{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T14:10:03Z","timestamp":1778249403952,"version":"3.51.4"},"publisher-location":"Cham","reference-count":32,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032253354","type":"print"},{"value":"9783032253361","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-25336-1_9","type":"book-chapter","created":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T13:12:55Z","timestamp":1778245975000},"page":"239-267","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Special Soundness and\u00a0Binding Properties: A Framework for\u00a0Tightly Secure zk-SNARKs"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-0728-0603","authenticated-orcid":false,"given":"Erki","family":"K\u00fclaots","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8393-6821","authenticated-orcid":false,"given":"Helger","family":"Lipmaa","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-2241-801X","authenticated-orcid":false,"given":"Roberto","family":"Parisella","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5824-7215","authenticated-orcid":false,"given":"Janno","family":"Siim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,9]]},"reference":[{"key":"9_CR1","doi-asserted-by":"publisher","unstructured":"Abraham, I., Jovanovic, P., Maller, M., Meiklejohn, S., Stern, G.: Bingo: adaptivity and asynchrony in verifiable secret sharing and distributed key generation. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO\u00a02023, Part\u00a0I. LNCS, vol. 14081, pp. 39\u201370. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38557-5_2","DOI":"10.1007\/978-3-031-38557-5_2"},{"key":"9_CR2","doi-asserted-by":"crossref","unstructured":"Alhaddad, N., Varia, M., Yang, Z.: Haven++: batched and packed dual-threshold asynchronous complete secret sharing with applications. IACR Commun. Cryptol. 1(4) (2024)","DOI":"10.62056\/a0qj5w7sf"},{"key":"9_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"479","DOI":"10.1007\/978-3-662-64331-0_25","volume-title":"Financial Cryptography and Data Security","author":"N AlHaddad","year":"2021","unstructured":"AlHaddad, N., Varia, M., Zhang, H.: High-threshold AVSS with optimal communication complexity. In: Borisov, N., Diaz, C. (eds.) FC 2021. LNCS, vol. 12675, pp. 479\u2013498. Springer, Heidelberg (2021). https:\/\/doi.org\/10.1007\/978-3-662-64331-0_25"},{"key":"9_CR4","doi-asserted-by":"publisher","unstructured":"Attema, T., Fehr, S., Kloo\u00df, M.: Fiat-Shamir transformation of multi-round interactive proofs. In: Kiltz, E., Vaikuntanathan, V. (eds.) TCC\u00a02022, Part\u00a0I. LNCS, vol. 13747, pp. 113\u2013142. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-22318-1_5","DOI":"10.1007\/978-3-031-22318-1_5"},{"key":"9_CR5","doi-asserted-by":"publisher","unstructured":"Ben-Sasson, E., Bentov, I., Horesh, Y., Riabzev, M.: Fast reed-solomon interactive oracle proofs of proximity. In: Chatzigiannakis, I., Kaklamanis, C., Marx, D., Sannella, D. (eds.) ICALP 2018. LIPIcs, vol.\u00a0107, pp. 14:1\u201314:17. Schloss Dagstuhl (2018). https:\/\/doi.org\/10.4230\/LIPIcs.ICALP.2018.14","DOI":"10.4230\/LIPIcs.ICALP.2018.14"},{"issue":"2","key":"9_CR6","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1007\/s00145-007-9005-7","volume":"21","author":"D Boneh","year":"2008","unstructured":"Boneh, D., Boyen, X.: Short signatures without random oracles and the SDH assumption in bilinear groups. J. Cryptol. 21(2), 149\u2013177 (2008). https:\/\/doi.org\/10.1007\/s00145-007-9005-7","journal-title":"J. Cryptol."},{"key":"9_CR7","doi-asserted-by":"publisher","unstructured":"B\u00fcnz, B., Bootle, J., Boneh, D., Poelstra, A., Wuille, P., Maxwell, G.: Bulletproofs: short proofs for confidential transactions and more. In: 2018 IEEE Symposium on Security and Privacy, pp. 315\u2013334. IEEE Computer Society Press (2018). https:\/\/doi.org\/10.1109\/SP.2018.00020","DOI":"10.1109\/SP.2018.00020"},{"key":"9_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"677","DOI":"10.1007\/978-3-030-45721-1_24","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"B B\u00fcnz","year":"2020","unstructured":"B\u00fcnz, B., Fisch, B., Szepieniec, A.: Transparent SNARKs from DARK compilers. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020. LNCS, vol. 12105, pp. 677\u2013706. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45721-1_24"},{"key":"9_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/978-3-030-92078-4_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"B B\u00fcnz","year":"2021","unstructured":"B\u00fcnz, B., Maller, M., Mishra, P., Tyagi, N., Vesely, P.: Proofs for\u00a0inner pairing products and\u00a0applications. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021. LNCS, vol. 13092, pp. 65\u201397. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92078-4_3"},{"key":"9_CR10","doi-asserted-by":"publisher","unstructured":"Chairattana-Apirom, R., D\u00f6ttling, N., Lysyanskaya, A., Tessaro, S.: Everlasting Anonymous Rate-Limited Tokens (2025). https:\/\/doi.org\/10.1007\/978-981-95-5119-4_14","DOI":"10.1007\/978-981-95-5119-4_14"},{"key":"9_CR11","unstructured":"Chiesa, A., Guan, Z., Knabenhans, C., Yu, Z.: On the Fiat-Shamir Security of Succinct Arguments from Functional Commitments (2025). https:\/\/eprint.iacr.org\/2025\/902. Accessed 27 Oct 2025"},{"key":"9_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"738","DOI":"10.1007\/978-3-030-45721-1_26","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"A Chiesa","year":"2020","unstructured":"Chiesa, A., Hu, Y., Maller, M., Mishra, P., Vesely, N., Ward, N.: Marlin: preprocessing zkSNARKs with universal and updatable SRS. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020. LNCS, vol. 12105, pp. 738\u2013768. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45721-1_26"},{"key":"9_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"174","DOI":"10.1007\/3-540-48658-5_19","volume-title":"Advances in Cryptology \u2014 CRYPTO \u201994","author":"R Cramer","year":"1994","unstructured":"Cramer, R., Damg\u00e5rd, I., Schoenmakers, B.: Proofs of partial knowledge and simplified design of witness hiding protocols. In: Desmedt, Y.G. (ed.) CRYPTO 1994. LNCS, vol. 839, pp. 174\u2013187. Springer, Heidelberg (1994). https:\/\/doi.org\/10.1007\/3-540-48658-5_19"},{"key":"9_CR14","unstructured":"Eagen, L., Gabizon, A.: MERCURY: a multilinear polynomial commitment scheme with constant proof size and no prover FFTs. Cryptology ePrint Archive, Report 2025\/385 (2025). https:\/\/eprint.iacr.org\/2025\/385"},{"key":"9_CR15","doi-asserted-by":"publisher","unstructured":"Faonio, A., Fiore, D., Russo, L.: Real-world universal zkSNARKs are non-malleable. In: Luo, B., Liao, X., Xu, J., Kirda, E., Lie, D. (eds.) ACM CCS 2024, pp. 3138\u20133151. ACM Press (2024). https:\/\/doi.org\/10.1145\/3658644.3690351","DOI":"10.1145\/3658644.3690351"},{"key":"9_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1007\/3-540-47721-7_12","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 86","author":"A Fiat","year":"1987","unstructured":"Fiat, A., Shamir, A.: How to prove yourself: practical solutions to identification and signature problems. In: Odlyzko, A.M. (ed.) CRYPTO 1986. LNCS, vol. 263, pp. 186\u2013194. Springer, Heidelberg (1987). https:\/\/doi.org\/10.1007\/3-540-47721-7_12"},{"key":"9_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-319-96881-0_2","volume-title":"Advances in Cryptology \u2013 CRYPTO 2018","author":"G Fuchsbauer","year":"2018","unstructured":"Fuchsbauer, G., Kiltz, E., Loss, J.: The algebraic group model and its applications. In: Shacham, H., Boldyreva, A. (eds.) CRYPTO 2018. LNCS, vol. 10992, pp. 33\u201362. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-96881-0_2"},{"key":"9_CR18","unstructured":"Gabizon, A., Williamson, Z.J., Ciobotaru, O.: PLONK: Permutations over Lagrange-bases for oecumenical noninteractive arguments of knowledge. Cryptology ePrint Archive, Report 2019\/953 (2019). https:\/\/eprint.iacr.org\/2019\/953"},{"key":"9_CR19","doi-asserted-by":"publisher","unstructured":"Ganesh, C., Khoshakhlagh, H., Parisella, R.: NIWI and new notions of extraction for algebraic languages. In: Galdi, C., Jarecki, S. (eds.) SCN 22. LNCS, vol. 13409, pp. 687\u2013710. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-14791-3_30","DOI":"10.1007\/978-3-031-14791-3_30"},{"key":"9_CR20","doi-asserted-by":"crossref","unstructured":"Ganesh, C., Patranabis, S., Singh, N.: Samaritan: linear-time prover SNARK from new multilinear polynomial commitments. Cryptology ePrint Archive, Report 2025\/419 (2025). https:\/\/eprint.iacr.org\/2025\/419","DOI":"10.1007\/978-981-95-5116-3_15"},{"key":"9_CR21","unstructured":"Hall-Andersen, M., Simkin, M., Wagner, B.: Foundations of data availability sampling. Cryptology ePrint Archive, Report 2023\/1079 (2023). https:\/\/eprint.iacr.org\/2023\/1079"},{"key":"9_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1007\/978-3-642-17373-8_11","volume-title":"Advances in Cryptology - ASIACRYPT 2010","author":"A Kate","year":"2010","unstructured":"Kate, A., Zaverucha, G.M., Goldberg, I.: Constant-size commitments to polynomials and their applications. In: Abe, M. (ed.) ASIACRYPT 2010. LNCS, vol. 6477, pp. 177\u2013194. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-17373-8_11"},{"key":"9_CR23","unstructured":"K\u00fclaots, E., Lipmaa, H., Parisella, R., Siim, J.: Special soundness and binding properties: a framework for tightly secure zk-SNARKs. Cryptology ePrint Archive, Paper 2026\/326 (2026). https:\/\/eprint.iacr.org\/2026\/326"},{"key":"9_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"530","DOI":"10.1007\/978-3-030-26948-7_19","volume-title":"Advances in Cryptology \u2013 CRYPTO 2019","author":"RWF Lai","year":"2019","unstructured":"Lai, R.W.F., Malavolta, G.: Subvector commitments with application to succinct arguments. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019. LNCS, vol. 11692, pp. 530\u2013560. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26948-7_19"},{"key":"9_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/978-3-642-28914-9_10","volume-title":"Theory of Cryptography","author":"H Lipmaa","year":"2012","unstructured":"Lipmaa, H.: Progression-free sets and sublinear pairing-based non-interactive zero-knowledge arguments. In: Cramer, R. (ed.) TCC 2012. LNCS, vol. 7194, pp. 169\u2013189. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-28914-9_10"},{"key":"9_CR26","doi-asserted-by":"publisher","unstructured":"Lipmaa, H., Parisella, R., Siim, J.: Algebraic group model with oblivious sampling. In: Rothblum, G.N., Wee, H. (eds.) TCC\u00a02023, Part\u00a0IV. LNCS, vol. 14372, pp. 363\u2013392. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-48624-1_14","DOI":"10.1007\/978-3-031-48624-1_14"},{"key":"9_CR27","doi-asserted-by":"publisher","unstructured":"Lipmaa, H., Parisella, R., Siim, J.: Constant-size zk-SNARKs in ROM from falsifiable assumptions. In: Joye, M., Leander, G. (eds.) EUROCRYPT\u00a02024, Part\u00a0VI. LNCS, vol. 14656, pp. 34\u201364. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-58751-1_2","DOI":"10.1007\/978-3-031-58751-1_2"},{"key":"9_CR28","doi-asserted-by":"publisher","unstructured":"Lipmaa, H., Parisella, R., Siim, J.: On knowledge-soundness of plonk in ROM from falsifiable assumptions. In: Kalai, Y.T., Kamara, S.F. (eds.) CRYPTO\u00a02025, Part\u00a0VII. LNCS, vol. 16006, pp. 362\u2013395. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-032-01907-3_12","DOI":"10.1007\/978-3-032-01907-3_12"},{"key":"9_CR29","doi-asserted-by":"publisher","unstructured":"Momose, A., Das, S., Ren, L.: On the security of KZG commitment for VSS. In: Meng, W., Jensen, C.D., Cremers, C., Kirda, E. (eds.) ACM CCS 2023, pp. 2561\u20132575. ACM Press (2023). https:\/\/doi.org\/10.1145\/3576915.3623127","DOI":"10.1145\/3576915.3623127"},{"key":"9_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1007\/978-3-642-36594-2_13","volume-title":"Theory of Cryptography","author":"C Papamanthou","year":"2013","unstructured":"Papamanthou, C., Shi, E., Tamassia, R.: Signatures of correct computation. In: Sahai, A. (ed.) TCC 2013. LNCS, vol. 7785, pp. 222\u2013242. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-36594-2_13"},{"key":"9_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"704","DOI":"10.1007\/978-3-030-56877-1_25","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"S Setty","year":"2020","unstructured":"Setty, S.: Spartan: efficient and general-purpose zkSNARKs without trusted setup. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020. LNCS, vol. 12172, pp. 704\u2013737. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56877-1_25"},{"key":"9_CR32","unstructured":"Wagner, B., Zapico, A.: Proving the security of PeerDAS without the AGM. Cryptology ePrint Archive, Paper 2025\/1683 (2025). https:\/\/eprint.iacr.org\/2025\/1683"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2026"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-25336-1_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T13:12:59Z","timestamp":1778245979000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-25336-1_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032253354","9783032253361"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-25336-1_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"9 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Rome","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 May 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 May 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"45","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2026\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}