{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T01:05:49Z","timestamp":1766019949681,"version":"3.48.0"},"reference-count":28,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T00:00:00Z","timestamp":1766016000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T00:00:00Z","timestamp":1766016000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>This paper revisits Virgo, a well-known transparent zero-knowledge proof system that has been used in many subsequent studies. Through our analysis, we uncover previously overlooked limitations and several exploitable security vulnerabilities within Virgo\u2019s zkVPD protocol design and implementation. We subsequently address these issues and improve Virgo\u2019s zkVPD protocol. Our improvements feature simplified but more efficient VPD and zkVPD algorithms, offering enhanced support for computations over binary fields and their extension fields.<\/jats:p>","DOI":"10.1186\/s42400-025-00450-w","type":"journal-article","created":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T01:01:58Z","timestamp":1766019718000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Revisiting virgo: a study of vulnerabilities, limitations, and optimizations"],"prefix":"10.1186","volume":"8","author":[{"given":"Changchang","family":"Ding","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5169-4319","authenticated-orcid":false,"given":"Yan","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,12,18]]},"reference":[{"key":"450_CR1","doi-asserted-by":"publisher","unstructured":"Attema T, Cramer R, Kohl L (2021) A compressed $$\\varSigma $$-protocol theory for lattices. In: Malkin T, Peikert C (eds) CRYPTO\u00a02021, Part\u00a0II. LNCS, vol 12826, pp 549\u2013579. Virtual Event. https:\/\/doi.org\/10.1007\/978-3-030-84245-1_19","DOI":"10.1007\/978-3-030-84245-1_19"},{"key":"450_CR3","doi-asserted-by":"publisher","unstructured":"Ben-Sasson E, Bentov I, Horesh Y, Riabzev M (2018) Fast reed-solomon interactive oracle proofs of proximity. In: Chatzigiannakis I, Kaklamanis C, Marx D, Sannella D (eds) ICALP 2018. LIPIcs, vol 107, pp 14\u201311417. https:\/\/doi.org\/10.4230\/LIPIcs.ICALP.2018.14","DOI":"10.4230\/LIPIcs.ICALP.2018.14"},{"key":"450_CR2","doi-asserted-by":"publisher","unstructured":"Ben-Sasson E, Chiesa A, Riabzev M, Spooner N, Virza M, Ward NP (2019) Aurora: transparent succinct arguments for R1CS. In: Ishai Y, Rijmen V (eds) EUROCRYPT\u00a02019, Part\u00a0I. LNCS, vol 11476, pp 103\u2013128. https:\/\/doi.org\/10.1007\/978-3-030-17653-2_4","DOI":"10.1007\/978-3-030-17653-2_4"},{"key":"450_CR4","doi-asserted-by":"publisher","unstructured":"Ben-Sasson E, Carmon D, Ishai Y, Kopparty S, Saraf S (2020) Proximity gaps for reed-solomon codes. In: 61st FOCS, pp 900\u2013909.https:\/\/doi.org\/10.1109\/FOCS46700.2020.00088","DOI":"10.1109\/FOCS46700.2020.00088"},{"key":"450_CR5","doi-asserted-by":"publisher","unstructured":"Bhadauria R, Fang Z, Hazay C, Venkitasubramaniam M, Xie T, Zhang Y (2020) Ligero++: a new optimized sublinear IOP. In: Ligatti J, Ou X, Katz J, Vigna G (eds) ACM CCS 2020, pp 2025\u20132038.https:\/\/doi.org\/10.1145\/3372297.3417893","DOI":"10.1145\/3372297.3417893"},{"key":"450_CR6","doi-asserted-by":"publisher","first-page":"254","DOI":"10.1006\/ffta.1999.0243","volume":"5","author":"NP Byott","year":"1999","unstructured":"Byott NP, Chapman RJ (1999) Power sums over finite subspaces of a field. Finite Fields Their Appl 5:254","journal-title":"Finite Fields Their Appl"},{"key":"450_CR7","doi-asserted-by":"publisher","unstructured":"B\u00fcnz B, Bootle J, Boneh D, Poelstra A, Wuille P, Maxwell G (2018) Bulletproofs: short proofs for confidential transactions and more. In: 2018 IEEE symposium on security and privacy, pp 315\u2013334. https:\/\/doi.org\/10.1109\/SP.2018.00020","DOI":"10.1109\/SP.2018.00020"},{"key":"450_CR9","unstructured":"Chiesa A, Forbes MA, Spooner N (2017) A zero knowledge sumcheck and its applications. Cryptology ePrint Archive, Report 2017\/305 . https:\/\/eprint.iacr.org\/2017\/305"},{"key":"450_CR8","unstructured":"Chiesa A, Wu A, Ovsiankin M, Hu Y, Ward N, etc, AR (2024) Aurora: C++ library for IOP-based zkSNARKs. Accessed in August, https:\/\/github.com\/scipr-lab\/libiop"},{"key":"450_CR10","unstructured":"Diamond BE, Posen J (2023) Succinct arguments over towers of binary fields. Cryptology ePrint Archive, Report 2023\/1784. https:\/\/eprint.iacr.org\/2023\/1784"},{"key":"450_CR11","unstructured":"Diamond BE, Posen J (2024) Polylogarithmic proofs for multilinears over binary towers. Cryptology ePrint Archive, Report 2024\/504 . https:\/\/eprint.iacr.org\/2024\/504"},{"issue":"1","key":"450_CR12","doi-asserted-by":"publisher","first-page":"544","DOI":"10.2478\/popets-2022-0027","volume":"2022","author":"S Fu","year":"2022","unstructured":"Fu S, Gong G (2022) Polaris: transparent succinct zero-knowledge arguments for R1CS with efficient verifier. PoPETs 2022(1):544\u2013564. https:\/\/doi.org\/10.2478\/popets-2022-0027","journal-title":"PoPETs"},{"key":"450_CR13","doi-asserted-by":"publisher","first-page":"6265","DOI":"10.1109\/TIT.2010.2079016","volume":"56","author":"S Gao","year":"2010","unstructured":"Gao S, Mateer T (2010) Additive fast Fourier transforms over finite fields. IEEE Trans Inf Theory 56:6265","journal-title":"IEEE Trans Inf Theory"},{"key":"450_CR14","doi-asserted-by":"publisher","unstructured":"Goldwasser S, Kalai YT, Rothblum GN (2008) Delegating computation: interactive proofs for muggles. In: Ladner RE, Dwork C (eds) 40th ACM STOC, pp 113\u2013122.https:\/\/doi.org\/10.1145\/1374376.1374396","DOI":"10.1145\/1374376.1374396"},{"key":"450_CR15","doi-asserted-by":"publisher","unstructured":"Golovnev A, Lee J, Setty STV, Thaler J, Wahby RS (2023) Brakedown: linear-time and field-agnostic SNARKs for R1CS. In: Handschuh H, Lysyanskaya A (eds) CRYPTO\u00a02023, Part\u00a0II. LNCS, vol 14082, pp 193\u2013226.https:\/\/doi.org\/10.1007\/978-3-031-38545-2_7","DOI":"10.1007\/978-3-031-38545-2_7"},{"key":"450_CR16","doi-asserted-by":"publisher","first-page":"5343","DOI":"10.1109\/TIT.2016.2600417","volume":"62","author":"S-J Lin","year":"2016","unstructured":"Lin S-J, Al-Naffouri TY, Han YS (2016) FFT algorithm for binary extension finite fields and its application to reed-solomon codes. IEEE Trans Inf Theory 62:5343","journal-title":"IEEE Trans Inf Theory"},{"key":"450_CR17","doi-asserted-by":"publisher","unstructured":"Liu T, Xie X, Zhang Y (2021) zkCNN: Zero knowledge proofs for convolutional neural network predictions and accuracy. In: Vigna G, Shi E (eds) ACM CCS 2021, pp 2968\u20132985. https:\/\/doi.org\/10.1145\/3460120.3485379","DOI":"10.1145\/3460120.3485379"},{"key":"450_CR18","doi-asserted-by":"publisher","unstructured":"Liu T, Xie T, Zhang J, Song D, Zhang Y (2024) Pianist: scalable zkrollups via fully distributed zero-knowledge proofs. In: 2024 IEEE symposium on security and privacy, pp 1777\u20131793. https:\/\/doi.org\/10.1109\/SP54263.2024.00035","DOI":"10.1109\/SP54263.2024.00035"},{"key":"450_CR19","doi-asserted-by":"publisher","unstructured":"Lund C, Fortnow L, Karloff HJ, Nisan N (1990) Algebraic methods for interactive proof systems. In: 31st FOCS, pp 2\u201310.https:\/\/doi.org\/10.1109\/FSCS.1990.89518","DOI":"10.1109\/FSCS.1990.89518"},{"key":"450_CR20","doi-asserted-by":"publisher","unstructured":"Lyubashevsky V, Nguyen NK, Plan\u00e7on M (2022) Lattice-based zero-knowledge proofs and applications: shorter, simpler, and more general. In: Dodis Y, Shrimpton T (eds) CRYPTO\u00a02022, Part\u00a0II. LNCS, vol 13508, pp 71\u2013101. https:\/\/doi.org\/10.1007\/978-3-031-15979-4_3","DOI":"10.1007\/978-3-031-15979-4_3"},{"key":"450_CR21","doi-asserted-by":"publisher","unstructured":"Merkle RC (1988) A digital signature based on a conventional encryption function. In: Pomerance C (ed) CRYPTO\u201987. LNCS, vol 293, pp 369\u2013378 .https:\/\/doi.org\/10.1007\/3-540-48184-2_32","DOI":"10.1007\/3-540-48184-2_32"},{"key":"450_CR22","unstructured":"Rubinfeld R, Sudan M (1992) Self-testing polynomial functions efficiently and over rational domains. In: Frederickson GN (ed) 3rd SODA, pp 23\u201332"},{"key":"450_CR23","doi-asserted-by":"publisher","unstructured":"Wahby RS, Tzialla I, shelat a, Thaler J, Walfish M (2018) Doubly-efficient zkSNARKs without trusted setup. In: 2018 IEEE symposium on security and privacy, pp 926\u2013943. https:\/\/doi.org\/10.1109\/SP.2018.00060","DOI":"10.1109\/SP.2018.00060"},{"key":"450_CR24","doi-asserted-by":"publisher","unstructured":"Xie T, Zhang J, Zhang Y, Papamanthou C, Song D (2019) Libra: succinct zero-knowledge proofs with optimal prover computation. In: Boldyreva A, Micciancio D (eds) CRYPTO\u00a02019, Part\u00a0III. LNCS, vol 11694, pp 733\u2013764. https:\/\/doi.org\/10.1007\/978-3-030-26954-8_24","DOI":"10.1007\/978-3-030-26954-8_24"},{"key":"450_CR25","doi-asserted-by":"publisher","unstructured":"Xie T, Zhang Y, Song D (2022) Orion: Zero knowledge proof with linear prover time. In: Dodis Y, Shrimpton T (eds) CRYPTO\u00a02022, Part\u00a0IV. LNCS, vol 13510, pp 299\u2013328. https:\/\/doi.org\/10.1007\/978-3-031-15985-5_11","DOI":"10.1007\/978-3-031-15985-5_11"},{"key":"450_CR26","doi-asserted-by":"publisher","unstructured":"Xie T, Zhang J, Cheng Z, Zhang F, Zhang Y, Jia Y, Boneh D, Song D (2022) zkBridge: trustless cross-chain bridges made practical. In: Yin H, Stavrou A, Cremers C, Shi E (eds) ACM CCS 2022, pp 3003\u20133017.https:\/\/doi.org\/10.1145\/3548606.3560652","DOI":"10.1145\/3548606.3560652"},{"key":"450_CR27","doi-asserted-by":"publisher","unstructured":"Zhang J, Xie T, Zhang Y, Song D (2020) Transparent polynomial delegation and its applications to zero knowledge proof. In: 2020 IEEE symposium on security and privacy, pp 859\u2013876. https:\/\/doi.org\/10.1109\/SP40000.2020.00052","DOI":"10.1109\/SP40000.2020.00052"},{"key":"450_CR28","unstructured":"Zhang J, Xie T, Hoang T, Shi E, Zhang Y (2022) Polynomial commitment with a one-to-many prover and applications. In: Butler KRB, Thomas K (eds) USENIX Security 2022, pp 2965\u20132982"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00450-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00450-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00450-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T01:02:00Z","timestamp":1766019720000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00450-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,18]]},"references-count":28,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["450"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00450-w","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,18]]},"assertion":[{"value":"17 March 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 July 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 December 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no conflict of interest about the research results in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"118"}}