Paper 2026/2067
Maltese: Succinct Polynomial Commitment from Lattices
Abstract
Succinct polynomial commitment schemes are a key building block in succinct non-interactive arguments of knowledge (SNARKs). Existing succinct lattice-based polynomial commitment schemes take a "split-and-fold" strategy making use of homomorphism to compress proof size to $O(\text{polylog} N)$ for polynomials of size $N$. Prior works either (1) incur superlogarithmic verifier work (e.g., $O(\sqrt{N})$), (2) incur concretely large proof sizes and verifier work (e.g., hundreds of MB), or (3) rely on non-standard lattice assumptions. We proprose a new succinct polynomial commitment scheme Maltese that operates over a Merkle tree commitment of the lattice-based Ajtai hash function. We employ a folding strategy and propose new sum-check-based reductions for managing norm growth of the tree commitment over folding rounds. Maltese is secure under the standard Module-SIS assumption and produces opening proofs of $335$KB for multilinear polynomials of size $N=2^{30}$; proofs are around $300\times$ smaller than prior work with polylogarithmic verifier complexity but between $2$-$6\times$ larger than prior work with larger verifier complexity or stronger structured assumptions.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published by the IACR in ASIACRYPT 2026
- Keywords
- latticespolynomial commitment schemeSNARKsinteractive reductions
- Contact author(s)
-
katch @ cs washington edu
wilsonnguyen @ microsoft com
nirvan tyagi @ gmail com - History
- 2026-09-19: approved
- 2026-09-17: received
- See all versions
- Short URL
- https://ia.cr/2026/2067
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2067,
author = {Katarina Cheng and Wilson Nguyen and Nirvan Tyagi},
title = {Maltese: Succinct Polynomial Commitment from Lattices},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2067},
year = {2026},
url = {https://eprint.iacr.org/2026/2067}
}