An incomplete guide to Folding: Nova, Sangria, SuperNova, HyperN… — Taiko Labs
In this article, we explore the folding scheme technique that can be applied to achieve a more efficient approach to the IVC when verifying a single proof verifies the entire computation chain.
Special thanks to arnaucube **,* Brecht Devos , Barak, Benedikt Bünz , Binyi Chen , and Ben Wan for review.* TL;DR The goal, the whole zk industry is working on, – is to (i) decrease the proof generation cost as much as possible while (ii) preserving proof as small as possible and (iii) verification as efficient as possible. It’s possible through prover optimisation or, as an alternative, one can compress the data the prover proves. Huge work was done on folding scheme techniques within the last several years by the zk scientific community. In this article, we explore the folding scheme techni
related reading
- 370.pdfeprint.iacr.org
- Protogalaxy: Efficient Protostar-style folding of multiple instances[0.72cm]eprint.iacr.org
- 17 misconceptions about SNARKs - a16z cryptoa16zcrypto.com
- Towards a Nova-based ZK VM - General - zk researchzkresear.ch
- ProofsArgsAndZK.pdfpeople.cs.georgetown.edu
- Explaining Halo 2 - Electric Coin Companyelectriccoin.co
- Flock: Fast Proving for Batch Boolean Computationseprint.iacr.org
- Zero Knowledge Canon, part 1 & 2 - a16z cryptoa16zcrypto.com
- WHIR: Reed–Solomon Proximity Testing with Super-Fast Verificationeprint.iacr.org
- ZK-Friendly Hash Functions | Zellic — Researchzellic.io
- Putting the zk in zkVM: Jolt now supports zero knowledge - a16z cryptoa16zcrypto.com
- Marlin: Preprocessing zkSNARKs with Universal and Updatable SRSeprint.iacr.org