Paper 2026/1317

ProtogaLattice: Lattice-based Algebraic Folding

David Balbás, ETH Zurich
Anca Nitulescu, Input Output
Maxime Plançon, Input Output
Abstract

Folding schemes are gaining traction recently as they are suited to prove streaming computations with low memory footprint. In particular, there has been a growing interest in post-quantum folding schemes for more expressive relations, and with improved proof sizes. While the landscape is vast, every lattice-based construction, such as Latticefold+, (Super)Neo, and Cyclo, heavily rely on the sumcheck protocol. Sumcheck gives efficient proving times, but the verifier circuits become very large, partially because of the many random oracle invocations required. When folding sequential computations, this significantly inflates the recursive overhead, as the prover must run the verification at every iteration. We present ProtogaLattice, a new lattice-based folding scheme for general high-degree polynomial relations that drastically reduces the size of the verifier's circuits. Our folding backbone deviates from the sumcheck approach and uses algebraic techniques. Our contribution is twofold: i) a folding scheme that combines multiple instances of polynomial relations into accumulators for a bounded number of iterations, and ii) a bootstrapping protocol to reduce the norm of the witnesses underlying these accumulators, which can be used in complement to our bounded-depth folding scheme to unlock unlimited depth. A full iteration of ProtogaLattice for witnesses of length $2^{30}$ gives a 4$\times$ shorter proof size than the state-of-the-art, with only $8.13$ KB. Additionally, ProtogaLattice requires less random oracle evaluations and achieves a smaller verifier circuit than its sumcheck counterparts. Our techniques open new directions towards building efficient lattice-based proofs for expressive relations and that present small recursion overheads, challenging the established sumcheck-based approaches.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Lattice-based CryptographyFolding SchemesSuccinct Proof SystemsIVCPCDReductions of Knowledge
Contact author(s)
dbalbas @ ethz ch
anca nitulescu @ iohk io
maxime plancon @ iohk io
History
2026-09-18: revised
2026-06-25: received
See all versions
Short URL
https://ia.cr/2026/1317
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1317,
      author = {David Balbás and Anca Nitulescu and Maxime Plançon},
      title = {{ProtogaLattice}: Lattice-based Algebraic Folding},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1317},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1317}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.