📬 Refine commitment scheme definitions and fix typos - #47
DarkWindman wants to merge 3 commits into
Conversation
ZamDimon
left a comment
There was a problem hiding this comment.
LGTM, I added small comments below
| \begin{remark} | ||
| Note that \textbf{no} commitment scheme can be perfectly binding and perfectly hiding at the same time. | ||
| \end{remark} |
There was a problem hiding this comment.
Let us add proof/justification to that statement. See this post as a good example.
| \begin{enumerate} | ||
| \item $\mathsf{Setup}(1^{\lambda})$ initializes the hash function $\mathsf{H}$. | ||
| \item $\mathsf{Com}(\mathsf{pp}, m, r) \to c$ samples the blinding factor $r$ from some finite subset of $\{0,1\}^*$ and outputs $c \gets \mathsf{H}(m \,\|\, r)$. | ||
| \item $\mathsf{Setup}(1^{\lambda})$ initializes the hash function $\mathsf{H}$ and outputs $\mathsf{pp} \gets (\mathsf{H}, \mathcal{R})$, where $\mathcal{R} := \{0,1\}^{k}$ is the space of blinding factors. |
There was a problem hiding this comment.
I intentionally did not introduce the randomness space notation
There was a problem hiding this comment.
I am personally inclined to not introduce them since the section is not very formal anyway
There was a problem hiding this comment.
I am personally inclined to not introduce them since the section is not very formal anyway
Agreed!
| \begin{remark} | ||
| To satisfy the \emph{binding} property, the blinding factor length $k$ must be fixed to avoid the situation where the adversary could find two distinct messages $m_0 \neq m_1$ and blinding factors $r_0, r_1$ such that $(m_0 \,\|\, r_0) = (m_1 \,\|\, r_1)$. Such a pair breaks binding without being a collision of $\mathsf{H}$. | ||
| \end{remark} |
There was a problem hiding this comment.
To be honest I am not sure whether this remark is very insightful
There was a problem hiding this comment.
Yeah, agree, we can fix that at the definition level, a variable length attack would be possible if we didn't fix the message and randomness length
There was a problem hiding this comment.
Agreed, removed the remark. The message and randomness lengths are now fixed in the definition
| $\Pi$ is called \textbf{homomorphic} if | ||
| \begin{equation*} | ||
| \mathsf{Com}(m_0 \times m_1) = \mathsf{Com}(m_0) \star \mathsf{Com}(m_1) \; \commentgray{for any messages $m_0,m_1 \in \mathcal{M}$.} | ||
| \mathsf{Com}(m_0 \times m_1; r_0 \times r_1) = \mathsf{Com}(m_0; r_0) \star \mathsf{Com}(m_1; r_1) \; \commentgray{for any $m_0,m_1 \in \mathcal{M}$.} |
There was a problem hiding this comment.
then it should be "for any
| For more details, refer to \Cref{subsection:simulation}. | ||
| \end{remark} | ||
|
|
||
| Analyzing the scheme, one can notice that the Pedersen polynomial commitment scheme is just a combination of $d$ calls to the plain Pedersen commitment scheme: the resulting commitment is a vector of $d$ group elements, each being a commitment to the corresponding coefficient of the polynomial. This means that the scheme is not succinct, as the size of the commitment grows linearly with the degree of the polynomial. Since we want the scheme to be both succinct and computationally efficient, let us consider the following scheme, which removes these drawbacks. |
There was a problem hiding this comment.
Awesome paragraph, I like it
There was a problem hiding this comment.
The binding game uses a different Com syntax that includes randomness r, we need to adjust the notation to be coherent across all the definitions. Also pay attention to the usage of public parameters, suddenly it was omitted here. IMO, we need to add a randomness r to all the definitions and games.
There was a problem hiding this comment.
I'm not entirely sure we really need to add r in all cases. I've looked at several sources, and they write the hiding definition (and the game) without r, but include it for the binding property, as seen here, or here. We also don't use r in KZG, so I think it makes sense not to fix it everywhere. However, I completely agree that we shouldn't forget to include pp in the algorithm, since we specified it earlier in Setup().
There was a problem hiding this comment.
Generally I agree with @DarkWindman. Hiding is impossible without r, so the definition includes it; binding is fine without blinding terms, so the definition is stated just in terms of a message.
I would just personally add that commitments notation is commonly confusing and not very well standardized, so small inconsistencies are fine. For example, I was always confused about the Com(*) syntax. Say, many papers write
"Let Com(x;r) = [x]G+[r]H denote the Pedersen commitment"
But this is technically incorrect since Com(*) must specify how the randomness is chosen inside the procedure (this is especially relevant for lattice protocols). So a more correct way may be writing
"Let Com(x)->(C,r) proceed as follows: sample r randomly from Z/qZ, compute C:=[x]G+[r]H and output (C,r)"
But no one writes like that because it complicates things as hell; for instance, in such case one must differentiate Com(x) (which generates randomness underneath and thus outputs two values) and Com(x;r) (which given pre-computed randomness and message, computes the commitment, which is a single-element output).
All that said, we just hope the reader is fine with notation and doesn't feel lost
|
|
||
| We introduce the most basic class of commitment schemes: \emph{hash-based commitments}. | ||
| As the name implies, we are going to use a cryptographic hash function \(\mathsf{H}\). | ||
| As the name implies, we are going to use a cryptographic hash function~\(\mathsf{H}\). |
There was a problem hiding this comment.
How about making the common notation in this and other sections in the macros form ? writing \hash one time is way simpler than repeating \mathsf{H} across all the text. Perhaps consider having macro definitions for each individual section and also for the entire book so some notation can be shared among all the sections (\hash, \GG, \adv)
There was a problem hiding this comment.
Yeah, I am planning to do that in the final review of the whole book, if I will have time; I have a set of all these macros from the lattice sigs paper, but it will take a non-negligible time to fix all such notation throughout the book
There was a problem hiding this comment.
Looks like a perfect task for some Sonnet :) Of course with the after-review, but I think it's not that hard
| \begin{remark} | ||
| To satisfy the \emph{binding} property, the blinding factor length $k$ must be fixed to avoid the situation where the adversary could find two distinct messages $m_0 \neq m_1$ and blinding factors $r_0, r_1$ such that $(m_0 \,\|\, r_0) = (m_1 \,\|\, r_1)$. Such a pair breaks binding without being a collision of $\mathsf{H}$. | ||
| \end{remark} |
There was a problem hiding this comment.
Yeah, agree, we can fix that at the definition level, a variable length attack would be possible if we didn't fix the message and randomness length
| Unfortunately, the scheme from the previous section is not succinct, as the size of the commitment grows linearly with the degree of the polynomial. | ||
| However, using pairing (\Cref{section:ecpairing}), one can build the commitment scheme that requires only a single point in $\mathbb{G}$ to commit to the whole polynomial. | ||
| This is exactly the KZG scheme that we describe in this section. | ||
| In this section, we describe the KZG commitment scheme \cite{kate2010constant}. This scheme is succinct and requires only a single point in $\mathbb{G}$ to commit to the whole polynomial, with pairings (\Cref{section:ecpairing}) used to verify openings. |
There was a problem hiding this comment.
consider moving all the bib references in this book to cryptobib format
|
|
||
| To turn this into a sound scheme, before receiving $\rho$, the prover must first \emph{commit} to polynomial $f$ (call it $\mathsf{com}(f)$). | ||
| After obtaining $\rho$, the prover commits to $q$ (call it $\mathsf{com}(q)$) and then the verifier must check the identity $f(T)-y = (T-\rho)g(T)$. | ||
| After obtaining $\rho$, the prover commits to $u$ (call it $\mathsf{com}(u)$) and then the verifier must check the identity $f(T)-y = (T-\rho)u(T)$. |
There was a problem hiding this comment.
again, we are incoherent in the notation (\mathsf{com}, \mathsf{Com}) within the margins of the single section. We need to somehow fix that once and forever (see my macro comment).
f77950d to
652cda6
Compare
This PR improves the Commitment Schemes section by making several definitions more precise and correcting the remaining typos.