Duty-Free Bits: Projectivizing Garbling Schemes
Nakul Khambhati, Anwesh Bhattacharya, David Heath
Abstract
Garbling schemes are powerful primitives that enable secure computation between a mutually untrusting garbler and evaluator. A projective garbling scheme is one that encodes the evaluator's input in a simple bit-by-bit manner. Projective schemes, such as the seminal scheme of Yao, are versatile, as they are naturally compatible with other simple tools, such as -out-of- oblivious transfer (OT). There exist garbling schemes that naturally operate over large finite fields, some of which require only efficient information-theoretic (IT) techniques. However, here the evaluator's input is encoded via an affine function over a large field, so these schemes are not naturally projective, reducing their versatility.
We provide a transformation that efficiently projectivizes such schemes. Consider an arithmetic garbling scheme where the evaluator's input consists of elements from a large prime field. Our symmetric-key-based garbling techniques give a mechanism to translate from Yao-style garbled labels to IT-style garbled labels at cost proportional to the input and output labels: crossing the border is duty-free!
We apply our technique to two problems. (1) Recent works show that projective garbling schemes solve a problem central to trust-minimized bridges for the Bitcoin blockchain. BABE (Garg et al., 2026) and Argo MAC (Eagen and Lai, 2026) give two different approaches. Both works implicitly construct an efficient IT garbling scheme, then use naive bit-decomposition to achieve projectivity. We construct drop-in replacements for both; we improve BABE's encoding size by , and Argo MAC's by . (2) Our technique implies a non-interactive reduction from vector oblivious linear evaluations (VOLEs) over to -out-of- OTs. To our knowledge, ours is the state-of-the-art Minicrypt (plus base OTs) protocol for large field VOLE secure against a malicious receiver. It costs only bits.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 336548fd-22b2-4ae0-b097-059d5200f832Cited by top-tier papers1
Ask how each one uses itRelated papers
- New Ways to Garble Arithmetic CircuitsMarshall Ball, Hanjun Li, Huijia Lin, Tianren LiuEUROCRYPT 2023 · 15 citations
- TinyLabels: How to Compress Garbled Circuit Input Labels, EfficientlyMarian Dietz, Hanjun Li, Huijia LinEUROCRYPT 2025
- A Unified Framework for Succinct Garbling from Homomorphic Secret SharingYuval Ishai, Hanjun Li, Huijia LinCRYPTO 2025 · 11 citations
- BABE: Verifying Proofs on Bitcoin Made 1000x CheaperSanjam Garg, Dimitris Kolonelos, Mikhail Sergeevitch, Srivatsan Sridhar et al.CCS 2026
- Actively Secure Arithmetic Computation and VOLE with Constant Computational OverheadBenny Applebaum, Niv KonstantiniEUROCRYPT 2023 · 10 citations
