Paper 2026/532
S-two Whitepaper
Abstract
This whitepaper describes S-two, a circle STARK (Haböck, Levit, Papini 2024) over the Mersenne prime field with modulus $p =2^{31} -1$. We formalize the "flat AIR" circuit model, a modern arithmetization paradigm used by several contemporary zero-knowledge virtual machines, and we provide an in-depth security analysis of our proof of proximity for flat AIRs. For the latter, we highlight the importance of "cross-domain correlated agreement", a notion which is crucial for taming the soundness error of multi-table proofs. We show that multi-table circle FRI satisfies this notion up to the Johnson bound of the code, and we discuss two plausible conjectures on the list-decodability and line-decodability of Reed-Solomon codes, which are in alignment with the recent progress on proximity gaps.
Note: Updated author list
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- Proof of proximityReed-Solomon codescorrelated agreementproximity gaps
- Contact author(s)
-
dancar @ starkware co
lior @ starkware co
ulrich @ starkware co
leo @ starkware co
ilya @ starkware co
spapini @ attestable com
shahars @ attestable com - History
- 2026-03-24: last of 2 revisions
- 2026-03-16: received
- See all versions
- Short URL
- https://ia.cr/2026/532
- License
-
CC BY-SA
BibTeX
@misc{cryptoeprint:2026/532,
author = {Dan Carmon and Lior Goldberg and Ulrich Haböck and Leonardo Lerer and Ilya Lesokhin and Shahar Papini and Shahar Samocha},
title = {S-two Whitepaper},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/532},
year = {2026},
url = {https://eprint.iacr.org/2026/532}
}