# Post-Quantum Proving

> Initiatives QL-01 and QL-02. A lattice commitment in place of the pairing-based one, and a field chosen to match it, so that the proving core no longer rests on discrete logarithms.

QL-01 · QL-02 Lattice commitments Re-fielding Status: active development

## What breaks, and where

Every cryptographic assumption under Apogee v1.0.0 involves BN254. Mercury and KZG are sound under q-DLOG in the algebraic group model; the recursion tree folds pairing checks; the decider is Groth16. Shor's algorithm solves discrete logarithms on a quantum computer of sufficient size, and with them every one of these assumptions. The guest's computation would still be what it was; the proof that it ran correctly would no longer mean anything.

The commitment is where the dependence is concentrated. Every column of every shard is committed with it, every opening ends in its pairing, and recursion exists to fold those pairings. Replace the commitment, and the rest of the proving core has nothing left that depends on a discrete logarithm.

## QL-01 · Lattice commitments

A lattice commitment is a linear map, `t = A·s mod q`, applied to a vector `s` with small entries. It is binding as long as nobody can find a short vector the matrix sends to zero: Module-SIS, the assumption family under ML-DSA and ML-KEM, NIST's post-quantum standards, with worst-case reductions and decades of cryptanalysis behind it.

It keeps what made KZG so useful to Apogee and that hash-based commitments give up: **it is homomorphic.** Commitments to many chunks combine under challenge coefficients, and the combination opens by a single vector. Batching a shard's columns, deferring checks and folding them up a tree are linear operations, and linear operations survive the move. Merkle paths cannot be combined at all.

The price is a constraint with no analogue elsewhere: the commitment binds only short vectors, every combination makes the vector longer, and the prover must show it is still short enough. The schemes of the last two years differ mainly in how they pay that price, and they have moved fast. For polynomials of `2^30` coefficients, the published Module-SIS schemes give evaluation proofs of **53 to 72 KB**, and verification fell from 2.8 seconds in 2024 to **8 to 16 milliseconds** in 2026. The expository [Lattice-Based Polynomial Commitment Schemes](https://www.gweb3networks.com/expositories/lattice-based-polynomial-commitments.html) surveys them scheme by scheme and reads the numbers against the hash-based side.

## QL-02 · Re-fielding

The lattice schemes do not live in BN254's world. The leading constructions work over small prime moduli, with evaluation points drawn from an extension field to keep soundness, which fits a small-field proof system and does not fit a 254-bit one. So the commitment's move brings the field with it: v2.0.0 **re-fields the arithmetization**, moving every circuit from BN254's scalar field to a small field matched to the commitment.

The move pays for itself:

- **Every layer gets cheaper.** A GKR prover spends its time in field arithmetic, and a multiplication in a small field is a fraction of one in a 254-bit field. The engine's central economy, that intermediate layers are never committed, compounds with cheaper arithmetic on every layer that remains.
- **Commitments get cheaper.** Committing a trace column is a linear map over small digits, paid per nonzero entry, rather than a multi-scalar multiplication over a curve.
- **The engine carries over.** GKR and sumcheck are defined over any field. Challenges move to an extension field; the backward pass, the layer model and the arguments built on it keep their structure.

What has to be rebuilt is everything that assumed a large field: word-level values that fit one BN254 element with room to spare, range arguments and carries sized against a 254-bit modulus, canonicity chains, and the recursion format's field cells. Each is re-derived for the new field and specified as v1.0.0's were, with its own oracle and tamper twins.

## Settlement

Ethereum's verification precompiles today are pairing-based. How a post-quantum proving core settles on that chain, and what of the final step can rest on lattices, is part of the same programme of work, and will be specified with the same care as the core before it ships.

Back to the [mission brief](https://apogee.gweb3networks.com/docs/quantum-leap).
