Benedikt Bünz - Linear*-Time Permutation Check
Автор: CMU × LayerZero Crypto Seminar
Загружено: 2025-11-13
Просмотров: 126
Описание:
Permutation and lookup arguments are at the core of most deployed SNARK protocols today. Most modern techniques for performing them require a grand product check. This requires either committing to large field elements (E.g. in Plonk) or using GKR (E.g. in Spartan) which has worse verifier cost and proof size. Sadly, both have a soundness error that grows linearly with the input size.
We present two permutation arguments that have almost linear proving time and polylog(n)/|F| soundness error. Moreover, the arguments achieve log(n) verification cost and proof size without ever needing to commit to anything beyond the witness. Our permutation arguments generalize to lookups. We demonstrate how our arguments can be used to improve SNARK systems such as HyperPlonk and Spartan, and build a GKR-based protocol for proving nonuniform circuits.
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: