AC4: Algebraic Computation Checker for Circuit Constraints in ZKPs

📅 2024-03-23
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
In zero-knowledge proofs (ZKPs), under-constrained (false-acceptance) and over-constrained (unsatisfiability) circuits in zk-SNARKs compromise verification security. This work models circuit constraints as polynomial equation systems over finite fields and leverages computer algebra systems (CAS) for symbolic solving and solution-set classification, enabling precise detection of both constraint defects. We introduce a fine-grained verification result classification mechanism that significantly enhances the expressiveness of constraint modeling and improves vulnerability detection accuracy. Our approach supports formal verification and parsing of Circom and Halo2 circuits. Experimental evaluation demonstrates that, within the solvable domain, our method achieves 29% higher constraint coverage than Picus and 10% higher than halo2-analyzer, while reducing analysis time by an order of magnitude.

Technology Category

Constraint Satisfaction and Optimization: SatisfiabilityComputer Vision: Adversarial Attacks & RobustnessReasoning under Uncertainty: Other Foundations of Reasoning under Uncertainty

Application Category

Security and Privacy: Data transparency and provenanceGraph Algorithms and Modeling for the Web: Algorithms and analysis for incomplete, noisy, or partially observed Web-related graphsWeb Mining and Content Analysis: Web data provenance, reliability, and authenticity
📝 Abstract
Zero-knowledge proof (ZKP) systems have surged attention and held a fundamental role in contemporary cryptography. Zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK) protocols dominate the ZKP usage, implemented through arithmetic circuit programming paradigm. However, underconstrained or overconstrained circuits may lead to bugs. The former refers to circuits that lack the necessary constraints, resulting in unexpected solutions and causing the verifier to accept a bogus witness, and the latter refers to circuits that are constrained excessively, resulting in lacking necessary solutions and causing the verifier to accept no witness. This paper introduces a novel approach for pinpointing two distinct types of bugs in ZKP circuits. The method involves encoding the arithmetic circuit constraints to polynomial equation systems and solving them over finite fields by the computer algebra system. The classification of verification results is refined, greatly enhancing the expressive power of the system. A tool, AC4, is proposed to represent the implementation of the method. Experiments show that AC4 demonstrates a increase in the checked ratio, showing a 29% improvement over Picus, a checker for Circom circuits, and a 10% improvement over halo2-analyzer, a checker for halo2 circuits. Within a solvable range, the checking time has also exhibited noticeable improvement, demonstrating a magnitude increase compared to previous efforts.
Problem

Research questions and friction points this paper is trying to address.

Detects underconstrained and overconstrained bugs in ZKP circuits.
Encodes circuit constraints into polynomial systems for analysis.
Improves verification accuracy and efficiency over existing tools.
Innovation

Methods, ideas, or system contributions that make the work stand out.

Encodes circuit constraints into polynomial equation systems
Solves polynomial systems over finite fields via computer algebra
Refines verification classification to enhance system expressiveness
🔎 Similar Papers
No similar papers found.