Bibliographic Details
| Title: |
SPARKs: Succinct Parallelizable Arguments of Knowledge. |
| Authors: |
EPHRAIM, NAOMI1 nephraim@cs.cornell.edu, FREITAG, CODY1 cfreitag@cs.cornell.edu, KOMARGODSKI, ILAN2,3 ilank@cs.huji.ac.il, PASS, RAFAEL1 rafael@cs.cornell.edu |
| Source: |
Journal of the ACM. Sep2022, Vol. 69 Issue 5, p1-88. 88p. |
| Subject Terms: |
*Parallel programming, Polynomial time algorithms, Argument |
| Abstract: |
We introduce the notion of a Succinct Parallelizable Argument of Knowledge (SPARK). This is an argument of knowledge with the following three efficiency properties for computing and proving a (non-deterministic, polynomial time) parallel RAMcomputation that can be computed in parallel timeT with at most p processors: -- The prover's (parallel) running time is T + polylog(T · p). (In other words, the prover's running time is essentially T for large computation times!) -- The prover uses at most p · polylog(T · p) processors. -- The communication and verifier complexity are both polylog(T · p). The combination of all three is desirable, as it gives a way to leverage a moderate increase in parallelism in favor of near-optimal running time. We emphasize that even a factor two overhead in the prover's parallel running time is not allowed. Our main contribution is a generic construction of SPARKs from any succinct argument of knowledge where the prover's parallel running time is T · polylog(T · p) when using p processors, assuming collisionresistant hash functions. When suitably instantiating our construction, we achieve a four-round SPARK for any parallel RAM computation assuming only collision resistance. Additionally assuming the existence of a succinct non-interactive argument of knowledge (SNARK), we construct a non-interactive SPARK that also preserves the space complexity of the underlying computation up to polylog(T · p) factors. We also show the following applications of non-interactive SPARKs. First, they immediately imply delegation protocols with near optimal prover (parallel) running time. This, in turn, gives a way to construct verifiable delay functions (VDFs) from any sequential function. When the sequential function is also memoryhard, this yields the first construction of a memory-hard VDF. [ABSTRACT FROM AUTHOR] |
|
Copyright of Journal of the ACM is the property of Association for Computing Machinery and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) |
| Database: |
Business Source Index |