Paper 2026/1750
Threshold Lattice-Based Zero-Knowledge Proofs
Abstract
Lattice-based zero-knowledge proofs are now efficient enough for practical use, but in all known constructions a single prover holds the entire witness and is therefore a single point of failure. Thresholdizing them is understood only for three-round $\Sigma$-protocols, which certify shortness only $\textit{approximately}$. The $\textit{exact}$ statements needed by applications such as anonymous credentials require more rounds and rely on rejection sampling, and neither property survives thresholdization. We construct the first lattice-based threshold zero-knowledge proof systems for exact relations. The witness is Shamir-shared among $\mathtt{n}$ parties, any $\mathtt{t}$ of them can jointly produce a proof, and the proof has the same form as a single-prover proof, only a factor $\sqrt{\mathtt{t}}$ larger, with verification unchanged. We thresholdize the product proof of Attema, Lyubashevsky, and Seiler (CRYPTO 2020) and the exact proof of Esgin, Nguyen, and Seiler (ASIACRYPT 2020), making both rejection-free using Hint-MLWE and evaluating them over threshold homomorphic encryption. We define threshold commit-and-prove protocols with the corresponding zero-knowledge and simulation-extractability notions, and prove our constructions secure against passive adversaries that statically corrupt at most $\mathtt{t}-1$ parties. Of independent interest, we show that the Fiat--Shamir transforms of both proof systems are simulation-extractable in the random oracle model, and that MLWE remains hard when secrets are drawn from the subring fixed by a ring automorphism.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- LatticesThreshold cryptographyZero-knowledge proofs
- Contact author(s)
-
scottgriffy @ gmail com
vyoudomk @ cs brown edu
ngoc_khanh nguyen @ kcl ac uk
tjerand silde @ ntnu no - History
- 2026-08-22: approved
- 2026-08-20: received
- See all versions
- Short URL
- https://ia.cr/2026/1750
- License
-
CC BY-SA
BibTeX
@misc{cryptoeprint:2026/1750,
author = {Scott Griffy and Victor Youdom Kemmoe and Ngoc Khanh Nguyen and Tjerand Silde},
title = {Threshold Lattice-Based Zero-Knowledge Proofs},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1750},
year = {2026},
url = {https://eprint.iacr.org/2026/1750}
}