Featured Developer Sponsor • Zero-Token Protection
R1CS & QAP Arithmetic
Groth16 vs PLONK vs STARK
BN254 Bilinear Pairings
Circom 2 & SnarkJS
Zero-Knowledge Proofs (ZKP), zk-SNARKs & Cryptographic Circuit Studio
Architect zero-knowledge systems and verifiable computation: construct arithmetic circuits and solve R1CS constraints, model Groth16 vs PLONK vs STARK prover time and memory footprints, inspect BN254 elliptic curve bilinear pairing equations, and generate production Circom 2 and Solidity contracts.
4 R1CS Gates
Circuit Constraints
128 Bytes
Groth16 Proof Size (BN254)
Satisfied
Constraint Verification
~220k Gas
EVM Verification Cost
📐
R1CS Equation: Every arithmetic gate represents a multiplication
(A · s) ∘ (B · s) = (C · s) over finite field F_p. Enter your secret witness and test whether the circuit is mathematically satisfied.
Witness Vector s = [1, public, ...witness]
R1CS Gate Constraints Decomposition
⚡
Prover Complexity: Prover time scales as
O(N log N) where N is the constraint count, driven by Multi-Scalar Multiplication (MSM) and Number Theoretic Transforms (NTT).
Proof System Resource Sizing
| Prover Protocol | Proof Size | Prover Generation Time | Prover Peak Memory | Verification Latency | Ethereum Gas Cost |
|---|
🔬
Bilinear Pairing Verification: In Groth16, verification reduces to checking a single equality over target group
G_T: e(A, B) = e(alpha, beta) · e(public_inputs, gamma) · e(C, delta).
=== GROTH16 PAIRING VERIFICATION EQUATION (BN254) ===
Given Proof points:
A in G_1 (64 bytes: x, y in F_p)
B in G_2 (128 bytes: x in F_p^2, y in F_p^2)
C in G_1 (64 bytes: x, y in F_p)
And Verification Key elements from Trusted Setup:
alpha in G_1, beta in G_2, gamma in G_2, delta in G_2
IC_0, IC_1, ... in G_1 (Public input generators)
Verifier Evaluates:
e(A, B) == e(alpha, beta) * e(IC_0 + sum(x_i * IC_i), gamma) * e(C, delta)
On Ethereum EVM:
Executed via precompile 0x08 (ecPairing):
staticcall(gas, 0x08, input, 384, output, 32)
Consumes exactly 45,000 + 34,000 * 4 = 181,000 gas for 4 point pairs!
| Dimension | Groth16 (BBS+ R1CS) | PLONK (Permutation / Custom) | zk-STARK (FRI / Hash-Based) |
|---|---|---|---|
| Trusted Setup Ceremony | Circuit-Specific (Requires fresh ceremony per circuit) | Universal & Updateable (Powers of Tau up to 2^k gates) | Transparent: ZERO trusted setup required. |
| Proof Size | ~128 Bytes (Constant: 2x G1, 1x G2) | ~400 - 800 Bytes (Constant) | ~50 KB - 120 KB (Logarithmic) |
| Verification Time | ~1.5 ms (3 pairings) | ~3.5 ms (2 pairings + polynomial evals) | ~5 - 15 ms (Merkle path & FRI checks) |
| Post-Quantum Resilience | No (Broken by Shor's algorithm on Elliptic Curves) | No (Broken by Shor's algorithm on Elliptic Curves) | Yes: Immune (Relies on SHA3 / Blake3 hashes) |
| EVM Gas Cost | ~220,000 gas (Cheapest on-chain) | ~320,000 gas | ~1,500,000+ gas (High Merkle hash cost) |
| Primary Ecosystem | Tornado Cash, Semaphore, Zcash, Identity circuits | zkSync Era, Aztec, Polygon zkEVM | Starknet, dYdX v3, StarkEx, Cairo VM |
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement