Skip to content
Research noteZK-2026-0204

A folding scheme that drops the SIMD requirement

Microsoft Research revises Neo and SuperNeo, lattice-based folding aimed at post-quantum security without giving up small fields.

2 minZero-Knowledge Proofs

Wilson Nguyen and Srinath Setty of Microsoft Research posted a revision of Neo and SuperNeo on 14 August; the paper was first received in February. The pair are lattice-based folding schemes built on the Module-SIS assumption with Ajtai commitments, supporting CCS relations over arbitrary extension fields.

The claim is a combination rather than a single result. The authors argue their construction achieves plausible post-quantum security, pay-per-bit commitment costs, field-native arithmetic, support for general constraint systems rather than only SIMD ones, compatibility with small fields such as Goldilocks, and low recursion overhead — all at once.

Why the combination is the point

The abstract sets out what each existing family gives up. Group-based schemes are not post-quantum. Other lattice-based schemes pay for their security in efficiency. Hash-based alternatives need verification circuits expensive enough to hurt in recursion.

The difference between the two schemes is the constraint. Neo requires SIMD-shaped constraints; SuperNeo removes that requirement, which is what makes it applicable to general circuits rather than to workloads that happen to be uniform.

One thing to be clear about: the abstract carries no performance figures. The efficiency claims are structural — a single sum-check invocation over a small field extension, pay-per-bit commitment costs — and until someone publishes measurements against an existing scheme, that is an argument about asymptotics rather than a benchmark.

Retold from IACR ePrint. This is a summary in our own words; follow the link for the original reporting.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined