Tight State-Restoration Soundness in the Algebraic Group Model.
Ashrujit Ghoshal, Stefano Tessaro · IACR Cryptology ePrint Archive · 2020
Most efficient zero-knowledge arguments lack a concrete security analysis, making parameter choices and efficiency comparisons challenging. This is even more true for non-interactive versions of these systems obtained via the Fiat-Shamir transform, for which the security guarantees generically derived from the interactive protocol are often too weak, even when assuming a random oracle.