Skip to content

LibraryPrivacy2019Design paperCorpus record

Aurora: Transparent Succinct Arguments for R1CS

Aurora. Eli Ben-Sasson, Alessandro Chiesa, Michael Riabzev, Nicholas Spooner, Madars Virza and Nicholas P. Ward.

Aurora proves rank-one constraint systems with a transparent setup, using a FRI-style proximity test rather than a pairing.

A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.

If a rollup says the setup is transparent, ask whether a new circuit needs new toxic waste. Aurora's answer is no.

The five-minute read

The defect

A succinct proof that needs a ceremony cannot be generated for a new program by a person who missed the ceremony.

The proposal

Aurora proves rank-one constraint systems with a transparent setup, using a FRI-style proximity test rather than a pairing.

Transparent means the setup is public randomness.

R1CS is the circuit language, not a chain.

The bound

Transparent does not mean trustless in the sense of no assumption. The hash and the code are the assumptions.

One action, walked through

  1. Write the computation as a constraint system.
  2. Prove proximity of a polynomial to a Reed-Solomon code.
  3. The verifier samples from public randomness and checks the transcript.
  4. What is the constraint language?

The argument, unpacked

What the paper is for

If a rollup says the setup is transparent, ask whether a new circuit needs new toxic waste. Aurora's answer is no.

What happened after

STARKs and later FRI systems are the production line. Aurora is a specific R1CS argument on that line.

What has to be true

  • Transparent does not mean trustless in the sense of no assumption. The hash and the code are the assumptions.
  • Proving time is the cost this family pays.
  • It is not Groth16 and not PLONK.

What happened after the paper

STARKs and later FRI systems are the production line. Aurora is a specific R1CS argument on that line.

What to check before you use the idea

  • Does a new program need a new setup?
  • What is the constraint language?
  • What does the verifier assume about the hash?

Terms

Transparent setup
Public randomness. No secret the prover must not know.
R1CS
A way to write a computation as rank-one constraints.

The problem the paper names

A succinct proof that needs a ceremony cannot be generated for a new program by a person who missed the ceremony.

What the design proposes

  • Transparent means the setup is public randomness.
  • R1CS is the circuit language, not a chain.
  • Succinct is a communication claim, not a claim that proving is cheap.

How the mechanism is specified

  • Write the computation as a constraint system.
  • Prove proximity of a polynomial to a Reed-Solomon code.
  • The verifier samples from public randomness and checks the transcript.

What this page does not treat as proven

  • Transparent does not mean trustless in the sense of no assumption. The hash and the code are the assumptions.
  • Proving time is the cost this family pays.
  • It is not Groth16 and not PLONK.

Why a venture studio still reads it

If a rollup says the setup is transparent, ask whether a new circuit needs new toxic waste. Aurora's answer is no.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.