Bulletproofs++: Next Generation Confidential Transactions via Reciprocal Set Membership Arguments
Liam Eagen, Sanket Kanjalkar, Tim Ruffing, Jonas Nick
Abstract
Zero-knowledge proofs are a cryptographic cornerstone of privacy-preserving technologies such as "Confidential Transactions" (CT), which aims at hiding monetary amounts in cryptocurrency transactions. Due to its asymptotically logarithmic proof size and transparent setup, most state-of-the-art CT protocols use the Bulletproofs (BP) zero-knowledge proof system for set membership proofs such as range proofs. However, even taking into account recent efficiency improvements, BP comes with a serious overhead in terms of concrete proof size as well as verifier running time and thus puts a large burden on practical deployments of CT and its extensions.
In this work, we introduce Bulletproofs++ (BP++), a drop-in replacement for BP that improves its concrete efficiency and compactness significantly. As for BP, the security of BP++ relies only on the hardness of the discrete logarithm problem in the random oracle model, and BP++ retains all features of Bulletproofs including transparent setup and support for proof aggregation, multi-party proving and batch verification. Asymptotically, BP++ range proofs require only group scalar multiplications compared to for BP and BP+.
At the heart of our construction are novel techniques for permutation and set membership, which enable us to prove statements encoded as arithmetic circuits very efficiently. Concretely, a single BP++ range proof to establish that a committed value is in a 64-bit range (as commonly required by CT) is just 416 bytes over a 256-bit elliptic curve, 38% smaller than an equivalent BP and 27% smaller than BP+. When instantiated using the secp256k1 curve as used in Bitcoin, our benchmarks show that proving is about 5 times faster than BP and verification is about 3 times faster than BP. When aggregating 32 range proofs, proving and verification are about 9.5 times and 5.5 times faster, respectively.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 01cb727a-2a75-44a8-824c-206334b46b34Cited by top-tier papers5
- QV-net: Decentralized Self-Tallying Quadratic Voting with Maximal Ballot SecrecyZibo Zhou, Zongyang Zhang, Feng Hao, Bowen Zheng et al.CCS 2025 · 1 citation
- SoK: Understanding zk-SNARKs: The Gap Between Research and PracticeJunkai Liang, Daqi Hu, Pengfei Wu, Yunbo Yang et al.USENIX Security 2025
- BulletCT: Towards More Scalable Ring Confidential Transactions With Transparent SetupNan Wang, Qianhui Wang, Dongxi Liu, Muhammed F. Esgin et al.USENIX Security 2025
- Just One Bit Vector: Complement-Free Ring Confidential Transactions with Transparent SetupHao Gao, Qianhong Wu, Bo Qin, Fudong Wu et al.USENIX Security 2026
- Revisiting Keyed-Verification Anonymous CredentialsMichele OrrùCCS 2025
Related papers
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- SwiftRange: A Short and Efficient Zero-Knowledge Range Argument For Confidential Transactions and MoreNan Wang, Sid Chi-Kin Chau, Dongxi LiuS&P 2024 · 13 citations
- Sharp: Short Relaxed Range ProofsGeoffroy Couteau, Dahmun Goudarzi, Michael Klooß, Michael ReichleCCS 2022 · 14 citations
- Efficient Range Proofs with Transparent Setup from Bounded Integer CommitmentsGeoffroy Couteau, Michael Klooß, Huang Lin, Michael ReichleEUROCRYPT 2021 · 37 citations
- Compressed -Protocol Theory and Practical Application to Plug & Play Secure AlgorithmicsThomas Attema, Ronald CramerCRYPTO 2020 · 73 citations
