天成彩票

学术科研
天成彩票当前位置: 学院天成彩票 > 学术科研 > 正文
天成彩票 信息安全团队在分布式隐私计算领域取得突破
天成彩票发布日期 2026-09-28 天成彩票浏览次数

(图文|杜志力 编辑|信息 审核|徐士伟)近日,天成彩票 天成彩票 信息安全团队研究成果“SDA-zkDel: Scalable, Delegator-offline, and Authenticated zkSNARK Delegation”被国际网络与分布式系统安全会议Network and Distributed System Security Symposium(NDSS 2027)录用。NDSS是全球信息安全领域公认的顶级学术会议,被中国计算机学会(CCF)列为A类国际学术会议,与IEEE S&P、ACM CCS、USENIX Security并称为信息安全领域“四大”顶级会议(即:信安BIG4)。该会议以评审严格、创新性强著称,近十年平均录用率约为17%,今年第一轮录用率更是低至不足14%,该会议所录论文代表着网络与分布式系统安全领域的最前沿研究方向。此次,是华中农业大学首次以第一单位、独立单位在信息安全CCF A类顶会上取得突破。

天成彩票

随着区块链与隐私计算快速发展,零知识简洁非交互式知识论证(zkSNARKs)已成为区块链系统的重要密码学组件。然而,其证明生成计算开销巨大,手机、旧式计算机等资源受限设备难以独立完成。将证明生成外包给多台远程服务器的私有委托方案,被认为是一条可行路径,但现有分布式委托框架普遍面临水平扩展性不足、缺乏运行时认证、委托方需频繁在线交互等问题。

针对上述难题,天成彩票 信息安全团队提出针对广泛部署zkSNARK的委托框架SDA-zkDel。该框架一方面针对快速傅里叶变换和乘积检查等zkSNARK核心瓶颈操作设计并行方案,使计算负载能够随worker服务器数量增加而下降;另一方面采用三方复制秘密共享并集成基于信息论的消息认证码,使worker服务器在计算过程中即可验证中间结果,及时发现恶意worker的篡改。委托方只需在初始阶段分发认证份额,之后便可完全离线,由worker服务器自主协调证明生成,最终再由委托方收集份额并重构证明。

在技术实现上,SDA-zkDel将快速傅里叶变换分解为相互独立的行、列计算任务,通过并行执行降低单节点计算负载,提升系统整体扩展性;对乘积检查过程进行模块化分解与并行化设计,提高计算效率,实现系统的可扩展计算。在安全层面,通过轻量级认证机制,使每次乘法运算后都能进行完整性验证,避免私密见证在委托过程中泄露。该设计在保证安全性的同时,兼顾了实际部署效率。

大量实验表明,在每方8个计算节点的集群上,SDA-zkDel对Groth16实现最高4倍加速,对PLONK实现最高6倍加速。与最新运行时认证方案相比,其预处理速度提升超过2倍,份额计算速度最高提升1.92倍。在Zcash和Mina等真实区块链系统上,在相同worker服务器的情况下,尽管SDA-zkDel提供了同类方案所缺失的运行时认证能力,其委托方运行时间仍分别仅为同类方案的十分之一(Groth16)和三分之一(PLONK),总运行时间也更低。实验结果表明,SDA-zkDel使资源受限设备上的zkSNARK证明生成变得切实可行,该研究有望为依赖zkSNARKs的分布式系统(如:区块链、P2P网络等)隐私计算研究提供新启发。

天成彩票 计算机科学系徐士伟副教授、郭曦副教授为论文共同通讯作者。天成彩票 2024级硕士研究生杜志力,2023级硕士研究生王俊为论文共同第一作者,其他参与者包括天成彩票 童言老师、尹江津老师等。

论文摘要

Zero-Knowledge Succinct Non-interactive Arguments of Knowledge (zkSNARKs) are widely deployed in Layer 1 blockchain systems (e.g., cryptocurrencies, smart contract platforms), but their high computational cost limits deployment on resource-constrained devices. Instead of upgrading blockchains that may cause a hard fork, private delegation offloads the proof generation to workers for acceleration, with secure Multi-Party Computation (MPC) preventing private witness leakage. However, existing hardware-independent frameworks lack horizontal scalability (notably for FFT and univariate product check in widely-deployed zkSNARKs), fail to resist runtime tampering attacks that may leak private witness, or require cumbersome online interaction between delegator and workers. To address these limitations, we propose SDA-zkDel, a scalable, delegator-offline, and authenticated zkSNARK delegation framework for Layer 1 systems that employ zkSNARKs. First, we design tailored parallelization schemes for the bottlenecks of widely-deployed zkSNARKs to achieve horizontal scalability. To further enable efficient runtime authentication and delegator-offline operations, we perform quantitative analysis and empirical evaluations that identify 3-party Replicated Secret Sharing (RSS) as a more suitable and delegator-friendly MPC scheme for protecting widely-deployed zkSNARKs. We then develop a runtime authentication mechanism by integrating 3-party RSS with SPDZ-style IT-MAC tag, in which runtime tampering can be efficiently detected by honest workers without requiring the delegator to be online. We implement SDA-zkDel on a legacy cluster (up to 8 workers/party), achieving up to 4× speedup for Groth16 and 6× for PLONK over a single-worker baseline. Our authenticated RSS offers over 2× faster setup and up to 1.9× faster share computation than the latest runtime-authenticated schemes (which lack horizontal scalability). On real-world Layer 1 systems (Zcash and Mina), SDA-zkDel dramatically cuts proving time on resource-constrained nodes, making proof generation practical on legacy devices. Under a fair 24-node budget, despite providing runtime authentication (which zkSaaS lacks and risks witness leakage), our delegator runtime is only 1/10 (Groth16) and 1/3 (PLONK) of zkSaaS's, with lower total runtime as well.