Paper 2026/2398
Note on Extractability of PST Polynomial Commitment Scheme
Abstract
A recent work by Belohorec et al. (Crypto, 2025) shows that the well-known PST multivariate polynomial commitment scheme is black-box extractable under falsifiable assumptions. They show that a minimally modified (extended) PST is extractable under an assumption ARSDH($n$), and that the canonical PST is extractable under an assumption GARSDH($n$). Both of these assumptions are new and more specialized than the original ARSDH assumption proposed by Lipmaa et al. (Eurocrypt, 2024) to prove black-box extractability of the univariate KZG polynomial commitment. A natural question is whether these assumptions are actually stronger than the original ARSDH assumption. We answer this negatively: we show that both ARSDH($n$) and GARSDH($n$) are equivalent to the original ARSDH assumption. Secondly, we point out a gap in the proof that canonical PST is extractable under GARSDH($n$) assumption.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Published by the IACR in CIC 2026
- Keywords
- Polynomial commitment schemesFalsifiable assumptionsPST commitment schemeARSDH assumption
- Contact author(s)
-
jannosiim @ gmail com
iampritampal23 @ gmail com - History
- 2026-10-08: approved
- 2026-10-07: received
- See all versions
- Short URL
- https://ia.cr/2026/2398
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2398,
author = {Janno Siim and Pritam Pal},
title = {Note on Extractability of {PST} Polynomial Commitment Scheme},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2398},
year = {2026},
url = {https://eprint.iacr.org/2026/2398}
}