Horst Meets Fluid-SPN: Griffin for Zero-Knowledge Applications
Lorenzo Grassi, Yonglin Hao, Christian Rechberger, Markus Schofnegger, Roman Walch, Qingju Wang
Abstract
Zero-knowledge (ZK) applications form a large group of use cases in modern cryptography, and recently gained in popularity due to novel proof systems. For many of these applications, cryptographic hash functions are used as the main building blocks, and they often dominate the overall performance and cost of these approaches.
Therefore, in the last years several new hash functions were built in order to reduce the cost in these scenarios, including Poseidon and Rescue among others. These hash functions often look very different from more classical designs such as AES or SHA-2. For example, they work natively over prime fields rather than binary ones. At the same time, for example Poseidon and Rescue share some common features, such as being SPN schemes and instantiating the nonlinear layer with invertible power maps. While this allows the designers to provide simple and strong arguments for establishing their security, it also introduces crucial limitations in the design, which may affect the performance in the target applications.
In this paper, we propose the Horst construction, in which the addition in a Feistel scheme (x, y) -> (y + F(x), x) is extended via a multiplication, i.e., (x, y) -> (y * G(x) + F(x), x).
By carefully analyzing the performance metrics in SNARK and STARK protocols, we show how to combine an expanding Horst scheme with a Rescue-like SPN scheme in order to provide security and better efficiency in the target applications. We provide an extensive security analysis for our new design Griffin and a comparison with all current competitors.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get e6dc36d7-58a0-4c0c-aafa-1e749143d950Cited by top-tier papers4
- The Algebraic FreeLunch: Efficient Gröbner Basis Attacks Against Arithmetization-Oriented PrimitivesAugustin Bariant, Aurélien Boeuf, Axel Lemoine, Irati Manterola Ayala et al.CRYPTO 2024 · 17 citations
- Improved Resultant Attack Against Arithmetization-Oriented PrimitivesAugustin Bariant, Aurélien Boeuf, Pierre Briaud, Maël Hostettler et al.CRYPTO 2025 · 4 citations
- Boosting Efficiency and Security in Arithmetization-Oriented Hashing for Zero-Knowledge Proof SystemsElena Andreeva, Rishiraj Bhattacharyya, Arnab Roy, Stefano TrevisaniUSENIX Security 2026
- Eva: Efficient Privacy-Preserving Proof of Authenticity for Lossily Encoded VideosChengru Zhang, Xiao Yang, David F. Oswald, Mark Ryan et al.S&P 2025
Related papers
- Poseidon: A New Hash Function for Zero-Knowledge Proof SystemsLorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy et al.USENIX Security 2021 · 410 citations
- New Design Techniques for Efficient Arithmetization-Oriented Hash Functions: ttAnemoi Permutations and ttJive Compression ModeClémence Bouvier, Pierre Briaud, Pyrros Chaidos, Léo Perrin et al.CRYPTO 2023 · 37 citations
- Reinforced Concrete: A Fast Hash Function for Verifiable ComputationLorenzo Grassi, Dmitry Khovratovich, Reinhard Lüftenegger, Christian Rechberger et al.CCS 2022 · 34 citations
- Graeffe-Based Attacks on Poseidon and NTT Lower BoundsZiyu Zhao, Antonio Sanso, Giuseppe Vitto, Jintai DingCRYPTO 2026 · 2 citations
- AcclMT: A Highly Resource-Efficient and Flexible Poseidon Hash-Based Merkle Tree ArchitectureChangxu Liu, Hao Zhou, Lan Yang, Yifei Feng et al.DAC 2025
