Papers1 provider · 1 record
January 27, 2026· Cybersecurity
article
Open access

Proving multiplicative relations for lattice commitments in batch

Authors:Mengfan WangGuifang Huang *Dong FangLei Hu

Abstract

Abstract Lattice-based commitment schemes and their associated zero-knowledge proofs are essential building blocks for advanced lattice-based cryptographic protocols. In particular, proofs of algebraic relations among committed messages are widely used in privacy-preserving protocols such as range proofs. At CRYPTO 2020, Attema et al. proposed practical proofs for valid openings and multiplicative relations among committed values using the BDLOP commitment scheme. In their work, all commitments are generated using the same short randomness. In this paper, we consider a batch setting where commitments are generated using $$\ell$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>ℓ</mml:mi> </mml:math> independent random vectors and present a batch valid opening proof. Our construction generalizes the approach of Baum et al. by supporting a larger challenge set and removing the requirement for invertible challenge differences. As a result, the proof size scales logarithmically with $$\ell$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>ℓ</mml:mi> </mml:math> , rather than linearly. Furthermore, we introduce a product proof for committed messages with shared randomness across these $$\ell$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mi>ℓ</mml:mi> </mml:math> commitment groups. Compared to the naive approach of applying Attema’s product proof once and repeating the opening proof $$\ell -1$$ <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>ℓ</mml:mi> <mml:mo>-</mml:mo> <mml:mn>1</mml:mn> </mml:mrow> </mml:math> times, our method achieves significantly better communication efficiency.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.