Content
@
0 reply
0 recast
0 reaction
Cassie Heart
@cassie
Realizing ZK from MPC sounds like a mind-bender if more familiar with ZK but not MPC, but this lecture by Amit Sahai helps build the intuition that it is not only possible, but it can be a transformative tool for converting honest majority protocols into maliciously secure: https://www.youtube.com/watch?v=-HbqdiCzqE4
3 replies
33 recasts
216 reactions
Shriphani Palakodety
@shriphani
what a cool idea - run mpc locally across a bunch of "parties", reveal the trace of messages seen by a subset of these parties and that is your zkp - you get integrity of the result but no additional information.
2 replies
0 recast
3 reactions
Shriphani Palakodety
@shriphani
this kind of a zkp wouldn't be succinct though right?
1 reply
0 recast
0 reaction
Cassie Heart
@cassie
Correct, although there are some ways to reduce the size, and some specific cases where the proofs can be succinct
0 reply
0 recast
2 reactions