Paper 2024/1364
FLIP-and-prove R1CS
Abstract
We present the first folding framework that achieves sublinear verification and communication when a single prover must convince a verifier of $k$ independent R1CS instances. - $\mathbf{FLIP}$ (Fold-Inner-Product) folds the $k$ instance-witness pairs in only $\log k$ rounds. Built on the homomorphic two-tier commitment of Abe et al. (CRYPTO 2010), FLIP transmits $O(\log k)$ group elements. - $\mathbf{r \operatorname{-} Groth}$ is a commit-and-prove variant of Groth16 that natively handles relaxed R1CS. It retains Groth16’s three-element proof and two pairing checks, requires only a slightly modified (instance-independent) trusted setup, and does not rely on elliptic-curve cycles or foreign-field arithmetic. Combined, FLIP + r-Groth replace the $k-1$ extra Groth16 proofs demanded by aggregation schemes and avoid the heavy verifier-in-circuit logic of recursive systems. The total prover work is essentially one Groth16 run plus light folding, while the verifier processes $O(\log k)$ group elements and two pairings. This design is immediately applicable to roll-ups, Proof-of-Space, and other "proving-as-a-service" scenarios where all witnesses reside on a single machine.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published by the IACR in CIC 2025
- DOI
- https://doi.org/10.62056/ayc3tx4e-
- Keywords
- zero-knowledge proofsSNARKsblockchain
- Contact author(s)
-
anca nitulescu @ iohk io
nikitas paslis @ upf edu
carla rafols @ upf edu - History
- 2026-08-28: revised
- 2024-08-29: received
- See all versions
- Short URL
- https://ia.cr/2024/1364
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/1364,
author = {Anca Nitulescu and Nikitas Paslis and Carla Ràfols},
title = {{FLIP}-and-prove {R1CS}},
howpublished = {Cryptology {ePrint} Archive, Paper 2024/1364},
year = {2024},
doi = {https://doi.org/10.62056/ayc3tx4e-},
url = {https://eprint.iacr.org/2024/1364}
}