{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T14:10:23Z","timestamp":1778249423449,"version":"3.51.4"},"publisher-location":"Cham","reference-count":56,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032253354","type":"print"},{"value":"9783032253361","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-25336-1_13","type":"book-chapter","created":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T13:14:29Z","timestamp":1778246069000},"page":"359-388","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Critical Rounds in\u00a0Multi-round Proofs: Proof of\u00a0Partial Knowledge and\u00a0Trapdoor Commitments"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-1614-0587","authenticated-orcid":false,"given":"Masayuki","family":"Abe","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4864-1125","authenticated-orcid":false,"given":"David","family":"Balb\u00e1s","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7049-733X","authenticated-orcid":false,"given":"Dung","family":"Bui","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-8656-035X","authenticated-orcid":false,"given":"Miyako","family":"Ohkubo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-9115-0117","authenticated-orcid":false,"given":"Zehua","family":"Shang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8556-3053","authenticated-orcid":false,"given":"Akira","family":"Takahashi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2736-2963","authenticated-orcid":false,"given":"Mehdi","family":"Tibouchi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,9]]},"reference":[{"key":"13_CR1","doi-asserted-by":"publisher","unstructured":"Aardal, M.A., Aranha, D.F., Boudgoust, K., Kolby, S., Takahashi, A.: Aggregating falcon signatures with LaBRADOR. In: CRYPTO\u00a02024, Part\u00a0I, pp. 71\u2013106. LNCS (2024). https:\/\/doi.org\/10.1007\/978-3-031-68376-3_3","DOI":"10.1007\/978-3-031-68376-3_3"},{"key":"13_CR2","doi-asserted-by":"publisher","unstructured":"Abe, M., Ambrona, M., Bogdanov, A., Ohkubo, M., Rosen, A.: Non-interactive composition of sigma-protocols via share-then-hash. In: Moriai, S., Wang, H. (eds.) ASIACRYPT\u00a02020, Part\u00a0III. LNCS, vol. 12493, pp. 749\u2013773 (2020). https:\/\/doi.org\/10.1007\/978-3-030-64840-4_25","DOI":"10.1007\/978-3-030-64840-4_25"},{"key":"13_CR3","doi-asserted-by":"publisher","unstructured":"Abe, M., Ambrona, M., Bogdanov, A., Ohkubo, M., Rosen, A.: Acyclicity programming for sigma-protocols. In: Nissim, K., Waters, B. (eds.) TCC\u00a02021, Part\u00a0I. LNCS, vol. 13042, pp. 435\u2013465 (2021). https:\/\/doi.org\/10.1007\/978-3-030-90459-3_15","DOI":"10.1007\/978-3-030-90459-3_15"},{"key":"13_CR4","unstructured":"Abe, M., et al.: Critical rounds in multi-round proofs: proof of partial knowledge and trapdoor commitments. Cryptology ePrint Archive, Paper 2024\/1766 (2024). https:\/\/eprint.iacr.org\/2024\/1766"},{"key":"13_CR5","doi-asserted-by":"crossref","unstructured":"Abe, M., et al.: CDS composition of multi-round protocols. In: Advances in Cryptology - CRYPTO 2024 - 44th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 18-22, 2024, Proceedings, Part IX. Lecture Notes in Computer Science, vol. 14928, pp. 391\u2013423. Springer (2024)","DOI":"10.1007\/978-3-031-68400-5_12"},{"key":"13_CR6","doi-asserted-by":"publisher","unstructured":"Attema, T., Cramer, R.: Compressed $$\\Sigma $$-protocol theory and practical application to plug & play secure algorithmics. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO\u00a02020, Part\u00a0III. LNCS, vol. 12172, pp. 513\u2013543 (2020). https:\/\/doi.org\/10.1007\/978-3-030-56877-1_18","DOI":"10.1007\/978-3-030-56877-1_18"},{"key":"13_CR7","doi-asserted-by":"publisher","unstructured":"Attema, T., Cramer, R., Fehr, S.: Compressing proofs of k-out-of-n partial knowledge. In: Malkin, T., Peikert, C. (eds.) CRYPTO\u00a02021, Part\u00a0IV. LNCS, vol. 12828, pp. 65\u201391. Virtual Event (2021). https:\/\/doi.org\/10.1007\/978-3-030-84259-8_3","DOI":"10.1007\/978-3-030-84259-8_3"},{"key":"13_CR8","doi-asserted-by":"publisher","unstructured":"Attema, T., Cramer, R., Kohl, L.: A compressed $$\\Sigma $$-protocol theory for lattices. In: Malkin, T., Peikert, C. (eds.) CRYPTO\u00a02021, Part\u00a0II. LNCS, vol. 12826, pp. 549\u2013579. Virtual Event (2021). https:\/\/doi.org\/10.1007\/978-3-030-84245-1_19","DOI":"10.1007\/978-3-030-84245-1_19"},{"key":"13_CR9","doi-asserted-by":"publisher","unstructured":"Attema, T., Fehr, S.: Parallel repetition of ($$k_1, \\dots , k_{\\mu }$$)-special-sound multi-round interactive proofs. In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO\u00a02022, Part\u00a0I. LNCS, vol. 13507, pp. 415\u2013443 (2022). https:\/\/doi.org\/10.1007\/978-3-031-15802-5_15","DOI":"10.1007\/978-3-031-15802-5_15"},{"key":"13_CR10","doi-asserted-by":"publisher","unstructured":"Attema, T., Fehr, S., Kloo\u00df, M.: Fiat-Shamir transformation of multi-round interactive proofs (extended version). J. Cryptol. 36(4), 36 (2023). https:\/\/doi.org\/10.1007\/s00145-023-09478-y","DOI":"10.1007\/s00145-023-09478-y"},{"key":"13_CR11","doi-asserted-by":"publisher","unstructured":"Attema, T., Fehr, S., Resch, N.: Generalized special-sound interactive proofs and their knowledge soundness. In: TCC\u00a02023, Part\u00a0III, pp. 424\u2013454. LNCS (2023). https:\/\/doi.org\/10.1007\/978-3-031-48621-0_15","DOI":"10.1007\/978-3-031-48621-0_15"},{"key":"13_CR12","unstructured":"Attema, T., Kloo\u00df, M., Lai, R.W.F., Yatsyna, P.: Adaptive special soundness: improved knowledge extraction by adaptive useful challenge sampling. Cryptology ePrint Archive, Paper 2024\/2038 (2024). https:\/\/eprint.iacr.org\/2024\/2038"},{"key":"13_CR13","doi-asserted-by":"publisher","unstructured":"Avitabile, G., Botta, V., Friolo, D., Venturi, D., Visconti, I.: Compact proofs of partial knowledge for overlapping CNF formulae. J. Cryptol. 38(1), 7 (2025). https:\/\/doi.org\/10.1007\/s00145-024-09532-3","DOI":"10.1007\/s00145-024-09532-3"},{"key":"13_CR14","doi-asserted-by":"publisher","unstructured":"Avitabile, G., Botta, V., Friolo, D., Visconti, I.: Efficient proofs of knowledge for threshold relations. In: Atluri, V., Di Pietro, R., Jensen, C.D., Meng, W. (eds.) ESORICS\u00a02022, Part\u00a0III. LNCS, vol. 13556, pp. 42\u201362 (2022). https:\/\/doi.org\/10.1007\/978-3-031-17143-7_3","DOI":"10.1007\/978-3-031-17143-7_3"},{"key":"13_CR15","doi-asserted-by":"publisher","unstructured":"Baum, C., Nof, A.: Concretely-efficient zero-knowledge arguments for arithmetic circuits and their application to lattice-based cryptography. In: Kiayias, A., Kohlweiss, M., Wallden, P., Zikas, V. (eds.) PKC\u00a02020, Part\u00a0I. LNCS, vol. 12110, pp. 495\u2013526 (2020). https:\/\/doi.org\/10.1007\/978-3-030-45374-9_17","DOI":"10.1007\/978-3-030-45374-9_17"},{"key":"13_CR16","doi-asserted-by":"publisher","unstructured":"Ben-Sasson, E., Chiesa, A., Spooner, N.: Interactive oracle proofs. In: Hirt, M., Smith, A.D. (eds.) TCC\u00a02016-B, Part\u00a0II. LNCS, vol.\u00a09986, pp. 31\u201360 (2016). https:\/\/doi.org\/10.1007\/978-3-662-53644-5_2","DOI":"10.1007\/978-3-662-53644-5_2"},{"key":"13_CR17","doi-asserted-by":"publisher","unstructured":"Block, A.R., Garreta, A., Tiwari, P.R., Zajac, M.: On soundness notions for interactive oracle proofs. J. Cryptol. 38(1), 4 (2025). https:\/\/doi.org\/10.1007\/s00145-024-09520-7","DOI":"10.1007\/s00145-024-09520-7"},{"key":"13_CR18","unstructured":"Blum, M.: How to prove a theorem so no one else can claim it. In: The International Congress of Mathematicians (ICM), 1986 (1986)"},{"key":"13_CR19","doi-asserted-by":"publisher","unstructured":"Bootle, J., Cerulli, A., Chaidos, P., Groth, J., Petit, C.: Efficient zero-knowledge arguments for arithmetic circuits in the discrete log setting. In: Fischlin, M., Coron, J.S. (eds.) EUROCRYPT\u00a02016, Part\u00a0II. LNCS, vol.\u00a09666, pp. 327\u2013357 (2016). https:\/\/doi.org\/10.1007\/978-3-662-49896-5_12","DOI":"10.1007\/978-3-662-49896-5_12"},{"key":"13_CR20","doi-asserted-by":"publisher","unstructured":"Botta, V., Ciampi, M., Orsini, E., Siniscalchi, L., Visconti, I.: Black-box (and fast) non-malleable zero knowledge, pp. 458\u2013490. LNCS (2024). https:\/\/doi.org\/10.1007\/978-3-031-68400-5_14","DOI":"10.1007\/978-3-031-68400-5_14"},{"key":"13_CR21","doi-asserted-by":"publisher","unstructured":"B\u00fcnz, B., et al.: Bulletproofs: Short proofs for confidential transactions and more. In: 2018 IEEE Symposium on Security and Privacy, pp. 315\u2013334. IEEE Computer Society Press (2018). https:\/\/doi.org\/10.1109\/SP.2018.00020","DOI":"10.1109\/SP.2018.00020"},{"key":"13_CR22","doi-asserted-by":"publisher","unstructured":"B\u00fcnz, B., Fisch, B.: Multilinear schwartz-zippel mod N and lattice-based succinct arguments. In: TCC\u00a02023, Part\u00a0III, pp. 394\u2013423. LNCS (2023). https:\/\/doi.org\/10.1007\/978-3-031-48621-0_14","DOI":"10.1007\/978-3-031-48621-0_14"},{"key":"13_CR23","doi-asserted-by":"publisher","unstructured":"B\u00fcnz, B., Fisch, B., Szepieniec, A.: Transparent SNARKs from DARK compilers. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT\u00a02020, Part\u00a0I. LNCS, vol. 12105, pp. 677\u2013706 (2020). https:\/\/doi.org\/10.1007\/978-3-030-45721-1_24","DOI":"10.1007\/978-3-030-45721-1_24"},{"key":"13_CR24","doi-asserted-by":"publisher","unstructured":"Catalano, D., Visconti, I.: Hybrid trapdoor commitments and their applications. In: Caires, L., Italiano, G.F., Monteiro, L., Palamidessi, C., Yung, M. (eds.) ICALP 2005. LNCS, vol.\u00a03580, pp. 298\u2013310. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11523468_25","DOI":"10.1007\/11523468_25"},{"key":"13_CR25","doi-asserted-by":"publisher","unstructured":"Chiesa, A., et al.: Marlin: Preprocessing zkSNARKs with universal and updatable SRS. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT\u00a02020, Part\u00a0I. LNCS, vol. 12105, pp. 738\u2013768 (2020). https:\/\/doi.org\/10.1007\/978-3-030-45721-1_26","DOI":"10.1007\/978-3-030-45721-1_26"},{"key":"13_CR26","doi-asserted-by":"publisher","unstructured":"Ciampi, M., Persiano, G., Scafuro, A., Siniscalchi, L., Visconti, I.: Improved OR-composition of sigma-protocols. In: Kushilevitz, E., Malkin, T. (eds.) TCC\u00a02016-A, Part\u00a0II. LNCS, vol.\u00a09563, pp. 112\u2013141 (2016). https:\/\/doi.org\/10.1007\/978-3-662-49099-0_5","DOI":"10.1007\/978-3-662-49099-0_5"},{"key":"13_CR27","doi-asserted-by":"publisher","unstructured":"Ciampi, M., Persiano, G., Scafuro, A., Siniscalchi, L., Visconti, I.: Online\/offline OR composition of sigma protocols. In: Fischlin, M., Coron, J.S. (eds.) EUROCRYPT\u00a02016, Part\u00a0II. LNCS, vol.\u00a09666, pp. 63\u201392 (2016). https:\/\/doi.org\/10.1007\/978-3-662-49896-5_3","DOI":"10.1007\/978-3-662-49896-5_3"},{"key":"13_CR28","unstructured":"Cramer, R.: Modular Design of Secure yet Practical Cryptographic Protocols. Ph.D. thesis, University of Amsterdam (1996)"},{"key":"13_CR29","doi-asserted-by":"publisher","unstructured":"Cramer, R., Damg\u00e5rd, I., MacKenzie, P.D.: Efficient zero-knowledge proofs of knowledge without intractability assumptions. In: Imai, H., Zheng, Y. (eds.) PKC\u00a02000. LNCS, vol.\u00a01751, pp. 354\u2013372 (2000). https:\/\/doi.org\/10.1007\/978-3-540-46588-1_24","DOI":"10.1007\/978-3-540-46588-1_24"},{"key":"13_CR30","doi-asserted-by":"publisher","unstructured":"Cramer, R., Damg\u00e5rd, I., Schoenmakers, B.: Proofs of partial knowledge and simplified design of witness hiding protocols. In: Desmedt, Y. (ed.) CRYPTO\u201994. LNCS, vol.\u00a0839, pp. 174\u2013187 (1994). https:\/\/doi.org\/10.1007\/3-540-48658-5_19","DOI":"10.1007\/3-540-48658-5_19"},{"key":"13_CR31","doi-asserted-by":"publisher","unstructured":"Damg\u00e5rd, I.: On the existence of bit commitment schemes and zero-knowledge proofs. In: Brassard, G. (ed.) CRYPTO\u201989. LNCS, vol.\u00a0435, pp. 17\u201327 (1990). https:\/\/doi.org\/10.1007\/0-387-34805-0_3","DOI":"10.1007\/0-387-34805-0_3"},{"key":"13_CR32","doi-asserted-by":"publisher","unstructured":"Damg\u00e5rd, I.: Efficient concurrent zero-knowledge in the auxiliary string model. In: Preneel, B. (ed.) EUROCRYPT\u00a02000. LNCS, vol.\u00a01807, pp. 418\u2013430 (2000). https:\/\/doi.org\/10.1007\/3-540-45539-6_30","DOI":"10.1007\/3-540-45539-6_30"},{"key":"13_CR33","doi-asserted-by":"publisher","unstructured":"Dao, Q., Grubbs, P.: Spartan and bulletproofs are simulation-extractable (for free!). In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0II. LNCS, vol. 14005, pp. 531\u2013562 (2023). https:\/\/doi.org\/10.1007\/978-3-031-30617-4_18","DOI":"10.1007\/978-3-031-30617-4_18"},{"key":"13_CR34","doi-asserted-by":"publisher","unstructured":"Don, J., Fehr, S., Majenz, C., Schaffner, C.: Online-extractability in the quantum random-oracle model. In: Dunkelman, O., Dziembowski, S. (eds.) EUROCRYPT\u00a02022, Part\u00a0III. LNCS, vol. 13277, pp. 677\u2013706 (2022). https:\/\/doi.org\/10.1007\/978-3-031-07082-2_24","DOI":"10.1007\/978-3-031-07082-2_24"},{"key":"13_CR35","doi-asserted-by":"publisher","unstructured":"Feneuil, T., Joux, A., Rivain, M.: Syndrome decoding in the head: shorter signatures from zero-knowledge proofs. In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO\u00a02022, Part\u00a0II. LNCS, vol. 13508, pp. 541\u2013572 (2022). https:\/\/doi.org\/10.1007\/978-3-031-15979-4_19","DOI":"10.1007\/978-3-031-15979-4_19"},{"key":"13_CR36","doi-asserted-by":"publisher","unstructured":"Fiat, A., Shamir, A.: How to prove yourself: practical solutions to identification and signature problems. In: Odlyzko, A.M. (ed.) CRYPTO\u201986. LNCS, vol.\u00a0263, pp. 186\u2013194 (1987). https:\/\/doi.org\/10.1007\/3-540-47721-7_12","DOI":"10.1007\/3-540-47721-7_12"},{"key":"13_CR37","unstructured":"Fischlin, M.: Trapdoor commitment schemes and their applications (2001)"},{"key":"13_CR38","doi-asserted-by":"publisher","unstructured":"Fouque, P.A., Georgescu, A., Qian, C., Roux-Langlois, A., Wen, W.: A generic transform from multi-round interactive proof to NIZK. In: Boldyreva, A., Kolesnikov, V. (eds.) PKC\u00a02023, Part\u00a0II. LNCS, vol. 13941, pp. 461\u2013481 (2023). https:\/\/doi.org\/10.1007\/978-3-031-31371-4_16","DOI":"10.1007\/978-3-031-31371-4_16"},{"key":"13_CR39","unstructured":"Gabizon, A., Williamson, Z.J., Ciobotaru, O.: PLONK: Permutations over Lagrange-bases for oecumenical noninteractive arguments of knowledge. Cryptology ePrint Archive, Report 2019\/953 (2019). https:\/\/eprint.iacr.org\/2019\/953"},{"key":"13_CR40","doi-asserted-by":"publisher","unstructured":"Ganesh, C., Khoshakhlagh, H., Kohlweiss, M., Nitulescu, A., Zajac, M.: What makes Fiat-Shamir zkSNARKs (updatable SRS) simulation extractable? pp. 735\u2013760. LNCS (2022). https:\/\/doi.org\/10.1007\/978-3-031-14791-3_32","DOI":"10.1007\/978-3-031-14791-3_32"},{"key":"13_CR41","doi-asserted-by":"publisher","unstructured":"Ganesh, C., Orlandi, C., Pancholi, M., Takahashi, A., Tschudi, D.: Fiat-Shamir bulletproofs are non-malleable (in the random oracle model). J. Cryptol. 38(1), 11 (2025). https:\/\/doi.org\/10.1007\/S00145-024-09525-2","DOI":"10.1007\/S00145-024-09525-2"},{"key":"13_CR42","doi-asserted-by":"publisher","unstructured":"Goel, A., Green, M., Hall-Andersen, M., Kaptchuk, G.: Stacking sigmas: a framework to compose $$\\Sigma $$-protocols for disjunctions. In: Dunkelman, O., Dziembowski, S. (eds.) EUROCRYPT\u00a02022, Part\u00a0II. LNCS, vol. 13276, pp. 458\u2013487 (2022). https:\/\/doi.org\/10.1007\/978-3-031-07085-3_16","DOI":"10.1007\/978-3-031-07085-3_16"},{"key":"13_CR43","doi-asserted-by":"publisher","unstructured":"Goel, A., Hall-Andersen, M., Kaptchuk, G., Spooner, N.: Speed-stacking: fast sublinear zero-knowledge proofs for disjunctions. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0II. LNCS, vol. 14005, pp. 347\u2013378 (2023). https:\/\/doi.org\/10.1007\/978-3-031-30617-4_12","DOI":"10.1007\/978-3-031-30617-4_12"},{"issue":"3","key":"13_CR44","doi-asserted-by":"publisher","first-page":"691","DOI":"10.1145\/116825.116852","volume":"38","author":"O Goldreich","year":"1991","unstructured":"Goldreich, O., Micali, S., Wigderson, A.: Proofs that yield nothing but their validity for all languages in NP have zero-knowledge proof systems. J. ACM 38(3), 691\u2013729 (1991)","journal-title":"J. ACM"},{"key":"13_CR45","doi-asserted-by":"publisher","unstructured":"Haque, A., Scafuro, A.: Threshold ring signatures: new definitions and post-quantum security. In: Kiayias, A., Kohlweiss, M., Wallden, P., Zikas, V. (eds.) PKC\u00a02020, Part\u00a0II. LNCS, vol. 12111, pp. 423\u2013452 (2020). https:\/\/doi.org\/10.1007\/978-3-030-45388-6_15","DOI":"10.1007\/978-3-030-45388-6_15"},{"key":"13_CR46","doi-asserted-by":"publisher","unstructured":"Hazay, C., Venkitasubramaniam, M.: On the power of secure two-party computation. J. Cryptol. 33(1), 271\u2013318 (2020). https:\/\/doi.org\/10.1007\/s00145-019-09314-2","DOI":"10.1007\/s00145-019-09314-2"},{"key":"13_CR47","doi-asserted-by":"publisher","unstructured":"Jakobsson, M., Sako, K., Impagliazzo, R.: Designated verifier proofs and their applications. In: Maurer, U.M. (ed.) EUROCRYPT\u201996. LNCS, vol.\u00a01070, pp. 143\u2013154 (1996). https:\/\/doi.org\/10.1007\/3-540-68339-9_13","DOI":"10.1007\/3-540-68339-9_13"},{"key":"13_CR48","unstructured":"Kales, D., Zaverucha, G.: Efficient lifting for shorter zero-knowledge proofs and post-quantum signatures. Cryptology ePrint Archive, Report 2022\/588 (2022). https:\/\/eprint.iacr.org\/2022\/588"},{"key":"13_CR49","doi-asserted-by":"publisher","unstructured":"Kate, A., Zaverucha, G.M., Goldberg, I.: Constant-size commitments to polynomials and their applications. In: Abe, M. (ed.) ASIACRYPT\u00a02010. LNCS, vol.\u00a06477, pp. 177\u2013194 (2010). https:\/\/doi.org\/10.1007\/978-3-642-17373-8_11","DOI":"10.1007\/978-3-642-17373-8_11"},{"key":"13_CR50","doi-asserted-by":"publisher","unstructured":"Katz, J., Kolesnikov, V., Wang, X.: Improved non-interactive zero knowledge with applications to post-quantum signatures. In: Lie, D., Mannan, M., Backes, M., Wang, X. (eds.) ACM CCS 2018, pp. 525\u2013537. ACM Press (2018). https:\/\/doi.org\/10.1145\/3243734.3243805","DOI":"10.1145\/3243734.3243805"},{"key":"13_CR51","doi-asserted-by":"publisher","unstructured":"Kim, A., Liang, X., Pandey, O.: A new approach to efficient non-malleable zero-knowledge. In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO\u00a02022, Part\u00a0IV. LNCS, vol. 13510, pp. 389\u2013418 (2022). https:\/\/doi.org\/10.1007\/978-3-031-15985-5_14","DOI":"10.1007\/978-3-031-15985-5_14"},{"key":"13_CR52","doi-asserted-by":"publisher","unstructured":"Lipmaa, H.: Plonk is simulation extractable in ROM under falsifiable assumptions. In: Applebaum, B., Lin, H.R. (eds.) Theory of Cryptography - 23rd International Conference, TCC 2025, Aarhus, Denmark, December 1\u20135, 2025, Proceedings, Part IV. Lecture Notes in Computer Science, vol. 16271, pp. 3\u201336. Springer (2025). https:\/\/doi.org\/10.1007\/978-3-032-12290-2_1","DOI":"10.1007\/978-3-032-12290-2_1"},{"key":"13_CR53","doi-asserted-by":"publisher","unstructured":"Lipmaa, H., Parisella, R., Siim, J.: On knowledge-soundness of plonk in ROM from falsifiable assumptions. In: Kalai, Y.T., Kamara, S.F. (eds.) Advances in Cryptology - CRYPTO 2025 - 45th Annual International Cryptology Conference, Santa Barbara, CA, USA, 17\u201321 August 2025, Proceedings, Part VII. Lecture Notes in Computer Science, vol. 16006, pp. 362\u2013395. Springer (2025). https:\/\/doi.org\/10.1007\/978-3-032-01907-3_12","DOI":"10.1007\/978-3-032-01907-3_12"},{"key":"13_CR54","doi-asserted-by":"publisher","unstructured":"Reingold, O., Rothblum, G.N., Rothblum, R.D.: Constant-round interactive proofs for delegating computation. In: Wichs, D., Mansour, Y. (eds.) 48th ACM STOC, pp. 49\u201362. ACM Press (2016). https:\/\/doi.org\/10.1145\/2897518.2897652","DOI":"10.1145\/2897518.2897652"},{"key":"13_CR55","doi-asserted-by":"publisher","unstructured":"Setty, S.: Spartan: efficient and general-purpose zkSNARKs without trusted setup. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO\u00a02020, Part\u00a0III. LNCS, vol. 12172, pp. 704\u2013737 (2020). https:\/\/doi.org\/10.1007\/978-3-030-56877-1_25","DOI":"10.1007\/978-3-030-56877-1_25"},{"key":"13_CR56","doi-asserted-by":"publisher","unstructured":"Zeng, G., Lai, J., Huang, Z., Wang, Y., Zheng, Z.: DAG-$$\\Sigma $$: A DAG-based sigma protocol for relations in CNF. In: Agrawal, S., Lin, D. (eds.) ASIACRYPT\u00a02022, Part\u00a0II. LNCS, vol. 13792, pp. 340\u2013370 (2022). https:\/\/doi.org\/10.1007\/978-3-031-22966-4_12","DOI":"10.1007\/978-3-031-22966-4_12"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2026"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-25336-1_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T13:14:35Z","timestamp":1778246075000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-25336-1_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032253354","9783032253361"],"references-count":56,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-25336-1_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"9 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Rome","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 May 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 May 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"45","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2026\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}