Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up
R1CS & QAP Arithmetic Groth16 vs PLONK vs STARK BN254 Bilinear Pairings Circom 2 & SnarkJS

Zero-Knowledge Proofs (ZKP), zk-SNARKs & Cryptographic Circuit Studio

Architect zero-knowledge systems and verifiable computation: construct arithmetic circuits and solve R1CS constraints, model Groth16 vs PLONK vs STARK prover time and memory footprints, inspect BN254 elliptic curve bilinear pairing equations, and generate production Circom 2 and Solidity contracts.

4 R1CS Gates
Circuit Constraints
128 Bytes
Groth16 Proof Size (BN254)
Satisfied
Constraint Verification
~220k Gas
EVM Verification Cost
📐
R1CS Equation: Every arithmetic gate represents a multiplication (A · s) ∘ (B · s) = (C · s) over finite field F_p. Enter your secret witness and test whether the circuit is mathematically satisfied.

Witness Vector s = [1, public, ...witness]

R1CS Gate Constraints Decomposition

⚡
Prover Complexity: Prover time scales as O(N log N) where N is the constraint count, driven by Multi-Scalar Multiplication (MSM) and Number Theoretic Transforms (NTT).
Circuit Constraint Count (N Gates): 65,536 gates (2^16)
Prover Hardware Acceleration: 16-core CPU
1: Single-thread CPU | 2: 16-Core Server CPU | 3: RTX 4090 GPU | 4: Dual NVIDIA A100 GPU
Elliptic Curve: BN254 (alt_bn128)
Public Input Variables: 4 variables

Proof System Resource Sizing

Prover Protocol Proof Size Prover Generation Time Prover Peak Memory Verification Latency Ethereum Gas Cost
🔬
Bilinear Pairing Verification: In Groth16, verification reduces to checking a single equality over target group G_T: e(A, B) = e(alpha, beta) · e(public_inputs, gamma) · e(C, delta).
=== GROTH16 PAIRING VERIFICATION EQUATION (BN254) === Given Proof points: A in G_1 (64 bytes: x, y in F_p) B in G_2 (128 bytes: x in F_p^2, y in F_p^2) C in G_1 (64 bytes: x, y in F_p) And Verification Key elements from Trusted Setup: alpha in G_1, beta in G_2, gamma in G_2, delta in G_2 IC_0, IC_1, ... in G_1 (Public input generators) Verifier Evaluates: e(A, B) == e(alpha, beta) * e(IC_0 + sum(x_i * IC_i), gamma) * e(C, delta) On Ethereum EVM: Executed via precompile 0x08 (ecPairing): staticcall(gas, 0x08, input, 384, output, 32) Consumes exactly 45,000 + 34,000 * 4 = 181,000 gas for 4 point pairs!
Dimension Groth16 (BBS+ R1CS) PLONK (Permutation / Custom) zk-STARK (FRI / Hash-Based)
Trusted Setup Ceremony Circuit-Specific (Requires fresh ceremony per circuit) Universal & Updateable (Powers of Tau up to 2^k gates) Transparent: ZERO trusted setup required.
Proof Size ~128 Bytes (Constant: 2x G1, 1x G2) ~400 - 800 Bytes (Constant) ~50 KB - 120 KB (Logarithmic)
Verification Time ~1.5 ms (3 pairings) ~3.5 ms (2 pairings + polynomial evals) ~5 - 15 ms (Merkle path & FRI checks)
Post-Quantum Resilience No (Broken by Shor's algorithm on Elliptic Curves) No (Broken by Shor's algorithm on Elliptic Curves) Yes: Immune (Relies on SHA3 / Blake3 hashes)
EVM Gas Cost ~220,000 gas (Cheapest on-chain) ~320,000 gas ~1,500,000+ gas (High Merkle hash cost)
Primary Ecosystem Tornado Cash, Semaphore, Zcash, Identity circuits zkSync Era, Aztec, Polygon zkEVM Starknet, dYdX v3, StarkEx, Cairo VM
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement