Featured Developer Sponsor • Zero-Token Protection
Post-Quantum Lattice Cryptography
FIPS 204 / Dilithium Compatible
Lattice ZK & Module-LWE/SIS Protocol Studio
Simulate quantum-resistant zero-knowledge proofs of knowledge based on Module-LWE and Module-SIS. Step through polynomial ring arithmetic, Lyubashevsky rejection sampling, NTT coordinate transforms, and verify zero-knowledge soundness.
1. Lattice & Ring Parameters
2. Witness & Proof Generation
[Click "Generate Public Relation" to initialize witness s]
Rejection sampling abort probability: ~15-25% per attempt
3. Interactive Transcript & Rejection Sampling Log
Waiting for relation generation...
4. Verifier Validation & Soundness
PROOFS AWAITING EXECUTION
Verifier evaluates A*z - c*t = w mod q and ||z||_inf < gamma1 - beta
Response Norm ||z||_inf
-
Allowed Bound (gamma1 - beta)
-
Estimated Proof Size
-
Quantum Hardness (Core-SVP)
-
5. Ring Element & NTT Coefficient Spectrum Visualizer
Inspect polynomial coefficients in the quotient ring R_q = Z_q[X]/(X^n + 1). Toggle between normal polynomial domain and Number Theoretic Transform (NTT) frequency domain.
Domain:
Displaying first 64 coefficients
6. Post-Quantum Lattice Zero-Knowledge Protocols Comparison
| Protocol / Scheme | Underlying Problem | Proof Type | Typical Size | Quantum Resistance Mechanism |
|---|---|---|---|---|
| ML-DSA (Dilithium / FIPS 204) | M-LWE / M-SIS | Fiat-Shamir with Aborts | 2.4 KB - 4.6 KB | High-dimensional lattice shortest vector hardness |
| Lattice Bulletproofs (Bootle et al.) | Ring-SIS / Ring-LWE | Logarithmic inner-product | 8 KB - 22 KB | Exact Euclidean norm bounds without trusted setup |
| LaBRADOR (del Pino et al.) | Ring-SIS / M-LWE | Recursive polynomial argument | 58 KB (Rank 10^6) | Succinct post-quantum argument for R1CS relations |
| Classical SNARKs (Groth16 / PLONK) | Discrete Log / Pairing | Bilinear Pairings / KZG | 128 B - 800 B | Broken by Shor's Quantum Algorithm |
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement