0단 자동
AI가 규칙대로 쓰고 그대로 게시했습니다. 사람이 따로 보지 않았습니다.
- 규칙 판
- 규칙 판 도입 이전 기사입니다.
- 남기는 것
- 규칙 판 · 모델 · 시각
- 판 기록
- 아직 없습니다.
On the Security of Constraint-Friendly Map-to-Curve Relations
- 1.Asiacrypt 2025의 제약회로 친화적 map-to-curve 기법에서 보안증명의 세 가지 허점을 지적
- 2.EC-GGM이 실제 배치된 곡선의 대수구조를 포착 못 한다는 점을 이용해 구체적 서명 위조 공격을 시연
- 3.y-증분 변형으로 공격을 무력화하는 대안을 제시, gnark(Go)로 구현하고 저자들의 Noir 구현에서도 공격을 확인
왜 중요한가?
ZK 회로 비용 절감을 노린 최신 hash-to-curve 우회 기법이 실제로는 위조 가능함을 보여, ZK 프로토콜 구현자들에게 구체적 보안 경고를 제공한다.
본문 미리보기
Standard hash-to-curve constructions first hash the message to a field element through a cryptographic hash-to-field step, then map this field element to an elliptic-curve point. Inside constraint systems, this inner cryptographic hash is often the dominant cost. Groth, Malvai, Miller and Zhang (Asiacrypt 2025) introduced \emph{constraint-friendly map-to-elliptic-curve-group relations} that bypass this step, achieving substantial reductions in circuit size. Their security proof works in the El
전체 내용이 궁금하다면?
원문을 직접 읽어보세요
이 글이 만들어진 과정
- 11:24AI 초안



