{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,9]],"date-time":"2025-09-09T22:18:48Z","timestamp":1757456328859,"version":"3.37.3"},"reference-count":32,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2021,3,2]],"date-time":"2021-03-02T00:00:00Z","timestamp":1614643200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,3,2]],"date-time":"2021-03-02T00:00:00Z","timestamp":1614643200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Des. Codes Cryptogr."],"published-print":{"date-parts":[[2021,5]]},"DOI":"10.1007\/s10623-021-00851-1","type":"journal-article","created":{"date-parts":[[2021,3,2]],"date-time":"2021-03-02T13:02:49Z","timestamp":1614690169000},"page":"925-963","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Lattice-based zero-knowledge arguments for additive and multiplicative relations"],"prefix":"10.1007","volume":"89","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7724-2601","authenticated-orcid":false,"given":"Veronika","family":"Kuchta","sequence":"first","affiliation":[]},{"given":"Amin","family":"Sakzad","sequence":"additional","affiliation":[]},{"given":"Ron","family":"Steinfeld","sequence":"additional","affiliation":[]},{"given":"Joseph K.","family":"Liu","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2021,3,2]]},"reference":[{"issue":"3","key":"851_CR1","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1515\/jmc-2015-0016","volume":"9","author":"MR Albrecht","year":"2015","unstructured":"Albrecht M.R., Player R., Scott S.: On the concrete hardness of learning with errors. J. Math. Cryptol. 9(3), 169\u2013203 (2015).","journal-title":"J. Math. Cryptol."},{"key":"851_CR2","first-page":"478","volume-title":"How to Prove Knowledge of Small Secrets. CRYPTO","author":"C Baum","year":"2016","unstructured":"Baum C., Damg\u00e5rd I., Larsen K.G., Nielsen M.: How to Prove Knowledge of Small Secrets. CRYPTO, pp. 478\u2013498. Springer, New Yor (2016)."},{"key":"851_CR3","doi-asserted-by":"crossref","unstructured":"Baum, C., Damg\u00e5rd, I., Lyubashevsky, V., Oechsner, S., Peikert, C.: More efficient commitments from structured lattice assumptions. In: Security and Cryptography for Networks - 11th International Conference, SCN: Proceedings, ser. Lecture Notes in Computer Science, vol. 11035. Springer, pp. 368\u2013385 (2018)","DOI":"10.1007\/978-3-319-98113-0_20"},{"key":"851_CR4","doi-asserted-by":"crossref","unstructured":"Bayer, S., Groth, J.: Zero-knowledge argument for polynomial evaluation with application to blacklists. In: EUROCRYPT, ser. LNCS, vol. 7881. Springer, 2013, pp. 646\u2013663","DOI":"10.1007\/978-3-642-38348-9_38"},{"key":"851_CR5","doi-asserted-by":"crossref","unstructured":"Benhamouda, F., Camenisch, J., Krenn, S., Lyubashevsky, V., Neven, G.: Better zero-knowledge proofs for lattice encryption and their application to group signatures. In: ASIACRYPT. Springer, 2014, pp. 551\u2013572","DOI":"10.1007\/978-3-662-45611-8_29"},{"key":"851_CR6","first-page":"305","volume":"2015","author":"F Benhamouda","year":"2015","unstructured":"Benhamouda F., Krenn S., Lyubashevsky V., Pietrzak K.: Efficient zero-knowledge proofs for commitments from learning with errors over rings. ESORICS 2015, 305\u2013325 (2015).","journal-title":"ESORICS"},{"key":"851_CR7","doi-asserted-by":"crossref","unstructured":"Bootle, J., Cerulli, A., Chaidos, P., Groth, J., Petit, C.: Efficient zero-knowledge arguments for arithmetic circuits in the discrete log setting. In EUROCRYPT. Springer, 2016, pp. 327\u2013357","DOI":"10.1007\/978-3-662-49896-5_12"},{"issue":"90","key":"851_CR8","doi-asserted-by":"publisher","first-page":"297","DOI":"10.1090\/S0025-5718-1965-0178586-1","volume":"19","author":"J Cooley","year":"1965","unstructured":"Cooley J., Tukey J.: An algorithm for the machine calculation of complex fourier series. Math. Comput. 19(90), 297\u2013301 (1965).","journal-title":"Math. Comput."},{"key":"851_CR9","doi-asserted-by":"crossref","unstructured":"del Pino, R., Lyubashevsky, V., Seiler, G.: Lattice-based group signatures and zero-knowledge proofs of automorphism stability. In: ACM SIGSAC CCS. ACM, 2018, pp. 574\u2013591","DOI":"10.1145\/3243734.3243852"},{"key":"851_CR10","doi-asserted-by":"crossref","unstructured":"Esgin, M.F., Steinfeld, R., Liu, J.\u00a0K., Liu, D.: Lattice-based zero-knowledge proofs: New techniques for shorter and faster constructions and applications. In: CRYPTO, ser. LNCS. Springer, 2019, pp. 115\u2013146","DOI":"10.1007\/978-3-030-26948-7_5"},{"key":"851_CR11","doi-asserted-by":"crossref","unstructured":"Esgin, M.\u00a0F., Steinfeld, R., Sakzad, A., Liu, J.\u00a0K., Liu, D.: Short lattice-based one-out-of-many proofs and applications to ring signatures. In: ACNS. Springer, 2019, pp. 67\u201388","DOI":"10.1007\/978-3-030-21568-2_4"},{"key":"851_CR12","doi-asserted-by":"crossref","unstructured":"Esgin, M.\u00a0F., Zhao, R.\u00a0K., Steinfeld, R., Liu, J.\u00a0K., Liu, D.: Matrict: Efficient, scalable and post-quantum blockchain confidential transactions protocol. In: to appear in CCS, (preprint obtained by private communication with the authors), 2019","DOI":"10.1145\/3319535.3354200"},{"key":"851_CR13","doi-asserted-by":"crossref","unstructured":"Goldreich, O., Goldwasser, S.: On the limits of non-approximability of lattice problems. In: ACM STOC. ACM, 1998, pp. 1\u20139.","DOI":"10.1145\/276698.276704"},{"key":"851_CR14","doi-asserted-by":"crossref","unstructured":"Goldwasser, S., Micali, S., Rackoff, C.: The knowledge complexity of interactive proof-systems (extended abstract). In: ACM STOC. ACM, 1985, pp. 291\u2013304","DOI":"10.1145\/22145.22178"},{"key":"851_CR15","unstructured":"Harvey, D., van\u00a0der Hoeven, J.: Faster integer multiplication using short lattice vectors. CoRR, (2018). http:\/\/arxiv.org\/abs\/1802.07932"},{"key":"851_CR16","unstructured":"Harvey, D., Van Der\u00a0Hoeven, J.: Integer multiplication in time O(n log n). https:\/\/hal.archives-ouvertes.fr\/hal-02070778 (2019)"},{"key":"851_CR17","doi-asserted-by":"crossref","unstructured":"Kawachi, A., Tanaka, K., Xagawa, K.: Concurrently secure identification schemes based on the worst-case hardness of lattice problems. In: ASIACRYPT, ser. LNCS, vol. 5350. Springer, pp. 372\u2013389 (2008)","DOI":"10.1007\/978-3-540-89255-7_23"},{"key":"851_CR18","doi-asserted-by":"crossref","unstructured":"Kilian, J.: A note on efficient zero-knowledge proofs and arguments (extended abstract). In: ACM STOC. ACM, pp. 723\u2013732 (1992)","DOI":"10.1145\/129712.129782"},{"key":"851_CR19","doi-asserted-by":"crossref","unstructured":"Libert, B., Ling, S., Mouhartem, F., Nguyen, K., Wang, H.: Zero-knowledge arguments for matrix-vector relations and lattice-based group encryption. In: ASIACRYPT, pp. 101\u2013131 (2016)","DOI":"10.1007\/978-3-662-53890-6_4"},{"key":"851_CR20","doi-asserted-by":"crossref","unstructured":"Libert, B., Ling, S., Nguyen, K., Wang, H.: Zero-knowledge arguments for lattice-based accumulators: Logarithmic-size ring signatures and group signatures without trapdoors. In: EUROCRYPT. Springer, pp. 1\u201331 (2016)","DOI":"10.1007\/978-3-662-49896-5_1"},{"key":"851_CR21","doi-asserted-by":"crossref","unstructured":"Libert, B., Ling, S., Nguyen, K., Wang, H.: Zero-knowledge arguments for lattice-based prfs and applications to e-cash. In: ASIACRYPT. Springer, pp. 304\u2013335 (2017)","DOI":"10.1007\/978-3-319-70700-6_11"},{"key":"851_CR22","doi-asserted-by":"crossref","unstructured":"Libert, B., Ling, S., Nguyen, K., Wang, H.: Lattice-based zero-knowledge arguments for integer relations. In CRYPTO, ser. LNCS, vol. 10992. Springer, pp. 700\u2013732 (2018)","DOI":"10.1007\/978-3-319-96881-0_24"},{"key":"851_CR23","doi-asserted-by":"crossref","unstructured":"Ling, S., Nguyen, K., Stehl\u00e9, D., Wang, H.: Improved zero-knowledge proofs of knowledge for the ISIS problem, and applications. In: PKC. Springer, pp. 107\u2013124 (2013)","DOI":"10.1007\/978-3-642-36362-7_8"},{"key":"851_CR24","unstructured":"L\u00fcders, C.: Fast multiplication of large integers: Implementation and analysis of the DKSS algorithm. http:\/\/arxiv.org\/abs\/1503.04955"},{"key":"851_CR25","doi-asserted-by":"crossref","unstructured":"Lyubashevsky, V.: Fiat-shamir with aborts: Applications to lattice and factoring-based signatures. In: ASIACRYPT. Springer, pp. 598\u2013616 (2009)","DOI":"10.1007\/978-3-642-10366-7_35"},{"key":"851_CR26","doi-asserted-by":"crossref","unstructured":"Lyubashevsky, V.: Lattice signatures without trapdoors. In: EUROCRYPT. Springer, pp. 738\u2013755 (2012).","DOI":"10.1007\/978-3-642-29011-4_43"},{"key":"851_CR27","doi-asserted-by":"crossref","unstructured":"Micciancio, D., Vadhan, S.\u00a0P.: Statistical zero-knowledge proofs with efficient provers: Lattice problems and more. In: CRYPTO. Springer, pp. 282\u2013298 (2003).","DOI":"10.1007\/978-3-540-45146-4_17"},{"key":"851_CR28","doi-asserted-by":"crossref","unstructured":"Miers, I., Garman, C., Green, M., Rubin, A.\u00a0D.: Zerocoin: Anonymous distributed e-cash from bitcoin. In: 2013 IEEE SP, 2013, pp. 397\u2013411 (2013)","DOI":"10.1109\/SP.2013.34"},{"key":"851_CR29","doi-asserted-by":"crossref","unstructured":"Stern, J.: A new identification scheme based on syndrome decoding. In: CRYPTO. Springer, pp. 13\u201321 (1993).","DOI":"10.1007\/3-540-48329-2_2"},{"key":"851_CR30","first-page":"456","volume":"2017","author":"S Sun","year":"2017","unstructured":"Sun S., Au M.H., Liu J.K., Yuen T.H.: Ringct 2.0: A compact accumulator-based (linkable ring signature) protocol for blockchain cryptocurrency monero. ESORICS 2017, 456\u2013474 (2017).","journal-title":"ESORICS"},{"key":"851_CR31","first-page":"496","volume":"150","author":"AL Toom","year":"1963","unstructured":"Toom A.L.: The complexity of a scheme of functional elements simulating the multiplication of integers. Dokl. Akad. Nauk SSSR 150, 496\u2013498 (1963).","journal-title":"Dokl. Akad. Nauk SSSR"},{"key":"851_CR32","doi-asserted-by":"crossref","unstructured":"Yang, R., Au, M.H., Zhang, Z., Xu, Q., Yu, Z., Whyte, W.: Efficient lattice-based zero-knowledge arguments with standard soundness: Construction and applications. In: Advances in Cryptology - CRYPTO, : Proceedings, Part I, ser. Lecture Notes in Computer Science, vol. 11692. Springer, pp. 147\u2013175 (2019)","DOI":"10.1007\/978-3-030-26948-7_6"}],"container-title":["Designs, Codes and Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-021-00851-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10623-021-00851-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-021-00851-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,5,5]],"date-time":"2021-05-05T18:30:00Z","timestamp":1620239400000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10623-021-00851-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,3,2]]},"references-count":32,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2021,5]]}},"alternative-id":["851"],"URL":"https:\/\/doi.org\/10.1007\/s10623-021-00851-1","relation":{},"ISSN":["0925-1022","1573-7586"],"issn-type":[{"type":"print","value":"0925-1022"},{"type":"electronic","value":"1573-7586"}],"subject":[],"published":{"date-parts":[[2021,3,2]]},"assertion":[{"value":"3 February 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 February 2021","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"5 February 2021","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 March 2021","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}