Lune

CCS2026Top-tier venue

Wasp: Succinct Non-Interactive Zero-Knowledge Proofs from VOLE

Zhanpeng Guo, Zhelei Zhou, Yun Li, Chenkai Weng, Cheng Hong, Tao Wei

2026Year

Abstract

Zero-knowledge proofs (ZKPs) based on vector oblivious linear evaluation (VOLE) excel in prover efficiency but typically require linear communication and verification. Antman (Weng et al., CCS '22) introduced information-theoretic polynomial authentication codes (IT-PACs) to achieve sublinear communication: O(B+C)O(B + C) for SIMD (single-instruction-multiple-data) circuits and O(B3+C)O(B^3 + C) for general circuits, where N=B⋅CN=B \cdot C is the total circuit size and B,CB,C are batch size and subcircuit size, respectively. Antman++ (Bui et al., J. Cryptol. '25) further reduced the general-case communication to O(B+C)O(B + C). However, these protocols remain interactive and cannot be made non-interactive via traditional techniques like Fiat-Shamir, due to limited functionalities of IT-PACs; also, the verifier of Antman++ is not succinct for processing N×NN\times N public matrices.

In this work, we present a succinct non-interactive ZKP system Wasp\mathsf{Wasp}. Specifically, (1) we enhance the IT-PAC primitive to a fully functional polynomial commitment scheme (PCS) with the support of generic evaluation openings. With this PCS, we construct WaspS\mathsf{Wasp^S}, a non-interactive ZKP for SIMD circuits based on Antman; also, we build WaspG\mathsf{Wasp^G}, a general zkSNARK with constant verifier time and proof size based on the Plonkish constraint system. (2) We optimize the SIMD-to-general compiler from Antman++ by exploiting sparse representation of matrices and extending preprocessing techniques to the SIMD setting, and achieve a sublinear verifier. All our protocols achieve non-interactivity in the VOLE-hybrid model (i.e., given preprocessed VOLE correlations). Experiments show the non-interactive verifier of our SIMD zkSNARK WaspS\mathsf{Wasp^S} is 1∼21\sim 2 orders of magnitude faster than the interactive one of Antman; when compiled with our compiler, the general-case verifier is 2∼32\sim 3 orders of magnitude faster than the one in Antman++. Our general zkSNARK WaspG\mathsf{Wasp^G} has a 1∼21\sim 2 orders of magnitude faster prover than pairing-based, coding-based and lattice-based zkSNARKs, with less than 1 ms verifier time and 122 KB proof size; compared to the non-succinct VOLE-based ZKP, WaspG\mathsf{Wasp^G} is 3∼22×3\sim22\times slower in proving but can be 4 orders of magnitude faster in verification with 33 orders of magnitude smaller proof size.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 180052fa-be2b-43af-979a-61ae241f0abd

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines