LibraryPrivacy2016Design paperCorpus record
Efficient Zero-Knowledge Arguments for Arithmetic Circuits in the Discrete Log Setting
Inner-product arguments. Jonathan Bootle, Andrea Cerulli, Pyrros Chaidos, Jens Groth and Christophe Petit.
The paper compresses an inner-product argument so a circuit proof can be logarithmic without a trusted setup, in the discrete-log model.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
When someone says the proof has no setup, ask whether they mean this family or a hash-based STARK. The assumptions are different.
The five-minute read
The defect
Pairing-based SNARKs were short and needed a setup. Discrete-log arguments were transparent and too large.
The proposal
The paper compresses an inner-product argument so a circuit proof can be logarithmic without a trusted setup, in the discrete-log model.
No structured reference string.
The prover and verifier pay in group operations.
The bound
Logarithmic is not constant size. Groth16 is still shorter.
One action, walked through
- Commit to vectors.
- Recurse on the inner product by folding the vectors in half.
- The verifier checks a logarithmic transcript against the discrete-log assumption.
- How does the proof grow with the circuit?
The argument, unpacked
What the paper is for
When someone says the proof has no setup, ask whether they mean this family or a hash-based STARK. The assumptions are different.
What happened after
Bulletproofs cite this compression. Later folding schemes are a further branch, not this paper.
What has to be true
- Logarithmic is not constant size. Groth16 is still shorter.
- The discrete-log assumption is the one that fails against a quantum adversary.
- This is not PLONK.
What happened after the paper
Bulletproofs cite this compression. Later folding schemes are a further branch, not this paper.
What to check before you use the idea
- Is there a trusted setup?
- How does the proof grow with the circuit?
- Which assumption does soundness use?
Terms
- Inner product
- A sum of pairwise products. The argument proves it without sending the vectors.
- Discrete log
- The assumption that a group element does not reveal its exponent.
The problem the paper names
Pairing-based SNARKs were short and needed a setup. Discrete-log arguments were transparent and too large.
What the design proposes
- No structured reference string.
- The prover and verifier pay in group operations.
- The argument is what Bulletproofs later specialised for ranges.
How the mechanism is specified
- Commit to vectors.
- Recurse on the inner product by folding the vectors in half.
- The verifier checks a logarithmic transcript against the discrete-log assumption.
What this page does not treat as proven
- Logarithmic is not constant size. Groth16 is still shorter.
- The discrete-log assumption is the one that fails against a quantum adversary.
- This is not PLONK.
Why a venture studio still reads it
When someone says the proof has no setup, ask whether they mean this family or a hash-based STARK. The assumptions are different.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
