Lune

CCS2026顶会

Tempora-Fusion: Time-Lock Puzzle with Efficient Verifiable Homomorphic Linear Combination

Aydin Abadi, Jakub K. Szeląg

2026年份

摘要

Homomorphic time-lock puzzles (TLPs) let parties lock sensitive values now so that they become recoverable only after a designated delay, without requiring the owners to remain available at release time. In many settings, however, an authorized aggregate over several hidden inputs may need to be released and publicly verified before the underlying inputs themselves are opened. Existing homomorphic TLPs support computation over puzzles; however, these TLPs do not offer an efficient mechanism for publicly verifying that a released result is the prescribed linear combination of the intended puzzles. Homomorphic timed commitments provide publicly recomputable aggregation and efficiently verifiable forced opening, but existing constructions place the commitments and their aggregate under a common delay. Thus, they cannot give the aggregate a shorter, independently chosen release time while the constituent values remain locked under their respective delays.

We present Tempora-Fusion, the first homomorphic TLP scheme with efficient public verification of both individual puzzle solutions and homomorphic linear combinations. Tempora-Fusion lets clients generate puzzles independently, later authorize a linear combination with its own release time, and enables any party to verify the released result without trusted setup or costly asymmetric-key proof systems. Technically, our construction maps independently generated RSA-based puzzles into a common finite field, uses oblivious linear evaluation to refresh blinding factors during evaluation, and embeds a hidden verification structure by encoding messages as polynomials with committed secret roots. We formalize verifiable homomorphic linear-combination TLPs, prove privacy and solution validity in this model, and capture the setting in which the evaluation result may be released before the underlying client puzzles are opened. Our prototype implementation shows that verifying an evaluated result takes less than 3 ms.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper4

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖