Paper 2026/2398

Note on Extractability of PST Polynomial Commitment Scheme

Janno Siim, University of Tartu
Pritam Pal, University of Tartu
Abstract

A recent work by Belohorec et al. (Crypto, 2025) shows that the well-known PST multivariate polynomial commitment scheme is black-box extractable under falsifiable assumptions. They show that a minimally modified (extended) PST is extractable under an assumption ARSDH($n$), and that the canonical PST is extractable under an assumption GARSDH($n$). Both of these assumptions are new and more specialized than the original ARSDH assumption proposed by Lipmaa et al. (Eurocrypt, 2024) to prove black-box extractability of the univariate KZG polynomial commitment. A natural question is whether these assumptions are actually stronger than the original ARSDH assumption. We answer this negatively: we show that both ARSDH($n$) and GARSDH($n$) are equivalent to the original ARSDH assumption. Secondly, we point out a gap in the proof that canonical PST is extractable under GARSDH($n$) assumption.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published by the IACR in CIC 2026
Keywords
Polynomial commitment schemesFalsifiable assumptionsPST commitment schemeARSDH assumption
Contact author(s)
jannosiim @ gmail com
iampritampal23 @ gmail com
History
2026-10-08: approved
2026-10-07: received
See all versions
Short URL
https://ia.cr/2026/2398
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2398,
      author = {Janno Siim and Pritam Pal},
      title = {Note on Extractability of {PST} Polynomial Commitment Scheme},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2398},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2398}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.