Sign in

Christian Knabenhans

@cknabs.bsky.social
140 followers 118 following 16 posts

PhD student @EPFL; ex-@ETH Taking privacy-enhancing crypto (mainly zkSNARKs & FHE) from theory to practice, and back. 🇨🇭🇫🇷 🏳️‍🌈

PostsRepliesMedia
Christian Knabenhans @cknabs.bsky.social · 12/06/2026
I joined @msftresearch.bsky.social this week for a summer internship! Very excited to be working with Greg Zaverucha on encryptedspaces.org, an ambitious research agenda for the future of secure collaboration tools. Check out the whitepaper by Greg, @tumbolia.bsky.social, Nora, and Trevor!
encryptedspaces.org
Encrypted Spaces — Research preview
An architecture for collaborative applications where data is encrypted and operations are cryptographically verifiable.
150
Christian Knabenhans @cknabs.bsky.social · 20/05/2025
Finally, we're thinking about high-assurance. We're working on a formally verified constant-time implementation of client-side FHE operations (in Jasmin+EasyCrypt), and we're exploring how to best use high-assurance tools (hax/hacspec, Jasmin, Lean) for lattirust. Stay tuned!
020
Christian Knabenhans @cknabs.bsky.social · 20/05/2025
At the moment we're relying on existing lattice estimators to set concrete parameters, but Xavier Marchon did a semester project to write a SIS-specific, Rust lattice estimator, which will be directly integrated in lattirust.
100
Christian Knabenhans @cknabs.bsky.social · 20/05/2025
What's next? Emile Hreich already explored GPU acceleration in a semester project, based on @ingonyama.com's Icicle, since lattice crypto is basically linear algebra over rings. We have promising results, with more coming up soon.
111
Christian Knabenhans @cknabs.bsky.social · 20/05/2025
Lattirust implements LaBRADOR and Lova, and we'll soon have implementations for the Greyhound PCS. I'll also upstream Nethermind's Latticefold implementation (which actually started from a fork of an early version of lattirust). We're working on some new schemes too 😉
100
Christian Knabenhans @cknabs.bsky.social · 20/05/2025
Lattirust implements fast (arkworks-compatible!) arithmetic for rings and polynomial rings, various challenge spaces, linear algebra and norms, and interfaces with spongefish for effortless Fiat–Shamir. It also has nice interfaces for relations and interactive reductions.
100
Christian Knabenhans @cknabs.bsky.social · 20/05/2025
I'm happy to finally open-source lattirust, a library for lattice-based zero-knowledge/succinct arguments! Lattirust is somewhat like arkworks, but for lattices; and like lattigo, but for arguments. ➔ github.com/lattirust
github.com
lattirust
Lattice zero-knowledge/succinct arguments, and more - lattirust
23216
Christian Knabenhans @cknabs.bsky.social · 09/12/2024
Read the paper on ePrint ia.cr/2024/1964, my blog post at cknabs.github.io/post/lova, or watch Tu’s presentation at Asiacrypt! I’ll also make the code open-source soon™, along with a lot more lattice implementations. Stay tuned! (8/8)
ia.cr
Lova: Lattice-Based Folding Scheme from Unstructured Lattices
Folding schemes (Kothapalli et al., CRYPTO 2022) are a conceptually simple, yet powerful cryptographic primitive that can be used as a building block to realise incrementally verifiable computation (I...
050
Christian Knabenhans @cknabs.bsky.social · 09/12/2024
Finally, an open problem: Lova is very algebraic but uses plain SIS, Latticefold uses MSIS but relies on sumcheck, which is a powerful tool (too powerful?). Can we get a scheme that uses MSIS and barely does more than a single random linear combination? (7/8)
150
Christian Knabenhans @cknabs.bsky.social · 09/12/2024
Lova vs Latticefold In a concurrent work, @danboneh and @charles_chen533 build a lattice folding scheme from MSIS. It's not implemented yet, but we can expect Latticefold to be more concretely efficient. We’ll have to see how they compare on recursion-friendliness. (6/8)
150
Christian Knabenhans @cknabs.bsky.social · 09/12/2024
However, since Lova uses the unstructured SIS assumption, and because we’re constrained to a small challenge set, we need to amplify soundness quite a bit, leading to large-ish proofs (dozens of MB) and proving times >10 minutes. (5/8)
110
Christian Knabenhans @cknabs.bsky.social · 09/12/2024
Is Lova concretely efficient? Lova has some nice features: it is very algebraic (great for prover parallelism!) and only requires a single challenge matrix, which makes it recursion-friendly. We also use the modulus q=2^64 and get rid of modular reduction. (4/8)
110
Christian Knabenhans @cknabs.bsky.social · 09/12/2024
One thing I’m proud of in this paper is the notation: while lattice crypto papers are typically heavy notationally, we use matrix notation throughout which leads to a very concise (and imho elegant) notation. Here’s the entire protocol for our core folding step! (3/8)
120
Christian Knabenhans @cknabs.bsky.social · 09/12/2024
Lattice folding schemes face two issues: witness norm growth (completeness), and norm growth when extracting (non-relaxed knowledge soundness). We use a split-and-fold technique to get around #1, and we use witness cross-terms (which we also fold) for #2. (2/8)
110
Christian Knabenhans @cknabs.bsky.social · 09/12/2024
Lova 💕 (aka lattice Nova): Duc Tu Pham, @giacomofenzi.bsky.social, Ngoc Khanh Nguyen and I built a folding scheme from (unstructured) lattice assumptions, which will be presented at Asiacrypt this week! (1/8)
171
Christian Knabenhans @cknabs.bsky.social · 04/11/2024
We're starting a study group on Alessandro Chiesa and Eylon Yogev's snargsbook.org on the ZK Hack Discord! Join us this Thursday at 6pm CET for an intro by Alessandro: discord.com/channels/740...
discord.com
Discord - Group Chat That’s All Fun & Games
Discord is great for playing games and chilling with friends, or even building a worldwide community. Customize your own space to talk, play, and hang out.
030