Paper 2026/033
Faster Short Pairing-Based NIZK Proofs for Ring LWE Ciphertexts
Abstract
Several works explored the use of discrete-logarithm-based zero-knowledge proof systems in order to prove the validity of Ring LWE ciphertexts and/or FHE ciphertexts. A technique suggested by del Pino {\it et al.} (PKC'19) notably enables proofs of $1$KB for the task of proving the validity of NewHope ciphertext using a variant of BulletProofs. A recent work of Libert (PKC'24) described a pairing-based adaptation of del Pino {\it et al.}'s approach with proofs of $3$ or $6$ group elements. While space-efficient, the latter solution is rather expensive in terms of proving time. In this work, we provide new NIZK arguments for the Ring-LWE-based public-key scheme proposed by Joye (CT-RSA'24), which is used in a variant of TFHE. The new schemes feature slightly longer proofs than in earlier pairing-based constructions with short proofs, but the prover is much faster. The number of exponentiations is reduced by a factor $\approx 7$ and the common reference string is compressed by a factor $\approx 9$ (and reduced to $1.5$MB for practically relevant parameters). We provide implementation results that confirm these estimations.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- NIZK proofsRing LWE and FHE ciphertexts
- Contact author(s)
-
olivier bernard @ zama ai
sarah elkazdadi @ gmail com
benoit libert @ zama ai
arthur meyre @ zama ai
jb orfila @ zama ai
Nicolas sarlin @ zama ai - History
- 2026-01-09: approved
- 2026-01-08: received
- See all versions
- Short URL
- https://ia.cr/2026/033
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/033,
author = {Olivier Bernard and Sarah Elkazdadi and Benoit Libert and Arthur Meyre and Jean-Baptiste Orfila and Nicolas Sarlin},
title = {Faster Short Pairing-Based {NIZK} Proofs for Ring {LWE} Ciphertexts},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/033},
year = {2026},
url = {https://eprint.iacr.org/2026/033}
}