Cyclo: Lightweight Lattice-Based Folding via Partial Range Checks
Albert Garreta, Helger Lipmaa, Urmas Luhaäär, Michal Osadnik
Abstract
Folding is a powerful technique for constructing efficient succinct proof systems, especially for computations that are expressed in a streaming fashion. In this work, we present Cyclo, a new lattice-based folding protocol that improves upon LatticeFold+ [Boneh and Chen '25] in multiple dimensions and which incorporates, among others, the pay-per-bit techniques from Neo when folding constraints expressed over a field [Nguyen and Setty '25]. Cyclo proposes a new framework for building lattice-based folding schemes that eliminates the need for norm checks on the accumulator by adopting an amortized norm-refreshing design, ensuring that the witness norm grows additively per round within a (generously) bounded number of folds. This design simplifies the protocol and reduces prover overhead. In particular, Cyclo only performs range checks on the input non-accumulated witness, and when applied to fold constraints over , it does not decompose any witnesses into low-norm chunks within the folding protocol itself. Cyclo, supporting a complete family of cyclotomic rings, combines two simple building blocks: an extension commitment that reduces the norm of the witness by decomposing it and recommitting, and an range test via a sum-check protocol. We demonstrate, by proving communication and runtime estimates, that the construction results in an efficient and proof-size-friendly folding scheme. We also establish an algebraic connection between and using the polynomial evaluation map, enabling efficient reduction from R1CS/CCS over to a linear relation over , providing a new and simpler formulation of the techniques in [Nguyen and Setty '25]. In practical settings, Cyclo achieves succinct proof sizes on the order of KB, improving by an order of magnitude over LatticeFold+. Our efficiency benchmarks indicate that our protocol also outperforms LatticeFold+ in practice.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 98d61d1a-182e-481a-abbe-f6f5f15f5842Cited by top-tier papers1
Ask how each one uses itRelated papers
- LatticeFold+: Faster, Simpler, Shorter Lattice-Based Folding for Succinct Proof SystemsDan Boneh, Binyi ChenCRYPTO 2025 · 16 citations
- Neo and SuperNeo: Post-quantum Folding with Pay-per-Bit Costs over Small FieldsWilson Nguyen, Srinath SettyCRYPTO 2026 · 1 citation
- NeutronNova: Group-Based Folding Done RightAbhiram Kothapalli, Srinath SettyCRYPTO 2026
- BaseFold: Efficient Field-Agnostic Polynomial Commitment Schemes from Foldable CodesHadas Zeilberger, Binyi Chen, Ben FischCRYPTO 2024 · 38 citations
- Khatam: Proximity Gaps for Multilinear Evaluation for all Linear CodesHadas ZeilbergerCRYPTO 2026
