\in K}e_{j}}=U){\mathrm{~a n d~i f~}}b=1.
$$

$$
C ^ {\prime} \leftarrow C \cdot \prod_ {j \in K} S _ {j} ^ {\mathsf {F} _ {j}}, \quad U ^ {\prime} \leftarrow U ^ {\Pi_ {i \in K} e _ {i}}, \quad \Lambda_ {I} ^ {\prime} \leftarrow \Lambda_ {I} \cdot \prod_ {j \in K} \left(S _ {j} ^ {1 / \Pi_ {i \in I} e _ {i}}\right) ^ {\mathsf {F} _ {j}}, \quad S _ {I} ^ {\prime} \leftarrow S _ {I} ^ {\Pi_ {i \in K} e _ {i}}
$$

Q
1= eiQ
<sub>i2I</sub>
where *S* = Sham<sup>i</sup>rTrick(*S*<sub>I</sub>*;*S<sub>j</sub>; *e*<sub>i</sub>*;e*<sub>j</sub>) for each *j 2 K*.
j i2I
Q
e

$$
\begin{array}{l}{S_{j}^{1/\prod_{i\in I}e_{i}}=\mathbf{S h a m i r T r i c k}(S_{I},S_{j},\prod_{i\in I}e_{i},e_{j})}\\ \end{array}
$$

$$
j\in K
$$

$$
-\mathrm{\sf~o p}=\mathsf{d e l}\ \ varDeltaDelta:K K\ \mathrm a~n var\ var{}_{\Delta}:=(\mathsf{F}_{K},S_{K}).\ \mathrm{C o n p u t e}\ b\leftarrow(S_{K}^{\prod\_j in K K}e_{j}=U)\ \mathrm{a n d~i f}\ b=1
$$

$$
\begin{aligned}{}&{{}C^{\prime}\leftarrow\frac{C}{\prod_{j\in K}s_{j}^{\mathsf{F}_{j}}},\qquad U^{\prime}\leftarrow S_{K},}\\ {}&{{}A_{I}^{\prime}\leftarrow\frac{\Lambda_{I}^{\prod_{i\in K\cap I}e_{i}}}{\prod_{j\in K\cap I}\left(S_{j}^{1}\prod_{i\in K\cap I}e_{i}\right)^{\mathsf{F}_{j}}},\qquad S_{I}^{\prime}\leftarrow\mathbf{S h a m i r T r i c k}(S_{I},S_{K\setminus I},\prod_{i\in I}c_{i},\prod_{i\in K\backslash I}e_{i})}\\ \end{aligned}
$$

StrgNode*:* Retrieve(*;n;* st*;I;*F<sub>I</sub>*;Q*)*!* (F<sub>Q</sub>*;*<sub>Q</sub>)disaggregates

$$
(\delta , n, \mathrm {s t}, I, \mathrm {F} _ {I}, Q) \rightarrow (\mathrm {F} _ {Q}, \pi_ {Q})
$$

$$
S_{Q}\leftarrow S_{I}^{\prod_{i\in I\setminus Q}e_{i}}\ \ {operatorname a n n}\ \varLambda_{Q}\leftarrow\ \mathsf{V C}D i s a g g(S_{Q},I,\mathsf{F}_{I},\varLambda_{I},Q)
$$

The algorithms for client nodes are:

ClntNode*:* VerRetrieve(*;Q;*F<sub>Q</sub>*;*<sub>Q</sub>)*! b* output

$$
(left(\delta,Q,\mathsf{F}_{Q},\pi_{Q})\to b
$$

$$
b\leftarrow\mathsf{V C.V e r}(\mathsf{p p},C,Q,\mathsf{F}_{Q},\varLambda_{Q})\wedge S_{Q}^{\prod_{i\in Q}e_{i}}=U
$$

$$
(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},\mathsf{o p},\varDelta,\varUpsilon,\varUpsilon_{\varDelta})
$$

AggregateCerticates(*;* (*I;*F<sub>I</sub>*;*<sub>I</sub>)*;* (*J;*F<sub>J</sub>*;*<sub>J</sub>))*!*<sub>K</sub>return

$$
\left(\delta,(I,\mathsf{F}_{I},\pi_{I}),(J,\mathsf{F}_{J},\pi_{J})\right)\to\pi_{K}
$$

$$
S _ {I \cup J} \leftarrow \operatorname {S h a m i r T rick} \left(S _ {I}, S _ {J}, \prod_ {i \in I} e _ {i}, \prod_ {i \in J} e _ {i}\right) \text {a n d} \Lambda_ {K} \leftarrow \mathrm {V C}. \mathrm {A g g} \left((S _ {I}, S _ {J}), (I, \vec {\mathbf {F}} _ {I}, \Lambda_ {I}), (J, \vec {\mathbf {F}} _ {J}, \Lambda_ {J})\right)
$$

We note that we do not dene an ecient StrgNode*:* CreateFrom operation for the VDS₂ construction. While general-purpose SNARKs would work to achieve this result, they would be extremely
expensive. We leave it as an open problem to nd an ecient arguments of knowledge of subvector
opening for this scheme.

$$
\mathsf{V D S_{2}}
$$

Theorem 8.3(VDS₂). *Let* G Ggen(1 ) *be a hidden order group where the strong Distinct-*
*Prime-Product Root and the Low Order assumptions hold. Then the* VDS *scheme presented above*
*is a correct and secure Veriable Decentralized Storage scheme.*

$$
\mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda})
$$

$$
(\mathsf{V D S}_{2})
$$

The intuition of the above theorem is as follows: the VDS scheme can be seen as preserving
and updating a vector commitment *C* and an RSA Accumulator *U*. So correctness of VDS comes
from correctness of the updatable vector commitment SVC and correctness of updates of the RSA
Accumulator (see [BBF19]). Similarly, security comes from security of SVC and the RSA accumulator’s security, which in turn rely on the strong distinct-prime-product root assumption and the strong RSA assumption respectively. Note that strong Distinct-Prime-Product Root implies strong
RSA (the opposite also holds in RSA groups).

Recall that *U* is an RSA accumulator of all *e*<sub>i</sub>’s and is used to verify *S*<sub>I</sub>’s. The RSA accumulator’s
security demands that the accumulated value *U* is honestly computed, which is ensured in the VDS
setting since we assume a valid history. So given a valid history one knows that<sub>Q</sub>*U* is of correct
i2[n]ei
form (i.e. *U* = *g*) a<sub>n</sub>d th<sub>e</sub>n can securely check that *S*<sub>I</sub>is of correct form (by checking
Q
<sub>i2I</sub><sub>e</sub><sub>i</sub>
*S* = *U*), which is ensured from RSA Accumulator’s security. After checking the validity of
I
*S*<sub>I</sub>it all boils down to position binding of the vector commitment. To conclude, the gap between
position binding of the original VC and security of our VDS construction is to ensure that *S*<sub>I</sub>is
well formed, which in turn relies on the correct form of *U*.

$$
S_{I}\,^{\prime}\mathrm{S}
$$

$$
e_{i}
$$

$$
S_{I}
$$

$$
U\,=\,g^{\prod_{i\in[n]}e_{i}})
$$

$$
S_{I}^{\prod_{i\in I}e_{i}}=U]
$$

$$
S_{I}
$$

$$
S_{I}
$$

$$
U
$$

## 8.3 Eciency and Comparison

In Table3we provide a detailed eciency analysis and comparison of the two VDS schemes, VDS₁
and VDS₂, proposed in the two earlier sections.

$$
\mathsf{V D S}_{1}
$$

$$
\mathsf{V D S_{2}}
$$

In terms of performances, the two schemes do similarly, though VDS₂ outperforms the rst one
by a logarithmic factor. Its eciency advantage comes from the fact that operations are not bit-bybit as in the rst one. More in detail, in VDS₁ most of the operations require one exponentiation
with an-bit prime for each bit and each position of the suble, roughly *O*(*‘ jIj*) group
operations. In VDS₂, the main overhead is related to handling the distributed parameters *fS*<sub>i</sub>*g*.
In fact, computing *S*<sub>i</sub>for each *i 2 I*, given *S*<sub>I</sub>takes *O*(*I* log *jIj*) exponentiations with (*‘* + 1)-bit
primes, roughly *O*(*‘ jIj* log *jIj*) group operations.

$$
\mathsf{V D S_{2}}
$$

$$
\mathsf{V D S}_{1}
$$

$$
O(\ell\,\cdot\,|I|\,\cdot\,\alpha)
$$

$$
\mathrm {V D S} _ {2}
$$

$$
\left\{S_{i}\right\}
$$

$$
i\in I
$$

$$
S_{I}
$$

$$
O(I\log|I|)
$$

$$
O(\ell\cdot|left|I|\cdot\log|I|)
$$

To compare the two methods, recall that is at least log(*‘n*) (since we need at least *‘n* distinct
primes), which means that VDS₁ has a (logarithmic) dependence on the size of the le. On the
other hand, VDS₂’s cost depends only on the size of the suble that is processed. Hence, since
*>* log(*‘n*) *>* log(*n*) log(*jIj*) the VDS₂ always outperforms VDS₁ (see Table3).

$$
\alpha
$$

$$
\log(\ell n)
$$

$$
\mathsf{V D S_{1}}
$$

$$
\mathsf{V D S_{2}}
$$

$$
a>\log(\ n)>\log(n)\geq\log(\ \ I
$$

$$
\mathsf{V D S}_{1}
$$

$$
\mathsf{V D S_{2}}
$$

Another notable dierence regards the StrgNode*:* PushUpdate algorithm for op = mod. In VDS₂,
the running time depends solely on the size of the update, whereas in VDS₁ it depends on the size
of the entire suble stored locally. This can be a huge dierence for nodes that decide to store large
portions, and it constitutes a major theoretical (and practical) improvement of VDS₂ over VDS₁.

$$
{\mathsf{o p}}={\mathsf{m o d}}
$$

$$
\mathsf{V D S_{2}}
$$

$$
\mathsf{V D S_{1}}
$$

$$
\mathsf{V D S_{2}}
$$

$$
\mathsf{V D S_{1}}
$$

In terms of security, VDS₁ is based on a weaker assumption, over groups of unknown order, than
VDS₂ (although for the specic case of RSA groups the two assumptions are equivalent). Finally, in
terms of functionality, VDS₁ is the only scheme that supports eciently the StrgNode*:* CreateFrom
functionality and the (compact) Proofs of Data Possession; this is thanks to its compatibility with
the ecient succinct arguments of knowledge that we propose in section6.

$$
\mathsf{V D S}_{1}
$$

$$
\mathsf{V D S_{2}}
$$

$$
\mathsf{V D S_{1}}
$$

---

| Metric | VDS1 | VDS2 |
| --- | --- | --- |
| Bootstrap | O(1) | O(1) |
| |pp| | 3|G| | 1|G| |
| Digest |δ| | 2|G|+log|F| | 2|G|+log|F| |
| Storage Node storing(I,FI) |  |  |
| State |stI| | 2|G| | 2|G| |
| StrgNode.AddStorage(K) | O(λ·α·(|I|+|K|)) | O(λ·(|I|log|I|+|K|log|K|)) |
| StrgNode.RmvStorage(K) | O(λ·α·|K|) | O(λ·|K|log|K|) |
| StrgNode.CreateFrom(J) | O(λ·α·|I|) | no1 |
| |YJ| | 9|G|+2|Z2λ| | no1 |
| mod | O(λ·α·|I|) | O(λ·|Δ|log|Δ|) |
| add | O(λ·α·|Δ|) | O(λ·|Δ|log|Δ|) |
| del | O(λ·α·(|I|-|Δ|)) | O(λ·(|I|-|Δ|)+|Δ|log|Δ|)) |
| |YΔ| | O(|Δ|)+2|G| | O(|Δ|)+1|G| |
| mod,del | ∅ | 1 |
| add | O(λ·α·(|I|+|Δ|)) | O(λ·(|I|+|Δ|log|Δ|)) |
| mod | O(λ·α·(|I|+|Δ|)) | O(λ·(|I|+|Δ|log|Δ|)) |
| add | O(λ·α·(|I|+|Δ|)) | O(λ·(|I|+|Δ|log|Δ|)) |
| del | O(λ·α·(|I|-|Δ|)) | O(λ·(|I|-|Δ|)+|Δ|log|Δ|)) |
| StrgNode.Retrieve(Q) | O(λ·α·(|I|-|Q|)) | O(λ·(|I|-|Q|)log(|I|-|Q|)) |
| |πQ| | 2|G| | 2|G| |
| Client Node |  |  |
| CIntNode.GetCreate(J) | O(λ·α·|J|) | no1 |
| CIntNode.VerRetrieve(Q) | O(λ·α·|Q|) | O(λ·|Q|log|Q|) |
| CIntNode.ApplyUpdate(Δ)(mod,add,del) | O(λ·α·|Δ|) | O(λ·|Δ|log|Δ|) |
| AggregateCertificates(I,J) | O(λ·α·(|I|+|J|)) | O(λ·(|I|log|I|+|J|log|J|)) |
| PoR | yes | yes |
| PDP | yes | no1 |

$$
\mathsf{V D S_{1}}
$$

$$
\mathsf{V D S_{2}}
$$

$$
O(1)
$$

$$
O(1)
$$

$$
3\mid mathbb G
$$

$$
1\mid mathbb G
$$

$$
2\ |\mathbb{G}|+\log|\mathsf{F}|
$$

$$
2\ |\mathbb{G}|+\log|\mathbb{F}|
$$

$$
(I,\mathsf{F}_{I})
$$

$$
2\mid|\mathbb{G}|
$$

$$
2\mid mathbb G
$$

$$
O\big(\ell\cdot\alpha\cdot(|I|+|K|)\big)
$$

$$
O(\ell\cdot\ (|I|\log|I|+|K|\log|K|)\,)
$$

$$
O(\ell\cdot\alpha\cdot|K|)
$$

$$
O(\ell\cdot|K|\log|K|)
$$

$$
O(\ell\cdot\alpha\cdot|I|)
$$

$$
|T_{J}|
$$

$$
9\ |\mathbb{G}|+2\ |\mathbb{Z}_{2^{\lambda}}|
$$

$$
\mathrm {n o} ^ {1}
$$

$$
O(\ell\cdot\alpha\cdot|I|)
$$

$$
O \left(\ell \cdot | \Delta | \log | \Delta |\right)
$$

$$
O(\ell\cdot\alpha\cdot|\varDelta|)
$$

$$
O(\ell\cdot|\varDelta|\log|\varDelta)|
$$

$$
O \left(\ell \cdot \alpha \cdot \left(| I | - | \Delta |\right)\right)
$$

$$
O \left(\ell \cdot \left(| I | - | \Delta | + | \Delta | \log | \Delta |\right)\right)
$$

$$
O(|\varDelta|)+2\cdot|\mathbb{G}|
$$

$$
O(|\varDelta|)+1\cdot|\mathbb{G}|
$$

$$
\left| \gamma_ {\Delta} \right|
$$

$$
O \left(\ell \cdot \alpha \cdot \left(| I | + | \Delta |\right)\right)
$$

$$
\overline{{O(\ell\cdot(|I|+|\varDelta|\log|\varDelta|)}})
$$

$$
O(\ell\cdot\alpha\cdot|\varDelta|)
$$

$$
O(\ell\cdot(|I|+|\varDelta|\log|\varDelta|))
$$

$$
O \left(\ell \cdot \alpha \cdot \left(| I | + | \Delta |\right)\right)
$$

$$
O \left(\ell \cdot \left(| I | + | \Delta | \log | \Delta |\right)\right)
$$

$$
O\big(\ell\cdot\alpha\cdot\big( vert I|\ -\vert Q\vert\big)\big)
$$

$$
O(\ell\cdot\ (left|{I}|-|{Q}|)\log\bigl(|{I}|-|{Q}|)\bigr)
$$

$$
\mathrm{~n~o~}^{1}
$$

$$
O(\ell\cdot\alpha\cdot|J|)
$$

$$
O(\ell\cdot\alpha\cdot|Q|)
$$

$$
O(\ell\cdot|Q|\operatorname{l o g}|Q|)
$$

$$
O(\ell\cdot\alpha\cdot|\varDelta|)
$$

$$
O(\ell\cdot|\varDelta|\operatorname{l o g}|\varDelta|)
$$

$$
O\big(\ell\cdot\alpha\cdot\ (|I|+|J|)\big)
$$

$$
O(\ell\cdot\left(\left|I\right|\!_{0}\!_{\!}^{\!{\mathfrak{g}}}\left|I\right|+\left|J\right|\!_{0}\!_{\!}{\!{\mathfrak{g}}}\left|J\right|\right))
$$

$$
\mathrm{y e s}
$$

$$
\mathrm{~n~o~}^{1}
$$

Table 3. Comparison between our two VDS schemes. The running time is expressed in number of G-group operations. Notation for the sets of positions: *I* are the ones held by the storage node, *K* the ones added or removed
from local storage by the storage node, *J* the ones used to create the le in StrgNode*:* CreateFrom, the updated
ones, and *Q* the ones of a retrieval query. In VDS₁, denotes the size of the primes (returned by PrimeGen); so
‘ n
log(*n‘*) where *n* is the size of the le and *‘* the bit-size of each position (i.e. F *2* (*f*0*;* 1*g*)).

$$
\ \mathsf{V D S_{1}}.
$$

$$
\alpha\geq\log(n\ell)
$$

$$
\mathsf{F}\in(\{0,1\}^{\ell})^{n})
$$

<sup>1</sup>
Such a protocol exists but it is either inecient for the prover (SNARKs) or it has a large overhead in communication complexity (-protocols or PoKE -based ones).

## 9 Experimental Evaluation

We have implemented in Rust our new SVC scheme of section5.1(with and without preprocessing)
and the recent SVC of [BBF19] (referred as BBF in what follows). Here we discuss an experimen-

---

23
tal evaluation of these three schemes. Below is a summary of the comparison, details of the
experiments are in AppendixF.

{ Our SVC construction is faster in opening and verication than BBF (up to 2*:* 5 and 2*:* 3 faster
respectively), but at the cost of a slower commitment stage (up to 6 slower). These dierences
tend to atten for larger vectors and opening sizes.

{ Our SVC construction with preprocessing allows for extremely fast opening times compared to
non-preprocessing constructions. Namely, it can reduce the running time by several orders of
magnitude for various choices of vector and opening sizes, allowing to obtain practical opening
times|of the order of seconds|that would be impossible without preprocessing|of the order of
20
hundred of seconds. In a le of 1 Mibit (2 bits), preprocessing reduces the time to open 2048
bits from one hour to less than 5 seconds! This ecient opening, however, comes at the cost of a
one-time preprocessing (during commitment) and higher storage requirements. We discuss how to
mitigate these space requirements by trading for opening time and/or communication complexity
later in this section. We stress that it is thanks to the incremental aggregation property of our
construction that allows these tradeos (they are not possible in BBF with preprocessing).

$$
\ 2^{20}
$$

{ Although our SVC construction with preprocessing has an expensive commitment stage, this
tends to be amortized throughout very few openings²⁴, as few as 30 (see Figure9in AppendixF).
These eects are particularly signicant over a higher number of openings: over 1000 openings
our SVC construction with preprocessing has an amortized cost of less than 6 seconds, while our
SVC construction and BBF have amortized openings above 90 seconds.

Mitigating Space Requirements for Preprocessing Construction The experiments illustrated so far show the benet of using preprocessing to speedup opening time. This comes at the
cost of storing an auxiliary information|*N* openings|which, in spite of being much smaller than
in BBF, can still be quite large. Here we discuss two ways to mitigate this storage cost, which can
be used either separately or together.

{Hashing in blocks. Let us recall that by selecting a block size *‘* = 2 (e.g., 256) one can
combine our VC with a collision-resistant hash function and support larger vectors at virtually
the same cost. Concretely, given a vector *~v* of *N* blocks, each of *‘*<sub>H</sub>bits, one can obtain a vector
‘ N
*~v⁰ 2* (*f*0*;* 1*g*) by hashing each *‘*<sub>H</sub>-bits block into a *‘*-bits one. The downside of this approach is
that subvector openings with respect to the original vector *~v* are less ne grained. On the good
side, though, one gets that the eciency of a VC for a vector of size *N ‘*<sub>H</sub>is virtually the same²⁵ as
the one for a VC for a vector of size *N* 2. For example, by selecting *‘*<sub>H</sub>= 2 Kibit our timings for a
vector of 262 144 bits would work for one of 1 Mibit. This would yield a committing/preprocessing
time of roughly 10 minutes. These advantages also translate opening times: for example, if we
11
expect openings of roughly *M* = 2 bits we can expect a virtually instantaneous opening time
14
(as we just need to look up a cached precomputed proof). A larger opening size such as *M* = 2
17
(resp. *M* = 2) bits, would yield a running time of roughly 4 seconds (resp. 70 seconds).

$$
\ell_{H}
$$

$$
\vec{v}^{\prime}\in(\{0,1\}^{\ell})^{N}
$$

$$
\ell_{H}
$$

$$
\vec{v}
$$

$$
N\!\cdot\!\ell_{H}
$$

$$
\ell_{H}=2\;\mathrm{K i b i t}
$$

$$
M=2^{11}
$$

$$
M=2^{14}
$$

$$
M=2^{17})
$$

<sup>23</sup>
We did not include BBF with precomputation in our experimental evaluation because this scheme has worse
performances than our preprocessing construction in terms of both required storage and running time. We elaborate
on this in AppendixF

<sup>24</sup>
Amortized opening time roughly represents how computationally expensive a scheme is \in total" throughout all
its operations. *Amortized opening time for m openings* is the cost of one commitment plus the cost of *m* openings,
all averaged over the *m* openings.

<sup>25</sup>
This is because the cost of hashing is negligible compared to group operations.

---

{Selecting larger precomputed chunks. Another possibility to reduce storage is to precompute less openings by storing more aggregated openings, namely instead of an opening for every
chunk of *‘* bits, store one opening for every chunk of *B ‘* bits. This technique requires a bit
more computation in order to compute disaggregations|about *m*(*B* 1) G operations in the
worst case for *m* positions (cf. SectionB)|but opens the way to various tradeos to be explored.
For instance, one could use certain application-dependent heuristics to choose which positions
to precompute aggregated. As an example in the VC application to proofs of space and replication [Fis19] one opens a set of randomly chosen positions, and for each of them, also a set of
26
predetermined positions.

## predetermined positions. 26

## Acknowledgements

We thank Ben Fisch for valuable clarications about the notions of Proof of Retrievable Commitment and Proof of Replication, and Justin Drake for pointing out the need (due to the attack
discussed in [BBF18]) of using a hash function mapping into Primes(2) in the Fiat-Shamir transformation when making our succinct arguments of knowledge non-interactive.

Research leading to these results has been partially supported by the Spanish Government under
projects SCUM (ref. RTI2018-102043-B-I00), CRYPTOEPIC (refs. ERC2018-092822, EUR2019-
103816), and SECURITAS (ref. RED2018-102321-T), by the Madrid Regional Government under
project BLOQUES (ref. S2018/TCS-4339), and by research gifts from Protocol Labs.

## References

<sup>+</sup>
ABC 07.G. Ateniese, R. C. Burns, R. Curtmola, J. Herring, L. Kissner, Z. N. J. Peterson, and D. Song. Provable
data possession at untrusted stores. In P. Ning, S. De Capitani di Vimercati, and P. F. Syverson, editors,
*ACM CCS 2007*, pages 598{609. ACM Press, October 2007.
<sup>+</sup>
ABC 11.G. Ateniese, R. Burns, R. Curtmola, J. Herring, O. Khan, L. Kissner, Z. Peterson, and D. Song. Remote
Data Checking Using Provable Data Possession. *ACM Trans. Inf. Syst. Secur.*, 14(1):12:1{12:34, June
2011.
BBF18.D. Boneh, B. Bunz, and B. Fisch. A Survey of Two Veriable Delay Functions. Cryptology ePrint Archive,
Report 2018/712, 2018. https://eprint.iacr.org/2018/712.
BBF19.D. Boneh, B. Bunz, and B. Fisch. Batching Techniques for Accumulators with Applications to IOPs and
Stateless Blockchains. In A. Boldyreva and D. Micciancio, editors, *CRYPTO 2019, Part I*, volume 11692
of *LNCS*, pages 561{586. Springer, Heidelberg, August 2019.
BCS16.E. Ben-Sasson, A. Chiesa, and N. Spooner. Interactive Oracle Proofs. In M. Hirt and A. D. Smith, editors,
*TCC 2016-B, Part II*, volume 9986 of *LNCS*, pages 31{60. Springer, Heidelberg, October / November 2016.
Bd94.J. C. Benaloh and M. de Mare. One-Way Accumulators: A Decentralized Alternative to Digital Sinatures
(Extended Abstract). In T. Helleseth, editor, *EUROCRYPT’93*, volume 765 of *LNCS*, pages 274{285.
Springer, Heidelberg, May 1994.
BGR12.K. Brogle, S. Goldberg, and L. Reyzin. Sequential Aggregate Signatures with Lazy Verication from
Trapdoor Permutations - (Extended Abstract). In X. Wang and K. Sako, editors, *ASIACRYPT 2012*,
volume 7658 of *LNCS*, pages 644{662. Springer, Heidelberg, December 2012.
BGV11.S. Benabbas, R. Gennaro, and Y. Vahlis. Veriable Delegation of Computation over Large Datasets. In
P. Rogaway, editor, *CRYPTO 2011*, volume 6841 of *LNCS*, pages 111{131. Springer, Heidelberg, August
2011.
BH01.J. Buchmann and S. Hamdy. A Survey on *f*IQ*g* Cryptography, 2001.
BP97.N. Bari and B. Ptzmann. Collision-Free Accumulators and Fail-Stop Signature Schemes Without Trees.
In W. Fumy, editor, *EUROCRYPT’97*, volume 1233 of *LNCS*, pages 480{494. Springer, Heidelberg, May
1997.
<sup>26</sup>
There, each vector entry is the node of a DAG and one opens a set of randomly chosen nodes and for each of them

a given number of parents.

---

CF13.D. Catalano and D. Fiore. Vector Commitments and Their Applications. In K. Kurosawa and G. Hanaoka,
editors, *PKC 2013*, volume 7778 of *LNCS*, pages 55{72. Springer, Heidelberg, February / March 2013.
CL02.J. Camenisch and A. Lysyanskaya. Dynamic Accumulators and Application to Ecient Revocation of
Anonymous Credentials. In M. Yung, editor, *CRYPTO 2002*, volume 2442 of *LNCS*, pages 61{76. Springer,
Heidelberg, August 2002.
CMS99.C. Cachin, S. Micali, and M. Stadler. Computationally Private Information Retrieval with Polylogarithmic
Communication. In J. Stern, editor, *EUROCRYPT’99*, volume 1592 of *LNCS*, pages 402{414. Springer,
Heidelberg, May 1999.
CS99.R. Cramer and V. Shoup. Signature Schemes Based on the Strong RSA Assumption. In J. Motiwalla and
G. Tsudik, editors, *ACM CCS 99*, pages 46{51. ACM Press, November 1999.
CSWH01.I. Clarke, O. Sandberg, B. Wiley, and T. W. Hong. *Freenet: A Distributed Anonymous Information Storage*
*and Retrieval System*, pages 46{66. Springer Berlin Heidelberg, Berlin, Heidelberg, 2001.
DG20.S. Dobson and S. D. Galbraith. Trustless Groups of Unknown Order with Hyperelliptic Curves. Cryptology
ePrint Archive, Report 2020/196, 2020. https://eprint.iacr.org/2020/196.
DK02.I. Damgard and M. Koprowski. Generic Lower Bounds for Root Extraction and Signature Schemes in
General Groups. In L. R. Knudsen, editor, *EUROCRYPT 2002*, volume 2332 of *LNCS*, pages 256{271.
Springer, Heidelberg, April / May 2002.
Fis18.B. Fisch. PoReps: Proofs of Space on Useful Data. Cryptology ePrint Archive, Report 2018/678, 2018.
https://eprint.iacr.org/2018/678.
Fis19.B. Fisch. Tight Proofs of Space and Replication. In Y. Ishai and V. Rijmen, editors, *EUROCRYPT 2019,*
*Part II*, volume 11477 of *LNCS*, pages 324{348. Springer, Heidelberg, May 2019.
FS87.A. Fiat and A. Shamir. How to Prove Yourself: Practical Solutions to Identication and Signature Problems. In A. M. Odlyzko, editor, *CRYPTO’86*, volume 263 of *LNCS*, pages 186{194. Springer, Heidelberg,
August 1987.
GHR99.R. Gennaro, S. Halevi, and T. Rabin. Secure Hash-and-Sign Signatures Without the Random Oracle.
In J. Stern, editor, *EUROCRYPT’99*, volume 1592 of *LNCS*, pages 123{139. Springer, Heidelberg, May
1999.
<sup>+</sup>
GKM 18.J. Groth, M. Kohlweiss, M. Maller, S. Meiklejohn, and I. Miers. Updatable and Universal Common Reference Strings with Applications to zk-SNARKs. In H. Shacham and A. Boldyreva, editors, *CRYPTO 2018,*
*Part III*, volume 10993 of *LNCS*, pages 698{728. Springer, Heidelberg, August 2018.
GRWZ20.S. Gorbunov, L. Reyzin, H. Wee, and Z. Zhang. Pointproofs: Aggregating Proofs for Multiple Vector
Commitments. Cryptology ePrint Archive, Report 2020/419, 2020. https://eprint.iacr.org/2020/419.
JK07.A. Juels and B. S. Kaliski Jr. Pors: proofs of retrievability for large les. In P. Ning, S. De Capitani di
Vimercati, and P. F. Syverson, editors, *ACM CCS 2007*, pages 584{597. ACM Press, October 2007.
KZG10.A. Kate, G. M. Zaverucha, and I. Goldberg. Constant-Size Commitments to Polynomials and Their
Applications. In M. Abe, editor, *ASIACRYPT 2010*, volume 6477 of *LNCS*, pages 177{194. Springer,
Heidelberg, December 2010.
Lab17.P. Labs. Filecoin: A Decentralized Storage Network, 2017. https://filecoin.io/filecoin.pdf.
Lip12.H. Lipmaa. Secure Accumulators from Euclidean Rings without Trusted Setup. In F. Bao, P. Samarati,
and J. Zhou, editors, *ACNS 12*, volume 7341 of *LNCS*, pages 224{240. Springer, Heidelberg, June 2012.
LM19.R. W. F. Lai and G. Malavolta. Subvector Commitments with Application to Succinct Arguments. In
A. Boldyreva and D. Micciancio, editors, *CRYPTO 2019, Part I*, volume 11692 of *LNCS*, pages 530{560.
Springer, Heidelberg, August 2019.
LMRS04.A. Lysyanskaya, S. Micali, L. Reyzin, and H. Shacham. Sequential Aggregate Signatures from Trapdoor
Permutations. In C. Cachin and J. Camenisch, editors, *EUROCRYPT 2004*, volume 3027 of *LNCS*, pages
74{90. Springer, Heidelberg, May 2004.
LRY16.B. Libert, S. C. Ramanna, and M. Yung. Functional Commitment Schemes: From Polynomial Commitments to Pairing-Based Accumulators from Simple Assumptions. In I. Chatzigiannakis, M. Mitzenmacher, Y. Rabani, and D. Sangiorgi, editors, *ICALP 2016*, volume 55 of *LIPIcs*, pages 30:1{30:14. Schloss
Dagstuhl, July 2016.
LY10.B. Libert and M. Yung. Concise Mercurial Vector Commitments and Independent Zero-Knowledge Sets
with Short Proofs. In D. Micciancio, editor, *TCC 2010*, volume 5978 of *LNCS*, pages 499{517. Springer,
Heidelberg, February 2010.
Mer88.R. C. Merkle. A Digital Signature Based on a Conventional Encryption Function. In C. Pomerance,
editor, *CRYPTO’87*, volume 293 of *LNCS*, pages 369{378. Springer, Heidelberg, August 1988.
OWB19.A. Ozdemir, R. S. Wahby, and D. Boneh. Scaling Veriable Computation Using Ecient Set Accumulators.
Cryptology ePrint Archive, Report 2019/1494, 2019. https://eprint.iacr.org/2019/1494.

---

Sha83.A. Shamir. On the Generation of Cryptographically Strong Pseudorandom Sequences. *ACM Trans.*
*Comput. Syst.*, 1(1):38{44, 1983.
STY01.T. Sander, A. Ta-Shma, and M. Yung. Blind, Auditable Membership Proofs. In Y. Frankel, editor, *FC*
*2000*, volume 1962 of *LNCS*, pages 53{71. Springer, Heidelberg, February 2001.
<sup>+</sup>
TAB 20.A. Tomescu, I. Abraham, V. Buterin, J. Drake, D. Feist, and D. Khovratovich. Aggregatable Subvector
Commitments for Stateless Cryptocurrencies. Cryptology ePrint Archive, Report 2020/527, 2020. https:
//eprint.iacr.org/2020/527.
Tam03.R. Tamassia. Authenticated Data Structures. In G. Di Battista and U. Zwick, editors, *Algorithms - ESA*
*2003*, pages 2{5, Berlin, Heidelberg, 2003. Springer Berlin Heidelberg.
Wes18.B. Wesolowski. Ecient veriable delay functions. Cryptology ePrint Archive, Report 2018/623, 2018.
https://eprint.iacr.org/2018/623.

## A PoProd protocol for Union of RSA Accumulators

Let G be a an hidden order group as generated by Ggen, and let *g₁;g₂;g₃ 2* G be three honestly
sampled random generators. A more straightforward succinct argument of knowledge for the union
of RSA Accumulators is for the following relation

$$
g_{1},g_{2},g_{3}\in\mathbb{G}
$$

$$
R_{\mathsf{P o P r o d}}=\left\{((A,B,C),(a,b))\in\mathbb{G}^{3}\times\mathbb{Z}^{2}\::\:A=g_{1}^{a}\wedge B=g_{2}^{b}\wedge C=g_{3}^{a\cdot b}\:\:\right\}
$$

Our protocol PoProd is described below.

## PoProd protocol

Setup(1 ) : run G $ Ggen(1 ), *g₁;g₂;g₃* $ G, set crs := (G*;g₁;g₂;g₃*).
<u>Prover’s input:</u> (crs*;* (*A;B;C*)*;* (*a;b*<u>)). Verier’s input:</u> (crs*;* (*A;B;C*)).
<u>V</u><u>!</u> <u>P</u>: *‘* $ Primes()
<u>P</u><u>!</u> <u>V</u>: := ((*Q*<sub>A</sub>*;Q*<sub>B</sub>*;Q*<sub>C</sub>)*;r*<sub>a</sub>*;r*<sub>b</sub>) computed as follows
{ (*q*<sub>a</sub>*;q*<sub>b</sub>*;q*<sub>c</sub>) (*ba=‘c; bb=‘c; bab=‘c*)
{ (*r*<sub>a</sub>*;r*<sub>b</sub>) (*a* mod *‘;b* mod *‘*)
qa qbqc
{ (*Q*<sub>A</sub>*;Q*<sub>B</sub>*;Q*<sub>C</sub>) := (*g₁;g₂;g₃*)
<u>V(crs</u><u>;</u> <u>(</u><u>A;B;C</u><u>)</u><u>;‘;</u><u>):</u>
{ Compute *r*<sub>c</sub>*r*<sub>a</sub>*r*<sub>b</sub>mod *‘*
‘ ra ‘ rb ‘ rc
<u>{ Output 1 i</u> <u>r</u><sub>a</sub><u>;r</u><sub>b</sub><u>2</u> <u>[</u><u>‘</u><u>]</u> <u>^ Q g₁</u> <u>=</u> <u>A ^ Q g₂</u> <u>=</u> <u>B ^ Q g₃</u> <u>=</u> <u>C</u>
A B C

$$
\mathtt{S e t u p}(1^{\lambda})\ \colon{\tt r u n}\ \mathbb{G}\hookleftarrow\mathtt{G g e n}(1^{\lambda}),\;g_{1},g_{2},g_{3}\hookleftarrow\mathtt{G},\;{\tt s e t}\ {\tt c r s}:=(\mathbb{G},g_{1},g_{2},g_{3}).
$$

$$
(\mathsf{c r s},(A,B,C),(a,b))
$$

$$
(mathsf c r r,(A,B,C))
$$

$$
\underline{{\mathsf{V}}\to\mathsf{P}}:\ell\leftarrow\mathfrak{S}P\ m e s(\lambda)
$$

$$
\underline {{\mathrm {P} \rightarrow \mathrm {V}}}: \pi := \left(\left(Q _ {A}, Q _ {B}, Q _ {C}\right), r _ {a}, r _ {b}\right)
$$

$$
-\ (q_{a},q_{b},q_{c})\leftarrow(\lfloor a/\ell\rfloor,\lfloor b/\ell\rfloor,\lfloor a b/\ell\rfloor)
$$

$$
- \left(r _ {a}, r _ {b}\right) \leftarrow (c
$$

$$
-\ (Q_{A},Q_{B},Q_{C}):=(g_{1}^{q_{a}},g_{2}^{q_{b}},g_{3}^{q_{c}})
$$

$$
\mathsf{V}(\mathsf{c r s},(A,B,C),\ell,\pi)
$$

$$
- \mathrm {C o m p u t e} r _ {c} \leftarrow r _ {a} \cdot r _ {b}
$$

To prove the security of our protocol we rely on the adaptive root assumption and, in a nonblack-box way, on the knowledge extractability of the PoKE protocol from [BBF19]. The latter is
proven in the generic group model for hidden order groups (where also the adaptive root assumption
holds).

$$
\mathsf{P o K E}^{*}
$$

Theorem A.1. *The* PoProd *protocol is an argument of knowledge for R*<sub>PoProd</sub>*in the generic group*
*model.*

$$
R_{\mathsf P o\mathsf P r d}
$$

The proof is quite similar to the one of theorem5.1only instead of using the extractor if PoKRep
a b
protocol we use the extractors of two PoKE protocols (one for *g₁* = *A* <sup>a</sup>nd one for *g₂* = *B*).

$$
\mathsf{P o K E}^{*}
$$

$$
g_{1}^{a}=A
$$

$$
g_{2}^{b}=B boldsymbol{}
$$

---

## B Committing and Opening with Precomputation for the [BBF19] SVC

We discuss how the preprocessing technique can also be applied to the SVC scheme of [BBF19]
(instantiated for binary vectors of length *n* = *N‘*). In this case, however, we will not use the
incremental disaggregation and aggregation but only one-hop aggregation.
Q

$$
n\,=\,N\ell\,)
$$

n b
Let us recall that in [BBF19] a commitment to *~v 2f*0*;* 1*g* is *Acc* = *g* with *b* = *p*<sup>j</sup>.
<sup>j2</sup><sup>[</sup><sup>n</sup><sup>]</sup><sup>;v</sup>j<sup>=1</sup>
When asked for opening of some positions in the set *I*, the vector owner has to provide a batched
membership proof for all *fp*<sub>j</sub>: *j* = (*i* 1)*‘* +*l;i 2 I;l 2* [*‘*]*;v*<sub>j</sub>= 1*g* and a batched non-membership
proof for all *fp*<sub>j</sub>: *j* = (*i* 1)*‘* + *l;i 2 I;l 2* [*‘*]*;v*<sub>j</sub>= 0*g*.

$$
\vec{v}\in\{0,1\}^{n}
$$

$$
A c c=g^{b}
$$

$$
b=\prod_{j\in[n],v_{j}=1}p_{j}.
$$

$$
\{p_{j}:j=(i-1)\ell+l,i\in I,l\in[\ell],v_{j}=1\}
$$

$$
\{p_{j}:j=(i-1)\ell+\mathfrak{l},i\in I,l\in[\ell],v_{j}=0\}
$$

For the membership proofs, we can use ideas similar to the ones discussed earlier. In the com-
Q
b=bi
mitment phase one can precompute *fW*<sub>i</sub>= *g* : *i 2* [*N*]*g* where *b*<sub>i</sub>= *p*<sub>(</sub><sub>i</sub> <sub>1)</sub><sub>‘</sub><sub>+</sub><sub>l</sub>, which
l2[‘];vil=1
can be done in time *O*(*N* log*N ‘*log(*‘N*)) using the RootFactor algorithm from [STY01,BBF19].
This adds at most *N* elements of G to the advice information. Next, in the opening phase, in order
to compute a membership witness for a set of positions *I* one can use the aggregation property to
compute a witness *W*<sub>I</sub>from all *W*<sub>i</sub>with *i 2 I*, which is doable in time *O*(*m*log*m*).

$$
\left\{W _ {i} = g ^ {b / b _ {i}}: i \in [ N ] \right\}
$$

$$
b_{i}=\prod_{l\in[\ell|,v_{i l}=1}p_{(i-1)\ell+l}
$$

$$
O(N\log N{\cdot}\ell\log(\ell N))
$$

$$
W_{I}
$$

$$
i\in I
$$

$$
W_{i}
$$

For the non-membership proof, there are instead two options:

$$
O(m\log m)
$$

1.Compute the batch-nonmembership witness from scratch

2.Precompute and store (unbatched) non-membership witnesses for all 0’s of the vector and then
aggregate the necessary ones to provide the opening asked.

We argue that an intermediate solution of precomputing a fraction of non-membership witnesses and
computing the rest from scratch does not provide any benet since even if a single non-membership
witness needs to be computed, it requires the whole vector and computing the corresponding
product of primes. So, in the end the intermediate solution will be more costly than both the above
ones.

1. Compute non-membership witness from scratch. To compute a non-membership witness
one needs the product *b* of all the primes in the accumulator (i.e., all primes that correspond to 1’s
in *~v*). There are in turn two possible ways to deal with this:

{ Precompute and store *b*, which requires *O*(log(*N‘*) *N ‘*) computation and *jbj* = *O*(*N ‘* log(*N‘*))
bits of storage.

$$
|b|={(\}\{{{N}}{\cdot}{\ell}{\cdot}{\log}(\{{N}{\ell}}))
$$

{ Compute *b* online from all *p*<sub>i</sub>’s, which requires *O*(log(*N‘*) *N ‘*) computing power.

$$
{{p p_{i}}^{\ }}\mathrm{S}
$$

$$
O(\log(N\ell)\cdot N\cdot\ell)
$$

The computations needed to obtain a single non-membership witness is proportional to the size
of *b*, which is *O*(*‘ N* log(*‘N*)) G. Hence, virtually there is no big improvement in the opening
time by precomputing *b*, since the group exponentiations are more costly (although concretely it
saves the online computation of it). Furthermore, keeping *jbj* = *O*(*N ‘* log(*N‘*)) bits of storage
may get impractical for big *N*.

$$
O(\ell\cdot N\cdot\log{(\ell N)})\ \mathbb{G}
$$

$$
|b|=O(N\cdot\ell\cdot\log(N\ell))
$$

2. Precompute non-membership witnesses and then aggregate. The idea is similar to the
aggregation technique mentioned above for membership witnesses. However, a crucial dierence
is that, as stated in [BBF19], for non-membership witnesses one has only *one-hop* aggregation.
This means one must precompute and store non-membership witnesses for each block of the vector.
However these non-membership witnesses have size proportional to the number of bits of each block
(plus one group element).

---

This technique requires storage of *O*(*N*) group elements plus *O*(*N ‘*log(*N‘*)) eld elements
on average. Precisely, the size of a non-membeship witness for each block is *j*G*j* + log(*N‘*)
#*f*0-bits in the block*g*, hence the total size of non-membership witnesses is *N j*G*j* + *N‘* log(*N‘*)
in the worst case and *N j*G*j* + *N‘* log(*N‘*)*=*2 in an average case where half of the bits of the vector
are 0. To conclude, with the VC of [BBF19], one would need, on average, to precompute and store
2*N j*G*j* + *N‘* log(*N‘*)*=*2 bits.

$$
O(N\cdot\ell\operatorname{l o g}(N\ell))
$$

$$
O(N)
$$

$$
|\mathbb{G}|+\log(N\ell)\times
$$

$$
N|\mathbb{G}|+N\ell\log(N\ell)
$$

$$
N|\mathbb{G}|+N\ell\log(N\ell)/2
$$

$$
2N|\mathbb{G}|+N\ell\log(N\ell)/2
$$

Comparison. To conclude, even if we consider the case *B* = 1, both our solutions require much
less storage than in [BBF19]: 2*N j*G*j* vs. 2*N j*G*j*+*N‘* log(*N‘*)*=*2 bits. In terms of computing time, the
preprocessing has roughly the same complexity in all three solutions, although our second scheme
is slightly less favorable due to the log² *m* factor in the opening. Comparing [BBF19] and our rst
scheme, in [BBF19] the computing time for an opening of *m* blocks requires at least 50% more time
than in our rst scheme due to the handling of non-membership witnesses (which leads to 25%
more time in the average case).

$$
B=1
$$

$$
2N\ \ {mathbb G\\ {}}N\ell\log(N\ell)/2
$$

$$
\mathrm{l o g}^{2}
$$

## C Succinct Arguments of Knowledge for VDS

All the protocols below are for simplicity presented for the case of *k* = 1.

$$
k=1
$$

AoK of correct change
(

$$
R _ {\mathrm {P o K C h a n g e}} = \left\{ \begin{array}{c} \left(\left(C, C ^ {\prime}, I\right), \left(\pi_ {I}, \vec {v} _ {I}, \vec {v} _ {I} ^ {\prime}\right)\right): \mathrm {V C . V e r U p d a t e} (\mathrm {c r s}, C, \left(I, \pi_ {I}, \vec {v} _ {I}, \vec {v} _ {I} ^ {\prime}\right)) = 1 \\ \wedge C ^ {\prime} = \mathrm {V C . C o m U p d a t e} (\mathrm {c r s}, C, \left(I, \pi_ {I}, \vec {v} _ {I}, \vec {v} _ {I} ^ {\prime}\right)) \end{array} \right\}
$$

0 0 0 bIaI
In case of an update the new commitment is normally *C* := (*A;B*) = (*;*). Therefore the
I I
prover rst sends the proof<sub>I</sub>:= (<sub>I</sub>*;*<sub>I</sub>) to the verier. Then provides knowledge of the opening of
bI 0 aI 0
positions *I* with respect to *C* and further th<sub>a</sub>t = *A ^* = *B*. Putting all together the prover
I I
aIbI aIbIbI 0 aI 0
proves knowledge of (*a*<sub>I</sub>*;b*<sub>I</sub>) such th<sub>a</sub>t = *A ^* = *B ^ g* = *U*<sub>I</sub>*^* = *A ^* = *B*,
<sub>I</sub> <sub>I</sub> I I
uI
where *U*<sub>I</sub>*g* and *u*<sub>I</sub>PrimeProd(*I*).

$$
\mathcal{C}^{\prime}:=\left(A^{\prime},B^{\prime}\right)=\left(\varGamma_{I}^{b_{I}},\varDelta_{I}^{a_{I}}\right)
$$

$$
\pi_ {I} := \left(\Gamma_ {I}, \Delta_ {I}\right)
$$

$$
\Gamma_ {I} ^ {b _ {I}} = A ^ {\prime} \wedge \Delta_ {I} ^ {a _ {I}} = B ^ {\prime}
$$

$$
(a_{I},b_{I})
$$

$$
\ Gamma_{I}^{a_{I}}=A\wedge\ \ !{\it}_{I}^{b_{I}}=B\wedge g^{a_{I}\cdot b_{I}}=U_{I}\wedge\ \!\ \!_{I}^{b_{I}}=A^{\prime}\wedge\ \ \!\ _I{{}}{}_{I}=B^{\prime}
$$

$$
U_{I}\leftarrow g^{u_{I}}
$$

$$
u_{I}\leftarrow\mathsf{P r i m e P r o d}(I)
$$

AoK of correct add

$$
R_{\mathsf{P o l A A d d}}=\left\{\begin{matrix}{(\:(C,C^{\prime},I),\vec{v}_{I}^{\prime}\:):}&{\mathsf{V C}V e r U p d a t e(\mathsf{c r s},C,(I,\varnothing,\varnothing,\vec{v}_{I}^{\prime}))=1}\\ {\wedge}&{\mathrm C{'}=\mathsf{V C}.C o m J y d a t e(\mathsf{c r s},C,(I,\varnothing,\varnothing,\vec{v}_{I}^{\prime}))}\\ \end{matrix}\right\}
$$

0I 0I a00 b00 a b
The prover provides an argument of knowledge of (*a;b*) such th<sup>a</sup>t *AI*= *A ^BI*= *B ^g*<sup>I</sup> <sup>I</sup>=
uI
*U*<sub>I</sub>, where *U*<sub>I</sub>*g* and *u*<sup>I</sup>PrimeProd(*I*). Also, *C* := (*A;B*) and *C⁰* = (*A⁰;B⁰*) are part of the
statement.

$$
(a_{I}^{\prime},b_{I}^{\prime})
$$

$$
A^{a_{I}^{\prime}}=A^{\prime}\wedge B^{b_{I}^{\prime}}=B^{\prime}\wedge g^{a_{I}\cdot b_{I}}=
$$

$$
U_{I}
$$

$$
U_{I}\leftarrow g^{u_{I}}
$$

$$
u_{I}\gets\mathsf{P r i m e P r o d}(I)
$$

$$
C:=(A,B)
$$

$$
C^{\prime}=(A^{\prime},B^{\prime})
$$

AoK of correct delete
(

$$
R _ {\mathrm {P o K D e l e t e}} = \left\{ \begin{array}{c} \left(\left(C, C ^ {\prime}, I\right), \left(\pi_ {I}, \vec {v} _ {I}\right)\right): \mathrm {V C . V e r U p d a t e} (\mathrm {c r s}, C, \left(I, \pi_ {I}, \vec {v} _ {I}, \emptyset\right)) = 1 \\ \wedge C ^ {\prime} = \mathrm {V C . C o m U p d a t e} (\mathrm {c r s}, C, \left(I, \pi_ {I}, \vec {v} _ {I}, \emptyset\right)) \end{array} \right\}
$$

Recall that in case of deletion the new commitment *C⁰* is simply the proof<sub>I</sub>of the subvector
deleted. So the prover has only to provide an argument of knowledge of opening in the deleted
0aI0bIaIbIuI
positions *I*. That is (*a*<sub>I</sub>*;b*<sub>I</sub>) such that *A* = *A^B* = *B ^ g* = *U*<sup>I</sup>, where *U*<sub>I</sub>*g* and
*u*<sup>I</sup>PrimeProd(*I*). Also, *C* := (*A;B*) and *C⁰* = (*A⁰;B⁰*) are part of the statement.

$$
C^{\prime}
$$

$$
\pi\ I
$$

$$
(a_{I},b_{I})
$$

$$
A^{\prime a_{I}}\,=\,A\,\wedge\,B^{\prime b_{I}}\,=\,B\,\wedge\,g^{a_{I}\cdot b_{I}}\,=\,U_{I}
$$

$$
U_{I}\gets g^{u_{I}}
$$

$$
u_{I}\leftarrow\mathsf{P r i m e P r o d}(I)
$$

$$
C:=(A,B)
$$

$$
C^{\prime}=(A^{\prime},B^{\prime})
$$

---

## D VDS Proof of Storage

For a VDS scheme we additionally consider the possibility to ensure a client that a given le
is stored by the network at a certain point of time without having to retrieve it. To this end,
we extend the VDS notion to provide a *proof of storage* mechanism in the form of a proof of
+
retrievability (PoR) [JK07] or a proof of data possession (PDP) [ABC 07]. Our proof of storage
model for VDS is such that proofs are publicly veriable given the le’s digest. Also, in order to
support the decentralized and open nature of DSNs, the entire proof mechanism should not use any
secret. Finally, a main distinguishing feature compared to existing PoRs/PDPs is that proofs are
generated in a distributed fashion by a collection of storage nodes and remain compact regardless
of the number of nodes involved in the their generation.

$$
[\mathrm{A B C^{+}07}]
$$

Below we begin by dening the syntax and correctness of proof of storage for a VDS scheme;
these are dened the same for modeling both retrievability and data possession. The dierence
between the two is only in the security notion.

A VDS scheme VDS as in Denition7.1admits proofs of storage if there exist algorithms
(StrgNode*:* PoS-Challenge*;*StrgNode*:* PoS-Prove*;*ClntNode*:* PoS-Ver) that work as follows.

StrgNode*:* PoS-Challenge( )*! r* This is a probabilistic algorithm that, given a le’s digest, outputs
a challenge *r*.

$$
:(\delta)\to r
$$

$$
\delta,
$$

StrgNode*:* PoS-Prove(*;n;* st*;I;*F<sub>I</sub>*;r*)*!*<sub>r</sub>This algorithm allows a storage node to (partially) answer a PoS challenge *r*. The inputs include the local view of the storage node, i.e., digest, length
*n* local state st and le portion (*I;*F<sub>I</sub>), and a challenge *r 2C*. The output is a proof<sub>r</sub>.

$$
P S\ \ \mathsf P{r o v e}(\emptyset,n,\mathsf{s t},I,\mathsf{F}_{I},r)\to\pi_{r}
$$

$$
r\in{\mathcal{C}}.
$$

$$
(I,\mathsf{F}_{I})
$$

$$
\pi_{r}
$$

StrgNode*:* PoS-Aggregate(*;r;*<sub>r;</sub><sub>1</sub>;<sub>r;</sub><sub>2</sub>)*!* (*b;*<sub>r</sub>)On input a digest, a challenge *r 2 C* and two
partial proofs<sub>r;</sub><sub>1</sub>;<sub>r;</sub><sub>2</sub>, this algorithm outputs an aggregated proof<sub>r</sub>and a bit *b* such that *b* = 1
i<sub>r</sub>is a \complete" proof for challenge *r* (i.e., it can be veried).

$$
\delta,
$$

$$
r\in{\mathcal{C}}
$$

$$
\left(\delta,r,\pi_{r,1},\pi_{r,2}\right)\rightarrow\left(b,\pi_{r}\right)
$$

$$
\pi_{r}
$$

$$
\pi_{r,1},\pi_{r,2}
$$

$$
b=1
$$

$$
\pi_{r}
$$

ClntNode*:* PoS-Ver(*;r;*<sub>r</sub>)*! b* On input a digest, a challenge *r 2C* and a \complete" proof<sub>r</sub>,
this algorithm accepts (outputs 1) or rejects (outputs 0).

$$
\mathsf{P o S-V e r}(\delta,r,\pi_{r})\to b
$$

$$
\pi_{r}
$$

$$
r\in{\mathcal{C}}
$$

Denition D.1(Correctness of VDS PoS). *A VDS scheme* VDS *has a correct PoS mechanism*
*if* VDS *is* correct *and if for all honestly generated parameters* (pp*;*0*;*st₀) Bootstrap(1 )*, any le* F
S
‘
*of length n and any set of ‘ valid storage node’s local views* (*;n;* st<sub>j</sub>*;I*<sub>j</sub>; FIj) *such that* (I<sub>j</sub>*;* F<sub>I</sub><sub>j</sub>) =
<sub>j</sub><sub>=1</sub>
([n]*;*F)*, the following holds:*

$$
(\sf{p p},\delta_{0},\sf{s t}_{0})\leftarrow\sf{B o o t s t a p}(1^{\lambda})
$$

$$
(\delta,n,\mathsf{s t}_{j},I_{j},\mathsf{F}_{I_{j}})
$$

$$
\textstyle\bigcup_{j=1}^{\ell}(I_{j},\mathsf{F}_{I_{j}})=
$$

*if r* $ StrgNode*:* PoS*-*Challenge( )*,*r;jStrgNode*:* PoS*-*Prove(*;n;* stj*;I*j*;* FIj*;r*) *for all j 2*
[*‘*]*, and*<sub>r</sub>*is obtained by aggregating f*<sub>r;j</sub>*g*<sub>j2</sub><sub>[</sub><sub>‘</sub><sub>]</sub>*in an arbitrary order using repeated usage of*
StrgNode*:* PoS*-*Aggregate *until getting b* = 1*, then* ClntNode*:* PoS*-*Ver(*;r;*<sub>r</sub>) = 1*.*

$$
\pi_{r,j}\gets
$$

$$
\pi_{r}
$$

$$
(\delta,n,\mathsf{s t}_{j},I_{j},\mathsf{F}_{I_{j}},r)
$$

$$
j \in
$$

$$
\{\pi_{r,j}\}_{j\in[\ell]}
$$

$$
\mathsf{P o S-V e r}(\delta,r,\pi_{r})=1
$$

PoS Security. Here we dene two security properties for the above PoS mechanism: retrievability
+
and data possession. Similarly to [JK07,ABC 07], the idea is to ask that from any adversary, controlling all storage nodes, who creates a proof<sub>r</sub>that is accepted with suciently high probability
it is possible to extract the entire le. In the retrievability case, this is formalized through requiring
the existence of an extractor that extracts the le by interacting multiple times with such prover
(via rewinding). In the data possession case, it is the same except that the extractor is non-blackbox, i.e., we assume that for any adversary there is an extractor; in other words, the extractor is
a cryptographic one that does not exist in the real world, and for this reason the data possession
notion is weaker than retrievability.

$$
\mathrm{[J K07,A B C^{+}07]}
$$

$$
\pi_{r}
$$

---

We build our denitions inspired to the one of Proof of Retrievable commitment (PoRC) soundness in [Fis18]. To this end, we dene the following two experiments.

$$
\begin{array}{l l}{\frac{\mathsf{V D S P S S A d d}_{\mathsf{C S S}}^{\mathcal{A}}(\lambda)}{(mathsf{p s},\delta_{0},\mathbf{s t}_{0})\sim\mathsf{D o o t t r a p}(\delta^{1})}}&{\mathsf{V D S P S S e x t e}}\\\\ (\\mathsf{P e}^{*},\delta{\mathsf{s}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}{\mathsf{t}}{\mathsf{s}}\end{array}
$$

n 0 n0
Above, given two les F *2M* a<sup>n</sup>d F *2M* a<sup>n</sup>d a parameter *2* [0*;*1] we say that F agrees
0i
on a-fraction with F⁰, denoted F F⁰, if and only if *n* = *n⁰* and *jfi 2* [*n*] : F<sub>i</sub>= F *gj n*.

$$
\ {\mathsf{F}}\in{\mathcal{M}}^{n}
$$

$$
{\mathsf{F}}^{\prime}\in{\mathcal{M}}^{n^{\prime}}
$$

$$
\mu\in[0,1]
$$

$$
\mathsf{F}^{\prime}
$$

$$
\ {\sf F\\equiv_{\mu}\sf{F}^{\prime}}
$$

$$
n=n^{\prime}
$$

$$
|\{i\in\ n]:\mathsf{F}_{i}=\mathsf{F}_{i}^{\prime}\}|\geq\mu\cdot n
$$

A
The experiment VDSPoS<sup>A</sup>dm<sub>VDS</sub>() is parametrized by a two-stage adversary *A* = (*A₁; A₂*)
and models the interaction between an adversarial prover that creates a (valid) VDS history which
results into a digest and then replies to one honestly generated challenge. This experiment is
used to formalize the notion of-admissible adversaries, which in brief are adversaries that in
this game answer successfully to the challenge with probability at least. The second experiment
A;E
<sup>VDS</sup>PoSExtr () is again parametrized by a two-stage adversary *A* = (*A₁; A₂*), and additionally
VDS
by an extractor *E* having oracle access to *A₂*. The goal of the extractor is to return a le Fb which
agrees on a-fraction of indices with the le F implicitly returned by *A₁*.

$$
\mathsf{V D S P o S A d m}_{\mathsf{V D S}}^{\mathcal{A}}(\lambda)
$$

$$
\mathcal {A} = \left(\mathcal {A} _ {1}, \mathcal {A} _ {2}\right)
$$

$$
\delta^{*}
$$

$$
\mathsf{V D S P o S E x t r}_{\mathsf{V D S}}^{\mathcal{A},\mathcal{E}}(\lambda)
$$

$$
\mathcal{A}=(\mathcal{A}_{1},\mathcal{A}_{2})
$$

$$
\mathcal{E}
$$

$$
\mathcal{A}_{2}
$$

$$
\widehat{F}
$$

$$
\mu\mathrm{r a a t t i i l!}
$$

$$
\mathcal{A}_{1}
$$

Denition D.2(Admissible VDS PoS Adversary). *A VDS adversary A* = (*A₁; A₂*) *is-*
A
*admissible if and only if the experiment* VDSPoR<sup>A</sup>dm<sub>VDS</sub>() *does not abort with probability* 1
A
negl() *and* Pr[VDSPoR<sub>A</sub>dm<sub>VDS</sub>(*;*F) = 1]*.*

$$
\mathcal{A}=(\mathcal{A}_{1},\mathcal{A}_{2})
$$

$$
\mathsf{V D S P o R A d m}_{\mathsf{V D S}}^{\mathcal{A}}(\lambda)
$$

$$
11-
$$

$$
\operatorname{P r}[\sf{V D S P o R A d m}_{V D S}^{A}(\lambda,F)=1]\geq\epsilon
$$

Denition D.3(Retrievability for VDS). *A VDS scheme* VDS *is* (*;*)*-retrievable if it is se-*
*cure and for some*<sub>;</sub>*2 O*(log*=*log) *and every >* <sub>;</sub>*there exists an extractor E that runs in*
A;E
*time* poly(*;n;*1*=*) *such that for any adversary A which is-admissible we have* Pr[VDSPoSExtr () =
<sub>VDS</sub>
1] *2* negl()*.*

$$
(\mu,\epsilon)
$$

$$
\lambda_{\epsilon,\mu}\in O(\log\epsilon/\log\mu)
$$

$$
\lambda>\lambda_{\epsilon,\mu}
$$

$$
\ \left(\lambda,n,1/\epsilon\right)
$$

$$
\operatorname{P r}[\mathsf{V D S P o S E x t r}_{\mathsf{V D S}}^{\mathcal{A},\mathcal{E}}(\lambda)=
$$

$$
1]\in\mathsf{n e g l}(\lambda)
$$

Denition D.4(Data Possession for VDS). *A VDS scheme* VDS *has-data-possession if it*
*is secure and for some*<sub>;</sub>*2 O*(log*=*log) *and every >* <sub>;</sub>*and every adversary A which is-*
A;E
*admissible there is an extractor E that runs in time* poly(*;n;*1*=*) *such that* Pr[VDSPoSExtr () =
<sub>VDS</sub>
1] *2* negl()*.*

$$
\lambda_{\epsilon,\mu}\in O(\log\epsilon/\log\mu)
$$

$$
\lambda>\lambda_{\epsilon,\mu}
$$

$$
\epsilon-
$$

$$
\operatorname{P r}[\mathsf{V D S P o S E x t r}_{\mathsf{V D S}}^{\mathcal{A},\mathcal{E}}(\lambda)=
$$

$$
1]\in\mathsf{n e g l}(\lambda)
$$

$$
\ \left(\lambda,n,1/\epsilon\right)
$$

$$
\mathcal{E}
$$

Parallel Proof of Storage. We extend our PoS notion for VDS to a setting where one can
simultaneously check storage of *k* dierent les of the same length with a single challenge. The
syntactical change we do is to assume that one can generate a challenge by only knowing the length
of the les. Informally, the parallel version of retrievability (resp. data possession) is a parallel
repetition of the protocol, and then from any adversary that answers successfully for all les it is
possible to extract les so that each is consistent with at least a-fraction of the original one.

The parallel security experiments are as follows.

---

$$
\vee\ \ S P P o S\!P
$$

$$
\mathsf{V D S P o S-P a r-x x t r}_{\mathsf{V D S}}^{mathcal A\mathcal{E}}(\lambda)
$$

$$
(\mathrm {p p}, \delta_ {0}, \mathrm {s t} _ {0}) \leftarrow \operatorname {B o o t s t r a p} \left(1 ^ {\lambda}\right)
$$

$$
\{\big(\mathcal{H}_{i}^{*},\alpha_{i}^{*}\big)\}_{i=1}^{k}\leftarrow\mathcal{A}_{1}\big(\mathfrak{p p},\delta_{0},\mathfrak{s t}_{0}\big)
$$

$$
\{(b_{i}^{*},\delta_{i}^{*},\mathsf{F}_{i}^{*})\leftarrow\mathsf{E v a l H i s t o r y}(\mathsf{p p},\delta_{0},\mathsf{s t}_{0},\mathcal{H}_{i}^{*})\}_{i=1}^{k}
$$

$$
\{\big(\mathcal{H}_{i}^{*},\alpha_{i}^{*}\big)\}_{i=1}^{k}\leftarrow\mathcal{A}_{1}\big(\mathsf{p p},\delta_{0},\mathsf{s t}_{0}\big)
$$

$$
\exists i\in[k]:b_{i}^{*}=\mathbf{0}\lor\neg(\wedge_{i\in[k-1]}|\mathsf{F}_{i}^{*}|=|\mathsf{F}_{i+1}^{*}|)
$$

if *9i 2* [*k*] : *b*<sub>i</sub>= 0 *_:*(*^*<sub>i2</sub><sub>[</sub><sub>k</sub> <sub>1]</sub>*j*F<sub>i</sub>*j* = *j*F<sub>i</sub><sub>+1</sub>*j*) abort*;*

$$
\{(b_{i}^{*},\delta_{i}^{*},\mathsf{F}_{i}^{*})\xleftarrow{}\mathsf{E v a l H i s t o r y}(\mathsf{p p},\delta_{0},\mathsf{s t}_{0},\mathcal{H}_{i}^{*})\}_{i=1}^{k}
$$

else *r* $ StrgNode*:* PoS-Challenge(*j*F₁*j*);
k k

$$
\{\pi_{r,i}^{*}\}_{i=1}^{k}\leftarrow\mathcal{A}_{2}(\mathsf{p p},\delta_{0},\mathsf{s t}_{0},\{\delta_{i}^{*},\alpha_{i}^{*}\}_{i=1}^{k},r)
$$

$$
\{\widehat{\mathtt{F}}_{i}\}_{i=1}^{k}\xleftarrow{}\mathcal{E}^{\mathcal{A}_{2}(\mathtt{p p},\delta_{0},\mathtt{s t}_{0},\delta_{i}^{*},\alpha_{i}^{*},\cdot)}(\mathtt{p p},\delta_{0},\mathtt{s t}_{0},\{\delta_{i}^{*}\}_{i=1}^{k})
$$

return 1 i *8i 2* [*k*] : Fb 6=*?^9j 2* [*k*] : F *6* Fb
*i j* j

return 1 i ClntNode*:* PoS-Ver(<sub>i</sub>*;r;*<sub>r;i</sub>) *8i 2* [*k*]

$$
\mathrm {i f f} \forall i \in [ k ]: \widehat {\mathbf {F}} _ {i} \neq \perp \wedge \exists j \in [ k ]: \mathbf {F} _ {j} ^ {*} \neq \delta \widehat {\mathbf {F}} _ {j}
$$

Denition D.5(Admissible VDS PoS Parallel Adversary). *A VDS adversary A* = (*A₁; A₂*)
A
*is parallel-admissible if and only if the experiment* VDSPoS*-*Par*-*<sup>A</sup>dm<sub>VDS</sub>() *does not abort with*
*probability* 1 negl() *and*
A
Pr[VDSPoS*-*Par*-*<sup>A</sup>dm (*;*F) = 1]*.*

$$
\mathcal{A}=(\mathcal{A}_{1},\mathcal{A}_{2})
$$

$$
\vee D S P o S\cdot P\mathrm{A r}d M\cdot{\ S}({\lambda})
$$

$$
1-\mathsf{n e g}(\lambda)
$$

$$
\bf{P r}[\sf{V D S P o S\ P a r\ A A m m}_{D S}(\lambda,F)=1]\geq\epsilon.
$$

Denition D.6(Parallel Retrievability for VDS). *A VDS scheme* VDS *is parallel* (*;*)*-*
*retrievable if it is secure and for some*<sub>;</sub>*2 O*(log*=*log) *and every >* <sub>;</sub>*there exists an*
*extractor E that runs in time* poly(*;n;*1*=*) *such that for any adversary A which is parallel-*
*admissible we have*
A;E
Pr[VDSPoS*-*Par*-*Extr () = 1] *2* negl()*.*

$$
(\mu,\epsilon).
$$

$$
\lambda_{\epsilon,\mu}\,\in\,O(\log\epsilon/\log\mu)
$$

$$
\lambda>\lambda_{\epsilon,\mu}
$$

$$
\mathcal{E}
$$

$$
\left\langle\lambda,n,1/\epsilon\right\rangle
$$

$$
\bf{P r}[\sf{V D S P o S\ P a r\_E x t r}_{V Osf}S^{A,E}(\lambda){\ =\ }1]\in n e g l(\lambda).
$$

Denition D.7(Parallel Data Possession for VDS). *A VDS scheme* VDS *has parallel-*
*data-possession if it is secure and for some*<sub>;</sub>*2 O*(log*=*log) *and every >* <sub>;</sub>*and every*
*adversary A which is-admissible there is an extractor E that runs in time* poly(*;n;*1*=*) *such that*
A;E
Pr[VDSPoS*-*Par*-*Extr () = 1] *2* negl()*.*
VDS

$$
\epsilon-
$$

$$
\lambda_{\epsilon,\mu}\,\in\,O(\log\epsilon/\log\mu)
$$

$$
\lambda>\lambda_{\epsilon,\mu}
$$

$$
\mathcal{E}
$$

$$
\operatorname{P r}[\mathsf{V D S P o S\_P a r\_E x t r}_{\mathsf{V D S}}^{\mathcal{A},\varepsilon}(\lambda)=1]\in\mathsf{n e g l}(\lambda)
$$

$$
\ \left(\lambda,n,1\ \epsilon\right)
$$

With the following theorem we show that it is enough to prove security in the (nonparallel)
setting. The idea of the proof is that one can construct an extractor for the parallel game by running
*k* extractors of the nonparallel game. The analysis of this reduction is rather simple and is therefore
omitted.

Theorem D.1. *A VDS scheme that has* (*;*)*-retrievability (resp. data possession) also achieves*
*parallel* (*;*)*-retrievability (resp. data possession).*

$$
(\mu,\epsilon)
$$

## D.1 Proof of Storage for our rst VDS

In this section we show that our rst VDS scheme from Section8.1admits both a PoR and a PDP
mechanism, while our second VDS scheme from Section8.2admits a PoR.

Retrievability. In the case of PoR we can describe the algorithms generically from the VDS
algorithms. Namely, any VDS always admits a PoR.

StrgNode*:* PoS-Challenge(*n*)*! r* samplesposintegers *r₁;:::;r*pos $ [*n*] and dene *r* = *fr₁;:::;r*pos*g*
StrgNode*:* PoS-Prove(*;n;* st*;I;*F<sub>I</sub>*;r*)*!*<sub>r</sub>Parse *r* := *fr₁;:::;r*<sub>pos</sub>*g* and let *Q* := *I \ r*, compute
(F<sub>Q</sub>*;*<sub>Q</sub>) StrgNode*:* Retrieve(*;n;* st*;I;*F<sub>I</sub>*;Q*) and return<sub>r;Q</sub>:= (*Q;*F<sub>Q</sub>*;*<sub>Q</sub>*;Q*).

$$
P O S-C h a l l e n g e(n)\rightarrow r
$$

$$
\lambda_{\mathsf{p o s}}
$$

$$
r_{1},\ldots,r_{\lambda_{\mathsf p o s}}\leftarrow_{\mathfrak S}\ n
$$

$$
r=\left\{r_{1},\ldots,r_{\lambda_{\mathsf{p o s}}}\right\}
$$

$$
\ \ \\\ \\\ \\\ \\\ \\\ \\\ \\\ \\ \ \ {\ mathcal S}-{\sf P r o v e}(\partial,n,\mathfrak{s t},I,\mathfrak{F}_{I},r)\to\pi_{r}
$$

$$
Q:=I\cap r
$$

$$
\pi_{r,Q}:=\left(Q,\mathsf{F}_{Q},\pi_{Q},Q\right)
$$

StrgNode*:* PoS-Aggregate(*;r;*<sup>r;</sup><sup>1</sup>;<sup>r;</sup><sup>2</sup>)*!* (*b;*<sup>r</sup>)Parse<sup>r;</sup><sup>1</sup>:= (*Q₁;* F<sub>Q</sub><sub>1</sub>*;*<sub>Q</sub><sub>1</sub>) and<sub>r;</sub><sub>2</sub>:= (*Q₂;* F<sub>Q</sub><sub>2</sub>*;*<sub>Q</sub><sub>2</sub>).

$$
(\mathsf{F}_{Q},\pi_{Q})\leftarrow\mathsf{S t r g N o d e}.\mathsf{R e t r i e v e}(\delta,n,\mathsf{s t},I,\mathsf{F}_{I},Q)
$$

$$
\pi_{r,1}:=\left(Q_{1},\mathsf{F}_{Q_{1}},\pi_{Q_{1}}\right)
$$

$$
{\sf{t e}}(\delta,r,\pi_{r,1},\pi_{r,2})\rightarrow\ b,\pi_{r,1}
$$

$$
\exists i\in\{1,2\}
$$

$$
Q_{i}=r\;\ *{\sec}b:=1
$$

If *9i 2f*1*;* 2*g* such that *Q*<sub>i</sub>= *r* set *b* := 1 and<sub>r</sub>:=<sub>r;i</sub>.

$$
\pi_{r}:=\pi_{r,i}.
$$

Otherwise, compute (*Q;*F<sub>Q</sub>) := (*Q₁;* F<sub>Q</sub><sub>1</sub>) *[* (*Q₂;* F<sub>Q</sub><sub>2</sub>) and

$$
(\mathcal{Q},\mathsf{F}_{\mathcal{Q}}):=(\mathcal{Q}_{1},\mathsf{F}_{\mathcal{Q}_{1}})\cup(\mathcal{Q}_{2},\mathsf{F}_{\mathcal{Q}_{2}})
$$

QAggregateCerticates(*;* (*Q₁;* FQ1*;*Q1)*;* (*Q₂;* FQ2*;Q*2)), and setr:= (*Q;*FQ*;*Q). If *Q* = *r*,
set *b* := 1, otherwise set *b* := 0.

$$
\left(\delta,(Q_{1},\mathsf{F}_{Q_{1}},\pi_{Q_{1}}),(Q_{2},\mathsf{F}_{Q_{2}},\pi_{Q_{2}})\right)
$$

$$
\pi_{r}:=\left(Q,\mathsf{F}_{Q},\pi_{Q}\right)
$$

$$
Q=r
$$

$$
b:=1
$$

$$
b:=0
$$

Return (*b;*<sub>r</sub>)

$$
(b,\pi_{r})
$$

---

$$
\pi_{r}:=\left(Q,\mathsf{F}_{Q},\pi_{Q}\right)
$$

$$
\mathsf{P o S-V e r}(\delta,r,\pi_{r})\to b
$$

ClntNode*:* PoS-Ver(*;r;*<sub>r</sub>)*! b* parse<sub>r</sub>:= (*Q;*F<sub>Q</sub>*;*<sub>Q</sub>) and return 1 i *Q* = *r* and ClntNode*:* VerRetrieve(*;*
*Q;*F<sub>Q</sub>*;*<sub>Q</sub>) = 1.

$$
Q,\mathsf{F}_{Q},\pi_{Q})=1
$$

Correctness is easy by inspection and by the correctness of VDS.

For security we state the following theorem. The proof is omitted since it is almost identical to
the proof of the VC-PoRC construction in [Fis18]; the only dierence is that instead of reducing to
27
the position binding of the VC we reduce to the security of the VDS scheme.

Theorem D.2. *If the VDS scheme* VDS *from Section8.1is secure then its extension with the*
*PoS algorithms described above is a* (*;*)*-retrievable VDS for any >* 0 *such that*<sup>pos</sup>*is*
*non-negligible in.*

$$
a\ (\mu,\epsilon)
$$

$$
\epsilon-\mu^{\lambda_{\mathsf{p o s}}}
$$

Data Possession. The PDP for our VDS is almost the same as the PoR described above except
that the last step of aggregation \compacts" the proof by generating an AoK of opening (see Section
6). More precisely, let PoKOpen⁰ be the same as protocol PoKOpen but adjusted for the simpler
version of our VC scheme given in Section8.1. Namely, the one where the commitment is (*A;B*)
and the verication is the VC*:* Ver⁰ algorithm. So, the relation proven by PoKOpen⁰ is:

$$
R_{\mathsf{P o K O O p e}{^\prime\}}=\{(\:(C,I),\:(\vec{y},\pi_{I})\:):\mathsf{V C.V e r}^{\prime}(\mathsf{p p},C,I,\vec{y},\pi_{I})\:}
$$

Then, the PDP aggregation algorithm works as follows.

StrgNode*:* PoS-Aggregate(*;r;*<sub>r;</sub><sub>1</sub>;<sub>r;</sub><sub>2</sub>)*!* (*b;*<sub>r</sub>)Parse<sub>r;</sub><sub>1</sub>:= (*Q₁;* F<sub>Q</sub><sub>1</sub>*;*<sub>Q</sub><sub>1</sub>) and<sub>r;</sub><sub>2</sub>:= (*Q₂;* F<sub>Q</sub><sub>2</sub>*;*<sub>Q</sub><sub>2</sub>).
If *9i 2f*1*;* 2*g* such that *Q*<sub>i</sub>= *r* set *b* := 1 and (*Q;*F<sub>Q</sub>*;*<sub>Q</sub>) :=<sub>r;i</sub>.
Otherwise, compute (*Q;*F<sub>Q</sub>) := (*Q₁;* F<sub>Q</sub><sub>1</sub>) *[* (*Q₂;* F<sub>Q</sub><sub>2</sub>) and
*Q*AggregateCerticates(*;* (*Q₁;* FQ1*;*Q1)*;* (*Q₂;* FQ2*;*Q2)).

$$
\left(\hat{\delta},r,\pi_{r,1},\pi_{r,2}\right)\rightarrow\left(b,\pi_{r}\right)
$$

$$
\pi_{r,1}:=\left(Q_{1},\mathsf{F}_{Q_{1}},\pi_{Q_{1}}\right)
$$

$$
\pi_{r,2}:=\left(Q_{2},\mathsf{F}_{Q_{2}},\pi_{Q_{2}}\right)
$$

$$
\exists\dot{i}\in\{1,2\}
$$

$$
b:=1
$$

$$
Q_{i}=r
$$

$$
(Q,\mathsf{F}_{Q},\pi_{Q}):=\pi_{r,i}
$$

$$
(\mathcal{Q},\mathsf{F}_{\mathcal{Q}}):=(\mathcal{Q}_{1},\mathsf{F}_{\mathcal{Q}_{1}})\cup(\mathcal{Q}_{2},\mathsf{F}_{\mathcal{Q}_{2}})
$$

$$
\left(\emptyset,(Q_{1},\mathsf{F}_{Q_{1}},\pi_{Q_{1}}),(Q_{2},\mathsf{F}_{Q_{2}},\pi_{Q_{2}})\right)
$$

If *Q 6*= *r*, set<sub>r</sub>:= (*Q;*F<sub>Q</sub>*;*<sub>Q</sub>) and return (0*;*<sub>r</sub>). Otherwise, proceed to compute an AoK of
opening, i.e., compute<sub>r</sub>PoKOpen⁰*:* P((*;Q*)*;*(F<sub>Q</sub>*;*<sub>Q</sub>)), and then return (1*;*<sub>r</sub>)

$$
Q\neq r.
$$

$$
\left(0,\pi_{r}\right)
$$

$$
\pi_{r}:=\left(Q,\mathsf{F}_{Q},\pi_{Q}\right)
$$

$$
\pi_{r}\leftarrow\mathsf{P o K O p e n}^{\prime}.\mathsf{P}((\delta,Q),(\mathsf{F}_{Q},\pi_{Q}))
$$

$$
(1,\pi_{r})
$$

ClntNode*:* PoS-Ver(*;r;*<sub>r</sub>)*! b* return PoKOpen⁰*:* V((*;r*)*;*<sub>r</sub>).

$$
\mathsf{P o S-V e r}(\delta,r,\pi_{r})\to b
$$

$$
\mathsf{P o K O p e n}^{\prime}.\mathsf{V}((\delta,r),\pi_{r})
$$

Correctness is easy by inspection and by the correctness of VDS.

For security we state the following theorem. The proof is essentially the same as the one for
retrievability except that in this case we dene a non-black-box extractor which is build from the
extractor for PoKOpen⁰.

Theorem D.3. *If* PoKOpen⁰ *is a secure AoK for relation R 0 and the VDS scheme* VDS *from*
PoKOpen
*Section8.1is secure, then its extension with the PoS algorithms described above satises* (*;*)*-data*
*possession for any >* 0 *such that*<sup>pos</sup>*is non-negligible in.*

$$
\ {sf P P k V O p n}^{\prime}
$$

$$
R_{\mathsf{P o k O p e n}^{\prime}}
$$

$$
\epsilon>0
$$

$$
\epsilon-\mu^{\lambda_{\mathtt{p o s}}}
$$

$$
\lambda
$$

Parallel PDP. We observe that in the case of executing the PDP protocol in parallel for *k* dierent
digests, our construction has an interesting eciency property. While verifying one PDP takes time
ur
*O*(<sub>pos</sub>) due to the computation of the group element *U*<sub>r</sub>:= *g* with *u*<sup>r</sup>:= PrimeProd(*r*), in the
case of verifying *k* PDPs with the same challenge the element *U*<sub>r</sub>can be reused. This yields a total
verication time *O*(<sub>pos</sub>+ *k*) instead of *O*(*k*<sub>pos</sub>).

$$
U_{r}:=g^{u_{r}}
$$

$$
O(\lambda_{\mathsf{p o s}})
$$

$$
u_{r}:=\mathsf{P r i m e P r o d}(r)
$$

$$
U_{r}
$$

$$
O(\lambda_{\mathsf p{o o s}}+k)
$$

$$
O(k\cdot\lambda_{\mathtt{p o s}})
$$

<sup>27</sup>
For this we also observe that Fisch’s proof could go through even assuming a weaker notion of position binding
in which the adversary declares the whole committed vector in addition to the two discording openings for one
position.

---

## E A Variant VDS Construction with Strong Security

We dene a stronger notion of security for VDS schemes where the digest is chosen adversarially,
namely without having the verier need to check the corresponding history. Also, we show that a
variant of our second VDS construction can be proven secure under this strong notion; this however
comes at the price of dropping one of the eciency requirements as now the verier may sometimes
run in time linear in the size of the le (still all proofs remain short).

## E.1 Strong Security

In this notion the digest can diverge from a valid history, meaning that the VDS scheme is secure
independently of the corresponding history: an adversary cannot convince a client of a false data
block in a retrieval query for any arbitrary digest (that is possibly not an EvalHistory). This
notion is analogous to the position binding of vector commitments. This allows a client that has
not followed the complete history of the VDS to make certain that for the given digest no invalid
retrieval answers can be given.

Denition E.1(Strong Security for Veriable Decentralized Storage). *Consider the ex-*
A
*periment* VDS*-*strongSecurity<sup>VDS</sup>() *below. Then we say that a VDS scheme* VDS *is strongly-secure*
A
*if for all PPT A we have* Pr[VDS*-*strongSecurity<sub>VDS</sub>() = 1] *2* negl()*.*
A
<u>VDS-strongSecurity</u><sub>VDS</sub><u>()</u>
(pp*;*0*;*st₀) Bootstrap(1)
0Q 0
(*;Q;*F*Q;;*F*;*) *A* (pp*;*<sup>0</sup>*;*st₀)
0Q 0
*b* ClntNode*:* VerRetrieve(pp*;;Q;*F*;*)*^*
<sup>0Q</sup>
ClntNode*:* VerRetrieve(pp*;;Q;*F*Q;*) *^* F 6= F*Q*
return *b*

$$
y_{\mathsf{V D S}}^{\mathcal{A}}(\lambda)=1]\in\mathsf{n e g l}(\lambda)
$$

$$
(\delta^{*},\mathcal{Q},\mathsf{F}_{Q},\pi,\mathsf{F}_{Q}^{\prime},\pi^{\prime})\leftarrow\mathcal{A}(\mathfrak{p p},\delta_{0},\mathfrak{s t}_{0})
$$

$$
\delta^{*},Q,\mathsf{F}_{Q}^{\prime},\pi^{\prime})\wedge
$$

$$
\delta^{*},Q,\mathsf{F}_{Q},\pi)\wedge\mathsf{F}_{Q}^{\prime}\neq\mathsf{F}_{Q}
$$

## E.2 A VDS Construction with Strong Security

Our second VDS scheme from Section8.2is built upon the [CF13,LM19] SVC. This scheme is not
strongly secure although it inherits the standard position binding of VC (dierently from our other
construction). This property states that, even for adversarially chosen *C*’s, which possibly do not
0
come from a valid history, no PPT adversary can provide openings<sub>Q</sub>*;* for dierent subles.
Q

$$
\pi_{Q},\pi_{Q}^{\prime}
$$

What prevents our VDS scheme to be strongly secure is the<sub>Q</sub>*U*-part of the digest. For *U* it must
i2[n]ei
be ensured that it has the correct form *U g*. Th<sub>e</sub>re are two ways to ensure this, either one
follows the history of the VDS or it computes it from scratch when necessary. The rst case leads
to the VDS scheme of Section8.2, while the second one leads to a strongly-secure VDS scheme,
let us call it VDS⁰, that however has the drawback of having linear-time (in the size of the le)
verication of a retrieval.

$$
U\leftarrow g^{\prod_{i\in[n]}e_{i}}
$$

We note that in practice a client may not need to check *U* at each retrieval. Observe that it
only depends on the size of the le and not on its context, meaning that only addition and deletionQ
i2[n]ei
updates aect it. So one may keep *U*<sub>n</sub>= *g* stor<sub>e</sub>d and at the time of the query verication
update it with the new le length *n⁰*. This gives an *O*(*jn n⁰j*) computational cost for verication
at the cost of storing a single group element, *U*.

$$
U_{n}=g^{\prod_{i\in[n]}e_{i}}
$$

$$
O(|n-n^{\prime}|)
$$

$$
n^{\prime}
$$

Let the alternative verication algorithm be:

---

Q
0i2[n]ei
ClntNode*:* VerRetrieve (*;Q;*F<sup>Q</sup>*;*<sup>Q</sup>)*! b* comput<sup>e</sup> *U g* a<sup>n</sup>d output acceptance bit
Q
i2Qei
*b* VC*:* Ver(pp*;C;Q;*F<sub>Q</sub>*;*<sub>Q</sub>) *^ S* = *U*
<sub>Q</sub>

$$
U\leftarrow g^{\prod_{i\in[n]}e_{i}}
$$

$$
(left(\delta,Q,\mathsf{F}_{Q},\pi_{Q})\to b
$$

$$
b\leftarrow\mathsf{V C.V e r}(\mathsf{p p},C,Q,\mathsf{F}_{Q},\pi_{Q})\wedge S_{Q}^{\prod_{i\in Q}e_{i}}=U
$$

and the corresponding VDS scheme be the same as the one in Section8.2except for the verication
of retrieval query algorithm, i.e.,

VDS⁰ = (Bootstrap*;*StrgNode*:* AddStorage*;*StrgNode*:* RmvStorage*;*StrgNode*:* PushUpdate*;*
StrgNode*:* ApplyUpdate*;*StrgNode*:* Retrieve*;*ClntNode*:* VerRetrieve⁰*;*ClntNode*:* ApplyUpdate*;*
AggregateCerticates)

Theorem E.1(Security). *Let* G Ggen(1 ) *be a hidden order group where the Strong Distinct-*
*Prime-Product Root assumption, then the* VDS⁰ *scheme presented above is a strongly-secure Veri-*
*able Decentralized Storage scheme in the standard model.*

$$
\mathbb{G}\leftarrow\mathsf{G g e n}(1^{\lambda})
$$

The proof is almost the same to the one of Theorem8.3and is omitted.

## F Experimental Results

In this section we include complete tables and plots for our benchmarks.

In some of the tables and plots we show only results for openings of size at most 25% of the
vector size as this is often the case in practice. We remark that the timings for verication of our
SVC construction and BBF do not use proofs of knowledge of exponent, thus both timings can
in practice be reduced through the use of this technique. Finally, although we show amortized
openings (Figure9) for only openings of size 2048 bits, we stress that dierent choices of le and
opening size show very similar patterns.

We exclude BBF with precomputation from our experiments as its storage requirements and
running times dominate those of our construction with preprocessing. In terms of storage it is linear
in the number of the bits in the vector. For our choice of security parameters and block size, it
would require 3 more memory independently of the size of the vector. In terms of time, the running
times of BBF with preprocessing always dominate those of our preprocessing scheme. Concretely
opening and verication of each zero bit requires one more group exponentiation. Finally, the lack
of incremental aggregation makes this scheme less exible than ours as it does not allow to choose
dierent tradeos in terms of memory/running time.

The Experimental Setting We implemented our VC, its preprocessing variant and BBF²⁸ in
Rust. We executed our experiments on a virtual machine running Debian GNU/Linux with 8 Xeon
Gold 6154 cores and 30 GB of RAM.

$$
\mathrm{B B F^{28}}
$$

We measured running times for the commitment stage (including or not a preprocessing), opening and verication for dierent choices of vector length (*N*) and subvector openings (*m*). Vectors
have blocks of *‘* = 256 bits (which is representative of vectors where blocks are hash outputs) and
29
their total size *n* = *N‘* range from 16 kibibit (Kibit) to 1 mebibit (Mibit). For preprocessing we
considered the basic case in which we precompute one proof per block, i.e., a total of *n=‘* proofs is
precomputed. We chose *m*, the opening size to be of 1, 8 or 64 blocks (i.e. 256, 2048 or 16536 bits).
On security parameters: our experiments always used an RSA modulus of 2048 bits and primes of
64 bits for accumulation.

$$
n=N\ell
$$

$$
n/\ell
$$

<sup>28</sup>
https://github.com/nicola/rust-yinyan

<sup>29</sup> 10 10
1 Kibit = 2 bits; 1 Mibit = 2 Kibit. We choose powers of two for convenience.

$$
1\;\mathrm{K i b i t}=2^{10}
$$

$$
=2^{10}
$$

---

| n(file size in bits) | Running Time |
| --- | --- |
| 16384 | 52s |
| 32768 | 1m56s |
| 64536 | 4m23s |
| 131072 | 10m7s |
| 262144 | 24m5s |
| 524288 | 1h1m |
| 1048576 | 2h54m |

Table 4. Commitment times for our preprocessing construction (block size *‘* = 256).

| n(size in bits) | This work | BBF |
| --- | --- | --- |
| 16384 | 18s | 3s |
| 32768 | 37s | 8s |
| 64536 | 1m19s | 18s |
| 131072 | 3m0s | 45s |
| 262144 | 7m22s | 2m29s |
| 524288 | 20m12s | 7m8s |
| 1048576 | 1h10m | 29m54s |

Table 5. Commitment Times (no preprocessing)

| n(size in bits) | This work(precomp.) | This work | BBF |
| --- | --- | --- | --- |
| 16384 | $2\cdot10^{-4}$ | 5.56 | 5.86 |
| 32768 | $2\cdot10^{-4}$ | 11.17 | 11.69 |
| 64536 | $2\cdot10^{-4}$ | 22.44 | 23.26 |
| 131072 | $2\cdot10^{-4}$ | 44.68 | 45.49 |
| 262144 | $2\cdot10^{-4}$ | 88.98 | 90.72 |
| 524288 | $2\cdot10^{-4}$ | 178.94 | 184.86 |
| 1048576 | $2\cdot10^{-4}$ | 357.50 | 370.82 |

$$
\overline{{2\cdot10^{-4}}}
$$

$$
2\cdot10^{-4}
$$

$$
2\cdot10^{-4}
$$

$$
2\cdot10^{-4}
$$

$$
2\cdot{10}^{-4}
$$

$$
2\cdot10^{-4}
$$

$$
2\cdot{10}^{-4}
$$

Table 6. Opening Times (in s) for openings of 256 bits

| n(size in bits) | This work(precomp.) | This work | BBF |
| --- | --- | --- | --- |
| 16384 | 4.27 | 5.70 | 7.96 |
| 32768 | 4.27 | 11.34 | 14.75 |
| 64536 | 4.27 | 22.84 | 28.10 |
| 131072 | 4.27 | 45.44 | 54.17 |
| 262144 | 4.27 | 91.45 | 108.69 |
| 524288 | 4.27 | 182.29 | 222.47 |
| 1048576 | 4.27 | 362.50 | 453.28 |

Table 7. Opening Times (in s) for openings of 2048 bits

| n(size in bits) | This work(precomp.) | This work | BBF |
| --- | --- | --- | --- |
| 64536 | 73.57 | 25.96 | 66.16 |
| 131072 | 73.57 | 52.42 | 122.68 |
| 262144 | 73.57 | 104.63 | 238.07 |
| 524288 | 73.57 | 210.40 | 521.89 |
| 1048576 | 73.57 | 423.48 | 1100.10 |

Table 8. Opening Times (in s) for openings of 16384 bits

---

| m·l(opening in bits) | This work | BBF |
| --- | --- | --- |
| 256 | 3.31 | 7.72 |
| 2048 | 8.97 | 13.28 |
| 16384 | 309.82 | 314.28 |

Table 9. Verication Times (in ms)

Fig. 7. Commitment Experiments

---

Fig. 8. Opening Experiments

---

Fig. 9. Amortized Opening Experiments for a le of size 128 Kibib.
