Paper 2026/2106
Couplet: Multivariate Polynomial Commitments with Two-Group-Element Openings
Abstract
We present Couplet, a new pairing-based multivariate polynomial commitment scheme (PCS). Couplet is the first multivariate PCS whose opening proofs are solely two group elements. In addition, for the case of multilinear polynomials, Couplet is the first constant-proof PCS with a prover that requires only a sublinear number of group operations. We achieve those properties simultaneously at the expense of a quasilinear, polynomial-specific, one-time preprocessing phase, whose cost can be amortized over multiple subsequent openings. On BN254, our implementation opens multilinear polynomials with $20$ variables about $20\times$ faster than Mercury after preprocessing, breaking even in total prover time after roughly 100 openings. Our approach generalizes to batched evaluation proofs, yielding a constant-size proof for multiple evaluation points without using random oracles. Applications include verifying repeated inferences of a committed model as well as more efficient auditable authenticated dictionaries. Our main technique involves compressing Papamanthou--Shi--Tamassia (PST) evaluation proofs, giving a single commitment which encodes all $\log n$ quotient polynomials which are normally given out separately in a PST proof. In doing this, we reduce the verification to a univariate sumcheck problem, which we solve with techniques from Groth16 using a single additional group element. We prove extractability in the algebraic group model under a parameterized discrete-logarithm assumption. We give hiding variants and prove perfect zero-knowledge of the opening protocols. All opening protocols are noninteractive and require no random oracle.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Contact author(s)
-
weijie wang @ yale edu
tomescu alin @ gmail com
rex1fernando @ gmail com
charalampos papamanthou @ yale edu - History
- 2026-09-22: approved
- 2026-09-19: received
- See all versions
- Short URL
- https://ia.cr/2026/2106
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2106,
author = {Weijie Wang and Alin Tomescu and Rex Fernando and Charalampos Papamanthou},
title = {Couplet: Multivariate Polynomial Commitments with Two-Group-Element Openings},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2106},
year = {2026},
url = {https://eprint.iacr.org/2026/2106}
}