paper

Protocols for Univariate Sumcheck

arXiv:2505.00554

Abstract

Three candidate approaches for univariate sumcheck over roots of unity are presented. The first takes the form of a multilinear evaluation protocol, which can be combined with the standard multivariate sumcheck protocol. The other two are reductions from univariate domain identity and univariate sumcheck to multivariate evaluation, respectively, and each can be combined with Gemini (Bootle et al., Eurocrypt 2022). Optionally, natural round reductions from to or are supported, while retaining linear prover time.

To appear in APKC@AsiaCCS'26. Full version

Protocols for Univariate Sumcheck · wovepaper