Skip to content

LibraryPrivacy2016Design paperCorpus record

Efficient Zero-Knowledge Arguments for Arithmetic Circuits in the Discrete Log Setting

Inner-product arguments. Jonathan Bootle, Andrea Cerulli, Pyrros Chaidos, Jens Groth and Christophe Petit.

The paper compresses an inner-product argument so a circuit proof can be logarithmic without a trusted setup, in the discrete-log model.

A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.

When someone says the proof has no setup, ask whether they mean this family or a hash-based STARK. The assumptions are different.

The five-minute read

The defect

Pairing-based SNARKs were short and needed a setup. Discrete-log arguments were transparent and too large.

The proposal

The paper compresses an inner-product argument so a circuit proof can be logarithmic without a trusted setup, in the discrete-log model.

No structured reference string.

The prover and verifier pay in group operations.

The bound

Logarithmic is not constant size. Groth16 is still shorter.

One action, walked through

  1. Commit to vectors.
  2. Recurse on the inner product by folding the vectors in half.
  3. The verifier checks a logarithmic transcript against the discrete-log assumption.
  4. How does the proof grow with the circuit?

The argument, unpacked

What the paper is for

When someone says the proof has no setup, ask whether they mean this family or a hash-based STARK. The assumptions are different.

What happened after

Bulletproofs cite this compression. Later folding schemes are a further branch, not this paper.

What has to be true

  • Logarithmic is not constant size. Groth16 is still shorter.
  • The discrete-log assumption is the one that fails against a quantum adversary.
  • This is not PLONK.

What happened after the paper

Bulletproofs cite this compression. Later folding schemes are a further branch, not this paper.

What to check before you use the idea

  • Is there a trusted setup?
  • How does the proof grow with the circuit?
  • Which assumption does soundness use?

Terms

Inner product
A sum of pairwise products. The argument proves it without sending the vectors.
Discrete log
The assumption that a group element does not reveal its exponent.

The problem the paper names

Pairing-based SNARKs were short and needed a setup. Discrete-log arguments were transparent and too large.

What the design proposes

  • No structured reference string.
  • The prover and verifier pay in group operations.
  • The argument is what Bulletproofs later specialised for ranges.

How the mechanism is specified

  • Commit to vectors.
  • Recurse on the inner product by folding the vectors in half.
  • The verifier checks a logarithmic transcript against the discrete-log assumption.

What this page does not treat as proven

  • Logarithmic is not constant size. Groth16 is still shorter.
  • The discrete-log assumption is the one that fails against a quantum adversary.
  • This is not PLONK.

Why a venture studio still reads it

When someone says the proof has no setup, ask whether they mean this family or a hash-based STARK. The assumptions are different.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.