ENI6MA vs. AZTEC: Rosario–Wang Proof (RWP) — a pairing-free proof-of-knowledge vs. Aztec ZKP
Fuente:
Zenodo
Salvato in:
| Autore principale: | |
|---|---|
| Natura: | Recurso digital |
| Lingua: | inglese |
| Pubblicazione: |
Zenodo
2025
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866902217437478912 |
|---|---|
| author | Rosario, Frank |
| author_facet | Rosario, Frank |
| contents | <p>Technical white paper comparing two confidentiality-proof paradigms. The paper introduces the Rosario–Wang Proof (RWP) and ENI6MA architecture — a stateless, session-entropic, manifold-to-projection proof-of-knowledge that verifies membership via XOR and Boolean accumulators — and contrasts it with the pairing-based AZTEC ZKP (bn128, CRS, Fiat–Shamir). Key themes: verifier cost models, trust/setup tradeoffs (CRS trapdoor vs. session masks), platform portability (carrier-neutral bitwise ops vs. bn128 precompiles), and post-quantum posture (Grover-bounded vs. discrete-log assumptions). Practical guidance and per-equation cost models (TRWP vs. TAZTEC) are provided for architects targeting EVM, WASM, and mobile verifiers.<br><br>AZTEC offers a rigorous pairing-based NIZK, with strong algebra and a practical EVM pathway. But its advantages are<br>conditional on a perfect ceremony and on paying at least one pairing per verify. ENI6MA/RWP’s advantages are unconditional in those dimensions: there is no ceremony to get wrong, no trapdoor to guard, and no pairing to pay, ever.<br>The acceptance logic is a deterministic Boolean accumulator over session-fresh projections; the complexity is pure linear in the number of checked records; and the post-quantum narrative is anchored in the denial of reusable oracles, which<br>caps the attacker’s advantage to Grover-type √· speedups on per-session spaces.<br><br>The RWP verifier uses only CPU-native primitives; consequently its performance is stable across carriers (WASM, mobile,<br>embedded), and audits focus on straight-line logic rather than multi-precision field arithmetic or side-channel-sensitive curve code. <br><br>Trapdoor-free vs. trapdoor-fragile. AZTEC’s binding depends on a secret parameter y generated during the CRS ceremony. If y is ever recovered, an adversary can craft out-of-range commitments that nonetheless satisfy the pairing equation. </p> |
| format | Recurso digital |
| id | zenodo_https___doi_org_10_5281_zenodo_17049214 |
| institution | Zenodo |
| language | eng |
| publishDate | 2025 |
| publisher | Zenodo |
| record_format | zenodo |
| spellingShingle | ENI6MA vs. AZTEC: Rosario–Wang Proof (RWP) — a pairing-free proof-of-knowledge vs. Aztec ZKP Rosario, Frank ZKP zero-knowledge proofs pairing-based cryptography ZK AZTEC <p>Technical white paper comparing two confidentiality-proof paradigms. The paper introduces the Rosario–Wang Proof (RWP) and ENI6MA architecture — a stateless, session-entropic, manifold-to-projection proof-of-knowledge that verifies membership via XOR and Boolean accumulators — and contrasts it with the pairing-based AZTEC ZKP (bn128, CRS, Fiat–Shamir). Key themes: verifier cost models, trust/setup tradeoffs (CRS trapdoor vs. session masks), platform portability (carrier-neutral bitwise ops vs. bn128 precompiles), and post-quantum posture (Grover-bounded vs. discrete-log assumptions). Practical guidance and per-equation cost models (TRWP vs. TAZTEC) are provided for architects targeting EVM, WASM, and mobile verifiers.<br><br>AZTEC offers a rigorous pairing-based NIZK, with strong algebra and a practical EVM pathway. But its advantages are<br>conditional on a perfect ceremony and on paying at least one pairing per verify. ENI6MA/RWP’s advantages are unconditional in those dimensions: there is no ceremony to get wrong, no trapdoor to guard, and no pairing to pay, ever.<br>The acceptance logic is a deterministic Boolean accumulator over session-fresh projections; the complexity is pure linear in the number of checked records; and the post-quantum narrative is anchored in the denial of reusable oracles, which<br>caps the attacker’s advantage to Grover-type √· speedups on per-session spaces.<br><br>The RWP verifier uses only CPU-native primitives; consequently its performance is stable across carriers (WASM, mobile,<br>embedded), and audits focus on straight-line logic rather than multi-precision field arithmetic or side-channel-sensitive curve code. <br><br>Trapdoor-free vs. trapdoor-fragile. AZTEC’s binding depends on a secret parameter y generated during the CRS ceremony. If y is ever recovered, an adversary can craft out-of-range commitments that nonetheless satisfy the pairing equation. </p> |
| title | ENI6MA vs. AZTEC: Rosario–Wang Proof (RWP) — a pairing-free proof-of-knowledge vs. Aztec ZKP |
| topic | ZKP zero-knowledge proofs pairing-based cryptography ZK AZTEC |
| url | https://doi.org/10.5281/zenodo.17049214 |