Paper 2026/2100

Garbling Groth16 with Native Group Operations

Nakul Khambhati, University of California, Los Angeles
Aaron Feickert, Alpen Labs
Christian Lewe, Alpen Labs
Mukesh Tiwari, Alpen Labs
Abstract

The Groth16 verification equation has a compact algebraic description, yet garbling its Boolean implementation can require tens of gigabytes. We show how to garble this computation using native elliptic-curve group operations. Motivated by proof verification in trust-minimized Bitcoin bridges, we construct a projective partial garbling scheme for conditional disclosure on invalid Groth16 proofs. For a fixed verification key and public statement, evaluation reveals a garbler-held secret when the supplied proof is invalid and hides the secret when it is valid. The proof itself remains public. The main technical challenge is handling a pairing whose two arguments are supplied by the evaluator. We introduce a rekeying gadget that resolves this using a single private scalar multiplication. Building on Argo MAC (Eagen and Lai, 2026), BABE (Garg et al., 2026), and Duty-Free Bits (Khambhati et al., 2026), we prove a composition theorem for partial garbling across input representations and apply it to transform group encodings into bitwise projective encodings. This requires extending the projectivization technique of Duty-Free Bits to quadratic extension fields. The resulting garbled program has size $O(\lambda^2)$ bits, where $\lambda$ is the computational security parameter. We prove privacy under the decisional Diffie-Hellman assumption, in the random oracle model. Our BN254 implementation produces a 2.4 MiB garbled program, including projectivization, compared with the 48 GB reported for Boolean garbling of Groth16. Thus, we improve over prior state of the art in Groth16 garbling by over four orders of magnitude.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Garbled CircuitGroth162PCBitcoin Bridges
Contact author(s)
nakul @ cs ucla edu
aaron @ alpenlabs io
christian @ alpenlabs io
mukesh @ alpenlabs io
History
2026-09-22: approved
2026-09-18: received
See all versions
Short URL
https://ia.cr/2026/2100
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2100,
      author = {Nakul Khambhati and Aaron Feickert and Christian Lewe and Mukesh Tiwari},
      title = {Garbling Groth16 with Native Group Operations},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2100},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2100}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.