ROT256. · Apr 19, 2023
Mixed Trees: Trade-Off Between (In/Out-Of)-Circuit Costs
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
In applications where membership of the Merkle tree must be proved inside a SNARK, the concrete cost of expressing the compression function in the proof system (in terms of gates/R1CS constraints etc.) affects performance of the prover massively. This has lead to the study/creation of so-called SNARK-friendly hash functions: hash functions with ‘’nice algebraic’’…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.