Polymath: Groth16 Is Not the Limit
Helger Lipmaa
Abstract
Shortening the argument (three group elements or 1536 / 3072 bits over the BLS12-381/BLS24-509 curves) of the Groth16 zk-SNARK for R1CS is a long-standing open problem. We propose a zk-SNARK Polymath for the Square Arithmetic Programming constraint system using the KZG polynomial commitment scheme. Polymath has a shorter argument (1408 / 1792 bits over the same curves) than Groth16. At 192-bit security, Polymath's argument is nearly half the size, making it highly competitive for high-security future applications. Notably, we handle public inputs in a simple way. We optimized Polymath's prover through an exhaustive parameter search. Polymath's prover does not output elements, aiding in batch verification, SNARK aggregation, and recursion. Polymath's properties make it highly suitable to be the final SNARK in SNARK compositions.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6f415ee4-6b9d-4c8b-a9c7-b14871c7cd70Cited by top-tier papers1
Ask how each one uses itRelated papers
- Soloist: Distributed SNARK for R1CS with Constant Proof SizeWeihan Li, Zongyang Zhang, Yun Li, Pengfei Zhu et al.EUROCRYPT 2026
- Constant-Size zk-SNARKs in ROM from Falsifiable AssumptionsHelger Lipmaa, Roberto Parisella, Janno SiimEUROCRYPT 2024 · 14 citations
- RedShift: Transparent SNARKs from List Polynomial CommitmentsAssimakis A. Kattis, Konstantin Panarin, Alexander VlasovCCS 2022 · 15 citations
- Families of SNARK-Friendly 2-Chains of Elliptic CurvesYoussef El Housni, Aurore GuillevicEUROCRYPT 2022 · 29 citations
- Concretely Efficient Lattice-Based Polynomial Commitment from Standard AssumptionsIntak Hwang, Jinyeong Seo, Yongsoo SongCRYPTO 2024 · 9 citations
