USENIX Security2023Top-tier venue
VeriZexe: Decentralized Private Computation with Universal Setup
Alex Luoyuan Xiong, Binyi Chen, Zhenfei Zhang, Benedikt Bünz, Ben Fisch, Fernando Krell, Philippe Camacho
Abstract
Traditional blockchain systems execute program state transitions on-chain, requiring each network node participating in state-machine replication to re-compute every step of the program when validating transactions. This limits both scalability and privacy. Recently, Bowe et al. introduced a primitive called decentralized private computation (DPC) and provided an instantiation called ZEXE, which allows users to execute arbitrary computations off-chain without revealing the program logic to the network. Moreover, transaction validation takes only constant time, independent of the off-chain computation. However, ZEXE required a separate trusted setup for each application, which is highly impractical. Prior attempts to remove this per-application setup incurred significant performance loss. We propose a new DPC instantiation VERIZEXE that is highly efficient and requires only a single universal setup to support an arbitrary number of applications. Our benchmark improves the state-of-the-art by 9x in transaction generation time and by 3.4x in memory usage. Along the way, we also design efficient gadgets for variable-base multi-scalar multiplication and modular arithmetic within the PLONK constraint system, leading to a PLONK verifier gadget using only ∼ 21k constraints. Implementation Universal Setup Transaction Generation Memory Verification Proof Size Original ZEXE [12] ✗ 14.3 s 6.56 GB 15 ms 0.482 KB SnarkVM testnet-2 ✓ 151.4 s 22.81 GB 15 ms 0.482 KB VERIZEXE (this work) ✓ 16.9 s 6.61 GB 18 ms 4.138 KB 1 https://github.com/AleoHQ/snarkVM/tree/testnet1 2 The PLONK constraint system is very extensible from just add and mul gate to customized gates (TURBOPLONK), to support the lookup argument (ULTRAPLONK). These different flavors only affect the concrete encodings of the same constraint logic. Technically we encode a TURBOPLONK verifier in a ULTRAPLONK constraint system using 21k constraints. 3 Another promising application of our PLONK verifier gadget is private zkRollup protocols (such as Aztec [25] ) which aggregates already private transactions into a single rollup transaction with proof attesting to the correctness of all private transactions, achieving higher computation compression for the blockchain validator (who now only needs to verify the final rollup proof) while maintaining privacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 01dcc761-5687-4677-b65f-82e77e71df55Cited by top-tier papers3
- Need for zkSpeed: Accelerating HyperPlonk for Zero-Knowledge ProofsAlhad Daftardar, Jianqiao Mo, Joey Ah-kiow, Benedikt Bünz et al.ISCA 2025 · 12 citations
- zk-promises: Anonymous Moderation, Reputation, and Blocking from Anonymous Credentials with CallbacksMaurice Shih, Michael Rosenberg, Hari Kailad, Ian MiersUSENIX Security 2025
- Zero-Knowledge Location Privacy via Accurate Floating-Point SNARKsJens Ernstberger, Chengru Zhang, Luca Ciprian, Philipp Jovanovic et al.S&P 2025
Builds on8
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- Poseidon: A New Hash Function for Zero-Knowledge Proof SystemsLorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy et al.USENIX Security 2021 · 410 citations
- ZEXE: Enabling Decentralized Private ComputationSean Bowe, Alessandro Chiesa, Matthew Green, Ian Miers et al.S&P 2020 · 257 citations
- Transparent SNARKs from DARK CompilersBenedikt Bünz, Ben Fisch, Alan SzepieniecEUROCRYPT 2020 · 240 citations
- Solidus: Confidential Distributed Ledger Transactions via PVORMEthan Cecchetti, Fan Zhang, Yan Ji, Ahmed E. Kosba et al.CCS 2017 · 128 citations
Related papers
- GenZA: A General and Efficient Accelerator for Diverse Zero-Knowledge Proof ProtocolsCheng Wang, Jiangbin Dong, Mingyu GaoISCA 2026
- Pipelonk: Accelerating End-to-End Zero-Knowledge Proof Generation on GPUs for PLONK-Based ProtocolsZhiyuan Zhang, Yanxin Cai, Wenhao Yin, Xueyu Wu et al.PPoPP 2026 · 1 citation
- Hekaton: Horizontally-Scalable zkSNARKs Via Proof AggregationMichael Rosenberg, Tushar Mopuri, Hossein Hafezi, Ian Miers et al.CCS 2024 · 7 citations
- Scalable Collaborative zk-SNARK and Its Application to Fully Distributed Proof DelegationXuanming Liu, Zhelei Zhou, Yinghao Wang, Yanxin Pang et al.USENIX Security 2025
- Permissionless Verifiable Information Dispersal (Data Availability for Bitcoin Rollups)Ben Fisch, Arthur Lazzaretti, Zeyu Liu, Lei YangS&P 2025
