Dynark: Making Groth16 Dynamic
Tianyu Zhang, Yupeng Ouyang, Yupeng Zhang
Abstract
In recent years, numerous new and more efficient constructions of zero-knowledge succinct non-interactive argument of knowledge (zkSNARK) have been proposed, motivated by their growing practical applications. However, in most schemes, when the witness is changed, the prover has to recompute the proof from scratch even if the new witness is close to the old one. This is inefficient for applications where proofs are generated for dynamically changing witnesses with small changes.
In this paper, we introduce DYNARK, a dynamic zkSNARK scheme that can update the proof in sublinear time when the change of the witness is small. DYNARK is built on top of the seminal zkSNARK protocol of Groth, 2016. In the semi-dynamic setting, for an R1CS of size , after a preprocessing of group operations on the original witness, it only takes group operations and field operations to update the proof for a new witness with distance from the original witness, which is nearly optimal. In the fully-dynamic setting, the update time of DYNARK is group operations and field operations. Both the proof size and the verifier time are , which are exactly the same as Groth16. Compared to the scheme in a prior work by Wang et al. 2024, we reduce the proof size from to without relying on pairing product arguments or another zkSNARK, and the update time and the verifier time of DYNARK are faster in practice.
Experimental results show that for , after a one-time preprocessing of 74.3 seconds, it merely takes 3 milliseconds to update the proof in our semi-dynamic zkSNARK for , and 60 milliseconds to update the proof in our fully-dynamic zkSNARK. These are 1433 and 73 faster than Groth16, respectively. The proof size is 192 bytes and the verifier time is 4.4 milliseconds. The system is fully compatible with any existing deployment of Groth16 without changing the trusted setup, the proof and the verification algorithm.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 63046186-2358-41fc-92de-33ace4e55776Cited by top-tier papers2
- Lighthouse: Single-Server Secure Aggregation with O(1) Server-Committee Communication at ScaleSanjam Garg, Alireza Kavousi, Dimitris Kolonelos, Erkan Tairi et al.USENIX Security 2026 · 1 citation
- Designated-Verifier Dynamic zk-SNARKs with Applications to Dynamic Proofs of IndexWeijie Wang, Charalampos Papamanthou, Shravan Srinivasan, Dimitrios PapadopoulosCCS 2026
Related papers
- Dynamic zk-SNARKs (with Applications to Sparse zk-SNARKs and IVC)Weijie Wang, Charalampos Papamanthou, Shravan Srinivasan, Dimitrios PapadopoulosEUROCRYPT 2026 · 1 citation
- Spartan: Efficient and General-Purpose zkSNARKs Without Trusted SetupSrinath T. V. SettyCRYPTO 2020 · 262 citations
- Orion: Zero Knowledge Proof with Linear Prover TimeTiancheng Xie, Yupeng Zhang, Dawn SongCRYPTO 2022 · 83 citations
- Soloist: Distributed SNARK for R1CS with Constant Proof SizeWeihan Li, Zongyang Zhang, Yun Li, Pengfei Zhu et al.EUROCRYPT 2026
- DFS: Delegation-friendly zkSNARK and Private Delegation of ProversYuncong Hu, Pratyush Mishra, Xiao Wang, Jie Xie et al.USENIX Security 2025
