Paper 2025/1187

Ligerito: A Small and Concretely Fast Polynomial Commitment Scheme

Andrija Novakovic, Bain Capital Crypto
Guillermo Angeris, Bain Capital Crypto
Abstract

In this note we present Ligerito, a small and practically fast polynomial commitment and inner product scheme. For the case of univariate and multilinear polynomial evaluations, the scheme has a proof size of $\sim \log(N)^2/\log\log(N)$ up to constants and for a large enough field, where $N$ is the size of the input. Ligerito is also fast on consumer hardware: when run on an M1 MacBook Pro for a polynomial with $2^{24}$ coefficients over a 32-bit binary field, our Julia prover implementation has a proving time of 1.3 seconds and a proof size of 255 KiB. Ligerito is also relatively flexible: any linear code for which the rows of the generator matrix can be efficiently evaluated can be used. Such codes include Reed–Solomon codes, Reed–Muller codes, among others. This, in turn, allows for a high degree of flexibility on the choice of field and can likely give further efficiency gains in specific applications.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
polynomial commitment schemeinner product schemeligeroproximityerror correcting codesrandom oracle model
Contact author(s)
anovakovic @ baincapital com
gangeris @ baincapital com
History
2025-06-27: approved
2025-06-24: received
See all versions
Short URL
https://ia.cr/2025/1187
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1187,
      author = {Andrija Novakovic and Guillermo Angeris},
      title = {Ligerito: A Small and Concretely Fast Polynomial Commitment Scheme},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1187},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1187}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.