Paper 2026/1750

Threshold Lattice-Based Zero-Knowledge Proofs

Scott Griffy, Brown University
Victor Youdom Kemmoe, Brown University
Ngoc Khanh Nguyen, King's College London
Tjerand Silde, Norwegian University of Science and Technology
Abstract

Lattice-based zero-knowledge proofs are now efficient enough for practical use, but in all known constructions a single prover holds the entire witness and is therefore a single point of failure. Thresholdizing them is understood only for three-round $\Sigma$-protocols, which certify shortness only $\textit{approximately}$. The $\textit{exact}$ statements needed by applications such as anonymous credentials require more rounds and rely on rejection sampling, and neither property survives thresholdization. We construct the first lattice-based threshold zero-knowledge proof systems for exact relations. The witness is Shamir-shared among $\mathtt{n}$ parties, any $\mathtt{t}$ of them can jointly produce a proof, and the proof has the same form as a single-prover proof, only a factor $\sqrt{\mathtt{t}}$ larger, with verification unchanged. We thresholdize the product proof of Attema, Lyubashevsky, and Seiler (CRYPTO 2020) and the exact proof of Esgin, Nguyen, and Seiler (ASIACRYPT 2020), making both rejection-free using Hint-MLWE and evaluating them over threshold homomorphic encryption. We define threshold commit-and-prove protocols with the corresponding zero-knowledge and simulation-extractability notions, and prove our constructions secure against passive adversaries that statically corrupt at most $\mathtt{t}-1$ parties. Of independent interest, we show that the Fiat--Shamir transforms of both proof systems are simulation-extractable in the random oracle model, and that MLWE remains hard when secrets are drawn from the subring fixed by a ring automorphism.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
LatticesThreshold cryptographyZero-knowledge proofs
Contact author(s)
scottgriffy @ gmail com
vyoudomk @ cs brown edu
ngoc_khanh nguyen @ kcl ac uk
tjerand silde @ ntnu no
History
2026-08-22: approved
2026-08-20: received
See all versions
Short URL
https://ia.cr/2026/1750
License
Creative Commons Attribution-ShareAlike
CC BY-SA

BibTeX

@misc{cryptoeprint:2026/1750,
      author = {Scott Griffy and Victor Youdom Kemmoe and Ngoc Khanh Nguyen and Tjerand Silde},
      title = {Threshold Lattice-Based Zero-Knowledge Proofs},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1750},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1750}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.