Paper 2026/2175

$\mathsf{Rotor}$: SNARKs for Power-of-Two Rings

Chongrong Li, Shanghai Jiao Tong University
Yun Li, Ant Group
Pengfei Zhu, Tsinghua University
Zhechen Li, Ant Group
Michael Dong, Brevis Network
Alan Li, Brevis Network
Yuncong Hu, Shanghai Jiao Tong University
Abstract

Succinct proofs for arithmetic modulo powers of two are crucial for verifying machine-word computations in practice. However, designing SNARKs over such rings is challenging, since they lack the algebraic properties that common SNARKs over fields rely on to achieve negligible soundness error. Existing approaches either work over Galois rings, whose arithmetic is expensive, or lift the statement to the integers and prove it over a large random prime field, which is also several times slower than the structured primes used in practice. We present $\mathsf{Rotor}$, an efficient SNARK for circuits over $\mathbb Z_{2^k}$. Unlike prior work, $\mathsf{Rotor}$ operates natively over power-of-two rings and derives its soundness from three levels of ring precision. To prove statements over $\mathbb Z_{2^k}$, we first construct a sumcheck-style interactive oracle proof with tensor queries over a larger ring $\mathbb Z_{2^m}$. We then establish a weakened proximity gap for linear codes, in which proximity testing over a still larger ring $\mathbb Z_{2^\ell}$ ensures that the underlying vectors are close to the code after reduction to $\mathbb Z_{2^m}$. This yields a Brakedown-style commitment with tensor evaluation proofs over $\mathbb Z_{2^m}$. In both cases, a sufficiently large gap between the precisions guarantees negligible soundness error. Finally, we introduce compatible commitments, which link ring witnesses to their binary-field representations and enable permutation checks over fields to verify permutations over $\mathbb Z_{2^k}$, completing the construction of $\mathsf{Rotor}$. We implement $\mathsf{Rotor}$ and evaluate it on proving arithmetic circuits over $\mathbb Z_{2^{32}}$. It outperforms the Galois ring-based scheme of Wei et al. (PKC 2025) by up to $1{,}938\times$ in proving and $248\times$ in verification, and the integer proof system Zinc+ (ePrint 2026) by up to $44\times$ in proving and $5.07\times$ in verification. Compared with the field SNARKs based on Shout (CRYPTO 2026) and Binius (EUROCRYPT 2026), $\mathsf{Rotor}$ proves up to $86\times$ and $3.78\times$ faster, respectively, with comparable verification cost.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
SNARKPower-of-Two Rings
Contact author(s)
chongrongli @ sjtu edu cn
liyun24 @ antgroup com
zhupf321 @ gmail com
lizhechen lzc @ antgroup com
mdong @ brevis network
alan @ brevis network
huyuncong @ sjtu edu cn
History
2026-09-26: approved
2026-09-23: received
See all versions
Short URL
https://ia.cr/2026/2175
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2175,
      author = {Chongrong Li and Yun Li and Pengfei Zhu and Zhechen Li and Michael Dong and Alan Li and Yuncong Hu},
      title = {$\mathsf{Rotor}$: {SNARKs} for Power-of-Two Rings},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2175},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2175}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.