Christian Knabenhans @cknabs.bsky.social · 09/12/2024However, since Lova uses the unstructured SIS assumption, and because we’re constrained to a small challenge set, we need to amplify soundness quite a bit, leading to large-ish proofs (dozens of MB) and proving times >10 minutes. (5/8) 110
Christian Knabenhans @cknabs.bsky.social · 09/12/2024Lova vs Latticefold In a concurrent work, @danboneh and @charles_chen533 build a lattice folding scheme from MSIS. It's not implemented yet, but we can expect Latticefold to be more concretely efficient. We’ll have to see how they compare on recursion-friendliness. (6/8) 150
Christian Knabenhans @cknabs.bsky.social · 09/12/2024Finally, an open problem: Lova is very algebraic but uses plain SIS, Latticefold uses MSIS but relies on sumcheck, which is a powerful tool (too powerful?). Can we get a scheme that uses MSIS and barely does more than a single random linear combination? (7/8) 150