Paper 2026/1977
Lattice-based Secret-Key Functional Encryption for Constant-Degree Polynomials
Abstract
We present a lattice-based construction of secret-key functional encryption (FE) for low-norm polynomials of any constant degree $d$, hence also for $\mathsf{NC}^{0}$ circuits. We rely on two core ingredients: 1. New trapdoor and preimage sampling algorithms for certain degree-$d$ tensor-structured matrices, used to generate functional secret keys. 2. A new $k$-LWE-style assumption where short preimages of non-zero images with respect to the above tensor-structured matrix are given as hints, under which we prove that our secret-key FE scheme is selectively secure (under unbounded collusion). To gain confidence in the new assumption, we prove that the standard LWE assumption implies the degree-$1$ case and cryptanalyse the $d > 1$ case. As a corollary, we obtain a new pathway to post-quantum secure indistinguishability obfuscation (iO), conditioned on the above new assumption, standard LWE, and the existence of polynomial-stretch pseudorandom generators in $\mathsf{NC}^{0}$. Along the way, we give a new, simple (public-key) FE scheme for linear functions with selective security under the standard LWE assumption.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- latticefunctional encryptionobfuscation
- Contact author(s)
-
russell lai @ aalto fi
Akin Uenal @ ist ac at
ivy woo @ aalto fi - History
- 2026-09-13: approved
- 2026-09-11: received
- See all versions
- Short URL
- https://ia.cr/2026/1977
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1977,
author = {Valerio Cini and Russell W. F. Lai and Akin Ünal and Ivy K. Y. Woo},
title = {Lattice-based Secret-Key Functional Encryption for Constant-Degree Polynomials},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1977},
year = {2026},
url = {https://eprint.iacr.org/2026/1977}
}