The increasing usage of Zero-knowledge proof protocols has raised the need for cryptographic primitives that are efficient in that setting, called Arithmetization-oriented primitives. The security of such permutations is commonly evaluated with the CICO- problem. The best known CICO- attack against ZK-Friendly permutations over based on -inversions exploits resultants (ASIACRYPT 2024, CRYPTO 2025). It starts from one input variable and i
Resultants Meet Resultant: Improving CICO-1 and CICO-2 Attacks on ZK-Friendly Permutations
Vincent Neiger
