A Unified Framework for Succinct Garbling from Homomorphic Secret Sharing
Yuval Ishai, Hanjun Li, Huijia Lin
Abstract
A major challenge in cryptography is the construction of succinct garbling schemes that have asymptotically smaller size than Yao’s garbled circuit construction. We present a new framework for succinct garbling that replaces the heavy machinery of most previous constructions by lighter-weight homomorphic secret sharing techniques.
Concretely, we achieve 1-bit-per-gate (amortized) garbling size for Boolean circuits under circular variants of standard assumptions in composite-order or prime-order groups, as well as a lattice-based instantiation. We further extend these ideas to layered circuits, improving the per-gate cost below 1 bit, and to arithmetic circuits, eliminating the typical Ω(λ)-factor overhead for garbling mod-p computations. Our constructions also feature “leveled” variants that remove circular-security requirements at the cost of adding a depth-dependent term to the garbling size.
Our framework significantly extends a recent technique of Liu, Wang, Yang, and Yu (Eurocrypt 2025) for lattice-based succinct garbling, and opens new avenues toward practical succinct garbling. For moderately large circuits with a few million gates, our garbled circuits can be two orders of magnitude smaller than Yao-style garbling. While our garbling and evaluation algorithms are much slower, they are still practically feasible, unlike previous fully succinct garbling schemes that rely on expensive tools such as iO or a non-black-box combination of FHE and ABE. This trade-off can make our framework appealing when a garbled circuit is used as a functional ciphertext that is broadcast or stored in multiple locations (e.g., on a blockchain), in which case communication and storage may dominate computational cost.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers2
- Breaking the 1/λ-Rate Barrier for Arithmetic GarblingGeoffroy Couteau, Carmit Hazay, Aditya Hegde, Naman KumarEUROCRYPT 2025 · 4 citations
- Post-quantum Public-Key Pseudorandom Correlation Functions for OTShweta Agrawal, Kaartik Bhushan, Geoffroy Couteau, Mahshid RiahiniaCRYPTO 2026
Related papers
- Succinct Garbled Circuits with Low-Depth Garbling AlgorithmsHanjun Li, Huijia Lin, George LuEUROCRYPT 2026 · 2 citations
- ømega (1/λ )-Rate Boolean Garbling Scheme from Generic GroupsGeoffroy Couteau, Carmit Hazay, Aditya Hegde, Naman KumarCRYPTO 2025 · 2 citations
- Silent Circuit Relinearisation: Sublinear-Size (Boolean and Arithmetic) Garbled Circuits from DCRPierre Meyer, Claudio Orlandi, Lawrence Roy, Peter SchollCRYPTO 2025 · 13 citations
- New Ways to Garble Arithmetic CircuitsMarshall Ball, Hanjun Li, Huijia Lin, Tianren LiuEUROCRYPT 2023 · 15 citations
- Efficient Mixed Garbling from Homomorphic Secret Sharing and GGM-TreeJian Guo, Wenjie NanEUROCRYPT 2025 · 1 citation
