Pi , αPi ͷઢܗ݁߹Ͱ࡞Δඞཁ͕͋Δɻ Ҏ্ΑΓɺ ূ໌ऀ {gvk(s)}k∈[m] , {gαvk(s)}k∈[m] ,{gwk(s)}k∈[m] , {gαwk(s)}k∈[m] ,{gyk(s)}k∈[m] , {gαyk(s)}k∈[m] , {gsi }i∈[d] , {gαsi }i∈[d] ͔Β gv(s), gαv(s), gw(s), gαw(s), gy(s), gαy(s), gh(s), gαh(s) Λ࡞Δ͜ͱΛٻΊΒΕΔɻ 4.6 From Quadratic Arithmetic Programs to zk-SNRAK ͜Ε·Ͱূ໌ऀͱݕূऀͷ̎ऀؒʹΑΔରܕͷθϩࣝূ໌Λߦͬͨɻ͜͜Ͱূ໌ऀͱݕূऀͷؒ ʹ৴པͰ͖ΔୈࡾऀΛ͓͖ɺඇରܕͷθϩࣝূ໌ͷߏஙΛߦ͏ɻؔ R := {(x, w) ∈ Fn × Fh} ͱ͠ɺ x Λεςʔτϝϯτɺw Λূڌͱ͢Δɻ͜ͷؔ R ԋࢉճ࿏ C ͰݕূͰ͖ΔͷͰɺ(x, w) ∈ R ͱͳΔ ߹ͷΈɺf(x, w) = 1 ͱͳΔؔ f ͕͋Γɺೖྗ͕ f Λຬͨ͢߹ʹɺԋࢉճ࿏ͷग़ྗ͕ 1ɺͦ͏Ͱͳ ͍߹ग़ྗ͕ 0 ͱͳΔ͜ͱΛҙຯ͍ͯ͠Δɻ f(x, w) = { 1 ∀(x, w) ∈ R 0 ∀(x, w) / ∈ R ؔ R ͱ F ্ͷؔ f Λ༻͍ͯɺԋࢉճ࿏ C ͔Βେ͖͞ mɺ࣍ deg(t(x)) = d ͱͳΔ QAPQ := (V, W, Y, t(x)) Λߏங͢ΔɻN Λؔ f ͷೖग़ྗͱ͠ɺΠϯσοΫε I = {1, . . . , m} Λ 2 ͭͷू߹ Ifree , Ilabeled ʹׂ͠ɺIlabeled = {1, . . . , N}, Ifree = {N + 1, . . . , m} ͱදͤΔɻ·ͨɺIlabeled ͷ෦ ू߹ Iin = ∪i∈[n] Ii = {1, . . . , n} ͱͨ͠ͱ͖ɺImid = I \ Iin ͱ͢Δɻ Gen(1λ, R) → CRS(pk, vk) ηΩϡϦςΟʔύϥϝʔλ λ ͱؔ R ͔Β CRS ͱͳΔূ໌ऀʹ༩͑Δ pk ͱɺݕূऀʹ༩͑Δ vk Λੜ ͢ΔɻҰ༷ͳϥϯμϜͳ α, s ← F Λબ͠ɺҎԼΛߏங͢Δɻ {gsi }i∈[d] , {gαsi }i∈[d] ༩͑ΒΕͨଟ߲ࣜू߹ QAP Q := (V, W, Y, t(x)) ͔ΒɺҎԼΛߏங͢Δɻ {gvk(s)}k∈Lmid , {gαvk(s)}k∈Lmid , {gwk(s)}k∈[m] , {gαwk(s)}k∈[m] , {gyk(s)}k∈[m] , {gαyk(s)}k∈[m] ·ͨɺϥϯμϜͳ βv , βw , βy , γ ← F ΛબͼɺҎԼΛߏங͢Δɻ gβvt(s), gβwt(s), gβyt(s), {gβvvk(s)}k∈Imid , {gβwwk(s)}k∈[m] , {gβyyk(s)}k∈[m] , gβvγ, gβwγ, gβyγ, gγ ͜ΕΒ͕ηοτΞοϓͰੜ͞ΕΔ CRS Ͱ͋Δɻ࣍ʹ pk ͱ vk Λߏங͢Δɻ pk = ({gsi }i∈[d] , {gαsi }i∈[d] , {gvk(s)}k∈Lmid , {gαvk(s)}k∈Lmid , {gβvvk(s)}k∈Lmid , {gwk(s)}k∈[m] , {gαwk(s)}k∈[m] , {gβwwk(s)}k∈[m] , {gyk(s)}k∈[m] , {gαyk(s)}k∈[m] , {gβyyk(s)}k∈[m] ) vk = (g, gα, gγ, gβvγ, gβwγ, gβyγ, gt(s), {gvk(s)}k∈Iin , gv0(s), gw0(s), gy0(s)) 15