arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.27491cs.CR

Flock:面向批量布尔计算的快速证明

Flock: Fast Proving for Batch Boolean Computations

Benedikt Bünz, Ron D. Rothblum, William Wang

首次发表
浏览论文内容

中文总结 AI 辅助

Flock是一种基于哈希的SNARK,通过优化协议与协同设计的实现,大幅提升批量布尔计算的证明速度,在哈希评估证明性能上远超现有方案。

中文摘要 AI 辅助

对于许多SNARK应用而言,核心瓶颈是对SHA-256、Keccak或BLAKE3等标准密码哈希评估的大批量生成证明。我们提出Flock,一种基于哈希的SNARK,用于对此类批量布尔计算实现极快速的证明。Flock可对相同R1CS电路(含电路间的输入/输出关系)的批量生成证明,能证明哈希链与默克尔路径开放,原则上可扩展至全功能的基于哈希的签名验证。其核心是将lincheck和zerocheck协议的新优化,与由编码代理协同设计的激进优化概念验证实现相结合。在M4 Max处理器的单个核心上,Flock每秒可证明8.2万次BLAKE3压缩函数评估、4.2万次SHA-256压缩及3万次Keccak置换,仅比原生执行的开销小250倍以内;在10个核心上,吞吐量超过每秒66万次BLAKE3压缩,在SHA-256证明方面,Flock比此前的前沿方案Binius64快9倍以上,比我们测试的最快基于椭圆曲线的SNARK快500倍以上。

英文摘要

For many applications of SNARKs, a key bottleneck is proving large batches of standard cryptographic hash evaluations, such as SHA-256, Keccak, or BLAKE3. We introduce Flock, a hash-based SNARK for extremely fast proving of such batched Boolean computations. Flock proves batches of the same R1CS circuit (plus input/output relations between them), can prove hash-chains and Merkle path openings, and in principle can be extended to full-fledged hash-based signature verification. At its core, Flock combines new optimizations for the lincheck and zerocheck protocols with an aggressively optimized proof-of-concept implementation co-designed by coding agents. On a single core of an M4 Max processor, Flock proves 82k evaluations of the BLAKE3 compression function, 42k SHA-256 compressions, and 30k Keccak permutations per second --- less than a $250\times$ overhead over native execution. On ten cores, throughput exceeds 660k BLAKE3 compressions per second; in proving SHA-256, Flock is more than $9\times$ faster than Binius64, the prior state of the art, and more than $500\times$ faster than the fastest elliptic curve-based SNARK we measured against.

补充信息

↑