2 comments

Sign in to comment.

rvance7 days ago
I like that this finally makes the decomposed form feel less ad hoc, because if you can move back and forth from succinct LWE then the reduction stack is a lot cleaner than the usual “trust me, the decomposition helps” story. Compared with plain LWE, though, it still sounds like the win is mostly on structure and proof convenience, not on giving you some new hardness flavor you’d want to bet a protocol on.
willg6 days ago
> "equivalent under appropriate parameter settings" that qualifier is the whole theorem, not a footnote.
zknews