AI 中文总结
ShadowPath将凭证状态查询移至持有者端,以零知识证明实现隐私性,首次评估Verkle树在凭证撤销中的适用性并与稀疏默克尔树对比,验证了路径长度与零知识证明成本的关系。
AI 中文摘要
可验证凭证允许持有者在无需发行方参与每次展示的情况下出示数字签名声明,而撤销机制会干扰这一隐私模型,因为验证方必须判断凭证是否仍然有效。现有的状态检查可能会泄露重复标识符、注册表位置或请求元数据,此类信息可作为稳定句柄关联不同的展示过程。ShadowPath将凭证状态查询转移至持有者端,每次展示时,持有者以零知识证明的方式证明该凭证在验证方选定的注册表根下未被撤销,验证方可获知状态结果但无法获取可观测元数据。据我们所知,本文首次评估了Verkle树在凭证撤销中的适用性,并将其与稀疏默克尔树进行对比以评估其在实际应用中的可行性,对比测试旨在验证Verkle树缩短路径深度是否能抵消基于KZG的认证带来的更高成本。在30次桌面端测试中,使用稀疏默克尔树的Groth16证明中位数耗时为371.6ms,验证耗时为3.70ms;使用Verkle树的Groth16证明中位数耗时为2.11s,验证耗时为7.55ms。在两款主流移动设备上,Verkle树的Groth16证明耗时约为3s。结果表明,更短的认证路径并不一定能降低零知识证明的成本。在新鲜会话随机性的作用下,在会话值独立性的既定假设下,验证方可观测的状态数据不会泄露两次展示是否使用同一凭证,该保证排除了发行方与验证方合谋及同步流量的情况。
英文摘要
Verifiable credentials let holders present digitally signed claims without requiring the issuer to participate in every presentation. Revocation complicates this privacy model because a verifier must determine whether a credential remains valid. Existing status checks may expose recurring identifiers, registry positions, or request metadata. Such information can serve as stable handles to link separate presentations. ShadowPath moves the credential status lookup to the holder. For each presentation, the holder proves, in zero-knowledge, that the credential has not been revoked under the verifier-selected registry root. The verifier learns the status result but not observable metadata. To the best of our knowledge, we provide the first evaluation of Verkle trees for credential revocation and compare them with sparse Merkle trees to assess their applicability in real world applications. The comparison tests whether reducing path depth with Verkle trees offsets the higher cost of KZG-based authentication. Across 30 desktop trials, median Groth16 proving took 371.6ms with sparse Merkle and 2.11s with Verkle. Verification took 3.70ms and 7.55ms, respectively. Groth16 Verkle proving took about 3s on both primary mobile devices. The results show that shorter authenticated paths do not necessarily yield cheaper zero-knowledge proofs. With fresh session randomness, verifier-visible status data do not reveal whether two presentations use the same credential under the stated assumption of session-value independence. This guarantee excludes issuer-verifier collusion and synchronization traffic.