Halo and more: exploring incremental verification and SNARKs without pairings
Special thanks to Justin Drake and Sean Bowe for wonderfully pedantic and thoughtful feedback and review, and to Pratyush Mishra for discussion that contributed to the original IPA exposition. Readers who have been following the ZK-SNARK space closely should by now be familiar with the high level of how ZK-SNARKs work. ZK-SNARKs are based on checking equations where the elements going into the equations are mathematical abstractions like polynomials (or in rank-1 constraint systems matrices and vectors) that can hold a lot of data. There are three major families of cryptographic technologies that allow us to represent these abstractions succinctly: Merkle trees (for FRI), regular elliptic curves (for inner product arguments (IPAs)), and elliptic curves with pairings and trusted setups (for KZG commitments). These three technologies lead to the three types of proofs: FRI leads to STARKs, KZG commitments lead to "regular" SNARKs, and IPA-based schemes lead to bulletproofs. These three te
Dark Mode Toggle Halo and more: exploring incremental verification and SNARKs without pairings 2021 Nov 05 See all posts Halo and more: exploring incremental verification and SNARKs without pairings Special thanks to Justin Drake and Sean Bowe for wonderfully pedantic and thoughtful feedback and review, and to Pratyush Mishra for discussion that contributed to the original IPA exposition. Readers who have been following the ZK-SNARK space closely should by now be familiar with the high level of how ZK-SNARKs work. ZK-SNARKs are based on checking equations where the elements going into the equa
Explore this link on the map →related reading
- 17 misconceptions about SNARKs - a16z cryptoa16zcrypto.com
- Explaining Halo 2 - Electric Coin Companyelectriccoin.co
- ProofsArgsAndZK.pdfpeople.cs.georgetown.edu
- Why and How zk-SNARK Works 1: Introduction & the Medium of a Proof | by Maksym | Mediummedium.com
- Zero Knowledge Canon, part 1 & 2 - a16z cryptoa16zcrypto.com
- Zero Knowledge Proofs: An illustrated primer – A Few Thoughts on Cryptographic Engineeringblog.cryptographyengineering.com
- STARKs, Part I: Proofs with Polynomialsvitalik.eth.limo
- Binius: highly efficient proofs over binary fieldsvitalik.eth.limo
- ZK-Friendly Hash Functions | Zellic — Researchzellic.io
- thesis.pdfaayushg.com
- Intern Breakdown #4: Zero-Knowledge Proofsinternbreakdowns.substack.com
- Inner Product Arguments · Dankrad Feistdankradfeist.de