Paper 2026/033

Faster Short Pairing-Based NIZK Proofs for Ring LWE Ciphertexts

Olivier Bernard, Zama
Sarah Elkazdadi, Zama
Benoit Libert, Zama
Arthur Meyre, Zama
Jean-Baptiste Orfila, Zama
Nicolas Sarlin, Zama
Abstract

Several works explored the use of discrete-logarithm-based zero-knowledge proof systems in order to prove the validity of Ring LWE ciphertexts and/or FHE ciphertexts. A technique suggested by del Pino {\it et al.} (PKC'19) notably enables proofs of $1$KB for the task of proving the validity of NewHope ciphertext using a variant of BulletProofs. A recent work of Libert (PKC'24) described a pairing-based adaptation of del Pino {\it et al.}'s approach with proofs of $3$ or $6$ group elements. While space-efficient, the latter solution is rather expensive in terms of proving time. In this work, we provide new NIZK arguments for the Ring-LWE-based public-key scheme proposed by Joye (CT-RSA'24), which is used in a variant of TFHE. The new schemes feature slightly longer proofs than in earlier pairing-based constructions with short proofs, but the prover is much faster. The number of exponentiations is reduced by a factor $\approx 7$ and the common reference string is compressed by a factor $\approx 9$ (and reduced to $1.5$MB for practically relevant parameters). We provide implementation results that confirm these estimations.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
NIZK proofsRing LWE and FHE ciphertexts
Contact author(s)
olivier bernard @ zama ai
sarah elkazdadi @ gmail com
benoit libert @ zama ai
arthur meyre @ zama ai
jb orfila @ zama ai
Nicolas sarlin @ zama ai
History
2026-01-09: approved
2026-01-08: received
See all versions
Short URL
https://ia.cr/2026/033
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/033,
      author = {Olivier Bernard and Sarah Elkazdadi and Benoit Libert and Arthur Meyre and Jean-Baptiste Orfila and Nicolas Sarlin},
      title = {Faster Short Pairing-Based {NIZK} Proofs for Ring {LWE} Ciphertexts},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/033},
      year = {2026},
      url = {https://eprint.iacr.org/2026/033}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.