{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T01:15:17Z","timestamp":1779326117185,"version":"3.51.4"},"publisher-location":"Cham","reference-count":65,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032019066","type":"print"},{"value":"9783032019073","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-032-01907-3_11","type":"book-chapter","created":{"date-parts":[[2025,8,16]],"date-time":"2025-08-16T22:27:40Z","timestamp":1755383260000},"page":"327-361","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["LatticeFold+: Faster, Simpler, Shorter Lattice-Based Folding for\u00a0Succinct Proof Systems"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0820-0421","authenticated-orcid":false,"given":"Dan","family":"Boneh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0835-9678","authenticated-orcid":false,"given":"Binyi","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,8,17]]},"reference":[{"key":"11_CR1","doi-asserted-by":"crossref","unstructured":"Ajtai, M.: Generating hard instances of lattice problems (extended abstract). In: 28th ACM STOC, pp. 99\u2013108. ACM Press (1996)","DOI":"10.1145\/237814.237838"},{"key":"11_CR2","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"102","DOI":"10.1007\/978-3-031-15979-4_4","volume-title":"CRYPTO 2022, Part II","author":"MR Albrecht","year":"2022","unstructured":"Albrecht, M.R., Cini, V., Lai, R.W.F., Malavolta, G., Thyagarajan, S.A.K.: Lattice-based SNARKs: publicly verifiable, preprocessing, and recursively composable - (extended abstract). In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO 2022, Part II. LNCS, vol. 13508, pp. 102\u2013132. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-15979-4_4"},{"key":"11_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"519","DOI":"10.1007\/978-3-030-84245-1_18","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"MR Albrecht","year":"2021","unstructured":"Albrecht, M.R., Lai, R.W.F.: Subtractive sets over cyclotomic rings. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021, Part II. LNCS, vol. 12826, pp. 519\u2013548. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84245-1_18"},{"key":"11_CR4","doi-asserted-by":"crossref","unstructured":"Ames, S., Hazay, C., Ishai, Y., Venkitasubramaniam, M.: Ligero: lightweight sublinear arguments without a trusted setup. In: Thuraisingham, B.M., Evans, D., Malkin, T., Xu, D. (eds.) ACM CCS 2017, pp. 2087\u20132104. ACM Press (2017)","DOI":"10.1145\/3133956.3134104"},{"key":"11_CR5","unstructured":"Arun, A., Setty, S.: Nebula: efficient read-write memory and switchboard circuits for folding schemes. Cryptology ePrint Archive, Paper 2024\/1605 (2024)"},{"key":"11_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"549","DOI":"10.1007\/978-3-030-84245-1_19","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"T Attema","year":"2021","unstructured":"Attema, T., Cramer, R., Kohl, L.: A compressed $$\\varSigma $$-protocol theory for\u00a0lattices. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021, Part II. LNCS, vol. 12826, pp. 549\u2013579. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84245-1_19"},{"key":"11_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"470","DOI":"10.1007\/978-3-030-56880-1_17","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"T Attema","year":"2020","unstructured":"Attema, T., Lyubashevsky, V., Seiler, G.: Practical product proofs for lattice commitments. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020, Part II. LNCS, vol. 12171, pp. 470\u2013499. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56880-1_17"},{"key":"11_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"669","DOI":"10.1007\/978-3-319-96881-0_23","volume-title":"Advances in Cryptology \u2013 CRYPTO 2018","author":"C Baum","year":"2018","unstructured":"Baum, C., Bootle, J., Cerulli, A., del Pino, R., Groth, J., Lyubashevsky, V.: Sub-linear lattice-based zero-knowledge arguments for arithmetic circuits. In: Shacham, H., Boldyreva, A. (eds.) CRYPTO 2018, Part II. LNCS, vol. 10992, pp. 669\u2013699. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-96881-0_23"},{"key":"11_CR9","unstructured":"Ben-Sasson, E., Bentov, I., Horesh, Y., Riabzev, M.: Fast Reed-Solomon interactive oracle proofs of proximity. In: Chatzigiannakis, I., Kaklamanis, C., Marx, D., Sannella, D. (eds.) ICALP 2018. LIPIcs, vol. 107, pp. 14:1\u201314:17. Schloss Dagstuhl (2018)"},{"key":"11_CR10","unstructured":"Ben-Sasson, E., Bentov, I., Horesh, Y., Riabzev, M.: Scalable, transparent, and post-quantum secure computational integrity. Cryptology ePrint Archive, Report 2018\/046 (2018)"},{"key":"11_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1007\/978-3-030-17653-2_4","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2019","author":"E Ben-Sasson","year":"2019","unstructured":"Ben-Sasson, E., Chiesa, A., Riabzev, M., Spooner, N., Virza, M., Ward, N.P.: Aurora: transparent succinct arguments for R1CS. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT 2019, Part I. LNCS, vol. 11476, pp. 103\u2013128. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-17653-2_4"},{"key":"11_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"276","DOI":"10.1007\/978-3-662-44381-1_16","volume-title":"Advances in Cryptology \u2013 CRYPTO 2014","author":"E Ben-Sasson","year":"2014","unstructured":"Ben-Sasson, E., Chiesa, A., Tromer, E., Virza, M.: Scalable zero knowledge via cycles of elliptic curves. In: Garay, J.A., Gennaro, R. (eds.) CRYPTO 2014, Part II. LNCS, vol. 8617, pp. 276\u2013294. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-44381-1_16"},{"key":"11_CR13","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"518","DOI":"10.1007\/978-3-031-38554-4_17","volume-title":"CRYPTO 2023, Part V","author":"W Beullens","year":"2023","unstructured":"Beullens, W., Seiler, G.: LaBRADOR: compact proofs for R1CS from module-SIS. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO 2023, Part V. LNCS, vol. 14085, pp. 518\u2013548. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38554-4_17"},{"issue":"3","key":"11_CR14","doi-asserted-by":"publisher","first-page":"310","DOI":"10.1017\/S0963548317000566","volume":"27","author":"A Bishnoi","year":"2018","unstructured":"Bishnoi, A., Clark, P.L., Potukuchi, A., Schmitt, J.R.: On zeros of a polynomial in a finite grid. Comb. Probab. Comput. 27(3), 310\u2013333 (2018)","journal-title":"Comb. Probab. Comput."},{"key":"11_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"757","DOI":"10.1007\/978-3-319-96884-1_25","volume-title":"Advances in Cryptology \u2013 CRYPTO 2018","author":"D Boneh","year":"2018","unstructured":"Boneh, D., Bonneau, J., B\u00fcnz, B., Fisch, B.: Verifiable delay functions. In: Shacham, H., Boldyreva, A. (eds.) CRYPTO 2018, Part I. LNCS, vol. 10991, pp. 757\u2013788. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-96884-1_25"},{"key":"11_CR16","unstructured":"Boneh, D., Chen, B.: LatticeFold: a lattice-based folding scheme and its applications to succinct proof systems. Cryptology ePrint Archive, Report 2024\/257 (2024)"},{"key":"11_CR17","doi-asserted-by":"crossref","unstructured":"Boneh, D., Chen, B.: LatticeFold+: faster, simpler, shorter lattice-based folding for succinct proof systems. Cryptology ePrint Archive, Report 2025\/247 (2025)","DOI":"10.1007\/978-3-032-01907-3_11"},{"key":"11_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"649","DOI":"10.1007\/978-3-030-84242-0_23","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"D Boneh","year":"2021","unstructured":"Boneh, D., Drake, J., Fisch, B., Gabizon, A.: Halo Infinite: proof-carrying data from additive polynomial commitments. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021, Part I. LNCS, vol. 12825, pp. 649\u2013680. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84242-0_23"},{"key":"11_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"742","DOI":"10.1007\/978-3-030-84242-0_26","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"J Bootle","year":"2021","unstructured":"Bootle, J., Chiesa, A., Sotiraki, K.: Sumcheck arguments and their applications. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021, Part I. LNCS, vol. 12825, pp. 742\u2013773. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84242-0_26"},{"key":"11_CR20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/978-3-031-38545-2_8","volume-title":"CRYPTO 2023, Part II","author":"J Bootle","year":"2023","unstructured":"Bootle, J., Chiesa, A., Sotiraki, K.: Lattice-based succinct arguments for NP with polylogarithmic-time verification. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO 2023, Part II. LNCS, vol. 14082, pp. 227\u2013251. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38545-2_8"},{"key":"11_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"441","DOI":"10.1007\/978-3-030-56880-1_16","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"J Bootle","year":"2020","unstructured":"Bootle, J., Lyubashevsky, V., Nguyen, N.K., Seiler, G.: A non-PCP approach to succinct quantum-safe zero-knowledge. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020, Part II. LNCS, vol. 12171, pp. 441\u2013469. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56880-1_16"},{"key":"11_CR22","unstructured":"Bowe, S., Grigg, J., Hopwood, D.: Halo: recursive proof composition without a trusted setup. Cryptology ePrint Archive, Report 2019\/1021 (2019)"},{"key":"11_CR23","doi-asserted-by":"crossref","unstructured":"Brehm, M., Chen, B., Fisch, B., Resch, N., Rothblum, R.D., Zeilberger, H.: Blaze: Fast SNARKs from interleaved RAA codes. Cryptology ePrint Archive, Paper 2024\/1609 (2024)","DOI":"10.1007\/978-3-031-91134-7_5"},{"key":"11_CR24","doi-asserted-by":"crossref","unstructured":"B\u00fcnz, B., Bootle, J., Boneh, D., Poelstra, A., Wuille, P., Maxwell, G.: Bulletproofs: short proofs for confidential transactions and more. In: 2018 IEEE Symposium on Security and Privacy, pp. 315\u2013334. IEEE Computer Society Press (2018)","DOI":"10.1109\/SP.2018.00020"},{"key":"11_CR25","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/978-981-99-8724-5_3","volume-title":"ASIACRYPT 2023, Part II","author":"B B\u00fcnz","year":"2023","unstructured":"B\u00fcnz, B., Chen, B.: Protostar: generic efficient accumulation\/folding for special-sound protocols. In: Guo, J., Steinfeld, R. (eds.) ASIACRYPT 2023, Part II. LNCS, vol. 14439, pp. 77\u2013110. Springer, Singapore (2023). https:\/\/doi.org\/10.1007\/978-981-99-8724-5_3"},{"key":"11_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"681","DOI":"10.1007\/978-3-030-84242-0_24","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"B B\u00fcnz","year":"2021","unstructured":"B\u00fcnz, B., Chiesa, A., Lin, W., Mishra, P., Spooner, N.: Proof-carrying data without succinct arguments. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021, Part I. LNCS, vol. 12825, pp. 681\u2013710. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84242-0_24"},{"key":"11_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-030-64378-2_1","volume-title":"Theory of Cryptography","author":"B B\u00fcnz","year":"2020","unstructured":"B\u00fcnz, B., Chiesa, A., Mishra, P., Spooner, N.: Recursive proof composition from accumulation schemes. In: Pass, R., Pietrzak, K. (eds.) TCC 2020, Part II. LNCS, vol. 12551, pp. 1\u201318. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64378-2_1"},{"key":"11_CR28","unstructured":"B\u00fcnz, B., Mishra, P., Nguyen, W., Wang, W.: Arc: accumulation for Reed\u2013Solomon codes. Cryptology ePrint Archive, Paper 2024\/1731 (2024)"},{"key":"11_CR29","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"499","DOI":"10.1007\/978-3-031-30617-4_17","volume-title":"EUROCRYPT 2023, Part II","author":"B Chen","year":"2023","unstructured":"Chen, B., B\u00fcnz, B., Boneh, D., Zhang, Z.: HyperPlonk: plonk with linear-time prover and high-degree custom gates. In: Hazay, C., Stam, M. (eds.) EUROCRYPT 2023, Part II. LNCS, vol. 14005, pp. 499\u2013530. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30617-4_17"},{"key":"11_CR30","doi-asserted-by":"crossref","unstructured":"Chen, B., Waiwitlikhit, S., Stoica, I., Kang, D.: ZKML: an optimizing system for ML inference in zero-knowledge proofs. In: Proceedings of the Nineteenth European Conference on Computer Systems, EuroSys 2024, Athens, Greece, 22\u201325 April 2024, pp. 560\u2013574. ACM (2024)","DOI":"10.1145\/3627703.3650088"},{"key":"11_CR31","unstructured":"Chen, S., Cheon, J.H., Kim, D., Park, D.: Verifiable computing for approximate computation. Cryptology ePrint Archive, Report 2019\/762 (2019)"},{"key":"11_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"769","DOI":"10.1007\/978-3-030-45721-1_27","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2020","author":"A Chiesa","year":"2020","unstructured":"Chiesa, A., Ojha, D., Spooner, N.: Fractal: post-quantum and transparent recursive proofs from holography. In: Canteaut, A., Ishai, Y. (eds.) EUROCRYPT 2020, Part I. LNCS, vol. 12105, pp. 769\u2013793. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45721-1_27"},{"key":"11_CR33","unstructured":"Chiesa, A., Tromer, E.: Proof-carrying data and hearsay arguments from signature cards. In: Yao, A.C.-C. (ed.) ICS 2010, pp. 310\u2013331. Tsinghua University Press (2010)"},{"key":"11_CR34","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/978-3-031-68403-6_7","volume-title":"CRYPTO 2024, Part X","author":"V Cini","year":"2024","unstructured":"Cini, V., Malavolta, G., Nguyen, N.K., Wee, H.: Polynomial commitments from lattices: post-quantum security, fast verification and transparent setup. In: Reyzin, L., Stebila, D. (eds.) CRYPTO 2024, Part X. LNCS, vol. 14929, pp. 207\u2013242. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-68403-6_7"},{"key":"11_CR35","unstructured":"Datta, T., Boneh, D.: Using zk proofs to fight disinformation (2022). https:\/\/medium.com\/@boneh\/using-zk-proofs-to-fight-disinformation-17e7d57fe52f"},{"key":"11_CR36","unstructured":"Eagen, L., Gabizon, A.: ProtoGalaxy: efficient ProtoStar-style folding of multiple instances. Cryptology ePrint Archive, Report 2023\/1106 (2023)"},{"key":"11_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/978-3-030-64834-3_9","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"MF Esgin","year":"2020","unstructured":"Esgin, M.F., Nguyen, N.K., Seiler, G.: Practical exact proofs from lattices: new techniques to exploit fully-splitting rings. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020, Part II. LNCS, vol. 12492, pp. 259\u2013288. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_9"},{"key":"11_CR38","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1007\/978-981-96-0894-2_10","volume-title":"ASIACRYPT 2024, Part IV","author":"G Fenzi","year":"2024","unstructured":"Fenzi, G., Knabenhans, C., Nguyen, N.K., Pham, D.T.: Lova: lattice-based folding scheme from unstructured lattices. In: Chung, K.-M., Sasaki, Y. (eds.) ASIACRYPT 2024, Part IV. LNCS, vol. 15487, pp. 303\u2013326. Springer, Singapore (2024). https:\/\/doi.org\/10.1007\/978-981-96-0894-2_10"},{"issue":"3","key":"11_CR39","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1007\/s00145-024-09511-8","volume":"37","author":"G Fenzi","year":"2024","unstructured":"Fenzi, G., Moghaddas, H., Nguyen, N.K.: Lattice-based polynomial commitments: towards asymptotic and concrete efficiency. J. Cryptol. 37(3), 31 (2024)","journal-title":"J. Cryptol."},{"key":"11_CR40","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1007\/978-3-031-38545-2_7","volume-title":"CRYPTO 2023, Part II","author":"A Golovnev","year":"2023","unstructured":"Golovnev, A., Lee, J., Setty, S.T.V., Thaler, J., Wahby, R.S.: Brakedown: linear-time and field-agnostic SNARKs for R1CS. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO 2023, Part II. LNCS, vol. 14082, pp. 193\u2013226. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38545-2_7"},{"key":"11_CR41","unstructured":"Kang, D., Hashimoto, T., Stoica, I., Sun, Y.: ZK-IMG: attested images via zero-knowledge proofs to fight disinformation (2022)"},{"key":"11_CR42","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1007\/978-981-96-0935-2_7","volume-title":"ASIACRYPT 2024, Part V","author":"M Kloo\u00df","year":"2024","unstructured":"Kloo\u00df, M., Lai, R.W.F., Nguyen, N.K., Osadnik, M.: RoK, paper, SISsors toolkit for lattice-based succinct arguments - (extended abstract). In: Chung, K.-M., Sasaki, Y. (eds.) ASIACRYPT 2024, Part V. LNCS, vol. 15488, pp. 203\u2013235. Springer, Singapore (2024). https:\/\/doi.org\/10.1007\/978-981-96-0935-2_7"},{"key":"11_CR43","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"669","DOI":"10.1007\/978-3-031-38551-3_21","volume-title":"CRYPTO 2023, Part IV","author":"A Kothapalli","year":"2023","unstructured":"Kothapalli, A., Parno, B.: Algebraic reductions of knowledge. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO 2023, Part IV. LNCS, vol. 14084, pp. 669\u2013701. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38551-3_21"},{"key":"11_CR44","unstructured":"Kothapalli, A., Setty, S.: NeutronNova: Folding everything that reduces to zero-check. Cryptology ePrint Archive, Paper 2024\/1606 (2024)"},{"key":"11_CR45","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/978-3-031-15985-5_13","volume-title":"CRYPTO 2022, Part IV","author":"A Kothapalli","year":"2022","unstructured":"Kothapalli, A., Setty, S., Tzialla, I.: Nova: recursive zero-knowledge arguments from folding schemes. In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO 2022, Part IV. LNCS, vol. 13510, pp. 359\u2013388. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-15985-5_13"},{"key":"11_CR46","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"345","DOI":"10.1007\/978-3-031-68403-6_11","volume-title":"CRYPTO 2024, Part X","author":"A Kothapalli","year":"2024","unstructured":"Kothapalli, A., Setty, S.T.V.: HyperNova: recursive arguments for customizable constraint systems. In: Reyzin, L., Stebila, D. (eds.) CRYPTO 2024, Part X. LNCS, vol. 14929, pp. 345\u2013379. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-68403-6_11"},{"issue":"3","key":"11_CR47","first-page":"565","volume":"75","author":"A Langlois","year":"2015","unstructured":"Langlois, A., Stehl\u00e9, D.: Worst-case to average-case reductions for module lattices. DCC 75(3), 565\u2013599 (2015)","journal-title":"DCC"},{"key":"11_CR48","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"144","DOI":"10.1007\/11787006_13","volume-title":"Automata, Languages and Programming","author":"V Lyubashevsky","year":"2006","unstructured":"Lyubashevsky, V., Micciancio, D.: Generalized compact Knapsacks are collision resistant. In: Bugliesi, M., Preneel, B., Sassone, V., Wegener, I. (eds.) ICALP 2006, Part II. LNCS, vol. 4052, pp. 144\u2013155. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11787006_13"},{"key":"11_CR49","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/978-3-031-15979-4_3","volume-title":"CRYPTO 2022, Part II","author":"V Lyubashevsky","year":"2022","unstructured":"Lyubashevsky, V., Nguyen, N.K., Plan\u00e7on, M.: Lattice-based zero-knowledge proofs and applications: shorter, simpler, and more general. In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO 2022, Part II. LNCS, vol. 13508, pp. 71\u2013101. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-15979-4_3"},{"key":"11_CR50","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"204","DOI":"10.1007\/978-3-319-78381-9_8","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2018","author":"V Lyubashevsky","year":"2018","unstructured":"Lyubashevsky, V., Seiler, G.: Short, invertible elements in partially splitting cyclotomic rings and applications to lattice-based zero-knowledge proofs. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT 2018, Part I. LNCS, vol. 10820, pp. 204\u2013224. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78381-9_8"},{"key":"11_CR51","unstructured":"Mohnblatt, N.: Sangria: a folding scheme for PLONK (2023). https:\/\/geometry.xyz\/notebook\/sangria-a-folding-scheme-for-plonk"},{"key":"11_CR52","doi-asserted-by":"crossref","unstructured":"Naveh, A., Tromer, E.: PhotoProof: cryptographic image authentication for any set of permissible transformations. In: 2016 IEEE Symposium on Security and Privacy, pp. 255\u2013271. IEEE Computer Society Press (2016)","DOI":"10.1109\/SP.2016.23"},{"key":"11_CR53","unstructured":"Nethermind. Latticefold and lattice-based operations performance report (2024)"},{"key":"11_CR54","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1007\/978-3-031-68403-6_8","volume-title":"CRYPTO 2024, Part X","author":"NK Nguyen","year":"2024","unstructured":"Nguyen, N.K., Seiler, G.: Greyhound: fast polynomial commitments from lattices. In: Reyzin, L., Stebila, D. (eds.) CRYPTO 2024, Part X. LNCS, vol. 14929, pp. 243\u2013275. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-68403-6_8"},{"key":"11_CR55","unstructured":"Nguyen, W., Setty, S.: Neo: lattice-based folding scheme for CCS over small fields and pay-per-bit commitments. Cryptology ePrint Archive, Report 2025\/294 (2025)"},{"key":"11_CR56","doi-asserted-by":"crossref","unstructured":"Nguyen, W.D., Boneh, D., Setty, S.T.V.: Revisiting the nova proof system on a cycle of curves. In: 5th Conference on Advances in Financial Technologies, AFT 2023. LIPIcs, vol. 282, pp. 18:1\u201318:22 (2023)","DOI":"10.60079\/acsr.v1i1.51"},{"key":"11_CR57","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"308","DOI":"10.1007\/978-3-031-68403-6_10","volume-title":"CRYPTO 2024, Part X","author":"WD Nguyen","year":"2024","unstructured":"Nguyen, W.D., Datta, T., Chen, B., Tyagi, N., Boneh, D.: Mangrove: a scalable framework for folding-based SNARKs. In: Reyzin, L., Stebila, D. (eds.) CRYPTO 2024, Part X. LNCS, vol. 14929, pp. 308\u2013344. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-68403-6_10"},{"key":"11_CR58","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"145","DOI":"10.1007\/11681878_8","volume-title":"Theory of Cryptography","author":"C Peikert","year":"2006","unstructured":"Peikert, C., Rosen, A.: Efficient collision-resistant hashing from worst-case assumptions on cyclic lattices. In: Halevi, S., Rabin, T. (eds.) TCC 2006. LNCS, vol. 3876, pp. 145\u2013166. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11681878_8"},{"key":"11_CR59","unstructured":"R\u00e0fols, C., Zacharakis, A.: Folding schemes with selective verification. Cryptology ePrint Archive, Report 2022\/1576 (2022)"},{"key":"11_CR60","unstructured":"Setty, S., Thaler, J., Wahby, R.: Customizable constraint systems for succinct arguments. Cryptology ePrint Archive, Report 2023\/552 (2023)"},{"key":"11_CR61","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-78524-8_1","volume-title":"Theory of Cryptography","author":"P Valiant","year":"2008","unstructured":"Valiant, P.: Incrementally verifiable computation or proofs of knowledge imply time\/space efficiency. In: Canetti, R. (ed.) TCC 2008. LNCS, vol. 4948, pp. 1\u201318. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-78524-8_1"},{"key":"11_CR62","unstructured":"Whitehat, B.: Roll up token (2018). https:\/\/github.com\/barryWhiteHat\/roll_up_token"},{"key":"11_CR63","doi-asserted-by":"crossref","unstructured":"Xie, T., et al.: zkBridge: trustless cross-chain bridges made practical. In: Yin, H., Stavrou, A., Cremers, C., Shi, E. (eds.) ACM CCS 2022, pp. 3003\u20133017. ACM Press (2022)","DOI":"10.1145\/3548606.3560652"},{"key":"11_CR64","unstructured":"Yadav, C., Chowdhury, A.R., Boneh, D., Chaudhuri, K.: Fairproof: confidential and certifiable fairness for neural networks. In: ICML 2024. OpenReview.net (2024)"},{"key":"11_CR65","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"138","DOI":"10.1007\/978-3-031-68403-6_5","volume-title":"CRYPTO 2024, Part X","author":"H Zeilberger","year":"2024","unstructured":"Zeilberger, H., Chen, B., Fisch, B.: BaseFold: efficient field-agnostic polynomial commitment schemes from foldable codes. In: Reyzin, L., Stebila, D. (eds.) CRYPTO 2024, Part X. LNCS, vol. 14929, pp. 138\u2013169. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-68403-6_5"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-01907-3_11","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,10]],"date-time":"2025-09-10T01:22:44Z","timestamp":1757467364000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-01907-3_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783032019066","9783032019073"],"references-count":65,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-01907-3_11","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"17 August 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"45","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}