freenode
Internet & Protocols

CFRG opens adoption call for Longfellow ZK proof system

The post-quantum zero-knowledge draft already ships in Google Wallet and India’s UIDAI, with multiple independent implementations backing group change control.

The IRTF Crypto Forum Research Group has opened a two-week call for adoption of Longfellow ZK, a post-quantum zero-knowledge argument system designed for constrained devices and real-world identity statements.

Chair Nick Sullivan started the call on 25 September for draft-google-cfrg-libzk-03 by Matteo Frigo and Abhi Shelat. It ends 9 October 2026. Adoption would move change control to the research group. The authors have said they are ready.

The specification targets proofs that run on limited hardware while remaining expressive enough for ECDSA, SHA-256 and ML-DSA signature checks, string, integer and date comparisons, and basic parsing. Its Fiat-Shamir layer builds on the transformation CFRG has already adopted. The authors have presented at several IETF meetings, incorporated external review, and plan to release a Lean 4 formalization of the protocol and key circuits once internal review finishes. At least two independent groups have already implemented from the draft.

Outside the IETF the work appears in eIDAS and EU age-assurance documentation and is deployed in Google Wallet digital identities and India’s UIDAI application. Other IETF drafts intend to build on it.

Support on the list has been broad and practical. Implementers and reviewers from Yubico, ISRG and elsewhere backed adoption and offered further review or code. Several noted the value of an open venue for a scheme already in wide deployment, including privacy-preserving age checks and authentication that reuses existing ECDSA credentials without new trusted setup. One embedded-systems engineer asked that post-adoption work cover memory and compute guidance for constrained platforms and clarify that proofs over classical ECDSA credentials still inherit ECDSA’s quantum limits even though the proof system itself is post-quantum.

No objections naming a specific problem with the document or with CFRG taking it on had appeared in the early replies.