Wasp: Succinct Non-Interactive Zero-Knowledge Proofs from VOLE
Zhanpeng Guo, Zhelei Zhou, Yun Li, Chenkai Weng, Cheng Hong, Tao Wei
Abstract
Zero-knowledge proofs (ZKPs) based on vector oblivious linear evaluation (VOLE) excel in prover efficiency but typically require linear communication and verification. Antman (Weng et al., CCS '22) introduced information-theoretic polynomial authentication codes (IT-PACs) to achieve sublinear communication: for SIMD (single-instruction-multiple-data) circuits and for general circuits, where is the total circuit size and are batch size and subcircuit size, respectively. Antman++ (Bui et al., J. Cryptol. '25) further reduced the general-case communication to . However, these protocols remain interactive and cannot be made non-interactive via traditional techniques like Fiat-Shamir, due to limited functionalities of IT-PACs; also, the verifier of Antman++ is not succinct for processing public matrices.
In this work, we present a succinct non-interactive ZKP system . Specifically, (1) we enhance the IT-PAC primitive to a fully functional polynomial commitment scheme (PCS) with the support of generic evaluation openings. With this PCS, we construct , a non-interactive ZKP for SIMD circuits based on Antman; also, we build , a general zkSNARK with constant verifier time and proof size based on the Plonkish constraint system. (2) We optimize the SIMD-to-general compiler from Antman++ by exploiting sparse representation of matrices and extending preprocessing techniques to the SIMD setting, and achieve a sublinear verifier. All our protocols achieve non-interactivity in the VOLE-hybrid model (i.e., given preprocessed VOLE correlations). Experiments show the non-interactive verifier of our SIMD zkSNARK is orders of magnitude faster than the interactive one of Antman; when compiled with our compiler, the general-case verifier is orders of magnitude faster than the one in Antman++. Our general zkSNARK has a orders of magnitude faster prover than pairing-based, coding-based and lattice-based zkSNARKs, with less than 1 ms verifier time and 122 KB proof size; compared to the non-succinct VOLE-based ZKP, is slower in proving but can be 4 orders of magnitude faster in verification with orders of magnitude smaller proof size.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 180052fa-be2b-43af-979a-61ae241f0abdRelated papers
- Spartan: Efficient and General-Purpose zkSNARKs Without Trusted SetupSrinath T. V. SettyCRYPTO 2020 · 262 citations
- Soloist: Distributed SNARK for R1CS with Constant Proof SizeWeihan Li, Zongyang Zhang, Yun Li, Pengfei Zhu et al.EUROCRYPT 2026
- Wolverine: Fast, Scalable, and Communication-Efficient Zero-Knowledge Proofs for Boolean and Arithmetic CircuitsChenkai Weng, Kang Yang, Jonathan Katz, Xiao WangS&P 2021 · 205 citations
- Mac'n'Cheese: Zero-Knowledge Proofs for Boolean and Arithmetic Circuits with Nested DisjunctionsCarsten Baum, Alex J. Malozemoff, Marc B. Rosen, Peter SchollCRYPTO 2021 · 77 citations
- SubLogarithmic Linear Time SNARKs from Improved SumcheckSikhar Patranabis, Nitin Singh, Sayani SinhaCCS 2026
