Brakedown: Linear-Time and Field-Agnostic SNARKs for R1CS
Alexander Golovnev, Jonathan Lee, Srinath T. V. Setty, Justin Thaler, Riad S. Wahby
摘要
This paper introduces Brakedown, the first built system that provides linear-time SNARKs for NP, meaning the prover incurs finite field operations to prove the satisfiability of an -sized R1CS instance. Brakedown’s prover is faster, both concretely and asymptotically, than prior SNARK implementations. Brakedown does not require a trusted setup and is plausibly post-quantum secure. Furthermore, it is compatible with arbitrary finite fields of sufficient size; this property is new amongst implemented arguments with sublinear proof sizes.
To design Brakedown, we observe that recent work of Bootle, Chiesa, and Groth (BCG, TCC 2020) provides a polynomial commitment scheme that, when combined with the linear-time interactive proof system of Spartan (CRYPTO 2020), yields linear-time IOPs and SNARKs for R1CS (a similar theoretical result was previously established by BCG, but our approach is conceptually simpler, and crucial for achieving high-speed SNARKs). A core ingredient in the polynomial commitment scheme that we distill from BCG is a linear-time encodable code. Existing constructions of such codes are believed to be impractical. Nonetheless, we design and engineer a new one that is practical in our context.
We also implement a variant of Brakedown that uses Reed-Solomon codes instead of our linear-time encodable codes; we refer to this variant as Shockwave. Shockwave is not a linear-time SNARK, but it provides shorter proofs and lower verification times than Brakedown (it also provides a faster prover than prior plausibly post-quantum SNARKs).
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper22
- Accelerating Zero-Knowledge Proofs Through Hardware-Algorithm Co-DesignNikola Samardzic, Simon Langowski, Srinivas Devadas, Daniel SánchezMICRO 2024 · 被引用 24 次
- Blaze: Fast SNARKs from Interleaved RAA CodesMartijn Brehm, Binyi Chen, Ben Fisch, Nicolas Resch 等EUROCRYPT 2025 · 被引用 15 次
- IOPs with Inverse Polynomial Soundness ErrorGal Arnon, Alessandro Chiesa, Eylon YogevFOCS 2023 · 被引用 13 次
- Cirrus: Performant and Accountable Distributed SNARKWenhao Wang, Fangyan Shi, Dani Vilardell, Fan ZhangNDSS 2026 · 被引用 11 次
- Fast RS-IOP Multivariate Polynomial Commitments and Verifiable Secret SharingZongyang Zhang, Weihan Li, Yanpei Guo, Kexin Shi 等USENIX Security 2024 · 被引用 9 次
相关 Paper
- Field-Agnostic SNARKs from Expand-Accumulate CodesAlexander R. Block, Zhiyong Fang, Jonathan Katz, Justin Thaler 等CRYPTO 2024 · 被引用 12 次
- Bolt: Faster SNARKs from Sketched CodesKobi Gurkan, Andrija Novakovic, Ron D. RothblumCRYPTO 2026 · 被引用 4 次
- Spartan: Efficient and General-Purpose zkSNARKs Without Trusted SetupSrinath T. V. SettyCRYPTO 2020 · 被引用 262 次
- Succinct Arguments over Towers of Binary FieldsBenjamin E. Diamond, Jim PosenEUROCRYPT 2025 · 被引用 12 次
- BaseFold: Efficient Field-Agnostic Polynomial Commitment Schemes from Foldable CodesHadas Zeilberger, Binyi Chen, Ben FischCRYPTO 2024 · 被引用 38 次
