{"id":"https://openalex.org/W4389011089","doi":"https://doi.org/10.1007/978-3-031-48621-0_17","title":"How to\u00a0Compile Polynomial IOP into\u00a0Simulation-Extractable SNARKs: A Modular Approach","display_name":"How to\u00a0Compile Polynomial IOP into\u00a0Simulation-Extractable SNARKs: A Modular Approach","publication_year":2023,"publication_date":"2023-01-01","ids":{"openalex":"https://openalex.org/W4389011089","doi":"https://doi.org/10.1007/978-3-031-48621-0_17"},"language":"en","primary_location":{"id":"doi:10.1007/978-3-031-48621-0_17","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-031-48621-0_17","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-031-48621-0_17.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"bronze","oa_url":"https://link.springer.com/content/pdf/10.1007/978-3-031-48621-0_17.pdf","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5082774652","display_name":"Markulf Kohlweiss","orcid":"https://orcid.org/0000-0002-8660-9663"},"institutions":[{"id":"https://openalex.org/I4400573175","display_name":"Input Output (Singapore)","ror":"https://ror.org/04abwvq32","country_code":null,"type":"company","lineage":["https://openalex.org/I4400573175"]},{"id":"https://openalex.org/I98677209","display_name":"University of Edinburgh","ror":"https://ror.org/01nrxwf90","country_code":"GB","type":"education","lineage":["https://openalex.org/I98677209"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Markulf Kohlweiss","raw_affiliation_strings":["Input Output Global, Singapore, Singapore","The University of Edinburgh, Edinburgh, UK"],"raw_orcid":"https://orcid.org/0000-0002-8660-9663","affiliations":[{"raw_affiliation_string":"Input Output Global, Singapore, Singapore","institution_ids":["https://openalex.org/I4400573175"]},{"raw_affiliation_string":"The University of Edinburgh, Edinburgh, UK","institution_ids":["https://openalex.org/I98677209"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5064734346","display_name":"Mahak Pancholi","orcid":"https://orcid.org/0009-0006-5317-5535"},"institutions":[{"id":"https://openalex.org/I204337017","display_name":"Aarhus University","ror":"https://ror.org/01aj84f44","country_code":"DK","type":"education","lineage":["https://openalex.org/I204337017"]}],"countries":["DK"],"is_corresponding":false,"raw_author_name":"Mahak Pancholi","raw_affiliation_strings":["Aarhus University, Aarhus, Denmark"],"raw_orcid":"https://orcid.org/0009-0006-5317-5535","affiliations":[{"raw_affiliation_string":"Aarhus University, Aarhus, Denmark","institution_ids":["https://openalex.org/I204337017"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5062998951","display_name":"Akira Takahashi","orcid":"https://orcid.org/0000-0001-8556-3053"},"institutions":[{"id":"https://openalex.org/I2802755631","display_name":"Morgan Stanley (United States)","ror":"https://ror.org/00aphdz18","country_code":"US","type":"company","lineage":["https://openalex.org/I2802755631"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Akira Takahashi","raw_affiliation_strings":["J.P. Morgan AI Research & AlgoCRYPT CoE, New York, USA"],"raw_orcid":"https://orcid.org/0000-0001-8556-3053","affiliations":[{"raw_affiliation_string":"J.P. Morgan AI Research & AlgoCRYPT CoE, New York, USA","institution_ids":["https://openalex.org/I2802755631"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5062998951","https://openalex.org/A5082774652"],"corresponding_institution_ids":["https://openalex.org/I2802755631","https://openalex.org/I4400573175","https://openalex.org/I98677209"],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":null,"fwci":4.1081,"has_fulltext":true,"cited_by_count":8,"citation_normalized_percentile":{"value":0.95150776,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"486","last_page":"512"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10270","display_name":"Blockchain Technology Applications and Security","score":0.9973999857902527,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.973800003528595,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/soundness","display_name":"Soundness","score":0.8271069526672363},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6356569528579712},{"id":"https://openalex.org/keywords/oracle","display_name":"Oracle","score":0.6129757165908813},{"id":"https://openalex.org/keywords/compiler","display_name":"Compiler","score":0.5732375383377075},{"id":"https://openalex.org/keywords/falsifiability","display_name":"Falsifiability","score":0.5731903910636902},{"id":"https://openalex.org/keywords/mathematical-proof","display_name":"Mathematical proof","score":0.5511137247085571},{"id":"https://openalex.org/keywords/zero-knowledge-proof","display_name":"Zero-knowledge proof","score":0.49206870794296265},{"id":"https://openalex.org/keywords/modular-design","display_name":"Modular design","score":0.47559913992881775},{"id":"https://openalex.org/keywords/algebraic-number","display_name":"Algebraic number","score":0.4538669288158417},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.4457312226295471},{"id":"https://openalex.org/keywords/polynomial","display_name":"Polynomial","score":0.4330434799194336},{"id":"https://openalex.org/keywords/discrete-mathematics","display_name":"Discrete mathematics","score":0.41624248027801514},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.3013082444667816},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.2818463146686554},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.1718362271785736},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.10446810722351074}],"concepts":[{"id":"https://openalex.org/C39920170","wikidata":"https://www.wikidata.org/wiki/Q693083","display_name":"Soundness","level":2,"score":0.8271069526672363},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6356569528579712},{"id":"https://openalex.org/C55166926","wikidata":"https://www.wikidata.org/wiki/Q2892946","display_name":"Oracle","level":2,"score":0.6129757165908813},{"id":"https://openalex.org/C169590947","wikidata":"https://www.wikidata.org/wiki/Q47506","display_name":"Compiler","level":2,"score":0.5732375383377075},{"id":"https://openalex.org/C116222747","wikidata":"https://www.wikidata.org/wiki/Q220888","display_name":"Falsifiability","level":2,"score":0.5731903910636902},{"id":"https://openalex.org/C108710211","wikidata":"https://www.wikidata.org/wiki/Q11538","display_name":"Mathematical proof","level":2,"score":0.5511137247085571},{"id":"https://openalex.org/C176329583","wikidata":"https://www.wikidata.org/wiki/Q191943","display_name":"Zero-knowledge proof","level":3,"score":0.49206870794296265},{"id":"https://openalex.org/C101468663","wikidata":"https://www.wikidata.org/wiki/Q1620158","display_name":"Modular design","level":2,"score":0.47559913992881775},{"id":"https://openalex.org/C9376300","wikidata":"https://www.wikidata.org/wiki/Q168817","display_name":"Algebraic number","level":2,"score":0.4538669288158417},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.4457312226295471},{"id":"https://openalex.org/C90119067","wikidata":"https://www.wikidata.org/wiki/Q43260","display_name":"Polynomial","level":2,"score":0.4330434799194336},{"id":"https://openalex.org/C118615104","wikidata":"https://www.wikidata.org/wiki/Q121416","display_name":"Discrete mathematics","level":1,"score":0.41624248027801514},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.3013082444667816},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.2818463146686554},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.1718362271785736},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.10446810722351074},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1007/978-3-031-48621-0_17","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-031-48621-0_17","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-031-48621-0_17.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},{"id":"pmh:oai:pure.atira.dk:openaire/f93d5fc3-d41d-4e4a-859d-dda7481ebd69","is_oa":true,"landing_page_url":"https://pure.au.dk/portal/en/publications/f93d5fc3-d41d-4e4a-859d-dda7481ebd69","pdf_url":null,"source":null,"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Kohlweiss, M, Pancholi, M R & Takahashi, A 2023, How to Compile Polynomial IOP into Simulation-Extractable SNARKs : A Modular Approach. in G Rothblum & H Wee (eds), Theory of Cryptography : Book Subtitle 21st International Conference, TCC 2023, Taipei, Taiwan, November 29\u2013December 2, 2023, Proceedings, Part III. Springer, Cham, Lecture Notes in Computer Science, vol. 14371, pp. 486\u2013512. https://doi.org/10.1007/978-3-031-48621-0_17","raw_type":"info:eu-repo/semantics/publishedVersion"}],"best_oa_location":{"id":"doi:10.1007/978-3-031-48621-0_17","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-031-48621-0_17","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-031-48621-0_17.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.4300000071525574}],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4389011089.pdf","grobid_xml":"https://content.openalex.org/works/W4389011089.grobid-xml"},"referenced_works_count":34,"referenced_works":["https://openalex.org/W159162986","https://openalex.org/W1005246175","https://openalex.org/W1499934958","https://openalex.org/W1526993157","https://openalex.org/W1532874975","https://openalex.org/W1589034595","https://openalex.org/W1909324101","https://openalex.org/W2043007983","https://openalex.org/W2059808351","https://openalex.org/W2077140897","https://openalex.org/W2089128139","https://openalex.org/W2104648615","https://openalex.org/W2513989210","https://openalex.org/W2517744317","https://openalex.org/W2535060913","https://openalex.org/W2536319456","https://openalex.org/W2726052863","https://openalex.org/W2968027060","https://openalex.org/W2982474429","https://openalex.org/W2984674716","https://openalex.org/W2990120385","https://openalex.org/W3013005985","https://openalex.org/W3030841918","https://openalex.org/W3043762149","https://openalex.org/W3091322675","https://openalex.org/W3109568238","https://openalex.org/W3205422116","https://openalex.org/W3207075287","https://openalex.org/W3209656134","https://openalex.org/W4294768166","https://openalex.org/W4308015325","https://openalex.org/W4320082969","https://openalex.org/W4365806553","https://openalex.org/W4365807461"],"related_works":["https://openalex.org/W1516766811","https://openalex.org/W2035793348","https://openalex.org/W2969705217","https://openalex.org/W2157568248","https://openalex.org/W2362245488","https://openalex.org/W2384324714","https://openalex.org/W2997604978","https://openalex.org/W2949331520","https://openalex.org/W3204711402","https://openalex.org/W1005246175"],"abstract_inverted_index":{"Most":[0],"succinct":[1],"arguments":[2],"(SNARKs)":[3],"are":[4],"initially":[5],"only":[6,137],"proven":[7],"knowledge":[8,29,102,201],"sound":[9,30],"(KS).":[10],"We":[11,75],"show":[12,76],"that":[13,47,98,107,189],"the":[14,69,92,99,117,132,141,173,181,200,206,210,220],"commonly":[15],"employed":[16],"compilation":[17],"strategy":[18],"from":[19,104],"polynomial":[20,26,93,151],"interactive":[21],"oracle":[22],"proofs":[23],"(PIOP)":[24],"via":[25],"commitments":[27,152,166],"to":[28,78,163],"SNARKS":[31],"actually":[32],"also":[33,218],"achieves":[34],"other":[35],"desirable":[36],"properties:":[37],"weak":[38],"unique":[39],"response":[40],"(WUR)":[41],"and":[42,46,81,203],"trapdoorless":[43],"zero-knowledge":[44,178],"(TLZK);":[45],"together":[48],"they":[49],"imply":[50],"simulation":[51],"extractability":[52],"(SIM-EXT).":[53],"The":[54,183],"factoring":[55],"of":[56,68,71,101,134,185,196,199,205,212],"SIM-EXT":[57,221],"into":[58],"KS":[59,207],"+":[60,62],"WUR":[61,80,135],"TLZK":[63,82,143,217],"is":[64,144],"becoming":[65],"a":[66,145,156,176],"cornerstone":[67],"analysis":[70,100,191],"non-malleable":[72],"SNARK":[73,160],"systems.":[74],"how":[77],"prove":[79],"for":[83,175,180,216],"PIOP":[84,105],"compiled":[85],"SNARKs":[86],"under":[87],"mild":[88,138],"falsifiable":[89],"assumptions":[90,139],"on":[91,110,140],"commitment":[94],"scheme.":[95],"This":[96,170],"means":[97],"soundness":[103],"properties":[106],"inherently":[108],"relies":[109],"non-falsifiable":[111],"or":[112,122,209],"idealized":[113],"assumption":[114,202],"such":[115],"as":[116],"algebraic":[118],"group":[119,124],"model":[120,125,204],"(AGM)":[121],"generic":[123],"(GGM)":[126],"need":[127,174],"not":[128],"be":[129],"repeated.":[130],"While":[131],"proof":[133],"requires":[136],"PIOP,":[142],"different":[146],"matter.":[147],"As":[148],"perfectly":[149],"hiding":[150],"sometimes":[153],"come":[154],"at":[155],"substantial":[157],"performance":[158],"premium,":[159],"designers":[161],"prefer":[162],"employ":[164],"deterministic":[165],"with":[167],"some":[168],"leakage.":[169],"results":[171],"in":[172,194],"stronger":[177],"property":[179],"PIOP.":[182],"modularity":[184],"our":[186],"approach":[187],"implies":[188],"any":[190],"improvements,":[192],"e.g.":[193],"terms":[195],"tightness,":[197],"credibility":[198],"analysis,":[208],"precision":[211],"capturing":[213],"real-world":[214],"optimizations":[215],"benefits":[219],"guarantees.":[222]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":3}],"updated_date":"2026-05-07T13:39:58.223016","created_date":"2025-10-10T00:00:00"}
