MPC-in-the-Head Zero-Knowledge Proof for Rank Syndrome Decoding via Mixed-Field Secret Sharing
Abstract
1. Introduction
- We arithmetise the rank constraint of the RSD relation as a mixed-field matrix product with and . This algebraic identity turns a rank-metric statement into a relation suitable for a -secret-sharing MPC protocol without an explicit rank-check sub-circuit.
- We design a -secret-sharing MPC protocol for the mixed-field product, operating simultaneously over and , and apply the MPC-in-the-Head transformation to obtain a single-round interactive zero-knowledge -protocol with soundness error . The local view of each virtual party is formally defined in Section 3.3, where every value used by the verifier is shown to be either recomputable from the response or cryptographically bound by a commitment.
- We give a Fiat–Shamir compilation of the protocol into a non-interactive zero-knowledge proof (Section 5), with the security analysis explicitly restricted to the classical random oracle model. We do not claim security of the Fiat–Shamir variant in the Quantum Random Oracle Model, and we identify QROM security as future work. We instantiate the scheme at NIST Security Level 1 with parameters and validate the parameter choice using the Rank-Metric Estimator of Bardet et al. [15], whose detailed attack-cost breakdown is reported in Section 6.1. We additionally provide a reference implementation and the proposed scheme produces a 65.7 KB proof in approximately 22 ms and verifies it in approximately 14 ms.
2. Preliminaries
2.1. Notation
2.2. Rank Syndrome Decoding
2.3. MPC-in-the-Head
- Commit Phase: The prover locally simulates an N-party () MPC protocol in their local. The secret witness w is divided into corresponding shares and distributed to virtual parties . After the internal simulation, the prover generates a local view for each party and sends their hash commitments to the verifier.
- Challenge Phase: The verifier uniformly samples a random challenge and sends it to the prover, specifying which subset of views should be opened.
- Response and Verification Phase: The prover reveals a specific subset of views according to the challenge. The verifier then independently performs three strict checks: (1) Whether the opened views match the initial commitments (), (2) Whether the intermediate computation messages are logically consistent between the opened views, and (3) Whether the simulated MPC circuit ultimately outputs a valid result.
3. The Single-Round Interactive Protocol
3.1. Arithmetization of the Rank Constraint
3.2. (2, 3)-Secret Sharing Mechanism for Mixed Fields
3.3. Formal Definition of the Local View
- The seed is a uniformly random bit-string sampled by the prover at the beginning of the Commit phase. A pseudorandom generator with domain-separated tags expands deterministically into the party’s local randomness: for , expands to the triple ; for , expands only to the blinding factor .
- The auxiliary input carries the part of the party’s local randomness that is not derivable from any seed. It is defined aswhere and are determined by the prover’s secret witness and the seed-expanded shares of the other two parties.
- The local output share is the error-vector share computed by according to the cross-multiplication formula
- (C1) Explicitly transmitted: , , , , , .
- (C2) Deterministically recomputable from (C1): the input-and-randomness triples and obtained by PRG expansion of the transmitted seeds (or read from when is opened); the error share obtained by applying the cross-multiplication formula to these triples; the syndrome shares and ; and the view commitments and .
- (C3) Algebraically forced by the public statement: the unopened syndrome share , derived from the public syndrome relation . Furthermore, the values that do not fall into (C1)–(C3), namely the components of the unopened view , are cryptographically bound: the prover transmits as part of the response, and the first message binds the three per-party commitments together with the three syndrome shares. Under the collision-resistance of , the prover is therefore committed, before the challenge is issued, to a unique tuple () consistent with C.
3.4. Protocol
- Setup: Generate the parity-check matrix , the syndrome , the rank and the prover’s secret input , .
- Commit: (1) Sample three seeds from a true random source, and use a pseudorandom generator (PRG) to generate the blinding factors for each party; (2) The prover uses and to pseudorandomly generate the initial shares , of the views using a PRG, , . Since the input shares of the third virtual party cannot be pseudorandomly derived from a seed, we define auxiliary data if and if to explicitly transmit ; (3) Each virtual party performs local computations and determine its respective syndrome share ; (4). The prover defines the serialized local view of each virtual party as . It then computes the commitment for , and sends the round commitment to the verifier.
- Challenge: The verifier uniformly samples a challenge value and sends it to the prover.
- Response: The prover sends the tuple to the verifier, where and .
- Verify: (1) The verifier locally uses the to compute , and then re-executes the mixed-field cross-multiplication circuit to compute and read from the response. It then reconstructs the views and ; (2) Calculates the syndrome share and ; (3) The verifier derives the missing syndrome share utilizing the public syndrome ; (4) Re-computes the commitments and using the reconstructed views and read from the response; (5) The verifier accepts the proof if the re-computed commitment matches the C received in Step Commit, and execution steps are logically consistent; otherwise, the verifier rejects the proof.
4. Security Discussion of the Single-Round Protocol
- (1)
- three-move:
- Commit: sends a first message a to ;
- Challenge: sends a random challenge h to ;
- Response: replies a response z to .
- (2)
- Completeness: If both players and are honest and , then ;
- (3)
- s-Special Soundness: For any x and any set of s accepting conversations with if , a witness w for x can be efficiently computed;
- (4)
- Special Honest-Verifier Zero-Knowledge: There exists a PPT simulator such that on input and h outputs a triple with the same probability distribution as real conversations of the protocol.
5. Non-Interactive Extension
5.1. Non-Interactive Protocol
| Algorithm 1: Non-interactive Proof Generation (Prove) |
Input: Public parameters (, , ); Secret input , . Output: Zero-knowledge proof . ![]() |
5.2. Security Discussion
| Algorithm 2: Non-interactive Proof Verification (Verify) |
Input: Public parameters (, ); Non-interactive proof . Output: Accept or Reject. ![]() |
6. Performance Evaluation
6.1. Security Parameter
6.2. Communication Overhead and Proof Size
- Two seeds corresponding to the opened views are revealed, contributing bits.
- The hash commitment of the unopened view is provided, contributing bits.
- The error vector share required for cross-term reconstruction is provided, contributing bits.
- The third share and are algebraically computed rather than pseudo-randomly generated. Therefore, if the challenge , the prover must explicitly transmit as auxiliary plaintext. ( bits, bits).
6.3. Comparison with Existing Schemes
6.4. Computational Complexity and Implementation
- Field operations. The only multiplications in one round occur in the three syndrome evaluations , yielding multiplications per round; the three mixed-field matrix-vector products contribute additions in but no multiplications, since entries of lie in . Total per-round field cost: field multiplications and field additions.
- Hash calls. Four calls per round: three per-party view commitments and one round commitment . Total asymptotic cost: hash calls per round on inputs of size bits.
- PRG calls. Three calls per round, one per virtual party, each expanding a -bit seed to pseudorandom bits via domain-separated SHAKE-256.
- Commitment. The commitment scheme is realised as , so its cost is counted under hash calls; per round, three view commitments and one round commitment, totalling commitment operations on bits of input.
- Prover (per round). multiplications, additions, PRG and hash calls.
- Verifier (per round). Approximately two thirds of the prover’s work, since only two of the three views are reconstructed.
7. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Čapko, D.; Vukmirović, S.; Nedić, N. State of the art of zero-knowledge proofs in blockchain. In Proceedings of the 30th Telecommunications Forum (TELFOR), Belgrade, Serbia, 15–16 November 2022; pp. 1–4. [Google Scholar] [CrossRef] [Scilit]
- Giacomelli, I.; Madsen, J.; Orlandi, C. ZKBoo: Faster zero-knowledge for Boolean circuits. In Proceedings of the 25th USENIX Security Symposium, Austin, TX, USA, 10–12 August 2016; pp. 1069–1083. [Google Scholar]
- Dam, D.T.; Tran, T.H.; Hoang, V.P.; Pham, C.K.; Hoang, T.T. A survey of post-quantum cryptography: Start of a new race. Cryptography 2023, 7, 40. [Google Scholar] [CrossRef] [Scilit]
- Cherkaoui Dekkaki, K.; Tasic, I.; Cano, M.D. Exploring post-quantum cryptography: Review and directions for the transition process. Technologies 2024, 12, 241. [Google Scholar] [CrossRef] [Scilit]
- Stern, J. A new identification scheme based on syndrome decoding. In Proceedings of the Annual International Cryptology Conference (CRYPTO), Berlin, Heidelberg, 22–26 August 1993; pp. 13–21. [Google Scholar] [CrossRef] [Scilit]
- Véron, P. Improved Identification Schemes Based on Error-Correcting Codes. Appl. Algebra Eng. Commun. Comput. 1997, 8, 57–69. [Google Scholar] [CrossRef] [Scilit]
- Aguilar, C.; Gaborit, P.; Schrek, J. A New Zero-Knowledge Code Based Identification Scheme with Reduced Communication. In Proceedings of the 2011 IEEE Information Theory Workshop; IEEE: New York, NY, USA, 2011; pp. 648–652. [Google Scholar] [CrossRef] [Scilit]
- Alaoui, S.M.E.Y.; Cayrel, P.L.; Bansarkhani, R.E.; Hoffmann, G. Code-Based Identification and Signature Schemes in Software. In Proceedings of the Security Engineering and Intelligence Informatics-CD-ARES 2013 Workshops: MoCrySEn and SeCIHD, Berlin, Heidelberg, 2–6 September 2013; pp. 122–136. [Google Scholar] [CrossRef] [Scilit]
- Feneuil, T.; Joux, A.; Rivain, M. Syndrome decoding in the head: Shorter signatures from zero-knowledge proofs. In Proceedings of the Annual International Cryptology Conference (CRYPTO), Cham, Switzerland, 15–18 August 2022; pp. 541–572. [Google Scholar] [CrossRef] [Scilit]
- Gabidulin, E.M. Theory of codes with maximum rank distance. Probl. Inf. Transm. 1985, 21, 1–12. [Google Scholar]
- Bidoux, L.; Chi-Domínguez, J.J.; Feneuil, T.; Gaborit, P.; Joux, A.; Rivain, M.; Vinçotte, A. RYDE: A digital signature scheme based on rank syndrome decoding problem with MPC-in-the-Head paradigm. Des. Codes Cryptogr. 2025, 93, 1451–1486. [Google Scholar] [CrossRef] [Scilit]
- National Institute of Standards and Technology. NIST Announces 14 Candidates to Advance to the Second Round of the Additional Digital Signatures for the Post-Quantum Cryptography Standardization Process. 2024. Available online: https://csrc.nist.gov/news/2024/pqc-digital-signature-second-round-announcement (accessed on 8 April 2026).
- Ishai, Y.; Kushilevitz, E.; Ostrovsky, R.; Sahai, A. Zero-knowledge from secure multiparty computation. In Proceedings of the Annual ACM Symposium on Theory of Computing (STOC), San Diego, CA, USA, 11–13 June 2007; pp. 21–30. [Google Scholar] [CrossRef] [Scilit]
- Chase, M.; Derler, D.; Goldfeder, S.; Orlandi, C.; Ramacher, S.; Rechberger, C.; Slamanig, D.; Zaverucha, G. Post-quantum zero-knowledge and signatures from symmetric-key primitives. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), Salt Lake City, UT, USA, 14–18 October 2017; pp. 1825–1842. [Google Scholar] [CrossRef] [Scilit]
- Esser, A.; Bellini, E. Syndrome Decoding Estimator. In Proceedings of the International Conference on Practice and Theory of Public-Key Cryptography (PKC), Cham, Switzerland, 8–11 March 2022; pp. 115–142. [Google Scholar] [CrossRef] [Scilit]
- Feneuil, T. Building MPCitH-based signatures from MQ, MinRank, and rank SD. In Proceedings of the International Conference on Applied Cryptography and Network Security (ACNS), Cham, Switzerland, 5–8 March 2024; pp. 403–431. [Google Scholar] [CrossRef] [Scilit]
- Gaborit, P.; Zémor, G. On the hardness of the decoding and the minimum distance problems for rank codes. IEEE Trans. Inf. Theory 2016, 62, 7245–7252. [Google Scholar] [CrossRef] [Scilit]
- Bardet, M.; Bros, M.; Cabarcas, D.; Gaborit, P.; Perlner, R.; Smith-Tone, D.; Tillich, J.P.; Verbel, J. Improvements of Algebraic Attacks for Solving the Rank Decoding and MinRank Problems. In Proceedings of the ASIACRYPT 2020, Daejeon, Republic of Korea, 7–11 December 2020; pp. 507–536. [Google Scholar]
- Chabaud, F.; Stern, J. The Cryptographic Security of the Syndrome Decoding Problem for Rank Distance Codes. In Proceedings of the ASIACRYPT 1996, Kyongju, Republic of Korea, 3–7 November 1996. [Google Scholar]
- Ourivski, A.; Johansson, T. New Technique for Decoding Codes in the Rank Metric and Its Cryptography Applications. Probl. Inf. Transm. 2002, 38, 237–246. [Google Scholar] [CrossRef] [Scilit]
- Gaborit, P.; Ruatta, O.; Schrek, J. On the Complexity of the Rank Syndrome Decoding Problem. IEEE Trans. Inf. Theory 2016, 62, 1006–1019. [Google Scholar] [CrossRef] [Scilit]
- Aragon, N.; Gaborit, P.; Hauteville, A.; Tillich, J.P. A New Algorithm for Solving the Rank Syndrome Decoding Problem. In Proceedings of the IEEE International Symposium on Information Theory (ISIT) 2018, Vail, CO, USA, 17–22 June 2018; pp. 2421–2425. [Google Scholar]
- D’Alconzo, G.; Esser, A.; Gangemi, A.; Sanna, C. Sneaking up the ranks: Partial key exposure attacks on rank-based schemes. Des. Codes Cryptogr. 2026, 94, 15. [Google Scholar] [CrossRef] [Scilit]
- Debris-Alazard, T.; Tillich, J.P. Two Attacks on Rank Metric Code-Based Schemes: RankSign and an IBE Scheme. In Proceedings of the ASIACRYPT 2018, Brisbane, Australia, 2–6, December 2018; pp. 62–92. [Google Scholar]
- Bardet, M.; Bros, M.; Cabarcas, D.; Gaborit, P.; Perlner, R.; Smith-Tone, D.; Tillich, J.P.; Verbel, J. Algebraic Attacks for Solving the Rank Decoding and MinRank Problems Without Gröbner Basis. In Proceedings of the CRYPTO 2020, Santa Barbara, CA, USA, 17–21 August 2020; pp. 507–536. [Google Scholar]
- Don, J.; Fehr, S.; Majenz, C.; Schaffner, C. Security of the Fiat–Shamir Transformation in the Quantum Random-Oracle Model. In Proceedings of the Advances in Cryptology—CRYPTO 2019, Part II; Springer: Berlin/Heidelberg, Germany, 2019; pp. 356–383. [Google Scholar]
- Liu, Q.; Zhandry, M. Revisiting Post-quantum Fiat–Shamir. In Proceedings of the Advances in Cryptology—CRYPTO 2019, Part II; Springer: Berlin/Heidelberg, Germany, 2019; pp. 326–355. [Google Scholar]

| Notation | Definition |
|---|---|
| q | A prime power |
| The finite field of size q | |
| The extension field of degree m | |
| Transpose | |
| The element in the i-th row and j-th column for a matrix A | |
| The i-th component for a vector x | |
| The zero vector or matrix | |
| The identity matrix | |
| ⌀ | The empty set |
| The dimension of a vector space V defined over | |
| The rank weight of a vector e | |
| N | The number of virtual parties in the MPC-in-the-Head framework (default ) |
| The i-th virtual party | |
| The local view of the i-th party | |
| The commitment of the i-th party | |
| The verifier’s challenge | |
| The security parameter | |
| The number of repetitions | |
| X | The coefficient matrix over the base field |
| y | The basis vector over the extension field |
| The hash function |
| Quantity | Value |
|---|---|
| Base field | |
| Extension degree m | 41 |
| Code length n | 38 |
| Information dimension k | 19 |
| Rank weight r | 7 |
| Security parameter | 128 |
| Repetition count | 219 |
| Hash/PRG | SHA3-256/SHAKE-256 |
| Best classical attack | MaxMinors [18] |
| Family | Attack | Time (log2) | Memory (log2) |
|---|---|---|---|
| Combinatorial | Basis Enumeration [19] | 228.8 | 17.9 |
| Ourivski–Johansson (OJ1) [20] | 150.3 | 16.3 | |
| Ourivski–Johansson (OJ2) [20] | 249.4 | 15.1 | |
| GRS [21] | 160.8 | 19.2 | |
| Improved GRS [22] | 141.8 | 19.0 | |
| Guessing-Enhanced GRS [23] | 141.8 | 19.0 | |
| Annulator Polynomial [24] | 157.9 | 13.6 | |
| Algebraic | MaxMinors [18] | 130.7 | 40.5 |
| Support Minors [25] | 145.1 | 53.0 | |
| Security level achieved | — | ||
| Cat. | Scheme | Framework | Target | Size (KB) | Prov. (ms) | Verif. (ms) |
|---|---|---|---|---|---|---|
| (I) | ZKBoo [2] | MPCitH | SHA-1 | 441 | 19 | 11 |
| ZKB++ [14] | MPCitH | SHA-1 | 226 | 26 | 10 | |
| (II) | Generic MPCitH | ZKB++-style | RSD | ≈8300 | ≈1200 | ≈600 |
| Ours | MPCitH | RSD | 21 | 14 |
| Operation | Per Round | Total () |
|---|---|---|
| multiplications (prover) | ≈ | |
| multiplications (verifier) | ≈ | ≈ |
| additions (prover) | ≈ | ≈ |
| Hash calls (SHA3-256), prover | 4 | 877 |
| Hash calls (SHA3-256), verifier | 3 | 658 |
| PRG calls (SHAKE-256), prover | 3 | 657 |
| PRG calls (SHAKE-256), verifier | 2 | 438 |
| Commitment operations (=hash calls) | 4 | 876 |
| Quantity | Value |
|---|---|
| Proof generation (prover) | 21 ms |
| Proof verification | 14 ms |
| Proof size | KB |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Tang, X.; Qiao, K.; Wu, Q.; Wang, L. MPC-in-the-Head Zero-Knowledge Proof for Rank Syndrome Decoding via Mixed-Field Secret Sharing. Cryptography 2026, 10, 35. https://doi.org/10.3390/cryptography10030035
Tang X, Qiao K, Wu Q, Wang L. MPC-in-the-Head Zero-Knowledge Proof for Rank Syndrome Decoding via Mixed-Field Secret Sharing. Cryptography. 2026; 10(3):35. https://doi.org/10.3390/cryptography10030035
Chicago/Turabian StyleTang, Xueyi, Kexin Qiao, Qinghao Wu, and Licheng Wang. 2026. "MPC-in-the-Head Zero-Knowledge Proof for Rank Syndrome Decoding via Mixed-Field Secret Sharing" Cryptography 10, no. 3: 35. https://doi.org/10.3390/cryptography10030035
APA StyleTang, X., Qiao, K., Wu, Q., & Wang, L. (2026). MPC-in-the-Head Zero-Knowledge Proof for Rank Syndrome Decoding via Mixed-Field Secret Sharing. Cryptography, 10(3), 35. https://doi.org/10.3390/cryptography10030035



