Paper 2026/1317
ProtogaLattice: Lattice-based Algebraic Folding
Abstract
Folding schemes are gaining traction recently as they are suited to prove streaming computations with low memory footprint. In particular, there has been a growing interest in post-quantum folding schemes for more expressive relations, and with improved proof sizes. While the landscape is vast, every lattice-based construction, such as Latticefold+, (Super)Neo, and Cyclo, heavily rely on the sumcheck protocol. Sumcheck gives efficient proving times, but the verifier circuits become very large, partially because of the many random oracle invocations required. When folding sequential computations, this significantly inflates the recursive overhead, as the prover must run the verification at every iteration. We present ProtogaLattice, a new lattice-based folding scheme for general high-degree polynomial relations that drastically reduces the size of the verifier's circuits. Our folding backbone deviates from the sumcheck approach and uses algebraic techniques. Our contribution is twofold: i) a folding scheme that combines multiple instances of polynomial relations into accumulators for a bounded number of iterations, and ii) a bootstrapping protocol to reduce the norm of the witnesses underlying these accumulators, which can be used in complement to our bounded-depth folding scheme to unlock unlimited depth. A full iteration of ProtogaLattice for witnesses of length $2^{30}$ gives a 4$\times$ shorter proof size than the state-of-the-art, with only $8.13$ KB. Additionally, ProtogaLattice requires less random oracle evaluations and achieves a smaller verifier circuit than its sumcheck counterparts. Our techniques open new directions towards building efficient lattice-based proofs for expressive relations and that present small recursion overheads, challenging the established sumcheck-based approaches.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- Lattice-based CryptographyFolding SchemesSuccinct Proof SystemsIVCPCDReductions of Knowledge
- Contact author(s)
-
dbalbas @ ethz ch
anca nitulescu @ iohk io
maxime plancon @ iohk io - History
- 2026-09-18: revised
- 2026-06-25: received
- See all versions
- Short URL
- https://ia.cr/2026/1317
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1317,
author = {David Balbás and Anca Nitulescu and Maxime Plançon},
title = {{ProtogaLattice}: Lattice-based Algebraic Folding},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1317},
year = {2026},
url = {https://eprint.iacr.org/2026/1317}
}