Skip to content

LibraryScaling2010Design paperCorpus record

Constant-Size Commitments to Polynomials and Their Applications

KZG commitments. Aniket Kate, Gregory M. Zaverucha and Ian Goldberg.

Commit to a polynomial and later open it at a point, in constant size, with a pairing. The commitment is binding if the setup's trapdoor stays secret. Modern data-availability schemes use this as a brick. The paper is older than those schemes.

A KZG commitment binds a prover to a polynomial in one group element. They can later open the polynomial at a point with a constant-size proof. The binding depends on a structured setup whose trapdoor must be destroyed.

The five-minute read

One element, the whole polynomial

The commitment does not grow with the degree, up to the size of the setup. That is why later systems use it for large objects such as data blobs and circuits.

Openings are the feature

A hash would also bind. A hash would not let you prove the value at one index without revealing a large neighbourhood. The pairing equation is what makes the opening small.

The setup is a real trust

The structured string is a sequence of encrypted powers of a secret. Anyone who knows the secret can open the commitment dishonestly. A ceremony is an attempt to ensure nobody knows it.

It is a brick

KZG does not sample data, order transactions, or prove a virtual machine. Protocols that say they use KZG still have to say what polynomial they commit to and what else is checked.

One action, walked through

  1. A setup publishes encrypted powers of a secret and discards the secret.
  2. The prover evaluates their polynomial against that string and publishes one group element as the commitment.
  3. To claim the polynomial takes a value at a point, the prover publishes a quotient commitment.
  4. The verifier checks a pairing product. It does not read the coefficients.
  5. Multiple openings can be batched by later techniques. The 2010 paper is the single opening and the binding.

The argument, unpacked

Constant size moved the risk into the ceremony

The attractive property is exactly what a trapdoor undermines. A system that cannot name its powers-of-tau ceremony has a constant-size proof and an unnamed trusted party.

Commitments are not availability

A commitment can be published while the polynomial's actual coefficients are withheld. Sampling and dispersal, as in the fraud-and-data-availability line, are what talk about publication. KZG is what those schemes often commit with.

What has to be true

  • The pairing assumptions in the paper hold for the chosen groups.
  • The setup secret was destroyed. Knowledge of it breaks binding.
  • The degree of the polynomial is within the length of the setup. A longer polynomial is not committed by that string.
  • The verifier checks the pairing against the public setup everyone agreed on.

What happened after the paper

PLONK-style proofs and several data-availability designs use KZG as the polynomial commitment. Verkle trees and blob constructions sit in the same family. The 2010 paper does not mention blobs. It is the citation for the commitment, and the ceremony of each later system is a separate object that has to be audited on its own.

What to check before you use the idea

  • What polynomial is being committed to?
  • Which ceremony produced the setup, and how was the secret destroyed?
  • Is an opening checked on chain, or merely assumed?
  • What ensures the underlying data, not just the commitment, was published?

Terms

Polynomial commitment
A short object that binds the prover to one polynomial and lets them open it at chosen points.
Powers of tau
The structured setup: encrypted successive powers of a secret that must not be retained.

The problem the paper names

A hash commits to a string but does not let you prove a single evaluation cheaply. Polynomial commitments let a prover bind to a whole object and answer 'what is the value here' with a small proof.

What the design proposes

  • A structured reference string of encrypted powers.
  • A commitment that is one group element.
  • An evaluation proof that is one group element.

How the mechanism is specified

  • The verifier checks a pairing equation. It does not read the polynomial.
  • Whoever knows the trapdoor can open the commitment to a different polynomial. The ceremony is the assumption.
  • Batching many points is a later optimisation. The 2010 paper is the binding and the hiding.

What this page does not treat as proven

  • KZG is not a blockchain, a rollup, or a sampling protocol. It is a commitment.
  • A universal setup shared by many teams is still a setup. Updatability has to be proved of the ceremony they actually ran.
  • Do not describe a system's data availability as 'just KZG' . The coding, the dispersal, and the fork choice are separate.

Why a venture studio still reads it

If a diagram's only cryptographic label is KZG, ask what polynomial is being committed to, who ran the powers of tau, and what is checked besides the opening.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.