Saturday, August 29, 2026
  • Login
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
CRYPTO MARKETCAP
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
No Result
View All Result
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result

When using Groth16 on Ethereum through ᴇɪᴘ‒197, is it really needed to change both G₂ points of the public & private inputs in the trusted setup for avoiding public input forgery ?

by SB Crypto Guru News
October 5, 2024
in Ethereum
Reading Time: 4 mins read
0 0
A A
0


When using Groth16 on Ethereum through ᴇɪᴘ‒197, is it really needed to change both G₂ points of the public & private inputs in the trusted setup for avoiding public input forgery ?

First remember Ethereum only allow to check if a set of pairings is equal to 1 in Fp12 and not to compare equalities like in Zcash which is why the equations below are different and would worth downvotes on a cryptographic sub as a result… Otherwise I recognize this is more a mathematical problem but the place where I’m the most likely to find someone who do understand it remains on Ethereum as it’s partly cryptocurrency math specific.

For those who don’t know about Groth16 :

By convention, public portions of the witness are the first ℓ elements of the vector a. To make those elements public, the prover simply reveals them :

[a₁,a₂,…,aℓ]

For the verifier to test that those values were in fact used, verifier must carry out some of the computation that the prover was originally doing.

Specifically, the prover computes :

Sorry, but no MathJax on reddit

Note that only the computation of [C]₁ changed — the prover only uses the ai and Ψi terms ℓ+1 to m.

The verifier computes the first ℓ terms of the sum:

Sorry but no MathJax on reddit

And the ᴇɪᴘ‒197 equation in the case of Ethereum on Fp12 is : 1?=[A]₁∙[B]₂×[α]₁∙[β]₂×[X]₁∙G₂×[C]₁∙G₂

Part 2 : Separating the public inputs from the private inputs with γ and δ

The first attack described in the tutorial I read and how it’s said to be prevented :

The assumption in the equation above is that the prover is only using Ψ(ℓ+1) to Ψm to compute [C]₁, but nothing stops a dishonest prover from using Ψ₁ to Ψℓ to compute [C]₁, leading to a forged proof.

For example, here is our current ᴇɪᴘ‒197 verification equation :

Sorry but no MathJax on reddit

If we expand the C term under the hood, we get the following :

Sorry but no MathJax on reddit

Suppose for example and without loss of generality that a=[1,2,3,4,5] and ℓ=3. In that case, the public part of the witness is [1,2,3] and the private part is [4,5].

The final equation after evaluating the witness vector would be as follows :

Sorry but no MathJax on reddit

However since the discrete logarithm between the public and private point in G₂ is 1, nothing stops the prover from creating an valid portion of the public witness as [1,2,0] and moving the zeroed out public portion to the private part of the computation as follows :

Sorry but no MathJax on reddit

The equation above is valid, but the witness does not necessarily satisfy the original constraints.

Therefore, we need to prevent the prover from using Ψ₁ to Ψℓ as part of the computation of [C]₁.

Introducing γ and δ :

To avoid the problem above, the trusted setup introduces new scalars γ and δ to force Ψℓ+1 to Ψm to be separate from Ψ₁ to Ψℓ. To do this, the trusted setup divides (multiplies by the modular inverse) the private terms (that constitute [C]₁) by γ and the public terms (that constitute [X]₁, the sum the verifier computes) by δ.

Since the h(τ)t(τ) term is embedded in [C]₁, those terms also need to be divided by γ.

Again, no MathJax on reddit

The trusted setup publishes

Maybe I could use text for that one ?

The prover steps are the same as before and the verifier steps now include pairing by [γ]₂ and [δ]₂ to cancel out the denominators :

The ᴇɪᴘ‑197 with Groth16 as it’s expected to be

The thing I’m not understanding :

So it seems to me the description above is the attack is possible because the 2 G₂ points resulting from the witness input split for public inputs are equals and thus the discrete logarithm is know since it’s equal, In the other case why is it required to modify both the private and public terms ? How could proofs be still faked without knowing the discrete logarithms between δ and G₂ ?
Why not just divide the private terms that constitute [C]₁ by δ and leave the public terms as is ? This would mean :

Please compare with the last equation above and the first unmodified verifying equation

submitted by /u/AbbreviationsGreen90
[comments]



Source link

Tags: ampAvoidingBitcoin NewschangeCrypto NewsCrypto Updatesethereumᴇɪᴘ197forgeryG₂Groth16InputinputsLatest News on CryptoNeededpointsPrivatepublicSB Crypto Guru Newssetuptrusted
Previous Post

Building Web3 culture in Ukraine: Rostyslav Bortman’s mission

Next Post

MultiversX (EGLD) Continues To Lead All Crypto Gaming Projects in Level of Development Activity: Santiment

Related Posts

Glamsterdam Repricing Impact for Smart Contract Developers

by SB Crypto Guru News
August 24, 2026
0

TL;DR: The upcoming Glamsterdam upgrade includes a set of gas repricings. EIP-8037 and EIP-8038 (both scheduled for inclusion) adjust the...

Raising machine-checked security benchmarks to advance hash-based SNARKs through agentic collaboration

by SB Crypto Guru News
August 20, 2026
0

better.codes, an open autoresearch challenge built by the Ethereum Foundation Formal Verification team in collaboration with Yukon and zkSecurity, is...

Allocation Update – Q2 2026

by SB Crypto Guru News
August 18, 2026
0

DAOs/GovernanceResearchFaculty Research Fellowship: Ethereum Studies (AY 2025–2026)Enables Prof. Strnad to dedicate substantial research time to Ethereum-focused problems, including DAO governance,...

Announcing the Platåberget Testnet | Ethereum Foundation Blog

Announcing the Platåberget Testnet | Ethereum Foundation Blog

by SB Crypto Guru News
August 17, 2026
0

tl;dr: Meet Platåberget: Glamsterdam's (Gloas + Amsterdam) early testing ground open to public participation. This upgrade comes with breaking changes...

Trezor Data Breach exposes almost 14.000 customers home addresses tied to hardware-wallet purchases. Stay safe!

Trezor Data Breach exposes almost 14.000 customers home addresses tied to hardware-wallet purchases. Stay safe!

by SB Crypto Guru News
August 15, 2026
0

Key Takeaways In August 2026, a data exposure at Trezor's shipping provider, ShipMonk, affected approximately 14,000 customers, revealing names, email...

Load More
Next Post
MultiversX (EGLD) Continues To Lead All Crypto Gaming Projects in Level of Development Activity: Santiment

MultiversX (EGLD) Continues To Lead All Crypto Gaming Projects in Level of Development Activity: Santiment

Paypal Completes First Corporate Transaction Using PYUSD Stablecoin

Paypal Completes First Corporate Transaction Using PYUSD Stablecoin

  • Trending
  • Comments
  • Latest
Why the Founders Winning With AI Agents Aren’t the Ones Automating the Most

Why the Founders Winning With AI Agents Aren’t the Ones Automating the Most

August 14, 2026
AVAX Price Prediction: Bears Own This Chart — .98 Is the Next Stop

AVAX Price Prediction: Bears Own This Chart — $5.98 Is the Next Stop

August 16, 2026
How AI Agents Are Deleting the Steep Web3 Tooling Curve

How AI Agents Are Deleting the Steep Web3 Tooling Curve

August 15, 2026
Saylor and Strategy Officially Back CLARITY Act for US Crypto

Saylor and Strategy Officially Back CLARITY Act for US Crypto

July 31, 2026

TON Validators Prepare Node Update Ahead Of Collator Vote

August 22, 2026
How to Track Your Brand’s AI Visiblity in 2026 

How to Track Your Brand’s AI Visiblity in 2026 

August 1, 2026

Rotterdam’s Museum Boijmans Van Beuningen caught up in alleged bribery scandal as civil servants dismissed – The Art Newspaper

0

Debasement Trade Will Benefit Bitcoin, Says Grayscale

0

Grayscale Zcash ETF Filing Puts Privacy Coin Back In Regulatory Spotlight

0

Bitcoin ETFs Snap 9-Day Streak With $202M Exit as Ether Gains $102M

0

I’ve Built Companies in 6 Industries. The Same 5 Patterns Determine Success Every Time.

0

Polygon Labs issues urgent client upgrade notice following Austin and Kyoto hardforks

0

Bitcoin ETFs Snap 9-Day Streak With $202M Exit as Ether Gains $102M

August 29, 2026

NFL Returns to Draftkings and Fanduel, Still Shuns Prediction Markets

August 29, 2026

Polygon Labs issues urgent client upgrade notice following Austin and Kyoto hardforks

August 29, 2026

Ripple Donates $300K to Flood Relief in Nepal and Tibet Through WCK, Mercy Corps

August 29, 2026

GLM-5.3 Flash Cuts Costs by 17x with Minimal Quality Drop

August 29, 2026

Ripple Prime Expands Into Equity Derivatives With Delta One Launch

August 29, 2026
Facebook Twitter LinkedIn Tumblr RSS
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at SB Crypto Guru News.

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • Mining
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.