Paper 2026/1553

Amortized Multi-Verifier Proofs from Reductions of Knowledge

Nikitas Paslis, Universitat Pompeu Fabra
Carla Ràfols, Universitat Pompeu Fabra
Alexandros Zacharakis, Hasso Plattner Institute, University of Potsdam
Abstract

We study amortization of prover work in the multi-verifier setting, motivated by proof-as-a-service deployments in which a shared prover serves $K$ independent clients holding distinct statements. Each verifier checks only its own statement and proof, with no inter-verifier communication. The challenge is therefore to amortize prover work across many proofs while preserving local verification. We consider polynomial relations arising naturally in IOP-based proof systems, where verification reduces to polynomial identities and polynomial openings at verifier-chosen random points. Existing amortization techniques rely on shared verifier randomness, for example, to batch openings at a common evaluation point. However, under the standard Fiat--Shamir transform, independently verifiable proofs derive challenges from separate transcripts, preventing such amortization. We address this obstacle through a multi-verifier Fiat--Shamir transform that correlates verifier challenges across independently verifiable proofs while preserving locality. We further introduce promise local folding schemes, which defer polynomial-constraint checks generated during folding and amortize them later. Together, these techniques provide a generic framework for amortization under local verification. We apply this framework to the witness-independent component arising in R1CS- and CCS-based SNARK provers, which reduces to bivariate polynomial evaluation claims over the public constraint matrices. This component accounts for a substantial portion of the concrete proving cost. Applying our techniques to these claims reduces the server's cryptographic cost for this component from $O(K\cdot s)$ to $O(K\log K+s)$ group operations, where $s$ denotes the sparsity of the public constraint matrices, with each verifier performing only $O(\log K)$ cryptographic work and requiring no inter-verifier communication. Because the amortized component depends only on the public circuit description, our framework composes cleanly with collaborative zk-SNARK protocols, which target the complementary witness-dependent component.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
zkSNARKReductions of KnowledgeMulti-VerifierFiat-ShamirProof DelegationAmortizationLocal Folding
Contact author(s)
nikitas paslis @ upf edu
carla rafols @ upf edu
alexandros zacharakis @ hpi de
History
2026-08-03: approved
2026-07-29: received
See all versions
Short URL
https://ia.cr/2026/1553
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1553,
      author = {Nikitas Paslis and Carla Ràfols and Alexandros Zacharakis},
      title = {Amortized Multi-Verifier Proofs from Reductions of Knowledge},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1553},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1553}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.