Paper 2026/1931
SoK: Zero-Knowledge Friendly Hash Functions over Prime Fields
Abstract
Zero-Knowledge (ZK) proof systems have become a cornerstone of privacy-preserving technologies and blockchain scalability. However, traditional hash functions are often inefficient within ZK protocols due to their high constraint complexity in arithmetic circuits. While various ZK-friendly hash functions have been proposed to address this bottleneck, their diverse algebraic structures and varying security margins make it difficult for practitioners to select the optimal primitive. We conduct a systematic survey of ZK-friendly hash functions, covering both algorithmic design paradigms and modes of operation. We consolidate the relevant algebraic cryptanalysis techniques and review the third-party cryptanalysis of each design. For parameter sets broken by the best known attacks, we estimate the minimum number of rounds needed to withstand them - not as new recommendations, but to bring all constructions to a comparable level. On this basis, we analyze each construction across different arithmetization styles (R1CS, AIR, PLONK), both theoretically, by deriving the underlying constraint or gate counts, and empirically, through extensive benchmarks. This paper comes with a fully open-source implementation suite comprising a SageMath/Python reference framework, native Rust implementations, in-circuit implementations, and a reusable TikZ figure library.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Preprint.
- Keywords
- Zero-Knowledge ProofsHash FunctionsArithmetizationAlgebraic Cryptanalysis
- Contact author(s)
-
clemence bouvier @ inria fr
l grassi @ tue nl
katharina koschatko @ tugraz at
christian rechberger @ tugraz at
fabian schmid @ tugraz at
steiner matthias @ gmx at
pucun wz @ antgroup com
hailun yan @ ucas ac cn - History
- 2026-09-12: approved
- 2026-09-08: received
- See all versions
- Short URL
- https://ia.cr/2026/1931
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1931,
author = {Clémence Bouvier and Lorenzo Grassi and Katharina Koschatko and Christian Rechberger and Fabian Schmid and Matthias Johann Steiner and Zhuo Wu and Hailun Yan},
title = {{SoK}: Zero-Knowledge Friendly Hash Functions over Prime Fields},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1931},
year = {2026},
url = {https://eprint.iacr.org/2026/1931}
}