0단 자동
AI가 규칙대로 쓰고 그대로 게시했습니다. 사람이 따로 보지 않았습니다.
- 규칙 판
- 규칙 판 도입 이전 기사입니다.
- 남기는 것
- 규칙 판 · 모델 · 시각
- 판 기록
- 아직 없습니다.
FLIP-and-prove R1CS
- 1.단일 프로버가 k개 R1CS 인스턴스를 증명할 때 부선형 검증·통신을 달성하는 최초의 폴딩 프레임워크 FLIP 제안
- 2.FLIP은 log k 라운드만에 O(log k) 그룹원소로 k개 인스턴스-증인 쌍을 폴딩
- 3.완화된 R1CS를 네이티브로 다루는 r-Groth는 Groth16의 3원소 증명과 2번 페어링 검증을 그대로 유지
- 4.FLIP+r-Groth는 집계 스키마의 k-1개 추가 Groth16 증명과 재귀시스템의 무거운 온체인 로직을 모두 회피
왜 중요한가?
롤업이나 Proof-of-Space처럼 한 기계가 다수의 증인을 들고 있는 프루빙 서비스 시나리오에서, Groth16 수준의 가벼운 검증을 유지하면서 다중 인스턴스 증명 비용을 실질적으로 줄일 수 있는 실용적 대안을 제시한다.
본문 미리보기
We present the first folding framework that achieves sublinear verification and communication when a single prover must convince a verifier of $k$ independent R1CS instances. - $\mathbf{FLIP}$ (Fold-Inner-Product) folds the $k$ instance-witness pairs in only $\log k$ rounds. Built on the homomorphic two-tier commitment of Abe et al. (CRYPTO 2010), FLIP transmits $O(\log k)$ group elements. - $\mathbf{r \operatorname{-} Groth}$ is a commit-and-prove variant of Groth16 that natively handles
전체 내용이 궁금하다면?
원문을 직접 읽어보세요
이 글이 만들어진 과정
- 11:24AI 초안



