Skip to main navigation Skip to search Skip to main content

Simple and Efficient Batch Verification Techniques for Verifiable Delay Functions

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

10 Scopus citations

Abstract

We study the problem of batch verification for verifiable delay functions (VDFs), focusing on proofs of correct exponentiation (PoCE), which underlie recent VDF constructions. We show how to compile any PoCE into a batch PoCE, offering significant savings in both communication and verification time. Concretely, given any PoCE with communication complexity c, verification time t and soundness error δ, and any pseudorandom function with key length kprf and evaluation time tprf, we construct: A batch PoCE for verifying n instances with communication complexity m· c+ kprf, verification time m· t+ n· m· O(top+ tprf) and soundness error δ+ 2- m, where λ is the security parameter, m is an adjustable parameter that can take any integer value, and top is the time required to evaluate the group operation in the underlying group. This should be contrasted with the naïve approach, in which the communication complexity and verification time are n· c and n· t, respectively. The soundness of this compiler relies only on the soundness of the underlying PoCE and the existence of one-way functions.An improved batch PoCE based on the low order assumption. For verifying n instances, the batch PoCE requires communication complexity c+ kprf and verification time t+ n· (tprf+ log (s) · O(top) ), and has soundness error δ+ 1 / s. The parameter s can take any integer value, as long as it is hard to find group elements of order less than s in the underlying group. We discuss instantiations in which s can be exponentially large in the security parameter λ. If the underlying PoCE is constant round and public coin (as is the case for existing protocols), then so are all of our batch PoCEs, implying that they can be made non-interactive using the Fiat-Shamir transform. Additionally, for RSA groups with moduli which are the products of two safe primes, we show how to efficiently verify that certain elements are not of order 2. This protocol, together with the second compiler above and any (single-instance) PoCE in these groups, yields an efficient batch PoCE in safe RSA groups. To complete the picture, we also show how to extend Pietrzak’s protocol (which is statistically sound in the group QRN+ when N is the product of two safe primes) to obtain a statistically-sound PoCE in safe RSA groups.

Original languageEnglish
Title of host publicationTheory of Cryptography - 19th International Conference, TCC 2021, Proceedings
EditorsKobbi Nissim, Brent Waters, Brent Waters
PublisherSpringer Science and Business Media Deutschland GmbH
Pages382-414
Number of pages33
ISBN (Print)9783030904555
DOIs
StatePublished - 2021
Event19th International Conference on Theory of Cryptography, TCC 2021 - Raleigh, United States
Duration: 8 Nov 202111 Nov 2021

Publication series

NameLecture Notes in Computer Science
Volume13044 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference19th International Conference on Theory of Cryptography, TCC 2021
Country/TerritoryUnited States
CityRaleigh
Period8/11/2111/11/21

Bibliographical note

Publisher Copyright:
© 2021, International Association for Cryptologic Research.

Fingerprint

Dive into the research topics of 'Simple and Efficient Batch Verification Techniques for Verifiable Delay Functions'. Together they form a unique fingerprint.

Cite this