A Brief Survey of Two Recent Polynomial Commitment Schemes from Lattices
Abstract
A polynomial commitment scheme (PCS) enables a prover to commit to a polynomial and later prove the correctness of its evaluation without revealing the polynomial. Although discrete logarithm-based PCSs offer succinct proofs, they are not quantum-safe. Lattice-based PCSs provide post-quantum security and additive homomorphism, making them suitable for applications such as zero-knowledge proofs and secure multiparty computation. In this article, we review two recent lattice-based PCSs, Greyhound and HyperWolf, both relying on the Module-SIS assumption but differing in target polynomial classes and proof techniques. In particular, Greyhound achieves a smaller proof size O(log log N) through folding and LaBRADOR proofs, while HyperWolf supports univariate and multilinear polynomials with lower verifier cost O(log N) using hypercube evaluation.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.