Meet the foundational technology behind Mina, zkSync, and Polygon Zero.
A highly efficient universal SNARK, introducing a new circuit arithmetisation and the notion of 'selector polynomials', bound together by a permutation argument.
The first talk given about PLONK. Taking place September 2019 at the Simons Institute as part of the workshop on Probabilistically Checkable and Interactive Proof Systems.
Recorded at the Zero Knowledge Summit in San Francisco on Oct 26 2019.
Recorded at the fifth Zero Knowledge Summit. Explains the basic ideas and efficiency gains of Plookup and Ultra-PLONK
We explain how best to use lookup tables via sparse representations, taking a component of SHA-256 as an example. From the Dystopia Labs zkp & Privacy Summit.
Turbo-PLONK initiated the use of arbitrary arithmetic custom gates, whose possibility was alluded to in the original PLONK paper. This enabled breaking further away from the efficiency limitations of traditional R1CS, for example in the performance of elliptic curve operations.
This new scheme extends the Kate,Zaverucha and Goldberg polynomial commitment scheme to enable enhanced efficiency when openning multiple polynomials at multiple points.
Plookup enables extending PLONK's arithmetic gates with lookup gates from pre-computed tables. This opens a path to efficient proofs about "SNARK non-friendly functions" like SHA-256. We call the combination of PLONK and Plookup Ultra-PLONK
ZK-SNARK private assets are usually administrated using a pair of Merkle trees, a dense 'new note' tree and a sparse nullifier tree. This article explains the rationale for this architecture.
Demonstrating fast proof construction times over Pedersen hashes
Aztec's PLONK implementation delivers fast proof construction times over MiMC hashes