市值: $2.607T 0.90%
成交额(24h): $88.5549B -12.29%
  • 市值: $2.607T 0.90%
  • 成交额(24h): $88.5549B -12.29%
  • 恐惧与贪婪指数:
  • 市值: $2.607T 0.90%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$76464.156879 USD

0.86%

ethereum
ethereum

$2445.495804 USD

1.91%

tether
tether

$0.999058 USD

-0.01%

bnb
bnb

$725.991560 USD

1.93%

xrp
xrp

$1.303704 USD

0.85%

usd-coin
usd-coin

$0.999942 USD

0.00%

solana
solana

$100.064497 USD

3.06%

tron
tron

$0.335357 USD

0.24%

zcash
zcash

$1358.632097 USD

14.53%

hyperliquid
hyperliquid

$79.355311 USD

2.37%

dogecoin
dogecoin

$0.081165 USD

1.50%

monero
monero

$495.294239 USD

-2.55%

chainlink
chainlink

$11.205049 USD

3.83%

unus-sed-leo
unus-sed-leo

$8.932502 USD

0.55%

cardano
cardano

$0.198341 USD

1.78%

加密货币新闻

研究人员发现,电路层漏洞对基于 SNARK 的系统构成最重大威胁

2024/08/09 05:03

伦敦帝国理工学院的研究人员表示,电路层的漏洞对基于简洁非交互式知识论证(SNARK)的系统构成了最重大的威胁。

研究人员发现,电路层漏洞对基于 SNARK 的系统构成最重大威胁

Researchers at Imperial College London have found that vulnerabilities at the circuit layer pose the most significant threat to systems based on Succinct Non-Interactive Arguments of Knowledge (SNARKs).

伦敦帝国理工学院的研究人员发现,电路层的漏洞对基于简洁非交互式知识论证(SNARK)的系统构成了最重大的威胁。

The investigation examined 141 vulnerabilities from 107 audit reports, 16 vulnerability disclosures, and various bug trackers associated with popular SNARK projects. The findings were presented on Aug. 7 at the Science of Blockchain Conference at Columbia University.

该调查检查了 107 份审计报告中的 141 个漏洞、16 个漏洞披露以及与流行 SNARK 项目相关的各种错误跟踪器。研究结果于 8 月 7 日在哥伦比亚大学区块链科学会议上公布。

SNARKs are a type of zero-knowledge (ZK) proof that allows one to demonstrate that a statement is true without revealing any information about the statement. They are used extensively in Web3 to compress large computations and enable efficient on-chain verification.

SNARK 是一种零知识 (ZK) 证明,允许人们证明某个陈述是真实的,而无需透露有关该陈述的任何信息。它们在 Web3 中被广泛使用,以压缩大型计算并实现高效的链上验证。

However, the complexity and abstraction of ZK circuits can introduce vulnerabilities that might go unnoticed during the development and auditing processes.

然而,ZK 电路的复杂性和抽象性可能会引入在开发和审核过程中可能被忽视的漏洞。

To identify and categorize these vulnerabilities, the research team, led by Stefanos Chaliasos, a Ph.D. candidate at Imperial College London, proposed a vulnerability taxonomy and applied it to the analysis of vulnerabilities in circuit layers of several SNARK systems.

为了识别和分类这些漏洞,由博士 Stefanos Chaliasos 领导的研究团队。伦敦帝国理工学院的候选人提出了一种漏洞分类法,并将其应用于多个 SNARK 系统电路层的漏洞分析。

The team identified three main types of vulnerabilities in circuit layers: under-constrained, over-constrained and computational/hints error. The most frequent vulnerability found on zero knowledge circuits arises from insufficient constraints, which cause a verifier to accept invalid proofs, thus compromising a system’s soundness or completeness.

该团队确定了电路层中的三种主要漏洞类型:约束不足、约束过度和计算/提示错误。零知识电路上最常见的漏洞是由于约束不足引起的,这会导致验证者接受无效的证明,从而损害系统的健全性或完整性。

According to the research, 95 of the identified issues on SNARK-based systems affected soundness and four affected completeness. For instance, an attacker could exploit an insufficient input constraint to forge a valid proof for an invalid statement or to create a valid proof for a different statement than the one being proven.

根据研究,基于 SNARK 的系统中已识别的问题中有 95 个影响了健全性,有 4 个影响了完整性。例如,攻击者可以利用不充分的输入约束来为无效语句伪造有效证明,或者为与被证明的语句不同的语句创建有效证明。

“The primary challenge for developers lies in adapting to a different level of abstraction and optimizing circuits for efficiency, which directly impacts the cost of using SNARKs,” the paper notes.

“开发人员面临的主要挑战在于适应不同的抽象级别并优化电路以提高效率,这直接影响使用 SNARK 的成本,”论文指出。

Other root causes for vulnerabilities on ZK circuits include distinguishing between assignments and constraints, missing input constraints and unsafe reuse of circuits, among others.

ZK 电路漏洞的其他根本原因包括区分分配和约束、缺少输入约束以及电路的不安全重用等。

The research team also highlighted the importance of clear documentation and tooling to help developers identify and fix vulnerabilities early on in the development process.

研究团队还强调了清晰的文档和工具对于帮助开发人员在开发过程的早期识别和修复漏洞的重要性。

“The goal is to integrate these findings into a vulnerability scanner that will automatically identify and classify vulnerabilities in ZK circuits,” Chaliasos told Blockworks.

Chaliasos 告诉 Blockworks:“我们的目标是将这些发现集成到漏洞扫描器中,该扫描器将自动识别 ZK 电路中的漏洞并对其进行分类。”

Weighted VRFsThe first day of the conference also featured the Aptos team presenting their recently implemented weighted verifiable random functions, or weighted VRFs — a mechanism designed to enhance the randomness in the consensus process.

加权 VRF 会议第一天,Aptos 团队还展示了他们最近实现的加权可验证随机函数,或称加权 VRF——一种旨在增强共识过程中随机性的机制。

The approach extends the concept of VRFs by incorporating weights into the random selection process of verifying inputs and outputs on-chain. With weights, participants in the consensus mechanism have different probabilities of being chosen based on their stake (weights).

该方法通过将权重纳入验证链上输入和输出的随机选择过程中,扩展了 VRF 的概念。通过权重,共识机制中的参与者根据其权益(权重)有不同的被选择概率。

Aptos deployed the mechanism on its mainnet in June. “As far as you can tell, this is the first time you see a previously granular script that is unbiaseable, unpredictable, and operates as fast as the network,” said Alin Tomescu, head of cryptography at Aptos, during the presentation.

Aptos 于 6 月份在其主网上部署了该机制。 Aptos 密码学主管 Alin Tomescu 在演示中表示:“据您所知,这是您第一次看到以前的细粒度脚本,它是无偏见的、不可预测的,并且运行速度与网络一样快。”

According to Tomescu, Aptos has processed half a million calls through the new randomness API, with the distributed key generation (DKG) lasting about 20 seconds.

Tomescu 表示,Aptos 已通过新的随机性 API 处理了 50 万次调用,分布式密钥生成 (DKG) 持续约 20 秒。

原文来源:cointelegraph

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年09月18日 发表的其他文章