SwiftRange: A Short and Efficient Zero-Knowledge Range Argument For Confidential Transactions and More
Nan Wang, Sid Chi-Kin Chau, DongXi Liu
IEEE Symposium on Security and Privacy 2024 · Day 2 · Continental Ballroom 6
Overview
In an era where digital transactions are increasingly prevalent, the need for both transparency and privacy presents a significant challenge, particularly within decentralized blockchain systems. This talk by Nan Wang, a Post-doc Research Fellow at CSIRO, alongside collaborators Sid Chi-Kin Chau and DongXi Liu, introduces SwiftRange, a novel zero-knowledge range argument designed to bolster privacy in confidential transactions and other privacy-preserving applications. SwiftRange offers a compelling advancement in cryptographic proofs, specifically addressing the critical requirement that hidden transaction amounts remain non-negative without revealing the actual values.

Key moments
- 0:00 SwiftRange introduction, contributions, and Bulletproofs comparison
- 2:00 Confidential transactions and the need for range proofs
- 3:50 Understanding public coin zero-knowledge proof basics
- 5:00 SwiftRange's core equality and bit decomposition
- 6:10 Achieving zero-knowledge and composite generator merging
- 8:45 Adapting compression protocols for quadratic setting
- 10:30 SwiftRange experimental performance and efficiency
SwiftRange: A Short and Efficient Zero-Knowledge Range Argument For Confidential Transactions and More
Speakers: Nan Wang, Post-doc Research Fellow, CSIRO; Sid Chi-Kin Chau; DongXi Liu
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=8wySorFEABs
Overview
In an era where digital transactions are increasingly prevalent, the need for both transparency and privacy presents a significant challenge, particularly within decentralized blockchain systems. This talk by Nan Wang, a Post-doc Research Fellow at CSIRO, alongside collaborators Sid Chi-Kin Chau and DongXi Liu, introduces SwiftRange, a novel zero-knowledge range argument designed to bolster privacy in confidential transactions and other privacy-preserving applications. SwiftRange offers a compelling advancement in cryptographic proofs, specifically addressing the critical requirement that hidden transaction amounts remain non-negative without revealing the actual values.
The core innovation of SwiftRange lies in its ability to generate a logarithmic-sized proof in the discrete logarithm setting without requiring a trusted setup. This positions it as a direct competitor to existing state-of-the-art solutions like Bulletproofs. The research demonstrates that for 64-bit ranges, SwiftRange achieves a remarkable twofold increase in verifier efficiency and a 1.4 times improvement in prover efficiency compared to Bulletproofs, albeit with a marginal 1.1 times increase in communication costs. This efficiency gain makes SwiftRange an attractive "drop-in replacement" for enhancing the privacy and integrity of blockchain-based confidential transactions and a broad spectrum of other applications demanding value constraints.
Background
▶ Watch: SwiftRange introduction, contributions, and Bulletproofs comparison (0:00)
Blockchain technology has revolutionized digital interactions by enabling decentralized, peer-to-peer transactions free from central authority. This innovation underpins the existence of numerous cryptocurrencies like Bitcoin and Ethereum. However, the foundational design of many early blockchain systems, while ensuring transparency, inadvertently exposed sensitive transaction data. Each block, composed of multiple transactions, publicly displays the sender's address, recipient's address, and crucially, the transfer amount. This public visibility of transaction values poses a significant privacy concern for users and enterprises.
Beyond privacy, early blockchain systems also grappled with scalability, referring to their capacity to process a high volume of transactions within a specified timeframe. While scalability remains an ongoing area of research and development, the issue of privacy began to be addressed more directly after 2013 with the emergence of confidential transactions. These cryptographic schemes aim to hide the transfer amount from all external observers, ensuring that only the transacting parties have knowledge of the values exchanged. Some advanced confidential transaction schemes even extend this privacy to obscure the identities of the sender and recipient.
Hiding transaction amounts, while solving a privacy problem, introduces a new technical challenge: how to mathematically guarantee that the hidden amount is non-negative. Without such a guarantee, a malicious actor could theoretically "create" new currency by transferring a negative amount, effectively reversing the flow of value and undermining the entire economic integrity of the system. This is precisely where zero-knowledge range proofs become indispensable. A range proof allows a prover to demonstrate that a secret value lies within a specified range (e.g., between 0 and 2^N-1) without revealing the secret value itself. SwiftRange leverages public coin protocols – interactive cryptographic protocols where the verifier's messages are uniformly random and independent of the prover's messages – to construct its range proof, ensuring both the integrity and confidentiality of transactions.
Key Findings
▶ Watch: Understanding public coin zero-knowledge proof basics (3:50)
SwiftRange represents a significant leap forward in the design and efficiency of zero-knowledge range arguments, particularly for applications requiring robust privacy and integrity guarantees without sacrificing performance. The core contributions and key findings presented in the talk are multifaceted:
- Novel Logarithmic-Sized Zero-Knowledge Range Proof: The primary finding is the development of SwiftRange itself – a new type of zero-knowledge range proof that achieves a logarithmic proof size in the discrete logarithm setting. Crucially, it operates without a trusted setup, which is a highly desirable property as it removes a potential single point of failure and complex initialization process often associated with other ZKP schemes. SwiftRange can efficiently prove that a committed value
xresides within the range[0, 2^N - 1].
- Superior Prover and Verifier Efficiency: A central objective of SwiftRange was to compete with, and ideally surpass, existing state-of-the-art range proofs like Bulletproofs. The experimental benchmarks confirmed this success: for a typical 64-bit range, SwiftRange demonstrated twice the verifier efficiency and 1.4 times the prover efficiency compared to Bulletproofs. This substantial performance gain in computation makes it highly attractive for real-world deployment where verification and proof generation speeds are critical.
- Optimized Communication Costs: While achieving significant computational efficiency, SwiftRange maintains competitive communication costs. For the 64-bit range, it incurs only a 1.1 times increase in communication costs relative to Bulletproofs. This slight trade-off is often acceptable, given the substantial gains in processing speed.
- Smallest Proof Size for Bit-Decomposition Schemes: The research highlights that for 8-bit ranges, SwiftRange achieves the smallest proof size among all bit-decomposition based range proofs that do not rely on a trusted setup, coming in at a compact 353 bytes. This is an important metric for bandwidth-constrained environments.
- Efficient Aggregation of Proofs: SwiftRange's design extends effectively to scenarios requiring the aggregation of multiple single proofs generated by a single prover. In such aggregate proof settings, SwiftRange maintains its advantage in prover and verifier efficiency over Bulletproofs, exhibiting a logarithmically quicker growth in performance with increased aggregation size. While Flash Proofs (another work by Nan Wang) might be faster in aggregation, its proof size is significantly larger, making SwiftRange a strong contender where proof size and aggregation efficiency are balanced.
- Adapted Compression Protocol: A key technical innovation is the successful adaptation of the Adam Adel compression protocol (originally for linear settings) to a quadratic setting. This adaptation is fundamental to reducing the initial linear proof size of the core range protocol to the desired logarithmic size, significantly enhancing the overall efficiency and practicality of SwiftRange.
Technical Deep Dive
▶ Watch: SwiftRange's core equality and bit decomposition (5:00)
The technical foundation of SwiftRange is built upon a sophisticated combination of a novel range protocol and a series of recursive compression protocols, all operating within the discrete logarithm setting. The objective is to prove that a committed value x lies within a specified range [0, 2^N - 1] without revealing x, while maintaining a compact, logarithmic proof size.
The overall protocol is composed of two main parts: the New Range Protocol and the Compression Protocols. The initial range protocol, if uncompressed, would yield a linear proof size, which is impractical for many applications. The compression protocols are designed to recursively reduce this linear size to a desirable logarithmic size.
New Range Protocol: Bit Decomposition and Core Equality
SwiftRange employs a verifier-efficient variant of the bit decomposition approach. The fundamental idea is to represent the committed secret value x as a weighted sum of a binary vector B = (b_0, b_1, ..., b_{N-1}), where b_i are bits (0 or 1). That is, x = Σ b_i * 2^i. The range proof then effectively proves that each b_i is indeed a bit, and that x is correctly committed.
A significant optimization in SwiftRange's core equality, compared to Bulletproofs, is the use of only N+1 distinct generators, which is half the number typically used by Bulletproofs (2N+2). This reduction directly contributes to increased efficiency. The core equality, initially without considering zero-knowledge properties, is designed to verify the binary representation. It involves two main parts:
- Left Part: Rewrites
Gto the power of the weighted sum (G^x) into a product of appropriately weighted generators. Specifically, it transformsG^(Σ b_i 2^i)intoΠ (g_i)^(b_i 2^i), whereg_iare generators derived fromG. - Right Part: Imposes a series of binary constraints on the bit vector
B, ensuring that eachb_iis either 0 or 1.
To achieve the zero-knowledge property, the actual bit vector B is replaced by a masking vector Z. This Z vector is constructed in such a way that it statistically hides B while still allowing the verifier to confirm the binary constraints. The verification equation, after this substitution, includes a constant term. If this term correctly cancels out, the verifier is convinced that the masking vector Z indeed hides a valid bit vector B that constitutes the committed value x. The security of this step relies on the hardness of discrete logarithm relations between any two generators, which implies that the elements hidden by Z must indeed be binary.
Further facilitating the subsequent compression, a transformation is applied to obtain a composite generator H. This is achieved by merging generators whose exponent values are related to Z, streamlining the input for the compression protocols.
Compression Protocols: Adapting Adam Adel for Quadratic Settings
The key to reducing the proof size from linear to logarithmic lies in the compression protocols. SwiftRange adapts a compressed Sigma protocol for linear settings, originally presented by Adam Adel at Crypto 2021, to a quadratic setting. This adaptation is crucial because SwiftRange's core equality involves quadratic terms related to the bit vector Z.
Let's briefly review the original Adam Adel compression for linear settings:
Given a witness vector Z and a generator vector G satisfying the relation G^Z = W, the prover recursively reduces the dimension of G and Z until it reaches a dimension of 2. The "trick" involves computing a new generator vector G' by raising the left sub-generator vector to a challenge C. A drawback of this original scheme is that the group element W of the current recursion needs to be raised to the power of C and subsequently, W from previous recursions must consider the challenges of all subsequent recursions. This interdependency significantly increases computational overheads.
SwiftRange's adaptation for the quadratic setting addresses this limitation. The relation in the quadratic setting involves two generator vectors, H and G, and a witness vector Z, satisfying H^Z * G^(-Z^2) = W. The modifications are strategic:
- Recursive Dimension Reduction: The prover recursively reduces the dimension of the generator vectors and the witness vector
Z. However, unlike the linear protocol terminating at dimension 2, the quadratic setting's protocol terminates earlier at dimension 8. This is because each recursion in the quadratic setting involves four group elements instead of two, requiring a larger base case for efficient termination. - Decoupled Recursions: The most critical modification lies in how the new generators (
H'andG') are computed. Instead of raising the left sub-generator vector toC, SwiftRange raises the right sub-generator vector toC^-1andC^-2(whereCis the challenge). This ingenious trick ensures that in each recursion, the group elementWdoes not have exponents. This effectively decouples the recursions, meaning that the group elements from previous recursions no longer need to consider the challenges of subsequent recursions. This decoupling is the primary source of computational overhead savings, making the recursive compression significantly more efficient.
By combining the verifier-efficient bit decomposition with this optimized quadratic compression, SwiftRange achieves its superior performance characteristics, delivering a compact and efficient zero-knowledge range argument suitable for demanding cryptographic applications.
Demo / Proof of Concept
▶ Watch: Adapting compression protocols for quadratic setting (8:45)
The conference talk primarily focused on the theoretical construction, cryptographic properties, and experimental benchmarks of SwiftRange against existing state-of-the-art range proofs. While the presentation detailed the mathematical underpinnings and performance comparisons, it did not include a live software demonstration or a dedicated proof-of-concept walkthrough of SwiftRange in action. The results presented were based on comprehensive benchmarks conducted against Flash Proofs and Bulletproofs, showcasing the practical efficiency gains in terms of prover and verifier computation times and communication costs. The speaker encouraged attendees to refer to the full paper for complete technical details and experimental methodologies.
Defensive Implications
▶ Watch: SwiftRange experimental performance and efficiency (10:30)
SwiftRange's advancements in zero-knowledge range arguments have profound defensive implications for systems that rely on privacy-preserving mechanisms, particularly in the context of financial transactions and data integrity on decentralized platforms.
- Enhanced Confidentiality in Financial Transactions: The most direct implication is for confidential transactions on blockchains. By allowing transaction amounts to be hidden while cryptographically proving their non-negativity (and often, that they fall within acceptable limits), SwiftRange prevents malicious actors from "minting" new currency by transferring negative values. This maintains the integrity of the ledger and protects against inflation attacks, making the system more robust against financial fraud.
- Integrity for Privacy-Preserving Applications: Beyond financial systems, SwiftRange is applicable to a broader array of privacy-preserving applications. In scenarios like blackbox accumulation schemes, privacy-preserving cross-sensing, collaborative consumption, and smart IoT, users often provide committed values. The ability to attach a zero-knowledge range proof ensures that these committed values adhere to predefined constraints (e.g., age within a range, sensor readings within expected bounds, consumption limits) without revealing the exact values. This prevents malicious users from providing out-of-range or invalid inputs that could sabotage the execution or integrity of these applications.
- Efficiency for Resource-Constrained Environments: The improved verifier and prover efficiency, coupled with logarithmic proof sizes, makes SwiftRange particularly well-suited for resource-constrained environments. This includes mobile devices or IoT nodes that might act as verifiers or even provers. Faster verification times reduce latency in transaction processing and overall system overhead, contributing to a more responsive and scalable decentralized infrastructure.
- No Trusted Setup Reduces Risk: The fact that SwiftRange operates without a trusted setup is a critical defensive advantage. Schemes requiring a trusted setup introduce a significant security risk: if the setup parameters are compromised, the entire system's security can be undermined. Eliminating this requirement removes a complex and potentially vulnerable ceremony, simplifying deployment and enhancing the long-term security posture of systems utilizing SwiftRange.
- Drop-in Replacement for Existing Solutions: SwiftRange's design as a "drop-in replacement" for Bulletproofs means that developers can upgrade their existing confidential transaction implementations with minimal disruption, immediately benefiting from the improved efficiency. This ease of integration accelerates the adoption of stronger privacy and integrity guarantees across various decentralized applications.
In essence, SwiftRange empowers defenders to build more secure, private, and efficient decentralized systems by providing a cryptographic primitive that enforces value constraints without compromising user privacy or introducing complex setup dependencies.
Key Takeaways
- SwiftRange is a novel zero-knowledge range argument in the discrete logarithm setting, designed to prove a committed value lies within
[0, 2^N - 1]with a logarithmic proof size. - It operates without a trusted setup, eliminating a common point of vulnerability and complexity found in some other ZKP schemes.
- For 64-bit ranges, SwiftRange demonstrates twice the verifier efficiency and 1.4 times the prover efficiency compared to Bulletproofs, making it significantly faster for computation-critical scenarios.
- Communication costs are competitive, with only a 1.1 times increase over Bulletproofs, representing a favorable trade-off for the substantial efficiency gains.
- A key technical innovation is the adaptation of the Adam Adel compression protocol for quadratic settings, which effectively decouples recursive operations to save computational overheads and achieve logarithmic proof sizes.
- SwiftRange is a suitable drop-in replacement for blockchain-based confidential transactions and can be applied to a wide range of privacy-preserving applications like blackbox accumulation schemes, collaborative consumption, and smart IoT, ensuring data integrity without revealing sensitive values.
About the Speaker(s)
Nan Wang is a Post-doc Research Fellow at CSIRO, Australia's national science agency. He is the lead presenter of the SwiftRange work and has a notable background in cryptographic research, previously having been affiliated with the Australian National University. His expertise extends to other significant contributions in the field, as he is also recognized as the first author of Flash Proofs, a state-of-the-art range proof published in AsiaCrypt 2022.
Sid Chi-Kin Chau and DongXi Liu are co-authors on the SwiftRange paper. Part of the work was conducted while Nan Wang and Sid Chi-Kin Chau were at the Australian National University. Their collaborative efforts underscore a strong research focus on advancing cryptographic techniques for privacy and efficiency in decentralized systems.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
SwiftRange offers a genuinely novel zero-knowledge range argument, achieving superior prover and verifier efficiency over Bulletproofs without a trusted setup. Its clever adaptation of compression protocols for quadratic settings makes it a critical, high-impact primitive for confidential transactions and privacy-preserving systems.
Heather Calloway (CISO) — STRONG ACCEPT
SwiftRange presents a compelling advancement in zero-knowledge range proofs, offering significant efficiency gains and, critically, eliminating the need for a trusted setup. This directly enhances the integrity and privacy of critical financial and data systems, providing a robust primitive for architects building resilient decentralized platforms. It's a clear operational upgrade for those engaged in confidential transactions.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024