ZEE200: Zero Knowledge for Everything and Everyone @ 200 KHz
Sunghyeon Jo, Vladimir Kolesnikov, Yibin Yang
Abstract
Zero-knowledge execution of high-level programs proceeds by repeatedly evaluating CPU steps. Each such step privately selects and evaluates an instruction (possibly involving memory access) from a rich instruction set. Building on this paradigm, ZEE (Heath et al., S&P'21) realized a full toolchain supporting arbitrary ANSI C programs, demonstrating this capability by proving SIR-and CVE-reported bugs in off-the-shelf Linux programs sed and gzip. We revamp the state of the art by building a new ZK system ZEE200, which is about 20-40× faster than ZEE. ZEE200 is built on a novel and convenient cryptographic framework for efficiently proving general statements represented as real-world programs. Our framework integrates several crucial recent advances, such as Tight ZK CPU (Yang et al., CCS'24) and fast ZK RAM (Yang and Heath, USENIX Security'24). We develop better encodings for Z 2 32 arithmetic, and numerous low-level optimizations. Compared to ZEE's ≈10 KHz CPU speed on a limited ISA, ZEE200 runs at ≈200 KHz (still on a commodity laptop and a LAN!), while supporting a much richer ISA. For example, we rerun a ZEE's benchmark, proving a SIR-reported vulnerability in off-the-shelf Linux utility sed. On a 2021 ThinkPad X1 Carbon Gen 9 under a simulated 1 Gbps LAN (single-threaded), ZEE200 completed the proof in 1.5 seconds, compared to ZEE's 30.1 seconds, a 20× improvement.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6e86df20-d082-4009-b897-dbba8505d863Builds on31
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- Sonic: Zero-Knowledge SNARKs from Linear-Size Universal and Updatable Structured Reference StringsMary Maller, Sean Bowe, Markulf Kohlweiss, Sarah MeiklejohnCCS 2019 · 412 citations
- Marlin: Preprocessing zkSNARKs with Universal and Updatable SRSAlessandro Chiesa, Yuncong Hu, Mary Maller, Pratyush Mishra et al.EUROCRYPT 2020 · 356 citations
- Ligero: Lightweight Sublinear Arguments Without a Trusted SetupScott Ames, Carmit Hazay, Yuval Ishai, Muthuramakrishnan VenkitasubramaniamCCS 2017 · 338 citations
- Compressing Vector OLEElette Boyle, Geoffroy Couteau, Niv Gilboa, Yuval IshaiCCS 2018 · 220 citations
Related papers
- Zero Knowledge for Everything and Everyone: Fast ZK Processor with Cached ORAM for ANSI C ProgramsDavid Heath, Yibin Yang, David Devecsery, Vladimir KolesnikovS&P 2021 · 22 citations
- Tight ZK CPU: Batched ZK Branching with Cost Proportional to Evaluated InstructionYibin Yang, David Heath, Carmit Hazay, Vladimir Kolesnikov et al.CCS 2024 · 5 citations
- A 2.1 KHz Zero-Knowledge Processor with BubbleRAMDavid Heath, Vladimir KolesnikovCCS 2020 · 15 citations
- Evaluating Compiler Optimization Impacts on zkVM PerformanceThomas Gassmann, Stefanos Chaliasos, Thodoris Sotiropoulos, Zhendong SuASPLOS 2026 · 2 citations
- Efficient Branch-and-Bound Testing and Verification of zkVMsHideaki Takahashi, Suman Jana, Junfeng YangCCS 2026
