Publicly Verifiable Zero-Knowledge and Post-Quantum Signatures from VOLE-in-the-Head
Carsten Baum, Lennart Braun, Cyprien Delpech de Saint Guilhem, Michael Klooß, Emmanuela Orsini, Lawrence Roy, Peter Scholl
Abstract
We present a new method for transforming zero-knowledge protocols in the designated verifier setting into public-coin protocols, which can be made non-interactive and publicly verifiable. Our transformation applies to a large class of ZK protocols based on oblivious transfer. In particular, we show that it can be applied to recent, fast protocols based on vector oblivious linear evaluation (VOLE), with a technique we call VOLE-in-the-head, upgrading these protocols to support public verifiability. Our resulting ZK protocols have linear proof size, and are simpler, smaller and faster than related approaches based on MPC-in-the-head. To build VOLE-in-the-head while supporting both binary circuits and large finite fields, we develop several new technical tools. One of these is a new proof of security for the SoftSpokenOT protocol (Crypto 2022), which generalizes it to produce certain types of VOLE correlations over large fields. Secondly, we present a new ZK protocol that is tailored to take advantage of this form of VOLE, which leads to a publicly verifiable VOLE-in-the-head protocol with only 2x more communication than the best, designated-verifier VOLE-based protocols. We analyze the soundness of our approach when made non-interactive using the Fiat-Shamir transform, using round-by-round soundness. As an application of the resulting NIZK, we present , a post-quantum signature scheme based on AES. FAEST is the first AES-based signature scheme to be smaller than SPHINCS+, with signature sizes between 5.6 and 6.6kB at the 128-bit security level. Compared with the smallest version of SPHINCS+ (7.9kB), FAEST verification is slower, but the signing times are between 8x and 40x faster.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2c6d3e33-c8de-4757-a9f3-e1f87950918cCited by top-tier papers9
- Concretely Efficient Blind Signatures Based on VOLE-in-the-Head Proofs and the MAYO TrapdoorCarsten Baum, Marvin Beckmann, Ward Beullens, Shibam Mukherjee et al.USENIX Security 2026 · 1 citation
- ACTS: Attestations of Contents in TLS SessionsPierpaolo Della Monica, Ivan Visconti, Andrea Vitaletti, Marco ZecchiniNDSS 2026 · 1 citation
- Phecda: Post-Quantum Transparent zkSNARKs from Improved Polynomial Commitment and VOLE-in-the-Head with Application in Publicly Verifiable AESChangchang Ding, Yan HuangS&P 2025
- Post-quantum Public-Key Pseudorandom Correlation Functions for OTShweta Agrawal, Kaartik Bhushan, Geoffroy Couteau, Mahshid RiahiniaCRYPTO 2026
- ZHE: Efficient Zero-Knowledge Proofs for HE EvaluationsZhelei Zhou, Yun Li, Yuchen Wang, Zhaomin Yang et al.S&P 2025
Builds on15
- Ligero: Lightweight Sublinear Arguments Without a Trusted SetupScott Ames, Carmit Hazay, Yuval Ishai, Muthuramakrishnan VenkitasubramaniamCCS 2017 · 338 citations
- Post-Quantum Zero-Knowledge and Signatures from Symmetric-Key PrimitivesMelissa Chase, David Derler, Steven Goldfeder, Claudio Orlandi et al.CCS 2017 · 316 citations
- Improved Non-Interactive Zero Knowledge with Applications to Post-Quantum SignaturesJonathan Katz, Vladimir Kolesnikov, Xiao WangCCS 2018 · 257 citations
- Efficient Two-Round OT Extension and Silent Non-Interactive Secure ComputationElette Boyle, Geoffroy Couteau, Niv Gilboa, Yuval Ishai et al.CCS 2019 · 238 citations
- Compressing Vector OLEElette Boyle, Geoffroy Couteau, Niv Gilboa, Yuval IshaiCCS 2018 · 220 citations
Related papers
- Shorter, Tighter, FAESTer: Optimizations and Improved (QROM) Analysis for VOLE-in-the-Head SignaturesCarsten Baum, Ward Beullens, Lennart Braun, Cyprien Delpech de Saint Guilhem et al.CRYPTO 2025 · 2 citations
- Shorter VOLE-in-the-Head-based Signatures from Vector Semi-CommitmentSeongkwang Kim, Byeonghak Lee, Mincheol SonCCS 2026 · 1 citation
- Improving Line-Point Zero Knowledge: Two Multiplications for the Price of OneSamuel Dittmer, Yuval Ishai, Steve Lu, Rafail OstrovskyCCS 2022 · 30 citations
- A New Simple Technique to Bootstrap Various Lattice Zero-Knowledge Proofs to QROM Secure NIZKsShuichi KatsumataCRYPTO 2021 · 29 citations
- Thresholdizing Standardized FALCON SignaturesRadhika Garg, Daniel Escudero, Antigoni Polychroniadou, Akira Takahashi et al.CCS 2026
