BABE: Verifying Proofs on Bitcoin Made 1000x Cheaper
Sanjam Garg, Dimitris Kolonelos, Mikhail Sergeevitch, Srivatsan Sridhar, David Tse
摘要
Endowing Bitcoin with the ability to verify succinct proofs has been a longstanding problem with important applications such as scaling Bitcoin and allowing the Bitcoin asset to be used in other blockchains trustlessly. It is a challenging problem due to the lack of expressiveness in the Bitcoin scripting language and the small Bitcoin block space. BitVM2 [LAA + 25] is the state-of-the-art verification protocol for Bitcoin used in several mainnets and testnets [Bit25a, Cit25, BOB25a], but it suffers from very high on-chain Bitcoin transaction fees in the unhappy path (over $14, 000 in a recent experiment [LAA + 25]). Recent research BitVM3 dramatically reduces this on-chain cost by using a garbled SNARK verifier circuit to shift most of the verification off-chain [Rub24, Lin24], but each garbled circuit is 42 GiBytes in size, so the off-chain storage and setup costs are huge. This paper introduces BABE, a new proof verification protocol on Bitcoin, which preserves BitVM3's savings of on-chain costs but reduces its off-chain storage and setup costs by three orders-of-magnitude. BABE uses a witness encryption scheme for linear pairing relations [GKPW24] to verify Groth16 proofs. Since Groth16 verification involves non-linear pairings, this witness encryption scheme is augmented with a secure two-party computation protocol implemented using a very efficient garbled circuit for scalar multiplication on elliptic curves. The design of this garbled circuit builds on the recent work of Argo MAC [EL26], a garbling primitive that efficiently computes homomorphic MACs on such curves.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper12
- Threshold Encryption with Silent SetupSanjam Garg, Dimitris Kolonelos, Guru-Vamsi Policharla, Mingyuan WangCRYPTO 2024 · 被引用 31 次
- Succinct Zero-Knowledge Batch Proofs for Set AccumulatorsMatteo Campanelli, Dario Fiore, Semin Han, Jihye Kim 等CCS 2022 · 被引用 22 次
- How to Prove Statements Obliviously?Sanjam Garg, Aarushi Goel, Mingyuan WangCRYPTO 2024 · 被引用 22 次
- Efficiently-Thresholdizable Batched Identity Based Encryption, with ApplicationsAmit Agarwal, Rex Fernando, Benny PinkasCRYPTO 2025 · 被引用 12 次
- Bridging Bitcoin to Second Layers via BitVM2Robin Linus Woll, Lukas Aumayr, Zeta Avarikioti, Matteo Maffei 等USENIX Security 2026 · 被引用 6 次
相关 Paper
- Duty-Free Bits: Projectivizing Garbling SchemesNakul Khambhati, Anwesh Bhattacharya, David HeathCCS 2026
- Garuda and Pari: Faster and Smaller SNARKs via Equifficient Polynomial CommitmentsMichel Dellepere, Pratyush Mishra, Alireza ShirzadUSENIX Security 2026 · 被引用 12 次
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra 等S&P 2018 · 被引用 1,285 次
- Cryptographic Oracle-based Conditional PaymentsVarun Madathil, Sri Aravinda Krishnan Thyagarajan, Dimitrios Vasilopoulos, Lloyd Fournier 等NDSS 2023
- Recursion over Public-Coin Interactive Proof Systems; Faster Hash VerificationAlexandre Belling, Azam Soleimanian, Olivier BégassatCCS 2023 · 被引用 5 次
