Paper 2026/1864

Subring VOLE over Galois Rings with Applications to ZK over $\mathbb{Z}_{p^k}$

Ignacio Cascudo, IMDEA Software
Xiang Liu, IMDEA Software, Universidad Politécnica de Madrid
Abstract

Vector oblivious linear evaluation (VOLE) is a type of correlation that is widely used in multiparty computation (MPC) and zero-knowledge (ZK) proofs. Recently, the generation of VOLE correlation has become very efficient due to the pseudorandom correlation generator (PCGs) paradigm (Boyle et al. CCS 2018) and SoftSpokenOT (Roy Crypto 2022). This has driven a line of research on VOLE-based ZK, which enjoys linear prover time, low memory cost and post-quantum security. However, most existing works build VOLE and VOLE-based ZK over finite fields, whereas the constructions over integer rings are less satisfactory, especially in terms of communication and public verifiability. In this work, we address some of these problems using a newly introduced primitive called subring VOLE (srVOLE), which is a generalization of subfield VOLE to Galois rings. Specifically, (1) We propose two maliciously secure srVOLE protocols. One is a PCG-like protocol that achieves extremely low amortized communication. The other is a SoftSpoken-like protocol, which is compatible with the VOLE-in-the-head (VOLEitH) technique and thus can be used to construct publicly verifiable VOLE-based ZK. (2) We find that the VOLE correlation over $\mathbb{Z}_{2^k}$ used in Moz$\mathbb{Z}_{2^k}$arella (Baum et al. Crypto 2022) is a special case of our srVOLE. Therefore, based on our construction, their designated-verifier ZK protocol can be made publicly verifiable. (3) We adapt the QuickSilver (Yang et al. CCS 2021) protocols to any Galois ring and compare with existing VOLE-based ZK protocols over rings. For circuit satisfiability, our protocol only communicates 1 subring element per multiplication gate, reducing the communication by more than half. For polynomial satisfiability, our protocol supports arbitrary low-degree relations, overcoming the restrictions of existing work on degree-2 relations.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A major revision of an IACR publication in ASIACRYPT 2026
Keywords
Vector Oblivious Linear EvaluationZero-Knowledge ProofPseudorandom Correlation GeneratorPublic Verifiability
Contact author(s)
ignacio cascudo @ imdea org
xiang liu @ imdea org
History
2026-09-06: approved
2026-09-02: received
See all versions
Short URL
https://ia.cr/2026/1864
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1864,
      author = {Ignacio Cascudo and Xiang Liu},
      title = {Subring {VOLE} over Galois Rings with Applications to {ZK} over $\mathbb{Z}_{p^k}$},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1864},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1864}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.