{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,9]],"date-time":"2026-01-09T21:23:02Z","timestamp":1767993782222,"version":"3.49.0"},"publisher-location":"Cham","reference-count":62,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032122865","type":"print"},{"value":"9783032122872","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,12,2]],"date-time":"2025-12-02T00:00:00Z","timestamp":1764633600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,12,2]],"date-time":"2025-12-02T00:00:00Z","timestamp":1764633600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-12287-2_16","type":"book-chapter","created":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T16:17:57Z","timestamp":1764605877000},"page":"452-474","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["A Fiat\u2013Shamir Transformation from Duplex Sponges"],"prefix":"10.1007","author":[{"given":"Alessandro","family":"Chiesa","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6518-2712","authenticated-orcid":false,"given":"Michele","family":"Orr\u00f9","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,12,2]]},"reference":[{"key":"16_CR1","unstructured":"Ashur, T., et al.: Generalized Indifferentiable Sponge and its Application to Polygon Miden VM. Cryptology ePrint Archive, Paper 2024\/911 (2024)"},{"key":"16_CR2","doi-asserted-by":"publisher","unstructured":"Attema, T., et al.: Fiat-Shamir Transformation of Multi-round Interactive Proofs, vol. 13747. TCC \u201922 (2022). https:\/\/doi.org\/10.1007\/978-3-031-22318-1_5","DOI":"10.1007\/978-3-031-22318-1_5"},{"key":"16_CR3","doi-asserted-by":"publisher","unstructured":"Albrecht, M.R., et al.: MiMC: efficient encryption and cryptographic hashing with minimal multiplicative complexity. In: ASIACRYPT \u201916 (2016). https:\/\/doi.org\/10.1007\/978-3-662-53887-6_7","DOI":"10.1007\/978-3-662-53887-6_7"},{"key":"16_CR4","unstructured":"Aumasson, J., et al.: SAFE: Sponge API for Field Elements. Cryptology ePrint Archive, Paper 2023\/522 (2023)"},{"key":"16_CR5","unstructured":"A library of useful cryptographic primitives. https:\/\/github.com\/arkworksrs\/crypto-primitives"},{"key":"16_CR6","unstructured":"Arkworks. arkworks: an ecosystem for developing and programming with zkSNARKs. https:\/\/github.com\/arkworks-rs"},{"key":"16_CR7","unstructured":"Arnon, G., et al.: Towards a white-box secure fiat-shamir transformation. Cryptology ePrint Archive, Paper 2025\/329 (2025). https:\/\/eprint.iacr.org\/2025\/329"},{"key":"16_CR8","unstructured":"Aztec. Aztec monorepo. https:\/\/github.com\/AztecProtocol\/aztecpackages\/"},{"key":"16_CR9","doi-asserted-by":"crossref","unstructured":"Barak, B.: How to go beyond the black-box simulation barrier. In: FOCS \u201901 (2001)","DOI":"10.1109\/SFCS.2001.959885"},{"key":"16_CR10","doi-asserted-by":"publisher","unstructured":"Bouvier, C., et al.: New design techniques for efficient arithmetization-oriented hash functions: anemoi permutations and jive compression mode. In: CRYPTO\u201923. ISBN: 978-3-031-38547-6. https:\/\/doi.org\/10.1007\/978-3-031-38548-3_17","DOI":"10.1007\/978-3-031-38548-3_17"},{"key":"16_CR11","unstructured":"Bartusek, J., et al.: On the (In)security of Kilian-Based SNARGs. In: TCC \u201919 (2019). ISBN: 978-3-030-36033-7"},{"key":"16_CR12","doi-asserted-by":"crossref","unstructured":"Ben-Sasson, E., et al.: Interactive oracle proofs. In: TCC \u201916 (2016)","DOI":"10.1007\/978-3-662-53644-5_2"},{"key":"16_CR13","doi-asserted-by":"crossref","unstructured":"Bertoni, G., et al.: Farfalle: parallel permutation-based cryptography. In: FSE \u201918 (2018)","DOI":"10.46586\/tosc.v2017.i4.1-38"},{"key":"16_CR14","doi-asserted-by":"publisher","unstructured":"Bertoni, G., et al.: On the indifferentiability of the sponge construction. In: EUROCRYPT \u201908 (2008). https:\/\/doi.org\/10.1007\/978-3-540-78967-3_11","DOI":"10.1007\/978-3-540-78967-3_11"},{"key":"16_CR15","unstructured":"Bertoni, G., et al.: Duplexing the sponge: single-pass authenticated encryption and other applications. Springer, Berlin, Heidelberg (2012). ISBN: 978-3-642-28496-0"},{"key":"16_CR16","doi-asserted-by":"publisher","unstructured":"Brakerski, Z., et al.: NIZK from LPN and trapdoor hash via correlation intractability for approximable relations. In: CRYPTO \u201920 (2020). https:\/\/doi.org\/10.1007\/978-3-030-56877-1_26","DOI":"10.1007\/978-3-030-56877-1_26"},{"key":"16_CR17","unstructured":"Bowe, S., et al.: The Halo2 zero-knowledge proving system. https:\/\/github.com\/zcash\/halo2"},{"key":"16_CR18","doi-asserted-by":"publisher","unstructured":"Bellare, M., et al.: The security of triple encryption and a framework for code- based game-playing proofs. In: EUROCRYPT \u201906 (2006). https:\/\/doi.org\/10.1007\/11761679_25","DOI":"10.1007\/11761679_25"},{"key":"16_CR19","unstructured":"Canetti, R., et al.: Fiat-Shamir From Simpler Assumptions. IACR Cryptol. ePrint Arch. (2018). https:\/\/eprint.iacr.org\/2018\/1004"},{"key":"16_CR20","doi-asserted-by":"publisher","unstructured":"Canetti, R., et al.: Fiat-Shamir: from practice to theory. In: STOC \u201919 (2019). https:\/\/doi.org\/10.1145\/3313276.3316380","DOI":"10.1145\/3313276.3316380"},{"key":"16_CR21","doi-asserted-by":"publisher","unstructured":"Canetti, R., et al.: On the correlation intractability of obfuscated pseudorandom functions. In: TCC \u201916 (2016). https:\/\/doi.org\/10.1007\/978-3-662-49096-9_17","DOI":"10.1007\/978-3-662-49096-9_17"},{"key":"16_CR22","doi-asserted-by":"publisher","unstructured":"Canetti, R., et al.: Fiat-shamir and correlation intractability from strong KDMSecure encryption. In: EUROCRYPT \u201918 (2018). https:\/\/doi.org\/10.1007\/978-3-319-78381-9_4","DOI":"10.1007\/978-3-319-78381-9_4"},{"key":"16_CR23","doi-asserted-by":"publisher","unstructured":"Camenisch, J., et al.: The wonderful world of global random oracles. In: EUROCRYPT\u2019 18 (2018). https:\/\/doi.org\/10.1007\/978-3-319-78381-9_11","DOI":"10.1007\/978-3-319-78381-9_11"},{"key":"16_CR24","doi-asserted-by":"publisher","unstructured":"Chiesa, A., et al.: zkSNARKs in the ROM with unconditional UC-security. In: TCC \u201924 (2024). https:\/\/doi.org\/10.1007\/978-3-031-78011-0_3","DOI":"10.1007\/978-3-031-78011-0_3"},{"key":"16_CR25","doi-asserted-by":"crossref","unstructured":"Canetti, R., et al.: The random oracle methodology, revisited. J. ACM (2004)","DOI":"10.1145\/1008731.1008734"},{"key":"16_CR26","doi-asserted-by":"publisher","unstructured":"Choudhuri, A.R., et al.: Correlation intractability an SNARGs from sub-exponential DDH. In: CRYPTO \u201923 (2023). https:\/\/doi.org\/10.1007\/978-3-031-38551-3_20","DOI":"10.1007\/978-3-031-38551-3_20"},{"key":"16_CR27","doi-asserted-by":"publisher","unstructured":"Canetti, R., et al.: Practical UC security with a Global Random Oracle. In: CCS \u201914 (2014). https:\/\/doi.org\/10.1145\/2660267.2660374","DOI":"10.1145\/2660267.2660374"},{"key":"16_CR28","doi-asserted-by":"publisher","unstructured":"Connolly, D., et al.: The flexible round-optimized Schnorr Threshold (FROST) Protocol for Two-Round Schnorr signatures. RFC 9591. https:\/\/doi.org\/10.17487\/RFC9591, https:\/\/www.rfc-editor.org\/info\/rfc9591","DOI":"10.17487\/RFC9591"},{"key":"16_CR29","doi-asserted-by":"publisher","unstructured":"Chiesa, A., et al.: Succinct arguments in the quantum random oracle model. In: TCC 2019 (2019). https:\/\/doi.org\/10.1007\/978-3-030-36033-7_1","DOI":"10.1007\/978-3-030-36033-7_1"},{"key":"16_CR30","unstructured":"Chiesa, A., et al.: A Fiat\u2013Shamir transformation from duplex sponges. Cryptology ePrint Archive, Paper 2025\/536 (2025). https:\/\/eprint.iacr.org\/2025\/536"},{"key":"16_CR31","unstructured":"Chiesa, A., et al.: Building Cryptographic Proofs from Hash Functions (2024). https:\/\/snargsbook.org\/"},{"key":"16_CR32","doi-asserted-by":"publisher","unstructured":"Davidson, A., et al.: Oblivious Pseudorandom Functions (OPRFs) using prime- order groups. RFC 9497. https:\/\/doi.org\/10.17487\/RFC9497, https:\/\/www.rfceditor.org\/info\/rfc9497","DOI":"10.17487\/RFC9497"},{"key":"16_CR33","doi-asserted-by":"publisher","unstructured":"Don, J., et al.: Security of the Fiat-Shamir transformation in the quantum random- oracle model. In: CRYPTO \u201919. Springer (2019). https:\/\/doi.org\/10.1007\/978-3-030-26951-7_13","DOI":"10.1007\/978-3-030-26951-7_13"},{"key":"16_CR34","unstructured":"Dusk-network. safe: Sponge API for Field Elements. https:\/\/github.com\/dusk-network\/safe"},{"key":"16_CR35","unstructured":"Ethereum Foundation. zkEVM Formal Verification Project. https:\/\/verifiedzkevm.org\/"},{"key":"16_CR36","unstructured":"Fiat, A., et al.: How to prove yourself: practical solutions to identification and signature problems. In: CRYPTO \u201986 (1986)"},{"key":"16_CR37","unstructured":"Goldwasser, S., et al.: On the (In)security of the Fiat-Shamir Paradigm. In: FOCS \u201903 (2003)"},{"key":"16_CR38","unstructured":"Grassi, L., et al.: Poseidon: a new hash function for zero-knowledge proof systems. In: USENIX Security \u201921 (2021)"},{"key":"16_CR39","unstructured":"Hamburg, M.: The STROBE protocol framework. IACR Cryptol. ePrint Arch. (2017). http:\/\/eprint.iacr.org\/2017\/003"},{"key":"16_CR40","doi-asserted-by":"publisher","unstructured":"Hao, F.: Schnorr Non-interactive Zero-Knowledge Proof. RFC 8235. https:\/\/doi.org\/10.17487\/RFC8235. https:\/\/www.rfc-editor.org\/info\/rfc8235","DOI":"10.17487\/RFC8235"},{"key":"16_CR41","doi-asserted-by":"publisher","unstructured":"Holmgren, J., et al.: Cryptographic Hashing from Strong One-Way Functions (Or: One-Way Product Functions and Their Applications). In: FOCS \u201918 (2018). https:\/\/doi.org\/10.1109\/FOCS.2018.00085","DOI":"10.1109\/FOCS.2018.00085"},{"key":"16_CR42","doi-asserted-by":"publisher","unstructured":"Holmgren, J., et al.: Fiat\u2013Shamir via list-recoverable codes (or: parallel repetition of GMW is not zero-knowledge). In: STOC \u201921 (2021). https:\/\/doi.org\/10.1145\/3406325.3451116","DOI":"10.1145\/3406325.3451116"},{"key":"16_CR43","doi-asserted-by":"publisher","unstructured":"Jain, A., et al.: Non-interactive zero knowledge from sub-exponential DDH. In: EUROCRYPT \u201921 (2021). https:\/\/doi.org\/10.1007\/978-3-030-77870-5_1","DOI":"10.1007\/978-3-030-77870-5_1"},{"key":"16_CR44","doi-asserted-by":"publisher","unstructured":"Jawale, R., et al.: SNARGs for bounded depth computations and PPAD hardness from sub-exponential LWE. In: STOC \u201921 (2021). https:\/\/doi.org\/10.1145\/3406325.3451055","DOI":"10.1145\/3406325.3451055"},{"key":"16_CR45","doi-asserted-by":"publisher","unstructured":"Kalai, Y.T., et al.: SNARGs and PPAD hardness from the decisional diffie-hellman assumption. In: EUROCRYPT \u201923 (2023). https:\/\/doi.org\/10.1007\/978-3-031-30617-4_16","DOI":"10.1007\/978-3-031-30617-4_16"},{"key":"16_CR46","doi-asserted-by":"crossref","unstructured":"Khovratovich, D., et al.: Generic security of the SAFE API and its applications. In: ASIACRYPT (2023)","DOI":"10.1007\/978-981-99-8742-9_10"},{"key":"16_CR47","unstructured":"Kalai, Y.T., et al.: From obfuscation to the security of fiat-shamir for proofs. In: CRYPTO \u201917 (2017). ISBN: 978-3-319-63715-0"},{"key":"16_CR48","doi-asserted-by":"crossref","unstructured":"Khovratovich, D., et al.: How to prove false statements: practical attacks on Fiat- Shamir. Cryptology ePrint Archive, Paper 2025\/118 (2025). https:\/\/eprint.iacr.org\/2025\/118","DOI":"10.1007\/978-3-032-01887-8_1"},{"key":"16_CR49","unstructured":"Looker, T., et al.: The BBS Signature Scheme. Internet-Draft draft-irtf-cfrg-bbssignatures- 07. Work in Progress. Internet Engineering Task Force. https:\/\/datatracker.ietf.org\/doc\/draft-irtf-cfrg-bbs-signatures\/07\/"},{"key":"16_CR50","doi-asserted-by":"publisher","unstructured":"Liu, Q., et al.: Revisiting Post-quantum Fiat-Shamir. In: CRYPTO \u201919 (2019). https:\/\/doi.org\/10.1007\/978-3-030-26951-7_12","DOI":"10.1007\/978-3-030-26951-7_12"},{"key":"16_CR51","doi-asserted-by":"publisher","unstructured":"Mittelbach, A., et al.: The Theory of Hash Functions and Random Oracles - An Approach to Modern Cryptography. Inf. Secur. Cryptography (2021). ISBN: 978-3-030-63286-1. https:\/\/doi.org\/10.1007\/978-3-030-63287-8","DOI":"10.1007\/978-3-030-63287-8"},{"key":"16_CR52","doi-asserted-by":"publisher","unstructured":"Maurer, U.M., et al.: Indifferentiability, impossibility results on reductions, and applications to the random oracle methodology. In: TCC \u201904 (2004). https:\/\/doi.org\/10.1007\/978-3-540-24638-1_2","DOI":"10.1007\/978-3-540-24638-1_2"},{"key":"16_CR53","doi-asserted-by":"crossref","unstructured":"Pass, R.: On deniability in the common reference string and random oracle model. In: CRYPTO \u201903 (2003)","DOI":"10.1007\/978-3-540-45146-4_19"},{"key":"16_CR54","doi-asserted-by":"publisher","unstructured":"Peikert, C., et al.: Noninteractive zero knowledge for NP from (Plain) learning with errors. In: CRYPTO \u201919 (2019). https:\/\/doi.org\/10.1007\/978-3-030-26948-7_4","DOI":"10.1007\/978-3-030-26948-7_4"},{"key":"16_CR55","unstructured":"Setty, S.: Nova: high-speed recursive arguments from folding schemes. https:\/\/github.com\/microsoft\/Nova\/"},{"key":"16_CR56","unstructured":"SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions. National Institute of Standards and Technology, NIST FIPS PUB 202, U.S. Department of Commerce"},{"key":"16_CR57","unstructured":"Signal Foundation. libsignal\u2019s proof of knowledge stateful hash object. https:\/\/github.com\/signalapp\/libsignal\/tree\/main\/rust\/poksho\/"},{"key":"16_CR58","unstructured":"StarkWare. Cairo. https:\/\/github.com\/starkware-libs\/cairo-lang\/"},{"key":"16_CR59","unstructured":"de Valence, H.: Merlin: composable proof transcripts for public-coin arguments of knowledge. https:\/\/github.com\/dalek-cryptography\/merlin. Version 1.0"},{"key":"16_CR60","doi-asserted-by":"publisher","unstructured":"Wee, H.: Zero knowledge in the random oracle model, revisited. In: Proceedings of the 15th International Conference on the Theory and Application of Cryptology and Information Security. ASIACRYPT \u201909, pp. 417\u2013 434. Springer, Berlin, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-10366-7_25","DOI":"10.1007\/978-3-642-10366-7_25"},{"key":"16_CR61","unstructured":"Wright, O.: Decree Fiat Shamir Library. https:\/\/github.com\/trailofbits\/decree. 0.1.0"},{"key":"16_CR62","doi-asserted-by":"publisher","unstructured":"Yamakawa, T., et al.: Classical vs Quantum Random Oracles. In: EUROCRYPT\u201921 (2021). https:\/\/doi.org\/10.1007\/978-3-030-77886-6_20","DOI":"10.1007\/978-3-030-77886-6_20"}],"container-title":["Lecture Notes in Computer Science","Theory of Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-12287-2_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T16:18:12Z","timestamp":1764605892000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-12287-2_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,2]]},"ISBN":["9783032122865","9783032122872"],"references-count":62,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-12287-2_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,2]]},"assertion":[{"value":"2 December 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"TCC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Theory of Cryptography Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Aarhus","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Denmark","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 December 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"5 December 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"tcc2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/tcc.iacr.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}