Snarkpack

Recall a Groth16 verification with verification key and proof . It's made to sum to zero and signs are absorbed into the constants.

Take proofs and linearly combine them using :

Question. Can we proof soundness if the prover only provided and/or the equivalent for or ? Extreme case

where is derived by pseudorandom function from .


https://eprint.iacr.org/2021/529

Remco Bloemen
Math & Engineering
https://2π.com