Home > Cryptographic Primitives > ZKAttest
ZKAttest¶
Description¶
Enables ring and group signatures for existing ECDSA keys using zero-knowledge proofs. A party can prove membership in a group or ring without revealing which key they hold, using Pedersen commitments combined with SNARKs.
Properties¶
- Completeness: Yes
- Soundness: Computational
- Zero-knowledge: Yes (which key is used is hidden)
Based on¶
Pedersen-Commitments, Sigma-Protocols-Damgard
Used by¶
Resources¶
- Paper: SAS22-ZKAttest
- Explainer: