Our new paper avoids arithmetization overhead for symmetric hashes and encryption, lattice-ring operations, and more! Instead of one field Fq, we support simultaneous constraints over Q[X] and Fq[X] for multiple q, plus ideal membership constraints. Unoptimized implementation is already hella fast 🔥
add a skeleton here at some point
20 days ago