发表机构
Mysten Labs; University College London(Mysten Labs; 伦敦大学学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对轻客户端依赖完整状态承诺负担重的问题,提出 Guppy 协议,通过验证者仅承诺状态更新,并利用递归零知识证明维护完整 Merkle 树,实现高效包含证明,验证者开销低,延迟仅对数增长。
AI 中文摘要
传统轻客户端依赖验证者在每个区块通过状态承诺(如 Merkle 树)对完整区块链状态进行承诺,使客户端能够利用短证明验证事实。然而,维护庞大且不断增长的状态树给验证者带来了显著负担,并处于区块生产的关键路径上。因此,许多现代高吞吐量链完全避免采用这种方法。本研究探讨是否能在不要求验证者维护完整状态承诺的情况下支持高效的包含证明。我们提出 Guppy 协议,通过让验证者仅承诺状态更新来实现这一目标。一个由递归零知识证明(ZKPs)保障安全的链下不可信服务,随后维护覆盖完整状态的可验证 Merkle 树。该设计使验证者开销可忽略不计,且不增加区块构建的渐近复杂度。我们的设计基于两个关键技术思想。首先,哈希链承诺将验证者签名验证移出 ZK 电路,保持证明电路高效。其次,我们设计了一个并行递归证明流水线,利用现代 ZKP 中廉价的递归,确保延迟仅随吞吐量对数增长。我们基于 Plonky2 的实现表明,Guppy 能够维护大小为 2^30 的 Merkle 树,同时每秒处理数千次更新,仅增加 2-4 秒的延迟。
英文摘要
Traditional light clients rely on validators committing to the entire blockchain state at every block via a state commitment such as a Merkle tree, allowing clients to verify facts using short proofs. However, maintaining large and ever-growing state trees imposes a significant burden on validators and lies on the critical path of block production. As a result, many modern high-throughput chains avoid this approach altogether. This work asks whether efficient inclusion proofs can be supported without requiring validators to maintain full state commitments. We present Guppy, a protocol that achieves this by having validators commit to just the state updates. An off-chain, untrusted service, secured by recursive Zero-Knowledge Proofs (ZKPs), then maintains a verifiable Merkle tree over the full state. This design keeps validator overhead negligible and does not increase the asymptotic complexity of block construction. Our design rests on two key technical ideas. First, a hash-chain commitment moves validator signature verification out of the ZK circuit, keeping the proving circuit efficient. Second, we design a parallel recursive proving pipeline that leverages cheap recursion in modern ZKPs to ensure latency grows only logarithmically with throughput. Our Plonky2-based implementation demonstrates that Guppy can maintain a Merkle tree of size 2^30 while processing thousands of updates per second, adding only 2-4 s of latency.