Paper 2025/719

SNARKs over Small Prime Fields without Extension Field Multiplication

Yuanju Wei, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China, School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China
Kaixuan Wang, Shanghai Jiao Tong University
Binwu Xiang, East China Normal University
Xinxuan Zhang, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China, School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China
Yi Deng, School of Cryptology, Xidian University, Xi’an, China
Xudong Zhu, Development and Strategy Department, China Mobile Yunnan Company
Hailong Wang, Digital Technologies, Ant Group
Li Lin, Digital Technologies, Ant Group
Lei Wang, Shanghai Jiao Tong University
Abstract

Sumcheck-based transparent SNARKs over small prime fields encounter a basic soundness bottleneck. When instantiated over $\mathbb{F}_p$, the round-by-round soundness error is $O(d/p)$, where $d$ is the degree parameter in the sumcheck instance. This is non-negligible for small $p$. A common remedy is to work over an extension field, which departs from native $\mathbb{F}_p$ arithmetic and requires implementing general $\mathbb{F}_{p^k}$ arithmetic, in particular multiplication. A natural alternative is to amplify soundness by parallel repetition. However, naive $k$-parallel repetition does not achieve a proportional $k$-fold increase in round-by-round soundness for multi-round sumcheck. In this work, we propose the \emph{packed sumcheck protocol}, which amplifies round-by-round soundness over $\mathbb{F}_p$ by combining repetition with folding, while avoiding extension field multiplication. The core idea is to couple $k$ independent instances within each round using random matrix challenges from the matrix ring $\mathbb{F}_p^{k \times k}$, so that every folding step mixes all $k$ coordinates. For degree-$d$ claims, we obtain round-by-round soundness error $\bigl(((2k-1)d)/p\bigr)^k$. The prover uses $O((kd^2+k^2d)N)$ base field multiplications and the verifier uses $O(k^2 d\mu)$ base field operations, with communication $O(k d\mu)$ base field elements, where $N=2^\mu$ is the size of the $\mu$-dimensional Boolean hypercube. To compile the packed sumcheck protocol into SNARKs, we introduce \emph{matrix-weighted multilinear extension (MW-MLE) commitments}, capturing the matrix-weighted linear forms induced by packed sumcheck, and instantiate them by adapting Brakedown (CRYPTO~2023) and Basefold (CRYPTO~2024). The resulting components are integrated into the HyperPlonk (EUROCRYPT~2023) framework by replacing its sumcheck and polynomial commitment modules with packed variants, obtaining transparent SNARK instantiations without extension field multiplication in the Random Oracle Model. We further apply our packed techniques to construct a TFHE-friendly SNARK; we evaluate its prover performance for a single bootstrapping, obtaining a prover time of 2.2 seconds.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A minor revision of an IACR publication in ASIACRYPT 2026
Keywords
SNARKssumchecksmall prime fields.
Contact author(s)
weiyuanju @ iie ac cn
wangkaixuan @ sjtu edu cn
bwxiang @ sc ecnu edu cn
zhangxinxuan @ iie ac cn
ydeng cas @ gmail com
zhuxudong @ yn chinamobile com
whl383799 @ antgroup com
felix ll @ alibaba-inc com
wanglei_hb @ sjtu edu cn
History
2026-09-14: last of 4 revisions
2025-04-22: received
See all versions
Short URL
https://ia.cr/2025/719
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/719,
      author = {Yuanju Wei and Kaixuan Wang and Binwu Xiang and Xinxuan Zhang and Yi Deng and Xudong Zhu and Hailong Wang and Li Lin and Lei Wang},
      title = {{SNARKs} over Small Prime Fields without Extension Field Multiplication},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/719},
      year = {2025},
      url = {https://eprint.iacr.org/2025/719}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.