Paper 2026/1931

SoK: Zero-Knowledge Friendly Hash Functions over Prime Fields

Clémence Bouvier, Université de Lorraine, CNRS, Inria, LORIA
Lorenzo Grassi, Eindhoven University of Technology
Katharina Koschatko, Graz University of Technology
Christian Rechberger, Graz University of Technology
Fabian Schmid, Graz University of Technology
Matthias Johann Steiner, Freischaffender Forscher
Zhuo Wu, Digital Technologies, Ant Group
Hailun Yan, University of Chinese Academy of Sciences
Abstract

Zero-Knowledge (ZK) proof systems have become a cornerstone of privacy-preserving technologies and blockchain scalability. However, traditional hash functions are often inefficient within ZK protocols due to their high constraint complexity in arithmetic circuits. While various ZK-friendly hash functions have been proposed to address this bottleneck, their diverse algebraic structures and varying security margins make it difficult for practitioners to select the optimal primitive. We conduct a systematic survey of ZK-friendly hash functions, covering both algorithmic design paradigms and modes of operation. We consolidate the relevant algebraic cryptanalysis techniques and review the third-party cryptanalysis of each design. For parameter sets broken by the best known attacks, we estimate the minimum number of rounds needed to withstand them - not as new recommendations, but to bring all constructions to a comparable level. On this basis, we analyze each construction across different arithmetization styles (R1CS, AIR, PLONK), both theoretically, by deriving the underlying constraint or gate counts, and empirically, through extensive benchmarks. This paper comes with a fully open-source implementation suite comprising a SageMath/Python reference framework, native Rust implementations, in-circuit implementations, and a reusable TikZ figure library.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Zero-Knowledge ProofsHash FunctionsArithmetizationAlgebraic Cryptanalysis
Contact author(s)
clemence bouvier @ inria fr
l grassi @ tue nl
katharina koschatko @ tugraz at
christian rechberger @ tugraz at
fabian schmid @ tugraz at
steiner matthias @ gmx at
pucun wz @ antgroup com
hailun yan @ ucas ac cn
History
2026-09-12: approved
2026-09-08: received
See all versions
Short URL
https://ia.cr/2026/1931
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1931,
      author = {Clémence Bouvier and Lorenzo Grassi and Katharina Koschatko and Christian Rechberger and Fabian Schmid and Matthias Johann Steiner and Zhuo Wu and Hailun Yan},
      title = {{SoK}: Zero-Knowledge Friendly Hash Functions over Prime Fields},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1931},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1931}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.