The Fischlin transform yields non-interactive zero-knowledge proofs with straight-line extractability in the classical random oracle model. This is done by forcing a prover to generate multiple accepting transcripts through a proof-of-work mechanism. Whether the Fischlin transform is straight-line extractable against quantum adversaries has remained open due to the difficulty of reasoning about the likelihood of query transcripts in the quantum-accessible random oracle model (QROM), even when using the compressed oracle methodology. In this work, we prove that the Fischlin transform remains straight-line extractable in the QROM, via an extractor based on the compressed oracle. This establishes the post-quantum security of the Fischlin transform, providing a post-quantum straight-line extractable NIZK alternative to Pass' transform with smaller proof size. Our techniques include tail bounds for sums of independent random variables and for martingales as well as symmetrization, query amplitude and quantum union bound arguments.
翻译:Fischlin变换通过在经典随机预言机模型中利用工作量证明机制,迫使证明者生成多个可接受的交互记录,从而实现了具备直通线可提取性的非交互零知识证明。Fischlin变换能否在量子敌手场景下保持直通线可提取性一直是一个开放问题——即使采用压缩预言机方法论,量子可访问随机预言机模型中查询交互记录发生概率的论证难度仍构成主要挑战。在本文中,我们通过基于压缩预言机的提取器证明Fischlin变换在量子随机预言机模型中仍保持直通线可提取性。这一结果确立了Fischlin变换的后量子安全性,为Pass变换提供了具有更短证明长度的后量子直通线可提取非交互零知识证明替代方案。我们的技术方法包括独立随机变量和与鞅的尾界、对称化技术、查询振幅论证以及量子联合界论证。