{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T01:13:32Z","timestamp":1779326012860,"version":"3.51.4"},"publisher-location":"Cham","reference-count":45,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031780165","type":"print"},{"value":"9783031780172","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,11,28]],"date-time":"2024-11-28T00:00:00Z","timestamp":1732752000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,11,28]],"date-time":"2024-11-28T00:00:00Z","timestamp":1732752000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-78017-2_16","type":"book-chapter","created":{"date-parts":[[2024,11,27]],"date-time":"2024-11-27T23:48:24Z","timestamp":1732751304000},"page":"464-496","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Security Bounds for\u00a0Proof-Carrying Data from\u00a0Straightline Extractors"],"prefix":"10.1007","author":[{"given":"Alessandro","family":"Chiesa","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ziyi","family":"Guan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shahar","family":"Samocha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eylon","family":"Yogev","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,11,28]]},"reference":[{"key":"16_CR1","unstructured":"Barbara, A., Chiesa, A., Guan, Z.: Relativized succinct arguments in the ROM do not exist. Cryptology ePrint Archive, Paper 2024\/728 (2024). https:\/\/eprint.iacr.org\/2024\/728"},{"key":"16_CR2","doi-asserted-by":"crossref","unstructured":"Bartusek, J., Bronfman, L., Holmgren, J., Ma, F., Rothblum, R.D.: On the (in)security of Kilian-based SNARGs. In: Proceedings of the 17th Theory of Cryptography Conference, pp. 522\u2013551. TCC\u00a02019 (2019)","DOI":"10.1007\/978-3-030-36033-7_20"},{"key":"16_CR3","unstructured":"Beal, J., Fisch, B.: Derecho: privacy pools with proof-carrying disclosures. Cryptology ePrint Archive, Paper 2023\/273 (2023). https:\/\/eprint.iacr.org\/2023\/273"},{"key":"16_CR4","doi-asserted-by":"crossref","unstructured":"Bellare, M., Rogaway, P.: Random oracles are practical: A paradigm for designing efficient protocols. In: Proceedings of the 1st ACM Conference on Computer and Communications Security, pp. 62\u201373. CCS\u00a01993 (1993)","DOI":"10.1145\/168588.168596"},{"key":"16_CR5","doi-asserted-by":"crossref","unstructured":"Ben-Sasson, E., Bentov, I., Horesh, Y., Riabzev, M.: Scalable zero knowledge with no trusted setup. In: Proceedings of the 39th Annual International Cryptology Conference, pp. 733\u2013764. CRYPTO\u00a02019 (2019)","DOI":"10.1007\/978-3-030-26954-8_23"},{"key":"16_CR6","doi-asserted-by":"crossref","unstructured":"Ben-Sasson, E., Chiesa, A., Spooner, N.: Interactive oracle proofs. In: Proceedings of the 14th Theory of Cryptography Conference, pp. 31\u201360. TCC\u00a02016-B (2016)","DOI":"10.1007\/978-3-662-53644-5_2"},{"key":"16_CR7","doi-asserted-by":"publisher","unstructured":"Ben-Sasson, E., Chiesa, A., Tromer, E., Virza, M.: Scalable zero knowledge via cycles of elliptic curves. In: Garay, J.A., Gennaro, R. (eds.) CRYPTO 2014. LNCS, vol. 8617, pp. 276\u2013294. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-44381-1_16","DOI":"10.1007\/978-3-662-44381-1_16"},{"key":"16_CR8","doi-asserted-by":"crossref","unstructured":"Bitansky, N., Canetti, R., Chiesa, A., Tromer, E.: Recursive composition and bootstrapping for SNARKs and proof-carrying data. In: Proceedings of the 45th ACM Symposium on the Theory of Computing, pp. 111\u2013120. STOC\u00a02013 (2013)","DOI":"10.1145\/2488608.2488623"},{"key":"16_CR9","doi-asserted-by":"crossref","unstructured":"Boneh, D., Drake, J., Fisch, B., Gabizon, A.: Halo infinite: proof-carrying data from additive polynomial commitments. In: Proceedings of the 41st Annual International Cryptology Conference, pp. 649\u2013680. CRYPTO\u00a02021 (2021)","DOI":"10.1007\/978-3-030-84242-0_23"},{"key":"16_CR10","unstructured":"Bonneau, J., Meckler, I., Rao, V., Shapiro, E.: Coda: Decentralized cryptocurrency at scale. IACR Cryptology ePrint Archive, Report 2020\/352 (2020)"},{"key":"16_CR11","unstructured":"Bowe, S., Grigg, J., Hopwood, D.: Halo: Recursive proof composition without a trusted setup. Cryptology ePrint Archive, Report 2019\/1021 (2019)"},{"key":"16_CR12","doi-asserted-by":"crossref","unstructured":"B\u00fcnz, B., Chen, B.: ProtoStar: generic efficient accumulation\/folding for special-soundprotocols. In: Proceedings of the 29th International Conference on the Theory and Application of Cryptology and Information Security, pp. 77\u2013110. ASIACRYPT\u00a02023 (2023)","DOI":"10.1007\/978-981-99-8724-5_3"},{"key":"16_CR13","doi-asserted-by":"crossref","unstructured":"B\u00fcnz, B., Chiesa, A., Lin, W., Mishra, P., Spooner, N.: Proof-carrying data without succinct arguments. In: Proceedings of the 41st Annual International Cryptology Conference, pp. 681\u2013710. CRYPTO\u00a02021 (2021)","DOI":"10.1007\/978-3-030-84242-0_24"},{"key":"16_CR14","doi-asserted-by":"crossref","unstructured":"B\u00fcnz, B., Chiesa, A., Mishra, P., Spooner, N.: Proof-carrying data from accumulation schemes. In: Proceedings of the 18th Theory of Cryptography Conference, pp. 1\u201318. TCC\u00a02020 (2020)","DOI":"10.1007\/978-3-030-64378-2_1"},{"issue":"4","key":"16_CR15","doi-asserted-by":"publisher","first-page":"557","DOI":"10.1145\/1008731.1008734","volume":"51","author":"R Canetti","year":"2004","unstructured":"Canetti, R., Goldreich, O., Halevi, S.: The random oracle methodology, revisited. J. ACM 51(4), 557\u2013594 (2004)","journal-title":"J. ACM"},{"key":"16_CR16","doi-asserted-by":"crossref","unstructured":"Chen, M., Chiesa, A., Gur, T., O\u2019Connor, J., Spooner, N.: Proof-carrying data from arithmetized random oracles. In: Proceedings of the 42nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, pp. 379\u2013404. EUROCRYPT\u00a02023 (2023)","DOI":"10.1007\/978-3-031-30617-4_13"},{"key":"16_CR17","doi-asserted-by":"crossref","unstructured":"Chen, M., Chiesa, A., Spooner, N.: On succinct non-interactive arguments in relativized worlds. In: Proceedings of the 41st Annual International Conference on the Theory and Applications of Cryptographic Techniques. EUROCRYPT\u00a02022 (2022)","DOI":"10.1007\/978-3-031-07085-3_12"},{"key":"16_CR18","unstructured":"Chen, W., Chiesa, A., Dauterman, E., Ward, N.P.: Reducing participation costs via incremental verification for ledger systems. Cryptology ePrint Archive, Report 2020\/1522 (2020)"},{"key":"16_CR19","unstructured":"Chiesa, A., Liu, S.: On the impossibility of probabilistic proofs in relativized worlds. In: Proceedings of the 11th Innovations in Theoretical Computer Science Conference. ITCS\u00a02020 (2020)"},{"key":"16_CR20","doi-asserted-by":"crossref","unstructured":"Chiesa, A., Ojha, D., Spooner, N.: Fractal: Post-quantum and transparent recursive proofs from holography. In: Proceedings of the 39th Annual International Conference on the Theory and Applications of Cryptographic Techniques, pp. 769\u2013793. EUROCRYPT\u00a02020 (2020)","DOI":"10.1007\/978-3-030-45721-1_27"},{"key":"16_CR21","unstructured":"Chiesa, A., Tromer, E.: Proof-carrying data and hearsay arguments from signature cards. In: Proceedings of the 1st Symposium on Innovations in Computer Science, pp. 310\u2013331. ICS\u00a02010 (2010)"},{"key":"16_CR22","doi-asserted-by":"crossref","unstructured":"Chiesa, A., Tromer, E., Virza, M.: Cluster computing in zero knowledge. In: Proceedings of the 34th Annual International Conference on Theory and Application of Cryptographic Techniques, pp. 371\u2013403. EUROCRYPT\u00a02015 (2015)","DOI":"10.1007\/978-3-662-46803-6_13"},{"key":"16_CR23","doi-asserted-by":"crossref","unstructured":"Chiesa, A., Yogev, E.: Subquadratic SNARGs in the random oracle model. In: Proceedings of the 41st Annual International Cryptology Conference, pp. 711\u2013741. CRYPTO\u00a02021 (2021)","DOI":"10.1007\/978-3-030-84242-0_25"},{"key":"16_CR24","doi-asserted-by":"crossref","unstructured":"Chiesa, A., Yogev, E.: Tight security bounds for Micali\u2019s SNARGs. In: Proceedings of the 19th Theory of Cryptography Conference, pp. 401\u2013434. TCC\u00a02021 (2021)","DOI":"10.1007\/978-3-030-90459-3_14"},{"key":"16_CR25","unstructured":"Chiesa, A., Yogev, E.: Building Cryptographic Proofs from Hash Functions (2024). https:\/\/github.com\/hash-based-snargs-book"},{"key":"16_CR26","unstructured":"Chong, S., Tromer, E., Vaughan, J.A.: Enforcing language semantics using proof-carrying data. Cryptology ePrint Archive, Report 2013\/513 (2013)"},{"key":"16_CR27","unstructured":"Ethereum. Zero-Knowledge Rollups (2023). https:\/\/ethereum.org\/en\/developers\/docs\/ scaling\/zk-rollups\/"},{"key":"16_CR28","doi-asserted-by":"crossref","unstructured":"Fiore, D., Nitulescu, A.: On the (in)security of SNARKs in the presence of oracles. In: Proceedings of the 14th Theory of Cryptography Conference, pp. 108\u2013138. TCC\u00a02016-B (2016)","DOI":"10.1007\/978-3-662-53641-4_5"},{"key":"16_CR29","doi-asserted-by":"crossref","unstructured":"Gentry, C., Wichs, D.: Separating succinct non-interactive arguments from all falsifiable assumptions. In: Proceedings of the 43rd Annual ACM Symposium on Theory of Computing, pp. 99\u2013108. STOC\u00a02011 (2011)","DOI":"10.1145\/1993636.1993651"},{"key":"16_CR30","unstructured":"Goldberg, L., Papini, S., Riabzev, M.: Cairo: a turing-complete STARK-friendly CPU architecture. IACR Cryptology ePrint Archive, Report 2021\/1063 (2021)"},{"key":"16_CR31","doi-asserted-by":"crossref","unstructured":"Hall-Andersen, M., Nielsen, J.B.: On valiant\u2019s conjecture: impossibility of incrementally verifiable computation from random oracles. In: Proceedings of the 42nd Annual International Conference on the Theory and Applications of Cryptographic Techniques. EUROCRYPT\u00a02023 (2023)","DOI":"10.1007\/978-3-031-30617-4_15"},{"key":"16_CR32","doi-asserted-by":"crossref","unstructured":"Kattis, A., Bonneau, J.: Proof of necessary work: Succinct state verification with fairness guarantees. In: Proceedings of the 27th Financial Cryptography and Data Security. FC\u00a02023 (2023)","DOI":"10.1007\/978-3-031-47751-5_2"},{"key":"16_CR33","unstructured":"Kothapalli, A., Setty, S.: SuperNova: proving universal machine executions without universal circuits. Cryptology ePrint Archive, Paper 2022\/1758 (2022)"},{"key":"16_CR34","doi-asserted-by":"crossref","unstructured":"Kothapalli, A., Setty, S., Tzialla, I.: Nova: recursive zero-knowledge arguments from folding schemes. In: Proceedings of the 42nd Annual International Cryptology Conference, pp. 359\u2013388. CRYPTO\u00a02022 (2022)","DOI":"10.1007\/978-3-031-15985-5_13"},{"key":"16_CR35","unstructured":"Matter Labs. zkSync v1.1 \u201cReddit Edition\u201d: Recursion (2020). https:\/\/blog.matter-labs.io\/zksync-v1-1-reddit-edition-recursion-up-to-3-000-tps-subscriptionsand-more-fea668b5b0ff"},{"key":"16_CR36","doi-asserted-by":"crossref","unstructured":"Micali, S.: Computationally sound proofs. SIAM J. Comput. 30(4), 1253\u20131298 (2000). preliminary version appeared in FOCS\u00a01994","DOI":"10.1137\/S0097539795284959"},{"key":"16_CR37","doi-asserted-by":"crossref","unstructured":"Naveh, A., Tromer, E.: PhotoProof: cryptographic image authentication for any set of permissible transformations. In: Proceedings of the 37th IEEE Symposium on Security and Privacy, pp. 255\u2013271. S &P\u00a02016 (2016)","DOI":"10.1109\/SP.2016.23"},{"key":"16_CR38","unstructured":"O(1) Labs: Mina Cryptocurrency (2017). https:\/\/minaprotocol.com\/"},{"key":"16_CR39","doi-asserted-by":"crossref","unstructured":"Paneth, O., Pass, R.: Incrementally verifiable computation via rate-1 batch arguments. In: Proceedings of the 63rd Annual IEEE Symposium on Foundations of Computer Science, pp. 1045\u20131056. FOCS\u00a02022 (2022)","DOI":"10.1109\/FOCS54457.2022.00102"},{"key":"16_CR40","unstructured":"Polygon: The go fast machine: adding recursion to polygon zkEVM (2023). https:\/\/polygon.technology\/blog\/the-go-fast-machine-adding-recursion-to-polygon-zkevm"},{"key":"16_CR41","unstructured":"Polymer Labs: a tutorial on writing proofs with Plonky2 (2022). https:\/\/polymerlabs.medium.com\/a-tutorial-on-writing-zk-proofs-with-plonky2-part-i-be5812f6b798"},{"key":"16_CR42","unstructured":"StarkWare Industries: Starkware: SHARP Verifier (2021). https:\/\/etherscan.io\/address\/0x47312450b3ac8b5b8e247a6bb6d523e7605bdb60"},{"key":"16_CR43","unstructured":"StarkWare Industries: Recursive STARKs (2022). https:\/\/medium.com\/@starkware\/recursive-starks-78f8dd401025"},{"key":"16_CR44","doi-asserted-by":"crossref","unstructured":"Tyagi, N., Fisch, B., Zitek, A., Bonneau, J., Tessaro, S.: VeRSA: Verifiable registries with efficient client audits from RSA authenticated dictionaries. In: Proceedings of the 29th ACM Conference on Computer and Communications Security. pp. 2793\u20132807. CCS\u00a0\u201922 (2022)","DOI":"10.1145\/3548606.3560605"},{"key":"16_CR45","doi-asserted-by":"crossref","unstructured":"Valiant, P.: Incrementally verifiable computation or proofs of knowledge imply time\/space efficiency. In: Proceedings of the 5th Theory of Cryptography Conference, pp. 1\u201318. TCC\u00a02008 (2008)","DOI":"10.1007\/978-3-540-78524-8_1"}],"container-title":["Lecture Notes in Computer Science","Theory of Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-78017-2_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,28]],"date-time":"2024-11-28T00:18:04Z","timestamp":1732753084000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-78017-2_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,28]]},"ISBN":["9783031780165","9783031780172"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-78017-2_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11,28]]},"assertion":[{"value":"28 November 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"TCC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Theory of Cryptography Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 December 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 December 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"tcc2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/tcc.iacr.org\/2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}