Paper 2026/1202

Morphic Accumulators and Applications: Optimal Range Proofs, Polynomial Commitments, and Ring Signatures

Dimitrios Papadopoulos, Hong Kong University of Science and Technology
Qiang Tang, The University of Sydney
Jiajun Xin, The University of Sydney
Abstract

Cryptographic accumulators based on groups of unknown order (GUO) provide constant-size set membership proofs. For security purposes, existing works require first encoding set elements via division-intractable (DI) hash functions, typically instantiated as random oracles that destroy any algebraic structure. This confines GUO-based accumulators to a purely set-membership role, making them "incompatible" with various existing cryptographic proof techniques over committed integers in the same groups as the GUO, such as constant-size proofs of exponentiation and modular exponent relations. We introduce the notion of morphic accumulators, which replaces the DI hash with a discrete logarithm encoding $H_g(x) = g^x$, mapping set elements to a group before accumulation. We prove, under a variant of the subset product assumption in the generic group model, that this encoding is inherently division intractable, achieving the same security guarantee as random-oracle DI hashes, while simultaneously being a group homomorphism: accumulated elements retain their group-algebraic relationships. This resolves a fundamental tension between compact representation and algebraic structure: the accumulator serves simultaneously as a binding commitment to a set and as a substrate for homomorphic computation over its elements. Morphic accumulators yield asymptotically optimal constructions across multiple domains: range proofs with $O(n)$ prover time, $O(1)$ proof size, $O(1)$ verification with transparent setups (the first scheme to simultaneously achieve these optimal bounds); polynomial commitments with $O(n)$ prover and $O(1)$ proof size, resolving the cubic bottleneck in prior constant-proof-size GUO-based schemes; and the first linkable ring signatures with $O(1)$ signature size, transparent setup, $O(n)$ offline signing and $O(1)$ online signing.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A major revision of an IACR publication in CRYPTO 2026
Keywords
Cryptographic accumulatorsRange proofsPolynomial commitmentsRing signatures
Contact author(s)
dipapado @ cse ust hk
qiang tang @ sydney edu au
jiajun xin @ sydney edu au
History
2026-06-10: approved
2026-06-08: received
See all versions
Short URL
https://ia.cr/2026/1202
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1202,
      author = {Dimitrios Papadopoulos and Qiang Tang and Jiajun Xin},
      title = {Morphic Accumulators and Applications: Optimal Range Proofs, Polynomial Commitments, and Ring Signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1202},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1202}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.