{"barriers":[{"claim":"The Gentry–Wichs barrier, as restated and used by the 2025 boosting analysis, rules out proving the scoped all-NP SNARG via a polynomial-time black-box reduction to a falsifiable assumption.","does_not_exclude":["Non-black-box reductions that inspect the adversary's code","Non-adaptive soundness or proper subclasses of NP","Constructions from non-falsifiable, obfuscation, or proof-complexity assumptions","A sharper impossibility theorem under additional hypotheses"],"escape_hatches":["non_black_box_reduction","weaken_adaptivity","restrict_language_class","change_assumption_class"],"evidence":"primary_source_checked","excludes":["A route whose only novelty is a new polynomial-time black-box reduction from an all-NP adaptively sound SNARG to LWE, DDH, or another falsifiable assumption"],"id":"PROOF-BARRIER-001","scope":{"assumption":"falsifiable","object":"adaptively_sound_SNARG_for_sufficiently_hard_NP_languages","reduction":"polynomial_time_black_box_reduction"},"status":"scoped_literature_barrier","targets":["PROOF-OP-001"],"title":"Black-box falsifiable-assumption barrier for all-NP SNARGs"},{"claim":"In the audited boundary, Behemoth reaches the constant opening/verifier endpoint without a post-quantum claim, while the post-quantum transparent branches retain logarithmic or polylogarithmic opening or verifier cost.","does_not_exclude":["A new hash-, code-, lattice-, isogeny-, or other post-quantum technique reaching all four coordinates","An impossibility theorem for a precisely defined transparent post-quantum model","Constant amortized cost under an explicitly different batched interface"],"escape_hatches":["new_post_quantum_algebraic_backend","degree_independent_terminal_check","formal_impossibility"],"evidence":"claim_audited","excludes":["Treating transparency alone as post-quantum security","Combining the constant-cost cells of Behemoth with the quantum-security cells of a different PCS as if one construction achieved the conjunction"],"id":"PROOF-BARRIER-002","scope":{"coordinates":["transparent_setup","post_quantum_security","opening_size","verifier_time"],"corpus":"audited_Behemoth_WHIR_and_lattice_PCS_branches_through_2026_08_13"},"status":"scoped_frontier_boundary","targets":["PROOF-OP-002"],"title":"Constant-succinctness and post-quantum security are reached by different audited PCS branches"},{"claim":"The current IBCS reduction proves its stated knowledge-soundness notion, but measurement and the no-cloning constraint prevent treating the extracted adversary state as automatically reusable by an enclosing protocol.","does_not_exclude":["A coherent extractor with an explicit state-repair invariant","A different vector-commitment property that enables stronger extraction","Strong extraction for a restricted IOP or adversary class"],"escape_hatches":["coherent_state_repair","stronger_collapsing_interface","restricted_composition_class"],"evidence":"primary_source_checked","excludes":["Inferring state-preserving or witness-extended extraction directly from Theorem 1's ordinary knowledge-soundness conclusion","A classical copy-and-rewind proof that duplicates an unknown quantum auxiliary state"],"id":"PROOF-BARRIER-003","scope":{"desired_property":"state_preserving_or_witness_extended_extraction","proof":"quantum_rewinding_reduction_for_IBCS"},"status":"scoped_technique_barrier","targets":["PROOF-OP-003"],"title":"Quantum state disturbance blocks a naive strengthening of IBCS extraction"},{"claim":"In the audited constructions, Fiat–Shamir in a random oracle or a knowledge-style assumption supplies the challenge/extraction behavior required by non-interactive recursive accumulation; replacing the oracle by a concrete hash is only heuristic.","does_not_exclude":["A new standard-model compiler using correlation intractability or another carefully scoped assumption","Interactive accumulation under standard assumptions","A black-box impossibility theorem for a delimited predicate/reduction class"],"escape_hatches":["standard_model_noninteractive_compiler","interaction","scoped_impossibility"],"evidence":"primary_source_checked","excludes":["Labeling a concrete-hash Fiat–Shamir instantiation as a standard-model proof","Claiming the 2020 accumulation-to-PCD theorem itself constructs a standard-model non-interactive accumulator under ordinary falsifiable assumptions"],"id":"PROOF-BARRIER-004","scope":{"constructions":"audited_noninteractive_accumulation_and_folding_instantiations","security_goal":"adaptive_knowledge_soundness_for_PCD"},"status":"scoped_frontier_boundary","targets":["PROOF-OP-004"],"title":"Fiat–Shamir supplies the non-interactive challenge in current folding and accumulation routes"}],"benchmarkRuns":[{"artifact_commit":"783da5d32010e707f85085d59ae0451f6d8a6b25","comparable":false,"comparison_group":"none","compatibility_key":{"commitment_backend":"HyperKZG over BN254","compiler_flags":"Cargo release profile; additional code-generation flags not reported","configuration":"RV32IM Jolt with BN254 HyperKZG and Keccak transcript at 783da5d","curve_field":"BN254 scalar field","estimator":"not_reported","evidence_state":"official_ci_reported_not_reproduced","hardware":"GitHub-hosted public ubuntu-24.04 x64 runner class; exact VM CPU model not reported","implementation_version":"783da5d32010e707f85085d59ae0451f6d8a6b25","metric_definition":"prover runtime is the source Instant interval around prove_sha2_chain; memory is GNU time maximum resident set size for the cargo-run process","network":"not_applicable_to_local_prove_verify_run","os":"ubuntu-24.04 GitHub-hosted runner image","preprocessing_accounting":"Prover timer starts after build_sha2_chain; peak RSS covers the timed cargo-run process; compile is performed before the run","problem_size":"100 iterations; constraint and realized trace counts not reported by the dashboard row","security_level":"not_reported","software_toolchain":"Rust nightly-2024-09-30; riscv32im-unknown-none-elf target","thread_count":"not_reported","workload":"SHA2-chain guest; input [5u8; 32]; 100 sequential SHA-256 iterations"},"configuration_id":"PROOF-SYSTEM-JOLT","evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-BENCH-2025-JOLT-SHA2-783DA5D","implementation_id":"PROOF-IMPL-2025-JOLT-783DA5D","metrics":{"peak_rss_kb":"11033940","proof_size":"not_reported","prover_time_seconds":"63.0816","verifier_time":"not_reported"},"non_comparability_reasons":["Exact host CPU model and prover thread count are not reported.","Concrete security level and estimator are not reported.","The later curated Jolt run changes VM width, PCS, toolchain, and workload size."],"primaryUrl":"https://a16z.github.io/jolt/dev/bench/data.js","source_locator":"benchmark data entry for commit 783da5d, sha2-chain-time and sha2-chain-mem; pinned examples/sha2-chain and CI workflow","source_urls":["https://a16z.github.io/jolt/dev/bench/data.js","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/.github/workflows/ci-bench.yml","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/examples/run_benchmarks.sh","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/examples/sha2-chain/src/main.rs","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/examples/sha2-chain/guest/src/lib.rs"],"status":"reported","title":"Jolt 783da5d SHA2-chain CI observation","year":2025},{"artifact_commit":"915faf453f36871249615a7fdf2704d77a88f259","comparable":false,"comparison_group":"none","compatibility_key":{"commitment_backend":"Dory over BN254 with Pedersen vector commitments","compiler_flags":"Cargo release profile; additional code-generation flags not reported","configuration":"RV64IMAC Jolt with Dory over BN254 and default legacy Blake2b transcript at 915faf4","curve_field":"BN254 scalar field","estimator":"not_reported","evidence_state":"official_ci_reported_not_reproduced","hardware":"GitHub-hosted public ubuntu-24.04 x64 runner class; exact VM CPU model not reported","implementation_version":"915faf453f36871249615a7fdf2704d77a88f259","metric_definition":"prover runtime is the source Instant interval around prove_sha2_chain; memory is GNU time maximum resident set size for the cargo-run process","network":"not_applicable_to_local_prove_verify_run","os":"ubuntu-24.04 GitHub-hosted runner image","preprocessing_accounting":"Prover timer starts after guest compilation and shared/prover/verifier preprocessing; peak RSS covers the timed cargo-run process; compilation is performed before the run","problem_size":"1000 iterations; guest max_trace_length 4194304; realized trace count not reported by dashboard row","security_level":"not_reported","software_toolchain":"Rust 1.95; riscv32imac and riscv64imac bare-metal targets configured","thread_count":"not_reported","workload":"SHA2-chain guest; input [5u8; 32]; 1000 sequential Jolt-inline SHA-256 iterations"},"configuration_id":"PROOF-SYSTEM-JOLT","evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-BENCH-2026-JOLT-SHA2-915FAF4","implementation_id":"PROOF-IMPL-2026-JOLT-915FAF4","metrics":{"peak_rss_kb":"2123752","proof_size":"not_reported","prover_time_seconds":"102.4157","verifier_time":"not_reported"},"non_comparability_reasons":["Exact host CPU model and prover thread count are not reported.","Concrete security level and estimator are not reported.","The earlier curated Jolt run uses RV32IM, HyperKZG, a different toolchain, and one tenth as many SHA-256 iterations."],"primaryUrl":"https://a16z.github.io/jolt/dev/bench/data.js","source_locator":"benchmark data entry for commit 915faf4, sha2-chain-time and sha2-chain-mem; pinned examples/sha2-chain, host_utils, rust-toolchain, and CI workflow","source_urls":["https://a16z.github.io/jolt/dev/bench/data.js","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/.github/workflows/ci-bench.yml","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/examples/run_ci_benchmarks.sh","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/examples/sha2-chain/src/main.rs","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/examples/sha2-chain/guest/src/lib.rs"],"status":"reported","title":"Jolt 915faf4 SHA2-chain CI observation","year":2026}],"catalogVersion":"proof-systems-v1-theory-practice-measurement-atlas","claims":[{"claim_scope":null,"id":"PROOF-CONTRIB-1986-FS-COMPILER","lens":"foundations","limitations":"does not give a standard-model compiler for arbitrary interactive proofs; security does not follow from syntax alone","paper_id":"PROOF-PAPER-1986-FS","paper_title":"How to Prove Yourself: Practical Solutions to Identification and Signature Problems","paper_url":"https://doi.org/10.1007/3-540-47721-7_12","review_status":"primary_source_checked","role":"compiler","security_model":null,"source_locator":"CRYPTO 1986 paper, identification-to-signature transformation","statement":"The Fiat–Shamir transform replaces a verifier-sampled public-coin challenge with a hash of the statement and commitment, yielding the foundational non-interactive compilation pattern for identification protocols.","title":"Hash-derived challenges compile public-coin identification into non-interactive proofs","visibility":"backbone","year":1986},{"claim_scope":null,"id":"PROOF-CONTRIB-1988-BFM-NIZK-MODEL","lens":"foundations","limitations":"FLS90 §1.1 footnote 1, printed p. 308 / PDF p. 1 (https://doi.org/10.1109/FSCS.1990.89549), reports that BFM88's proposed method for overcoming reference-string reuse was found flawed; no reusable-construction result is admitted from BFM88 §4 here.; The model definition does not imply adaptive-statement security, simulation soundness, extractability, succinctness, or an efficient witness-equipped prover.; The single-theorem QRA construction and informal chosen-ciphertext application are separate claims, not part of this definition atom.; Full-text review of this ten-page extended abstract is not independent verification of its construction proofs or a substitute for another paper's corrected result.","paper_id":"PROOF-PAPER-1988-BFM","paper_title":"Non-Interactive Zero-Knowledge and Its Applications (Extended Abstract)","paper_url":"https://doi.org/10.1145/62212.62222","review_status":"fulltext_checked","role":"definition","security_model":null,"source_locator":"STOC 1988 extended abstract: §1.1, printed p. 104 / PDF p. 2; Definition 2.2, printed p. 105 / PDF p. 3; Definition 3.1 and following verifier-view remark, printed p. 106 / PDF p. 4; §4 and Definition 4.1, printed pp. 108–109 / PDF pp. 6–7, for the distinct many-theorem target only.","statement":"Blum, Feldman, and Micali formalize non-interactive zero knowledge in a model where prover and verifier share a uniformly random string and a written proof is checked without further verifier messages. Their single-theorem definition requires completeness, soundness, and computational simulation of the joint reference-string and proof distribution from the statement.","title":"Shared-random-string model for non-interactive zero knowledge","visibility":"catalog_only","year":1988},{"claim_scope":null,"id":"PROOF-CONTRIB-1989-GMR-ZK","lens":"foundations","limitations":"the definition is not itself a succinct or non-interactive construction; later notions refine verifier and auxiliary-input models","paper_id":"PROOF-PAPER-1989-GMR","paper_title":"The Knowledge Complexity of Interactive Proof Systems","paper_url":"https://doi.org/10.1137/0218012","review_status":"primary_source_checked","role":"definition","security_model":null,"source_locator":"Abstract and Sections 1–2","statement":"Goldwasser, Micali, and Rackoff formalize knowledge complexity for interactive proofs and identify zero knowledge as the case where interaction conveys no additional efficiently usable knowledge beyond validity.","title":"Zero knowledge formalized as revealing no knowledge beyond statement validity","visibility":"backbone","year":1989},{"claim_scope":null,"id":"PROOF-CONTRIB-1990-FLS-MULTI-THEOREM","lens":"foundations","limitations":"One-way functions alone are not claimed to construct the required bounded NIZK for NP; the transformation preserves rather than removes that premise.; The ordinary bounded-base guarantee is not automatically adaptive zero knowledge; statement selection after seeing the reference string requires the separately qualified adaptive base.; The admitted result covers polynomially many proofs of polynomial-length statements within the base protocol's supported statement bounds. The unbounded-size remark in §3.3 omits details and is not promoted into this claim.; Reuse of a reference string is not proof aggregation, recursion, succinct proof size, low verifier cost, knowledge extraction, or simulation extractability.; This is a source check of the 1990 extended abstract, which contains proof sketches and omitted details, not an independent verification of its theorems or a review of the 1999 journal version.","paper_id":"PROOF-PAPER-1990-FLS","paper_title":"Multiple Non-Interactive Zero Knowledge Proofs Based on a Single Random String (Extended Abstract)","paper_url":"https://doi.org/10.1109/FSCS.1990.89549","review_status":"fulltext_checked","role":"compiler","security_model":null,"source_locator":"FOCS 1990 extended abstract: §3.1 and Definition 3.7, PDF p. 5 (printed p. 312); §3.2, Lemmas 3.9 and 3.11, and §3.3, Theorem 3.12 and proof, PDF pp. 6–7 (printed pp. 313–314); adaptive scope in §4.1, Definitions 4.14 and 4.16, and §4.2, Theorem 4.20, PDF pp. 8–9 (printed pp. 315–316); historical comparison in §1.1 and footnote 1, PDF p. 1 (printed p. 308)","statement":"Given a bounded NIZK proof system for an NP-complete language whose prover runs in polynomial time with a witness, and a pseudorandom generator obtained from one-way functions, the FLS transformation supports polynomially many independent provers proving polynomially many polynomial-length statements using one shared random reference string, with joint computational zero knowledge for the nonadaptive statement sequences of Definition 3.7.","title":"Single-to-many NIZK with a shared random reference string","visibility":"catalog_only","year":1990},{"claim_scope":null,"id":"PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT","lens":"foundations","limitations":"does not imply a transparent or post-quantum instantiation; succinct verifier communication does not bound prover work","paper_id":"PROOF-PAPER-1992-KILIAN","paper_title":"A Note on Efficient Zero-Knowledge Proofs and Arguments","paper_url":"https://doi.org/10.1145/129712.129782","review_status":"primary_source_checked","role":"construction_method","security_model":null,"source_locator":"Main construction and theorem","statement":"Kilian compiles probabilistically checkable proof access through cryptographic commitments so that a verifier queries only authenticated PCP locations, obtaining communication-efficient computational arguments.","title":"Commitment-authenticated PCP access yields communication-efficient arguments","visibility":"backbone","year":1992},{"claim_scope":null,"id":"PROOF-CONTRIB-1992-LFKN-SUMCHECK","lens":"multilinear-sumcheck","limitations":"requires a separately justified final evaluation; soundness depends on degree and field size","paper_id":"PROOF-PAPER-1992-LFKN","paper_title":"Algebraic Methods for Interactive Proof Systems","paper_url":"https://doi.org/10.1145/146585.146605","review_status":"primary_source_checked","role":"protocol","security_model":null,"source_locator":"Algebraic protocol sections; sum-check reduction","statement":"The algebraic protocol now isolated as sum-check verifies a claimed sum of a low-degree multivariate polynomial over a product domain by reducing it round by round to one polynomial evaluation.","title":"Sum-check reduces a multivariate polynomial sum to one evaluation claim","visibility":"backbone","year":1992},{"claim_scope":null,"id":"PROOF-CONTRIB-2010-KZG-PCS","lens":"universal-polynomial","limitations":"not transparent; not post-quantum; batch-opening security requires configuration-specific analysis","paper_id":"PROOF-PAPER-2010-KZG","paper_title":"Constant-Size Commitments to Polynomials and Their Applications","paper_url":"https://eprint.iacr.org/2010/009","review_status":"primary_source_checked","role":"component_construction","security_model":null,"source_locator":"Abstract and Section 3","statement":"KZG commits to a bounded-degree univariate polynomial and proves one evaluation with constant-size group elements using pairing groups and degree-bounded structured public parameters.","title":"Pairing-based polynomial commitments give constant-size single-point openings","visibility":"backbone","year":2010},{"claim_scope":null,"id":"PROOF-CONTRIB-2016-GROTH-3ELEMENT","lens":"pairing-succinct","limitations":"circuit-specific structured setup; not post-quantum; implementation security depends on exact ceremony and curve choices","paper_id":"PROOF-PAPER-2016-GROTH","paper_title":"On the Size of Pairing-based Non-interactive Arguments","paper_url":"https://eprint.iacr.org/2016/260","review_status":"primary_source_checked","role":"system_construction","security_model":null,"source_locator":"Abstract; main construction and efficiency statement","statement":"Groth16 gives a preprocessing pairing-based non-interactive zero-knowledge argument for arithmetic-circuit satisfiability whose proof in the displayed construction contains three group elements.","title":"Arithmetic-circuit NIZK argument compressed to three group elements","visibility":"backbone","year":2016},{"claim_scope":null,"id":"PROOF-CONTRIB-2017-BULLETPROOFS-AGG","lens":"recursion-ivc","limitations":"specialized aggregation rather than generic recursion; verifier work does not become constant","paper_id":"PROOF-PAPER-2017-BULLETPROOFS","paper_title":"Bulletproofs: Short Proofs for Confidential Transactions and More","paper_url":"https://eprint.iacr.org/2017/1066","review_status":"primary_source_checked","role":"composition","security_model":null,"source_locator":"Abstract and aggregated range-proof section","statement":"Bulletproofs aggregates multiple range statements into one proof whose size grows only logarithmically with the number and bit length of the committed values rather than linearly across separate proofs.","title":"Multiple range statements aggregate with logarithmic additive proof growth","visibility":"reviewed_related","year":2017},{"claim_scope":null,"id":"PROOF-CONTRIB-2017-BULLETPROOFS-IPA","lens":"transparent-hash","limitations":"verifier work is linear in witness dimension; not a general constant-size SNARK","paper_id":"PROOF-PAPER-2017-BULLETPROOFS","paper_title":"Bulletproofs: Short Proofs for Confidential Transactions and More","paper_url":"https://eprint.iacr.org/2017/1066","review_status":"primary_source_checked","role":"protocol","security_model":null,"source_locator":"Abstract and Sections 2–4","statement":"Bulletproofs constructs logarithmic-size proofs from a discrete-log inner-product argument and Pedersen-style commitments without a trusted setup, with verification work that remains linear in the witness dimension.","title":"Discrete-log inner-product argument gives logarithmic proofs without trusted setup","visibility":"backbone","year":2017},{"claim_scope":null,"id":"PROOF-CONTRIB-2018-STARK-SYSTEM","lens":"transparent-hash","limitations":"proofs are not constant size; exact post-quantum claim depends on hash and protocol analysis","paper_id":"PROOF-PAPER-2018-STARK","paper_title":"Scalable, Transparent, and Post-Quantum Secure Computational Integrity","paper_url":"https://eprint.iacr.org/2018/046","review_status":"primary_source_checked","role":"system_construction","security_model":null,"source_locator":"Abstract and system overview","statement":"The STARK architecture combines algebraic execution constraints, interactive-oracle techniques for codes, and hash-authenticated oracle commitments to obtain transparent computational-integrity proofs with sublinear verification for the demonstrated computations.","title":"AIR and coded-oracle checks form a transparent scalable proof architecture","visibility":"backbone","year":2018},{"claim_scope":null,"id":"PROOF-CONTRIB-2019-HALO-RECURSION","lens":"recursion-ivc","limitations":"not a post-quantum construction; concrete recursion depends on the selected curve and commitment configuration","paper_id":"PROOF-PAPER-2019-HALO","paper_title":"Recursive Proof Composition without a Trusted Setup","paper_url":"https://eprint.iacr.org/2019/1021","review_status":"primary_source_checked","role":"composition","security_model":null,"source_locator":"Section 1.1 and Sections 3–6","statement":"Halo combines an inner-product polynomial commitment, nested amortization, and an elliptic-curve cycle to realize recursive proof composition without a trusted setup.","title":"Inner-product commitments enable recursive proof composition without trusted setup","visibility":"backbone","year":2019},{"claim_scope":null,"id":"PROOF-CONTRIB-2019-MARLIN-AHP","lens":"universal-polynomial","limitations":"universal structured setup is not transparent setup; security inherits the selected commitment assumptions","paper_id":"PROOF-PAPER-2019-MARLIN","paper_title":"Marlin: Preprocessing zkSNARKs with Universal and Updatable SRS","paper_url":"https://eprint.iacr.org/2019/1047","review_status":"primary_source_checked","role":"compiler","security_model":null,"source_locator":"Section 1.1 and Theorem 8.1","statement":"Marlin formalizes a compiler from public-coin algebraic holographic proofs and extractable polynomial commitments to preprocessing arguments with a universal and updatable structured reference string.","title":"Algebraic-holographic proofs compile to universal-updatable-SRS arguments","visibility":"reviewed_related","year":2019},{"claim_scope":null,"id":"PROOF-CONTRIB-2019-PLONK-PIOP","lens":"universal-polynomial","limitations":"not transparent; later PLONKish variants require separate security and configuration records","paper_id":"PROOF-PAPER-2019-PLONK","paper_title":"PLONK: Permutations over Lagrange-bases for Oecumenical Noninteractive arguments of Knowledge","paper_url":"https://eprint.iacr.org/2019/953","review_status":"primary_source_checked","role":"system_construction","security_model":null,"source_locator":"Abstract and Sections 1 and 8","statement":"PLONK gives a permutation-based polynomial proof architecture over Lagrange-basis constraints whose structured reference string is universal and updatable rather than circuit specific.","title":"Permutation-based polynomial protocol supports universal updatable setup","visibility":"backbone","year":2019},{"claim_scope":null,"id":"PROOF-CONTRIB-2019-SPARTAN-R1CS","lens":"multilinear-sumcheck","limitations":"exact succinctness depends on the commitment backend and variant; transparent preprocessing is not zero preprocessing","paper_id":"PROOF-PAPER-2019-SPARTAN","paper_title":"Spartan: Efficient and General-purpose zkSNARKs without Trusted Setup","paper_url":"https://eprint.iacr.org/2019/550","review_status":"primary_source_checked","role":"system_construction","security_model":null,"source_locator":"Abstract and Sections 1 and 4","statement":"Spartan reduces arbitrary R1CS satisfiability to sum-check and multilinear commitment machinery, giving transparent argument variants with sublinear verification after public preprocessing.","title":"Sum-check proves arbitrary R1CS with transparent preprocessing","visibility":"backbone","year":2019},{"claim_scope":null,"id":"PROOF-CONTRIB-2020-ACCUMULATION-PCD","lens":"recursion-ivc","limitations":"concrete non-interactive instantiations use random oracle or knowledge assumptions; standard-model accumulation remains open","paper_id":"PROOF-PAPER-2020-ACCUMULATION","paper_title":"Proof-Carrying Data from Accumulation Schemes","paper_url":"https://eprint.iacr.org/2020/499","review_status":"fulltext_checked","role":"definition_and_compiler","security_model":null,"source_locator":"Abstract; Section 1.1; Theorems 1–3","statement":"The paper defines accumulation schemes and proves that an argument equipped with a suitable accumulator yields proof-carrying data, with concrete non-interactive instantiations relying on a random oracle or knowledge assumptions.","title":"Accumulation schemes suffice to compile arguments into proof-carrying data","visibility":"reviewed_related","year":2020},{"claim_scope":null,"id":"PROOF-CONTRIB-2021-NOVA-FOLDING","lens":"recursion-ivc","limitations":"folding alone is not a SNARK; non-interactive deployment inherits transcript and final-decider assumptions","paper_id":"PROOF-PAPER-2021-NOVA","paper_title":"Nova: Recursive Zero-Knowledge Arguments from Folding Schemes","paper_url":"https://eprint.iacr.org/2021/370","review_status":"primary_source_checked","role":"definition_and_construction","security_model":null,"source_locator":"Section 1.1; folding definitions and constructions","statement":"Nova defines folding schemes as a weaker primitive than SNARKs and folds two relaxed-R1CS instances into one running instance to realize incrementally verifiable computation before an optional final compression step.","title":"Relaxed-R1CS folding realizes incrementally verifiable computation","visibility":"backbone","year":2021},{"claim_scope":null,"id":"PROOF-CONTRIB-2023-BEHEMOTH-CONSTANT","lens":"transparent-hash","limitations":"cubic prover; random-oracle and generic-group analysis; no post-quantum claim","paper_id":"PROOF-PAPER-2023-BEHEMOTH","paper_title":"Behemoth — Transparent Polynomial Commitment Scheme with Constant Opening Proof Size and Verifier Time","paper_url":"https://eprint.iacr.org/2023/670","review_status":"fulltext_checked","role":"component_construction","security_model":null,"source_locator":"Abstract; Sections 4–5 and 8","statement":"Behemoth constructs a transparent polynomial commitment with degree-independent opening-proof size and verifier time in a group of unknown order, with cubic prover time and analysis in the random-oracle and generic-group models.","title":"Transparent polynomial commitments with degree-independent opening size and verification","visibility":"reviewed_related","year":2023},{"claim_scope":null,"id":"PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD","lens":"recursion-ivc","limitations":"final succinctness remains configuration dependent; non-interactive security inherits transcript assumptions","paper_id":"PROOF-PAPER-2023-HYPERNOVA","paper_title":"Recursive Arguments for Customizable Constraint Systems","paper_url":"https://eprint.iacr.org/2023/573","review_status":"primary_source_checked","role":"composition","security_model":null,"source_locator":"Abstract and contributions in Section 1","statement":"HyperNova generalizes folding from relaxed R1CS to customizable constraint systems, folds multiple instances in one step, and supports non-uniform step circuits and PCD-oriented generalizations.","title":"CCS multi-folding supports multiple instances and non-uniform IVC steps","visibility":"backbone","year":2023},{"claim_scope":null,"id":"PROOF-CONTRIB-2023-JOLT-LOOKUPVM","lens":"lookups-zkvm","limitations":"paper architecture is distinct from later RV32 and RV64 implementation configurations; performance depends on backend and workload","paper_id":"PROOF-PAPER-2023-JOLT","paper_title":"Jolt: SNARKs for Virtual Machines via Lookups","paper_url":"https://eprint.iacr.org/2023/1217","review_status":"primary_source_checked","role":"system_architecture","security_model":null,"source_locator":"Abstract and Sections 1 and 3","statement":"Jolt organizes instruction execution around large structured lookups and combines the lookup argument with a sum-check-based proof for residual constraints plus a separate memory-checking protocol.","title":"Lookup-centric decomposition proves virtual-machine execution","visibility":"backbone","year":2023},{"claim_scope":null,"id":"PROOF-CONTRIB-2023-PROTOSTAR-GENERIC","lens":"recursion-ivc","limitations":"efficiency and non-interactive security remain instantiation dependent; not every protocol satisfies the compiler hypotheses","paper_id":"PROOF-PAPER-2023-PROTOSTAR","paper_title":"Protostar: Generic Efficient Accumulation/Folding for Special-Sound Protocols","paper_url":"https://eprint.iacr.org/2023/620","review_status":"primary_source_checked","role":"compiler","security_model":null,"source_locator":"Abstract; generic compiler and concrete Protostar construction","statement":"Protostar gives an accumulation or folding compiler for a class of special-sound protocols and instantiates it for non-uniform IVC with PLONK-style high-degree gates and vector lookups.","title":"Special-sound protocols compile into generic accumulation and folding","visibility":"reviewed_related","year":2023},{"claim_scope":null,"id":"PROOF-CONTRIB-2024-LATTICE-PCS-PQ","lens":"transparent-hash","limitations":"non-interactive form uses Fiat-Shamir in ROM; opening size and verifier time are not constant","paper_id":"PROOF-PAPER-2024-LATTICE-PCS","paper_title":"Polynomial Commitments from Lattices — Post-Quantum Security, Fast Verification and Transparent Setup","paper_url":"https://eprint.iacr.org/2024/281","review_status":"fulltext_checked","role":"component_construction","security_model":null,"source_locator":"Abstract; Section 1.1; Figure 2","statement":"The construction gives a transparent lattice-based polynomial commitment with polylogarithmic communication and verification, quasi-linear proving, and quantum knowledge soundness under Module-SIS; its non-interactive form uses Fiat–Shamir in the random-oracle model.","title":"Transparent lattice PCS gives post-quantum knowledge soundness with polylogarithmic openings","visibility":"reviewed_related","year":2024},{"claim_scope":"Specified PLONK variants and batch-opening protocols","id":"PROOF-CONTRIB-2024-PLONK-KS","lens":"security-audit","limitations":"not a blanket theorem for all PLONKish systems; exact variants and assumptions must match","paper_id":"PROOF-PAPER-2024-PLONK-KS","paper_title":"On Knowledge-Soundness of Plonk in ROM from Falsifiable Assumptions","paper_url":"https://eprint.iacr.org/2024/994","review_status":"primary_source_checked","role":"security_analysis","security_model":"Interactive computational special soundness and ROM knowledge soundness under stated assumptions","source_locator":"Abstract; main PLONK and batching theorems","statement":"The paper proves computational special soundness for specified batched KZG opening protocols and interactive PLONK variants under falsifiable assumptions, then relates those results to random-oracle-model knowledge soundness.","title":"Variant-scoped PLONK knowledge soundness covers batched KZG openings","visibility":"backbone","year":2024},{"claim_scope":"Optimized universal PIOP-based configurations satisfying the paper's stated conditions","id":"PROOF-CONTRIB-2024-REALWORLD-SE","lens":"security-audit","limitations":"does not automatically cover arbitrary forks backends or undocumented optimizations","paper_id":"PROOF-PAPER-2024-REALWORLD-SE","paper_title":"Real-world Universal zkSNARKs are Non-malleable","paper_url":"https://eprint.iacr.org/2024/721","review_status":"primary_source_checked","role":"security_analysis","security_model":"Simulation extractability under the paper's model and assumptions","source_locator":"Abstract; main theorems and optimization coverage","statement":"The paper establishes simulation extractability for optimized real-world PLONK- and Marlin-style universal zkSNARK configurations satisfying its stated protocol, backend, and optimization conditions.","title":"Optimized PLONK- and Marlin-style configurations receive simulation-extractability proofs","visibility":"backbone","year":2024},{"claim_scope":null,"id":"PROOF-CONTRIB-2024-WHIR-PROXIMITY","lens":"transparent-hash","limitations":"not constant-size; comparative performance depends on field rate security and implementation configuration","paper_id":"PROOF-PAPER-2024-WHIR","paper_title":"WHIR: Reed–Solomon Proximity Testing with Super-Fast Verification","paper_url":"https://eprint.iacr.org/2024/1586","review_status":"primary_source_checked","role":"component_construction","security_model":null,"source_locator":"Abstract; Sections 1 and 7","statement":"WHIR introduces a Reed–Solomon proximity-testing framework and resulting hash-based polynomial commitments designed to reduce verifier work relative to the compared transparent coded-oracle constructions.","title":"WHIR reduces verifier cost in Reed–Solomon proximity testing and hash-based PCS","visibility":"backbone","year":2024},{"claim_scope":null,"id":"PROOF-CONTRIB-2025-BOOSTING-SNARKS","lens":"foundations","limitations":"does not construct the mildly succinct base SNARK from standard assumptions","paper_id":"PROOF-PAPER-2025-BOOSTING-SNARKS","paper_title":"Boosting SNARKs and Rate-1 Barrier in Arguments of Knowledge","paper_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ICALP.2025.56","review_status":"fulltext_checked","role":"compiler","security_model":null,"source_locator":"Introduction; Theorems 1–2 and Corollary 3","statement":"Given suitable RAM delegation, the compiler promotes a mildly succinct SNARK for NP to a fully succinct SNARK while preserving whether the base extractor is black box or non-black box.","title":"RAM delegation boosts mildly succinct knowledge arguments to full succinctness","visibility":"reviewed_related","year":2025},{"claim_scope":null,"id":"PROOF-CONTRIB-2025-GALOIS-RINGS","lens":"transparent-hash","limitations":"full theorem scope not yet audited; exact backend and security coordinates remain to be normalized","paper_id":"PROOF-PAPER-2025-GALOIS","paper_title":"Transparent SNARKs over Galois Rings","paper_url":"https://eprint.iacr.org/2025/263","review_status":"abstract_checked","role":"system_construction","security_model":null,"source_locator":"Abstract and construction overview","statement":"The paper extends expander-code commitments and existing proof frameworks to transparent SNARK constructions over arbitrary Galois rings with the sublinear verifier and proof bounds stated in its abstract.","title":"Transparent SNARK constructions extend to arbitrary Galois rings","visibility":"catalog_only","year":2025},{"claim_scope":"Interactive BCS with the paper's semi-adaptive IOP and collapsing commitment conditions","id":"PROOF-CONTRIB-2025-IBCS-QUANTUM","lens":"security-audit","limitations":"does not prove fully adaptive IOP security; does not prove state-preserving or witness-extended extraction","paper_id":"PROOF-PAPER-2025-IBCS-QUANTUM","paper_title":"Quantum Rewinding for IOP-Based Succinct Arguments","paper_url":"https://eprint.iacr.org/2025/947","review_status":"fulltext_checked","role":"security_analysis","security_model":"Quantum soundness and Unruh-style knowledge soundness","source_locator":"Theorem 1; Theorem 6.1; Remark 2.1","statement":"The paper proves post-quantum soundness and Unruh-style knowledge soundness for interactive BCS instantiated with a semi-adaptive public-coin IOP and a collapse-position-binding vector commitment.","title":"Interactive BCS gains post-quantum soundness and Unruh-style knowledge soundness","visibility":"backbone","year":2025},{"claim_scope":null,"id":"PROOF-CONTRIB-2025-JOLT-SPACE","lens":"lookups-zkvm","limitations":"does not remove all implementation memory overhead; concrete benefit depends on configuration and workload","paper_id":"PROOF-PAPER-2025-JOLT-SPACE","paper_title":"Proving CPU Executions in Small Space","paper_url":"https://eprint.iacr.org/2025/611","review_status":"primary_source_checked","role":"optimization","security_model":null,"source_locator":"Abstract; Theorem 7.1 and Section 7","statement":"The paper gives a small-space honest-prover strategy for the Jolt stack by streaming witness-dependent data and recomputing selected values, with an explicit time–space tradeoff rather than recursion-based sharding.","title":"Streaming and recomputation reduce Jolt honest-prover memory","visibility":"reviewed_related","year":2025},{"claim_scope":null,"id":"PROOF-CONTRIB-2026-SNARG-UNPROVABILITY","lens":"foundations","limitations":"uses a new proof-complexity unprovability assumption; does not achieve adaptive soundness","paper_id":"PROOF-PAPER-2026-SNARG-UNPROVABILITY","paper_title":"SNARGs for NP from Unprovability of Mathematical Theorems","paper_url":"https://eccc.weizmann.ac.il/report/2026/098/","review_status":"fulltext_checked","role":"construction","security_model":null,"source_locator":"Abstract; Section 1.1; Theorem 1.1","statement":"The paper constructs a non-adaptively sound SNARG for all NP from prBPP = prP, LWE, SXDH, and a Hardness Certification assumption about proving Extended-Frege lower bounds in a weak bounded-arithmetic theory.","title":"All-NP non-adaptive SNARGs from cryptography plus proof-unprovability","visibility":"reviewed_related","year":2026}],"components":[{"component_kind":"arithmetization","id":"PROOF-COMP-AIR","paper_ids":["PROOF-PAPER-2018-STARK"],"summary":"Represents an execution trace with boundary and transition constraints over a field for coded-oracle proof systems.","tags":["air","trace","transition-constraints"],"title":"Algebraic Intermediate Representation (AIR)"},{"component_kind":"arithmetization","id":"PROOF-COMP-CCS","paper_ids":["PROOF-PAPER-2023-HYPERNOVA"],"summary":"Provides a common customizable relation format used by HyperNova to cover R1CS-, PLONKish-, and AIR-like constraints while retaining a folding-compatible interface.","tags":["air","ccs","plonkish","r1cs"],"title":"Customizable Constraint Systems (CCS)"},{"component_kind":"arithmetization","id":"PROOF-COMP-PLONKISH","paper_ids":["PROOF-PAPER-2019-PLONK","PROOF-PAPER-2023-PROTOSTAR"],"summary":"Uses polynomial identities and permutation-style consistency checks for wired arithmetic constraints. The term names an arithmetization family, not every complete system called PLONK.","tags":["custom-gates","permutation","plonkish"],"title":"PLONKish polynomial constraints"},{"component_kind":"arithmetization","id":"PROOF-COMP-QAP","paper_ids":["PROOF-PAPER-2016-GROTH"],"summary":"Translates circuit or R1CS consistency into a univariate polynomial divisibility relation used by pairing-based succinct arguments.","tags":["polynomial-representation","qap"],"title":"Quadratic Arithmetic Program (QAP)"},{"component_kind":"arithmetization","id":"PROOF-COMP-R1CS","paper_ids":["PROOF-PAPER-2016-GROTH","PROOF-PAPER-2019-SPARTAN","PROOF-PAPER-2021-NOVA"],"summary":"Encodes satisfiability through rank-1 bilinear constraints. R1CS is a relation representation, not a proof protocol or commitment backend.","tags":["r1cs","relation-representation"],"title":"Rank-1 Constraint System (R1CS)"},{"component_kind":"commitment_backend","id":"PROOF-COMP-MLPCS","paper_ids":["PROOF-PAPER-2019-SPARTAN","PROOF-PAPER-2023-JOLT","PROOF-PAPER-2024-WHIR"],"summary":"Binds multilinear polynomial evaluations for sum-check-based systems. Concrete group- or code-based instantiations have different setup, verifier, and quantum-security properties, so the interface never supplies those properties by inheritance.","tags":["backend-interface","multilinear-pcs","spark"],"title":"Extractable multilinear polynomial commitment interface"},{"component_kind":"commitment_backend","id":"PROOF-COMP-FRI","paper_ids":["PROOF-PAPER-2018-STARK","PROOF-PAPER-2024-WHIR"],"summary":"Combines code proximity testing with hash-authenticated oracle access. FRI/WHIR-style proximity machinery is distinguished from algebraic PCS backends such as KZG.","tags":["fri","merkle","proximity-testing","reed-solomon"],"title":"FRI-style coded-oracle proximity backend"},{"component_kind":"commitment_backend","id":"PROOF-COMP-KZG","paper_ids":["PROOF-PAPER-2010-KZG"],"summary":"Provides constant-size commitments and evaluation openings for bounded-degree univariate polynomials using pairing groups and structured public parameters.","tags":["kzg","pairing","structured-setup","univariate-pcs"],"title":"KZG polynomial commitment"},{"component_kind":"commitment_backend","id":"PROOF-COMP-IPA","paper_ids":["PROOF-PAPER-2017-BULLETPROOFS","PROOF-PAPER-2019-HALO","PROOF-PAPER-2021-NOVA"],"summary":"Represents the discrete-log homomorphic vector-commitment layer used beneath inner-product arguments and folding systems. The interactive inner-product protocol is stored separately because it plays a different stack role.","tags":["discrete-log","homomorphic-vector-commitment","no-trusted-setup","pedersen"],"title":"Pedersen / homomorphic vector commitment backend"},{"component_kind":"compiler","id":"PROOF-COMP-FIAT-SHAMIR","paper_ids":["PROOF-PAPER-1986-FS"],"summary":"Derives verifier challenges from a transcript hash to compile suitable public-coin protocols into non-interactive ones. Security is attached to a concrete transcript and model.","tags":["fiat-shamir","non-interactive","random-oracle"],"title":"Fiat–Shamir compiler"},{"component_kind":"composition_mechanism","id":"PROOF-COMP-MULTIFOLD","paper_ids":["PROOF-PAPER-2023-HYPERNOVA"],"summary":"Represents HyperNova's sum-check-based mechanism for folding multiple CCS instances in one step. Generic special-sound accumulation is a separate component because it accepts a different protocol interface.","tags":["ccs","multi-folding"],"title":"CCS multi-folding"},{"component_kind":"composition_mechanism","id":"PROOF-COMP-RECURSIVE-WRAP","paper_ids":["PROOF-PAPER-2019-HALO"],"summary":"Proves verification of a prior proof inside a new proof circuit. It is distinct from folding instances before a final decision procedure.","tags":["curve-cycle","recursion","verifier-circuit"],"title":"Recursive verifier wrapping"},{"component_kind":"composition_mechanism","id":"PROOF-COMP-RELAXED-FOLD","paper_ids":["PROOF-PAPER-2021-NOVA"],"summary":"Combines two relaxed-R1CS instances and witnesses into one folded instance, deferring a single final satisfiability decision for IVC.","tags":["folding","ivc","relaxed-r1cs"],"title":"Relaxed-R1CS folding"},{"component_kind":"composition_mechanism","id":"PROOF-COMP-SPECIAL-SOUND-ACCUMULATION","paper_ids":["PROOF-PAPER-2023-PROTOSTAR"],"summary":"Represents Protostar's compiler interface for accumulating a class of special-sound protocols. It is not interchangeable with CCS multi-folding merely because both mechanisms can support IVC.","tags":["accumulation","protostar","special-sound"],"title":"Special-sound protocol accumulation"},{"component_kind":"computation_model","id":"PROOF-COMP-CIRCUIT","paper_ids":["PROOF-PAPER-2016-GROTH"],"summary":"Represents a computation as additions and multiplications over a field before a separate arithmetization encodes satisfiability.","tags":["circuit","computation-model"],"title":"Arithmetic circuit computation model"},{"component_kind":"computation_model","id":"PROOF-COMP-RISCV","paper_ids":["PROOF-PAPER-2023-JOLT"],"summary":"Defines the bytecode/ISA-facing computation whose instruction, bytecode, register, and memory behavior is lowered into several proof subarguments.","tags":["isa","risc-v","zkvm"],"title":"RISC-V execution model"},{"component_kind":"protocol_iop","id":"PROOF-COMP-INNER-PRODUCT","paper_ids":["PROOF-PAPER-2017-BULLETPROOFS","PROOF-PAPER-2019-HALO"],"summary":"Recursively reduces an inner-product relation to smaller instances. It is an interactive argument component; the homomorphic vector commitment beneath it is a separate backend role.","tags":["discrete-log","inner-product-argument","logarithmic-protocol"],"title":"Logarithmic inner-product argument"},{"component_kind":"protocol_iop","id":"PROOF-COMP-PAIRING-QAP","paper_ids":["PROOF-PAPER-2016-GROTH"],"summary":"Encodes QAP witness relations into structured group elements and pairing equations. It is not modeled as a modular PCS substitution point.","tags":["pairing","qap","succinct-argument"],"title":"Pairing-based QAP argument"},{"component_kind":"protocol_iop","id":"PROOF-COMP-POLY-IOP","paper_ids":["PROOF-PAPER-2019-PLONK","PROOF-PAPER-2019-MARLIN"],"summary":"Carries algebraic soundness before polynomial oracles are cryptographically realized. A PCS and Fiat–Shamir are separate compiler/backend choices.","tags":["ahp","piop","polynomial-oracle"],"title":"Polynomial IOP / algebraic holographic proof layer"},{"component_kind":"protocol_iop","id":"PROOF-COMP-SUMCHECK","paper_ids":["PROOF-PAPER-1992-LFKN","PROOF-PAPER-2019-SPARTAN","PROOF-PAPER-2023-HYPERNOVA"],"summary":"Reduces a claimed sum of a low-degree multivariate polynomial over a product domain to a final evaluation claim through public-coin interaction.","tags":["multilinear","public-coin","sumcheck"],"title":"Sum-check protocol"},{"component_kind":"specialized_argument","id":"PROOF-COMP-MEMORY-CHECK","paper_ids":["PROOF-PAPER-2023-JOLT","PROOF-PAPER-2025-JOLT-SPACE"],"summary":"Proves consistency of register and RAM reads and writes. It is a specialized subargument in the zkVM stack, distinct from instruction lookups and the residual R1CS proof.","tags":["memory-checking","ram","zkvm"],"title":"Read/write memory-checking argument"},{"component_kind":"specialized_argument","id":"PROOF-COMP-LOOKUP","paper_ids":["PROOF-PAPER-2023-JOLT","PROOF-PAPER-2023-PROTOSTAR"],"summary":"Proves that values occur in a committed or structured table. Lookup is a reusable subargument, not a computation model or complete zkVM.","tags":["lasso","lookup","vector-lookup","zkvm"],"title":"Structured lookup argument"}],"constructions":[{"claim_ids":["PROOF-CONTRIB-2016-GROTH-3ELEMENT"],"complexity":{"memory":"not_reported","proof_size":"three_group_elements","prover":"linear_group_work_in_circuit_size","verifier":"constant_pairings_plus_public_input_work"},"configuration_note":"The structured group encoding is integral to this configuration; it is not represented as a modular PCS slot.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-GROTH16","name":"Groth16","paper_ids":["PROOF-PAPER-2016-GROTH"],"properties":{"interaction":"non_interactive","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"circuit_specific_structured_crs","soundness":"knowledge_soundness_in_stated_model"},"research_lenses":["pairing-succinct"],"stack":{"arithmetization":["PROOF-COMP-R1CS","PROOF-COMP-QAP"],"commitment_backend":[],"compiler":[],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-PAIRING-QAP"],"specialized_argument":[]},"stack_status":{"commitment_backend":"not_separate","compiler":"not_applicable","composition_mechanism":"not_applicable","specialized_argument":"not_applicable"},"status":"published","summary":"It is the compact pairing-based endpoint against which setup flexibility, transparency, and recursive friendliness are often contrasted.","system_family":"pairing_qap_snark","tasks":["succinct_argument_of_knowledge","zero_knowledge"],"title":"Groth16 · QAP / circuit-specific CRS","visibility":"backbone","year":2016},{"claim_ids":["PROOF-CONTRIB-2017-BULLETPROOFS-IPA"],"complexity":{"memory":"not_reported","proof_size":"logarithmic_in_witness_size","prover":"linear_in_witness_or_constraint_size","verifier":"linear_for_general_arithmetic_circuits"},"configuration_note":"General arithmetic-circuit row; aggregated range proofs are a related specialized task.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-BULLETPROOFS","name":"Bulletproofs","paper_ids":["PROOF-PAPER-2017-BULLETPROOFS"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"transparent_generators","soundness":"argument_of_knowledge_in_random_oracle_model"},"research_lenses":["transparent-hash","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-INNER-PRODUCT"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_separate","specialized_argument":"out_of_scope"},"status":"published","summary":"It shows that logarithmic proofs and no trusted setup do not imply a succinct verifier in every dimension.","system_family":"inner_product_argument","tasks":["zero_knowledge_argument","range_proof","aggregation"],"title":"Bulletproofs · general arithmetic-circuit configuration","visibility":"backbone","year":2017},{"claim_ids":["PROOF-CONTRIB-2018-STARK-SYSTEM"],"complexity":{"memory":"implementation_dependent","proof_size":"polylogarithmic_style_but_large_constants","prover":"quasilinear_style_for_supported_trace_encoding","verifier":"sublinear_polylogarithmic_style"},"configuration_note":"Representative 2018 coded-oracle architecture; FRI/IOP variants and later engineering are not merged into one benchmark row.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-STARK","name":"ZK-STARK","paper_ids":["PROOF-PAPER-2018-STARK"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"conditional_hash_model","privacy":"zero_knowledge_in_displayed_system","setup":"transparent","soundness":"computational_from_hash_and_iop_analysis"},"research_lenses":["transparent-hash"],"stack":{"arithmetization":["PROOF-COMP-AIR"],"commitment_backend":["PROOF-COMP-FRI"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","summary":"It makes transparency and hash-based assumptions visible as properties of a full AIR/IOP/backend stack.","system_family":"transparent_iop","tasks":["transparent_argument","zero_knowledge","scalable_verification"],"title":"ZK-STARK · AIR / coded-oracle configuration","visibility":"backbone","year":2018},{"claim_ids":["PROOF-CONTRIB-2019-HALO-RECURSION"],"complexity":{"memory":"implementation_dependent","proof_size":"does_not_grow_with_recursion_depth","prover":"configuration_dependent_recursive_work","verifier":"does_not_grow_with_recursion_depth"},"configuration_note":"Original recursive composition architecture using nested amortization and a cycle of non-pairing curves; this release does not normalize it to the later Halo2 PLONKish arithmetization.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-HALO","name":"Halo","paper_ids":["PROOF-PAPER-2019-HALO"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"conditional_on_full_configuration","setup":"transparent_generators","soundness":"argument_in_stated_random_oracle_model"},"research_lenses":["recursion-ivc","transparent-hash"],"stack":{"arithmetization":[],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-RECURSIVE-WRAP"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-INNER-PRODUCT"],"specialized_argument":[]},"stack_status":{"arithmetization":"not_normalized","specialized_argument":"out_of_scope"},"status":"published","summary":"Halo’s recursive wrapping is compared with folding only in the composition table, where the mechanism distinction is explicit.","system_family":"recursive_ipa_argument","tasks":["recursive_composition","proof_aggregation"],"title":"Halo · IPA / curve-cycle recursive configuration","visibility":"backbone","year":2019},{"claim_ids":["PROOF-CONTRIB-2019-MARLIN-AHP","PROOF-CONTRIB-2024-REALWORLD-SE"],"complexity":{"memory":"implementation_dependent","proof_size":"constant_number_of_commitments_and_openings","prover":"quasilinear_polynomial_work","verifier":"succinct_after_preprocessing"},"configuration_note":"Concrete representative instantiation of the AHP compiler with KZG.","evidence":"claim_audited","id":"PROOF-SYSTEM-MARLIN-KZG","name":"Marlin + KZG","paper_ids":["PROOF-PAPER-2019-MARLIN","PROOF-PAPER-2010-KZG"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"universal_updatable_structured_srs","soundness":"knowledge_soundness_and_claim_specific_extractability"},"research_lenses":["universal-polynomial","security-audit"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-KZG"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","summary":"Marlin makes the AHP-to-PCS compiler boundary explicit, which is central to the atlas stack view.","system_family":"universal_ahp_snark","tasks":["preprocessing_snark","zero_knowledge"],"title":"Marlin · AHP / KZG configuration","visibility":"backbone","year":2019},{"claim_ids":["PROOF-CONTRIB-2019-PLONK-PIOP","PROOF-CONTRIB-2024-REALWORLD-SE","PROOF-CONTRIB-2024-PLONK-KS"],"complexity":{"memory":"implementation_dependent","proof_size":"constant_number_of_group_and_field_elements","prover":"quasilinear_polynomial_work","verifier":"succinct_plus_public_input_work"},"configuration_note":"Fixes the original PLONKish protocol with KZG and Fiat–Shamir; other Halo2-style or alternative-PCS configurations require separate rows.","evidence":"claim_audited","id":"PROOF-SYSTEM-PLONK-KZG","name":"PLONK + KZG","paper_ids":["PROOF-PAPER-2019-PLONK","PROOF-PAPER-2010-KZG"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"universal_updatable_structured_srs","soundness":"claim_and_variant_specific"},"research_lenses":["universal-polynomial","pairing-succinct","security-audit"],"stack":{"arithmetization":["PROOF-COMP-PLONKISH"],"commitment_backend":["PROOF-COMP-KZG"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","summary":"Security cards expose which batching and optimization choices are covered. The family name alone carries no automatic theorem.","system_family":"universal_polynomial_iop_snark","tasks":["succinct_argument_of_knowledge","zero_knowledge"],"title":"PLONK · original KZG-backed configuration","visibility":"backbone","year":2019},{"claim_ids":["PROOF-CONTRIB-2019-SPARTAN-R1CS"],"complexity":{"memory":"implementation_dependent","proof_size":"logarithmic_style_under_selected_commitment","prover":"linear_for_displayed_r1cs_path","verifier":"sublinear_after_public_preprocessing"},"configuration_note":"Representative transparent Spartan architecture; the multilinear PCS interface is explicit because concrete instantiations change proof and verifier costs.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-SPARTAN","name":"Spartan","paper_ids":["PROOF-PAPER-2019-SPARTAN"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_discrete_log_instantiation","privacy":"computational_zero_knowledge","setup":"transparent_with_public_preprocessing_for_sublinear_verification","soundness":"knowledge_soundness_in_stated_model"},"research_lenses":["multilinear-sumcheck","transparent-hash"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-MLPCS"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-SUMCHECK"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","summary":"It anchors the multilinear/sum-check path later reused in folding systems and lookup-oriented zkVMs.","system_family":"multilinear_sumcheck_snark","tasks":["transparent_zksnark","general_r1cs"],"title":"Spartan · transparent R1CS / sum-check configuration","visibility":"backbone","year":2019},{"claim_ids":["PROOF-CONTRIB-2021-NOVA-FOLDING"],"complexity":{"memory":"step_circuit_and_commitment_dependent","proof_size":"constant_size_running_ivc_state; a succinct final proof requires optional compression","prover":"per_step_linear_multiexponentiation_style","verifier":"constant_size_incremental_state_check_plus_separate_final_decider"},"configuration_note":"This row is the folding-based IVC core, not a claim that folding alone is a complete succinct proof system; optional SNARK compression and the final decider remain separate.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-NOVA","name":"Nova","paper_ids":["PROOF-PAPER-2021-NOVA"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_displayed_commitment","privacy":"zero_knowledge_in_paper_configuration","setup":"transparent_generators","soundness":"folding_soundness_plus_final_decider"},"research_lenses":["recursion-ivc","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-RELAXED-FOLD"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":[],"specialized_argument":[]},"stack_status":{"protocol_iop":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","summary":"Nova changes the recursion problem from repeatedly proving verifier execution to folding the relation instances themselves.","system_family":"folding_based_ivc","tasks":["ivc"],"title":"Nova · relaxed-R1CS folding core","visibility":"backbone","year":2021},{"claim_ids":["PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD"],"complexity":{"memory":"relation_and_commitment_dependent","proof_size":"constant_size_running_state_plus_optional_compression","prover":"one_primary_msm_style_per_fold_plus_sumcheck_work","verifier":"constant_size_incremental_state_plus_final_decider"},"configuration_note":"Displays CCS, multi-folding, and IVC/PCD capability as three different semantic layers.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-HYPERNOVA","name":"HyperNova","paper_ids":["PROOF-PAPER-2023-HYPERNOVA"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_displayed_commitment","privacy":"zero_knowledge_via_randomized_folding_in_updated_version","setup":"transparent_generators","soundness":"multifolding_soundness_plus_final_decider"},"research_lenses":["recursion-ivc","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-CCS"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-MULTIFOLD"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-SUMCHECK"],"specialized_argument":[]},"stack_status":{"specialized_argument":"out_of_scope"},"status":"published","summary":"It demonstrates how a more expressive relation layer and multi-instance composition should be represented without promoting either to a new top-level field.","system_family":"ccs_multifolding_ivc","tasks":["ivc","non_uniform_ivc","pcd"],"title":"HyperNova · CCS multi-folding configuration","visibility":"backbone","year":2023},{"claim_ids":["PROOF-CONTRIB-2023-JOLT-LOOKUPVM","PROOF-CONTRIB-2025-JOLT-SPACE"],"complexity":{"memory":"linear_baseline_with_source_backed_small_space_alternative","proof_size":"commitment_backend_dependent","prover":"dominated_by_execution_lookup_memory_and_commitment_work","verifier":"succinct_configuration_dependent"},"configuration_note":"Research architecture row; production implementations and PCS choices require versioned rows before benchmarking.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-JOLT","name":"Jolt","paper_ids":["PROOF-PAPER-2023-JOLT","PROOF-PAPER-2025-JOLT-SPACE"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"depends_on_selected_backend","privacy":"zero_knowledge_configuration_dependent","setup":"depends_on_selected_multilinear_commitment","soundness":"composition_of_spartan_lookup_and_memory_arguments"},"research_lenses":["lookups-zkvm","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-MLPCS"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-RISCV"],"protocol_iop":["PROOF-COMP-SUMCHECK"],"specialized_argument":["PROOF-COMP-LOOKUP","PROOF-COMP-MEMORY-CHECK"]},"stack_status":{"composition_mechanism":"optional_external"},"status":"published","summary":"Jolt makes visible why a zkVM is a system stack: ISA semantics, lookups, memory checking, R1CS/Spartan, and a PCS cannot be replaced by one “zkVM” category label.","system_family":"lookup_centric_zkvm","tasks":["zkvm","verifiable_cpu_execution"],"title":"Jolt · lookup-centric RISC-V zkVM stack","visibility":"backbone","year":2023},{"claim_ids":["PROOF-CONTRIB-2023-PROTOSTAR-GENERIC"],"complexity":{"memory":"not_reported","proof_size":"accumulator_state_plus_final_proof","prover":"per_step_cost_independent_of_lookup_table_size_in_stated_setting","verifier":"small_accumulation_verifier_plus_final_decider"},"configuration_note":"Concrete non-uniform IVC instantiation of the paper's generic special-sound accumulation compiler.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-PROTOSTAR","name":"Protostar","paper_ids":["PROOF-PAPER-2023-PROTOSTAR"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_displayed_commitment","privacy":"conditional_on_full_configuration","setup":"transparent_generators","soundness":"special_sound_accumulation_plus_final_decider"},"research_lenses":["recursion-ivc","lookups-zkvm"],"stack":{"arithmetization":["PROOF-COMP-PLONKISH"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-SPECIAL-SOUND-ACCUMULATION"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":["PROOF-COMP-LOOKUP"]},"stack_status":{},"status":"published","summary":"Generic accumulation and the Protostar PLONK/lookup instantiation are distinct objects linked by the source contribution.","system_family":"special_sound_accumulation_ivc","tasks":["non_uniform_ivc","vector_lookups"],"title":"Protostar · special-sound accumulation for PLONK","visibility":"backbone","year":2023}],"edges":[{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-0096734BDEAF28","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-IMPL-2026-JOLT-915FAF4","target":"PROOF-PAPER-2025-JOLT-SPACE","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-012BBFE2CFF349","note":"commitment_backend","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-BULLETPROOFS","target":"PROOF-COMP-IPA","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-017D63FD588112","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-IMPL-2025-LIBSPARTAN-3A2C097","target":"PROOF-PAPER-2019-SPARTAN","type":"DESCRIBED_IN"},{"evidenceLocator":"Jolt Section 3 system decomposition","evidenceUrl":"https://eprint.iacr.org/2023/1217","id":"PROOF-REL-047D5971C5E59E","note":"Jolt combines a Spartan-style sum-check SNARK for the residual R1CS relation with lookup and memory-checking arguments for a RISC-V execution.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2019-SPARTAN-R1CS","target":"PROOF-CONTRIB-2023-JOLT-LOOKUPVM","type":"COMBINES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-074669CE3C4A57","note":"arithmetization","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-SPARTAN","target":"PROOF-COMP-R1CS","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-0A84FF7214C259","note":"commitment_backend","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-NOVA","target":"PROOF-COMP-IPA","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-0AF33F4DC16E5A","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-IMPL-2026-NOVA-9092303","target":"PROOF-PAPER-2021-NOVA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-0B5B660BC8C3D6","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-PAPER-2025-BOOSTING-SNARKS","target":"PROOF-OP-001","type":"APPROACHES"},{"evidenceLocator":"HyperNova abstract and comparison with Nova","evidenceUrl":"https://eprint.iacr.org/2023/573","id":"PROOF-REL-0C05ED35D09A2B","note":"HyperNova generalizes the folding approach from relaxed R1CS to CCS, multiple folded instances, and non-uniform step circuits.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2021-NOVA-FOLDING","target":"PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD","type":"GENERALIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-0C9148A333CE19","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-R1CS","target":"PROOF-PAPER-2016-GROTH","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-0D59C2378E8DAC","note":"computation_model","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PROTOSTAR","target":"PROOF-COMP-CIRCUIT","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-0D9DE0585E737F","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-OP-003","target":"PROOF-PAPER-2025-IBCS-QUANTUM","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-0DEA4592A25A0B","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-FIAT-SHAMIR","target":"PROOF-PAPER-1986-FS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-11C33C881437DC","note":"arithmetization","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HYPERNOVA","target":"PROOF-COMP-CCS","type":"USES_COMPONENT"},{"evidenceLocator":"pinned jolt-sdk/src/host_utils.rs; jolt-core/src/jolt/vm/rv32i_vm.rs; rust-toolchain.toml; CI benchmark workflow","evidenceUrl":"https://github.com/a16z/jolt/tree/783da5d32010e707f85085d59ae0451f6d8a6b25","id":"PROOF-REL-12739731B7F566","note":"exact_commit_profile","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-IMPL-2025-JOLT-783DA5D","target":"PROOF-SYSTEM-JOLT","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-13036B4C784484","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-PAPER-2025-IBCS-QUANTUM","target":"PROOF-OP-003","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-15B32A02A27EA2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-R1CS","target":"PROOF-PAPER-2021-NOVA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-16301D0F640B78","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2019-SPARTAN","target":"PROOF-CONTRIB-2019-SPARTAN-R1CS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-165F0088E64B51","note":"protocol_iop","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HALO","target":"PROOF-COMP-INNER-PRODUCT","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-16B2966DAAC323","note":"","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-ROUTE-003","target":"PROOF-OP-003","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-175972E4E2ADE4","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-SUMCHECK","target":"PROOF-PAPER-1992-LFKN","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-1760BC9DECB2F9","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-002-03","target":"PROOF-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"benchmark data entry for commit 783da5d, sha2-chain-time and sha2-chain-mem; pinned examples/sha2-chain and CI workflow","evidenceUrl":"https://a16z.github.io/jolt/dev/bench/data.js","id":"PROOF-REL-179E79F98A0E75","note":"SHA2-chain guest; input [5u8; 32]; 100 sequential SHA-256 iterations","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-BENCH-2025-JOLT-SHA2-783DA5D","target":"PROOF-IMPL-2025-JOLT-783DA5D","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-17A0229134DCC0","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-CCS","target":"PROOF-PAPER-2023-HYPERNOVA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-17B0CECBBFA8BA","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-1990-FLS","target":"PROOF-CONTRIB-1990-FLS-MULTI-THEOREM","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-1A7DCF4680CC4C","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2025-IBCS-QUANTUM","target":"PROOF-CONTRIB-2025-IBCS-QUANTUM","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-1AB975597A437C","note":"arithmetization","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-BULLETPROOFS","target":"PROOF-COMP-R1CS","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-1CC015FD89BE9D","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2017-BULLETPROOFS","target":"PROOF-CONTRIB-2017-BULLETPROOFS-AGG","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-1D96B9F7EBAF61","note":"commitment_backend","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-JOLT","target":"PROOF-COMP-MLPCS","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-1ECC15427B4E86","note":"protocol_iop","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-JOLT","target":"PROOF-COMP-SUMCHECK","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-224494BB51E186","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-FRI","target":"PROOF-PAPER-2024-WHIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-22DD0BACF87936","note":"composition_mechanism","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-NOVA","target":"PROOF-COMP-RELAXED-FOLD","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-231D3F3ED6F874","note":"","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-ROUTE-004","target":"PROOF-OP-004","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-23EAE2839DEF1F","note":"compiler","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-NOVA","target":"PROOF-COMP-FIAT-SHAMIR","type":"USES_COMPONENT"},{"evidenceLocator":"Marlin Section 1.1 and polynomial-commitment instantiation","evidenceUrl":"https://eprint.iacr.org/2019/1047","id":"PROOF-REL-24483CEAD41F0E","note":"Marlin instantiates its AHP compiler with an extractable polynomial commitment; the promoted configuration uses the KZG line.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2010-KZG-PCS","target":"PROOF-CONTRIB-2019-MARLIN-AHP","type":"INSTANTIATES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-24917A72E1F877","note":"commitment_backend","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-STARK","target":"PROOF-COMP-FRI","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-2507BDDFC1D672","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-PAPER-2023-BEHEMOTH","target":"PROOF-OP-002","type":"APPROACHES"},{"evidenceLocator":"Proving CPU Executions in Small Space abstract and Section 7","evidenceUrl":"https://eprint.iacr.org/2025/611","id":"PROOF-REL-2574C6B903C2EF","note":"The small-space work retains the Jolt stack while changing the honest prover algorithm through streaming and recomputation instead of recursive sharding.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2023-JOLT-LOOKUPVM","target":"PROOF-CONTRIB-2025-JOLT-SPACE","type":"OPTIMIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-293DCBD72A76C3","note":"commitment_backend","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HYPERNOVA","target":"PROOF-COMP-IPA","type":"USES_COMPONENT"},{"evidenceLocator":"Nova introduction and folding-schemes section","evidenceUrl":"https://eprint.iacr.org/2021/370","id":"PROOF-REL-2D349218C0627D","note":"Nova uses relaxed-instance folding where recursive-wrapping approaches such as the displayed Halo configuration verify prior proofs; this compares composition objects and does not establish Halo-specific technical inheritance or unconditional improvement.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2019-HALO-RECURSION","target":"PROOF-CONTRIB-2021-NOVA-FOLDING","type":"CHANGES_COMPOSITION_MECHANISM"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-2D76CA71102C38","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PLONK-KZG","target":"PROOF-PAPER-2010-KZG","type":"DESCRIBED_IN"},{"evidenceLocator":"README, Details of the library, Supported front-ends, Cargo Features, Tests and examples, and Universal Setup","evidenceUrl":"https://github.com/microsoft/Nova/tree/909230314a7173b0f96d06e0c810d10f65f599f1","id":"PROOF-REL-2EBAE82623ED72","note":"versioned_library_with_multiple_explicit_backends","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-IMPL-2026-NOVA-9092303","target":"PROOF-SYSTEM-NOVA","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-2F1D403A2A12DC","note":"protocol_iop","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-STARK","target":"PROOF-COMP-POLY-IOP","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-307EBC38241A9D","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-1992-LFKN","target":"PROOF-CONTRIB-1992-LFKN-SUMCHECK","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3182E30D1287C8","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HYPERNOVA","target":"PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-321EAAFDD10F35","note":"commitment_backend","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PLONK-KZG","target":"PROOF-COMP-KZG","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-323957359D759F","note":"computation_model","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PLONK-KZG","target":"PROOF-COMP-CIRCUIT","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-33ED5BD81957A3","note":"arithmetization","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-MARLIN-KZG","target":"PROOF-COMP-R1CS","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3749150FDFF4F1","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PROTOSTAR","target":"PROOF-PAPER-2023-PROTOSTAR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3813A95734DA5C","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-OP-002","target":"PROOF-PAPER-2023-BEHEMOTH","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3944D1A00E7BBB","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-STARK","target":"PROOF-PAPER-2018-STARK","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-39C9E47A57DC01","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-BULLETPROOFS","target":"PROOF-CONTRIB-2017-BULLETPROOFS-IPA","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3A195B88952A7B","note":"computation_model","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HYPERNOVA","target":"PROOF-COMP-CIRCUIT","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3A5D15853DE2B9","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-MLPCS","target":"PROOF-PAPER-2019-SPARTAN","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3AFE67EE0DCB12","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-IMPL-2026-JOLT-915FAF4","target":"PROOF-PAPER-2023-JOLT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3B4CA4AA14E3DF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-SPECIAL-SOUND-ACCUMULATION","target":"PROOF-PAPER-2023-PROTOSTAR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3C7DC79EE82FC0","note":"computation_model","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-BULLETPROOFS","target":"PROOF-COMP-CIRCUIT","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3C90A562ED42F2","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-PAPER-2023-PROTOSTAR","target":"PROOF-OP-004","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3E06E6F55B7ED4","note":"protocol_iop","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HYPERNOVA","target":"PROOF-COMP-SUMCHECK","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3E94E326D0CE47","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2016-GROTH","target":"PROOF-CONTRIB-2016-GROTH-3ELEMENT","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-3F5D04FE3CB574","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-MEMORY-CHECK","target":"PROOF-PAPER-2025-JOLT-SPACE","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-40C79BFA06C2D0","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-1992-KILIAN","target":"PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-44C52D36C20921","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-003-03","target":"PROOF-OP-003","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-4624E584E21258","note":"arithmetization","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-JOLT","target":"PROOF-COMP-R1CS","type":"USES_COMPONENT"},{"evidenceLocator":"PLONK introduction and comparison table","evidenceUrl":"https://eprint.iacr.org/2019/953","id":"PROOF-REL-46726C69FDBD97","note":"Relative to the compared circuit-specific Groth16 configuration, PLONK offers a degree-bounded universal and updatable structured reference string; the comparison changes setup reuse, not an unconditional ordering of proof size, security, or all configurations.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2016-GROTH-3ELEMENT","target":"PROOF-CONTRIB-2019-PLONK-PIOP","type":"CHANGES_SETUP"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-47485F839E2915","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-JOLT","target":"PROOF-CONTRIB-2025-JOLT-SPACE","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-48C4A6866F60A3","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-IMPL-2024-STONE-1414A54","target":"PROOF-PAPER-2018-STARK","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-4915B1162B81E4","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-001-02","target":"PROOF-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-4987B950A4D345","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2018-STARK","target":"PROOF-CONTRIB-2018-STARK-SYSTEM","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-4C9525CA2D184E","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-001-03","target":"PROOF-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-4CE06382709391","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-MULTIFOLD","target":"PROOF-PAPER-2023-HYPERNOVA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-4D2AF15120AD6A","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-LOOKUP","target":"PROOF-PAPER-2023-JOLT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-4E5C695B57B5EF","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-002-01","target":"PROOF-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-4E9155CC96B8FB","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-STARK","target":"PROOF-CONTRIB-2018-STARK-SYSTEM","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-4F73244786502E","note":"specialized_argument","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PROTOSTAR","target":"PROOF-COMP-LOOKUP","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-53E42B1D65A225","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-RISCV","target":"PROOF-PAPER-2023-JOLT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-53E67FDFF1AD7E","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2023-PROTOSTAR","target":"PROOF-CONTRIB-2023-PROTOSTAR-GENERIC","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-5435F3218E213D","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2024-PLONK-KS","target":"PROOF-CONTRIB-2024-PLONK-KS","type":"HAS_RESULT"},{"evidenceLocator":"Halo Section 1.1 and polynomial commitment section","evidenceUrl":"https://eprint.iacr.org/2019/1021","id":"PROOF-REL-55081A704D13E7","note":"Halo builds its polynomial commitment from the inner-product argument line and adds amortization and curve-cycle machinery for recursive composition.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2017-BULLETPROOFS-IPA","target":"PROOF-CONTRIB-2019-HALO-RECURSION","type":"BUILDS_ON_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-5544C176C73DA6","note":"specialized_argument","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-JOLT","target":"PROOF-COMP-MEMORY-CHECK","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-55BD66B7E7BA9A","note":"","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-BARRIER-001","target":"PROOF-OP-001","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-5875C5F4602725","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-MARLIN-KZG","target":"PROOF-CONTRIB-2019-MARLIN-AHP","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-58F70452750D88","note":"","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-ROUTE-002","target":"PROOF-OP-002","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-5942195F27DCE2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-CIRCUIT","target":"PROOF-PAPER-2016-GROTH","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-59438705E834EA","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-004-02","target":"PROOF-OP-004","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-5A9648D31E686F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-POLY-IOP","target":"PROOF-PAPER-2019-MARLIN","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-5AF39CEB103742","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2024-LATTICE-PCS","target":"PROOF-CONTRIB-2024-LATTICE-PCS-PQ","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-5BD5D978B75A33","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-SUMCHECK","target":"PROOF-PAPER-2019-SPARTAN","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-5DCD30664CFDA1","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HALO","target":"PROOF-PAPER-2019-HALO","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-5DEBAB6BA25AAA","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2017-BULLETPROOFS","target":"PROOF-CONTRIB-2017-BULLETPROOFS-IPA","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-5E4DC86800517C","note":"commitment_backend","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HALO","target":"PROOF-COMP-IPA","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-64FE21DD3A744A","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-IPA","target":"PROOF-PAPER-2017-BULLETPROOFS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-652C7C9033DB5C","note":"commitment_backend","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-SPARTAN","target":"PROOF-COMP-MLPCS","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-678B2516F14F86","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2024-WHIR","target":"PROOF-CONTRIB-2024-WHIR-PROXIMITY","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-680E496F341ABB","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2019-HALO","target":"PROOF-CONTRIB-2019-HALO-RECURSION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-6993158B5964BE","note":"computation_model","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-MARLIN-KZG","target":"PROOF-COMP-CIRCUIT","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-6A97500D77DD04","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2010-KZG","target":"PROOF-CONTRIB-2010-KZG-PCS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-6BA749FCB06246","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-OP-001","target":"PROOF-PAPER-2026-SNARG-UNPROVABILITY","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-6C741AC1F4AEEF","note":"arithmetization","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PROTOSTAR","target":"PROOF-COMP-PLONKISH","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-6C879B772996DE","note":"composition_mechanism","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PROTOSTAR","target":"PROOF-COMP-SPECIAL-SOUND-ACCUMULATION","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-6E424D3FF44341","note":"computation_model","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HALO","target":"PROOF-COMP-CIRCUIT","type":"USES_COMPONENT"},{"evidenceLocator":"PLONK polynomial commitment instantiation and protocol sections","evidenceUrl":"https://eprint.iacr.org/2019/953","id":"PROOF-REL-6E502D4DCE0872","note":"The displayed PLONK configuration realizes polynomial commitments and evaluation openings with the KZG structured pairing backend.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2010-KZG-PCS","target":"PROOF-CONTRIB-2019-PLONK-PIOP","type":"INSTANTIATES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-6F25BB7F14854D","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-BARRIER-002","target":"PROOF-OP-002","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-6F6763056CD968","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-JOLT","target":"PROOF-CONTRIB-2023-JOLT-LOOKUPVM","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-7043EE72C1B4E6","note":"compiler","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-SPARTAN","target":"PROOF-COMP-FIAT-SHAMIR","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-709D5409BCC74C","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-INNER-PRODUCT","target":"PROOF-PAPER-2017-BULLETPROOFS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-7238224865E205","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-003-01","target":"PROOF-OP-003","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-725984038920AA","note":"computation_model","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-JOLT","target":"PROOF-COMP-RISCV","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-72B05D76CCF58B","note":"commitment_backend","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-MARLIN-KZG","target":"PROOF-COMP-KZG","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-736B1D50690BFF","note":"computation_model","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-SPARTAN","target":"PROOF-COMP-CIRCUIT","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-74480104B03D7A","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PLONK-KZG","target":"PROOF-CONTRIB-2019-PLONK-PIOP","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"benchmark data entry for commit 915faf4, sha2-chain-time and sha2-chain-mem; pinned examples/sha2-chain, host_utils, rust-toolchain, and CI workflow","evidenceUrl":"https://a16z.github.io/jolt/dev/bench/data.js","id":"PROOF-REL-76F83C8E517169","note":"SHA2-chain guest; input [5u8; 32]; 1000 sequential Jolt-inline SHA-256 iterations","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-BENCH-2026-JOLT-SHA2-915FAF4","target":"PROOF-IMPL-2026-JOLT-915FAF4","type":"BENCHMARKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-7717B4A0D21EBF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-MARLIN-KZG","target":"PROOF-PAPER-2010-KZG","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-7761AF366B2477","note":"arithmetization","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-NOVA","target":"PROOF-COMP-R1CS","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-77EF9F85E95DC6","note":"protocol_iop","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PLONK-KZG","target":"PROOF-COMP-POLY-IOP","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-79EFEB67D093BB","note":"composition_mechanism","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HALO","target":"PROOF-COMP-RECURSIVE-WRAP","type":"USES_COMPONENT"},{"evidenceLocator":"Cargo.toml package version; README, Highlights, Implementation details, Examples, Building libspartan, and Performance","evidenceUrl":"https://github.com/microsoft/Spartan/tree/3a2c097cab39ffa191560f445440a41ed40db5b3","id":"PROOF-REL-7A4EF91376FD35","note":"exact_spartan_library_variant","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-IMPL-2025-LIBSPARTAN-3A2C097","target":"PROOF-SYSTEM-SPARTAN","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-7D62457783EC34","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2024-REALWORLD-SE","target":"PROOF-CONTRIB-2024-REALWORLD-SE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-80E1B0D092040A","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2026-SNARG-UNPROVABILITY","target":"PROOF-CONTRIB-2026-SNARG-UNPROVABILITY","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-81BCCAD6A1E81D","note":"compiler","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-BULLETPROOFS","target":"PROOF-COMP-FIAT-SHAMIR","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-8456E750BD0821","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-MEMORY-CHECK","target":"PROOF-PAPER-2023-JOLT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-847359985E08F2","note":"compiler","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-STARK","target":"PROOF-COMP-FIAT-SHAMIR","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-864A7D060DF9A4","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-PLONKISH","target":"PROOF-PAPER-2023-PROTOSTAR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-869ED6379D0293","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-POLY-IOP","target":"PROOF-PAPER-2019-PLONK","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-86C18362D4E0CC","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-MLPCS","target":"PROOF-PAPER-2024-WHIR","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-88CF4BADC70EA6","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2023-BEHEMOTH","target":"PROOF-CONTRIB-2023-BEHEMOTH-CONSTANT","type":"HAS_RESULT"},{"evidenceLocator":"STARK introduction and related-work discussion","evidenceUrl":"https://eprint.iacr.org/2018/046","id":"PROOF-REL-89A4A9AFF5CDEF","note":"STARKs and Kilian's commitment-backed PCP construction share the authenticated-oracle proof tradition; the recorded comparison does not establish that the displayed STARK stack directly instantiates Kilian's construction.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT","target":"PROOF-CONTRIB-2018-STARK-SYSTEM","type":"ARCHITECTURAL_CONTEXT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-8DC8F6140313D2","note":"computation_model","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-NOVA","target":"PROOF-COMP-CIRCUIT","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-8F9FFB9A5728AE","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2021-NOVA","target":"PROOF-CONTRIB-2021-NOVA-FOLDING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-8FF5C0A77D0B72","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-MARLIN-KZG","target":"PROOF-CONTRIB-2024-REALWORLD-SE","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"WHIR introduction and experimental comparison","evidenceUrl":"https://eprint.iacr.org/2024/1586","id":"PROOF-REL-9312A8A51155FB","note":"WHIR improves verifier work for compared Reed-Solomon proximity and hash-based commitment configurations relevant to transparent proof systems; the recorded comparison does not establish a drop-in improvement of the entire displayed STARK stack.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2018-STARK-SYSTEM","target":"PROOF-CONTRIB-2024-WHIR-PROXIMITY","type":"RELATED_COMPONENT_OPTIMIZATION"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-93652EF9BB0077","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-SPARTAN","target":"PROOF-PAPER-2019-SPARTAN","type":"DESCRIBED_IN"},{"evidenceLocator":"Spartan abstract and protocol overview","evidenceUrl":"https://eprint.iacr.org/2019/550","id":"PROOF-REL-93D2E6508F315E","note":"Spartan composes its R1CS encoding and commitment machinery with the sum-check protocol to obtain its core interactive argument.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-1992-LFKN-SUMCHECK","target":"PROOF-CONTRIB-2019-SPARTAN-R1CS","type":"BUILDS_ON_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-94B0D1B19875C1","note":"compiler","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-JOLT","target":"PROOF-COMP-FIAT-SHAMIR","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-96A2715C0D6497","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-IMPL-2025-JOLT-783DA5D","target":"PROOF-PAPER-2023-JOLT","type":"DESCRIBED_IN"},{"evidenceLocator":"pinned README; jolt-sdk/src/host_utils.rs; rust-toolchain.toml; CI workflow; examples/sha2-chain; benchmark dashboard","evidenceUrl":"https://github.com/a16z/jolt/tree/915faf453f36871249615a7fdf2704d77a88f259","id":"PROOF-REL-970F266B392715","note":"exact_commit_profile","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-IMPL-2026-JOLT-915FAF4","target":"PROOF-SYSTEM-JOLT","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-984112718A25D0","note":"computation_model","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-STARK","target":"PROOF-COMP-CIRCUIT","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-9A1261B234916D","note":"arithmetization","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-GROTH16","target":"PROOF-COMP-QAP","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-9A6F19B3548386","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-SPARTAN","target":"PROOF-CONTRIB-2019-SPARTAN-R1CS","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-9B6D92C89F20A4","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-NOVA","target":"PROOF-CONTRIB-2021-NOVA-FOLDING","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-9C2E35DDDE6A05","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-OP-001","target":"PROOF-PAPER-2025-BOOSTING-SNARKS","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-9C51AA6CAE34E2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-IMPL-2026-NOVA-9092303","target":"PROOF-PAPER-2023-HYPERNOVA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-9DF7A5BFD02325","note":"arithmetization","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-STARK","target":"PROOF-COMP-AIR","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-A14EF14C67302E","note":"protocol_iop","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-MARLIN-KZG","target":"PROOF-COMP-POLY-IOP","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-A2E7638F8CC40D","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-PAIRING-QAP","target":"PROOF-PAPER-2016-GROTH","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-A4E6B9E5789ABE","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-PAPER-2021-NOVA","target":"PROOF-OP-004","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-A5A182FB394684","note":"protocol_iop","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-SPARTAN","target":"PROOF-COMP-SUMCHECK","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-A6366FC3EF3ED2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-AIR","target":"PROOF-PAPER-2018-STARK","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-A7EC8DF90760D6","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-1988-BFM","target":"PROOF-CONTRIB-1988-BFM-NIZK-MODEL","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-A7F190BE388F98","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-PAPER-2020-ACCUMULATION","target":"PROOF-OP-004","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-A7F24EBCA6B972","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-OP-004","target":"PROOF-PAPER-2020-ACCUMULATION","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-AA222AB2E7E2EF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-INNER-PRODUCT","target":"PROOF-PAPER-2019-HALO","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-AB27CE181B4105","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-002-02","target":"PROOF-OP-002","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-AC365D5E046BDA","note":"arithmetization","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PLONK-KZG","target":"PROOF-COMP-PLONKISH","type":"USES_COMPONENT"},{"evidenceLocator":"benchmark data entry for commit 783da5d, sha2-chain-time and sha2-chain-mem; pinned examples/sha2-chain and CI workflow","evidenceUrl":"https://a16z.github.io/jolt/dev/bench/data.js","id":"PROOF-REL-AFD3D9ADBFDE15","note":"RV32IM Jolt with BN254 HyperKZG and Keccak transcript at 783da5d","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-BENCH-2025-JOLT-SHA2-783DA5D","target":"PROOF-SYSTEM-JOLT","type":"MEASURES_CONFIGURATION"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-B0DC4AFBA1E2C1","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-BULLETPROOFS","target":"PROOF-PAPER-2017-BULLETPROOFS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-B1C22B878E2952","note":"compiler","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PLONK-KZG","target":"PROOF-COMP-FIAT-SHAMIR","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-B1C5AB7C9254E8","note":"computation_model","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-GROTH16","target":"PROOF-COMP-CIRCUIT","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-B21EBF9A122335","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-R1CS","target":"PROOF-PAPER-2019-SPARTAN","type":"DESCRIBED_IN"},{"evidenceLocator":"On Knowledge-Soundness of Plonk abstract and batching theorems","evidenceUrl":"https://eprint.iacr.org/2024/994","id":"PROOF-REL-B2207181576363","note":"The PLONK knowledge-soundness work analyzes computational special soundness for KZG batch-opening protocols used by modern configurations.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2010-KZG-PCS","target":"PROOF-CONTRIB-2024-PLONK-KS","type":"ANALYZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-B545D3ED1DDB41","note":"arithmetization","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-GROTH16","target":"PROOF-COMP-R1CS","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-B626EC291F6C3C","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HYPERNOVA","target":"PROOF-PAPER-2023-HYPERNOVA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-B78E743313097E","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-QAP","target":"PROOF-PAPER-2016-GROTH","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-B7EFE1B9CFA4D7","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-1986-FS","target":"PROOF-CONTRIB-1986-FS-COMPILER","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-B9EB3CECC5D0BA","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-GROTH16","target":"PROOF-PAPER-2016-GROTH","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-BADDF7D6C3A4DA","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-1989-GMR","target":"PROOF-CONTRIB-1989-GMR-ZK","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-BB27DBC66090BD","note":"protocol_iop","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-GROTH16","target":"PROOF-COMP-PAIRING-QAP","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-BD0C216C61C7EB","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-004-03","target":"PROOF-OP-004","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-BF7AE292721895","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-NOVA","target":"PROOF-PAPER-2021-NOVA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-BFD177C2C53E0E","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-RECURSIVE-WRAP","target":"PROOF-PAPER-2019-HALO","type":"DESCRIBED_IN"},{"evidenceLocator":"On Knowledge-Soundness of Plonk abstract and PLONK theorems","evidenceUrl":"https://eprint.iacr.org/2024/994","id":"PROOF-REL-BFE8D181C2F435","note":"The later work isolates interactive PLONK special soundness and the assumptions needed before a random-oracle compilation claim.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2019-PLONK-PIOP","target":"PROOF-CONTRIB-2024-PLONK-KS","type":"ANALYZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-C135BBD343DC3A","note":"protocol_iop","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-BULLETPROOFS","target":"PROOF-COMP-INNER-PRODUCT","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-C1F0FA3D72FEB0","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2019-MARLIN","target":"PROOF-CONTRIB-2019-MARLIN-AHP","type":"HAS_RESULT"},{"evidenceLocator":"Protostar abstract and concrete instantiation","evidenceUrl":"https://eprint.iacr.org/2023/620","id":"PROOF-REL-C2AF51BFB137A8","note":"Protostar instantiates its special-sound accumulation compiler for a PLONK-style relation with high-degree gates and vector lookups.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2019-PLONK-PIOP","target":"PROOF-CONTRIB-2023-PROTOSTAR-GENERIC","type":"ACCUMULATES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-C3E9E26BFE106A","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-IPA","target":"PROOF-PAPER-2021-NOVA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-C5C9759EA2FD9D","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-IPA","target":"PROOF-PAPER-2019-HALO","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-C8A3181825BB0F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2019-PLONK","target":"PROOF-CONTRIB-2019-PLONK-PIOP","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-CB57397E948F2A","note":"","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-ROUTE-001","target":"PROOF-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-CCC35D329CABD9","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-SUMCHECK","target":"PROOF-PAPER-2023-HYPERNOVA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-CD23E930D64695","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-LOOKUP","target":"PROOF-PAPER-2023-PROTOSTAR","type":"DESCRIBED_IN"},{"evidenceLocator":"benchmark data entry for commit 915faf4, sha2-chain-time and sha2-chain-mem; pinned examples/sha2-chain, host_utils, rust-toolchain, and CI workflow","evidenceUrl":"https://a16z.github.io/jolt/dev/bench/data.js","id":"PROOF-REL-D15249CA39CFA7","note":"RV64IMAC Jolt with Dory over BN254 and default legacy Blake2b transcript at 915faf4","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-BENCH-2026-JOLT-SHA2-915FAF4","target":"PROOF-SYSTEM-JOLT","type":"MEASURES_CONFIGURATION"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-D2E9ECF70A56AE","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HALO","target":"PROOF-CONTRIB-2019-HALO-RECURSION","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-D36879BE109600","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-PLONKISH","target":"PROOF-PAPER-2019-PLONK","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-D6123DFB756B37","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-JOLT","target":"PROOF-PAPER-2025-JOLT-SPACE","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-D7B6B75597D3B4","note":"composition_mechanism","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HYPERNOVA","target":"PROOF-COMP-MULTIFOLD","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-D81C2D63F59A02","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2025-JOLT-SPACE","target":"PROOF-CONTRIB-2025-JOLT-SPACE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-D8EF4D8A815028","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PLONK-KZG","target":"PROOF-CONTRIB-2024-PLONK-KS","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"Real-world Universal zkSNARKs abstract and system coverage","evidenceUrl":"https://eprint.iacr.org/2024/721","id":"PROOF-REL-D94790239E7969","note":"The later security analysis includes optimized Marlin-style universal zkSNARK configurations within its simulation-extractability framework.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2019-MARLIN-AHP","target":"PROOF-CONTRIB-2024-REALWORLD-SE","type":"ANALYZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-DA6AA42E4025CD","note":"compiler","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PROTOSTAR","target":"PROOF-COMP-FIAT-SHAMIR","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-DACDFF04E21700","note":"protocol_iop","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PROTOSTAR","target":"PROOF-COMP-POLY-IOP","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-DBC5FF15AF7624","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-PAPER-2024-LATTICE-PCS","target":"PROOF-OP-002","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-DE6FBC6268488C","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PLONK-KZG","target":"PROOF-CONTRIB-2024-REALWORLD-SE","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"Real-world Universal zkSNARKs abstract and main theorems","evidenceUrl":"https://eprint.iacr.org/2024/721","id":"PROOF-REL-DFF51E65DB7B0B","note":"The later security analysis proves simulation extractability for optimized real-world PLONK-style configurations satisfying its conditions.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-2019-PLONK-PIOP","target":"PROOF-CONTRIB-2024-REALWORLD-SE","type":"ANALYZES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-E01D0E8F9E40ED","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-KZG","target":"PROOF-PAPER-2010-KZG","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-E0B52D33EDF878","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-004-01","target":"PROOF-OP-004","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-E14B3D5A1D47B6","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-001-01","target":"PROOF-OP-001","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-E2CFB5F98E1C41","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-JOLT","target":"PROOF-PAPER-2023-JOLT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-E4E3D6034F51FF","note":"compiler","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-MARLIN-KZG","target":"PROOF-COMP-FIAT-SHAMIR","type":"USES_COMPONENT"},{"evidenceLocator":"HyperNova abstract and folding construction overview","evidenceUrl":"https://eprint.iacr.org/2023/573","id":"PROOF-REL-E5ECFB2A91ECEB","note":"HyperNova's CCS multi-folding protocol uses sum-check-style reductions to fold multiple constraint instances.","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-CONTRIB-1992-LFKN-SUMCHECK","target":"PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD","type":"BUILDS_ON_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-E8DA932C73DAA2","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-RELAXED-FOLD","target":"PROOF-PAPER-2021-NOVA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-EA7E7B779AF038","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2020-ACCUMULATION","target":"PROOF-CONTRIB-2020-ACCUMULATION-PCD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-EAD164023FF6DF","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PLONK-KZG","target":"PROOF-PAPER-2019-PLONK","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-EDE700213C3EAF","note":"","resultId":null,"reviewStatus":"source_derived","source":"PROOF-MILESTONE-003-02","target":"PROOF-OP-003","type":"STEPPING_STONE_FOR"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-EE0CC1ED3CB505","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2023-HYPERNOVA","target":"PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-EEE9945A6EDAF4","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PROTOSTAR","target":"PROOF-CONTRIB-2023-PROTOSTAR-GENERIC","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"README, Overview, Installation, proof-generation walkthrough, verifier note, and input-size configuration","evidenceUrl":"https://github.com/starkware-libs/stone-prover/tree/1414a545e4fb38a85391289abe91dd4467d268e1","id":"PROOF-REL-EF67CB57964791","note":"exact_cairo_cpu_air_profile","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-IMPL-2024-STONE-1414A54","target":"PROOF-SYSTEM-STARK","type":"IMPLEMENTS"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F00779E8215207","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2025-GALOIS","target":"PROOF-CONTRIB-2025-GALOIS-RINGS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F04E92EEBE6011","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-FRI","target":"PROOF-PAPER-2018-STARK","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F131DCD250D9A6","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2025-BOOSTING-SNARKS","target":"PROOF-CONTRIB-2025-BOOSTING-SNARKS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F13728A6700142","note":"","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-BARRIER-004","target":"PROOF-OP-004","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F2212DF6DD8CCF","note":"compiler","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HYPERNOVA","target":"PROOF-COMP-FIAT-SHAMIR","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F3C3677F2DD86A","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-PAPER-2026-SNARG-UNPROVABILITY","target":"PROOF-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F4DA4D02743651","note":"specialized_argument","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-JOLT","target":"PROOF-COMP-LOOKUP","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F518D36BB7A2FC","note":"compiler","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-HALO","target":"PROOF-COMP-FIAT-SHAMIR","type":"USES_COMPONENT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F56DF99A371EB4","note":"","resultId":null,"reviewStatus":"primary_source_checked","source":"PROOF-BARRIER-003","target":"PROOF-OP-003","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F62B51B13BA712","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-PAPER-2023-JOLT","target":"PROOF-CONTRIB-2023-JOLT-LOOKUPVM","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F72B2BF732688F","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-COMP-MLPCS","target":"PROOF-PAPER-2023-JOLT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F7651F7671CDAD","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-MARLIN-KZG","target":"PROOF-PAPER-2019-MARLIN","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F79B48A1995AA3","note":"","resultId":null,"reviewStatus":"claim_audited","source":"PROOF-PAPER-2024-WHIR","target":"PROOF-OP-002","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F80FA57D59C290","note":"","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-GROTH16","target":"PROOF-CONTRIB-2016-GROTH-3ELEMENT","type":"SUPPORTED_BY_CLAIM"},{"evidenceLocator":"","evidenceUrl":"","id":"PROOF-REL-F933EBD7550784","note":"commitment_backend","resultId":null,"reviewStatus":"source_declared","source":"PROOF-SYSTEM-PROTOSTAR","target":"PROOF-COMP-IPA","type":"USES_COMPONENT"}],"implementations":[{"artifact":{"commit":"1414a545e4fb38a85391289abe91dd4467d268e1","commit_url":"https://github.com/starkware-libs/stone-prover/tree/1414a545e4fb38a85391289abe91dd4467d268e1","repository":"https://github.com/starkware-libs/stone-prover","version":"Stone-v3-1414a54"},"artifact_type":"open-source prover and verifier","availability":"public repository and Dockerfile; Linux-only support stated","backend":"Cairo CPU AIR with FRI-based STARK prover and verifier","benchmark_eligibility_note":"The repository documents end-to-end execution but does not publish a compatibility-complete timing observation bound to this commit.","benchmark_eligible":false,"configuration_binding":"exact_cairo_cpu_air_profile","configuration_ids":["PROOF-SYSTEM-STARK"],"evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-IMPL-2024-STONE-1414A54","language":"C++ with Docker build and Cairo/CairoZero tooling","maturity":"engineering artifact with explicit verifier boundary","paper_ids":["PROOF-PAPER-2018-STARK"],"primaryUrl":"https://github.com/starkware-libs/stone-prover/tree/1414a545e4fb38a85391289abe91dd4467d268e1","realized_stack":{"arithmetization":"CPU AIR","commitment_backend":"FRI and hash-authenticated oracle layers","compiler":"Fiat-Shamir style non-interactive prover configuration","composition_mechanism":"not_applicable","computation_model":"Cairo/CairoZero CPU execution","protocol_iop":"STARK polynomial IOP","specialized_argument":"Cairo CPU builtins handled by configuration and external checks"},"source_locator":"README, Overview, Installation, proof-generation walkthrough, verifier note, and input-size configuration","source_urls":["https://github.com/starkware-libs/stone-prover/blob/1414a545e4fb38a85391289abe91dd4467d268e1/README.md"],"status":"reported","title":"Stone Prover v3 at 1414a54","year":2024},{"artifact":{"commit":"783da5d32010e707f85085d59ae0451f6d8a6b25","commit_url":"https://github.com/a16z/jolt/tree/783da5d32010e707f85085d59ae0451f6d8a6b25","repository":"https://github.com/a16z/jolt","version":"commit-783da5d"},"artifact_type":"open-source alpha zkVM","availability":"public repository","backend":"RV32IM Jolt with BN254 HyperKZG PCS and Keccak transcript","benchmark_eligibility_note":"One commit-bound CI observation is curated; missing CPU/thread/security coordinates keep it out of rankings.","benchmark_eligible":true,"configuration_binding":"exact_commit_profile","configuration_ids":["PROOF-SYSTEM-JOLT"],"evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-IMPL-2025-JOLT-783DA5D","language":"Rust","maturity":"alpha, unaudited research implementation","paper_ids":["PROOF-PAPER-2023-JOLT"],"primaryUrl":"https://github.com/a16z/jolt/tree/783da5d32010e707f85085d59ae0451f6d8a6b25","realized_stack":{"arithmetization":"Jolt instruction and memory constraints","commitment_backend":"HyperKZG over BN254","compiler":"Fiat-Shamir with Keccak transcript","composition_mechanism":"not_applicable","computation_model":"RV32IM","protocol_iop":"lookup/sum-check architecture","specialized_argument":"Lasso-style instruction lookups and memory checking"},"source_locator":"pinned jolt-sdk/src/host_utils.rs; jolt-core/src/jolt/vm/rv32i_vm.rs; rust-toolchain.toml; CI benchmark workflow","source_urls":["https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/jolt-sdk/src/host_utils.rs","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/jolt-core/src/jolt/vm/rv32i_vm.rs","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/rust-toolchain.toml","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/.github/workflows/ci-bench.yml"],"status":"reported","title":"Jolt RV32IM / HyperKZG at 783da5d","year":2025},{"artifact":{"commit":"3a2c097cab39ffa191560f445440a41ed40db5b3","commit_url":"https://github.com/microsoft/Spartan/tree/3a2c097cab39ffa191560f445440a41ed40db5b3","repository":"https://github.com/microsoft/Spartan","version":"0.9.0+3a2c097"},"artifact_type":"open-source research library","availability":"public repository and crates.io package","backend":"Ristretto255 vector commitments, Spartan SNARK and NIZK APIs, Merlin transcript","benchmark_eligibility_note":"The README preserves profiler output, but does not bind that historical output to an immutable generating commit, so it is not promoted as a benchmark run.","benchmark_eligible":false,"configuration_binding":"exact_spartan_library_variant","configuration_ids":["PROOF-SYSTEM-SPARTAN"],"evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-IMPL-2025-LIBSPARTAN-3A2C097","language":"Rust","maturity":"unaudited research library","paper_ids":["PROOF-PAPER-2019-SPARTAN"],"primaryUrl":"https://github.com/microsoft/Spartan/tree/3a2c097cab39ffa191560f445440a41ed40db5b3","realized_stack":{"arithmetization":"R1CS","commitment_backend":"Ristretto255 discrete-log vector commitment","compiler":"Merlin Fiat-Shamir transcript","composition_mechanism":"not_applicable","computation_model":"arbitrary R1CS instance","protocol_iop":"Spartan sum-check reductions","specialized_argument":"not_applicable"},"source_locator":"Cargo.toml package version; README, Highlights, Implementation details, Examples, Building libspartan, and Performance","source_urls":["https://github.com/microsoft/Spartan/blob/3a2c097cab39ffa191560f445440a41ed40db5b3/Cargo.toml","https://github.com/microsoft/Spartan/blob/3a2c097cab39ffa191560f445440a41ed40db5b3/README.md"],"status":"reported","title":"libspartan at 3a2c097","year":2025},{"artifact":{"commit":"915faf453f36871249615a7fdf2704d77a88f259","commit_url":"https://github.com/a16z/jolt/tree/915faf453f36871249615a7fdf2704d77a88f259","repository":"https://github.com/a16z/jolt","version":"commit-915faf4"},"artifact_type":"open-source alpha zkVM","availability":"public repository, documentation, and continuous benchmark dashboard","backend":"RV64IMAC Jolt with Dory PCS over BN254 and Pedersen vector commitments","benchmark_eligibility_note":"One commit-bound CI observation is curated; missing CPU/thread/security coordinates keep it out of rankings.","benchmark_eligible":true,"configuration_binding":"exact_commit_profile","configuration_ids":["PROOF-SYSTEM-JOLT"],"evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-IMPL-2026-JOLT-915FAF4","language":"Rust","maturity":"alpha, unaudited research implementation","paper_ids":["PROOF-PAPER-2023-JOLT","PROOF-PAPER-2025-JOLT-SPACE"],"primaryUrl":"https://github.com/a16z/jolt/tree/915faf453f36871249615a7fdf2704d77a88f259","realized_stack":{"arithmetization":"Jolt instruction, bytecode, memory, and R1CS layers","commitment_backend":"Dory over BN254 with Pedersen vector commitments","compiler":"legacy Blake2b transcript in default host profile","composition_mechanism":"optional_external","computation_model":"RV64IMAC","protocol_iop":"lookup/sum-check architecture","specialized_argument":"instruction lookup and memory-checking stack"},"source_locator":"pinned README; jolt-sdk/src/host_utils.rs; rust-toolchain.toml; CI workflow; examples/sha2-chain; benchmark dashboard","source_urls":["https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/README.md","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/jolt-sdk/src/host_utils.rs","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/rust-toolchain.toml","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/.github/workflows/ci-bench.yml"],"status":"reported","title":"Jolt RV64IMAC / Dory at 915faf4","year":2026},{"artifact":{"commit":"909230314a7173b0f96d06e0c810d10f65f599f1","commit_url":"https://github.com/microsoft/Nova/tree/909230314a7173b0f96d06e0c810d10f65f599f1","repository":"https://github.com/microsoft/Nova","version":"0.73.0+9092303"},"artifact_type":"open-source research library","availability":"public repository","backend":"Nova folding with Pedersen/IPA, HyperKZG, or Mercury compression paths over supported curve cycles","benchmark_eligibility_note":"A benchmark row must select curve cycle, commitment/compression backend, circuit frontend, feature set, and whether setup/compression is included; no such run is curated here.","benchmark_eligible":false,"configuration_binding":"versioned_library_with_multiple_explicit_backends","configuration_ids":["PROOF-SYSTEM-NOVA"],"evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-IMPL-2026-NOVA-9092303","language":"Rust","maturity":"research library with experimental feature gates","paper_ids":["PROOF-PAPER-2021-NOVA","PROOF-PAPER-2023-HYPERNOVA"],"primaryUrl":"https://github.com/microsoft/Nova/tree/909230314a7173b0f96d06e0c810d10f65f599f1","realized_stack":{"arithmetization":"relaxed R1CS folding core","commitment_backend":"Pedersen/IPA on supported cycles; HyperKZG or Mercury on BN254","compiler":"library transcript and selected frontend path","composition_mechanism":"Nova folding with optional compression/decider","computation_model":"bellman-style step circuits; external Circom middleware documented","protocol_iop":"Spartan-based optional compression","specialized_argument":"not_applicable"},"source_locator":"README, Details of the library, Supported front-ends, Cargo Features, Tests and examples, and Universal Setup","source_urls":["https://github.com/microsoft/Nova/blob/909230314a7173b0f96d06e0c810d10f65f599f1/Cargo.toml","https://github.com/microsoft/Nova/blob/909230314a7173b0f96d06e0c810d10f65f599f1/README.md"],"status":"reported","title":"nova-snark at 9092303","year":2026}],"lenses":[{"description":"Zero knowledge, public-coin compilation, sum-check, and succinct-argument roots.","id":"foundations","label":"Foundations & definitions","question":"Which definitions and compiler ideas establish the proof contract?"},{"description":"Circuit-specific and universal structured-reference-string configurations.","id":"pairing-succinct","label":"Pairing-based succinctness","question":"How much proof and verifier work can structured pairings compress?"},{"description":"PLONKish constraints, AHP/PIOP protocols, polynomial commitments, and compilers.","id":"universal-polynomial","label":"Universal polynomial IOPs","question":"Which layer makes the setup reusable across circuits?"},{"description":"Discrete-log generator, coded-oracle, and hash-authenticated configurations.","id":"transparent-hash","label":"Transparent systems","question":"What replaces a secret structured setup?"},{"description":"R1CS, CCS, sum-check, multilinear commitments, and their descendants.","id":"multilinear-sumcheck","label":"Multilinear & sum-check","question":"How do multilinear extensions turn large relations into evaluation claims?"},{"description":"Recursive wrapping, accumulation, folding, multi-folding, IVC, and PCD.","id":"recursion-ivc","label":"Recursion, IVC & folding","question":"What is composed: proofs, verifier work, or relation instances?"},{"description":"Instruction lookups, memory checking, residual constraints, PCS choices, and prover space.","id":"lookups-zkvm","label":"Lookups & zkVMs","question":"How is an ISA-level execution split across reusable subarguments?"},{"description":"Knowledge soundness, simulation extractability, batching, and configuration scope.","id":"security-audit","label":"Security of deployed variants","question":"Which exact optimization set is covered by the theorem?"}],"milestones":[{"evidence":"source_derived","id":"PROOF-MILESTONE-001-01","metadata":{"frontier_track":"assumptions","order":1,"parent_problem_id":"PROOF-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-001","summary":"Remove the Hardness Certification assumption from the 2026 non-adaptive all-NP construction while retaining its other coordinates.","tags":["weaker-target","assumptions"],"title":"Remove the Hardness Certification assumption from the 2026 non-adaptive all-NP construction while retaining…","type":"milestone","venue":null,"year":null},{"evidence":"source_derived","id":"PROOF-MILESTONE-001-02","metadata":{"frontier_track":"security","order":2,"parent_problem_id":"PROOF-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-001","summary":"Achieve adaptive soundness for all NP while retaining the 2026 assumption set.","tags":["weaker-target","security"],"title":"Achieve adaptive soundness for all NP while retaining the 2026 assumption set.","type":"milestone","venue":null,"year":null},{"evidence":"source_derived","id":"PROOF-MILESTONE-001-03","metadata":{"frontier_track":"compiler","order":3,"parent_problem_id":"PROOF-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-001","summary":"Construct a mildly succinct knowledge-sound argument for all NP from standard assumptions that satisfies the 2025 boosting compiler's hypotheses.","tags":["weaker-target","compiler"],"title":"Construct a mildly succinct knowledge-sound argument for all NP from standard assumptions that satisfies the…","type":"milestone","venue":null,"year":null},{"evidence":"source_derived","id":"PROOF-MILESTONE-002-01","metadata":{"frontier_track":"succinctness","order":1,"parent_problem_id":"PROOF-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-002","summary":"Obtain a transparent post-quantum PCS with constant opening proofs and logarithmic verifier time.","tags":["weaker-target","succinctness"],"title":"Obtain a transparent post-quantum PCS with constant opening proofs and logarithmic verifier time.","type":"milestone","venue":null,"year":null},{"evidence":"source_derived","id":"PROOF-MILESTONE-002-02","metadata":{"frontier_track":"prover","order":2,"parent_problem_id":"PROOF-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-002","summary":"Obtain logarithmic proof and verifier costs with linear prover time and a full quantum knowledge-soundness proof.","tags":["weaker-target","prover"],"title":"Obtain logarithmic proof and verifier costs with linear prover time and a full quantum knowledge-soundness…","type":"milestone","venue":null,"year":null},{"evidence":"source_derived","id":"PROOF-MILESTONE-002-03","metadata":{"frontier_track":"batching","order":3,"parent_problem_id":"PROOF-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-002","summary":"Add secure same-polynomial and multi-polynomial batching without losing the target setup or quantum-security coordinates.","tags":["weaker-target","batching"],"title":"Add secure same-polynomial and multi-polynomial batching without losing the target setup or quantum-security…","type":"milestone","venue":null,"year":null},{"evidence":"source_derived","id":"PROOF-MILESTONE-003-01","metadata":{"frontier_track":"extraction","order":1,"parent_problem_id":"PROOF-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-003","summary":"Prove a composable extraction notion weaker than full witness-extended emulation but with an explicit post-extraction state-distance guarantee.","tags":["weaker-target","extraction"],"title":"Prove a composable extraction notion weaker than full witness-extended emulation but with an explicit…","type":"milestone","venue":null,"year":null},{"evidence":"source_derived","id":"PROOF-MILESTONE-003-02","metadata":{"frontier_track":"adaptivity","order":2,"parent_problem_id":"PROOF-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-003","summary":"Extend post-quantum soundness and ordinary knowledge soundness from semi-adaptive to fully adaptive public-coin IOP verifiers.","tags":["weaker-target","adaptivity"],"title":"Extend post-quantum soundness and ordinary knowledge soundness from semi-adaptive to fully adaptive…","type":"milestone","venue":null,"year":null},{"evidence":"source_derived","id":"PROOF-MILESTONE-003-03","metadata":{"frontier_track":"lower_bound","order":3,"parent_problem_id":"PROOF-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-003","summary":"Give a separation or counterexample showing that the current IBCS interface cannot satisfy one named stronger extraction notion.","tags":["weaker-target","lower_bound"],"title":"Give a separation or counterexample showing that the current IBCS interface cannot satisfy one named…","type":"milestone","venue":null,"year":null},{"evidence":"source_derived","id":"PROOF-MILESTONE-004-01","metadata":{"frontier_track":"interaction","order":1,"parent_problem_id":"PROOF-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-004","summary":"Construct an interactive standard-model accumulation scheme for a useful argument predicate with the target succinct accumulator.","tags":["weaker-target","interaction"],"title":"Construct an interactive standard-model accumulation scheme for a useful argument predicate with the target…","type":"milestone","venue":null,"year":null},{"evidence":"source_derived","id":"PROOF-MILESTONE-004-02","metadata":{"frontier_track":"compiler","order":2,"parent_problem_id":"PROOF-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-004","summary":"Prove a standard-model compiler from a named special-sound folding protocol to non-interactive accumulation under correlation-intractability or another explicitly falsifiable intermediate assumption not known to imply SNARKs.","tags":["weaker-target","compiler"],"title":"Prove a standard-model compiler from a named special-sound folding protocol to non-interactive accumulation…","type":"milestone","venue":null,"year":null},{"evidence":"source_derived","id":"PROOF-MILESTONE-004-03","metadata":{"frontier_track":"lower_bound","order":3,"parent_problem_id":"PROOF-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-004","summary":"Prove a black-box impossibility for a precisely delimited class of accumulation predicates and reductions.","tags":["weaker-target","lower_bound"],"title":"Prove a black-box impossibility for a precisely delimited class of accumulation predicates and reductions.","type":"milestone","venue":null,"year":null}],"nodes":[{"evidence":"primary_source_checked","id":"PROOF-BARRIER-001","metadata":{"claim":"The Gentry–Wichs barrier, as restated and used by the 2025 boosting analysis, rules out proving the scoped all-NP SNARG via a polynomial-time black-box reduction to a falsifiable assumption.","does_not_exclude":["Non-black-box reductions that inspect the adversary's code","Non-adaptive soundness or proper subclasses of NP","Constructions from non-falsifiable, obfuscation, or proof-complexity assumptions","A sharper impossibility theorem under additional hypotheses"],"dossier_type":"barrier","escape_hatches":["non_black_box_reduction","weaken_adaptivity","restrict_language_class","change_assumption_class"],"evidence":"primary_source_checked","excludes":["A route whose only novelty is a new polynomial-time black-box reduction from an all-NP adaptively sound SNARG to LWE, DDH, or another falsifiable assumption"],"id":"PROOF-BARRIER-001","scope":{"assumption":"falsifiable","object":"adaptively_sound_SNARG_for_sufficiently_hard_NP_languages","reduction":"polynomial_time_black_box_reduction"},"status":"scoped_literature_barrier","targets":["PROOF-OP-001"],"title":"Black-box falsifiable-assumption barrier for all-NP SNARGs"},"primaryUrl":null,"sections":[{"content":"PROOF-PAPER-2025-BOOSTING-SNARKS, Introduction, LIPIcs pp. 56:2–56:3. The card deliberately does not turn a black-box reduction barrier into an impossibility of SNARGs.","heading":"Evidence locator"}],"status":"scoped_literature_barrier","subtitle":"","summary":"PROOF-PAPER-2025-BOOSTING-SNARKS, Introduction, LIPIcs pp. 56:2–56:3. The card deliberately does not turn a black-box reduction barrier into an impossibility of SNARGs.","tags":[],"title":"Black-box falsifiable-assumption barrier for all-NP SNARGs","type":"barrier","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-BARRIER-001"},{"evidence":"claim_audited","id":"PROOF-BARRIER-002","metadata":{"claim":"In the audited boundary, Behemoth reaches the constant opening/verifier endpoint without a post-quantum claim, while the post-quantum transparent branches retain logarithmic or polylogarithmic opening or verifier cost.","does_not_exclude":["A new hash-, code-, lattice-, isogeny-, or other post-quantum technique reaching all four coordinates","An impossibility theorem for a precisely defined transparent post-quantum model","Constant amortized cost under an explicitly different batched interface"],"dossier_type":"barrier","escape_hatches":["new_post_quantum_algebraic_backend","degree_independent_terminal_check","formal_impossibility"],"evidence":"claim_audited","excludes":["Treating transparency alone as post-quantum security","Combining the constant-cost cells of Behemoth with the quantum-security cells of a different PCS as if one construction achieved the conjunction"],"id":"PROOF-BARRIER-002","scope":{"coordinates":["transparent_setup","post_quantum_security","opening_size","verifier_time"],"corpus":"audited_Behemoth_WHIR_and_lattice_PCS_branches_through_2026_08_13"},"status":"scoped_frontier_boundary","targets":["PROOF-OP-002"],"title":"Constant-succinctness and post-quantum security are reached by different audited PCS branches"},"primaryUrl":null,"sections":[{"content":"Behemoth Section 8.3; CRYPTO 2024 lattice PCS Abstract and Section 1.1; WHIR Abstract and Sections 1 and 7. This is a current-result separation, not a lower bound.","heading":"Evidence locator"}],"status":"scoped_frontier_boundary","subtitle":"","summary":"Behemoth Section 8.3; CRYPTO 2024 lattice PCS Abstract and Section 1.1; WHIR Abstract and Sections 1 and 7. This is a current-result separation, not a lower bound.","tags":[],"title":"Constant-succinctness and post-quantum security are reached by different audited PCS branches","type":"barrier","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-BARRIER-002"},{"evidence":"primary_source_checked","id":"PROOF-BARRIER-003","metadata":{"claim":"The current IBCS reduction proves its stated knowledge-soundness notion, but measurement and the no-cloning constraint prevent treating the extracted adversary state as automatically reusable by an enclosing protocol.","does_not_exclude":["A coherent extractor with an explicit state-repair invariant","A different vector-commitment property that enables stronger extraction","Strong extraction for a restricted IOP or adversary class"],"dossier_type":"barrier","escape_hatches":["coherent_state_repair","stronger_collapsing_interface","restricted_composition_class"],"evidence":"primary_source_checked","excludes":["Inferring state-preserving or witness-extended extraction directly from Theorem 1's ordinary knowledge-soundness conclusion","A classical copy-and-rewind proof that duplicates an unknown quantum auxiliary state"],"id":"PROOF-BARRIER-003","scope":{"desired_property":"state_preserving_or_witness_extended_extraction","proof":"quantum_rewinding_reduction_for_IBCS"},"status":"scoped_technique_barrier","targets":["PROOF-OP-003"],"title":"Quantum state disturbance blocks a naive strengthening of IBCS extraction"},"primaryUrl":null,"sections":[{"content":"PROOF-PAPER-2025-IBCS-QUANTUM, Section 1.1 open problems and Remark 2.1. The source calls the stronger property open; it does not prove an impossibility.","heading":"Evidence locator"}],"status":"scoped_technique_barrier","subtitle":"","summary":"PROOF-PAPER-2025-IBCS-QUANTUM, Section 1.1 open problems and Remark 2.1. The source calls the stronger property open; it does not prove an impossibility.","tags":[],"title":"Quantum state disturbance blocks a naive strengthening of IBCS extraction","type":"barrier","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-BARRIER-003"},{"evidence":"primary_source_checked","id":"PROOF-BARRIER-004","metadata":{"claim":"In the audited constructions, Fiat–Shamir in a random oracle or a knowledge-style assumption supplies the challenge/extraction behavior required by non-interactive recursive accumulation; replacing the oracle by a concrete hash is only heuristic.","does_not_exclude":["A new standard-model compiler using correlation intractability or another carefully scoped assumption","Interactive accumulation under standard assumptions","A black-box impossibility theorem for a delimited predicate/reduction class"],"dossier_type":"barrier","escape_hatches":["standard_model_noninteractive_compiler","interaction","scoped_impossibility"],"evidence":"primary_source_checked","excludes":["Labeling a concrete-hash Fiat–Shamir instantiation as a standard-model proof","Claiming the 2020 accumulation-to-PCD theorem itself constructs a standard-model non-interactive accumulator under ordinary falsifiable assumptions"],"id":"PROOF-BARRIER-004","scope":{"constructions":"audited_noninteractive_accumulation_and_folding_instantiations","security_goal":"adaptive_knowledge_soundness_for_PCD"},"status":"scoped_frontier_boundary","targets":["PROOF-OP-004"],"title":"Fiat–Shamir supplies the non-interactive challenge in current folding and accumulation routes"},"primaryUrl":null,"sections":[{"content":"PROOF-PAPER-2020-ACCUMULATION, Section 1.1; PROOF-PAPER-2021-NOVA, Sections 1.1 and 4.2. This card records a dependency of known routes, not a general impossibility.","heading":"Evidence locator"}],"status":"scoped_frontier_boundary","subtitle":"","summary":"PROOF-PAPER-2020-ACCUMULATION, Section 1.1; PROOF-PAPER-2021-NOVA, Sections 1.1 and 4.2. This card records a dependency of known routes, not a general impossibility.","tags":[],"title":"Fiat–Shamir supplies the non-interactive challenge in current folding and accumulation routes","type":"barrier","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-BARRIER-004"},{"evidence":"primary_source_checked","id":"PROOF-BENCH-2025-JOLT-SHA2-783DA5D","metadata":{"artifact_commit":"783da5d32010e707f85085d59ae0451f6d8a6b25","comparable":false,"comparison_group":"none","compatibility_key":{"commitment_backend":"HyperKZG over BN254","compiler_flags":"Cargo release profile; additional code-generation flags not reported","configuration":"RV32IM Jolt with BN254 HyperKZG and Keccak transcript at 783da5d","curve_field":"BN254 scalar field","estimator":"not_reported","evidence_state":"official_ci_reported_not_reproduced","hardware":"GitHub-hosted public ubuntu-24.04 x64 runner class; exact VM CPU model not reported","implementation_version":"783da5d32010e707f85085d59ae0451f6d8a6b25","metric_definition":"prover runtime is the source Instant interval around prove_sha2_chain; memory is GNU time maximum resident set size for the cargo-run process","network":"not_applicable_to_local_prove_verify_run","os":"ubuntu-24.04 GitHub-hosted runner image","preprocessing_accounting":"Prover timer starts after build_sha2_chain; peak RSS covers the timed cargo-run process; compile is performed before the run","problem_size":"100 iterations; constraint and realized trace counts not reported by the dashboard row","security_level":"not_reported","software_toolchain":"Rust nightly-2024-09-30; riscv32im-unknown-none-elf target","thread_count":"not_reported","workload":"SHA2-chain guest; input [5u8; 32]; 100 sequential SHA-256 iterations"},"configuration_id":"PROOF-SYSTEM-JOLT","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-BENCH-2025-JOLT-SHA2-783DA5D","implementation_id":"PROOF-IMPL-2025-JOLT-783DA5D","metrics":{"peak_rss_kb":"11033940","proof_size":"not_reported","prover_time_seconds":"63.0816","verifier_time":"not_reported"},"non_comparability_reasons":["Exact host CPU model and prover thread count are not reported.","Concrete security level and estimator are not reported.","The later curated Jolt run changes VM width, PCS, toolchain, and workload size."],"primary_url":"https://a16z.github.io/jolt/dev/bench/data.js","source_locator":"benchmark data entry for commit 783da5d, sha2-chain-time and sha2-chain-mem; pinned examples/sha2-chain and CI workflow","source_urls":["https://a16z.github.io/jolt/dev/bench/data.js","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/.github/workflows/ci-bench.yml","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/examples/run_benchmarks.sh","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/examples/sha2-chain/src/main.rs","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/examples/sha2-chain/guest/src/lib.rs"],"status":"reported","tags":["benchmark","jolt","sha2-chain","ci","rv32im","hyperkzg","non-comparable"],"title":"Jolt 783da5d SHA2-chain CI observation","year":2025},"primaryUrl":"https://a16z.github.io/jolt/dev/bench/data.js","sections":[{"content":"This is a commit-bound observation, not a timeless Jolt performance number. The dashboard supplies the commit and metrics; the pinned repository supplies the workload, VM/backend profile, toolchain, and accounting code. Missing host and security coordinates prevent ranking.","heading":"Interpretation"}],"status":"reported","subtitle":"2025","summary":"This is a commit-bound observation, not a timeless Jolt performance number. The dashboard supplies the commit and metrics; the pinned repository supplies the workload, VM/backend profile, toolchain, and accounting code. Missing host and security coordinates prevent ranking.","tags":["benchmark","ci","hyperkzg","jolt","non-comparable","rv32im","sha2-chain"],"title":"Jolt 783da5d SHA2-chain CI observation","type":"benchmark_run","venue":null,"year":2025,"sourcePath":"data/proof-systems-catalog.json#PROOF-BENCH-2025-JOLT-SHA2-783DA5D"},{"evidence":"primary_source_checked","id":"PROOF-BENCH-2026-JOLT-SHA2-915FAF4","metadata":{"artifact_commit":"915faf453f36871249615a7fdf2704d77a88f259","comparable":false,"comparison_group":"none","compatibility_key":{"commitment_backend":"Dory over BN254 with Pedersen vector commitments","compiler_flags":"Cargo release profile; additional code-generation flags not reported","configuration":"RV64IMAC Jolt with Dory over BN254 and default legacy Blake2b transcript at 915faf4","curve_field":"BN254 scalar field","estimator":"not_reported","evidence_state":"official_ci_reported_not_reproduced","hardware":"GitHub-hosted public ubuntu-24.04 x64 runner class; exact VM CPU model not reported","implementation_version":"915faf453f36871249615a7fdf2704d77a88f259","metric_definition":"prover runtime is the source Instant interval around prove_sha2_chain; memory is GNU time maximum resident set size for the cargo-run process","network":"not_applicable_to_local_prove_verify_run","os":"ubuntu-24.04 GitHub-hosted runner image","preprocessing_accounting":"Prover timer starts after guest compilation and shared/prover/verifier preprocessing; peak RSS covers the timed cargo-run process; compilation is performed before the run","problem_size":"1000 iterations; guest max_trace_length 4194304; realized trace count not reported by dashboard row","security_level":"not_reported","software_toolchain":"Rust 1.95; riscv32imac and riscv64imac bare-metal targets configured","thread_count":"not_reported","workload":"SHA2-chain guest; input [5u8; 32]; 1000 sequential Jolt-inline SHA-256 iterations"},"configuration_id":"PROOF-SYSTEM-JOLT","dossier_type":"benchmark_run","evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-BENCH-2026-JOLT-SHA2-915FAF4","implementation_id":"PROOF-IMPL-2026-JOLT-915FAF4","metrics":{"peak_rss_kb":"2123752","proof_size":"not_reported","prover_time_seconds":"102.4157","verifier_time":"not_reported"},"non_comparability_reasons":["Exact host CPU model and prover thread count are not reported.","Concrete security level and estimator are not reported.","The earlier curated Jolt run uses RV32IM, HyperKZG, a different toolchain, and one tenth as many SHA-256 iterations."],"primary_url":"https://a16z.github.io/jolt/dev/bench/data.js","source_locator":"benchmark data entry for commit 915faf4, sha2-chain-time and sha2-chain-mem; pinned examples/sha2-chain, host_utils, rust-toolchain, and CI workflow","source_urls":["https://a16z.github.io/jolt/dev/bench/data.js","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/.github/workflows/ci-bench.yml","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/examples/run_ci_benchmarks.sh","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/examples/sha2-chain/src/main.rs","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/examples/sha2-chain/guest/src/lib.rs"],"status":"reported","tags":["benchmark","jolt","sha2-chain","ci","rv64imac","dory","non-comparable"],"title":"Jolt 915faf4 SHA2-chain CI observation","year":2026},"primaryUrl":"https://a16z.github.io/jolt/dev/bench/data.js","sections":[{"content":"This observation deliberately excludes guest compilation and preprocessing from the reported prover interval; maximum RSS has a broader whole-process boundary. It cannot be compared directly with the 2025 row because the configuration and workload changed.","heading":"Interpretation"}],"status":"reported","subtitle":"2026","summary":"This observation deliberately excludes guest compilation and preprocessing from the reported prover interval; maximum RSS has a broader whole-process boundary. It cannot be compared directly with the 2025 row because the configuration and workload changed.","tags":["benchmark","ci","dory","jolt","non-comparable","rv64imac","sha2-chain"],"title":"Jolt 915faf4 SHA2-chain CI observation","type":"benchmark_run","venue":null,"year":2026,"sourcePath":"data/proof-systems-catalog.json#PROOF-BENCH-2026-JOLT-SHA2-915FAF4"},{"evidence":"primary_source_checked","id":"PROOF-SYSTEM-GROTH16","metadata":{"claim_ids":["PROOF-CONTRIB-2016-GROTH-3ELEMENT"],"complexity":{"memory":"not_reported","proof_size":"three_group_elements","prover":"linear_group_work_in_circuit_size","verifier":"constant_pairings_plus_public_input_work"},"configuration_note":"The structured group encoding is integral to this configuration; it is not represented as a modular PCS slot.","dossier_type":"construction","evidence":"primary_source_checked","id":"PROOF-SYSTEM-GROTH16","name":"Groth16","paper_ids":["PROOF-PAPER-2016-GROTH"],"properties":{"interaction":"non_interactive","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"circuit_specific_structured_crs","soundness":"knowledge_soundness_in_stated_model"},"research_lenses":["pairing-succinct"],"stack":{"arithmetization":["PROOF-COMP-R1CS","PROOF-COMP-QAP"],"commitment_backend":[],"compiler":[],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-PAIRING-QAP"],"specialized_argument":[]},"stack_status":{"commitment_backend":"not_separate","compiler":"not_applicable","composition_mechanism":"not_applicable","specialized_argument":"not_applicable"},"status":"published","system_family":"pairing_qap_snark","tasks":["succinct_argument_of_knowledge","zero_knowledge"],"title":"Groth16 · QAP / circuit-specific CRS","visibility":"backbone","year":2016},"primaryUrl":null,"sections":[{"content":"It is the compact pairing-based endpoint against which setup flexibility, transparency, and recursive friendliness are often contrasted.","heading":"Why this configuration matters"},{"content":"The row does not cover every library, curve, ceremony, batch verifier, or simulation-extractable variant named Groth16.","heading":"Boundary"}],"status":"published","subtitle":"pairing qap snark · 2016","summary":"It is the compact pairing-based endpoint against which setup flexibility, transparency, and recursive friendliness are often contrasted.","tags":["pairing-succinct"],"title":"Groth16 · QAP / circuit-specific CRS","type":"construction","venue":null,"year":2016,"sourcePath":"data/proof-systems-catalog.json#PROOF-SYSTEM-GROTH16"},{"evidence":"primary_source_checked","id":"PROOF-SYSTEM-BULLETPROOFS","metadata":{"claim_ids":["PROOF-CONTRIB-2017-BULLETPROOFS-IPA"],"complexity":{"memory":"not_reported","proof_size":"logarithmic_in_witness_size","prover":"linear_in_witness_or_constraint_size","verifier":"linear_for_general_arithmetic_circuits"},"configuration_note":"General arithmetic-circuit row; aggregated range proofs are a related specialized task.","dossier_type":"construction","evidence":"primary_source_checked","id":"PROOF-SYSTEM-BULLETPROOFS","name":"Bulletproofs","paper_ids":["PROOF-PAPER-2017-BULLETPROOFS"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"transparent_generators","soundness":"argument_of_knowledge_in_random_oracle_model"},"research_lenses":["transparent-hash","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-INNER-PRODUCT"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_separate","specialized_argument":"out_of_scope"},"status":"published","system_family":"inner_product_argument","tasks":["zero_knowledge_argument","range_proof","aggregation"],"title":"Bulletproofs · general arithmetic-circuit configuration","visibility":"backbone","year":2017},"primaryUrl":null,"sections":[{"content":"It shows that logarithmic proofs and no trusted setup do not imply a succinct verifier in every dimension.","heading":"Why this configuration matters"}],"status":"published","subtitle":"inner product argument · 2017","summary":"It shows that logarithmic proofs and no trusted setup do not imply a succinct verifier in every dimension.","tags":["multilinear-sumcheck","transparent-hash"],"title":"Bulletproofs · general arithmetic-circuit configuration","type":"construction","venue":null,"year":2017,"sourcePath":"data/proof-systems-catalog.json#PROOF-SYSTEM-BULLETPROOFS"},{"evidence":"primary_source_checked","id":"PROOF-SYSTEM-STARK","metadata":{"claim_ids":["PROOF-CONTRIB-2018-STARK-SYSTEM"],"complexity":{"memory":"implementation_dependent","proof_size":"polylogarithmic_style_but_large_constants","prover":"quasilinear_style_for_supported_trace_encoding","verifier":"sublinear_polylogarithmic_style"},"configuration_note":"Representative 2018 coded-oracle architecture; FRI/IOP variants and later engineering are not merged into one benchmark row.","dossier_type":"construction","evidence":"primary_source_checked","id":"PROOF-SYSTEM-STARK","name":"ZK-STARK","paper_ids":["PROOF-PAPER-2018-STARK"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"conditional_hash_model","privacy":"zero_knowledge_in_displayed_system","setup":"transparent","soundness":"computational_from_hash_and_iop_analysis"},"research_lenses":["transparent-hash"],"stack":{"arithmetization":["PROOF-COMP-AIR"],"commitment_backend":["PROOF-COMP-FRI"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","system_family":"transparent_iop","tasks":["transparent_argument","zero_knowledge","scalable_verification"],"title":"ZK-STARK · AIR / coded-oracle configuration","visibility":"backbone","year":2018},"primaryUrl":null,"sections":[{"content":"It makes transparency and hash-based assumptions visible as properties of a full AIR/IOP/backend stack.","heading":"Why this configuration matters"}],"status":"published","subtitle":"transparent iop · 2018","summary":"It makes transparency and hash-based assumptions visible as properties of a full AIR/IOP/backend stack.","tags":["transparent-hash"],"title":"ZK-STARK · AIR / coded-oracle configuration","type":"construction","venue":null,"year":2018,"sourcePath":"data/proof-systems-catalog.json#PROOF-SYSTEM-STARK"},{"evidence":"primary_source_checked","id":"PROOF-SYSTEM-HALO","metadata":{"claim_ids":["PROOF-CONTRIB-2019-HALO-RECURSION"],"complexity":{"memory":"implementation_dependent","proof_size":"does_not_grow_with_recursion_depth","prover":"configuration_dependent_recursive_work","verifier":"does_not_grow_with_recursion_depth"},"configuration_note":"Original recursive composition architecture using nested amortization and a cycle of non-pairing curves; this release does not normalize it to the later Halo2 PLONKish arithmetization.","dossier_type":"construction","evidence":"primary_source_checked","id":"PROOF-SYSTEM-HALO","name":"Halo","paper_ids":["PROOF-PAPER-2019-HALO"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"conditional_on_full_configuration","setup":"transparent_generators","soundness":"argument_in_stated_random_oracle_model"},"research_lenses":["recursion-ivc","transparent-hash"],"stack":{"arithmetization":[],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-RECURSIVE-WRAP"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-INNER-PRODUCT"],"specialized_argument":[]},"stack_status":{"arithmetization":"not_normalized","specialized_argument":"out_of_scope"},"status":"published","system_family":"recursive_ipa_argument","tasks":["recursive_composition","proof_aggregation"],"title":"Halo · IPA / curve-cycle recursive configuration","visibility":"backbone","year":2019},"primaryUrl":null,"sections":[{"content":"Halo’s recursive wrapping is compared with folding only in the composition table, where the mechanism distinction is explicit.","heading":"Boundary"}],"status":"published","subtitle":"recursive ipa argument · 2019","summary":"Halo’s recursive wrapping is compared with folding only in the composition table, where the mechanism distinction is explicit.","tags":["recursion-ivc","transparent-hash"],"title":"Halo · IPA / curve-cycle recursive configuration","type":"construction","venue":null,"year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-SYSTEM-HALO"},{"evidence":"claim_audited","id":"PROOF-SYSTEM-MARLIN-KZG","metadata":{"claim_ids":["PROOF-CONTRIB-2019-MARLIN-AHP","PROOF-CONTRIB-2024-REALWORLD-SE"],"complexity":{"memory":"implementation_dependent","proof_size":"constant_number_of_commitments_and_openings","prover":"quasilinear_polynomial_work","verifier":"succinct_after_preprocessing"},"configuration_note":"Concrete representative instantiation of the AHP compiler with KZG.","dossier_type":"construction","evidence":"claim_audited","id":"PROOF-SYSTEM-MARLIN-KZG","name":"Marlin + KZG","paper_ids":["PROOF-PAPER-2019-MARLIN","PROOF-PAPER-2010-KZG"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"universal_updatable_structured_srs","soundness":"knowledge_soundness_and_claim_specific_extractability"},"research_lenses":["universal-polynomial","security-audit"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-KZG"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","system_family":"universal_ahp_snark","tasks":["preprocessing_snark","zero_knowledge"],"title":"Marlin · AHP / KZG configuration","visibility":"backbone","year":2019},"primaryUrl":null,"sections":[{"content":"Marlin makes the AHP-to-PCS compiler boundary explicit, which is central to the atlas stack view.","heading":"Why this configuration matters"}],"status":"published","subtitle":"universal ahp snark · 2019","summary":"Marlin makes the AHP-to-PCS compiler boundary explicit, which is central to the atlas stack view.","tags":["security-audit","universal-polynomial"],"title":"Marlin · AHP / KZG configuration","type":"construction","venue":null,"year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-SYSTEM-MARLIN-KZG"},{"evidence":"claim_audited","id":"PROOF-SYSTEM-PLONK-KZG","metadata":{"claim_ids":["PROOF-CONTRIB-2019-PLONK-PIOP","PROOF-CONTRIB-2024-REALWORLD-SE","PROOF-CONTRIB-2024-PLONK-KS"],"complexity":{"memory":"implementation_dependent","proof_size":"constant_number_of_group_and_field_elements","prover":"quasilinear_polynomial_work","verifier":"succinct_plus_public_input_work"},"configuration_note":"Fixes the original PLONKish protocol with KZG and Fiat–Shamir; other Halo2-style or alternative-PCS configurations require separate rows.","dossier_type":"construction","evidence":"claim_audited","id":"PROOF-SYSTEM-PLONK-KZG","name":"PLONK + KZG","paper_ids":["PROOF-PAPER-2019-PLONK","PROOF-PAPER-2010-KZG"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"universal_updatable_structured_srs","soundness":"claim_and_variant_specific"},"research_lenses":["universal-polynomial","pairing-succinct","security-audit"],"stack":{"arithmetization":["PROOF-COMP-PLONKISH"],"commitment_backend":["PROOF-COMP-KZG"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","system_family":"universal_polynomial_iop_snark","tasks":["succinct_argument_of_knowledge","zero_knowledge"],"title":"PLONK · original KZG-backed configuration","visibility":"backbone","year":2019},"primaryUrl":null,"sections":[{"content":"Security cards expose which batching and optimization choices are covered. The family name alone carries no automatic theorem.","heading":"Claim boundary"}],"status":"published","subtitle":"universal polynomial iop snark · 2019","summary":"Security cards expose which batching and optimization choices are covered. The family name alone carries no automatic theorem.","tags":["pairing-succinct","security-audit","universal-polynomial"],"title":"PLONK · original KZG-backed configuration","type":"construction","venue":null,"year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-SYSTEM-PLONK-KZG"},{"evidence":"primary_source_checked","id":"PROOF-SYSTEM-SPARTAN","metadata":{"claim_ids":["PROOF-CONTRIB-2019-SPARTAN-R1CS"],"complexity":{"memory":"implementation_dependent","proof_size":"logarithmic_style_under_selected_commitment","prover":"linear_for_displayed_r1cs_path","verifier":"sublinear_after_public_preprocessing"},"configuration_note":"Representative transparent Spartan architecture; the multilinear PCS interface is explicit because concrete instantiations change proof and verifier costs.","dossier_type":"construction","evidence":"primary_source_checked","id":"PROOF-SYSTEM-SPARTAN","name":"Spartan","paper_ids":["PROOF-PAPER-2019-SPARTAN"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_discrete_log_instantiation","privacy":"computational_zero_knowledge","setup":"transparent_with_public_preprocessing_for_sublinear_verification","soundness":"knowledge_soundness_in_stated_model"},"research_lenses":["multilinear-sumcheck","transparent-hash"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-MLPCS"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-SUMCHECK"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","system_family":"multilinear_sumcheck_snark","tasks":["transparent_zksnark","general_r1cs"],"title":"Spartan · transparent R1CS / sum-check configuration","visibility":"backbone","year":2019},"primaryUrl":null,"sections":[{"content":"It anchors the multilinear/sum-check path later reused in folding systems and lookup-oriented zkVMs.","heading":"Why this configuration matters"}],"status":"published","subtitle":"multilinear sumcheck snark · 2019","summary":"It anchors the multilinear/sum-check path later reused in folding systems and lookup-oriented zkVMs.","tags":["multilinear-sumcheck","transparent-hash"],"title":"Spartan · transparent R1CS / sum-check configuration","type":"construction","venue":null,"year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-SYSTEM-SPARTAN"},{"evidence":"primary_source_checked","id":"PROOF-SYSTEM-NOVA","metadata":{"claim_ids":["PROOF-CONTRIB-2021-NOVA-FOLDING"],"complexity":{"memory":"step_circuit_and_commitment_dependent","proof_size":"constant_size_running_ivc_state; a succinct final proof requires optional compression","prover":"per_step_linear_multiexponentiation_style","verifier":"constant_size_incremental_state_check_plus_separate_final_decider"},"configuration_note":"This row is the folding-based IVC core, not a claim that folding alone is a complete succinct proof system; optional SNARK compression and the final decider remain separate.","dossier_type":"construction","evidence":"primary_source_checked","id":"PROOF-SYSTEM-NOVA","name":"Nova","paper_ids":["PROOF-PAPER-2021-NOVA"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_displayed_commitment","privacy":"zero_knowledge_in_paper_configuration","setup":"transparent_generators","soundness":"folding_soundness_plus_final_decider"},"research_lenses":["recursion-ivc","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-RELAXED-FOLD"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":[],"specialized_argument":[]},"stack_status":{"protocol_iop":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","system_family":"folding_based_ivc","tasks":["ivc"],"title":"Nova · relaxed-R1CS folding core","visibility":"backbone","year":2021},"primaryUrl":null,"sections":[{"content":"Nova changes the recursion problem from repeatedly proving verifier execution to folding the relation instances themselves.","heading":"Why this configuration matters"}],"status":"published","subtitle":"folding based ivc · 2021","summary":"Nova changes the recursion problem from repeatedly proving verifier execution to folding the relation instances themselves.","tags":["multilinear-sumcheck","recursion-ivc"],"title":"Nova · relaxed-R1CS folding core","type":"construction","venue":null,"year":2021,"sourcePath":"data/proof-systems-catalog.json#PROOF-SYSTEM-NOVA"},{"evidence":"primary_source_checked","id":"PROOF-SYSTEM-HYPERNOVA","metadata":{"claim_ids":["PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD"],"complexity":{"memory":"relation_and_commitment_dependent","proof_size":"constant_size_running_state_plus_optional_compression","prover":"one_primary_msm_style_per_fold_plus_sumcheck_work","verifier":"constant_size_incremental_state_plus_final_decider"},"configuration_note":"Displays CCS, multi-folding, and IVC/PCD capability as three different semantic layers.","dossier_type":"construction","evidence":"primary_source_checked","id":"PROOF-SYSTEM-HYPERNOVA","name":"HyperNova","paper_ids":["PROOF-PAPER-2023-HYPERNOVA"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_displayed_commitment","privacy":"zero_knowledge_via_randomized_folding_in_updated_version","setup":"transparent_generators","soundness":"multifolding_soundness_plus_final_decider"},"research_lenses":["recursion-ivc","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-CCS"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-MULTIFOLD"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-SUMCHECK"],"specialized_argument":[]},"stack_status":{"specialized_argument":"out_of_scope"},"status":"published","system_family":"ccs_multifolding_ivc","tasks":["ivc","non_uniform_ivc","pcd"],"title":"HyperNova · CCS multi-folding configuration","visibility":"backbone","year":2023},"primaryUrl":null,"sections":[{"content":"It demonstrates how a more expressive relation layer and multi-instance composition should be represented without promoting either to a new top-level field.","heading":"Why this configuration matters"}],"status":"published","subtitle":"ccs multifolding ivc · 2023","summary":"It demonstrates how a more expressive relation layer and multi-instance composition should be represented without promoting either to a new top-level field.","tags":["multilinear-sumcheck","recursion-ivc"],"title":"HyperNova · CCS multi-folding configuration","type":"construction","venue":null,"year":2023,"sourcePath":"data/proof-systems-catalog.json#PROOF-SYSTEM-HYPERNOVA"},{"evidence":"primary_source_checked","id":"PROOF-SYSTEM-JOLT","metadata":{"claim_ids":["PROOF-CONTRIB-2023-JOLT-LOOKUPVM","PROOF-CONTRIB-2025-JOLT-SPACE"],"complexity":{"memory":"linear_baseline_with_source_backed_small_space_alternative","proof_size":"commitment_backend_dependent","prover":"dominated_by_execution_lookup_memory_and_commitment_work","verifier":"succinct_configuration_dependent"},"configuration_note":"Research architecture row; production implementations and PCS choices require versioned rows before benchmarking.","dossier_type":"construction","evidence":"primary_source_checked","id":"PROOF-SYSTEM-JOLT","name":"Jolt","paper_ids":["PROOF-PAPER-2023-JOLT","PROOF-PAPER-2025-JOLT-SPACE"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"depends_on_selected_backend","privacy":"zero_knowledge_configuration_dependent","setup":"depends_on_selected_multilinear_commitment","soundness":"composition_of_spartan_lookup_and_memory_arguments"},"research_lenses":["lookups-zkvm","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-MLPCS"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-RISCV"],"protocol_iop":["PROOF-COMP-SUMCHECK"],"specialized_argument":["PROOF-COMP-LOOKUP","PROOF-COMP-MEMORY-CHECK"]},"stack_status":{"composition_mechanism":"optional_external"},"status":"published","system_family":"lookup_centric_zkvm","tasks":["zkvm","verifiable_cpu_execution"],"title":"Jolt · lookup-centric RISC-V zkVM stack","visibility":"backbone","year":2023},"primaryUrl":null,"sections":[{"content":"Jolt makes visible why a zkVM is a system stack: ISA semantics, lookups, memory checking, R1CS/Spartan, and a PCS cannot be replaced by one “zkVM” category label.","heading":"Why this configuration matters"}],"status":"published","subtitle":"lookup centric zkvm · 2023","summary":"Jolt makes visible why a zkVM is a system stack: ISA semantics, lookups, memory checking, R1CS/Spartan, and a PCS cannot be replaced by one “zkVM” category label.","tags":["lookups-zkvm","multilinear-sumcheck"],"title":"Jolt · lookup-centric RISC-V zkVM stack","type":"construction","venue":null,"year":2023,"sourcePath":"data/proof-systems-catalog.json#PROOF-SYSTEM-JOLT"},{"evidence":"primary_source_checked","id":"PROOF-SYSTEM-PROTOSTAR","metadata":{"claim_ids":["PROOF-CONTRIB-2023-PROTOSTAR-GENERIC"],"complexity":{"memory":"not_reported","proof_size":"accumulator_state_plus_final_proof","prover":"per_step_cost_independent_of_lookup_table_size_in_stated_setting","verifier":"small_accumulation_verifier_plus_final_decider"},"configuration_note":"Concrete non-uniform IVC instantiation of the paper's generic special-sound accumulation compiler.","dossier_type":"construction","evidence":"primary_source_checked","id":"PROOF-SYSTEM-PROTOSTAR","name":"Protostar","paper_ids":["PROOF-PAPER-2023-PROTOSTAR"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_displayed_commitment","privacy":"conditional_on_full_configuration","setup":"transparent_generators","soundness":"special_sound_accumulation_plus_final_decider"},"research_lenses":["recursion-ivc","lookups-zkvm"],"stack":{"arithmetization":["PROOF-COMP-PLONKISH"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-SPECIAL-SOUND-ACCUMULATION"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":["PROOF-COMP-LOOKUP"]},"stack_status":{},"status":"published","system_family":"special_sound_accumulation_ivc","tasks":["non_uniform_ivc","vector_lookups"],"title":"Protostar · special-sound accumulation for PLONK","visibility":"backbone","year":2023},"primaryUrl":null,"sections":[{"content":"Generic accumulation and the Protostar PLONK/lookup instantiation are distinct objects linked by the source contribution.","heading":"Boundary"}],"status":"published","subtitle":"special sound accumulation ivc · 2023","summary":"Generic accumulation and the Protostar PLONK/lookup instantiation are distinct objects linked by the source contribution.","tags":["lookups-zkvm","recursion-ivc"],"title":"Protostar · special-sound accumulation for PLONK","type":"construction","venue":null,"year":2023,"sourcePath":"data/proof-systems-catalog.json#PROOF-SYSTEM-PROTOSTAR"},{"evidence":"primary_source_checked","id":"PROOF-IMPL-2024-STONE-1414A54","metadata":{"artifact":{"commit":"1414a545e4fb38a85391289abe91dd4467d268e1","commit_url":"https://github.com/starkware-libs/stone-prover/tree/1414a545e4fb38a85391289abe91dd4467d268e1","repository":"https://github.com/starkware-libs/stone-prover","version":"Stone-v3-1414a54"},"artifact_type":"open-source prover and verifier","availability":"public repository and Dockerfile; Linux-only support stated","backend":"Cairo CPU AIR with FRI-based STARK prover and verifier","benchmark_eligibility_note":"The repository documents end-to-end execution but does not publish a compatibility-complete timing observation bound to this commit.","benchmark_eligible":false,"configuration_binding":"exact_cairo_cpu_air_profile","configuration_ids":["PROOF-SYSTEM-STARK"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-IMPL-2024-STONE-1414A54","language":"C++ with Docker build and Cairo/CairoZero tooling","maturity":"engineering artifact with explicit verifier boundary","paper_ids":["PROOF-PAPER-2018-STARK"],"primary_url":"https://github.com/starkware-libs/stone-prover/tree/1414a545e4fb38a85391289abe91dd4467d268e1","realized_stack":{"arithmetization":"CPU AIR","commitment_backend":"FRI and hash-authenticated oracle layers","compiler":"Fiat-Shamir style non-interactive prover configuration","composition_mechanism":"not_applicable","computation_model":"Cairo/CairoZero CPU execution","protocol_iop":"STARK polynomial IOP","specialized_argument":"Cairo CPU builtins handled by configuration and external checks"},"source_locator":"README, Overview, Installation, proof-generation walkthrough, verifier note, and input-size configuration","source_urls":["https://github.com/starkware-libs/stone-prover/blob/1414a545e4fb38a85391289abe91dd4467d268e1/README.md"],"status":"reported","tags":["implementation","stark","air","fri","cairo","cpp"],"title":"Stone Prover v3 at 1414a54","year":2024},"primaryUrl":"https://github.com/starkware-libs/stone-prover/tree/1414a545e4fb38a85391289abe91dd4467d268e1","sections":[{"content":"Stone implements the Cairo CPU AIR profile rather than every system commonly called a STARK. Its README warns that the verifier checks consistency with the proof's public-input section but does not independently validate the Cairo program or builtin memory segment sizes; those checks remain external.","heading":"Scope"}],"status":"reported","subtitle":"2024","summary":"Stone implements the Cairo CPU AIR profile rather than every system commonly called a STARK. Its README warns that the verifier checks consistency with the proof's public-input section but does not independently validate the Cairo program or builtin memory segment sizes; those checks remain external.","tags":["air","cairo","cpp","fri","implementation","stark"],"title":"Stone Prover v3 at 1414a54","type":"implementation","venue":null,"year":2024,"sourcePath":"data/proof-systems-catalog.json#PROOF-IMPL-2024-STONE-1414A54"},{"evidence":"primary_source_checked","id":"PROOF-IMPL-2025-JOLT-783DA5D","metadata":{"artifact":{"commit":"783da5d32010e707f85085d59ae0451f6d8a6b25","commit_url":"https://github.com/a16z/jolt/tree/783da5d32010e707f85085d59ae0451f6d8a6b25","repository":"https://github.com/a16z/jolt","version":"commit-783da5d"},"artifact_type":"open-source alpha zkVM","availability":"public repository","backend":"RV32IM Jolt with BN254 HyperKZG PCS and Keccak transcript","benchmark_eligibility_note":"One commit-bound CI observation is curated; missing CPU/thread/security coordinates keep it out of rankings.","benchmark_eligible":true,"configuration_binding":"exact_commit_profile","configuration_ids":["PROOF-SYSTEM-JOLT"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-IMPL-2025-JOLT-783DA5D","language":"Rust","maturity":"alpha, unaudited research implementation","paper_ids":["PROOF-PAPER-2023-JOLT"],"primary_url":"https://github.com/a16z/jolt/tree/783da5d32010e707f85085d59ae0451f6d8a6b25","realized_stack":{"arithmetization":"Jolt instruction and memory constraints","commitment_backend":"HyperKZG over BN254","compiler":"Fiat-Shamir with Keccak transcript","composition_mechanism":"not_applicable","computation_model":"RV32IM","protocol_iop":"lookup/sum-check architecture","specialized_argument":"Lasso-style instruction lookups and memory checking"},"source_locator":"pinned jolt-sdk/src/host_utils.rs; jolt-core/src/jolt/vm/rv32i_vm.rs; rust-toolchain.toml; CI benchmark workflow","source_urls":["https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/jolt-sdk/src/host_utils.rs","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/jolt-core/src/jolt/vm/rv32i_vm.rs","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/rust-toolchain.toml","https://github.com/a16z/jolt/blob/783da5d32010e707f85085d59ae0451f6d8a6b25/.github/workflows/ci-bench.yml"],"status":"reported","tags":["implementation","jolt","rv32im","hyperkzg","alpha"],"title":"Jolt RV32IM / HyperKZG at 783da5d","year":2025},"primaryUrl":"https://github.com/a16z/jolt/tree/783da5d32010e707f85085d59ae0451f6d8a6b25","sections":[{"content":"This is the exact artifact version behind the selected February 2025 CI observation. It is separate from the later RV64IMAC/Dory implementation because the VM profile and commitment backend changed.","heading":"Scope"}],"status":"reported","subtitle":"2025","summary":"This is the exact artifact version behind the selected February 2025 CI observation. It is separate from the later RV64IMAC/Dory implementation because the VM profile and commitment backend changed.","tags":["alpha","hyperkzg","implementation","jolt","rv32im"],"title":"Jolt RV32IM / HyperKZG at 783da5d","type":"implementation","venue":null,"year":2025,"sourcePath":"data/proof-systems-catalog.json#PROOF-IMPL-2025-JOLT-783DA5D"},{"evidence":"primary_source_checked","id":"PROOF-IMPL-2025-LIBSPARTAN-3A2C097","metadata":{"artifact":{"commit":"3a2c097cab39ffa191560f445440a41ed40db5b3","commit_url":"https://github.com/microsoft/Spartan/tree/3a2c097cab39ffa191560f445440a41ed40db5b3","repository":"https://github.com/microsoft/Spartan","version":"0.9.0+3a2c097"},"artifact_type":"open-source research library","availability":"public repository and crates.io package","backend":"Ristretto255 vector commitments, Spartan SNARK and NIZK APIs, Merlin transcript","benchmark_eligibility_note":"The README preserves profiler output, but does not bind that historical output to an immutable generating commit, so it is not promoted as a benchmark run.","benchmark_eligible":false,"configuration_binding":"exact_spartan_library_variant","configuration_ids":["PROOF-SYSTEM-SPARTAN"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-IMPL-2025-LIBSPARTAN-3A2C097","language":"Rust","maturity":"unaudited research library","paper_ids":["PROOF-PAPER-2019-SPARTAN"],"primary_url":"https://github.com/microsoft/Spartan/tree/3a2c097cab39ffa191560f445440a41ed40db5b3","realized_stack":{"arithmetization":"R1CS","commitment_backend":"Ristretto255 discrete-log vector commitment","compiler":"Merlin Fiat-Shamir transcript","composition_mechanism":"not_applicable","computation_model":"arbitrary R1CS instance","protocol_iop":"Spartan sum-check reductions","specialized_argument":"not_applicable"},"source_locator":"Cargo.toml package version; README, Highlights, Implementation details, Examples, Building libspartan, and Performance","source_urls":["https://github.com/microsoft/Spartan/blob/3a2c097cab39ffa191560f445440a41ed40db5b3/Cargo.toml","https://github.com/microsoft/Spartan/blob/3a2c097cab39ffa191560f445440a41ed40db5b3/README.md"],"status":"reported","tags":["implementation","spartan","r1cs","ristretto255","rust"],"title":"libspartan at 3a2c097","year":2025},"primaryUrl":"https://github.com/microsoft/Spartan/tree/3a2c097cab39ffa191560f445440a41ed40db5b3","sections":[{"content":"This record covers the official libspartan artifact at one immutable commit. It does not turn the README's historical profiler transcript into a commit-bound benchmark observation, and the repository states that the library has not received a security review or audit.","heading":"Scope"}],"status":"reported","subtitle":"2025","summary":"This record covers the official libspartan artifact at one immutable commit. It does not turn the README's historical profiler transcript into a commit-bound benchmark observation, and the repository states that the library has not received a security review or audit.","tags":["implementation","r1cs","ristretto255","rust","spartan"],"title":"libspartan at 3a2c097","type":"implementation","venue":null,"year":2025,"sourcePath":"data/proof-systems-catalog.json#PROOF-IMPL-2025-LIBSPARTAN-3A2C097"},{"evidence":"primary_source_checked","id":"PROOF-IMPL-2026-JOLT-915FAF4","metadata":{"artifact":{"commit":"915faf453f36871249615a7fdf2704d77a88f259","commit_url":"https://github.com/a16z/jolt/tree/915faf453f36871249615a7fdf2704d77a88f259","repository":"https://github.com/a16z/jolt","version":"commit-915faf4"},"artifact_type":"open-source alpha zkVM","availability":"public repository, documentation, and continuous benchmark dashboard","backend":"RV64IMAC Jolt with Dory PCS over BN254 and Pedersen vector commitments","benchmark_eligibility_note":"One commit-bound CI observation is curated; missing CPU/thread/security coordinates keep it out of rankings.","benchmark_eligible":true,"configuration_binding":"exact_commit_profile","configuration_ids":["PROOF-SYSTEM-JOLT"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-IMPL-2026-JOLT-915FAF4","language":"Rust","maturity":"alpha, unaudited research implementation","paper_ids":["PROOF-PAPER-2023-JOLT","PROOF-PAPER-2025-JOLT-SPACE"],"primary_url":"https://github.com/a16z/jolt/tree/915faf453f36871249615a7fdf2704d77a88f259","realized_stack":{"arithmetization":"Jolt instruction, bytecode, memory, and R1CS layers","commitment_backend":"Dory over BN254 with Pedersen vector commitments","compiler":"legacy Blake2b transcript in default host profile","composition_mechanism":"optional_external","computation_model":"RV64IMAC","protocol_iop":"lookup/sum-check architecture","specialized_argument":"instruction lookup and memory-checking stack"},"source_locator":"pinned README; jolt-sdk/src/host_utils.rs; rust-toolchain.toml; CI workflow; examples/sha2-chain; benchmark dashboard","source_urls":["https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/README.md","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/jolt-sdk/src/host_utils.rs","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/rust-toolchain.toml","https://github.com/a16z/jolt/blob/915faf453f36871249615a7fdf2704d77a88f259/.github/workflows/ci-bench.yml"],"status":"reported","tags":["implementation","jolt","rv64imac","dory","alpha"],"title":"Jolt RV64IMAC / Dory at 915faf4","year":2026},"primaryUrl":"https://github.com/a16z/jolt/tree/915faf453f36871249615a7fdf2704d77a88f259","sections":[{"content":"The repository explicitly labels Jolt alpha and not suitable for production use. The record binds the default host profile at this commit; alternative crates, transcript features, profiling paths, and experimental code are not silently merged into the benchmark configuration.","heading":"Scope"}],"status":"reported","subtitle":"2026","summary":"The repository explicitly labels Jolt alpha and not suitable for production use. The record binds the default host profile at this commit; alternative crates, transcript features, profiling paths, and experimental code are not silently merged into the benchmark configuration.","tags":["alpha","dory","implementation","jolt","rv64imac"],"title":"Jolt RV64IMAC / Dory at 915faf4","type":"implementation","venue":null,"year":2026,"sourcePath":"data/proof-systems-catalog.json#PROOF-IMPL-2026-JOLT-915FAF4"},{"evidence":"primary_source_checked","id":"PROOF-IMPL-2026-NOVA-9092303","metadata":{"artifact":{"commit":"909230314a7173b0f96d06e0c810d10f65f599f1","commit_url":"https://github.com/microsoft/Nova/tree/909230314a7173b0f96d06e0c810d10f65f599f1","repository":"https://github.com/microsoft/Nova","version":"0.73.0+9092303"},"artifact_type":"open-source research library","availability":"public repository","backend":"Nova folding with Pedersen/IPA, HyperKZG, or Mercury compression paths over supported curve cycles","benchmark_eligibility_note":"A benchmark row must select curve cycle, commitment/compression backend, circuit frontend, feature set, and whether setup/compression is included; no such run is curated here.","benchmark_eligible":false,"configuration_binding":"versioned_library_with_multiple_explicit_backends","configuration_ids":["PROOF-SYSTEM-NOVA"],"dossier_type":"implementation","evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","id":"PROOF-IMPL-2026-NOVA-9092303","language":"Rust","maturity":"research library with experimental feature gates","paper_ids":["PROOF-PAPER-2021-NOVA","PROOF-PAPER-2023-HYPERNOVA"],"primary_url":"https://github.com/microsoft/Nova/tree/909230314a7173b0f96d06e0c810d10f65f599f1","realized_stack":{"arithmetization":"relaxed R1CS folding core","commitment_backend":"Pedersen/IPA on supported cycles; HyperKZG or Mercury on BN254","compiler":"library transcript and selected frontend path","composition_mechanism":"Nova folding with optional compression/decider","computation_model":"bellman-style step circuits; external Circom middleware documented","protocol_iop":"Spartan-based optional compression","specialized_argument":"not_applicable"},"source_locator":"README, Details of the library, Supported front-ends, Cargo Features, Tests and examples, and Universal Setup","source_urls":["https://github.com/microsoft/Nova/blob/909230314a7173b0f96d06e0c810d10f65f599f1/Cargo.toml","https://github.com/microsoft/Nova/blob/909230314a7173b0f96d06e0c810d10f65f599f1/README.md"],"status":"reported","tags":["implementation","nova","folding","ivc","rust"],"title":"nova-snark at 9092303","year":2026},"primaryUrl":"https://github.com/microsoft/Nova/tree/909230314a7173b0f96d06e0c810d10f65f599f1","sections":[{"content":"The repository is a versioned implementation entity, not one benchmark configuration. Its backend choice can change setup and verifier performance, so the catalog does not inherit one timeless performance claim from the Nova family.","heading":"Scope"}],"status":"reported","subtitle":"2026","summary":"The repository is a versioned implementation entity, not one benchmark configuration. Its backend choice can change setup and verifier performance, so the catalog does not inherit one timeless performance claim from the Nova family.","tags":["folding","implementation","ivc","nova","rust"],"title":"nova-snark at 9092303","type":"implementation","venue":null,"year":2026,"sourcePath":"data/proof-systems-catalog.json#PROOF-IMPL-2026-NOVA-9092303"},{"evidence":"source_derived","id":"PROOF-MILESTONE-001-01","metadata":{"frontier_track":"assumptions","order":1,"parent_problem_id":"PROOF-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-001","summary":"Remove the Hardness Certification assumption from the 2026 non-adaptive all-NP construction while retaining its other coordinates.","tags":["weaker-target","assumptions"],"title":"Remove the Hardness Certification assumption from the 2026 non-adaptive all-NP construction while retaining…","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-001-01"},{"evidence":"source_derived","id":"PROOF-MILESTONE-001-02","metadata":{"frontier_track":"security","order":2,"parent_problem_id":"PROOF-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-001","summary":"Achieve adaptive soundness for all NP while retaining the 2026 assumption set.","tags":["weaker-target","security"],"title":"Achieve adaptive soundness for all NP while retaining the 2026 assumption set.","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-001-02"},{"evidence":"source_derived","id":"PROOF-MILESTONE-001-03","metadata":{"frontier_track":"compiler","order":3,"parent_problem_id":"PROOF-OP-001"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-001","summary":"Construct a mildly succinct knowledge-sound argument for all NP from standard assumptions that satisfies the 2025 boosting compiler's hypotheses.","tags":["weaker-target","compiler"],"title":"Construct a mildly succinct knowledge-sound argument for all NP from standard assumptions that satisfies the…","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-001-03"},{"evidence":"source_derived","id":"PROOF-MILESTONE-002-01","metadata":{"frontier_track":"succinctness","order":1,"parent_problem_id":"PROOF-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-002","summary":"Obtain a transparent post-quantum PCS with constant opening proofs and logarithmic verifier time.","tags":["weaker-target","succinctness"],"title":"Obtain a transparent post-quantum PCS with constant opening proofs and logarithmic verifier time.","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-002-01"},{"evidence":"source_derived","id":"PROOF-MILESTONE-002-02","metadata":{"frontier_track":"prover","order":2,"parent_problem_id":"PROOF-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-002","summary":"Obtain logarithmic proof and verifier costs with linear prover time and a full quantum knowledge-soundness proof.","tags":["weaker-target","prover"],"title":"Obtain logarithmic proof and verifier costs with linear prover time and a full quantum knowledge-soundness…","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-002-02"},{"evidence":"source_derived","id":"PROOF-MILESTONE-002-03","metadata":{"frontier_track":"batching","order":3,"parent_problem_id":"PROOF-OP-002"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-002","summary":"Add secure same-polynomial and multi-polynomial batching without losing the target setup or quantum-security coordinates.","tags":["weaker-target","batching"],"title":"Add secure same-polynomial and multi-polynomial batching without losing the target setup or quantum-security…","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-002-03"},{"evidence":"source_derived","id":"PROOF-MILESTONE-003-01","metadata":{"frontier_track":"extraction","order":1,"parent_problem_id":"PROOF-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-003","summary":"Prove a composable extraction notion weaker than full witness-extended emulation but with an explicit post-extraction state-distance guarantee.","tags":["weaker-target","extraction"],"title":"Prove a composable extraction notion weaker than full witness-extended emulation but with an explicit…","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-003-01"},{"evidence":"source_derived","id":"PROOF-MILESTONE-003-02","metadata":{"frontier_track":"adaptivity","order":2,"parent_problem_id":"PROOF-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-003","summary":"Extend post-quantum soundness and ordinary knowledge soundness from semi-adaptive to fully adaptive public-coin IOP verifiers.","tags":["weaker-target","adaptivity"],"title":"Extend post-quantum soundness and ordinary knowledge soundness from semi-adaptive to fully adaptive…","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-003-02"},{"evidence":"source_derived","id":"PROOF-MILESTONE-003-03","metadata":{"frontier_track":"lower_bound","order":3,"parent_problem_id":"PROOF-OP-003"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-003","summary":"Give a separation or counterexample showing that the current IBCS interface cannot satisfy one named stronger extraction notion.","tags":["weaker-target","lower_bound"],"title":"Give a separation or counterexample showing that the current IBCS interface cannot satisfy one named…","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-003-03"},{"evidence":"source_derived","id":"PROOF-MILESTONE-004-01","metadata":{"frontier_track":"interaction","order":1,"parent_problem_id":"PROOF-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-004","summary":"Construct an interactive standard-model accumulation scheme for a useful argument predicate with the target succinct accumulator.","tags":["weaker-target","interaction"],"title":"Construct an interactive standard-model accumulation scheme for a useful argument predicate with the target…","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-004-01"},{"evidence":"source_derived","id":"PROOF-MILESTONE-004-02","metadata":{"frontier_track":"compiler","order":2,"parent_problem_id":"PROOF-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-004","summary":"Prove a standard-model compiler from a named special-sound folding protocol to non-interactive accumulation under correlation-intractability or another explicitly falsifiable intermediate assumption not known to imply SNARKs.","tags":["weaker-target","compiler"],"title":"Prove a standard-model compiler from a named special-sound folding protocol to non-interactive accumulation…","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-004-02"},{"evidence":"source_derived","id":"PROOF-MILESTONE-004-03","metadata":{"frontier_track":"lower_bound","order":3,"parent_problem_id":"PROOF-OP-004"},"primaryUrl":null,"sections":[],"status":"open","subtitle":"Weaker target toward PROOF-OP-004","summary":"Prove a black-box impossibility for a precisely delimited class of accumulation predicates and reductions.","tags":["weaker-target","lower_bound"],"title":"Prove a black-box impossibility for a precisely delimited class of accumulation predicates and reductions.","type":"milestone","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-MILESTONE-004-03"},{"evidence":"claim_audited","id":"PROOF-OP-001","metadata":{"barriers":["PROOF-BARRIER-001"],"closest_results":["PROOF-PAPER-2026-SNARG-UNPROVABILITY","PROOF-PAPER-2025-BOOSTING-SNARKS"],"dossier_type":"open_problem","evidence":"claim_audited","faithful_source_statement":"Cheng–Goyal describe all-NP SNARGs in the standard model from standard falsifiable assumptions as longstanding and note that prior constructions cover subclasses; Hsieh–Jain–Li–Mathialagan reach all NP with non-adaptive soundness by adding a new Hardness Certification assumption.","hierarchy_links":[],"hierarchy_role":"research_line_endpoint","id":"PROOF-OP-001","milestone_tracks":["assumptions","security","compiler"],"milestones":["Remove the Hardness Certification assumption from the 2026 non-adaptive all-NP construction while retaining its other coordinates.","Achieve adaptive soundness for all NP while retaining the 2026 assumption set.","Construct a mildly succinct knowledge-sound argument for all NP from standard assumptions that satisfies the 2025 boosting compiler's hypotheses."],"normalization_delta":"The historical target is updated after the June 2026 all-NP result. The residual explicitly asks to remove its proof-complexity unprovability assumption and to upgrade non-adaptive to adaptive soundness; it does not claim that the 2026 construction failed to reach all NP.","order":1,"originType":"normalized_lineage_gap","origin_evidence":[{"locator":"Introduction, LIPIcs pp. 56:2–56:3","paper":"PROOF-PAPER-2025-BOOSTING-SNARKS","relation":"explicit_field_target"},{"locator":"Abstract; Section 1.1; Theorem 1.1","paper":"PROOF-PAPER-2026-SNARG-UNPROVABILITY","relation":"closest_result_and_residual"}],"origin_type":"normalized_lineage_gap","profile":{"assumptions":"fixed_standard_falsifiable_cryptographic_assumptions","excluded_idealizations":["random_oracle","knowledge_assumption","indistinguishability_obfuscation","witness_encryption","proof_complexity_unprovability"],"model":"common_reference_string_standard_model","proof_size":"poly_security_instance_and_log_computation_not_witness_length","reduction_access":"non_black_box_allowed","relation_class":"all_NP","soundness":"adaptive_statement_selection_after_CRS","task":"succinct_noninteractive_argument","verification":"public_and_succinct"},"provenance":["PROOF-PAPER-2025-BOOSTING-SNARKS","PROOF-PAPER-2026-SNARG-UNPROVABILITY"],"resolutionCondition":"A primary-source construction gives a publicly verifiable, adaptively sound, fully succinct SNARG for every NP relation in the CRS standard model, with proof length and verifier work independent of witness length except through logarithmic computation parameters, and bases security only on explicitly named standard falsifiable cryptographic assumptions; a black-box reduction is not required.","resolution_condition":"A primary-source construction gives a publicly verifiable, adaptively sound, fully succinct SNARG for every NP relation in the CRS standard model, with proof length and verifier work independent of witness length except through logarithmic computation parameters, and bases security only on explicitly named standard falsifiable cryptographic assumptions; a black-box reduction is not required.","routes":["PROOF-ROUTE-001"],"status":"open","target_profile":{"assumptions":"fixed_standard_falsifiable_cryptographic_assumptions","excluded_idealizations":["random_oracle","knowledge_assumption","indistinguishability_obfuscation","witness_encryption","proof_complexity_unprovability"],"model":"common_reference_string_standard_model","proof_size":"poly_security_instance_and_log_computation_not_witness_length","reduction_access":"non_black_box_allowed","relation_class":"all_NP","soundness":"adaptive_statement_selection_after_CRS","task":"succinct_noninteractive_argument","verification":"public_and_succinct"},"title":"Adaptive fully succinct SNARGs for all NP from standard falsifiable assumptions"},"primaryUrl":null,"sections":[{"content":"Construct a publicly verifiable SNARG for every polynomial-time NP relation in the CRS model. The prover sends one proof after seeing the CRS, the adversary may choose its false statement after seeing that CRS, and proof length plus verifier work are poly(λ, |x|, log T) rather than polynomial in the witness length or NP verification time T. Security must reduce to a fixed, explicitly stated collection of standard falsifiable cryptographic assumptions. The target excludes a programmed random oracle, knowledge/extractability assumptions, iO or witness encryption, and a separate proof-complexity or mathematical-unprovability assumption. Because of the Gentry–Wichs barrier, a non-black-box reduction is allowed.","heading":"Exact normalized target"},{"content":"PROOF-PAPER-2026-SNARG-UNPROVABILITY reaches all NP with succinct proofs, but its theorem is non-adaptive and adds the Hardness Certification assumption. PROOF-PAPER-2025-BOOSTING-SNARKS shows that a suitable mildly succinct SNARK can be promoted to full succinctness, but does not supply that base object from standard assumptions.","heading":"Closest known results"},{"content":"A result for P, batch NP, or another proper subclass; a random-oracle or knowledge-assumption SNARK; or a non-adaptively sound all-NP construction still counts as a weaker milestone.","heading":"What would not resolve it"}],"status":"open","subtitle":"","summary":"Construct a publicly verifiable SNARG for every polynomial-time NP relation in the CRS model. The prover sends one proof after seeing the CRS, the adversary may choose its false statement after seeing that CRS, and proof length plus verifier work are poly(λ, |x|, log T) rather than polynomial in the witness length or NP verification time T. Security must reduce to a fixed, explicitly stated collection of standard falsifiable…","tags":[],"title":"Adaptive fully succinct SNARGs for all NP from standard falsifiable assumptions","type":"open_problem","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-OP-001"},{"evidence":"claim_audited","id":"PROOF-OP-002","metadata":{"barriers":["PROOF-BARRIER-002"],"closest_results":["PROOF-PAPER-2023-BEHEMOTH","PROOF-PAPER-2024-LATTICE-PCS","PROOF-PAPER-2024-WHIR"],"dossier_type":"open_problem","evidence":"claim_audited","faithful_source_statement":"Behemoth asks whether a transparent, plausibly post-quantum polynomial commitment can have both constant-size opening proofs and constant-time verification.","hierarchy_links":[],"hierarchy_role":"research_line_endpoint","id":"PROOF-OP-002","milestone_tracks":["succinctness","prover","batching"],"milestones":["Obtain a transparent post-quantum PCS with constant opening proofs and logarithmic verifier time.","Obtain logarithmic proof and verifier costs with linear prover time and a full quantum knowledge-soundness proof.","Add secure same-polynomial and multi-polynomial batching without losing the target setup or quantum-security coordinates."],"normalization_delta":"The card makes the degree parameter, evaluation interface, negligible soundness, and proof-of-knowledge/binding obligation explicit. It does not add batching or quasi-linear proving to the resolution condition; those remain desirable strengthenings.","order":2,"originType":"explicit_open_question","origin_evidence":[{"locator":"Section 8.3, printed pp. 30–31","paper":"PROOF-PAPER-2023-BEHEMOTH","relation":"explicit_open_question"}],"origin_type":"explicit_open_question","profile":{"opening_proof_size":"O_security_1_independent_of_N","polynomial_domain":"univariate_degree_at_most_N_over_declared_field_or_ring","preprocessing":"no_secret_trapdoor","quantum_security":"binding_or_knowledge_soundness_against_quantum_adversaries","setup":"transparent_public_coin","soundness_error":"negligible","task":"polynomial_evaluation_commitment","verifier_time":"O_security_1_independent_of_N"},"provenance":["PROOF-PAPER-2023-BEHEMOTH"],"resolutionCondition":"A primary-source PCS construction and security proof provide transparent setup, plausible post-quantum binding or knowledge soundness, negligible error, O(poly(lambda)) opening-proof bits, and O(poly(lambda)) verifier time for one evaluation, with both costs independent of polynomial degree N.","resolution_condition":"A primary-source PCS construction and security proof provide transparent setup, plausible post-quantum binding or knowledge soundness, negligible error, O(poly(lambda)) opening-proof bits, and O(poly(lambda)) verifier time for one evaluation, with both costs independent of polynomial degree N.","routes":["PROOF-ROUTE-002"],"status":"open","target_profile":{"opening_proof_size":"O_security_1_independent_of_N","polynomial_domain":"univariate_degree_at_most_N_over_declared_field_or_ring","preprocessing":"no_secret_trapdoor","quantum_security":"binding_or_knowledge_soundness_against_quantum_adversaries","setup":"transparent_public_coin","soundness_error":"negligible","task":"polynomial_evaluation_commitment","verifier_time":"O_security_1_independent_of_N"},"title":"Transparent post-quantum polynomial commitments with constant openings and verification"},"primaryUrl":null,"sections":[{"content":"For degree bound N, construct Setup, Commit, Open, and Verify for polynomial evaluation such that setup uses only public randomness and no hidden trapdoor. Against quantum polynomial-time adversaries, the scheme has the declared binding or extractable-binding property with negligible error. A single evaluation opening contains poly(λ) bits and verification costs poly(λ) bit or field operations, with neither depending on N. Commitment generation and opening must remain polynomial time; quasi-linear proving and batching are strengthenings, not part of the minimum closing condition.","heading":"Exact normalized target"},{"content":"Behemoth meets transparency and the two constant-cost coordinates, but uses a group of unknown order, ROM/GGM analysis, a cubic prover, and makes no post-quantum claim. The CRYPTO 2024 lattice PCS gives transparent post-quantum knowledge soundness with polylogarithmic proof and verification. WHIR gives a modern hash-based transparent/PQ-compatible route with logarithmic-family rather than constant endpoints.","heading":"Closest known results"}],"status":"open","subtitle":"","summary":"For degree bound N, construct Setup, Commit, Open, and Verify for polynomial evaluation such that setup uses only public randomness and no hidden trapdoor. Against quantum polynomial-time adversaries, the scheme has the declared binding or extractable-binding property with negligible error. A single evaluation opening contains poly(λ) bits and verification costs poly(λ) bit or field operations, with neither depending on N.…","tags":[],"title":"Transparent post-quantum polynomial commitments with constant openings and verification","type":"open_problem","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-OP-002"},{"evidence":"claim_audited","id":"PROOF-OP-003","metadata":{"barriers":["PROOF-BARRIER-003"],"closest_results":["PROOF-PAPER-2025-IBCS-QUANTUM"],"dossier_type":"open_problem","evidence":"claim_audited","faithful_source_statement":"The quantum-rewinding analysis proves Unruh-style knowledge soundness for IBCS and explicitly leaves stronger extraction—such as witness-extended or state-preserving extraction—open.","hierarchy_links":[],"hierarchy_role":"research_line_endpoint","id":"PROOF-OP-003","milestone_tracks":["extraction","adaptivity","lower_bound"],"milestones":["Prove a composable extraction notion weaker than full witness-extended emulation but with an explicit post-extraction state-distance guarantee.","Extend post-quantum soundness and ordinary knowledge soundness from semi-adaptive to fully adaptive public-coin IOP verifiers.","Give a separation or counterexample showing that the current IBCS interface cannot satisfy one named stronger extraction notion."],"normalization_delta":"The card selects state-preserving witness extraction as the concrete stronger notion and fixes the already-proved semi-adaptive public-coin IOP plus collapsing-VC setting. Fully adaptive IOP verification is recorded as a weaker adjacent milestone, not conjoined with the closing condition.","order":3,"originType":"explicit_open_question","origin_evidence":[{"locator":"Section 1.1, Open problems, printed pp. 4–5","paper":"PROOF-PAPER-2025-IBCS-QUANTUM","relation":"explicit_open_question"}],"origin_type":"explicit_open_question","profile":{"adversary":"quantum_polynomial_time_with_auxiliary_quantum_state","compiler":"interactive_BCS","cryptographic_input":"collapse_position_binding_vector_commitment","extraction":"state_preserving_witness_extraction_or_witness_extended_emulation","information_theoretic_input":"semi_adaptive_public_coin_IOP_proof_of_knowledge","model":"standard_model_no_random_oracle"},"provenance":["PROOF-PAPER-2025-IBCS-QUANTUM"],"resolutionCondition":"A primary-source theorem shows that IBCS in the stated semi-adaptive-IOP and collapse-position-binding-VC setting satisfies a formally defined state-preserving witness-extraction or witness-extended-emulation notion against quantum adversaries, with an efficient extractor and explicit disturbance/error bounds sufficient for sequential composition.","resolution_condition":"A primary-source theorem shows that IBCS in the stated semi-adaptive-IOP and collapse-position-binding-VC setting satisfies a formally defined state-preserving witness-extraction or witness-extended-emulation notion against quantum adversaries, with an efficient extractor and explicit disturbance/error bounds sufficient for sequential composition.","routes":["PROOF-ROUTE-003"],"status":"open","target_profile":{"adversary":"quantum_polynomial_time_with_auxiliary_quantum_state","compiler":"interactive_BCS","cryptographic_input":"collapse_position_binding_vector_commitment","extraction":"state_preserving_witness_extraction_or_witness_extended_emulation","information_theoretic_input":"semi_adaptive_public_coin_IOP_proof_of_knowledge","model":"standard_model_no_random_oracle"},"title":"State-preserving post-quantum extraction for IOP-based succinct arguments"},"primaryUrl":null,"sections":[{"content":"Fix the interactive BCS compiler applied to a semi-adaptive public-coin IOP proof of knowledge and a collapse-position-binding vector commitment. Define a quantum extractor that, from any successful quantum argument prover with auxiliary state, outputs a valid NP witness while returning a residual adversary/environment state that is indistinguishable—or within an explicit composable trace-distance bound—from the state of an accepting real interaction. The theorem must quantify extractor size, success loss, and state disturbance and must not appeal to a random oracle.","heading":"Exact normalized target"},{"content":"The 2025 theorem already proves post-quantum soundness and its stated argument-of-knowledge notion. This card does not relabel that theorem as incomplete; it tracks the stronger compositional property the authors themselves distinguish.","heading":"Scope boundary"}],"status":"open","subtitle":"","summary":"Fix the interactive BCS compiler applied to a semi-adaptive public-coin IOP proof of knowledge and a collapse-position-binding vector commitment. Define a quantum extractor that, from any successful quantum argument prover with auxiliary state, outputs a valid NP witness while returning a residual adversary/environment state that is indistinguishable—or within an explicit composable trace-distance bound—from the state of an…","tags":[],"title":"State-preserving post-quantum extraction for IOP-based succinct arguments","type":"open_problem","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-OP-003"},{"evidence":"claim_audited","id":"PROOF-OP-004","metadata":{"barriers":["PROOF-BARRIER-004"],"closest_results":["PROOF-PAPER-2020-ACCUMULATION","PROOF-PAPER-2021-NOVA","PROOF-PAPER-2023-PROTOSTAR"],"dossier_type":"open_problem","evidence":"claim_audited","faithful_source_statement":"Bünz–Chiesa–Mishra–Spooner state that known non-interactive accumulation schemes use random oracles or knowledge assumptions and ask for accumulation for non-interactive arguments, or another interesting predicate, from standard assumptions not already known to imply SNARKs.","hierarchy_links":[],"hierarchy_role":"research_line_endpoint","id":"PROOF-OP-004","milestone_tracks":["interaction","compiler","lower_bound"],"milestones":["Construct an interactive standard-model accumulation scheme for a useful argument predicate with the target succinct accumulator.","Prove a standard-model compiler from a named special-sound folding protocol to non-interactive accumulation under correlation-intractability or another explicitly falsifiable intermediate assumption not known to imply SNARKs.","Prove a black-box impossibility for a precisely delimited class of accumulation predicates and reductions."],"normalization_delta":"The broad source question is specialized to accumulation for a non-interactive argument with succinct accumulation verification and a standard-model security proof. The target excludes assumptions already known to imply general SNARKs, while allowing any explicitly named falsifiable standard assumption.","order":4,"originType":"explicit_open_question","origin_evidence":[{"locator":"Section 1.1, paragraph Open problem — accumulation in the standard model","paper":"PROOF-PAPER-2020-ACCUMULATION","relation":"explicit_open_question"}],"origin_type":"explicit_open_question","profile":{"accumulator_size":"succinct_independent_of_number_of_accumulated_instances","assumptions":"standard_falsifiable_and_not_known_to_imply_general_SNARKs","excluded_idealizations":["random_oracle","Fiat_Shamir_heuristic","knowledge_assumption"],"interaction":"noninteractive_accumulation_proof","model":"CRS_standard_model","security":"adaptive_knowledge_soundness_sufficient_for_PCD","task":"accumulation_scheme_for_noninteractive_arguments","verifier_work":"sublinear_in_total_accumulated_verification_work"},"provenance":["PROOF-PAPER-2020-ACCUMULATION"],"resolutionCondition":"A primary-source construction gives a non-interactive accumulation scheme for a nontrivial argument predicate in the CRS standard model, proves the completeness and adaptive knowledge-soundness conditions needed by the PCD compiler, keeps accumulator size independent of the number of accumulated objects and verification sublinear in their total direct cost, and uses only named standard falsifiable assumptions not already known to imply general SNARKs.","resolution_condition":"A primary-source construction gives a non-interactive accumulation scheme for a nontrivial argument predicate in the CRS standard model, proves the completeness and adaptive knowledge-soundness conditions needed by the PCD compiler, keeps accumulator size independent of the number of accumulated objects and verification sublinear in their total direct cost, and uses only named standard falsifiable assumptions not already known to imply general SNARKs.","routes":["PROOF-ROUTE-004"],"status":"open","target_profile":{"accumulator_size":"succinct_independent_of_number_of_accumulated_instances","assumptions":"standard_falsifiable_and_not_known_to_imply_general_SNARKs","excluded_idealizations":["random_oracle","Fiat_Shamir_heuristic","knowledge_assumption"],"interaction":"noninteractive_accumulation_proof","model":"CRS_standard_model","security":"adaptive_knowledge_soundness_sufficient_for_PCD","task":"accumulation_scheme_for_noninteractive_arguments","verifier_work":"sublinear_in_total_accumulated_verification_work"},"title":"Non-interactive accumulation from standard assumptions without random oracles"},"primaryUrl":null,"sections":[{"content":"Construct a CRS-model accumulation scheme for a non-interactive argument predicate. Given prior accumulator(s) and fresh argument instance(s), the prover emits a non-interactive accumulation proof and a new accumulator whose size is independent of the number of accumulated inputs; the verifier's update work is sublinear in checking all inputs directly. The decider and PCD compiler satisfy their stated adaptive knowledge-soundness conditions. The security proof uses no random oracle, Fiat–Shamir heuristic, or knowledge assumption, and relies only on named falsifiable assumptions not already known to yield general SNARKs.","heading":"Exact normalized target"},{"content":"The 2020 paper provides the accumulation-to-PCD framework and concrete ROM/knowledge-assumption instantiations. Nova and Protostar give efficient folding/accumulation mechanisms, but their non-interactive use does not supply the missing standard-model theorem under the target assumption class.","heading":"Closest known results"}],"status":"open","subtitle":"","summary":"Construct a CRS-model accumulation scheme for a non-interactive argument predicate. Given prior accumulator(s) and fresh argument instance(s), the prover emits a non-interactive accumulation proof and a new accumulator whose size is independent of the number of accumulated inputs; the verifier's update work is sublinear in checking all inputs directly. The decider and PCD compiler satisfy their stated adaptive…","tags":[],"title":"Non-interactive accumulation from standard assumptions without random oracles","type":"open_problem","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-OP-004"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-1986-FS","metadata":{"authors":["Amos Fiat","Adi Shamir"],"contribution_ids":["PROOF-CONTRIB-1986-FS-COMPILER"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-1986-FS","keywords":["foundations","security-audit"],"lenses":["foundations","security-audit"],"primary_url":"https://doi.org/10.1007/3-540-47721-7_12","status":"published","title":"How to Prove Yourself: Practical Solutions to Identification and Signature Problems","venue":"CRYPTO 1986","versions":["CRYPTO 1986"],"year":1986},"primaryUrl":"https://doi.org/10.1007/3-540-47721-7_12","sections":[],"status":"published","subtitle":"Amos Fiat, Adi Shamir · 1986","summary":"Fiat–Shamir is stored as a compiler component. Its security model and exact applicability remain attached to each system claim rather than being inferred globally.","tags":["foundations","security-audit"],"title":"How to Prove Yourself: Practical Solutions to Identification and Signature Problems","type":"paper","venue":"CRYPTO 1986","year":1986,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-1986-FS"},{"evidence":"fulltext_checked","id":"PROOF-PAPER-1988-BFM","metadata":{"authors":["Manuel Blum","Paul Feldman","Silvio Micali"],"contribution_ids":["PROOF-CONTRIB-1988-BFM-NIZK-MODEL"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PROOF-PAPER-1988-BFM","keywords":["non-interactive-zero-knowledge","shared-random-string"],"primary_url":"https://doi.org/10.1145/62212.62222","status":"published","title":"Non-Interactive Zero-Knowledge and Its Applications (Extended Abstract)","venue":"STOC 1988, 103–112","versions":["STOC 1988: Non-Interactive Zero-Knowledge and Its Applications (Extended Abstract), 103–112; https://doi.org/10.1145/62212.62222"],"year":1988},"primaryUrl":"https://doi.org/10.1145/62212.62222","sections":[{"content":"This record describes the STOC 1988 extended abstract by Blum, Feldman, and Micali. The publication identity and pages were checked against the ACM publication record and Manuel Blum's bibliography. The user-supplied original conference PDF was read on 2026-09-05: ten PDF pages corresponding to printed pp. 103–112. Definitions and their quantifiers were checked visually against the scan, not just extracted text. The distinct 1991 SIAM article *Noninteractive Zero-Knowledge*, by Blum, De Santis, Micali, and Persiano (DOI 10.1137/0220068), is not recorded as a version of BFM88. Its statements must not be substituted for claims in the 1988 extended abstract.","heading":"Version and bibliographic notes"},{"content":"PROOF-CONTRIB-1988-BFM-NIZK-MODEL: the shared-random-string model for non-interactive zero knowledge. The source locator is §1.1 (printed p. 104, PDF p. 2), Definition 2.2 (printed p. 105, PDF p. 3), and Definition 3.1 with its verifier-view remark (printed p. 106, PDF p. 4). Section 4 and Definition 4.1 (printed pp. 108–109, PDF pp. 6–7) separately specify the many-theorem target; this is not an endorsement of that section's construction.","heading":"Atomic contributions"},{"content":"Definition 3.1 gives a single-theorem contract: a prover and verifier share a uniformly random string, communication goes only from prover to verifier, and the joint distribution of reference string and proof must be computationally simulatable from the statement. Definition 2.2 permits expected polynomial-time simulation. The verifier is polynomial-time; the definition does not require a polynomial-time prover given a witness. Statements are quantified before sampling the reference string, rather than chosen adaptively as a function of it. Theorem 3.1 and §§3.1–3.2 (printed pp. 106–108, PDF pp. 4–6) present a single-theorem 3-colorability construction under quadratic residuosity. The paper explicitly postpones its rigorous proof to a final paper; this batch records the model, not a separately certified construction. The reuse warning at the end of §3.2 (printed p. 108, PDF p. 6) explains that reusing this construction's randomness for another graph can leak relations between colorings. Section 4 does not merely repeat the single-theorem contract. It defines a many-theorem target with one initialization proof and separately generated statement proofs, then proposes a realization under the stronger 2-or-3-prime indistinguishability assumption (§2.3, printed p. 106, PDF p. 4; §§4.1–4.2, printed pp. 109–111, PDF pp. 7–9). However, FLS90, §1.1 footnote 1 (printed p. 308, PDF p. 1), explicitly reports that BFM88's proposed method for overcoming the reuse difficulty was found flawed. The original proposal remains part of the publication history, not an admitted reusable-NIZK feasibility result.","heading":"Definition and construction boundaries"},{"content":"fulltext_checked records review of this exact extended abstract's model and stated boundaries, not independent verification of every construction or proof. No modern adaptive-statement, simulation-soundness, extractability, succinctness, or efficient-witness-prover guarantee is inferred from the model introduction. The advertised chosen-ciphertext application in §5 (printed pp. 111–112, PDF pp. 9–10) is informal and is not promoted to an exact encryption-security claim here. Neither BDMP91's results nor a later version's proof may silently repair or strengthen this conference record. Any separately reviewed correction needs its own exact source and contribution identity.","heading":"Limitations and unresolved review"}],"status":"published","subtitle":"Manuel Blum, Paul Feldman, Silvio Micali · 1988","summary":"This record describes the STOC 1988 extended abstract by Blum, Feldman, and Micali. The publication identity and pages were checked against the ACM publication record and Manuel Blum's bibliography. The user-supplied original conference PDF was read on 2026-09-05: ten PDF pages corresponding to printed pp. 103–112. Definitions and their quantifiers were checked visually against the scan, not just extracted text. The distinct…","tags":[],"title":"Non-Interactive Zero-Knowledge and Its Applications (Extended Abstract)","type":"paper","venue":"STOC 1988, 103–112","year":1988,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-1988-BFM"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-1989-GMR","metadata":{"authors":["Shafi Goldwasser","Silvio Micali","Charles Rackoff"],"contribution_ids":["PROOF-CONTRIB-1989-GMR-ZK"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-1989-GMR","keywords":["foundations"],"lenses":["foundations"],"primary_url":"https://doi.org/10.1137/0218012","status":"published","title":"The Knowledge Complexity of Interactive Proof Systems","venue":"SIAM Journal on Computing 18(1), 186–208","versions":["STOC 1985 preliminary version","SIAM Journal on Computing 1989"],"year":1989},"primaryUrl":"https://doi.org/10.1137/0218012","sections":[{"content":"The atlas uses the journal version for the promoted definition-level claim. Bibliographic correction, 2026-09-05: the journal, pages, and DOI were checked against the SIAM publisher record. This corrects the former JACM attribution, not the scope or review depth of the definition. The existing claim locator, evidence status, and last_checked dates are retained; this was not a new full-text audit.","heading":"Evidence boundary"}],"status":"published","subtitle":"Shafi Goldwasser, Silvio Micali, Charles Rackoff · 1989","summary":"This is the semantic root for the privacy property. Zero knowledge is therefore modeled as a property of a protocol or configuration, not as a peer technical mechanism beside folding or polynomial commitments. Definitions and independent zero-knowledge research remain separately readable contributions; they are not confined to configuration-property filters.","tags":["foundations"],"title":"The Knowledge Complexity of Interactive Proof Systems","type":"paper","venue":"SIAM Journal on Computing 18(1), 186–208","year":1989,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-1989-GMR"},{"evidence":"fulltext_checked","id":"PROOF-PAPER-1990-FLS","metadata":{"authors":["Uriel Feige","Dror Lapidot","Adi Shamir"],"contribution_ids":["PROOF-CONTRIB-1990-FLS-MULTI-THEOREM"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PROOF-PAPER-1990-FLS","keywords":["non-interactive-zero-knowledge","shared-random-string","multiple-theorem"],"primary_url":"https://doi.org/10.1109/FSCS.1990.89549","status":"published","title":"Multiple Non-Interactive Zero Knowledge Proofs Based on a Single Random String (Extended Abstract)","venue":"FOCS 1990, 308–317","versions":["FOCS 1990: Multiple Non-Interactive Zero Knowledge Proofs Based on a Single Random String (Extended Abstract), 308–317; https://doi.org/10.1109/FSCS.1990.89549","SIAM Journal on Computing 29(1), 1999: Multiple NonInteractive Zero Knowledge Proofs Under General Assumptions, 1–28; https://doi.org/10.1137/S0097539792230010"],"year":1990},"primaryUrl":"https://doi.org/10.1109/FSCS.1990.89549","sections":[{"content":"The stable paper ID and year use the original FOCS 1990 publication by Feige, Lapidot, and Shamir (conference record). The later journal version has a different title, *Multiple NonInteractive Zero Knowledge Proofs Under General Assumptions*, and appears in SIAM Journal on Computing 29(1), 1–28, 1999 (journal record). These versions are retained for bibliographic tracking. Theorem numbering, assumptions, and security guarantees from the journal version are not attributed to the conference version without a version-specific claim audit. The user-supplied ten-page IEEE proceedings PDF was reviewed on 2026-09-05. It is the FOCS 1990 extended abstract, printed pages 308–317, not the later 28-page journal article. All locators below refer to this conference version. The journal version remains unreviewed; its definitions, assumptions, proof details, and theorem numbers are not imported here.","heading":"Version and bibliographic notes"},{"content":"PROOF-CONTRIB-1990-FLS-MULTI-THEOREM: converts an efficient-prover bounded NIZK for an NP-complete language, together with a one-way-function/PRG assumption, into a general NIZK supporting polynomially many independent provers and polynomially many statements on the same random reference string. The main source is §3.1, Definition 3.7, and §3.3, Theorem 3.12 and its proof (PDF pp. 5–7; printed pp. 312–314). This is a transform with a required base proof system, not an NIZK existence claim from one-way functions alone. The contribution records the conditional adaptive extension separately as a scope qualifier: §4.2, Theorem 4.20 requires a single-statement adaptive base (PDF p. 9; printed p. 316), under the definitions in §4.1 (PDF pp. 7–8). It does not turn every bounded base into an adaptively secure system.","heading":"Atomic contributions"},{"content":"The source check covers the exact single-to-many transform and its stated boundaries. It is not an independent theorem verification. The conference text contains proof sketches and omitted details; the unrestricted statement-size extension is only a remark attributing an adaptable technique to [BDMP89] (§3.3, PDF p. 7; printed p. 314), so no independent unbounded-size guarantee is admitted. The paper's distinct preprocessing and hidden-bit constructions in §2 are not separate contributions in this batch. In particular, the generic §3 transform does not require replacing its explicit efficient-prover bounded-NIZK premise with an unsupported one-way-functions-only construction claim. The §2.4 trapdoor-permutation instantiation and any journal-version refinements need their own version-specific audit before entering a comparison. For historical accuracy, §1.1 footnote 1 (PDF p. 1; printed p. 308) reports that the same-string reuse method proposed in BFM88 was flawed. This is a scoped later-source warning about that proposal, not a rejection of BFM88's NIZK model or an independently reproduced attack. Multiple proofs here are not proof aggregation, recursion, succinctness, knowledge extraction, or simulation extractability.","heading":"Limitations and unresolved review"}],"status":"published","subtitle":"Uriel Feige, Dror Lapidot, Adi Shamir · 1990","summary":"The stable paper ID and year use the original FOCS 1990 publication by Feige, Lapidot, and Shamir (conference record). The later journal version has a different title, *Multiple NonInteractive Zero Knowledge Proofs Under General Assumptions*, and appears in SIAM Journal on Computing 29(1), 1–28, 1999 (journal record). These versions are retained for bibliographic tracking. Theorem numbering, assumptions, and security…","tags":[],"title":"Multiple Non-Interactive Zero Knowledge Proofs Based on a Single Random String (Extended Abstract)","type":"paper","venue":"FOCS 1990, 308–317","year":1990,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-1990-FLS"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-1992-KILIAN","metadata":{"authors":["Joe Kilian"],"contribution_ids":["PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-1992-KILIAN","keywords":["foundations","transparent-hash"],"lenses":["foundations","transparent-hash"],"primary_url":"https://doi.org/10.1145/129712.129782","status":"published","title":"A Note on Efficient Zero-Knowledge Proofs and Arguments","venue":"STOC 1992","versions":["STOC 1992"],"year":1992},"primaryUrl":"https://doi.org/10.1145/129712.129782","sections":[],"status":"published","subtitle":"Joe Kilian · 1992","summary":"This contribution is a compiler architecture, not a complete modern STARK configuration. It anchors the later coded-oracle and Merkle-commitment lineage.","tags":["foundations","transparent-hash"],"title":"A Note on Efficient Zero-Knowledge Proofs and Arguments","type":"paper","venue":"STOC 1992","year":1992,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-1992-KILIAN"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-1992-LFKN","metadata":{"authors":["Carsten Lund","Lance Fortnow","Howard Karloff","Noam Nisan"],"contribution_ids":["PROOF-CONTRIB-1992-LFKN-SUMCHECK"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-1992-LFKN","keywords":["foundations","multilinear-sumcheck"],"lenses":["foundations","multilinear-sumcheck"],"primary_url":"https://doi.org/10.1145/146585.146605","status":"published","title":"Algebraic Methods for Interactive Proof Systems","venue":"Journal of the ACM 39(4)","versions":["FOCS 1990 preliminary version","JACM 1992"],"year":1992},"primaryUrl":"https://doi.org/10.1145/146585.146605","sections":[],"status":"published","subtitle":"Carsten Lund, Lance Fortnow, Howard Karloff et al. · 1992","summary":"The contribution is promoted as a reusable protocol component. Later systems use it through different arithmetizations and commitment backends.","tags":["foundations","multilinear-sumcheck"],"title":"Algebraic Methods for Interactive Proof Systems","type":"paper","venue":"Journal of the ACM 39(4)","year":1992,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-1992-LFKN"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2010-KZG","metadata":{"authors":["Aniket Kate","Gregory M. Zaverucha","Ian Goldberg"],"contribution_ids":["PROOF-CONTRIB-2010-KZG-PCS"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2010-KZG","keywords":["pairing-succinct","universal-polynomial"],"lenses":["pairing-succinct","universal-polynomial"],"primary_url":"https://eprint.iacr.org/2010/009","status":"published","title":"Constant-Size Commitments to Polynomials and Their Applications","venue":"ASIACRYPT 2010","versions":["IACR ePrint 2010/009","ASIACRYPT 2010"],"year":2010},"primaryUrl":"https://eprint.iacr.org/2010/009","sections":[{"content":"The source establishes a commitment component. Security and setup claims for PLONK or Marlin require their own compiler and protocol analyses.","heading":"Evidence boundary"}],"status":"published","subtitle":"Aniket Kate, Gregory M. Zaverucha, Ian Goldberg · 2010","summary":"The source establishes a commitment component. Security and setup claims for PLONK or Marlin require their own compiler and protocol analyses.","tags":["pairing-succinct","universal-polynomial"],"title":"Constant-Size Commitments to Polynomials and Their Applications","type":"paper","venue":"ASIACRYPT 2010","year":2010,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2010-KZG"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2016-GROTH","metadata":{"authors":["Jens Groth"],"contribution_ids":["PROOF-CONTRIB-2016-GROTH-3ELEMENT"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2016-GROTH","keywords":["pairing-succinct"],"lenses":["pairing-succinct"],"primary_url":"https://eprint.iacr.org/2016/260","status":"published","title":"On the Size of Pairing-based Non-interactive Arguments","venue":"EUROCRYPT 2016","versions":["IACR ePrint 2016/260","EUROCRYPT 2016"],"year":2016},"primaryUrl":"https://eprint.iacr.org/2016/260","sections":[{"content":"The atlas labels the concrete QAP/R1CS, circuit-specific CRS configuration as Groth16 rather than treating every later implementation variant as identical.","heading":"Configuration note"}],"status":"published","subtitle":"Jens Groth · 2016","summary":"The atlas labels the concrete QAP/R1CS, circuit-specific CRS configuration as Groth16 rather than treating every later implementation variant as identical.","tags":["pairing-succinct"],"title":"On the Size of Pairing-based Non-interactive Arguments","type":"paper","venue":"EUROCRYPT 2016","year":2016,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2016-GROTH"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2017-BULLETPROOFS","metadata":{"authors":["Benedikt Bünz","Jonathan Bootle","Dan Boneh","Andrew Poelstra","Pieter Wuille","Greg Maxwell"],"contribution_ids":["PROOF-CONTRIB-2017-BULLETPROOFS-IPA","PROOF-CONTRIB-2017-BULLETPROOFS-AGG"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2017-BULLETPROOFS","keywords":["transparent-hash","multilinear-sumcheck"],"lenses":["transparent-hash","multilinear-sumcheck"],"primary_url":"https://eprint.iacr.org/2017/1066","status":"published","title":"Bulletproofs: Short Proofs for Confidential Transactions and More","venue":"IEEE Symposium on Security and Privacy 2018","versions":["IACR ePrint 2017/1066","IEEE S&P 2018"],"year":2017},"primaryUrl":"https://eprint.iacr.org/2017/1066","sections":[{"content":"General arithmetic-circuit and range-proof uses are distinguished. The linear verifier behavior is not hidden behind the phrase “short proof.”","heading":"Evidence boundary"}],"status":"published","subtitle":"Benedikt Bünz, Jonathan Bootle, Dan Boneh et al. · 2017","summary":"General arithmetic-circuit and range-proof uses are distinguished. The linear verifier behavior is not hidden behind the phrase “short proof.”","tags":["multilinear-sumcheck","transparent-hash"],"title":"Bulletproofs: Short Proofs for Confidential Transactions and More","type":"paper","venue":"IEEE Symposium on Security and Privacy 2018","year":2017,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2017-BULLETPROOFS"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2018-STARK","metadata":{"authors":["Eli Ben-Sasson","Iddo Bentov","Yinon Horesh","Michael Riabzev"],"contribution_ids":["PROOF-CONTRIB-2018-STARK-SYSTEM"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2018-STARK","keywords":["transparent-hash"],"lenses":["transparent-hash"],"primary_url":"https://eprint.iacr.org/2018/046","status":"published","title":"Scalable, Transparent, and Post-Quantum Secure Computational Integrity","venue":"IACR ePrint 2018/046","versions":["IACR ePrint 2018/046"],"year":2018},"primaryUrl":"https://eprint.iacr.org/2018/046","sections":[{"content":"The atlas records AIR/IOP, proximity testing, Merkle commitments, and Fiat–Shamir as separate stack layers. “STARK” is not used as a backend label.","heading":"Normalization note"}],"status":"published","subtitle":"Eli Ben-Sasson, Iddo Bentov, Yinon Horesh et al. · 2018","summary":"The atlas records AIR/IOP, proximity testing, Merkle commitments, and Fiat–Shamir as separate stack layers. “STARK” is not used as a backend label.","tags":["transparent-hash"],"title":"Scalable, Transparent, and Post-Quantum Secure Computational Integrity","type":"paper","venue":"IACR ePrint 2018/046","year":2018,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2018-STARK"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2019-HALO","metadata":{"authors":["Sean Bowe","Jack Grigg","Daira Hopwood"],"contribution_ids":["PROOF-CONTRIB-2019-HALO-RECURSION"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2019-HALO","keywords":["recursion-ivc","transparent-hash"],"lenses":["recursion-ivc","transparent-hash"],"primary_url":"https://eprint.iacr.org/2019/1021","status":"published","title":"Recursive Proof Composition without a Trusted Setup","venue":"IACR ePrint 2019/1021","versions":["IACR ePrint 2019/1021"],"year":2019},"primaryUrl":"https://eprint.iacr.org/2019/1021","sections":[{"content":"Halo is classified under recursive composition. The IPA commitment is a backend component, and recursion is a capability realized by the complete configuration.","heading":"Normalization note"}],"status":"published","subtitle":"Sean Bowe, Jack Grigg, Daira Hopwood · 2019","summary":"Halo is classified under recursive composition. The IPA commitment is a backend component, and recursion is a capability realized by the complete configuration.","tags":["recursion-ivc","transparent-hash"],"title":"Recursive Proof Composition without a Trusted Setup","type":"paper","venue":"IACR ePrint 2019/1021","year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2019-HALO"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2019-MARLIN","metadata":{"authors":["Alessandro Chiesa","Yuncong Hu","Mary Maller","Pratyush Mishra","Noah Vesely","Nicholas Ward"],"contribution_ids":["PROOF-CONTRIB-2019-MARLIN-AHP"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2019-MARLIN","keywords":["universal-polynomial"],"lenses":["universal-polynomial"],"primary_url":"https://eprint.iacr.org/2019/1047","status":"published","title":"Marlin: Preprocessing zkSNARKs with Universal and Updatable SRS","venue":"EUROCRYPT 2020","versions":["IACR ePrint 2019/1047","EUROCRYPT 2020"],"year":2019},"primaryUrl":"https://eprint.iacr.org/2019/1047","sections":[{"content":"The AHP, polynomial commitment, and Fiat–Shamir layers remain distinct so backend substitution does not erase the theorem conditions.","heading":"Evidence boundary"}],"status":"published","subtitle":"Alessandro Chiesa, Yuncong Hu, Mary Maller et al. · 2019","summary":"The AHP, polynomial commitment, and Fiat–Shamir layers remain distinct so backend substitution does not erase the theorem conditions.","tags":["universal-polynomial"],"title":"Marlin: Preprocessing zkSNARKs with Universal and Updatable SRS","type":"paper","venue":"EUROCRYPT 2020","year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2019-MARLIN"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2019-PLONK","metadata":{"authors":["Ariel Gabizon","Zachary J. Williamson","Oana Ciobotaru"],"contribution_ids":["PROOF-CONTRIB-2019-PLONK-PIOP"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2019-PLONK","keywords":["universal-polynomial","pairing-succinct"],"lenses":["universal-polynomial","pairing-succinct"],"primary_url":"https://eprint.iacr.org/2019/953","status":"published","title":"PLONK: Permutations over Lagrange-bases for Oecumenical Noninteractive arguments of Knowledge","venue":"IACR ePrint 2019/953","versions":["IACR ePrint 2019/953"],"year":2019},"primaryUrl":"https://eprint.iacr.org/2019/953","sections":[{"content":"The displayed system row fixes the original KZG-backed configuration. “PLONKish” elsewhere means the constraint-system family, not every PLONK implementation.","heading":"Configuration note"}],"status":"published","subtitle":"Ariel Gabizon, Zachary J. Williamson, Oana Ciobotaru · 2019","summary":"The displayed system row fixes the original KZG-backed configuration. “PLONKish” elsewhere means the constraint-system family, not every PLONK implementation.","tags":["pairing-succinct","universal-polynomial"],"title":"PLONK: Permutations over Lagrange-bases for Oecumenical Noninteractive arguments of Knowledge","type":"paper","venue":"IACR ePrint 2019/953","year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2019-PLONK"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2019-SPARTAN","metadata":{"authors":["Srinath Setty"],"contribution_ids":["PROOF-CONTRIB-2019-SPARTAN-R1CS"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2019-SPARTAN","keywords":["multilinear-sumcheck","transparent-hash"],"lenses":["multilinear-sumcheck","transparent-hash"],"primary_url":"https://eprint.iacr.org/2019/550","status":"published","title":"Spartan: Efficient and General-purpose zkSNARKs without Trusted Setup","venue":"CRYPTO 2020","versions":["IACR ePrint 2019/550","CRYPTO 2020"],"year":2019},"primaryUrl":"https://eprint.iacr.org/2019/550","sections":[{"content":"SPARK and the chosen multilinear commitment instantiation are modeled as components, not collapsed into the R1CS arithmetization.","heading":"Stack note"}],"status":"published","subtitle":"Srinath Setty · 2019","summary":"SPARK and the chosen multilinear commitment instantiation are modeled as components, not collapsed into the R1CS arithmetization.","tags":["multilinear-sumcheck","transparent-hash"],"title":"Spartan: Efficient and General-purpose zkSNARKs without Trusted Setup","type":"paper","venue":"CRYPTO 2020","year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2019-SPARTAN"},{"evidence":"fulltext_checked","id":"PROOF-PAPER-2020-ACCUMULATION","metadata":{"authors":["Benedikt Bünz","Alessandro Chiesa","Pratyush Mishra","Nicholas Spooner"],"contribution_ids":["PROOF-CONTRIB-2020-ACCUMULATION-PCD"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PROOF-PAPER-2020-ACCUMULATION","keywords":["recursion-ivc"],"lenses":["recursion-ivc"],"primary_url":"https://eprint.iacr.org/2020/499","status":"published","title":"Proof-Carrying Data from Accumulation Schemes","venue":"TCC 2020","versions":["IACR ePrint 2020/499","TCC 2020"],"year":2020},"primaryUrl":"https://eprint.iacr.org/2020/499","sections":[{"content":"Section 1.1, paragraph “Open problem: accumulation in the standard model”, asks whether non-interactive arguments—or another interesting predicate—admit accumulation from standard assumptions, or from assumptions not already known to imply SNARKs.","heading":"Open-problem locator"}],"status":"published","subtitle":"Benedikt Bünz, Alessandro Chiesa, Pratyush Mishra et al. · 2020","summary":"Section 1.1, paragraph “Open problem: accumulation in the standard model”, asks whether non-interactive arguments—or another interesting predicate—admit accumulation from standard assumptions, or from assumptions not already known to imply SNARKs.","tags":["recursion-ivc"],"title":"Proof-Carrying Data from Accumulation Schemes","type":"paper","venue":"TCC 2020","year":2020,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2020-ACCUMULATION"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2021-NOVA","metadata":{"authors":["Abhiram Kothapalli","Srinath Setty","Ioanna Tzialla"],"contribution_ids":["PROOF-CONTRIB-2021-NOVA-FOLDING"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2021-NOVA","keywords":["recursion-ivc","multilinear-sumcheck"],"lenses":["recursion-ivc","multilinear-sumcheck"],"primary_url":"https://eprint.iacr.org/2021/370","status":"published","title":"Nova: Recursive Zero-Knowledge Arguments from Folding Schemes","venue":"CRYPTO 2022","versions":["IACR ePrint 2021/370","CRYPTO 2022"],"year":2021},"primaryUrl":"https://eprint.iacr.org/2021/370","sections":[{"content":"Nova’s folding core is not labeled a SNARK by itself. Succinct final verification requires the displayed decider/compression boundary to be stated separately.","heading":"Boundary note"}],"status":"published","subtitle":"Abhiram Kothapalli, Srinath Setty, Ioanna Tzialla · 2021","summary":"Nova’s folding core is not labeled a SNARK by itself. Succinct final verification requires the displayed decider/compression boundary to be stated separately.","tags":["multilinear-sumcheck","recursion-ivc"],"title":"Nova: Recursive Zero-Knowledge Arguments from Folding Schemes","type":"paper","venue":"CRYPTO 2022","year":2021,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2021-NOVA"},{"evidence":"fulltext_checked","id":"PROOF-PAPER-2023-BEHEMOTH","metadata":{"authors":["István András Seres","Péter Burcsi"],"contribution_ids":["PROOF-CONTRIB-2023-BEHEMOTH-CONSTANT"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PROOF-PAPER-2023-BEHEMOTH","keywords":["transparent-hash","universal-polynomial"],"lenses":["transparent-hash","universal-polynomial"],"primary_url":"https://eprint.iacr.org/2023/670","status":"published","title":"Behemoth — Transparent Polynomial Commitment Scheme with Constant Opening Proof Size and Verifier Time","venue":"AFRICACRYPT 2025","versions":["IACR ePrint 2023/670","AFRICACRYPT 2025"],"year":2023},"primaryUrl":"https://eprint.iacr.org/2023/670","sections":[{"content":"Section 8.3, printed pp. 30–31, explicitly asks for a transparent, plausibly post-quantum polynomial commitment with constant-size opening proofs and constant-time verification.","heading":"Open-problem locator"}],"status":"published","subtitle":"István András Seres, Péter Burcsi · 2023","summary":"Section 8.3, printed pp. 30–31, explicitly asks for a transparent, plausibly post-quantum polynomial commitment with constant-size opening proofs and constant-time verification.","tags":["transparent-hash","universal-polynomial"],"title":"Behemoth — Transparent Polynomial Commitment Scheme with Constant Opening Proof Size and Verifier Time","type":"paper","venue":"AFRICACRYPT 2025","year":2023,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2023-BEHEMOTH"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2023-HYPERNOVA","metadata":{"authors":["Abhiram Kothapalli","Srinath Setty"],"contribution_ids":["PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2023-HYPERNOVA","keywords":["recursion-ivc","multilinear-sumcheck"],"lenses":["recursion-ivc","multilinear-sumcheck"],"primary_url":"https://eprint.iacr.org/2023/573","status":"published","title":"Recursive Arguments for Customizable Constraint Systems","venue":"CRYPTO 2024","versions":["IACR ePrint 2023/573","CRYPTO 2024"],"year":2023},"primaryUrl":"https://eprint.iacr.org/2023/573","sections":[{"content":"CCS is the arithmetization layer; multi-folding is the composition mechanism; IVC and PCD are tasks realized by the system configuration.","heading":"Boundary note"}],"status":"published","subtitle":"Abhiram Kothapalli, Srinath Setty · 2023","summary":"CCS is the arithmetization layer; multi-folding is the composition mechanism; IVC and PCD are tasks realized by the system configuration.","tags":["multilinear-sumcheck","recursion-ivc"],"title":"Recursive Arguments for Customizable Constraint Systems","type":"paper","venue":"CRYPTO 2024","year":2023,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2023-HYPERNOVA"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2023-JOLT","metadata":{"authors":["Arasu Arun","Srinath Setty","Justin Thaler"],"contribution_ids":["PROOF-CONTRIB-2023-JOLT-LOOKUPVM"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2023-JOLT","keywords":["lookups-zkvm","multilinear-sumcheck"],"lenses":["lookups-zkvm","multilinear-sumcheck"],"primary_url":"https://eprint.iacr.org/2023/1217","status":"published","title":"Jolt: SNARKs for Virtual Machines via Lookups","venue":"IACR ePrint 2023/1217","versions":["IACR ePrint 2023/1217"],"year":2023},"primaryUrl":"https://eprint.iacr.org/2023/1217","sections":[{"content":"The RISC-V-facing VM, lookup argument, R1CS/Spartan component, memory checker, and polynomial commitment are displayed as separate layers.","heading":"Stack note"}],"status":"published","subtitle":"Arasu Arun, Srinath Setty, Justin Thaler · 2023","summary":"The RISC-V-facing VM, lookup argument, R1CS/Spartan component, memory checker, and polynomial commitment are displayed as separate layers.","tags":["lookups-zkvm","multilinear-sumcheck"],"title":"Jolt: SNARKs for Virtual Machines via Lookups","type":"paper","venue":"IACR ePrint 2023/1217","year":2023,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2023-JOLT"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2023-PROTOSTAR","metadata":{"authors":["Benedikt Bünz","Binyi Chen"],"contribution_ids":["PROOF-CONTRIB-2023-PROTOSTAR-GENERIC"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2023-PROTOSTAR","keywords":["recursion-ivc","lookups-zkvm"],"lenses":["recursion-ivc","lookups-zkvm"],"primary_url":"https://eprint.iacr.org/2023/620","status":"published","title":"Protostar: Generic Efficient Accumulation/Folding for Special-Sound Protocols","venue":"ASIACRYPT 2023","versions":["IACR ePrint 2023/620","ASIACRYPT 2023"],"year":2023},"primaryUrl":"https://eprint.iacr.org/2023/620","sections":[{"content":"The generic compiler contribution and the concrete Protostar system configuration are separate objects.","heading":"Boundary note"}],"status":"published","subtitle":"Benedikt Bünz, Binyi Chen · 2023","summary":"The generic compiler contribution and the concrete Protostar system configuration are separate objects.","tags":["lookups-zkvm","recursion-ivc"],"title":"Protostar: Generic Efficient Accumulation/Folding for Special-Sound Protocols","type":"paper","venue":"ASIACRYPT 2023","year":2023,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2023-PROTOSTAR"},{"evidence":"fulltext_checked","id":"PROOF-PAPER-2024-LATTICE-PCS","metadata":{"authors":["Valerio Cini","Giulio Malavolta","Ngoc Khanh Nguyen","Hoeteck Wee"],"contribution_ids":["PROOF-CONTRIB-2024-LATTICE-PCS-PQ"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PROOF-PAPER-2024-LATTICE-PCS","keywords":["transparent-hash","security-audit"],"lenses":["transparent-hash","security-audit"],"primary_url":"https://eprint.iacr.org/2024/281","status":"published","title":"Polynomial Commitments from Lattices — Post-Quantum Security, Fast Verification and Transparent Setup","venue":"CRYPTO 2024","versions":["IACR ePrint 2024/281","CRYPTO 2024"],"year":2024},"primaryUrl":"https://eprint.iacr.org/2024/281","sections":[{"content":"This is a closest result for the post-quantum/transparent/security axes of PROOF-OP-002; it does not meet that card's constant-size and constant-verifier coordinates.","heading":"Comparison note"}],"status":"published","subtitle":"Valerio Cini, Giulio Malavolta, Ngoc Khanh Nguyen et al. · 2024","summary":"This is a closest result for the post-quantum/transparent/security axes of PROOF-OP-002; it does not meet that card's constant-size and constant-verifier coordinates.","tags":["security-audit","transparent-hash"],"title":"Polynomial Commitments from Lattices — Post-Quantum Security, Fast Verification and Transparent Setup","type":"paper","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2024-LATTICE-PCS"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2024-PLONK-KS","metadata":{"authors":["Helger Lipmaa","Roberto Parisella","Janno Siim"],"contribution_ids":["PROOF-CONTRIB-2024-PLONK-KS"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2024-PLONK-KS","keywords":["security-audit","universal-polynomial"],"lenses":["security-audit","universal-polynomial"],"primary_url":"https://eprint.iacr.org/2024/994","status":"published","title":"On Knowledge-Soundness of Plonk in ROM from Falsifiable Assumptions","venue":"IACR ePrint 2024/994","versions":["IACR ePrint 2024/994"],"year":2024},"primaryUrl":"https://eprint.iacr.org/2024/994","sections":[{"content":"Batch-opening optimizations are part of the claim scope, not an implementation footnote.","heading":"Claim-audit note"}],"status":"published","subtitle":"Helger Lipmaa, Roberto Parisella, Janno Siim · 2024","summary":"Batch-opening optimizations are part of the claim scope, not an implementation footnote.","tags":["security-audit","universal-polynomial"],"title":"On Knowledge-Soundness of Plonk in ROM from Falsifiable Assumptions","type":"paper","venue":"IACR ePrint 2024/994","year":2024,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2024-PLONK-KS"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2024-REALWORLD-SE","metadata":{"authors":["Antonio Faonio","Dario Fiore","Luigi Russo"],"contribution_ids":["PROOF-CONTRIB-2024-REALWORLD-SE"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2024-REALWORLD-SE","keywords":["security-audit","universal-polynomial"],"lenses":["security-audit","universal-polynomial"],"primary_url":"https://eprint.iacr.org/2024/721","status":"published","title":"Real-world Universal zkSNARKs are Non-malleable","venue":"ACM CCS 2024","versions":["IACR ePrint 2024/721","ACM CCS 2024"],"year":2024},"primaryUrl":"https://eprint.iacr.org/2024/721","sections":[{"content":"This record demonstrates why security claims attach to exact configurations and optimization sets, not to a family name alone.","heading":"Claim-audit note"}],"status":"published","subtitle":"Antonio Faonio, Dario Fiore, Luigi Russo · 2024","summary":"This record demonstrates why security claims attach to exact configurations and optimization sets, not to a family name alone.","tags":["security-audit","universal-polynomial"],"title":"Real-world Universal zkSNARKs are Non-malleable","type":"paper","venue":"ACM CCS 2024","year":2024,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2024-REALWORLD-SE"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2024-WHIR","metadata":{"authors":["Gal Arnon","Alessandro Chiesa","Giacomo Fenzi","Eylon Yogev"],"contribution_ids":["PROOF-CONTRIB-2024-WHIR-PROXIMITY"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2024-WHIR","keywords":["transparent-hash","multilinear-sumcheck"],"lenses":["transparent-hash","multilinear-sumcheck"],"primary_url":"https://eprint.iacr.org/2024/1586","status":"published","title":"WHIR: Reed–Solomon Proximity Testing with Super-Fast Verification","venue":"EUROCRYPT 2025","versions":["IACR ePrint 2024/1586","EUROCRYPT 2025"],"year":2024},"primaryUrl":"https://eprint.iacr.org/2024/1586","sections":[{"content":"WHIR is promoted as a backend/protocol gateway, not as a drop-in performance winner across unmatched fields, rates, soundness settings, or hardware.","heading":"Evidence boundary"}],"status":"published","subtitle":"Gal Arnon, Alessandro Chiesa, Giacomo Fenzi et al. · 2024","summary":"WHIR is promoted as a backend/protocol gateway, not as a drop-in performance winner across unmatched fields, rates, soundness settings, or hardware.","tags":["multilinear-sumcheck","transparent-hash"],"title":"WHIR: Reed–Solomon Proximity Testing with Super-Fast Verification","type":"paper","venue":"EUROCRYPT 2025","year":2024,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2024-WHIR"},{"evidence":"fulltext_checked","id":"PROOF-PAPER-2025-BOOSTING-SNARKS","metadata":{"authors":["Jiaqi Cheng","Rishab Goyal"],"contribution_ids":["PROOF-CONTRIB-2025-BOOSTING-SNARKS"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PROOF-PAPER-2025-BOOSTING-SNARKS","keywords":["foundations","security-audit"],"lenses":["foundations","security-audit"],"primary_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ICALP.2025.56","status":"published","title":"Boosting SNARKs and Rate-1 Barrier in Arguments of Knowledge","venue":"ICALP 2025","versions":["LIPIcs ICALP 2025 Article 56"],"year":2025},"primaryUrl":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ICALP.2025.56","sections":[{"content":"The introduction calls SNARGs for all NP in the standard model from standard, falsifiable assumptions a longstanding open problem and notes that audited positive results cover only subclasses of NP.","heading":"Frontier locator"}],"status":"published","subtitle":"Jiaqi Cheng, Rishab Goyal · 2025","summary":"The introduction calls SNARGs for all NP in the standard model from standard, falsifiable assumptions a longstanding open problem and notes that audited positive results cover only subclasses of NP.","tags":["foundations","security-audit"],"title":"Boosting SNARKs and Rate-1 Barrier in Arguments of Knowledge","type":"paper","venue":"ICALP 2025","year":2025,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2025-BOOSTING-SNARKS"},{"evidence":"abstract_checked","id":"PROOF-PAPER-2025-GALOIS","metadata":{"authors":["Yuanju Wei","Xinxuan Zhang","Yi Deng"],"contribution_ids":["PROOF-CONTRIB-2025-GALOIS-RINGS"],"dossier_type":"paper","evidence":"abstract_checked","id":"PROOF-PAPER-2025-GALOIS","keywords":["transparent-hash","multilinear-sumcheck"],"lenses":["transparent-hash","multilinear-sumcheck"],"primary_url":"https://eprint.iacr.org/2025/263","status":"published","title":"Transparent SNARKs over Galois Rings","venue":"PKC 2025","versions":["IACR ePrint 2025/263","PKC 2025"],"year":2025},"primaryUrl":"https://eprint.iacr.org/2025/263","sections":[],"status":"published","subtitle":"Yuanju Wei, Xinxuan Zhang, Yi Deng · 2025","summary":"The result is retained as a recent catalog item. It is not promoted into the default comparison until its algebraic and security coordinates receive a full claim audit.","tags":["multilinear-sumcheck","transparent-hash"],"title":"Transparent SNARKs over Galois Rings","type":"paper","venue":"PKC 2025","year":2025,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2025-GALOIS"},{"evidence":"fulltext_checked","id":"PROOF-PAPER-2025-IBCS-QUANTUM","metadata":{"authors":["Alessandro Chiesa","Marcel Dall’Agnol","Zijing Di","Ziyi Guan","Nicholas Spooner"],"contribution_ids":["PROOF-CONTRIB-2025-IBCS-QUANTUM"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PROOF-PAPER-2025-IBCS-QUANTUM","keywords":["security-audit","transparent-hash"],"lenses":["security-audit","transparent-hash"],"primary_url":"https://eprint.iacr.org/2025/947","status":"published","title":"Quantum Rewinding for IOP-Based Succinct Arguments","venue":"TCC 2025","versions":["IACR ePrint 2025/947","TCC 2025"],"year":2025},"primaryUrl":"https://eprint.iacr.org/2025/947","sections":[{"content":"The Open problems paragraph in Section 1.1, printed pp. 4–5, states that stronger extraction remains open and identifies state-preserving extraction as especially important in the quantum setting.","heading":"Open-problem locator"}],"status":"published","subtitle":"Alessandro Chiesa, Marcel Dall’Agnol, Zijing Di et al. · 2025","summary":"The Open problems paragraph in Section 1.1, printed pp. 4–5, states that stronger extraction remains open and identifies state-preserving extraction as especially important in the quantum setting.","tags":["security-audit","transparent-hash"],"title":"Quantum Rewinding for IOP-Based Succinct Arguments","type":"paper","venue":"TCC 2025","year":2025,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2025-IBCS-QUANTUM"},{"evidence":"primary_source_checked","id":"PROOF-PAPER-2025-JOLT-SPACE","metadata":{"authors":["Vineet Nair","Justin Thaler","Michael Zhu"],"contribution_ids":["PROOF-CONTRIB-2025-JOLT-SPACE"],"dossier_type":"paper","evidence":"primary_source_checked","id":"PROOF-PAPER-2025-JOLT-SPACE","keywords":["lookups-zkvm"],"lenses":["lookups-zkvm"],"primary_url":"https://eprint.iacr.org/2025/611","status":"published","title":"Proving CPU Executions in Small Space","venue":"IACR ePrint 2025/611","versions":["IACR ePrint 2025/611"],"year":2025},"primaryUrl":"https://eprint.iacr.org/2025/611","sections":[{"content":"This is an algorithmic prover-space contribution. It is not stored as a benchmark ranking or a new proof-system family.","heading":"Evidence boundary"}],"status":"published","subtitle":"Vineet Nair, Justin Thaler, Michael Zhu · 2025","summary":"This is an algorithmic prover-space contribution. It is not stored as a benchmark ranking or a new proof-system family.","tags":["lookups-zkvm"],"title":"Proving CPU Executions in Small Space","type":"paper","venue":"IACR ePrint 2025/611","year":2025,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2025-JOLT-SPACE"},{"evidence":"fulltext_checked","id":"PROOF-PAPER-2026-SNARG-UNPROVABILITY","metadata":{"authors":["Yao-Ching Hsieh","Abhishek Jain","Jiatu Li","Surya Mathialagan"],"contribution_ids":["PROOF-CONTRIB-2026-SNARG-UNPROVABILITY"],"dossier_type":"paper","evidence":"fulltext_checked","id":"PROOF-PAPER-2026-SNARG-UNPROVABILITY","keywords":["foundations","security-audit"],"lenses":["foundations","security-audit"],"primary_url":"https://eccc.weizmann.ac.il/report/2026/098/","status":"preprint","title":"SNARGs for NP from Unprovability of Mathematical Theorems","venue":"ECCC TR26-098","versions":["ECCC TR26-098"],"year":2026},"primaryUrl":"https://eccc.weizmann.ac.il/report/2026/098/","sections":[{"content":"This 2026 result closes the bare “any SNARG for all NP” formulation under its stated new assumption. It does not close PROOF-OP-001, whose remaining coordinates require adaptive soundness and assumptions confined to standard falsifiable cryptographic families.","heading":"Residual note"}],"status":"preprint","subtitle":"Yao-Ching Hsieh, Abhishek Jain, Jiatu Li et al. · 2026","summary":"This 2026 result closes the bare “any SNARG for all NP” formulation under its stated new assumption. It does not close PROOF-OP-001, whose remaining coordinates require adaptive soundness and assumptions confined to standard falsifiable cryptographic families.","tags":["foundations","security-audit"],"title":"SNARGs for NP from Unprovability of Mathematical Theorems","type":"paper","venue":"ECCC TR26-098","year":2026,"sourcePath":"data/proof-systems-catalog.json#PROOF-PAPER-2026-SNARG-UNPROVABILITY"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-1986-FS-COMPILER","metadata":{"claim_slug":"fs-compiler","contribution_kind":"transform","contribution_role":"compiler","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"interaction_change":["interactive-to-noninteractive"],"mechanism":["fiat-shamir"],"proof_model":["hash-model-dependent"]},"historical_context":{"narrative":"Public-coin identification protocols relied on an online verifier to choose an unpredictable challenge after seeing the prover's first message. Fiat and Shamir replaced that sampled challenge with a hash of the statement and commitment, producing a transcript that can be generated and checked without further interaction. The atomic contribution is the compilation pattern, not a claim that every public-coin proof is secure after hashing. At publication it supplied a remarkably simple route from identification protocols to signatures and non-interactive proofs, while leaving the exact security theorem dependent on the protocol and the model used for the hash function.","prior_boundary":"Identification protocols obtained soundness through an online verifier challenge, so a prover could not publish one transcript for later verification without additional setup or interaction.","significance_at_publication":"The transform supplied a simple bridge from interactive identification to publicly checkable transcripts, while leaving its security dependent on how the hash function is modeled.","technical_delta":"Fiat and Shamir derive the public-coin challenge by hashing the statement and first prover message, turning the three-move identification pattern into a non-interactive proof or signature heuristic."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-1986-FS-COMPILER","keywords":["fiat-shamir","compiler","public-coin","non-interactive"],"lens":"foundations","limitations":["does not give a standard-model compiler for arbitrary interactive proofs","security does not follow from syntax alone"],"paper_id":"PROOF-PAPER-1986-FS","qualifiers":["public-coin three-move protocol","hash-derived challenge","heuristic or ROM-dependent security"],"research_lenses":["foundations"],"role":"compiler","source_locator":{"dossier_section":"PROOF-PAPER-1986-FS § Protocol transformation","primary_source":"CRYPTO 1986 paper, identification-to-signature transformation","primary_source_url":"https://doi.org/10.1007/3-540-47721-7_12","status":"primary_source_checked"},"statement":"The Fiat–Shamir transform replaces a verifier-sampled public-coin challenge with a hash of the statement and commitment, yielding the foundational non-interactive compilation pattern for identification protocols.","statement_status":"source_normalized_statement","status":"published","title":"Hash-derived challenges compile public-coin identification into non-interactive proofs","visibility":"backbone","work_id":"PROOF-PAPER-1986-FS","year":1986},"primaryUrl":"https://doi.org/10.1007/3-540-47721-7_12","sections":[{"content":"Fiat–Shamir compilation This card records the transform as an atomic mechanism; concrete instantiations require their own security claims.","heading":"Overview"}],"status":"published","subtitle":"How to Prove Yourself: Practical Solutions to Identification and Signature Problems","summary":"The Fiat–Shamir transform replaces a verifier-sampled public-coin challenge with a hash of the statement and commitment, yielding the foundational non-interactive compilation pattern for identification protocols.","tags":["atomic-result","backbone","compiler","foundations"],"title":"Hash-derived challenges compile public-coin identification into non-interactive proofs","type":"result","venue":"CRYPTO 1986","year":1986,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-1986-FS-COMPILER"},{"evidence":"fulltext_checked","id":"PROOF-CONTRIB-1988-BFM-NIZK-MODEL","metadata":{"claim_slug":"shared-random-string-nizk-model","contribution_kind":"definition","contribution_role":"definition","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"interaction":["non-interactive"],"property":["zero-knowledge"],"research_layer":["security-definition"],"setup":["shared-random-string"]},"historical_context":{"narrative":"Earlier simulation-based zero knowledge was formulated around an exchange between prover and verifier. Blum, Feldman, and Micali instead gave both parties a common random string and defined what it means for a written proof to be convincing without further verifier messages. Simulation must reproduce the joint distribution of the public string and proof, not merely hide the witness inside a transcript. This separated non-interactive zero knowledge as a model from the constructions intended to realize it. The paper also distinguished a single-theorem contract from a many-theorem target; whether one reference string can safely support repeated proofs is an additional requirement, not an automatic consequence of removing interaction.","prior_boundary":"Simulation-based zero knowledge had been formulated for interactive proofs, in which the prover and verifier exchange messages.","significance_at_publication":"The model made non-interactive zero knowledge a distinct research target while exposing reference-string reuse as a separate condition that constructions must satisfy.","technical_delta":"A common random string replaces verifier interaction as a model resource, and the simulation target includes that public string together with the written proof."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-1988-BFM-NIZK-MODEL","keywords":["non-interactive-zero-knowledge","shared-random-string","simulation","definition"],"lens":"foundations","limitations":["FLS90 §1.1 footnote 1, printed p. 308 / PDF p. 1 (https://doi.org/10.1109/FSCS.1990.89549), reports that BFM88's proposed method for overcoming reference-string reuse was found flawed; no reusable-construction result is admitted from BFM88 §4 here.","The model definition does not imply adaptive-statement security, simulation soundness, extractability, succinctness, or an efficient witness-equipped prover.","The single-theorem QRA construction and informal chosen-ciphertext application are separate claims, not part of this definition atom.","Full-text review of this ten-page extended abstract is not independent verification of its construction proofs or a substitute for another paper's corrected result."],"paper_id":"PROOF-PAPER-1988-BFM","qualifiers":["The shared string is uniformly random and visible to both parties; this is not the plain model without a shared setup resource.","Definition 3.1 fixes the statement before the reference string is sampled and targets the joint string-and-proof distribution.","Definition 2.2 uses expected polynomial-time simulation, while Definition 3.1 requires a polynomial-time verifier but does not require a polynomial-time witness-equipped prover.","Definition 4.1 separately formulates a many-theorem target with one initialization proof; recording that definition does not validate the proposed reusable construction."],"research_lenses":["foundations"],"role":"definition","source_locator":{"dossier_section":"PROOF-PAPER-1988-BFM § Definition and construction boundaries","primary_source":"STOC 1988 extended abstract: §1.1, printed p. 104 / PDF p. 2; Definition 2.2, printed p. 105 / PDF p. 3; Definition 3.1 and following verifier-view remark, printed p. 106 / PDF p. 4; §4 and Definition 4.1, printed pp. 108–109 / PDF pp. 6–7, for the distinct many-theorem target only.","primary_source_url":"https://doi.org/10.1145/62212.62222","status":"section_checked"},"statement":"Blum, Feldman, and Micali formalize non-interactive zero knowledge in a model where prover and verifier share a uniformly random string and a written proof is checked without further verifier messages. Their single-theorem definition requires completeness, soundness, and computational simulation of the joint reference-string and proof distribution from the statement.","statement_status":"source_normalized_statement","status":"published","title":"Shared-random-string model for non-interactive zero knowledge","visibility":"catalog_only","work_id":"PROOF-PAPER-1988-BFM","year":1988},"primaryUrl":"https://doi.org/10.1145/62212.62222","sections":[{"content":"Shared-random-string non-interactive zero knowledge The atom is the model and simulation contract, not the entire BFM88 paper. Definition 3.1 (printed p. 106, PDF p. 4) handles a single statement; §4 and Definition 4.1 (printed pp. 108–109, PDF pp. 6–7) separately describe a many-theorem goal whose proofs share an initialization. These distinctions prevent both calling the paper exclusively single-theorem and treating its advertised reuse construction as an established result. The warning about reusing the single-theorem construction appears at the end of §3.2 (printed p. 108, PDF p. 6). The later report of a flaw in BFM88's proposed workaround is FLS90, §1.1 footnote 1 (printed p. 308, PDF p. 1). That report is a source-backed limitation, not a reconstruction of the attack or an attribution of BDMP91's results to BFM88.","heading":"Overview"}],"status":"published","subtitle":"Non-Interactive Zero-Knowledge and Its Applications (Extended Abstract)","summary":"Blum, Feldman, and Micali formalize non-interactive zero knowledge in a model where prover and verifier share a uniformly random string and a written proof is checked without further verifier messages. Their single-theorem definition requires completeness, soundness, and computational simulation of the joint reference-string and proof distribution from the statement.","tags":["atomic-result","catalog_only","definition","foundations"],"title":"Shared-random-string model for non-interactive zero knowledge","type":"result","venue":"STOC 1988, 103–112","year":1988,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-1988-BFM-NIZK-MODEL"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-1989-GMR-ZK","metadata":{"claim_slug":"gmr-zk","contribution_kind":"definition","contribution_role":"definition","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"interaction":["interactive"],"property":["zero-knowledge"],"research_layer":["security-definition"]},"historical_context":{"narrative":"Interactive proofs already explained how a prover could convince a verifier, but they lacked a precise contract for what the verifier learned during that interaction. Goldwasser, Micali, and Rackoff introduced knowledge complexity and used simulation to define the zero-knowledge boundary: the verifier's view should be reproducible without the witness, apart from what follows from the statement's validity. The contribution is a security definition and methodology rather than one complete modern proof stack. It mattered because privacy became an auditable property distinct from completeness and soundness, allowing later constructions, compilers, and implementations to state exactly which zero-knowledge notion they claim.","prior_boundary":"Interactive proofs had been studied for their power and soundness, but there was no simulation-based contract for saying that a convincing interaction disclosed nothing beyond validity.","significance_at_publication":"It made privacy of proofs a formal property separable from completeness and soundness and created the security interface against which later proof systems could be analyzed.","technical_delta":"The paper defines knowledge complexity through simulation and isolates zero knowledge as the limiting case in which the verifier's view can be generated without access to the witness."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-1989-GMR-ZK","keywords":["zero-knowledge","knowledge-complexity","simulation","definition"],"lens":"foundations","limitations":["the definition is not itself a succinct or non-interactive construction","later notions refine verifier and auxiliary-input models"],"paper_id":"PROOF-PAPER-1989-GMR","qualifiers":["interactive proofs","simulation-based privacy","verifier-view formulation"],"research_lenses":["foundations"],"role":"definition","source_locator":{"dossier_section":"PROOF-PAPER-1989-GMR § Knowledge complexity","primary_source":"Abstract and Sections 1–2","primary_source_url":"https://doi.org/10.1137/0218012","status":"primary_source_checked"},"statement":"Goldwasser, Micali, and Rackoff formalize knowledge complexity for interactive proofs and identify zero knowledge as the case where interaction conveys no additional efficiently usable knowledge beyond validity.","statement_status":"source_normalized_statement","status":"published","title":"Zero knowledge formalized as revealing no knowledge beyond statement validity","visibility":"backbone","work_id":"PROOF-PAPER-1989-GMR","year":1989},"primaryUrl":"https://doi.org/10.1137/0218012","sections":[{"content":"Zero-knowledge definition This card treats the formal privacy contract separately from the systems later built to satisfy it.","heading":"Overview"}],"status":"published","subtitle":"The Knowledge Complexity of Interactive Proof Systems","summary":"Goldwasser, Micali, and Rackoff formalize knowledge complexity for interactive proofs and identify zero knowledge as the case where interaction conveys no additional efficiently usable knowledge beyond validity.","tags":["atomic-result","backbone","definition","foundations"],"title":"Zero knowledge formalized as revealing no knowledge beyond statement validity","type":"result","venue":"SIAM Journal on Computing 18(1), 186–208","year":1989,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-1989-GMR-ZK"},{"evidence":"fulltext_checked","id":"PROOF-CONTRIB-1990-FLS-MULTI-THEOREM","metadata":{"claim_slug":"fls-efficient-prover-single-to-many-nizk","contribution_kind":"transform","contribution_role":"compiler","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"capability":["zero knowledge"],"interaction":["non-interactive"],"privacy":["computational ZK"],"soundness":["conditional"]},"historical_context":{"narrative":"A NIZK guarantee for one statement did not automatically permit reuse of its random reference string, and earlier reuse did not give independent provers the same capability. Feige, Lapidot, and Shamir turn a suitable bounded NIZK into a system for polynomially many proofs by independent provers. They add an alternative witness: a seed whose pseudorandom output matches a reference statement. The simulator knows that seed, and witness indistinguishability hides its substitution for each real witness. This separates the reuse mechanism from a particular number-theoretic construction, while retaining an efficient-prover bounded base and a one-way-function assumption. Adaptive statement selection needs the separately stated adaptive-base condition; multiple proofs do not imply aggregation or succinctness.","prior_boundary":"A bounded NIZK guarantee for one statement did not by itself justify reusing the same reference string for many proofs; the prior single-prover reuse result did not give independently operating provers the same capability.","significance_at_publication":"Reuse of one random reference string across independent efficient provers became a generic transformation of a suitable bounded base, without fixing the transformation to a particular number-theoretic construction.","technical_delta":"The transformation adds a reference statement about membership in a pseudorandom generator's image and proves an OR statement through the bounded base; the simulator knows the generator seed, while witness indistinguishability hides its use across polynomially many proofs."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-1990-FLS-MULTI-THEOREM","keywords":["nizk","multiple-theorem","shared-random-string","witness-indistinguishability","simulation-transform"],"lens":"foundations","limitations":["One-way functions alone are not claimed to construct the required bounded NIZK for NP; the transformation preserves rather than removes that premise.","The ordinary bounded-base guarantee is not automatically adaptive zero knowledge; statement selection after seeing the reference string requires the separately qualified adaptive base.","The admitted result covers polynomially many proofs of polynomial-length statements within the base protocol's supported statement bounds. The unbounded-size remark in §3.3 omits details and is not promoted into this claim.","Reuse of a reference string is not proof aggregation, recursion, succinct proof size, low verifier cost, knowledge extraction, or simulation extractability.","This is a source check of the 1990 extended abstract, which contains proof sketches and omitted details, not an independent verification of its theorems or a review of the 1999 journal version."],"paper_id":"PROOF-PAPER-1990-FLS","qualifiers":["The base is a bounded NIZK for an NP-complete language with a polynomial-time prover given a witness; §3.1 explicitly excludes bases that require an exponential-time prover.","The added cryptographic premise is a generator stretching an n-bit seed to 2n pseudorandom bits, secure against nonuniform polynomial-time distinguishers, obtained from one-way functions; this premise does not supply the required base NIZK by itself.","A publicly known witness-preserving reduction maps the disjunction of the original statement and the reference string's PRG-image statement into the base NP-complete language.","In the real execution the added 2n-bit reference statement is uniform and lies in the generator image with probability at most 2^-n; simulation instead uses a pseudorandom statement with a known seed and one independently sampled base reference string shared by all simulated proofs.","Definition 3.7 covers polynomial sequences of statements fixed independently of the reference string; the efficient public prover algorithm permits polynomially many provers to act independently with their own witnesses.","Theorem 4.20 gives the adaptive extension only from a single-statement adaptive NIZK base. Its adaptive definitions use nonuniform polynomial-time adversaries, not an admitted unrestricted adaptive soundness guarantee."],"research_lenses":["foundations"],"role":"compiler","source_locator":{"dossier_section":"PROOF-PAPER-1990-FLS § Atomic contributions","primary_source":"FOCS 1990 extended abstract: §3.1 and Definition 3.7, PDF p. 5 (printed p. 312); §3.2, Lemmas 3.9 and 3.11, and §3.3, Theorem 3.12 and proof, PDF pp. 6–7 (printed pp. 313–314); adaptive scope in §4.1, Definitions 4.14 and 4.16, and §4.2, Theorem 4.20, PDF pp. 8–9 (printed pp. 315–316); historical comparison in §1.1 and footnote 1, PDF p. 1 (printed p. 308)","primary_source_url":"https://doi.org/10.1109/FSCS.1990.89549","status":"section_checked"},"statement":"Given a bounded NIZK proof system for an NP-complete language whose prover runs in polynomial time with a witness, and a pseudorandom generator obtained from one-way functions, the FLS transformation supports polynomially many independent provers proving polynomially many polynomial-length statements using one shared random reference string, with joint computational zero knowledge for the nonadaptive statement sequences of Definition 3.7.","statement_status":"source_normalized_statement","status":"published","title":"Single-to-many NIZK with a shared random reference string","visibility":"catalog_only","work_id":"PROOF-PAPER-1990-FLS","year":1990},"primaryUrl":"https://doi.org/10.1109/FSCS.1990.89549","sections":[{"content":"Single-to-many NIZK with one random reference string Section 3.3 splits the reference string into a uniform 2n-bit statement y and the reference string for the base protocol. Each real prover proves the disjunction that its input is in the language or that y has a generator seed. The real prover uses its original witness. The simulator replaces y by a generator output, knows a seed, and can use that same alternative witness for each simulated proof. The proof combines generator indistinguishability with the bounded-to-multiple witness-indistinguishability argument of §3.2. This card treats the mechanism and its stated conditional adaptive extension as one transform, not as separate automatic claims about every NIZK. Theorem 3.12 supplies the main nonadaptive result; Theorem 4.20 is read together with its single-statement adaptive premise and the precise §4.1 adversary model. Neither the shared setup nor the presence of many proofs supplies a configuration-level succinctness, extraction, or composition guarantee.","heading":"Overview"}],"status":"published","subtitle":"Multiple Non-Interactive Zero Knowledge Proofs Based on a Single Random String (Extended Abstract)","summary":"Given a bounded NIZK proof system for an NP-complete language whose prover runs in polynomial time with a witness, and a pseudorandom generator obtained from one-way functions, the FLS transformation supports polynomially many independent provers proving polynomially many polynomial-length statements using one shared random reference string, with joint computational zero knowledge for the nonadaptive statement sequences of Definition 3.7.","tags":["atomic-result","catalog_only","compiler","foundations"],"title":"Single-to-many NIZK with a shared random reference string","type":"result","venue":"FOCS 1990, 308–317","year":1990,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-1990-FLS-MULTI-THEOREM"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT","metadata":{"claim_slug":"kilian-pcp-commit","contribution_kind":"transform","contribution_role":"construction_method","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["commit-and-open"],"source_object":["pcp"],"target_object":["succinct-argument"]},"historical_context":{"narrative":"Probabilistically checkable proofs showed that a verifier could inspect very few locations of a long encoded proof, but they did not by themselves force a remote prover to answer those locations consistently. Kilian's construction commits to the encoded proof and opens only the verifier's requested positions, thereby converting local PCP verification into a communication-efficient computational argument. The contribution is this authenticated-oracle compilation step, not a claim that prover work or setup disappears. It mattered because it separated the verifier's succinct access pattern from the prover's large proof object and established a durable blueprint for later commitment-backed succinct arguments.","prior_boundary":"PCP-style verification could inspect only a few proof locations, but a remote prover still needed to bind itself consistently to the full proof oracle across adaptive queries.","significance_at_publication":"It established the commitment-to-oracle-proof blueprint underlying later succinct arguments, while retaining computational soundness and the costs of generating the encoded proof.","technical_delta":"The construction commits to the PCP oracle and opens only the verifier-requested locations, converting local PCP checking into a cryptographic argument with small communication."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT","keywords":["pcp","commitment","succinct-argument","compiler"],"lens":"foundations","limitations":["does not imply a transparent or post-quantum instantiation","succinct verifier communication does not bound prover work"],"paper_id":"PROOF-PAPER-1992-KILIAN","qualifiers":["PCP oracle access","cryptographic commitment","computational soundness"],"research_lenses":["foundations"],"role":"construction_method","source_locator":{"dossier_section":"PROOF-PAPER-1992-KILIAN § Main construction","primary_source":"Main construction and theorem","primary_source_url":"https://doi.org/10.1145/129712.129782","status":"theorem_checked"},"statement":"Kilian compiles probabilistically checkable proof access through cryptographic commitments so that a verifier queries only authenticated PCP locations, obtaining communication-efficient computational arguments.","statement_status":"source_normalized_statement","status":"published","title":"Commitment-authenticated PCP access yields communication-efficient arguments","visibility":"backbone","work_id":"PROOF-PAPER-1992-KILIAN","year":1992},"primaryUrl":"https://doi.org/10.1145/129712.129782","sections":[{"content":"PCP access through commitments The claim concerns the compilation architecture and retains its computational-soundness boundary.","heading":"Overview"}],"status":"published","subtitle":"A Note on Efficient Zero-Knowledge Proofs and Arguments","summary":"Kilian compiles probabilistically checkable proof access through cryptographic commitments so that a verifier queries only authenticated PCP locations, obtaining communication-efficient computational arguments.","tags":["atomic-result","backbone","construction_method","foundations"],"title":"Commitment-authenticated PCP access yields communication-efficient arguments","type":"result","venue":"STOC 1992","year":1992,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-1992-LFKN-SUMCHECK","metadata":{"claim_slug":"lfkn-sumcheck","contribution_kind":"mechanism","contribution_role":"protocol","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"claim_reduction":["sum-to-evaluation"],"interaction":["interactive"],"mechanism":["sum-check"]},"historical_context":{"narrative":"Algebraic interactive proofs required a way to certify a sum over an exponentially large product domain without asking the verifier to enumerate all points. The sum-check protocol reduces that claim one variable at a time: the prover sends a univariate polynomial, the verifier checks consistency and samples a fresh field point, and the interaction ends at one evaluation claim. The atomic contribution is this low-degree reduction, not a complete non-interactive proof system or a polynomial commitment. It mattered because later arithmetizations could delegate large structured sums to one reusable protocol and then supply the final evaluation through a separate commitment or oracle backend.","prior_boundary":"Algebraic interactive proofs needed a reusable way to verify exponentially large structured sums without the verifier evaluating every summand.","significance_at_publication":"It provided a compact algebraic reduction that later systems could compose with arithmetizations and commitments rather than rechecking an entire computation directly.","technical_delta":"Sum-check eliminates one variable per round through prover-supplied univariate polynomials and random verifier challenges, ending at a single evaluation whose consistency controls soundness."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-1992-LFKN-SUMCHECK","keywords":["sum-check","low-degree","interactive-proof","multilinear"],"lens":"multilinear-sumcheck","limitations":["requires a separately justified final evaluation","soundness depends on degree and field size"],"paper_id":"PROOF-PAPER-1992-LFKN","qualifiers":["low-degree polynomial","product-domain sum","interactive public coins"],"research_lenses":["multilinear-sumcheck"],"role":"protocol","source_locator":{"dossier_section":"PROOF-PAPER-1992-LFKN § Algebraic protocol","primary_source":"Algebraic protocol sections; sum-check reduction","primary_source_url":"https://doi.org/10.1145/146585.146605","status":"primary_source_checked"},"statement":"The algebraic protocol now isolated as sum-check verifies a claimed sum of a low-degree multivariate polynomial over a product domain by reducing it round by round to one polynomial evaluation.","statement_status":"source_normalized_statement","status":"published","title":"Sum-check reduces a multivariate polynomial sum to one evaluation claim","visibility":"backbone","work_id":"PROOF-PAPER-1992-LFKN","year":1992},"primaryUrl":"https://doi.org/10.1145/146585.146605","sections":[{"content":"Sum-check protocol The record isolates the reusable reduction from systems that later instantiate its evaluation oracle.","heading":"Overview"}],"status":"published","subtitle":"Algebraic Methods for Interactive Proof Systems","summary":"The algebraic protocol now isolated as sum-check verifies a claimed sum of a low-degree multivariate polynomial over a product domain by reducing it round by round to one polynomial evaluation.","tags":["atomic-result","backbone","multilinear-sumcheck","protocol"],"title":"Sum-check reduces a multivariate polynomial sum to one evaluation claim","type":"result","venue":"Journal of the ACM 39(4)","year":1992,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-1992-LFKN-SUMCHECK"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2010-KZG-PCS","metadata":{"claim_slug":"kzg-pcs","contribution_kind":"mechanism","contribution_role":"component_construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"component_role":["commitment-backend"],"mechanism":["pairing-quotient-opening"],"setup":["structured"]},"historical_context":{"narrative":"Algebraic proof protocols needed a backend that could bind a high-degree polynomial and later authenticate an evaluation without revealing all of its coefficients. KZG uses structured powers of a hidden point to form the commitment and a quotient polynomial to form an opening that a pairing equation can check. The changed coordinate is the size of the commitment and one evaluation proof, both constant in the degree; it is not a transparent setup claim. This mattered because polynomial protocols could obtain very small proof objects and verifier checks from a reusable component, at the price of a degree-bounded structured reference string and pairing-based assumptions.","prior_boundary":"Commitment-backed algebraic protocols needed a concise way to bind a polynomial and later authenticate evaluations without transmitting the polynomial or a logarithmic opening path.","significance_at_publication":"It turned polynomial evaluation into a succinct reusable backend, while concentrating trust and security obligations in the structured parameters and pairing assumptions.","technical_delta":"KZG encodes polynomial coefficients against powers of a hidden evaluation point and verifies quotient-based openings with a pairing, making commitments and single-point proofs constant size."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2010-KZG-PCS","keywords":["kzg","polynomial-commitment","pairing","constant-opening"],"lens":"universal-polynomial","limitations":["not transparent","not post-quantum","batch-opening security requires configuration-specific analysis"],"paper_id":"PROOF-PAPER-2010-KZG","qualifiers":["bounded-degree univariate polynomial","single-point evaluation","structured public parameters"],"research_lenses":["universal-polynomial"],"role":"component_construction","source_locator":{"dossier_section":"PROOF-PAPER-2010-KZG § Polynomial commitments","primary_source":"Abstract and Section 3","primary_source_url":"https://eprint.iacr.org/2010/009","status":"section_checked"},"statement":"KZG commits to a bounded-degree univariate polynomial and proves one evaluation with constant-size group elements using pairing groups and degree-bounded structured public parameters.","statement_status":"source_normalized_statement","status":"published","title":"Pairing-based polynomial commitments give constant-size single-point openings","visibility":"backbone","work_id":"PROOF-PAPER-2010-KZG","year":2010},"primaryUrl":"https://eprint.iacr.org/2010/009","sections":[{"content":"KZG polynomial commitments The constant-size statement applies to the declared commitment and opening interface, not to an entire proof system.","heading":"Overview"}],"status":"published","subtitle":"Constant-Size Commitments to Polynomials and Their Applications","summary":"KZG commits to a bounded-degree univariate polynomial and proves one evaluation with constant-size group elements using pairing groups and degree-bounded structured public parameters.","tags":["atomic-result","backbone","component_construction","universal-polynomial"],"title":"Pairing-based polynomial commitments give constant-size single-point openings","type":"result","venue":"ASIACRYPT 2010","year":2010,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2010-KZG-PCS"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2016-GROTH-3ELEMENT","metadata":{"claim_slug":"groth-three-element","contribution_kind":"construction","contribution_role":"system_construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"proof_size":["three-group-elements"],"setup":["circuit-specific-structured"],"system_family":["groth16"]},"historical_context":{"narrative":"Pairing-based preprocessing arguments had made circuit proofs succinct, but their concrete proof and verification costs still distinguished competing constructions. Groth's 2016 construction reorganized the QAP relation and proof elements so that an arithmetic-circuit satisfiability proof contains only three group elements and is checked by a small fixed set of pairing equations. The atomic delta is that compression within a circuit-specific preprocessing configuration, not a universal or transparent setup. At publication it provided a strikingly small proof format for general circuit relations and became an important configuration point against which later systems traded setup reuse, transparency, and different prover costs.","prior_boundary":"Pairing-based preprocessing arguments already offered succinct verification, but proof size and pairing checks remained a central cost for deployment-oriented circuit proofs.","significance_at_publication":"It established an exceptionally compact concrete endpoint for pairing-based circuit arguments, while retaining circuit-specific structured setup and pairing assumptions.","technical_delta":"Groth's construction reorganizes the QAP-based argument so that a proof consists of two source-group elements and one target-source-group element with a small fixed pairing verification equation."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2016-GROTH-3ELEMENT","keywords":["groth16","qap","pairing","succinct-proof"],"lens":"pairing-succinct","limitations":["circuit-specific structured setup","not post-quantum","implementation security depends on exact ceremony and curve choices"],"paper_id":"PROOF-PAPER-2016-GROTH","qualifiers":["arithmetic-circuit satisfiability","preprocessing NIZK argument","pairing-based"],"research_lenses":["pairing-succinct"],"role":"system_construction","source_locator":{"dossier_section":"PROOF-PAPER-2016-GROTH § Main construction","primary_source":"Abstract; main construction and efficiency statement","primary_source_url":"https://eprint.iacr.org/2016/260","status":"theorem_checked"},"statement":"Groth16 gives a preprocessing pairing-based non-interactive zero-knowledge argument for arithmetic-circuit satisfiability whose proof in the displayed construction contains three group elements.","statement_status":"source_normalized_statement","status":"published","title":"Arithmetic-circuit NIZK argument compressed to three group elements","visibility":"backbone","work_id":"PROOF-PAPER-2016-GROTH","year":2016},"primaryUrl":"https://eprint.iacr.org/2016/260","sections":[{"content":"Three-element pairing argument The card records the exact proof-size configuration together with its setup boundary.","heading":"Overview"}],"status":"published","subtitle":"On the Size of Pairing-based Non-interactive Arguments","summary":"Groth16 gives a preprocessing pairing-based non-interactive zero-knowledge argument for arithmetic-circuit satisfiability whose proof in the displayed construction contains three group elements.","tags":["atomic-result","backbone","pairing-succinct","system_construction"],"title":"Arithmetic-circuit NIZK argument compressed to three group elements","type":"result","venue":"EUROCRYPT 2016","year":2016,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2016-GROTH-3ELEMENT"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2017-BULLETPROOFS-AGG","metadata":{"claim_slug":"bulletproofs-agg","contribution_kind":"capability_result","contribution_role":"composition","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"setup":["transparent"],"statement_class":["range"],"task":["aggregation"]},"historical_context":{"narrative":"Repeating a range proof independently for every confidential value made total proof data grow with the number of outputs, even though the statements shared the same algebraic structure. Bulletproofs packs those range constraints into one vector relation and applies its inner-product argument to the combined witness, so adding values increases proof size only logarithmically rather than by one full proof each. The contribution changes the aggregation cost for this statement class; it is not recursive proof composition, IVC, or a generic proof accumulator. At publication this was important for transactions containing several hidden amounts because it preserved transparent setup while sharply reducing the marginal proof-size cost.","prior_boundary":"Proving many confidential values lay in range by repeating a proof caused proof data to scale with the number of values even when their verification context was shared.","significance_at_publication":"It made multi-output confidential-transaction proofs substantially more compact without adding trusted setup, while remaining specialized aggregation rather than recursive composition or IVC.","technical_delta":"The paper batches the range constraints into one vector inner-product relation, so the aggregate proof pays logarithmic rather than one-proof-per-value growth."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2017-BULLETPROOFS-AGG","keywords":["bulletproofs","aggregation","range-proof","confidential-transactions"],"lens":"recursion-ivc","limitations":["specialized aggregation rather than generic recursion","verifier work does not become constant"],"paper_id":"PROOF-PAPER-2017-BULLETPROOFS","qualifiers":["range proofs","shared generator context","logarithmic aggregate proof growth"],"research_lenses":["recursion-ivc"],"role":"composition","source_locator":{"dossier_section":"PROOF-PAPER-2017-BULLETPROOFS § Aggregated range proofs","primary_source":"Abstract and aggregated range-proof section","primary_source_url":"https://eprint.iacr.org/2017/1066","status":"section_checked"},"statement":"Bulletproofs aggregates multiple range statements into one proof whose size grows only logarithmically with the number and bit length of the committed values rather than linearly across separate proofs.","statement_status":"source_normalized_statement","status":"published","title":"Multiple range statements aggregate with logarithmic additive proof growth","visibility":"reviewed_related","work_id":"PROOF-PAPER-2017-BULLETPROOFS","year":2017},"primaryUrl":"https://eprint.iacr.org/2017/1066","sections":[{"content":"Aggregated range proofs The atlas keeps this capability result distinct from the paper's reusable inner-product mechanism.","heading":"Overview"}],"status":"published","subtitle":"Bulletproofs: Short Proofs for Confidential Transactions and More","summary":"Bulletproofs aggregates multiple range statements into one proof whose size grows only logarithmically with the number and bit length of the committed values rather than linearly across separate proofs.","tags":["atomic-result","composition","recursion-ivc","reviewed_related"],"title":"Multiple range statements aggregate with logarithmic additive proof growth","type":"result","venue":"IEEE Symposium on Security and Privacy 2018","year":2017,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2017-BULLETPROOFS-AGG"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2017-BULLETPROOFS-IPA","metadata":{"claim_slug":"bulletproofs-ipa","contribution_kind":"mechanism","contribution_role":"protocol","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["inner-product-argument"],"proof_size":["logarithmic"],"setup":["transparent"]},"historical_context":{"narrative":"Short range and arithmetic proofs were often obtained from pairing systems with a structured reference string, while transparent discrete-log alternatives had less attractive proof size. Bulletproofs recursively folds an inner-product relation, halving its vector dimension each round and leaving a logarithmic number of group elements to transmit. The atomic contribution is the no-trusted-setup inner-product argument and its communication bound, not constant-time verification: verifier work remains linear in the underlying dimension. This mattered because confidential-transaction applications gained a compact, transparent proof mechanism with standard discrete-log-style generators and a clearly different setup/performance tradeoff from pairing-based SNARKs.","prior_boundary":"Highly succinct pairing-based range and circuit proofs commonly depended on structured setup, while transparent discrete-log proofs paid larger proof-size costs.","significance_at_publication":"It made short transparent range proofs practical for confidential transactions, while exposing a proof-size versus verifier-work tradeoff different from constant-size pairing systems.","technical_delta":"The recursive inner-product argument halves vector dimension each round, producing logarithmic communication from standard generator vectors and Pedersen-style commitments without a trapdoor ceremony."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2017-BULLETPROOFS-IPA","keywords":["bulletproofs","inner-product-argument","transparent","logarithmic-proof"],"lens":"transparent-hash","limitations":["verifier work is linear in witness dimension","not a general constant-size SNARK"],"paper_id":"PROOF-PAPER-2017-BULLETPROOFS","qualifiers":["discrete-log setting","logarithmic communication","transparent generators"],"research_lenses":["transparent-hash"],"role":"protocol","source_locator":{"dossier_section":"PROOF-PAPER-2017-BULLETPROOFS § Inner-product argument","primary_source":"Abstract and Sections 2–4","primary_source_url":"https://eprint.iacr.org/2017/1066","status":"section_checked"},"statement":"Bulletproofs constructs logarithmic-size proofs from a discrete-log inner-product argument and Pedersen-style commitments without a trusted setup, with verification work that remains linear in the witness dimension.","statement_status":"source_normalized_statement","status":"published","title":"Discrete-log inner-product argument gives logarithmic proofs without trusted setup","visibility":"backbone","work_id":"PROOF-PAPER-2017-BULLETPROOFS","year":2017},"primaryUrl":"https://eprint.iacr.org/2017/1066","sections":[{"content":"Bulletproofs inner-product argument This contribution is separated from the same paper's aggregation result.","heading":"Overview"}],"status":"published","subtitle":"Bulletproofs: Short Proofs for Confidential Transactions and More","summary":"Bulletproofs constructs logarithmic-size proofs from a discrete-log inner-product argument and Pedersen-style commitments without a trusted setup, with verification work that remains linear in the witness dimension.","tags":["atomic-result","backbone","protocol","transparent-hash"],"title":"Discrete-log inner-product argument gives logarithmic proofs without trusted setup","type":"result","venue":"IEEE Symposium on Security and Privacy 2018","year":2017,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2017-BULLETPROOFS-IPA"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2018-STARK-SYSTEM","metadata":{"claim_slug":"stark-system","contribution_kind":"construction","contribution_role":"system_construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"backend":["coded-oracle-hash"],"representation":["air"],"setup":["transparent"],"system_family":["stark"]},"historical_context":{"narrative":"General-purpose succinct arguments were strongly associated with structured algebraic setup, while transparent PCP-style ideas had not yet been assembled into the same kind of scalable end-to-end architecture. STARKs express execution through AIR constraints, test encoded oracle tables with algebraic IOP and proximity machinery, and authenticate those tables with hashes. The atomic contribution is the integrated transparent proof architecture, not one isolated FRI component or a claim of constant proof size. It mattered because it made setup transparency and a hash-based, post-quantum-oriented security story central design coordinates for scalable computational integrity, while accepting a different proof-size and concrete-performance profile from pairing systems.","prior_boundary":"Succinct general-purpose arguments commonly relied on structured algebraic setup, while PCP-based transparent approaches had not yet been presented as an integrated scalable implementation stack with the same deployment emphasis.","significance_at_publication":"The work established a concrete transparent and post-quantum-oriented systems line, with larger proof objects but a scalable prover/verifier architecture and an implementation.","technical_delta":"STARKs encode execution as AIR, use coded-oracle proximity and consistency tests, and commit to oracle tables with hashes, avoiding a secret setup and relying on hash-oriented assumptions."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2018-STARK-SYSTEM","keywords":["stark","air","transparent","coded-oracle","post-quantum"],"lens":"transparent-hash","limitations":["proofs are not constant size","exact post-quantum claim depends on hash and protocol analysis"],"paper_id":"PROOF-PAPER-2018-STARK","qualifiers":["AIR computation model","hash-authenticated coded oracles","demonstrated sublinear verification"],"research_lenses":["transparent-hash"],"role":"system_construction","source_locator":{"dossier_section":"PROOF-PAPER-2018-STARK § System overview","primary_source":"Abstract and system overview","primary_source_url":"https://eprint.iacr.org/2018/046","status":"primary_source_checked"},"statement":"The STARK architecture combines algebraic execution constraints, interactive-oracle techniques for codes, and hash-authenticated oracle commitments to obtain transparent computational-integrity proofs with sublinear verification for the demonstrated computations.","statement_status":"source_normalized_statement","status":"published","title":"AIR and coded-oracle checks form a transparent scalable proof architecture","visibility":"backbone","work_id":"PROOF-PAPER-2018-STARK","year":2018},"primaryUrl":"https://eprint.iacr.org/2018/046","sections":[{"content":"Transparent coded-oracle architecture The contribution is an integrated configuration-level architecture; its components remain separately queryable.","heading":"Overview"}],"status":"published","subtitle":"Scalable, Transparent, and Post-Quantum Secure Computational Integrity","summary":"The STARK architecture combines algebraic execution constraints, interactive-oracle techniques for codes, and hash-authenticated oracle commitments to obtain transparent computational-integrity proofs with sublinear verification for the demonstrated computations.","tags":["atomic-result","backbone","system_construction","transparent-hash"],"title":"AIR and coded-oracle checks form a transparent scalable proof architecture","type":"result","venue":"IACR ePrint 2018/046","year":2018,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2018-STARK-SYSTEM"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2019-HALO-RECURSION","metadata":{"claim_slug":"halo-recursion","contribution_kind":"mechanism","contribution_role":"composition","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["nested-amortization","curve-cycle"],"setup":["transparent"],"task":["recursion"]},"historical_context":{"narrative":"Recursive proof composition had been demonstrated with succinct arguments, but practical configurations commonly inherited structured setup or expensive in-circuit verification. Halo combines an inner-product polynomial commitment with nested amortization and a cycle of elliptic curves so that the algebra needed to verify earlier work can itself be represented inside the next proof. The contribution is this no-trusted-setup recursion architecture, not the general claim that every inner-product proof recurses efficiently. At publication it provided a concrete alternative to pairing-based recursive stacks and made the commitment backend, curve cycle, and amortization boundary explicit parts of the composition design.","prior_boundary":"Recursive succinct proofs were available through pairing-based or other structured configurations, but practical recursion without a trusted setup remained a central systems boundary.","significance_at_publication":"It supplied a practical transparent recursion architecture and clarified that recursive composition depends on the commitment and curve configuration, not only on a high-level proof-system label.","technical_delta":"Halo amortizes inner-product opening work across an accumulation strategy and uses a cycle of elliptic curves so one proof circuit can verify the algebra needed for the previous proof."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2019-HALO-RECURSION","keywords":["halo","recursion","inner-product","curve-cycle","transparent"],"lens":"recursion-ivc","limitations":["not a post-quantum construction","concrete recursion depends on the selected curve and commitment configuration"],"paper_id":"PROOF-PAPER-2019-HALO","qualifiers":["inner-product polynomial commitment","elliptic-curve cycle","amortized recursion"],"research_lenses":["recursion-ivc"],"role":"composition","source_locator":{"dossier_section":"PROOF-PAPER-2019-HALO § Recursive composition","primary_source":"Section 1.1 and Sections 3–6","primary_source_url":"https://eprint.iacr.org/2019/1021","status":"section_checked"},"statement":"Halo combines an inner-product polynomial commitment, nested amortization, and an elliptic-curve cycle to realize recursive proof composition without a trusted setup.","statement_status":"source_normalized_statement","status":"published","title":"Inner-product commitments enable recursive proof composition without trusted setup","visibility":"backbone","work_id":"PROOF-PAPER-2019-HALO","year":2019},"primaryUrl":"https://eprint.iacr.org/2019/1021","sections":[{"content":"Halo recursion The card isolates the recursive mechanism from any particular implementation version.","heading":"Overview"}],"status":"published","subtitle":"Recursive Proof Composition without a Trusted Setup","summary":"Halo combines an inner-product polynomial commitment, nested amortization, and an elliptic-curve cycle to realize recursive proof composition without a trusted setup.","tags":["atomic-result","backbone","composition","recursion-ivc"],"title":"Inner-product commitments enable recursive proof composition without trusted setup","type":"result","venue":"IACR ePrint 2019/1021","year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2019-HALO-RECURSION"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2019-MARLIN-AHP","metadata":{"claim_slug":"marlin-ahp","contribution_kind":"transform","contribution_role":"compiler","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"component_boundary":["protocol-plus-pcs"],"mechanism":["ahp-compiler"],"setup":["universal-updatable-structured"]},"historical_context":{"narrative":"Preprocessing zkSNARKs commonly tied their structured reference string to one circuit, so changing the relation meant repeating setup. Marlin separates the algebraic holographic proof for an indexed relation from the extractable polynomial commitment used to compile it, allowing a universal degree-bounded SRS to support many circuits and to be updated. The atomic contribution is the AHP compiler interface and its universal-setup consequence, not a claim that the resulting system is transparent or backend-independent in security. It mattered because setup reuse became a first-class architectural property and the protocol, commitment, and compiler layers could be analyzed and replaced separately.","prior_boundary":"Preprocessing zkSNARKs often bound their structured reference string to one circuit, forcing a new setup when the supported relation changed.","significance_at_publication":"It made setup reuse a compiler-level property and exposed the information-theoretic protocol and cryptographic commitment as distinct stack layers.","technical_delta":"Marlin separates an algebraic holographic proof for indexed relations from an extractable polynomial-commitment backend, so one degree-bounded SRS can support many circuits and be updated."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2019-MARLIN-AHP","keywords":["marlin","ahp","universal-srs","compiler","polynomial-commitment"],"lens":"universal-polynomial","limitations":["universal structured setup is not transparent setup","security inherits the selected commitment assumptions"],"paper_id":"PROOF-PAPER-2019-MARLIN","qualifiers":["indexed relations","public-coin AHP","extractable polynomial commitment"],"research_lenses":["universal-polynomial"],"role":"compiler","source_locator":{"dossier_section":"PROOF-PAPER-2019-MARLIN § AHP compiler","primary_source":"Section 1.1 and Theorem 8.1","primary_source_url":"https://eprint.iacr.org/2019/1047","status":"theorem_checked"},"statement":"Marlin formalizes a compiler from public-coin algebraic holographic proofs and extractable polynomial commitments to preprocessing arguments with a universal and updatable structured reference string.","statement_status":"source_normalized_statement","status":"published","title":"Algebraic-holographic proofs compile to universal-updatable-SRS arguments","visibility":"reviewed_related","work_id":"PROOF-PAPER-2019-MARLIN","year":2019},"primaryUrl":"https://eprint.iacr.org/2019/1047","sections":[{"content":"Marlin AHP compiler This record treats Marlin's compiler delta separately from one concrete KZG-backed configuration.","heading":"Overview"}],"status":"published","subtitle":"Marlin: Preprocessing zkSNARKs with Universal and Updatable SRS","summary":"Marlin formalizes a compiler from public-coin algebraic holographic proofs and extractable polynomial commitments to preprocessing arguments with a universal and updatable structured reference string.","tags":["atomic-result","compiler","reviewed_related","universal-polynomial"],"title":"Algebraic-holographic proofs compile to universal-updatable-SRS arguments","type":"result","venue":"EUROCRYPT 2020","year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2019-MARLIN-AHP"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2019-PLONK-PIOP","metadata":{"claim_slug":"plonk-piop","contribution_kind":"construction","contribution_role":"system_construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"arithmetization":["plonkish"],"setup":["universal-updatable-structured"],"system_family":["plonk"]},"historical_context":{"narrative":"Compact pairing-based arguments such as Groth16 tied setup to a specific circuit, making relation changes operationally expensive. PLONK represents gate constraints and circuit wiring as polynomial identities over a Lagrange domain and enforces wiring with a permutation argument, so a universal degree-bounded structured reference string can serve many circuits. The atomic contribution is this permutation-based polynomial architecture and setup boundary, not every later system called PLONKish. At publication it provided a flexible foundation for custom gates and later lookup extensions while retaining a structured setup and leaving knowledge soundness dependent on the exact polynomial-commitment, batching, and Fiat–Shamir configuration.","prior_boundary":"Very small pairing-based circuit arguments used circuit-specific setup, while universal preprocessing systems had not yet offered the same PLONK-style gate and wiring interface.","significance_at_publication":"It created a flexible universal circuit-proof architecture whose arithmetization and commitment backend became durable extension points, while retaining structured setup and configuration-specific security obligations.","technical_delta":"PLONK expresses wiring through a permutation argument over Lagrange-basis polynomials and combines it with a universal degree-bounded commitment setup."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2019-PLONK-PIOP","keywords":["plonk","permutation-argument","plonkish","universal-srs"],"lens":"universal-polynomial","limitations":["not transparent","later PLONKish variants require separate security and configuration records"],"paper_id":"PROOF-PAPER-2019-PLONK","qualifiers":["polynomial protocol","permutation argument","universal updatable SRS"],"research_lenses":["universal-polynomial"],"role":"system_construction","source_locator":{"dossier_section":"PROOF-PAPER-2019-PLONK § Polynomial protocol","primary_source":"Abstract and Sections 1 and 8","primary_source_url":"https://eprint.iacr.org/2019/953","status":"section_checked"},"statement":"PLONK gives a permutation-based polynomial proof architecture over Lagrange-basis constraints whose structured reference string is universal and updatable rather than circuit specific.","statement_status":"source_normalized_statement","status":"published","title":"Permutation-based polynomial protocol supports universal updatable setup","visibility":"backbone","work_id":"PROOF-PAPER-2019-PLONK","year":2019},"primaryUrl":"https://eprint.iacr.org/2019/953","sections":[{"content":"PLONK polynomial architecture The card does not transfer the original theorem automatically to later optimized PLONKish variants.","heading":"Overview"}],"status":"published","subtitle":"PLONK: Permutations over Lagrange-bases for Oecumenical Noninteractive arguments of Knowledge","summary":"PLONK gives a permutation-based polynomial proof architecture over Lagrange-basis constraints whose structured reference string is universal and updatable rather than circuit specific.","tags":["atomic-result","backbone","system_construction","universal-polynomial"],"title":"Permutation-based polynomial protocol supports universal updatable setup","type":"result","venue":"IACR ePrint 2019/953","year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2019-PLONK-PIOP"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2019-SPARTAN-R1CS","metadata":{"claim_slug":"spartan-r1cs","contribution_kind":"construction","contribution_role":"system_construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["sum-check","multilinear-extension"],"representation":["r1cs"],"setup":["transparent"]},"historical_context":{"narrative":"Transparent arguments for general computation needed a disciplined way to turn an arbitrary R1CS instance into algebraic claims that a verifier could check without scanning the full relation. Spartan represents the matrices and witness through multilinear extensions and uses sum-check to reduce the R1CS identity to a small set of evaluation claims, which a commitment backend then authenticates. The contribution is this R1CS-to-sum-check architecture and its transparent preprocessing profile, not a claim that every backend has identical proof size or verifier time. It mattered because the multilinear protocol became a reusable general-purpose route with an explicit separation between relation encoding, sum-check, commitments, and non-interactive compilation.","prior_boundary":"General-purpose transparent arguments existed, but efficiently connecting arbitrary R1CS to algebraic checks without a trusted setup remained a central design challenge.","significance_at_publication":"It established a clean multilinear/sum-check route for general R1CS and separated transparent preprocessing from secret structured setup.","technical_delta":"Spartan encodes R1CS matrices and assignments as multilinear extensions and applies sum-check reductions before binding remaining evaluations with a commitment scheme."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2019-SPARTAN-R1CS","keywords":["spartan","r1cs","sum-check","multilinear","transparent"],"lens":"multilinear-sumcheck","limitations":["exact succinctness depends on the commitment backend and variant","transparent preprocessing is not zero preprocessing"],"paper_id":"PROOF-PAPER-2019-SPARTAN","qualifiers":["arbitrary R1CS","multilinear extensions","public preprocessing"],"research_lenses":["multilinear-sumcheck"],"role":"system_construction","source_locator":{"dossier_section":"PROOF-PAPER-2019-SPARTAN § R1CS protocol","primary_source":"Abstract and Sections 1 and 4","primary_source_url":"https://eprint.iacr.org/2019/550","status":"section_checked"},"statement":"Spartan reduces arbitrary R1CS satisfiability to sum-check and multilinear commitment machinery, giving transparent argument variants with sublinear verification after public preprocessing.","statement_status":"source_normalized_statement","status":"published","title":"Sum-check proves arbitrary R1CS with transparent preprocessing","visibility":"backbone","work_id":"PROOF-PAPER-2019-SPARTAN","year":2019},"primaryUrl":"https://eprint.iacr.org/2019/550","sections":[{"content":"Spartan R1CS argument The record identifies the reusable relation-to-sum-check architecture rather than one library version.","heading":"Overview"}],"status":"published","subtitle":"Spartan: Efficient and General-purpose zkSNARKs without Trusted Setup","summary":"Spartan reduces arbitrary R1CS satisfiability to sum-check and multilinear commitment machinery, giving transparent argument variants with sublinear verification after public preprocessing.","tags":["atomic-result","backbone","multilinear-sumcheck","system_construction"],"title":"Sum-check proves arbitrary R1CS with transparent preprocessing","type":"result","venue":"CRYPTO 2020","year":2019,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2019-SPARTAN-R1CS"},{"evidence":"fulltext_checked","id":"PROOF-CONTRIB-2020-ACCUMULATION-PCD","metadata":{"claim_slug":"accumulation-pcd","contribution_kind":"transform","contribution_role":"definition_and_compiler","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"compiler_target":["proof-carrying-data"],"mechanism":["accumulation"],"task":["pcd"]},"historical_context":{"narrative":"Recursive proof systems often embedded verification of a previous proof inside the next circuit, making full recursive wrapping appear to be the primitive required for PCD. Bünz, Chiesa, Mishra, and Spooner instead define accumulation schemes, which compress several pending validity obligations into one accumulator and defer the final check to a decider. They prove that a suitable accumulator for an argument is sufficient to build proof-carrying data. The atomic contribution is this definition-and-compiler boundary, not a standard-model non-interactive instantiation: the concrete constructions retain random-oracle or knowledge-style assumptions. It mattered because later composition work could target accumulation directly rather than reproduce a complete recursive verifier at every step.","prior_boundary":"Recursive composition was commonly phrased as verifying an entire prior proof inside a new proof, leaving unclear which weaker primitive actually sufficed for PCD.","significance_at_publication":"It separated composition semantics from recursive wrapping and opened a program of constructing accumulators under better models and assumptions.","technical_delta":"Accumulation compresses the validity obligations of several argument instances into one accumulator that a final decider checks, and the paper formalizes a compiler from this primitive to PCD."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2020-ACCUMULATION-PCD","keywords":["accumulation","pcd","compiler","recursion"],"lens":"recursion-ivc","limitations":["concrete non-interactive instantiations use random oracle or knowledge assumptions","standard-model accumulation remains open"],"paper_id":"PROOF-PAPER-2020-ACCUMULATION","qualifiers":["argument accumulation","PCD compiler","final decider"],"research_lenses":["recursion-ivc"],"role":"definition_and_compiler","source_locator":{"dossier_section":"PROOF-PAPER-2020-ACCUMULATION § Accumulation and PCD","primary_source":"Abstract; Section 1.1; Theorems 1–3","primary_source_url":"https://eprint.iacr.org/2020/499","status":"theorem_checked"},"statement":"The paper defines accumulation schemes and proves that an argument equipped with a suitable accumulator yields proof-carrying data, with concrete non-interactive instantiations relying on a random oracle or knowledge assumptions.","statement_status":"source_normalized_statement","status":"published","title":"Accumulation schemes suffice to compile arguments into proof-carrying data","visibility":"reviewed_related","work_id":"PROOF-PAPER-2020-ACCUMULATION","year":2020},"primaryUrl":"https://eprint.iacr.org/2020/499","sections":[{"content":"Accumulation-to-PCD compiler The explicit assumption boundary also grounds the dossier's standard-model accumulation problem.","heading":"Overview"}],"status":"published","subtitle":"Proof-Carrying Data from Accumulation Schemes","summary":"The paper defines accumulation schemes and proves that an argument equipped with a suitable accumulator yields proof-carrying data, with concrete non-interactive instantiations relying on a random oracle or knowledge assumptions.","tags":["atomic-result","definition_and_compiler","recursion-ivc","reviewed_related"],"title":"Accumulation schemes suffice to compile arguments into proof-carrying data","type":"result","venue":"TCC 2020","year":2020,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2020-ACCUMULATION-PCD"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2021-NOVA-FOLDING","metadata":{"claim_slug":"nova-folding","contribution_kind":"mechanism","contribution_role":"definition_and_construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["folding"],"representation":["relaxed-r1cs"],"task":["ivc"]},"historical_context":{"narrative":"Incrementally verifiable computation was commonly built by recursively proving that a verifier accepted the previous proof, which made every step pay for a recursive proof verifier. Nova introduces relaxed R1CS instances and a folding protocol that combines the running instance with the next computation step into one new relaxed instance. The folding core is deliberately weaker than a SNARK; succinct final verification belongs to a separate decider or compression layer. This distinction is the atomic contribution. It mattered because IVC could use a lightweight per-step algebraic update and postpone expensive succinctness, opening a new composition line organized around relation folding rather than recursive proof wrapping.","prior_boundary":"Practical IVC designs recursively verified a succinct proof at each step, so per-step work inherited the cost and setup constraints of the recursive proof configuration.","significance_at_publication":"It made folding a distinct composition primitive and changed what the prover performs at each incremental step.","technical_delta":"Nova relaxes R1CS with an error term and folds the current step and running instance into one new instance using a lightweight algebraic protocol, postponing succinct verification to a decider or compression phase."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2021-NOVA-FOLDING","keywords":["nova","folding","relaxed-r1cs","ivc"],"lens":"recursion-ivc","limitations":["folding alone is not a SNARK","non-interactive deployment inherits transcript and final-decider assumptions"],"paper_id":"PROOF-PAPER-2021-NOVA","qualifiers":["relaxed R1CS","per-step folding","separate decider or compression"],"research_lenses":["recursion-ivc"],"role":"definition_and_construction","source_locator":{"dossier_section":"PROOF-PAPER-2021-NOVA § Folding schemes","primary_source":"Section 1.1; folding definitions and constructions","primary_source_url":"https://eprint.iacr.org/2021/370","status":"section_checked"},"statement":"Nova defines folding schemes as a weaker primitive than SNARKs and folds two relaxed-R1CS instances into one running instance to realize incrementally verifiable computation before an optional final compression step.","statement_status":"source_normalized_statement","status":"published","title":"Relaxed-R1CS folding realizes incrementally verifiable computation","visibility":"backbone","work_id":"PROOF-PAPER-2021-NOVA","year":2021},"primaryUrl":"https://eprint.iacr.org/2021/370","sections":[{"content":"Nova folding The record keeps the folding primitive distinct from Nova's complete compressed configuration.","heading":"Overview"}],"status":"published","subtitle":"Nova: Recursive Zero-Knowledge Arguments from Folding Schemes","summary":"Nova defines folding schemes as a weaker primitive than SNARKs and folds two relaxed-R1CS instances into one running instance to realize incrementally verifiable computation before an optional final compression step.","tags":["atomic-result","backbone","definition_and_construction","recursion-ivc"],"title":"Relaxed-R1CS folding realizes incrementally verifiable computation","type":"result","venue":"CRYPTO 2022","year":2021,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2021-NOVA-FOLDING"},{"evidence":"fulltext_checked","id":"PROOF-CONTRIB-2023-BEHEMOTH-CONSTANT","metadata":{"claim_slug":"behemoth-constant","contribution_kind":"mechanism","contribution_role":"component_construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"component_role":["commitment-backend"],"opening_cost":["degree-independent"],"setup":["transparent"]},"historical_context":{"narrative":"Transparent polynomial commitments typically avoided a trapdoor at the cost of opening proofs or verifier work that grew with polynomial degree, whereas constant endpoints were associated with structured pairing parameters. Behemoth shows that transparent setup can coexist with degree-independent opening size and verification by working in a group of unknown order. The atomic delta is those two degree-independent coordinates; it does not include a post-quantum claim or an efficient prover. The prover is cubic, and the analysis uses random-oracle and generic-group models. At publication the result clarified that transparency alone does not force logarithmic openings and isolated quantum security and prover complexity as separate research targets.","prior_boundary":"Known transparent polynomial commitments generally paid logarithmic or polylogarithmic opening and verifier costs, while constant endpoints were associated with structured algebraic setup.","significance_at_publication":"It separated transparency from logarithmic opening costs and made post-quantum security and prover complexity the explicit remaining boundaries.","technical_delta":"Behemoth obtains constant opening size and verifier time from a group-of-unknown-order construction with transparent setup, trading those endpoints for cubic prover work and stronger proof models."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2023-BEHEMOTH-CONSTANT","keywords":["behemoth","polynomial-commitment","transparent","constant-opening"],"lens":"transparent-hash","limitations":["cubic prover","random-oracle and generic-group analysis","no post-quantum claim"],"paper_id":"PROOF-PAPER-2023-BEHEMOTH","qualifiers":["group of unknown order","transparent setup","degree-independent opening and verification"],"research_lenses":["transparent-hash"],"role":"component_construction","source_locator":{"dossier_section":"PROOF-PAPER-2023-BEHEMOTH § Constant opening construction","primary_source":"Abstract; Sections 4–5 and 8","primary_source_url":"https://eprint.iacr.org/2023/670","status":"section_checked"},"statement":"Behemoth constructs a transparent polynomial commitment with degree-independent opening-proof size and verifier time in a group of unknown order, with cubic prover time and analysis in the random-oracle and generic-group models.","statement_status":"source_normalized_statement","status":"published","title":"Transparent polynomial commitments with degree-independent opening size and verification","visibility":"reviewed_related","work_id":"PROOF-PAPER-2023-BEHEMOTH","year":2023},"primaryUrl":"https://eprint.iacr.org/2023/670","sections":[{"content":"Behemoth polynomial commitments The card's limitations are part of the contribution identity and ground a separate open target.","heading":"Overview"}],"status":"published","subtitle":"Behemoth — Transparent Polynomial Commitment Scheme with Constant Opening Proof Size and Verifier Time","summary":"Behemoth constructs a transparent polynomial commitment with degree-independent opening-proof size and verifier time in a group of unknown order, with cubic prover time and analysis in the random-oracle and generic-group models.","tags":["atomic-result","component_construction","reviewed_related","transparent-hash"],"title":"Transparent polynomial commitments with degree-independent opening size and verification","type":"result","venue":"AFRICACRYPT 2025","year":2023,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2023-BEHEMOTH-CONSTANT"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD","metadata":{"claim_slug":"hypernova-multifold","contribution_kind":"mechanism","contribution_role":"composition","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"mechanism":["multi-folding"],"representation":["ccs"],"task":["ivc","pcd"]},"historical_context":{"narrative":"Nova established folding for relaxed R1CS and uniform incremental steps, but that interface did not directly capture custom constraint gates, several instances per fold, or step circuits that vary across a computation. HyperNova moves the relation to CCS and uses sum-check-based multi-folding to combine multiple instances while supporting non-uniform IVC and PCD-oriented constructions. The atomic contribution is this generalized folding mechanism and capability boundary, not a claim that every CCS configuration has identical commitment or decider costs. It mattered because designers could preserve custom arithmetization structure and non-uniform computation inside the folding line rather than reduce everything to Nova's original relaxed-R1CS step interface.","prior_boundary":"Nova folded pairs of relaxed-R1CS instances for uniform-step IVC, leaving richer constraint systems, multiple simultaneous instances, and non-uniform computation as separate extensions.","significance_at_publication":"It widened folding from one R1CS-centric IVC configuration into a more expressive composition interface without collapsing CCS, multifolding, and PCD into one object.","technical_delta":"HyperNova builds a sum-check-based multi-folding protocol for CCS, allowing several instances and customizable constraints to be folded while supporting step circuits that change over time."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD","keywords":["hypernova","ccs","multifolding","ivc","pcd"],"lens":"recursion-ivc","limitations":["final succinctness remains configuration dependent","non-interactive security inherits transcript assumptions"],"paper_id":"PROOF-PAPER-2023-HYPERNOVA","qualifiers":["CCS","multi-folding","non-uniform IVC"],"research_lenses":["recursion-ivc"],"role":"composition","source_locator":{"dossier_section":"PROOF-PAPER-2023-HYPERNOVA § Contributions","primary_source":"Abstract and contributions in Section 1","primary_source_url":"https://eprint.iacr.org/2023/573","status":"section_checked"},"statement":"HyperNova generalizes folding from relaxed R1CS to customizable constraint systems, folds multiple instances in one step, and supports non-uniform step circuits and PCD-oriented generalizations.","statement_status":"source_normalized_statement","status":"published","title":"CCS multi-folding supports multiple instances and non-uniform IVC steps","visibility":"backbone","work_id":"PROOF-PAPER-2023-HYPERNOVA","year":2023},"primaryUrl":"https://eprint.iacr.org/2023/573","sections":[{"content":"HyperNova multi-folding The record preserves the generalization from Nova without turning CCS into a task category.","heading":"Overview"}],"status":"published","subtitle":"Recursive Arguments for Customizable Constraint Systems","summary":"HyperNova generalizes folding from relaxed R1CS to customizable constraint systems, folds multiple instances in one step, and supports non-uniform step circuits and PCD-oriented generalizations.","tags":["atomic-result","backbone","composition","recursion-ivc"],"title":"CCS multi-folding supports multiple instances and non-uniform IVC steps","type":"result","venue":"CRYPTO 2024","year":2023,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2023-JOLT-LOOKUPVM","metadata":{"claim_slug":"jolt-lookupvm","contribution_kind":"construction","contribution_role":"system_architecture","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"computation_model":["risc-v"],"mechanism":["lookup"],"stack_layers":["memory-checking","residual-r1cs"],"task":["zkvm"]},"historical_context":{"narrative":"Earlier zkVM architectures typically represented instruction semantics through many custom algebraic constraints, so adding an ISA and proving its execution were tightly coupled to a large arithmetization. Jolt instead treats instruction evaluation as structured table lookup, combines that lookup argument with a separate memory-checking protocol, and sends residual constraints through a Spartan-style sum-check stack. The atomic contribution is this lookup-centric VM decomposition, not a timeless performance claim for every Jolt implementation. It mattered because instruction semantics, memory consistency, residual R1CS, and the commitment backend became visible components that could be optimized or replaced independently in later artifacts.","prior_boundary":"zkVM designs commonly arithmetized instruction semantics as large collections of bespoke constraints, making instruction handling and prover cost a major architecture-specific burden.","significance_at_publication":"It made lookup decomposition the organizing principle of a general VM proof stack and exposed instruction, memory, residual constraints, and commitment backend as separable layers.","technical_delta":"Jolt moves instruction semantics into structured lookup tables and composes Lasso-style lookups with memory checking and a Spartan-style sum-check argument for the remaining R1CS relation."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2023-JOLT-LOOKUPVM","keywords":["jolt","zkvm","lookup","memory-checking","sum-check"],"lens":"lookups-zkvm","limitations":["paper architecture is distinct from later RV32 and RV64 implementation configurations","performance depends on backend and workload"],"paper_id":"PROOF-PAPER-2023-JOLT","qualifiers":["VM execution","Lasso-style structured lookups","separate memory checking"],"research_lenses":["lookups-zkvm","multilinear-sumcheck"],"role":"system_architecture","source_locator":{"dossier_section":"PROOF-PAPER-2023-JOLT § System decomposition","primary_source":"Abstract and Sections 1 and 3","primary_source_url":"https://eprint.iacr.org/2023/1217","status":"section_checked"},"statement":"Jolt organizes instruction execution around large structured lookups and combines the lookup argument with a sum-check-based proof for residual constraints plus a separate memory-checking protocol.","statement_status":"source_normalized_statement","status":"published","title":"Lookup-centric decomposition proves virtual-machine execution","visibility":"backbone","work_id":"PROOF-PAPER-2023-JOLT","year":2023},"primaryUrl":"https://eprint.iacr.org/2023/1217","sections":[{"content":"Jolt lookup-centric architecture Implementations and benchmark runs remain separate versioned objects linked to this architecture.","heading":"Overview"}],"status":"published","subtitle":"Jolt: SNARKs for Virtual Machines via Lookups","summary":"Jolt organizes instruction execution around large structured lookups and combines the lookup argument with a sum-check-based proof for residual constraints plus a separate memory-checking protocol.","tags":["atomic-result","backbone","lookups-zkvm","multilinear-sumcheck","system_architecture"],"title":"Lookup-centric decomposition proves virtual-machine execution","type":"result","venue":"IACR ePrint 2023/1217","year":2023,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2023-JOLT-LOOKUPVM"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2023-PROTOSTAR-GENERIC","metadata":{"claim_slug":"protostar-generic","contribution_kind":"transform","contribution_role":"compiler","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"input_property":["special-soundness"],"mechanism":["accumulation-compiler"],"task":["ivc"]},"historical_context":{"narrative":"Early folding systems were tightly coupled to a particular relaxed relation, which made richer gates or lookup-heavy arithmetizations require new relation-specific machinery. Protostar identifies a class of special-sound protocols as the input to a generic accumulation compiler and then instantiates that route for a PLONK-style relation containing high-degree gates and vector lookups. The atomic contribution is the compiler abstraction and its concrete instantiation, not a claim that every special-sound protocol automatically yields an equally efficient IVC system. It mattered because folding could be reasoned about as a transformation of a protocol interface, allowing arithmetization features and accumulation mechanics to evolve more independently.","prior_boundary":"Folding schemes were designed around particular relaxed relations, so adding high-degree custom gates or vector lookups often required a new bespoke folding construction.","significance_at_publication":"It reframed folding as a compiler over a protocol property and broadened the composition line beyond one fixed R1CS or CCS relation.","technical_delta":"Protostar abstracts special soundness as the compiler input and derives an accumulation scheme, then instantiates the interface for a PLONK-style relation with custom gates and lookups."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2023-PROTOSTAR-GENERIC","keywords":["protostar","accumulation","folding","compiler","special-soundness"],"lens":"recursion-ivc","limitations":["efficiency and non-interactive security remain instantiation dependent","not every protocol satisfies the compiler hypotheses"],"paper_id":"PROOF-PAPER-2023-PROTOSTAR","qualifiers":["special-sound protocols","accumulation compiler","PLONK-style instantiation"],"research_lenses":["recursion-ivc"],"role":"compiler","source_locator":{"dossier_section":"PROOF-PAPER-2023-PROTOSTAR § Generic compiler","primary_source":"Abstract; generic compiler and concrete Protostar construction","primary_source_url":"https://eprint.iacr.org/2023/620","status":"section_checked"},"statement":"Protostar gives an accumulation or folding compiler for a class of special-sound protocols and instantiates it for non-uniform IVC with PLONK-style high-degree gates and vector lookups.","statement_status":"source_normalized_statement","status":"published","title":"Special-sound protocols compile into generic accumulation and folding","visibility":"reviewed_related","work_id":"PROOF-PAPER-2023-PROTOSTAR","year":2023},"primaryUrl":"https://eprint.iacr.org/2023/620","sections":[{"content":"Protostar accumulation compiler The compiler and its PLONK-style instantiation are kept within one atomic contribution because the latter demonstrates the former's intended boundary.","heading":"Overview"}],"status":"published","subtitle":"Protostar: Generic Efficient Accumulation/Folding for Special-Sound Protocols","summary":"Protostar gives an accumulation or folding compiler for a class of special-sound protocols and instantiates it for non-uniform IVC with PLONK-style high-degree gates and vector lookups.","tags":["atomic-result","compiler","recursion-ivc","reviewed_related"],"title":"Special-sound protocols compile into generic accumulation and folding","type":"result","venue":"ASIACRYPT 2023","year":2023,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2023-PROTOSTAR-GENERIC"},{"evidence":"fulltext_checked","id":"PROOF-CONTRIB-2024-LATTICE-PCS-PQ","metadata":{"claim_slug":"lattice-pcs-pq","contribution_kind":"mechanism","contribution_role":"component_construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"assumption":["module-sis"],"component_role":["commitment-backend"],"quantum_security":["knowledge-soundness"],"setup":["transparent"]},"historical_context":{"narrative":"Transparent polynomial commitments with a post-quantum security story were available through hash- and code-based approaches, but the lattice route had not offered this combination of succinct openings, quasi-linear proving, and quantum knowledge soundness. This construction uses Module-SIS to obtain transparent setup, polylogarithmic communication and verifier work, and a quasi-linear prover, together with an explicit quantum extraction analysis. The atomic contribution is that lattice PCS cost-and-security profile; the non-interactive form still uses Fiat–Shamir in the random-oracle model, and the opening and verifier costs are not constant. At publication it created a distinct post-quantum commitment backend and sharpened the remaining constant-cost target.","prior_boundary":"Transparent post-quantum polynomial commitments offered hash- or code-based routes, while lattice commitments had not simultaneously supplied the paper's knowledge-soundness, verifier, communication, and prover bounds.","significance_at_publication":"It provided a lattice endpoint with an explicit quantum extraction theorem, while leaving constant opening and verifier costs unresolved.","technical_delta":"The paper builds a Module-SIS-based PCS with transparent setup, polylogarithmic opening communication and verification, quasi-linear prover work, and a quantum knowledge extractor for the declared protocol."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2024-LATTICE-PCS-PQ","keywords":["lattice","polynomial-commitment","post-quantum","module-sis","transparent"],"lens":"transparent-hash","limitations":["non-interactive form uses Fiat-Shamir in ROM","opening size and verifier time are not constant"],"paper_id":"PROOF-PAPER-2024-LATTICE-PCS","qualifiers":["Module-SIS","transparent setup","quantum knowledge soundness","polylogarithmic opening"],"research_lenses":["transparent-hash"],"role":"component_construction","source_locator":{"dossier_section":"PROOF-PAPER-2024-LATTICE-PCS § Main results","primary_source":"Abstract; Section 1.1; Figure 2","primary_source_url":"https://eprint.iacr.org/2024/281","status":"theorem_checked"},"statement":"The construction gives a transparent lattice-based polynomial commitment with polylogarithmic communication and verification, quasi-linear proving, and quantum knowledge soundness under Module-SIS; its non-interactive form uses Fiat–Shamir in the random-oracle model.","statement_status":"source_normalized_statement","status":"published","title":"Transparent lattice PCS gives post-quantum knowledge soundness with polylogarithmic openings","visibility":"reviewed_related","work_id":"PROOF-PAPER-2024-LATTICE-PCS","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/281","sections":[{"content":"Lattice polynomial commitments This card preserves the interactive theorem and non-interactive compiler boundary separately.","heading":"Overview"}],"status":"published","subtitle":"Polynomial Commitments from Lattices — Post-Quantum Security, Fast Verification and Transparent Setup","summary":"The construction gives a transparent lattice-based polynomial commitment with polylogarithmic communication and verification, quasi-linear proving, and quantum knowledge soundness under Module-SIS; its non-interactive form uses Fiat–Shamir in the random-oracle model.","tags":["atomic-result","component_construction","reviewed_related","transparent-hash"],"title":"Transparent lattice PCS gives post-quantum knowledge soundness with polylogarithmic openings","type":"result","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2024-LATTICE-PCS-PQ"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2024-PLONK-KS","metadata":{"claim_scope":"Specified PLONK variants and batch-opening protocols","claim_slug":"plonk-ks","contribution_kind":"security_analysis","contribution_role":"security_analysis","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"backend":["kzg"],"scope":["variant-specific"],"security_notions":["computational-special-soundness","knowledge-soundness"]},"historical_context":{"narrative":"Implemented PLONKish systems commonly combine the original polynomial protocol with batched KZG openings and Fiat–Shamir, but a citation to PLONK does not by itself prove knowledge soundness for that optimized configuration. This work analyzes specified batch-opening protocols and interactive PLONK variants through computational special soundness under falsifiable assumptions, then identifies how those claims connect to a random-oracle compilation. The atomic contribution is the variant-scoped security analysis, not a blanket repair or theorem for every PLONKish fork. It mattered because batching equations, commitment assumptions, and transcript compilation became explicit parts of the security claim rather than undocumented implementation details.","prior_boundary":"Deployed PLONKish systems combined Fiat–Shamir, batching, and KZG optimizations whose knowledge-soundness justification was not captured by simply citing the original high-level protocol.","significance_at_publication":"It replaced family-level security shorthand with a configuration-scoped proof obligation and showed why optimizations must be included in the audited theorem.","technical_delta":"The analysis isolates computational special soundness for exact batch-opening protocols and interactive PLONK variants and states the additional steps needed for a ROM knowledge-soundness theorem."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2024-PLONK-KS","keywords":["plonk","knowledge-soundness","kzg","batching","security-analysis"],"lens":"security-audit","limitations":["not a blanket theorem for all PLONKish systems","exact variants and assumptions must match"],"paper_id":"PROOF-PAPER-2024-PLONK-KS","qualifiers":["specified interactive PLONK variants","batched KZG openings","ROM compilation"],"research_lenses":["security-audit"],"role":"security_analysis","security_model":"Interactive computational special soundness and ROM knowledge soundness under stated assumptions","source_locator":{"dossier_section":"PROOF-PAPER-2024-PLONK-KS § Main security theorems","primary_source":"Abstract; main PLONK and batching theorems","primary_source_url":"https://eprint.iacr.org/2024/994","status":"theorem_checked"},"statement":"The paper proves computational special soundness for specified batched KZG opening protocols and interactive PLONK variants under falsifiable assumptions, then relates those results to random-oracle-model knowledge soundness.","statement_status":"source_normalized_statement","status":"published","title":"Variant-scoped PLONK knowledge soundness covers batched KZG openings","visibility":"backbone","work_id":"PROOF-PAPER-2024-PLONK-KS","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/994","sections":[{"content":"PLONK knowledge-soundness audit The theorem's variant boundary is part of the claim and must not be inherited by undocumented configurations.","heading":"Overview"}],"status":"published","subtitle":"On Knowledge-Soundness of Plonk in ROM from Falsifiable Assumptions","summary":"The paper proves computational special soundness for specified batched KZG opening protocols and interactive PLONK variants under falsifiable assumptions, then relates those results to random-oracle-model knowledge soundness.","tags":["atomic-result","backbone","security-audit","security_analysis"],"title":"Variant-scoped PLONK knowledge soundness covers batched KZG openings","type":"result","venue":"IACR ePrint 2024/994","year":2024,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2024-PLONK-KS"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2024-REALWORLD-SE","metadata":{"claim_scope":"Optimized universal PIOP-based configurations satisfying the paper's stated conditions","claim_slug":"realworld-se","contribution_kind":"security_analysis","contribution_role":"security_analysis","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"families":["plonk","marlin"],"scope":["configuration-specific"],"security_notions":["simulation-extractability"]},"historical_context":{"narrative":"Security proofs for universal zkSNARKs were often read at the level of a protocol family, even though implementations use batching and algebraic optimizations that may change extraction arguments. This work formalizes specified optimized PLONK- and Marlin-style configurations and proves simulation extractability under its stated models and assumptions. The atomic contribution is coverage of those concrete optimization patterns, not a global non-malleability badge for every universal or PLONKish system. At publication it reduced the distance between textbook protocols and deployed configurations and made a crucial audit rule visible: a fork, backend replacement, or undocumented optimization inherits the theorem only after its exact conditions are checked.","prior_boundary":"Simulation-extractability analyses often covered clean protocol descriptions, while deployed universal zkSNARKs used batching and algebraic optimizations whose inclusion in the theorem was uncertain.","significance_at_publication":"It narrowed the gap between textbook security and real configurations while making non-inheritance to arbitrary forks an explicit boundary.","technical_delta":"The work models specified optimized PLONK- and Marlin-style configurations and proves simulation extractability under its declared conditions rather than abstracting the optimizations away."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2024-REALWORLD-SE","keywords":["simulation-extractability","plonk","marlin","non-malleability","security-analysis"],"lens":"security-audit","limitations":["does not automatically cover arbitrary forks backends or undocumented optimizations"],"paper_id":"PROOF-PAPER-2024-REALWORLD-SE","qualifiers":["optimized universal PIOP configurations","stated PLONK and Marlin variants","simulation extractability"],"research_lenses":["security-audit"],"role":"security_analysis","security_model":"Simulation extractability under the paper's model and assumptions","source_locator":{"dossier_section":"PROOF-PAPER-2024-REALWORLD-SE § Main theorems","primary_source":"Abstract; main theorems and optimization coverage","primary_source_url":"https://eprint.iacr.org/2024/721","status":"theorem_checked"},"statement":"The paper establishes simulation extractability for optimized real-world PLONK- and Marlin-style universal zkSNARK configurations satisfying its stated protocol, backend, and optimization conditions.","statement_status":"source_normalized_statement","status":"published","title":"Optimized PLONK- and Marlin-style configurations receive simulation-extractability proofs","visibility":"backbone","work_id":"PROOF-PAPER-2024-REALWORLD-SE","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/721","sections":[{"content":"Real-world universal zkSNARK security The configuration conditions remain attached to the contribution and are visible in the claim-audit view.","heading":"Overview"}],"status":"published","subtitle":"Real-world Universal zkSNARKs are Non-malleable","summary":"The paper establishes simulation extractability for optimized real-world PLONK- and Marlin-style universal zkSNARK configurations satisfying its stated protocol, backend, and optimization conditions.","tags":["atomic-result","backbone","security-audit","security_analysis"],"title":"Optimized PLONK- and Marlin-style configurations receive simulation-extractability proofs","type":"result","venue":"ACM CCS 2024","year":2024,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2024-REALWORLD-SE"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2024-WHIR-PROXIMITY","metadata":{"claim_slug":"whir-proximity","contribution_kind":"optimization","contribution_role":"component_construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"component_role":["coded-oracle-backend"],"mechanism":["reed-solomon-proximity"],"optimized_resource":["verifier-work"]},"historical_context":{"narrative":"FRI-family coded-oracle protocols made transparent hash-based polynomial commitments practical, but their verifier work remained an important cost, especially when verification is embedded or bandwidth constrained. WHIR reorganizes the Reed–Solomon proximity test and its folding structure to target a much faster verifier, then derives hash-based polynomial-commitment configurations from the protocol. The atomic delta is verifier efficiency in this transparent coded-oracle line, not a claim of constant proof size or universal superiority across fields, rates, and soundness settings. At publication it supplied a new transparent backend point for systems whose bottleneck is verifier cost while preserving explicit parameter and configuration dependence.","prior_boundary":"FRI-family proximity tests made transparent hash-based commitments practical, but verifier arithmetic and query costs remained prominent in recursive and client-constrained settings.","significance_at_publication":"It shifted the transparent PCS frontier specifically on verifier efficiency without turning the result into a constant-size or configuration-independent claim.","technical_delta":"WHIR reorganizes folding and proximity checks to obtain the paper's super-fast verification profile and derives polynomial-commitment configurations from that coded-oracle protocol."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2024-WHIR-PROXIMITY","keywords":["whir","proximity-testing","reed-solomon","polynomial-commitment","verifier"],"lens":"transparent-hash","limitations":["not constant-size","comparative performance depends on field rate security and implementation configuration"],"paper_id":"PROOF-PAPER-2024-WHIR","qualifiers":["Reed-Solomon proximity testing","hash-based commitments","parameter-dependent verifier improvement"],"research_lenses":["transparent-hash"],"role":"component_construction","source_locator":{"dossier_section":"PROOF-PAPER-2024-WHIR § Proximity test and PCS","primary_source":"Abstract; Sections 1 and 7","primary_source_url":"https://eprint.iacr.org/2024/1586","status":"section_checked"},"statement":"WHIR introduces a Reed–Solomon proximity-testing framework and resulting hash-based polynomial commitments designed to reduce verifier work relative to the compared transparent coded-oracle constructions.","statement_status":"source_normalized_statement","status":"published","title":"WHIR reduces verifier cost in Reed–Solomon proximity testing and hash-based PCS","visibility":"backbone","work_id":"PROOF-PAPER-2024-WHIR","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/1586","sections":[{"content":"WHIR verifier optimization The title identifies the affected resource rather than using “fast” without a coordinate.","heading":"Overview"}],"status":"published","subtitle":"WHIR: Reed–Solomon Proximity Testing with Super-Fast Verification","summary":"WHIR introduces a Reed–Solomon proximity-testing framework and resulting hash-based polynomial commitments designed to reduce verifier work relative to the compared transparent coded-oracle constructions.","tags":["atomic-result","backbone","component_construction","transparent-hash"],"title":"WHIR reduces verifier cost in Reed–Solomon proximity testing and hash-based PCS","type":"result","venue":"EUROCRYPT 2025","year":2024,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2024-WHIR-PROXIMITY"},{"evidence":"fulltext_checked","id":"PROOF-CONTRIB-2025-BOOSTING-SNARKS","metadata":{"claim_slug":"boosting-snarks","contribution_kind":"transform","contribution_role":"compiler","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"input":["mildly-succinct-snark"],"mechanism":["succinctness-compiler"],"target":["fully-succinct-snark"]},"historical_context":{"narrative":"A mildly succinct knowledge argument can already beat direct verification without reaching proof and verifier costs polylogarithmic in the entire NP computation. Cheng and Goyal show that, when such an argument satisfies their hypotheses and is paired with suitable RAM delegation, it can be compiled into a fully succinct SNARK while preserving whether extraction uses black-box or non-black-box access. The atomic contribution is this conditional succinctness booster, not a construction of the required base SNARK from standard assumptions. It mattered because the frontier could be decomposed: one line can seek the mildly succinct knowledge-sound base object, while the compiler handles the remaining jump to full succinctness.","prior_boundary":"Constructions achieving only mild succinctness did not automatically yield proof length and verifier work polylogarithmic in the full NP computation time, and generic boosting could lose knowledge-soundness structure.","significance_at_publication":"It reduced the all-NP full-succinctness problem to constructing an appropriate mildly succinct base object rather than solving every cost coordinate at once.","technical_delta":"The paper combines a suitable mildly succinct knowledge argument with RAM delegation to obtain full succinctness while preserving the extractor-access character of the base scheme."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2025-BOOSTING-SNARKS","keywords":["snark","succinctness","compiler","ram-delegation","knowledge-soundness"],"lens":"foundations","limitations":["does not construct the mildly succinct base SNARK from standard assumptions"],"paper_id":"PROOF-PAPER-2025-BOOSTING-SNARKS","qualifiers":["conditional compiler","RAM delegation","knowledge-sound base argument"],"research_lenses":["foundations"],"role":"compiler","source_locator":{"dossier_section":"PROOF-PAPER-2025-BOOSTING-SNARKS § Main boosting theorems","primary_source":"Introduction; Theorems 1–2 and Corollary 3","primary_source_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ICALP.2025.56","status":"theorem_checked"},"statement":"Given suitable RAM delegation, the compiler promotes a mildly succinct SNARK for NP to a fully succinct SNARK while preserving whether the base extractor is black box or non-black box.","statement_status":"source_normalized_statement","status":"published","title":"RAM delegation boosts mildly succinct knowledge arguments to full succinctness","visibility":"reviewed_related","work_id":"PROOF-PAPER-2025-BOOSTING-SNARKS","year":2025},"primaryUrl":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ICALP.2025.56","sections":[{"content":"Succinctness boosting The input assumption is kept in the title story and limitations rather than hidden behind “boosting.”","heading":"Overview"}],"status":"published","subtitle":"Boosting SNARKs and Rate-1 Barrier in Arguments of Knowledge","summary":"Given suitable RAM delegation, the compiler promotes a mildly succinct SNARK for NP to a fully succinct SNARK while preserving whether the base extractor is black box or non-black box.","tags":["atomic-result","compiler","foundations","reviewed_related"],"title":"RAM delegation boosts mildly succinct knowledge arguments to full succinctness","type":"result","venue":"ICALP 2025","year":2025,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2025-BOOSTING-SNARKS"},{"evidence":"abstract_checked","id":"PROOF-CONTRIB-2025-GALOIS-RINGS","metadata":{"claim_slug":"galois-rings","contribution_kind":"capability_result","contribution_role":"system_construction","dossier_type":"contribution","evidence":"abstract_checked","facet_status":"partially_normalized","facets":{"capability":["galois-ring-computation"],"evidence_boundary":["abstract-checked"],"setup":["transparent"]},"historical_context":{"narrative":"Transparent SNARK constructions are usually presented over fields, so computations naturally expressed over rings can fall outside the assumed algebraic interface. This work extends expander-code commitment machinery and existing proof frameworks to arbitrary Galois rings and states transparent constructions with sublinear proof and verifier bounds. The atomic contribution is the supported algebraic domain, not a new universal performance ranking across field- and ring-based systems. Its publication-time significance is that ring-native computation can be treated inside a transparent succinct-proof framework. Only the abstract and construction overview have been checked here, however, so theorem scope and the exact configuration still require a full-text audit before this result can carry a default-map transition.","prior_boundary":"Transparent SNARK frameworks and their commitment layers were primarily formulated over fields or narrower algebraic domains, leaving arbitrary Galois-ring computation outside the normalized system comparison.","significance_at_publication":"It broadens the algebraic computation domain, but the atlas retains it as catalog-only until theorem-level locators and configuration details are audited.","technical_delta":"The work adapts expander-code commitments and proof-system machinery to Galois rings and states transparent constructions with sublinear proof and verifier bounds over that broader domain."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2025-GALOIS-RINGS","keywords":["galois-rings","transparent-snark","expander-code","catalog-only"],"lens":"transparent-hash","limitations":["full theorem scope not yet audited","exact backend and security coordinates remain to be normalized"],"paper_id":"PROOF-PAPER-2025-GALOIS","qualifiers":["arbitrary Galois rings","transparent setup","source-stated sublinear bounds"],"research_lenses":["transparent-hash"],"role":"system_construction","source_locator":{"dossier_section":"PROOF-PAPER-2025-GALOIS § Construction overview","primary_source":"Abstract and construction overview","primary_source_url":"https://eprint.iacr.org/2025/263","status":"abstract_checked"},"statement":"The paper extends expander-code commitments and existing proof frameworks to transparent SNARK constructions over arbitrary Galois rings with the sublinear verifier and proof bounds stated in its abstract.","statement_status":"source_normalized_statement","status":"published","title":"Transparent SNARK constructions extend to arbitrary Galois rings","visibility":"catalog_only","work_id":"PROOF-PAPER-2025-GALOIS","year":2025},"primaryUrl":"https://eprint.iacr.org/2025/263","sections":[{"content":"Galois-ring transparent SNARKs This contribution is intentionally excluded from the research map pending theorem-level review.","heading":"Overview"}],"status":"published","subtitle":"Transparent SNARKs over Galois Rings","summary":"The paper extends expander-code commitments and existing proof frameworks to transparent SNARK constructions over arbitrary Galois rings with the sublinear verifier and proof bounds stated in its abstract.","tags":["atomic-result","catalog_only","system_construction","transparent-hash"],"title":"Transparent SNARK constructions extend to arbitrary Galois rings","type":"result","venue":"PKC 2025","year":2025,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2025-GALOIS-RINGS"},{"evidence":"fulltext_checked","id":"PROOF-CONTRIB-2025-IBCS-QUANTUM","metadata":{"claim_scope":"Interactive BCS with the paper's semi-adaptive IOP and collapsing commitment conditions","claim_slug":"ibcs-quantum","contribution_kind":"security_analysis","contribution_role":"security_analysis","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"adaptivity":["semi-adaptive"],"compiler":["interactive-bcs"],"security_notions":["post-quantum-soundness","unruh-knowledge-soundness"]},"historical_context":{"narrative":"Turning an IOP into a succinct argument classically uses extraction and rewinding steps that do not automatically remain valid against a quantum prover. This work analyzes interactive BCS with a semi-adaptive public-coin IOP and a collapse-position-binding vector commitment, proving post-quantum soundness and an Unruh-style knowledge-soundness notion for that exact interface. The atomic contribution is the quantum security reduction and its stated prerequisites, not fully adaptive IOP security or state-preserving extraction. At publication it established a concrete post-quantum compiler theorem and, equally importantly, separated ordinary knowledge extraction from the stronger compositional properties that remain open.","prior_boundary":"Classical IOP-to-argument analyses did not automatically survive quantum rewinding, and existing post-quantum results did not provide the paper's knowledge-soundness theorem for the same interactive BCS interface.","significance_at_publication":"It supplies a configuration-scoped post-quantum theorem while identifying fully adaptive IOPs and state-preserving extraction as genuinely stronger open boundaries.","technical_delta":"The work develops a quantum-rewinding analysis for semi-adaptive public-coin IOPs combined with collapse-position-binding vector commitments and proves the stated soundness and extraction notions."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2025-IBCS-QUANTUM","keywords":["ibcs","quantum-rewinding","post-quantum","knowledge-soundness"],"lens":"security-audit","limitations":["does not prove fully adaptive IOP security","does not prove state-preserving or witness-extended extraction"],"paper_id":"PROOF-PAPER-2025-IBCS-QUANTUM","qualifiers":["interactive BCS","semi-adaptive public-coin IOP","collapse-position-binding vector commitment"],"research_lenses":["security-audit"],"role":"security_analysis","security_model":"Quantum soundness and Unruh-style knowledge soundness","source_locator":{"dossier_section":"PROOF-PAPER-2025-IBCS-QUANTUM § Quantum security theorems","primary_source":"Theorem 1; Theorem 6.1; Remark 2.1","primary_source_url":"https://eprint.iacr.org/2025/947","status":"theorem_checked"},"statement":"The paper proves post-quantum soundness and Unruh-style knowledge soundness for interactive BCS instantiated with a semi-adaptive public-coin IOP and a collapse-position-binding vector commitment.","statement_status":"source_normalized_statement","status":"published","title":"Interactive BCS gains post-quantum soundness and Unruh-style knowledge soundness","visibility":"backbone","work_id":"PROOF-PAPER-2025-IBCS-QUANTUM","year":2025},"primaryUrl":"https://eprint.iacr.org/2025/947","sections":[{"content":"Quantum IBCS security The card's non-claims align with the open-problem record for stronger extraction.","heading":"Overview"}],"status":"published","subtitle":"Quantum Rewinding for IOP-Based Succinct Arguments","summary":"The paper proves post-quantum soundness and Unruh-style knowledge soundness for interactive BCS instantiated with a semi-adaptive public-coin IOP and a collapse-position-binding vector commitment.","tags":["atomic-result","backbone","security-audit","security_analysis"],"title":"Interactive BCS gains post-quantum soundness and Unruh-style knowledge soundness","type":"result","venue":"TCC 2025","year":2025,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2025-IBCS-QUANTUM"},{"evidence":"primary_source_checked","id":"PROOF-CONTRIB-2025-JOLT-SPACE","metadata":{"claim_slug":"jolt-space","contribution_kind":"optimization","contribution_role":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized","facets":{"affected_system":["jolt"],"mechanism":["streaming","recomputation"],"optimized_resource":["prover-memory"]},"historical_context":{"narrative":"Jolt's lookup-centric proof stack can require the honest prover to retain large witness and polynomial state, making peak memory a practical limit even when asymptotic prover time is attractive. Recursive sharding can reduce memory but changes the architecture and adds recursive proof overhead. This work instead streams witness-dependent data, recomputes selected values, and reorganizes sum-check state to expose an explicit time–space tradeoff within the Jolt stack. The atomic contribution is the prover algorithm, not a new proof system or a universal benchmark result. It mattered because memory became a first-class optimization target that can be studied independently from the VM semantics, commitment backend, and recursive composition choice.","prior_boundary":"Jolt's lookup and sum-check stack could require memory proportional to large execution traces, and recursive sharding reduced peak memory only by changing the proof architecture and adding recursion overhead.","significance_at_publication":"It made prover memory an algorithmic optimization coordinate of the existing stack rather than treating low memory as a property of a new scheme family.","technical_delta":"The new prover schedules streaming, recomputation, and sum-check state so peak space falls without recursively splitting the computation, at a parameterized increase in work."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2025-JOLT-SPACE","keywords":["jolt","prover-memory","streaming","recomputation","optimization"],"lens":"lookups-zkvm","limitations":["does not remove all implementation memory overhead","concrete benefit depends on configuration and workload"],"paper_id":"PROOF-PAPER-2025-JOLT-SPACE","qualifiers":["honest prover","Jolt stack","streaming and recomputation","explicit time-space tradeoff"],"research_lenses":["lookups-zkvm"],"role":"optimization","source_locator":{"dossier_section":"PROOF-PAPER-2025-JOLT-SPACE § Small-space prover","primary_source":"Abstract; Theorem 7.1 and Section 7","primary_source_url":"https://eprint.iacr.org/2025/611","status":"theorem_checked"},"statement":"The paper gives a small-space honest-prover strategy for the Jolt stack by streaming witness-dependent data and recomputing selected values, with an explicit time–space tradeoff rather than recursion-based sharding.","statement_status":"source_normalized_statement","status":"published","title":"Streaming and recomputation reduce Jolt honest-prover memory","visibility":"reviewed_related","work_id":"PROOF-PAPER-2025-JOLT-SPACE","year":2025},"primaryUrl":"https://eprint.iacr.org/2025/611","sections":[{"content":"Small-space Jolt prover The optimization remains linked to Jolt rather than being promoted as a peer scheme.","heading":"Overview"}],"status":"published","subtitle":"Proving CPU Executions in Small Space","summary":"The paper gives a small-space honest-prover strategy for the Jolt stack by streaming witness-dependent data and recomputing selected values, with an explicit time–space tradeoff rather than recursion-based sharding.","tags":["atomic-result","lookups-zkvm","optimization","reviewed_related"],"title":"Streaming and recomputation reduce Jolt honest-prover memory","type":"result","venue":"IACR ePrint 2025/611","year":2025,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2025-JOLT-SPACE"},{"evidence":"fulltext_checked","id":"PROOF-CONTRIB-2026-SNARG-UNPROVABILITY","metadata":{"claim_slug":"snarg-unprovability","contribution_kind":"boundary_result","contribution_role":"construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized","facets":{"assumptions":["lwe","sxdh","hardness-certification"],"capability":["all-np-snarg"],"soundness":["non-adaptive"]},"historical_context":{"narrative":"Standard-model succinct arguments for all NP had remained beyond constructions based only on familiar falsifiable assumptions, with positive results either restricting the relation class or invoking stronger idealizations. This work reaches all NP by combining prBPP = prP, LWE, SXDH, and a new Hardness Certification assumption asserting difficulty of proving certain Extended-Frege lower bounds inside a weak theory. The atomic contribution is the resulting non-adaptively sound feasibility theorem and its exact assumption set, not a resolution under standard assumptions. It mattered because the all-NP boundary moved, while adaptive soundness and removal of the proof-unprovability assumption became explicit, separately testable residual goals.","prior_boundary":"Standard-model succinct arguments for all NP under ordinary falsifiable assumptions remained out of reach, with prior positive results covering restricted classes or using stronger idealized and knowledge-style assumptions.","significance_at_publication":"It changes the all-NP feasibility boundary while isolating adaptivity and removal of the new assumption as distinct residual targets.","technical_delta":"The construction reaches all NP and succinct non-adaptive soundness by combining standard cryptographic ingredients with a new proof-complexity unprovability assumption formalized as Hardness Certification."},"historical_context_status":"curator_synthesis","id":"PROOF-CONTRIB-2026-SNARG-UNPROVABILITY","keywords":["snarg","all-np","standard-model","proof-complexity","non-adaptive"],"lens":"foundations","limitations":["uses a new proof-complexity unprovability assumption","does not achieve adaptive soundness"],"paper_id":"PROOF-PAPER-2026-SNARG-UNPROVABILITY","qualifiers":["all NP","non-adaptive soundness","CRS standard model","Hardness Certification"],"research_lenses":["foundations"],"role":"construction","source_locator":{"dossier_section":"PROOF-PAPER-2026-SNARG-UNPROVABILITY § Main theorem","primary_source":"Abstract; Section 1.1; Theorem 1.1","primary_source_url":"https://eccc.weizmann.ac.il/report/2026/098/","status":"theorem_checked"},"statement":"The paper constructs a non-adaptively sound SNARG for all NP from prBPP = prP, LWE, SXDH, and a Hardness Certification assumption about proving Extended-Frege lower bounds in a weak bounded-arithmetic theory.","statement_status":"source_normalized_statement","status":"published","title":"All-NP non-adaptive SNARGs from cryptography plus proof-unprovability","visibility":"reviewed_related","work_id":"PROOF-PAPER-2026-SNARG-UNPROVABILITY","year":2026},"primaryUrl":"https://eccc.weizmann.ac.il/report/2026/098/","sections":[{"content":"All-NP SNARG feasibility boundary The contribution and the residual open problem are intentionally separate records.","heading":"Overview"}],"status":"preprint","subtitle":"SNARGs for NP from Unprovability of Mathematical Theorems","summary":"The paper constructs a non-adaptively sound SNARG for all NP from prBPP = prP, LWE, SXDH, and a Hardness Certification assumption about proving Extended-Frege lower bounds in a weak bounded-arithmetic theory.","tags":["atomic-result","construction","foundations","reviewed_related"],"title":"All-NP non-adaptive SNARGs from cryptography plus proof-unprovability","type":"result","venue":"ECCC TR26-098","year":2026,"sourcePath":"data/proof-systems-catalog.json#PROOF-CONTRIB-2026-SNARG-UNPROVABILITY"},{"evidence":"primary_source_checked","id":"PROOF-ROUTE-001","metadata":{"current_bottleneck":"The compiler assumes the central missing base object; known all-NP candidates either add non-falsifiable or proof-unprovability assumptions or weaken soundness.","dossier_type":"route","entry_results":["PROOF-PAPER-2025-BOOSTING-SNARKS"],"evidence":"primary_source_checked","falsifiable_next_test":"For one candidate mild all-NP argument, write the exact extractor runtime and succinctness factor and check every hypothesis of Theorems 1–2 before attempting the recursive boost.","id":"PROOF-ROUTE-001","mechanism":"Instantiate the Cheng–Goyal mild-to-full compiler with a mildly succinct, adaptively knowledge-sound argument for all NP whose base security uses standard falsifiable assumptions and whose extractor satisfies the compiler's efficiency requirement.","status":"source_grounded_route","targets":["PROOF-OP-001"],"title":"Bootstrap a mild standard-assumption SNARK to full succinctness"},"primaryUrl":null,"sections":[{"content":"The compiler is conditional progress, not itself a construction of the missing standard-assumption base SNARK.","heading":"Route boundary"}],"status":"source_grounded_route","subtitle":"","summary":"The compiler is conditional progress, not itself a construction of the missing standard-assumption base SNARK.","tags":[],"title":"Bootstrap a mild standard-assumption SNARK to full succinctness","type":"route","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-ROUTE-001"},{"evidence":"primary_source_checked","id":"PROOF-ROUTE-002","metadata":{"current_bottleneck":"Existing folding and proximity paths pay at least logarithmic transcript or verification cost, while known constant endpoints use non-post-quantum groups of unknown order.","dossier_type":"route","entry_results":["PROOF-PAPER-2024-LATTICE-PCS","PROOF-PAPER-2024-WHIR"],"evidence":"primary_source_checked","falsifiable_next_test":"Specify one proposed terminal compression and either prove degree-independent verifier work plus quantum binding, or exhibit the exact transcript/commitment term that still grows with log N.","id":"PROOF-ROUTE-002","mechanism":"Start from a quantum-audited hash- or lattice-based folding/proximity PCS and seek a degree-independent terminal check or recursion that preserves transparent setup and quantum extractability.","status":"source_grounded_route","targets":["PROOF-OP-002"],"title":"Compress transparent post-quantum polynomial openings past the logarithmic frontier"},"primaryUrl":null,"sections":[{"content":"Recursive compression is useful only if its own verification and extraction do not reintroduce an N-dependent cost or a non-post-quantum assumption.","heading":"Route boundary"}],"status":"source_grounded_route","subtitle":"","summary":"Recursive compression is useful only if its own verification and extraction do not reintroduce an N-dependent cost or a non-post-quantum assumption.","tags":[],"title":"Compress transparent post-quantum polynomial openings past the logarithmic frontier","type":"route","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-ROUTE-002"},{"evidence":"primary_source_checked","id":"PROOF-ROUTE-003","metadata":{"current_bottleneck":"The present reduction extracts an IOP adversary and proves the stated knowledge notion, but it does not return the stronger environment-compatible state required for witness-extended or state-preserving extraction.","dossier_type":"route","entry_results":["PROOF-PAPER-2025-IBCS-QUANTUM"],"evidence":"primary_source_checked","falsifiable_next_test":"Formalize a one-round state-distance invariant for the IBCS opening measurement and prove or refute that the repair procedure preserves it under collapse-position binding.","id":"PROOF-ROUTE-003","mechanism":"Refine the multi-round quantum rewinding reduction so each extraction/repair step maintains an invariant relating the adversary's residual state to an accepting real transcript, then compose these bounds across IOP rounds.","status":"source_grounded_route","targets":["PROOF-OP-003"],"title":"Coherent rewinding with an explicit residual-state invariant"},"primaryUrl":null,"sections":[{"content":"A smaller knowledge-error bound without a residual-state guarantee does not advance this route's defining extraction property.","heading":"Route boundary"}],"status":"source_grounded_route","subtitle":"","summary":"A smaller knowledge-error bound without a residual-state guarantee does not advance this route's defining extraction property.","tags":[],"title":"Coherent rewinding with an explicit residual-state invariant","type":"route","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-ROUTE-003"},{"evidence":"primary_source_checked","id":"PROOF-ROUTE-004","metadata":{"current_bottleneck":"The non-interactive challenge must remain unpredictable and extractable across recursive accumulation without programming a random oracle or assuming knowledge of committed exponents.","dossier_type":"route","entry_results":["PROOF-PAPER-2020-ACCUMULATION","PROOF-PAPER-2023-PROTOSTAR"],"evidence":"primary_source_checked","falsifiable_next_test":"Apply one candidate standard-model compiler to the two-instance accumulation game and either prove its adaptive knowledge-soundness reduction or produce a concrete circularity/dangling-extraction failure.","id":"PROOF-ROUTE-004","mechanism":"Isolate the exact challenge/commitment interface used by a special-sound folding or accumulation protocol and replace the Fiat–Shamir step with a standard-model non-interactive compiler under a named falsifiable assumption not already known to imply general SNARKs.","status":"source_grounded_route","targets":["PROOF-OP-004"],"title":"Standard-model compilation of a special-sound accumulation protocol"},"primaryUrl":null,"sections":[{"content":"Replacing the random oracle by a concrete hash function is a heuristic instantiation, not a standard-model proof for this target.","heading":"Route boundary"}],"status":"source_grounded_route","subtitle":"","summary":"Replacing the random oracle by a concrete hash function is a heuristic instantiation, not a standard-model proof for this target.","tags":[],"title":"Standard-model compilation of a special-sound accumulation protocol","type":"route","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-ROUTE-004"},{"evidence":"primary_source_checked","id":"PROOF-COMP-AIR","metadata":{"component_kind":"arithmetization","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-AIR","paper_ids":["PROOF-PAPER-2018-STARK"],"status":"published","tags":["air","trace","transition-constraints"],"title":"Algebraic Intermediate Representation (AIR)"},"primaryUrl":null,"sections":[{"content":"Represents an execution trace with boundary and transition constraints over a field for coded-oracle proof systems.","heading":"Role"}],"status":"published","subtitle":"arithmetization","summary":"Represents an execution trace with boundary and transition constraints over a field for coded-oracle proof systems.","tags":["air","trace","transition-constraints"],"title":"Algebraic Intermediate Representation (AIR)","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-AIR"},{"evidence":"primary_source_checked","id":"PROOF-COMP-CCS","metadata":{"component_kind":"arithmetization","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-CCS","paper_ids":["PROOF-PAPER-2023-HYPERNOVA"],"status":"published","tags":["ccs","r1cs","plonkish","air"],"title":"Customizable Constraint Systems (CCS)"},"primaryUrl":null,"sections":[{"content":"Provides a common customizable relation format used by HyperNova to cover R1CS-, PLONKish-, and AIR-like constraints while retaining a folding-compatible interface.","heading":"Role"}],"status":"published","subtitle":"arithmetization","summary":"Provides a common customizable relation format used by HyperNova to cover R1CS-, PLONKish-, and AIR-like constraints while retaining a folding-compatible interface.","tags":["air","ccs","plonkish","r1cs"],"title":"Customizable Constraint Systems (CCS)","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-CCS"},{"evidence":"source_normalized","id":"PROOF-COMP-CIRCUIT","metadata":{"component_kind":"computation_model","dossier_type":"technique","evidence":"source_normalized","id":"PROOF-COMP-CIRCUIT","paper_ids":["PROOF-PAPER-2016-GROTH"],"status":"catalogued","tags":["circuit","computation-model"],"title":"Arithmetic circuit computation model"},"primaryUrl":null,"sections":[{"content":"Represents a computation as additions and multiplications over a field before a separate arithmetization encodes satisfiability.","heading":"Role"}],"status":"catalogued","subtitle":"computation model","summary":"Represents a computation as additions and multiplications over a field before a separate arithmetization encodes satisfiability.","tags":["circuit","computation-model"],"title":"Arithmetic circuit computation model","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-CIRCUIT"},{"evidence":"primary_source_checked","id":"PROOF-COMP-FIAT-SHAMIR","metadata":{"component_kind":"compiler","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-FIAT-SHAMIR","paper_ids":["PROOF-PAPER-1986-FS"],"status":"published","tags":["fiat-shamir","random-oracle","non-interactive"],"title":"Fiat–Shamir compiler"},"primaryUrl":null,"sections":[{"content":"Derives verifier challenges from a transcript hash to compile suitable public-coin protocols into non-interactive ones. Security is attached to a concrete transcript and model.","heading":"Role"}],"status":"published","subtitle":"compiler","summary":"Derives verifier challenges from a transcript hash to compile suitable public-coin protocols into non-interactive ones. Security is attached to a concrete transcript and model.","tags":["fiat-shamir","non-interactive","random-oracle"],"title":"Fiat–Shamir compiler","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-FIAT-SHAMIR"},{"evidence":"source_normalized","id":"PROOF-COMP-FRI","metadata":{"component_kind":"commitment_backend","dossier_type":"technique","evidence":"source_normalized","id":"PROOF-COMP-FRI","paper_ids":["PROOF-PAPER-2018-STARK","PROOF-PAPER-2024-WHIR"],"status":"published","tags":["fri","proximity-testing","reed-solomon","merkle"],"title":"FRI-style coded-oracle proximity backend"},"primaryUrl":null,"sections":[{"content":"Combines code proximity testing with hash-authenticated oracle access. FRI/WHIR-style proximity machinery is distinguished from algebraic PCS backends such as KZG.","heading":"Role"}],"status":"published","subtitle":"commitment backend","summary":"Combines code proximity testing with hash-authenticated oracle access. FRI/WHIR-style proximity machinery is distinguished from algebraic PCS backends such as KZG.","tags":["fri","merkle","proximity-testing","reed-solomon"],"title":"FRI-style coded-oracle proximity backend","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-FRI"},{"evidence":"primary_source_checked","id":"PROOF-COMP-INNER-PRODUCT","metadata":{"component_kind":"protocol_iop","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-INNER-PRODUCT","paper_ids":["PROOF-PAPER-2017-BULLETPROOFS","PROOF-PAPER-2019-HALO"],"status":"published","tags":["inner-product-argument","logarithmic-protocol","discrete-log"],"title":"Logarithmic inner-product argument"},"primaryUrl":null,"sections":[{"content":"Recursively reduces an inner-product relation to smaller instances. It is an interactive argument component; the homomorphic vector commitment beneath it is a separate backend role.","heading":"Role"}],"status":"published","subtitle":"protocol iop","summary":"Recursively reduces an inner-product relation to smaller instances. It is an interactive argument component; the homomorphic vector commitment beneath it is a separate backend role.","tags":["discrete-log","inner-product-argument","logarithmic-protocol"],"title":"Logarithmic inner-product argument","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-INNER-PRODUCT"},{"evidence":"source_normalized","id":"PROOF-COMP-IPA","metadata":{"component_kind":"commitment_backend","dossier_type":"technique","evidence":"source_normalized","id":"PROOF-COMP-IPA","paper_ids":["PROOF-PAPER-2017-BULLETPROOFS","PROOF-PAPER-2019-HALO","PROOF-PAPER-2021-NOVA"],"status":"published","tags":["pedersen","homomorphic-vector-commitment","discrete-log","no-trusted-setup"],"title":"Pedersen / homomorphic vector commitment backend"},"primaryUrl":null,"sections":[{"content":"Represents the discrete-log homomorphic vector-commitment layer used beneath inner-product arguments and folding systems. The interactive inner-product protocol is stored separately because it plays a different stack role.","heading":"Role"}],"status":"published","subtitle":"commitment backend","summary":"Represents the discrete-log homomorphic vector-commitment layer used beneath inner-product arguments and folding systems. The interactive inner-product protocol is stored separately because it plays a different stack role.","tags":["discrete-log","homomorphic-vector-commitment","no-trusted-setup","pedersen"],"title":"Pedersen / homomorphic vector commitment backend","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-IPA"},{"evidence":"primary_source_checked","id":"PROOF-COMP-KZG","metadata":{"component_kind":"commitment_backend","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-KZG","paper_ids":["PROOF-PAPER-2010-KZG"],"status":"published","tags":["kzg","pairing","univariate-pcs","structured-setup"],"title":"KZG polynomial commitment"},"primaryUrl":null,"sections":[{"content":"Provides constant-size commitments and evaluation openings for bounded-degree univariate polynomials using pairing groups and structured public parameters.","heading":"Role"}],"status":"published","subtitle":"commitment backend","summary":"Provides constant-size commitments and evaluation openings for bounded-degree univariate polynomials using pairing groups and structured public parameters.","tags":["kzg","pairing","structured-setup","univariate-pcs"],"title":"KZG polynomial commitment","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-KZG"},{"evidence":"primary_source_checked","id":"PROOF-COMP-LOOKUP","metadata":{"component_kind":"specialized_argument","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-LOOKUP","paper_ids":["PROOF-PAPER-2023-JOLT","PROOF-PAPER-2023-PROTOSTAR"],"status":"published","tags":["lookup","lasso","vector-lookup","zkvm"],"title":"Structured lookup argument"},"primaryUrl":null,"sections":[{"content":"Proves that values occur in a committed or structured table. Lookup is a reusable subargument, not a computation model or complete zkVM.","heading":"Role"}],"status":"published","subtitle":"specialized argument","summary":"Proves that values occur in a committed or structured table. Lookup is a reusable subargument, not a computation model or complete zkVM.","tags":["lasso","lookup","vector-lookup","zkvm"],"title":"Structured lookup argument","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-LOOKUP"},{"evidence":"primary_source_checked","id":"PROOF-COMP-MEMORY-CHECK","metadata":{"component_kind":"specialized_argument","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-MEMORY-CHECK","paper_ids":["PROOF-PAPER-2023-JOLT","PROOF-PAPER-2025-JOLT-SPACE"],"status":"published","tags":["memory-checking","ram","zkvm"],"title":"Read/write memory-checking argument"},"primaryUrl":null,"sections":[{"content":"Proves consistency of register and RAM reads and writes. It is a specialized subargument in the zkVM stack, distinct from instruction lookups and the residual R1CS proof.","heading":"Role"}],"status":"published","subtitle":"specialized argument","summary":"Proves consistency of register and RAM reads and writes. It is a specialized subargument in the zkVM stack, distinct from instruction lookups and the residual R1CS proof.","tags":["memory-checking","ram","zkvm"],"title":"Read/write memory-checking argument","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-MEMORY-CHECK"},{"evidence":"source_normalized","id":"PROOF-COMP-MLPCS","metadata":{"component_kind":"commitment_backend","dossier_type":"technique","evidence":"source_normalized","id":"PROOF-COMP-MLPCS","paper_ids":["PROOF-PAPER-2019-SPARTAN","PROOF-PAPER-2023-JOLT","PROOF-PAPER-2024-WHIR"],"status":"published","tags":["multilinear-pcs","spark","backend-interface"],"title":"Extractable multilinear polynomial commitment interface"},"primaryUrl":null,"sections":[{"content":"Binds multilinear polynomial evaluations for sum-check-based systems. Concrete group- or code-based instantiations have different setup, verifier, and quantum-security properties, so the interface never supplies those properties by inheritance.","heading":"Role"}],"status":"published","subtitle":"commitment backend","summary":"Binds multilinear polynomial evaluations for sum-check-based systems. Concrete group- or code-based instantiations have different setup, verifier, and quantum-security properties, so the interface never supplies those properties by inheritance.","tags":["backend-interface","multilinear-pcs","spark"],"title":"Extractable multilinear polynomial commitment interface","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-MLPCS"},{"evidence":"primary_source_checked","id":"PROOF-COMP-MULTIFOLD","metadata":{"component_kind":"composition_mechanism","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-MULTIFOLD","paper_ids":["PROOF-PAPER-2023-HYPERNOVA"],"status":"published","tags":["multi-folding","ccs"],"title":"CCS multi-folding"},"primaryUrl":null,"sections":[{"content":"Represents HyperNova's sum-check-based mechanism for folding multiple CCS instances in one step. Generic special-sound accumulation is a separate component because it accepts a different protocol interface.","heading":"Role"}],"status":"published","subtitle":"composition mechanism","summary":"Represents HyperNova's sum-check-based mechanism for folding multiple CCS instances in one step. Generic special-sound accumulation is a separate component because it accepts a different protocol interface.","tags":["ccs","multi-folding"],"title":"CCS multi-folding","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-MULTIFOLD"},{"evidence":"primary_source_checked","id":"PROOF-COMP-PAIRING-QAP","metadata":{"component_kind":"protocol_iop","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-PAIRING-QAP","paper_ids":["PROOF-PAPER-2016-GROTH"],"status":"published","tags":["pairing","qap","succinct-argument"],"title":"Pairing-based QAP argument"},"primaryUrl":null,"sections":[{"content":"Encodes QAP witness relations into structured group elements and pairing equations. It is not modeled as a modular PCS substitution point.","heading":"Role"}],"status":"published","subtitle":"protocol iop","summary":"Encodes QAP witness relations into structured group elements and pairing equations. It is not modeled as a modular PCS substitution point.","tags":["pairing","qap","succinct-argument"],"title":"Pairing-based QAP argument","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-PAIRING-QAP"},{"evidence":"primary_source_checked","id":"PROOF-COMP-PLONKISH","metadata":{"component_kind":"arithmetization","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-PLONKISH","paper_ids":["PROOF-PAPER-2019-PLONK","PROOF-PAPER-2023-PROTOSTAR"],"status":"published","tags":["plonkish","permutation","custom-gates"],"title":"PLONKish polynomial constraints"},"primaryUrl":null,"sections":[{"content":"Uses polynomial identities and permutation-style consistency checks for wired arithmetic constraints. The term names an arithmetization family, not every complete system called PLONK.","heading":"Role"}],"status":"published","subtitle":"arithmetization","summary":"Uses polynomial identities and permutation-style consistency checks for wired arithmetic constraints. The term names an arithmetization family, not every complete system called PLONK.","tags":["custom-gates","permutation","plonkish"],"title":"PLONKish polynomial constraints","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-PLONKISH"},{"evidence":"primary_source_checked","id":"PROOF-COMP-POLY-IOP","metadata":{"component_kind":"protocol_iop","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-POLY-IOP","paper_ids":["PROOF-PAPER-2019-PLONK","PROOF-PAPER-2019-MARLIN"],"status":"published","tags":["piop","ahp","polynomial-oracle"],"title":"Polynomial IOP / algebraic holographic proof layer"},"primaryUrl":null,"sections":[{"content":"Carries algebraic soundness before polynomial oracles are cryptographically realized. A PCS and Fiat–Shamir are separate compiler/backend choices.","heading":"Role"}],"status":"published","subtitle":"protocol iop","summary":"Carries algebraic soundness before polynomial oracles are cryptographically realized. A PCS and Fiat–Shamir are separate compiler/backend choices.","tags":["ahp","piop","polynomial-oracle"],"title":"Polynomial IOP / algebraic holographic proof layer","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-POLY-IOP"},{"evidence":"primary_source_checked","id":"PROOF-COMP-QAP","metadata":{"component_kind":"arithmetization","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-QAP","paper_ids":["PROOF-PAPER-2016-GROTH"],"status":"published","tags":["qap","polynomial-representation"],"title":"Quadratic Arithmetic Program (QAP)"},"primaryUrl":null,"sections":[{"content":"Translates circuit or R1CS consistency into a univariate polynomial divisibility relation used by pairing-based succinct arguments.","heading":"Role"}],"status":"published","subtitle":"arithmetization","summary":"Translates circuit or R1CS consistency into a univariate polynomial divisibility relation used by pairing-based succinct arguments.","tags":["polynomial-representation","qap"],"title":"Quadratic Arithmetic Program (QAP)","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-QAP"},{"evidence":"source_normalized","id":"PROOF-COMP-R1CS","metadata":{"component_kind":"arithmetization","dossier_type":"technique","evidence":"source_normalized","id":"PROOF-COMP-R1CS","paper_ids":["PROOF-PAPER-2016-GROTH","PROOF-PAPER-2019-SPARTAN","PROOF-PAPER-2021-NOVA"],"status":"catalogued","tags":["r1cs","relation-representation"],"title":"Rank-1 Constraint System (R1CS)"},"primaryUrl":null,"sections":[{"content":"Encodes satisfiability through rank-1 bilinear constraints. R1CS is a relation representation, not a proof protocol or commitment backend.","heading":"Role"}],"status":"catalogued","subtitle":"arithmetization","summary":"Encodes satisfiability through rank-1 bilinear constraints. R1CS is a relation representation, not a proof protocol or commitment backend.","tags":["r1cs","relation-representation"],"title":"Rank-1 Constraint System (R1CS)","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-R1CS"},{"evidence":"primary_source_checked","id":"PROOF-COMP-RECURSIVE-WRAP","metadata":{"component_kind":"composition_mechanism","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-RECURSIVE-WRAP","paper_ids":["PROOF-PAPER-2019-HALO"],"status":"published","tags":["recursion","curve-cycle","verifier-circuit"],"title":"Recursive verifier wrapping"},"primaryUrl":null,"sections":[{"content":"Proves verification of a prior proof inside a new proof circuit. It is distinct from folding instances before a final decision procedure.","heading":"Role"}],"status":"published","subtitle":"composition mechanism","summary":"Proves verification of a prior proof inside a new proof circuit. It is distinct from folding instances before a final decision procedure.","tags":["curve-cycle","recursion","verifier-circuit"],"title":"Recursive verifier wrapping","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-RECURSIVE-WRAP"},{"evidence":"primary_source_checked","id":"PROOF-COMP-RELAXED-FOLD","metadata":{"component_kind":"composition_mechanism","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-RELAXED-FOLD","paper_ids":["PROOF-PAPER-2021-NOVA"],"status":"published","tags":["folding","relaxed-r1cs","ivc"],"title":"Relaxed-R1CS folding"},"primaryUrl":null,"sections":[{"content":"Combines two relaxed-R1CS instances and witnesses into one folded instance, deferring a single final satisfiability decision for IVC.","heading":"Role"}],"status":"published","subtitle":"composition mechanism","summary":"Combines two relaxed-R1CS instances and witnesses into one folded instance, deferring a single final satisfiability decision for IVC.","tags":["folding","ivc","relaxed-r1cs"],"title":"Relaxed-R1CS folding","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-RELAXED-FOLD"},{"evidence":"primary_source_checked","id":"PROOF-COMP-RISCV","metadata":{"component_kind":"computation_model","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-RISCV","paper_ids":["PROOF-PAPER-2023-JOLT"],"status":"published","tags":["risc-v","isa","zkvm"],"title":"RISC-V execution model"},"primaryUrl":null,"sections":[{"content":"Defines the bytecode/ISA-facing computation whose instruction, bytecode, register, and memory behavior is lowered into several proof subarguments.","heading":"Role"}],"status":"published","subtitle":"computation model","summary":"Defines the bytecode/ISA-facing computation whose instruction, bytecode, register, and memory behavior is lowered into several proof subarguments.","tags":["isa","risc-v","zkvm"],"title":"RISC-V execution model","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-RISCV"},{"evidence":"primary_source_checked","id":"PROOF-COMP-SPECIAL-SOUND-ACCUMULATION","metadata":{"component_kind":"composition_mechanism","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-SPECIAL-SOUND-ACCUMULATION","paper_ids":["PROOF-PAPER-2023-PROTOSTAR"],"status":"published","tags":["accumulation","special-sound","protostar"],"title":"Special-sound protocol accumulation"},"primaryUrl":null,"sections":[{"content":"Represents Protostar's compiler interface for accumulating a class of special-sound protocols. It is not interchangeable with CCS multi-folding merely because both mechanisms can support IVC.","heading":"Role"}],"status":"published","subtitle":"composition mechanism","summary":"Represents Protostar's compiler interface for accumulating a class of special-sound protocols. It is not interchangeable with CCS multi-folding merely because both mechanisms can support IVC.","tags":["accumulation","protostar","special-sound"],"title":"Special-sound protocol accumulation","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-SPECIAL-SOUND-ACCUMULATION"},{"evidence":"primary_source_checked","id":"PROOF-COMP-SUMCHECK","metadata":{"component_kind":"protocol_iop","dossier_type":"technique","evidence":"primary_source_checked","id":"PROOF-COMP-SUMCHECK","paper_ids":["PROOF-PAPER-1992-LFKN","PROOF-PAPER-2019-SPARTAN","PROOF-PAPER-2023-HYPERNOVA"],"status":"published","tags":["sumcheck","multilinear","public-coin"],"title":"Sum-check protocol"},"primaryUrl":null,"sections":[{"content":"Reduces a claimed sum of a low-degree multivariate polynomial over a product domain to a final evaluation claim through public-coin interaction.","heading":"Role"}],"status":"published","subtitle":"protocol iop","summary":"Reduces a claimed sum of a low-degree multivariate polynomial over a product domain to a final evaluation claim through public-coin interaction.","tags":["multilinear","public-coin","sumcheck"],"title":"Sum-check protocol","type":"technique","venue":null,"year":null,"sourcePath":"data/proof-systems-catalog.json#PROOF-COMP-SUMCHECK"}],"openProblems":[{"barrier_ids":["PROOF-BARRIER-001"],"closest_results":["PROOF-PAPER-2026-SNARG-UNPROVABILITY","PROOF-PAPER-2025-BOOSTING-SNARKS"],"evidence":"claim_audited","faithful_source_statement":"Cheng–Goyal describe all-NP SNARGs in the standard model from standard falsifiable assumptions as longstanding and note that prior constructions cover subclasses; Hsieh–Jain–Li–Mathialagan reach all NP with non-adaptive soundness by adding a new Hardness Certification assumption.","id":"PROOF-OP-001","normalization_delta":"The historical target is updated after the June 2026 all-NP result. The residual explicitly asks to remove its proof-complexity unprovability assumption and to upgrade non-adaptive to adaptive soundness; it does not claim that the 2026 construction failed to reach all NP.","order":1,"origin_type":"normalized_lineage_gap","profile":{"assumptions":"fixed_standard_falsifiable_cryptographic_assumptions","excluded_idealizations":["random_oracle","knowledge_assumption","indistinguishability_obfuscation","witness_encryption","proof_complexity_unprovability"],"model":"common_reference_string_standard_model","proof_size":"poly_security_instance_and_log_computation_not_witness_length","reduction_access":"non_black_box_allowed","relation_class":"all_NP","soundness":"adaptive_statement_selection_after_CRS","task":"succinct_noninteractive_argument","verification":"public_and_succinct"},"resolution_condition":"A primary-source construction gives a publicly verifiable, adaptively sound, fully succinct SNARG for every NP relation in the CRS standard model, with proof length and verifier work independent of witness length except through logarithmic computation parameters, and bases security only on explicitly named standard falsifiable cryptographic assumptions; a black-box reduction is not required.","route_ids":["PROOF-ROUTE-001"],"status":"open","title":"Adaptive fully succinct SNARGs for all NP from standard falsifiable assumptions"},{"barrier_ids":["PROOF-BARRIER-002"],"closest_results":["PROOF-PAPER-2023-BEHEMOTH","PROOF-PAPER-2024-LATTICE-PCS","PROOF-PAPER-2024-WHIR"],"evidence":"claim_audited","faithful_source_statement":"Behemoth asks whether a transparent, plausibly post-quantum polynomial commitment can have both constant-size opening proofs and constant-time verification.","id":"PROOF-OP-002","normalization_delta":"The card makes the degree parameter, evaluation interface, negligible soundness, and proof-of-knowledge/binding obligation explicit. It does not add batching or quasi-linear proving to the resolution condition; those remain desirable strengthenings.","order":2,"origin_type":"explicit_open_question","profile":{"opening_proof_size":"O_security_1_independent_of_N","polynomial_domain":"univariate_degree_at_most_N_over_declared_field_or_ring","preprocessing":"no_secret_trapdoor","quantum_security":"binding_or_knowledge_soundness_against_quantum_adversaries","setup":"transparent_public_coin","soundness_error":"negligible","task":"polynomial_evaluation_commitment","verifier_time":"O_security_1_independent_of_N"},"resolution_condition":"A primary-source PCS construction and security proof provide transparent setup, plausible post-quantum binding or knowledge soundness, negligible error, O(poly(lambda)) opening-proof bits, and O(poly(lambda)) verifier time for one evaluation, with both costs independent of polynomial degree N.","route_ids":["PROOF-ROUTE-002"],"status":"open","title":"Transparent post-quantum polynomial commitments with constant openings and verification"},{"barrier_ids":["PROOF-BARRIER-003"],"closest_results":["PROOF-PAPER-2025-IBCS-QUANTUM"],"evidence":"claim_audited","faithful_source_statement":"The quantum-rewinding analysis proves Unruh-style knowledge soundness for IBCS and explicitly leaves stronger extraction—such as witness-extended or state-preserving extraction—open.","id":"PROOF-OP-003","normalization_delta":"The card selects state-preserving witness extraction as the concrete stronger notion and fixes the already-proved semi-adaptive public-coin IOP plus collapsing-VC setting. Fully adaptive IOP verification is recorded as a weaker adjacent milestone, not conjoined with the closing condition.","order":3,"origin_type":"explicit_open_question","profile":{"adversary":"quantum_polynomial_time_with_auxiliary_quantum_state","compiler":"interactive_BCS","cryptographic_input":"collapse_position_binding_vector_commitment","extraction":"state_preserving_witness_extraction_or_witness_extended_emulation","information_theoretic_input":"semi_adaptive_public_coin_IOP_proof_of_knowledge","model":"standard_model_no_random_oracle"},"resolution_condition":"A primary-source theorem shows that IBCS in the stated semi-adaptive-IOP and collapse-position-binding-VC setting satisfies a formally defined state-preserving witness-extraction or witness-extended-emulation notion against quantum adversaries, with an efficient extractor and explicit disturbance/error bounds sufficient for sequential composition.","route_ids":["PROOF-ROUTE-003"],"status":"open","title":"State-preserving post-quantum extraction for IOP-based succinct arguments"},{"barrier_ids":["PROOF-BARRIER-004"],"closest_results":["PROOF-PAPER-2020-ACCUMULATION","PROOF-PAPER-2021-NOVA","PROOF-PAPER-2023-PROTOSTAR"],"evidence":"claim_audited","faithful_source_statement":"Bünz–Chiesa–Mishra–Spooner state that known non-interactive accumulation schemes use random oracles or knowledge assumptions and ask for accumulation for non-interactive arguments, or another interesting predicate, from standard assumptions not already known to imply SNARKs.","id":"PROOF-OP-004","normalization_delta":"The broad source question is specialized to accumulation for a non-interactive argument with succinct accumulation verification and a standard-model security proof. The target excludes assumptions already known to imply general SNARKs, while allowing any explicitly named falsifiable standard assumption.","order":4,"origin_type":"explicit_open_question","profile":{"accumulator_size":"succinct_independent_of_number_of_accumulated_instances","assumptions":"standard_falsifiable_and_not_known_to_imply_general_SNARKs","excluded_idealizations":["random_oracle","Fiat_Shamir_heuristic","knowledge_assumption"],"interaction":"noninteractive_accumulation_proof","model":"CRS_standard_model","security":"adaptive_knowledge_soundness_sufficient_for_PCD","task":"accumulation_scheme_for_noninteractive_arguments","verifier_work":"sublinear_in_total_accumulated_verification_work"},"resolution_condition":"A primary-source construction gives a non-interactive accumulation scheme for a nontrivial argument predicate in the CRS standard model, proves the completeness and adaptive knowledge-soundness conditions needed by the PCD compiler, keeps accumulator size independent of the number of accumulated objects and verification sublinear in their total direct cost, and uses only named standard falsifiable assumptions not already known to imply general SNARKs.","route_ids":["PROOF-ROUTE-004"],"status":"open","title":"Non-interactive accumulation from standard assumptions without random oracles"}],"researchMap":{"lanes":[{"id":"foundation","label":"Foundation","question":"What is the problem, and what can be established or ruled out?"},{"id":"construction","label":"Construction","question":"How is the goal realized?"},{"id":"efficiency","label":"Efficiency","question":"Which resource cost or trade-off is advanced?"}],"nodes":{"PROOF-CONTRIB-1986-FS-COMPILER":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Fiat–Shamir compiler","lane_rationale":"The claim supplies the hash-derived-challenge transformation from a public-coin identification pattern; historical importance does not make this concrete compiler a definition node.","lenses":["proof_succinct_verification"],"primary":true,"selection_rationale":"Establishes the hash-derived-challenge compiler that later non-interactive configurations must instantiate and analyze rather than treating non-interactivity as a primitive property.","thread":"proof_foundational_compilers","visibility":"backbone"},"PROOF-CONTRIB-1989-GMR-ZK":{"anchor_roles":["model_definition"],"group":"foundation","label":"Zero-knowledge definition","lane_rationale":"The contribution formalizes knowledge complexity and the simulation-based zero-knowledge contract, independently of any later succinct or non-interactive construction.","lenses":["proof_universal_expressiveness"],"primary":true,"selection_rationale":"Supplies the simulation-based privacy contract needed to distinguish a zero-knowledge property from a proof architecture or commitment mechanism.","thread":"proof_foundational_compilers","visibility":"backbone"},"PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT":{"anchor_roles":["first_feasibility","reusable_mechanism"],"group":"construction","label":"PCP + commitments","lane_rationale":"The node isolates a reusable authenticated-PCP compilation method using commitments and selective openings; it explains how a communication-efficient argument is realized.","lenses":["proof_succinct_verification"],"primary":true,"selection_rationale":"Captures the authenticated-oracle compilation step that makes PCP local checking into a communication-efficient computational argument.","thread":"proof_foundational_compilers","visibility":"backbone"},"PROOF-CONTRIB-1992-LFKN-SUMCHECK":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Sum-check","lane_rationale":"Sum-check is the concrete interactive sum-to-evaluation reduction reused as a mechanism, not the full surrounding complexity-theory theorem or a generic proof-system definition.","lenses":["proof_succinct_verification","proof_universal_expressiveness"],"primary":true,"selection_rationale":"Isolates the sum-to-evaluation reduction repeatedly used by the mapped Spartan and HyperNova contributions instead of assigning that mechanism to a later complete system.","thread":"proof_sumcheck_multilinear","visibility":"backbone"},"PROOF-CONTRIB-2010-KZG-PCS":{"anchor_roles":["reusable_mechanism","capability_boundary"],"group":"construction","label":"KZG commitments","lane_rationale":"The contribution supplies a pairing-based polynomial commitment and quotient-opening mechanism with a degree-bounded structured setup; its small openings are properties of the named reusable backend.","lenses":["proof_succinct_verification","proof_universal_expressiveness"],"primary":true,"selection_rationale":"Establishes the constant-size pairing-based polynomial-evaluation backend used by the mapped PLONK and Marlin configurations and later scrutinized under batching.","thread":"proof_polynomial_iop","visibility":"backbone"},"PROOF-CONTRIB-2016-GROTH-3ELEMENT":{"anchor_roles":["capability_boundary"],"group":"efficiency","label":"Three-element argument","lane_rationale":"The mapped atomic delta is the three-group-element proof-size endpoint and fixed pairing verification equation for preprocessing arithmetic-circuit arguments, not merely the presence of a new scheme.","lenses":["proof_succinct_verification"],"primary":true,"selection_rationale":"Marks the concrete three-group-element proof-size endpoint for circuit-specific pairing arguments, which later universal systems deliberately trade against setup reuse.","thread":"proof_pairing_qap","visibility":"backbone"},"PROOF-CONTRIB-2017-BULLETPROOFS-AGG":{"group":"efficiency","label":"Aggregated range proofs","lane_rationale":"The separate aggregation result reduces proof-data growth for multiple range statements through one vector relation; it is a specified size improvement, not generic recursive composition.","lenses":["proof_recursive_computation"],"selection_rationale":"Preserves the paper's distinct range-proof aggregation result without confusing specialized batching with generic recursion, accumulation, or IVC.","thread":"proof_recursive_composition","threads":["proof_recursive_composition","proof_inner_product"],"visibility":"reviewed_related"},"PROOF-CONTRIB-2017-BULLETPROOFS-IPA":{"anchor_roles":["reusable_mechanism","capability_boundary"],"group":"construction","label":"Logarithmic inner-product argument","lane_rationale":"The node isolates the recursive inner-product argument mechanism and transparent discrete-log commitment configuration used by later systems; linear verifier work remains a separate qualifier.","lenses":["proof_setup_transparency"],"primary":true,"selection_rationale":"Represents the practical logarithmic-communication no-trusted-setup inner-product configuration later used by Halo, while keeping linear verifier work visible.","thread":"proof_inner_product","visibility":"backbone"},"PROOF-CONTRIB-2018-STARK-SYSTEM":{"anchor_roles":["capability_boundary"],"group":"construction","label":"STARK stack","lane_rationale":"The contribution is the integrated AIR, coded-oracle, and hash-commitment architecture for transparent integrity proofs; the accompanying implementation does not turn it into an artifact-only node.","lenses":["proof_setup_transparency","proof_post_quantum"],"primary":true,"selection_rationale":"Marks the integrated transparent AIR/coded-oracle/hash architecture and its implementation-facing transition rather than presenting FRI alone as a complete system.","thread":"proof_transparent_oracle","visibility":"backbone"},"PROOF-CONTRIB-2019-HALO-RECURSION":{"anchor_roles":["reusable_mechanism","capability_boundary"],"group":"construction","label":"Halo recursion","lane_rationale":"Halo combines an inner-product polynomial commitment, nested amortization, and curve-cycle machinery to realize recursion without a trusted setup; it identifies a concrete composition method.","lenses":["proof_setup_transparency","proof_recursive_computation"],"primary":true,"selection_rationale":"Establishes the reviewed no-trusted-setup recursive-wrapping branch against which Nova's later change to relation folding is intelligible.","thread":"proof_recursive_composition","threads":["proof_recursive_composition","proof_inner_product"],"visibility":"backbone"},"PROOF-CONTRIB-2019-MARLIN-AHP":{"group":"construction","label":"Marlin AHP compiler","lane_rationale":"The principal contribution is the AHP-plus-extractable-PCS compiler yielding universal-updatable preprocessing arguments, with the selected backend and setup assumptions explicit.","lenses":["proof_universal_expressiveness"],"primary":true,"selection_rationale":"Retains the explicit AHP-plus-PCS compiler abstraction as reviewed-related because it explains universal setup modularity without duplicating PLONK's permutation architecture on the backbone.","thread":"proof_polynomial_iop","visibility":"reviewed_related"},"PROOF-CONTRIB-2019-PLONK-PIOP":{"anchor_roles":["capability_boundary","reusable_mechanism"],"group":"construction","label":"PLONK PIOP","lane_rationale":"The node presents the permutation-based polynomial proof architecture and Lagrange-basis gate/wiring interface under a universal-updatable SRS; setup is a condition of this construction.","lenses":["proof_universal_expressiveness"],"primary":true,"selection_rationale":"Marks the permutation-based universal-updatable polynomial architecture that later PLONKish gates, lookups, and configuration-specific security analyses deliberately modify.","thread":"proof_polynomial_iop","visibility":"backbone"},"PROOF-CONTRIB-2019-SPARTAN-R1CS":{"anchor_roles":["capability_boundary","reusable_mechanism"],"group":"construction","label":"Spartan R1CS","lane_rationale":"The contribution constructs the arbitrary-R1CS-to-multilinear-sum-check architecture with an explicit commitment stage and public preprocessing, rather than asserting uniform performance across backend variants.","lenses":["proof_universal_expressiveness"],"primary":true,"selection_rationale":"Provides the general R1CS-to-multilinear-sum-check architecture that anchors the mapped Jolt residual-constraint branch.","thread":"proof_sumcheck_multilinear","visibility":"backbone"},"PROOF-CONTRIB-2020-ACCUMULATION-PCD":{"group":"foundation","label":"Accumulation for PCD","lane_rationale":"The card explicitly isolates the new accumulation interface and the general theorem that suitable accumulation suffices for PCD; concrete instantiations are conditional examples, not a standard-model resolution.","lenses":["proof_recursive_computation"],"primary":true,"selection_rationale":"Preserves the accumulation-to-PCD definition and compiler as a gateway because it changes the composition interface even though its standard-model non-interactive target remains open.","thread":"proof_recursive_composition","visibility":"reviewed_related"},"PROOF-CONTRIB-2021-NOVA-FOLDING":{"anchor_roles":["reusable_mechanism","capability_boundary"],"group":"construction","label":"Nova folding","lane_rationale":"The mapped claim is the concrete relaxed-R1CS folding mechanism realizing IVC with a separate final decider or compression phase, rather than a standalone definition of all folding schemes.","lenses":["proof_recursive_computation"],"primary":true,"selection_rationale":"Introduces relation folding as the per-step IVC primitive and makes the separation between folding and a final succinct decider explicit.","thread":"proof_recursive_composition","visibility":"backbone"},"PROOF-CONTRIB-2023-BEHEMOTH-CONSTANT":{"group":"efficiency","label":"Constant transparent PCS","lane_rationale":"The specific frontier moves transparent opening size and verifier time to degree-independent bounds while paying cubic prover work and stronger proof models; it is a qualified resource trade-off.","lenses":["proof_succinct_verification","proof_setup_transparency"],"primary":true,"selection_rationale":"Records the degree-independent transparent opening endpoint as reviewed-related because its cubic prover and non-post-quantum group model make it a qualified frontier point rather than the default PCS path.","thread":"proof_transparent_pcs","visibility":"reviewed_related"},"PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD":{"anchor_roles":["capability_boundary","current_frontier"],"group":"construction","label":"HyperNova multifolding","lane_rationale":"HyperNova gives a concrete sum-check-based multifolding protocol for CCS and non-uniform steps, extending what the folding construction can realize rather than merely improving a cost scalar.","lenses":["proof_recursive_computation"],"primary":true,"selection_rationale":"Generalizes the reviewed folding contract from relaxed R1CS pairs to CCS, multiple instances, and non-uniform steps, so omitting it would understate the branch's expressiveness.","thread":"proof_recursive_composition","visibility":"backbone"},"PROOF-CONTRIB-2023-JOLT-LOOKUPVM":{"anchor_roles":["capability_boundary"],"group":"construction","label":"Jolt lookup VM","lane_rationale":"The node isolates a lookup-centric VM proof architecture composing residual sum-check constraints and separate memory checking, not later implementation releases or unmatched benchmarks.","lenses":["proof_zkvm_scalability","proof_universal_expressiveness"],"primary":true,"selection_rationale":"Marks the lookup-centric VM decomposition that connects proof mechanisms to a versioned implementation line without treating an artifact or benchmark as the research contribution.","thread":"proof_lookup_vm","visibility":"backbone"},"PROOF-CONTRIB-2023-PROTOSTAR-GENERIC":{"group":"construction","label":"Protostar accumulation","lane_rationale":"The contribution supplies a generic accumulation compiler for suitable special-sound protocols and its PLONK-style instantiation, keeping compiler hypotheses explicit.","lenses":["proof_recursive_computation"],"primary":true,"selection_rationale":"Keeps the special-sound-protocol accumulation compiler visible as a reviewed-related generalization rather than merging it with Nova's relation-specific folding mechanism.","thread":"proof_recursive_composition","visibility":"reviewed_related"},"PROOF-CONTRIB-2024-LATTICE-PCS-PQ":{"group":"construction","label":"Lattice PCS","lane_rationale":"The source gives a concrete transparent Module-SIS polynomial commitment with quantum knowledge soundness and stated prover/opening bounds; post-quantum assumptions are facets, not a lane.","lenses":["proof_setup_transparency","proof_post_quantum"],"primary":true,"selection_rationale":"Represents the transparent Module-SIS and quantum-knowledge-sound PCS route as reviewed-related because its polylogarithmic endpoints differ from both Behemoth and WHIR.","thread":"proof_transparent_pcs","visibility":"reviewed_related"},"PROOF-CONTRIB-2024-PLONK-KS":{"anchor_roles":["capability_boundary","current_frontier"],"group":"foundation","label":"PLONK knowledge audit","lane_rationale":"This is an independent computational-special-soundness and knowledge-soundness analysis of specified PLONK and batched-KZG variants, not a newly repaired protocol or a blanket theorem for all PLONKish systems.","lenses":["proof_deployed_security"],"primary":true,"selection_rationale":"Corrects family-level security shorthand by attaching knowledge soundness to exact PLONK and batched-KZG variants and their compiler assumptions.","thread":"proof_security_audit","visibility":"backbone"},"PROOF-CONTRIB-2024-REALWORLD-SE":{"anchor_roles":["capability_boundary","current_frontier"],"group":"foundation","label":"Simulation extractability","lane_rationale":"The contribution establishes simulation extractability for exact optimized PLONK/Marlin configurations under declared conditions; the research delta is a scoped security theorem.","lenses":["proof_deployed_security"],"primary":true,"selection_rationale":"Captures a stronger non-malleability-oriented guarantee for specified optimized universal configurations instead of letting the original family paper stand in for later security analysis.","thread":"proof_security_audit","visibility":"backbone"},"PROOF-CONTRIB-2024-WHIR-PROXIMITY":{"anchor_roles":["current_frontier"],"group":"efficiency","label":"WHIR proximity test","lane_rationale":"The principal mapped delta reduces verifier work in Reed-Solomon proximity/hash-based commitment configurations; comparison remains parameter-, rate-, and security-dependent.","lenses":["proof_succinct_verification","proof_setup_transparency"],"primary":true,"selection_rationale":"Marks a verifier-work frontier in the transparent coded-oracle thread and qualifies which resource is improved instead of presenting WHIR as a universally faster proof system.","thread":"proof_transparent_oracle","visibility":"backbone"},"PROOF-CONTRIB-2025-BOOSTING-SNARKS":{"group":"construction","label":"Succinctness booster","lane_rationale":"The node presents a conditional mild-to-full-succinctness compiler using RAM delegation while preserving extractor access; it does not supply the required base SNARK.","lenses":["proof_succinct_verification"],"primary":true,"selection_rationale":"Keeps the conditional mild-to-full succinctness compiler as reviewed-related because it reorganizes the open problem but does not supply the required base SNARK.","thread":"proof_foundational_compilers","visibility":"reviewed_related"},"PROOF-CONTRIB-2025-IBCS-QUANTUM":{"anchor_roles":["capability_boundary","current_frontier"],"group":"foundation","label":"Quantum IBCS security","lane_rationale":"The work proves post-quantum soundness and a specified extraction notion for semi-adaptive interactive BCS; it is an independent compiler-security analysis with explicit non-claims about stronger extraction.","lenses":["proof_deployed_security","proof_post_quantum"],"primary":true,"selection_rationale":"Establishes the exact post-quantum soundness and extraction boundary for semi-adaptive IOP-based arguments and directly grounds the stronger-extraction open problem.","thread":"proof_security_audit","visibility":"backbone"},"PROOF-CONTRIB-2025-JOLT-SPACE":{"group":"efficiency","label":"Small-space Jolt prover","lane_rationale":"The contribution lowers honest-prover space within the Jolt stack using streaming and recomputation with an explicit time-space trade-off, rather than a new recursive architecture.","lenses":["proof_zkvm_scalability"],"primary":true,"selection_rationale":"Records honest-prover memory as an optimization of the Jolt stack rather than promoting it to a new scheme or using an unmatched benchmark to imply improvement.","thread":"proof_lookup_vm","visibility":"reviewed_related"},"PROOF-CONTRIB-2026-SNARG-UNPROVABILITY":{"group":"foundation","label":"SNARG feasibility boundary","lane_rationale":"The card isolates the all-NP non-adaptive feasibility theorem and its new Hardness Certification assumption; it does not establish adaptive soundness or feasibility from ordinary assumptions alone.","lenses":["proof_succinct_verification"],"primary":true,"selection_rationale":"Records the all-NP non-adaptive feasibility change with its new proof-unprovability assumption while keeping the adaptive standard-assumption target open.","thread":"proof_foundational_compilers","visibility":"reviewed_related"}},"overview_focus_ids":["proof_succinct_verification","proof_setup_transparency","proof_universal_expressiveness","proof_zkvm_scalability","proof_deployed_security","proof_post_quantum"],"overview_reading_path":["PROOF-CONTRIB-1986-FS-COMPILER","PROOF-CONTRIB-1989-GMR-ZK","PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT","PROOF-CONTRIB-1992-LFKN-SUMCHECK","PROOF-CONTRIB-2010-KZG-PCS","PROOF-CONTRIB-2016-GROTH-3ELEMENT","PROOF-CONTRIB-2018-STARK-SYSTEM","PROOF-CONTRIB-2019-PLONK-PIOP","PROOF-CONTRIB-2019-SPARTAN-R1CS","PROOF-CONTRIB-2021-NOVA-FOLDING","PROOF-CONTRIB-2023-JOLT-LOOKUPVM","PROOF-CONTRIB-2024-PLONK-KS"],"problems":[{"id":"proof_succinct_verification","label":"Succinct proof and verifier cost","question":"Which mechanisms compress proofs and verification without hiding the prover or setup cost?","reading_path":["PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT","PROOF-CONTRIB-2010-KZG-PCS","PROOF-CONTRIB-2016-GROTH-3ELEMENT","PROOF-CONTRIB-2024-WHIR-PROXIMITY"]},{"id":"proof_setup_transparency","label":"Setup independence and transparency","question":"Which proof stacks avoid circuit-specific or secret structured setup, and at what cost?","reading_path":["PROOF-CONTRIB-2017-BULLETPROOFS-IPA","PROOF-CONTRIB-2018-STARK-SYSTEM","PROOF-CONTRIB-2019-HALO-RECURSION","PROOF-CONTRIB-2024-LATTICE-PCS-PQ"]},{"id":"proof_universal_expressiveness","label":"Universal relations and computation models","question":"Which arithmetizations and compilers support reusable setup or broad computation models?","reading_path":["PROOF-CONTRIB-1992-LFKN-SUMCHECK","PROOF-CONTRIB-2019-MARLIN-AHP","PROOF-CONTRIB-2019-PLONK-PIOP","PROOF-CONTRIB-2019-SPARTAN-R1CS"]},{"id":"proof_recursive_computation","label":"Aggregation, recursion, IVC, and PCD","question":"What is being composed, accumulated, or folded, and where does the final decider live?","reading_path":["PROOF-CONTRIB-2017-BULLETPROOFS-AGG","PROOF-CONTRIB-2019-HALO-RECURSION","PROOF-CONTRIB-2020-ACCUMULATION-PCD","PROOF-CONTRIB-2021-NOVA-FOLDING","PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD","PROOF-CONTRIB-2023-PROTOSTAR-GENERIC"]},{"id":"proof_zkvm_scalability","label":"zkVM prover time and memory","question":"Which lookup and decomposition choices reduce prover time, memory, and machine overhead?","reading_path":["PROOF-CONTRIB-2023-JOLT-LOOKUPVM","PROOF-CONTRIB-2025-JOLT-SPACE"]},{"id":"proof_deployed_security","label":"Exact security of optimized systems","question":"Which optimized configurations retain knowledge soundness or simulation extractability under their exact batching and commitment choices?","reading_path":["PROOF-CONTRIB-2024-PLONK-KS","PROOF-CONTRIB-2024-REALWORLD-SE","PROOF-CONTRIB-2025-IBCS-QUANTUM"]},{"id":"proof_post_quantum","label":"Post-quantum proof systems","question":"Which transparent components and compiler analyses retain soundness against quantum adversaries?","reading_path":["PROOF-CONTRIB-2018-STARK-SYSTEM","PROOF-CONTRIB-2024-LATTICE-PCS-PQ","PROOF-CONTRIB-2025-IBCS-QUANTUM"]}],"reading_collections":[{"coverage_note":"The seed covers pairing, unknown-order, lattice, and hash-based PCS results plus a specified batch-opening security analysis. It is a bounded reading sample, not a complete PCS history or a claim that all backends have interchangeable interfaces or evidence.","excludes":"A commitment-backend slot, a generic inner-product argument, or a proximity test alone does not establish a PCS contribution; system properties and guarantees are not inherited across configurations.","id":"proof_polynomial_commitments","includes":"Direct polynomial-commitment constructions, opening mechanisms, and analyses or optimizations of specified PCS protocols; supporting arguments and consuming proof architectures may appear as context.","label":"Polynomial commitments","members":[{"contribution_id":"PROOF-CONTRIB-2010-KZG-PCS","reason":"The contribution directly constructs bounded-degree univariate commitments and constant-size single-point openings using structured pairing parameters, with batching and setup limits preserved.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2023-BEHEMOTH-CONSTANT","reason":"The card directly constructs a transparent unknown-order-group PCS with degree-independent opening size and verification, retaining cubic prover work and its random-oracle and generic-group analysis.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2024-LATTICE-PCS-PQ","reason":"The atomic result constructs a Module-SIS PCS with explicit opening, verifier, prover, and quantum-knowledge-soundness claims; membership follows that PCS object rather than a post-quantum label.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2024-WHIR-PROXIMITY","reason":"The card explicitly derives hash-based polynomial-commitment configurations from its proximity framework and targets their verifier work, so membership is not inferred from proximity testing alone.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2024-PLONK-KS","reason":"The analysis directly proves computational special soundness for specified batched KZG opening protocols; only that exact PCS-security target is included, not a blanket claim about every PLONKish system.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2017-BULLETPROOFS-IPA","reason":"The inner-product reduction is a supporting argument interface, but this atomic card does not itself specify a polynomial-commitment construction; logarithmic communication also does not imply a succinct verifier.","role":"context"},{"contribution_id":"PROOF-CONTRIB-2019-HALO-RECURSION","reason":"Halo uses an inner-product polynomial commitment in its recursion and amortization construction; the selected atomic delta concerns recursive composition rather than a standalone PCS construction.","role":"context"},{"contribution_id":"PROOF-CONTRIB-2019-PLONK-PIOP","reason":"The permutation-based polynomial architecture combines its protocol with a universal degree-bounded commitment setup, illustrating a PCS consumer without making the whole architecture an independent PCS result.","role":"context"}],"question":"How are polynomials committed and evaluation claims opened, and which setup, security, prover, communication, and verifier trade-offs govern those interfaces?"},{"coverage_note":"This seed deliberately contains both specialized range-statement aggregation and recursive or incremental verification paths. It is not a complete history of generic proof aggregation, IVC, or PCD, and it creates no common performance or security comparison across those tasks.","excludes":"These tasks and mechanisms are not synonyms; a recursively described algebraic reduction is not automatically recursive proof composition, folding alone is not a SNARK, and sharing an inner-product or sum-check component does not confer membership.","id":"proof_aggregation_incremental_verification","includes":"Direct advances in statement aggregation, recursive proof composition, accumulation, folding, IVC, and PCD, while preserving the different objects combined and the final verification obligations of each mechanism.","label":"Aggregation and incremental verification","members":[{"contribution_id":"PROOF-CONTRIB-2017-BULLETPROOFS-AGG","reason":"The card directly aggregates multiple range statements into one logarithmically growing proof; this is specialized statement aggregation, not generic proof recursion or IVC.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2019-HALO-RECURSION","reason":"Nested amortization and an elliptic-curve cycle directly realize recursive proof composition without a trusted setup, subject to the selected commitment and curve configuration.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2020-ACCUMULATION-PCD","reason":"The work defines accumulation schemes and a compiler to proof-carrying data, directly reducing several validity obligations to an accumulator that still requires a final decider.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2021-NOVA-FOLDING","reason":"Folding relaxed-R1CS instances into a running instance directly enables incremental verification, with a distinct final decider or compression step rather than treating folding itself as a SNARK.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD","reason":"The atomic mechanism extends folding to CCS and multiple instances with non-uniform step circuits, directly changing the incremental-verification interface rather than merely using a shared backend.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2023-PROTOSTAR-GENERIC","reason":"The compiler derives accumulation or folding from a specified class of special-sound protocols and instantiates non-uniform IVC, with compiler hypotheses and configuration-dependent efficiency retained.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2017-BULLETPROOFS-IPA","reason":"The inner-product reduction supports the neighboring aggregation and recursion discussion, but recursively halving vectors is not itself aggregation of statements or recursive verification of proofs.","role":"context"},{"contribution_id":"PROOF-CONTRIB-1992-LFKN-SUMCHECK","reason":"Sum-check provides a reusable algebraic reduction relevant to the sum-check-based multi-folding route; its own atomic claim is neither an accumulator nor an IVC or PCD construction.","role":"context"}],"question":"How can multiple proof obligations be combined or computation be verified incrementally, and what remains to be checked by a final verifier or decider?"},{"coverage_note":"This bounded seed covers selected algebraic and authenticated-oracle interfaces and exact security analyses, not a complete IP, PCP, or IOP history. Independent model and expressive-power results, IP=PSPACE, and original GKR and FRI contributions remain coverage gaps; neither the GMR zero-knowledge definition card nor the LFKN sum-check card stands for a whole paper's additional results.","excludes":"Consuming an interactive protocol, using a PCS, or assuming a random oracle does not by itself establish a direct contribution to this collection. Compilers whose recorded target only removes interaction or produces folding or accumulation are not core merely because their input is an interactive protocol; selected boundary contributions may appear as context.","id":"proof_interactive_oracle_protocols","includes":"Direct constructions, algebraic reductions, authenticated realizations, and independent analyses of interactive or proof-oracle verification interfaces, including sum-check, inner-product arguments, PCP authentication, AHPs, PIOPs, and proximity testing. Oracle access here means access to a proof representation, not a random-oracle assumption.","label":"Interactive and oracle protocols","members":[{"contribution_id":"PROOF-CONTRIB-1992-LFKN-SUMCHECK","reason":"The contribution directly gives the round-by-round reduction of a low-degree polynomial sum to one evaluation claim, retaining the degree, field, and final-evaluation conditions rather than attributing IP=PSPACE to this atom.","role":"core"},{"contribution_id":"PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT","reason":"The compiler directly realizes selective PCP access through cryptographic commitments and authenticated openings, so the contribution changes the oracle-verification interface rather than merely consuming a proof system.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2017-BULLETPROOFS-IPA","reason":"The card supplies an interactive algebraic inner-product reduction that halves the vector dimension each round; logarithmic communication is retained separately from linear verifier work and does not turn this atom into a PCS construction.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2019-MARLIN-AHP","reason":"The atomic contribution formalizes the public-coin AHP and extractable-PCS compilation interface for universal-updatable-SRS preprocessing arguments, rather than merely selecting a commitment backend for an unchanged protocol.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2019-PLONK-PIOP","reason":"The permutation-based polynomial architecture directly specifies a verification interface over Lagrange-basis constraints, with universal and updatable structured setup; membership does not extend to every later PLONKish configuration.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2019-SPARTAN-R1CS","reason":"The card directly organizes R1CS matrices and witnesses into multilinear encodings and sum-check reductions ending in evaluation claims, so this is a protocol architecture rather than membership inherited from using sum-check.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2024-WHIR-PROXIMITY","reason":"The contribution directly introduces a Reed-Solomon proximity-testing framework and changes its verifier-work trade-off; its separately recorded derivation of PCS configurations does not replace this oracle-protocol target.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2024-PLONK-KS","reason":"The analysis directly targets computational special soundness of specified batched KZG opening protocols and interactive PLONK variants, before relating those interface-specific results to random-oracle-model knowledge soundness.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2025-IBCS-QUANTUM","reason":"The result directly analyzes interactive BCS with a semi-adaptive public-coin IOP and a collapse-position-binding vector commitment, establishing the stated post-quantum soundness and Unruh-style knowledge guarantee for that interface.","role":"core"},{"contribution_id":"PROOF-CONTRIB-1986-FS-COMPILER","reason":"Hash-derived challenges illustrate a bridge that removes public-coin interaction; this atomic compiler is not an interactive-protocol construction or a general theorem preserving zero knowledge or establishing NIZK security.","role":"context"},{"contribution_id":"PROOF-CONTRIB-1989-GMR-ZK","reason":"The simulation-based privacy definition explains a property that interactive proofs may satisfy, but this source atom does not independently record the interactive-proof model or its expressive power.","role":"context"}],"question":"How do interactive and oracle-access proof protocols represent and verify claims, and what soundness or knowledge guarantees hold for those interfaces?"},{"coverage_note":"The seed contains the GMR privacy definition, BFM's shared-random-string NIZK model, FLS's conditional single-to-many simulation transform, and selected modern knowledge and simulation-extractability analyses, plus one NIZK-construction example as context. This is not the full classical ZK or proof-of-knowledge history; Sigma and honest-verifier paths, concurrency, resettable, non-malleability, and composability research remain distinct gaps. BFM's model membership does not certify its later-reported-flawed reuse construction, and FLS's adaptive variant requires a single-statement adaptive base.","excludes":"A zero-knowledge configuration, a non-interactive transcript, or a construction's accompanying security proof does not automatically make its atomic delta security research. Do not infer NIZK or zero-knowledge preservation from Fiat-Shamir syntax, extraction from soundness alone, or unrestricted composability or non-malleability from a scoped analysis.","id":"proof_zero_knowledge_security","includes":"Definitions and research deltas directly targeting simulation or privacy, knowledge or extraction, or notion-preserving transformations, together with independent analyses of those guarantees for specified proof protocols. Zero knowledge, knowledge soundness, and simulation extractability remain distinct guarantees rather than interchangeable labels.","label":"Zero knowledge and knowledge extraction","members":[{"contribution_id":"PROOF-CONTRIB-1988-BFM-NIZK-MODEL","reason":"The contribution independently defines the shared-random-string proof and simulation interface, rather than merely attaching zero knowledge to a construction. Its model history is separated from the reuse-construction claim that FLS later reported flawed.","role":"core"},{"contribution_id":"PROOF-CONTRIB-1990-FLS-MULTI-THEOREM","reason":"The transformation independently establishes joint simulation under repeated use through witness indistinguishability and a pseudorandom-generator alternative witness, retaining the efficient-prover bounded-NIZK base and one-way-function prerequisites. Adaptive preservation requires the separately stated adaptive base, not ordinary single-statement zero knowledge alone.","role":"core"},{"contribution_id":"PROOF-CONTRIB-1989-GMR-ZK","reason":"The atomic contribution defines knowledge complexity and the simulation-based zero-knowledge privacy contract for interactive proofs; it is not treated as a proof-of-knowledge definition or as every result in the GMR paper.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2024-PLONK-KS","reason":"This independent analysis establishes computational special soundness and its connection to knowledge soundness for specified batched-KZG and PLONK variants, rather than inheriting a knowledge guarantee from the family name.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2024-REALWORLD-SE","reason":"The contribution directly proves simulation extractability for optimized PLONK- and Marlin-style universal zkSNARK configurations under the recorded protocol, backend, and optimization conditions, without covering arbitrary forks or all composition settings.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2025-IBCS-QUANTUM","reason":"The card directly establishes post-quantum soundness and Unruh-style knowledge soundness for the specified interactive BCS configuration; it does not claim fully adaptive, state-preserving, or witness-extended extraction.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2016-GROTH-3ELEMENT","reason":"The preprocessing pairing-based arithmetic-circuit NIZK illustrates a construction satisfying a privacy-bearing proof contract, but the recorded atomic advance is three-group-element proof compression rather than an independent zero-knowledge or extraction analysis.","role":"context"}],"question":"What do zero knowledge, knowledge extraction, and stronger proof-security notions guarantee, and which exact protocols or transformations satisfy those guarantees?"},{"coverage_note":"The seed now includes the BFM88 shared-random-string model and the FLS90 bounded-to-many transformation, alongside a concrete preprocessing NIZK construction and a specified modern zkSNARK security analysis; Fiat-Shamir remains a limited neighboring transform. These two original-source additions do not complete classical NIZK history. BFM's reported-flawed reuse construction is not promoted; BDMP and other early realizations, further setup/security evolution, and a comparison with the FLS99 journal version remain gaps.","excludes":"Non-interactivity, Fiat-Shamir compilation, knowledge soundness, succinctness, or a zk-prefixed system name alone does not establish this target. Configuration properties do not automatically become contribution membership.","id":"proof_nizk","includes":"Definitions, constructions, transformations, setup or reuse methods, and security or cost analyses whose recorded target is explicitly a non-interactive zero-knowledge proof or argument.","label":"Non-interactive zero knowledge","members":[{"contribution_id":"PROOF-CONTRIB-1988-BFM-NIZK-MODEL","reason":"The atomic contribution introduces the common-random-string model and the joint string-and-proof simulation contract for non-interactive zero knowledge. It records the model, not a blanket certification of the paper's constructions or applications.","role":"core"},{"contribution_id":"PROOF-CONTRIB-1990-FLS-MULTI-THEOREM","reason":"The result directly targets NIZK reuse by transforming an efficient-prover bounded NIZK for an NP-complete language, with one-way functions, into polynomially many proofs by independent provers on the same random reference string. This does not claim NIZK from one-way functions alone or aggregate those proofs into one object.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2016-GROTH-3ELEMENT","reason":"The atomic statement explicitly constructs a preprocessing NIZK argument for arithmetic-circuit satisfiability and advances its proof size to three group elements, retaining circuit-specific structured setup rather than inheriting NIZK membership from a configuration label.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2024-REALWORLD-SE","reason":"The contribution explicitly analyzes simulation extractability of optimized PLONK- and Marlin-style zkSNARKs, limited to configurations satisfying the recorded protocol, backend, and optimization conditions.","role":"core"},{"contribution_id":"PROOF-CONTRIB-1986-FS-COMPILER","reason":"The transform explains the neighboring task of eliminating public-coin interaction, but the current atom does not establish general zero-knowledge preservation or make every non-interactive transcript a NIZK.","role":"context"}],"question":"How can proofs or arguments achieve non-interactive zero knowledge, and what setup, reuse, security, and cost results directly concern those objects?"},{"coverage_note":"This seed spans authenticated-PCP arguments, pairing and algebraic constructions, communication-only trade-offs, specified security analyses, and conditional feasibility or compilation results. Galois-ring coverage remains an abstract_checked candidate with source-stated bounds, not theorem-audited comparison or map promotion. Earlier preprocessing, QAP, and compiler bridges remain incomplete.","excludes":"Neither non-interactivity nor zero knowledge follows from membership. A short commitment opening, a folding state, a VM decomposition, or a prover algorithm does not become a succinct-argument contribution merely through a backend or system name. Resource bounds and security guarantees are not inherited across configurations.","id":"proof_succinct_arguments","includes":"Direct succinct-argument constructions and compilation routes, feasibility or limitation results, and resource or independent security analyses of the recorded argument interfaces. Communication-only succinctness is included when verifier work is separately qualified; a new construction need not improve every cost coordinate.","label":"Short proofs and succinct arguments","members":[{"contribution_id":"PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT","reason":"The contribution directly compiles PCP queries through commitments and authenticated openings into a communication-efficient computational argument; membership does not assert non-interactivity, zero knowledge, or low prover work.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2016-GROTH-3ELEMENT","reason":"The construction directly advances arithmetic-circuit argument proof size to three group elements while retaining its circuit-specific structured setup and pairing-based configuration.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2017-BULLETPROOFS-IPA","reason":"The inner-product argument directly achieves logarithmic communication without trusted setup, while verifier work remains linear in witness dimension; short communication is not presented as succinct verification.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2017-BULLETPROOFS-AGG","reason":"This separate atomic result directly changes the proof-growth bound for multiple range statements through specialized aggregation; membership is not inherited from the same paper's IPA, and verification does not thereby become constant.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2018-STARK-SYSTEM","reason":"The integrated transparent computational-integrity architecture directly provides the recorded sublinear verification for demonstrated computations, without asserting constant proof size or universal post-quantum or zero-knowledge guarantees.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2019-MARLIN-AHP","reason":"The AHP and extractable-PCS compiler directly advances the preprocessing-argument construction route and its universal-updatable-SRS boundary; this setup-reuse result is not recast as an improvement in every cost or as backend-independent security.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2019-PLONK-PIOP","reason":"The permutation-based polynomial architecture directly advances a circuit-argument construction route with universal and updatable structured setup, rather than claiming a universal speedup or transferring the result to every PLONKish variant.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2019-SPARTAN-R1CS","reason":"The R1CS-to-multilinear and sum-check architecture directly yields the recorded argument variants with sublinear verification after public preprocessing; exact succinctness remains dependent on the commitment backend and variant.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2024-PLONK-KS","reason":"This independent knowledge-soundness analysis directly concerns specified PLONK argument and batched-KZG variants, without adding a performance claim or treating ROM compilation as a precise match to a zero-knowledge configuration.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2024-REALWORLD-SE","reason":"The analysis directly establishes simulation extractability for specified optimized universal zkSNARK configurations, preserving the exact protocol and backend conditions instead of certifying an entire system family.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2025-BOOSTING-SNARKS","reason":"The compiler directly turns a suitable mildly succinct SNARK and RAM delegation into a fully succinct SNARK while preserving extractor-access character; it neither supplies the required base SNARK nor automatically constructs NIZK.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2025-GALOIS-RINGS","reason":"The atomic claim directly extends the algebraic domain of transparent succinct constructions to Galois rings, but remains a catalog-only candidate with abstract_checked evidence and source-stated bounds. Membership adds no precise theorem parameters, comparison eligibility, evidence upgrade, or map admission.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2025-IBCS-QUANTUM","reason":"The current atom explicitly identifies an IOP-to-succinct-argument route and directly analyzes the quantum security of its specified interactive BCS interface; membership adds no query, proof, or verifier bounds and no fully adaptive or state-preserving extraction guarantee.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2026-SNARG-UNPROVABILITY","reason":"The contribution directly advances all-NP non-adaptively sound SNARG feasibility under prBPP = prP, LWE, SXDH, and Hardness Certification, without implying knowledge soundness, zero knowledge, adaptive soundness, or a construction from ordinary assumptions alone.","role":"core"},{"contribution_id":"PROOF-CONTRIB-2010-KZG-PCS","reason":"The polynomial-commitment interface explains a short-opening backend used by neighboring argument constructions, but a constant-size opening is not itself a complete succinct argument.","role":"context"},{"contribution_id":"PROOF-CONTRIB-2021-NOVA-FOLDING","reason":"The folding contribution distinguishes a running instance from the separate final decider or succinct compression phase; folding state alone is not a SNARK.","role":"context"}],"question":"How are arguments with short communication or low verifier work constructed and secured, and what prover, setup, preprocessing, and assumption costs accompany those guarantees?"}],"relations":[{"change_dimensions":["mechanism","model"],"evidence_locator":"STARK introduction and related-work discussion","evidence_url":"https://eprint.iacr.org/2018/046","id":"lineage-b513475b90fb79ac","map_relation":"related_work","predecessor":"PROOF-CONTRIB-1992-KILIAN-PCP-COMMIT","relation_basis":"technical_dependency","relation_type":"ARCHITECTURAL_CONTEXT","review_status":"primary_source_checked","statement":"STARKs and Kilian's commitment-backed PCP construction share the authenticated-oracle proof tradition; the recorded comparison does not establish that the displayed STARK stack directly instantiates Kilian's construction.","successor":"PROOF-CONTRIB-2018-STARK-SYSTEM"},{"change_dimensions":["mechanism"],"evidence_locator":"Spartan abstract and protocol overview","evidence_url":"https://eprint.iacr.org/2019/550","id":"lineage-073d86ded8222904","map_relation":"lineage","predecessor":"PROOF-CONTRIB-1992-LFKN-SUMCHECK","relation_basis":"technical_dependency","relation_type":"BUILDS_ON_RESULT","review_status":"primary_source_checked","statement":"Spartan composes its R1CS encoding and commitment machinery with the sum-check protocol to obtain its core interactive argument.","successor":"PROOF-CONTRIB-2019-SPARTAN-R1CS"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"HyperNova abstract and folding construction overview","evidence_url":"https://eprint.iacr.org/2023/573","id":"lineage-e405b60620165909","map_relation":"lineage","predecessor":"PROOF-CONTRIB-1992-LFKN-SUMCHECK","relation_basis":"technical_dependency","relation_type":"BUILDS_ON_RESULT","review_status":"primary_source_checked","statement":"HyperNova's CCS multi-folding protocol uses sum-check-style reductions to fold multiple constraint instances.","successor":"PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD"},{"change_dimensions":["mechanism"],"evidence_locator":"PLONK polynomial commitment instantiation and protocol sections","evidence_url":"https://eprint.iacr.org/2019/953","id":"lineage-170ac3998b812a9a","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2010-KZG-PCS","relation_basis":"technical_dependency","relation_type":"INSTANTIATES","review_status":"primary_source_checked","statement":"The displayed PLONK configuration realizes polynomial commitments and evaluation openings with the KZG structured pairing backend.","successor":"PROOF-CONTRIB-2019-PLONK-PIOP"},{"change_dimensions":["mechanism"],"evidence_locator":"Marlin Section 1.1 and polynomial-commitment instantiation","evidence_url":"https://eprint.iacr.org/2019/1047","id":"lineage-8a5df98a341bacda","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2010-KZG-PCS","relation_basis":"technical_dependency","relation_type":"INSTANTIATES","review_status":"primary_source_checked","statement":"Marlin instantiates its AHP compiler with an extractable polynomial commitment; the promoted configuration uses the KZG line.","successor":"PROOF-CONTRIB-2019-MARLIN-AHP"},{"change_dimensions":["model"],"evidence_locator":"PLONK introduction and comparison table","evidence_url":"https://eprint.iacr.org/2019/953","id":"lineage-fe4f36e00ed5770f","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2016-GROTH-3ELEMENT","relation_basis":"result_progression","relation_type":"CHANGES_SETUP","review_status":"primary_source_checked","statement":"Relative to the compared circuit-specific Groth16 configuration, PLONK offers a degree-bounded universal and updatable structured reference string; the comparison changes setup reuse, not an unconditional ordering of proof size, security, or all configurations.","successor":"PROOF-CONTRIB-2019-PLONK-PIOP"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"Halo Section 1.1 and polynomial commitment section","evidence_url":"https://eprint.iacr.org/2019/1021","id":"lineage-2923c964ebc8a85d","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2017-BULLETPROOFS-IPA","relation_basis":"technical_dependency","relation_type":"BUILDS_ON_RESULT","review_status":"primary_source_checked","statement":"Halo builds its polynomial commitment from the inner-product argument line and adds amortization and curve-cycle machinery for recursive composition.","successor":"PROOF-CONTRIB-2019-HALO-RECURSION"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"WHIR introduction and experimental comparison","evidence_url":"https://eprint.iacr.org/2024/1586","id":"lineage-a1095484d3b1f9e4","map_relation":"related_work","predecessor":"PROOF-CONTRIB-2018-STARK-SYSTEM","relation_basis":"result_progression","relation_type":"RELATED_COMPONENT_OPTIMIZATION","review_status":"primary_source_checked","statement":"WHIR improves verifier work for compared Reed-Solomon proximity and hash-based commitment configurations relevant to transparent proof systems; the recorded comparison does not establish a drop-in improvement of the entire displayed STARK stack.","successor":"PROOF-CONTRIB-2024-WHIR-PROXIMITY"},{"change_dimensions":["mechanism"],"evidence_locator":"Nova introduction and folding-schemes section","evidence_url":"https://eprint.iacr.org/2021/370","id":"lineage-07196f59e2ca39f0","map_relation":"related_work","predecessor":"PROOF-CONTRIB-2019-HALO-RECURSION","relation_basis":"result_progression","relation_type":"CHANGES_COMPOSITION_MECHANISM","review_status":"primary_source_checked","statement":"Nova uses relaxed-instance folding where recursive-wrapping approaches such as the displayed Halo configuration verify prior proofs; this compares composition objects and does not establish Halo-specific technical inheritance or unconditional improvement.","successor":"PROOF-CONTRIB-2021-NOVA-FOLDING"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"Jolt Section 3 system decomposition","evidence_url":"https://eprint.iacr.org/2023/1217","id":"lineage-054e22c7b5b82995","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2019-SPARTAN-R1CS","relation_basis":"technical_dependency","relation_type":"COMBINES","review_status":"primary_source_checked","statement":"Jolt combines a Spartan-style sum-check SNARK for the residual R1CS relation with lookup and memory-checking arguments for a RISC-V execution.","successor":"PROOF-CONTRIB-2023-JOLT-LOOKUPVM"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"Protostar abstract and concrete instantiation","evidence_url":"https://eprint.iacr.org/2023/620","id":"lineage-49e8ff4bffa9efda","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2019-PLONK-PIOP","relation_basis":"technical_dependency","relation_type":"ACCUMULATES","review_status":"primary_source_checked","statement":"Protostar instantiates its special-sound accumulation compiler for a PLONK-style relation with high-degree gates and vector lookups.","successor":"PROOF-CONTRIB-2023-PROTOSTAR-GENERIC"},{"change_dimensions":["mechanism","functionality","model"],"evidence_locator":"HyperNova abstract and comparison with Nova","evidence_url":"https://eprint.iacr.org/2023/573","id":"lineage-778ddcaa12791175","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2021-NOVA-FOLDING","relation_basis":"technical_dependency","relation_type":"GENERALIZES","review_status":"primary_source_checked","statement":"HyperNova generalizes the folding approach from relaxed R1CS to CCS, multiple folded instances, and non-uniform step circuits.","successor":"PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD"},{"change_dimensions":["security"],"evidence_locator":"Real-world Universal zkSNARKs abstract and main theorems","evidence_url":"https://eprint.iacr.org/2024/721","id":"lineage-faf7c1f1a8df512e","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2019-PLONK-PIOP","relation_basis":"analysis","relation_type":"ANALYZES","review_status":"primary_source_checked","statement":"The later security analysis proves simulation extractability for optimized real-world PLONK-style configurations satisfying its conditions.","successor":"PROOF-CONTRIB-2024-REALWORLD-SE"},{"change_dimensions":["security"],"evidence_locator":"Real-world Universal zkSNARKs abstract and system coverage","evidence_url":"https://eprint.iacr.org/2024/721","id":"lineage-6f0e0e9a101aeb2f","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2019-MARLIN-AHP","relation_basis":"analysis","relation_type":"ANALYZES","review_status":"primary_source_checked","statement":"The later security analysis includes optimized Marlin-style universal zkSNARK configurations within its simulation-extractability framework.","successor":"PROOF-CONTRIB-2024-REALWORLD-SE"},{"change_dimensions":["security","assumption"],"evidence_locator":"On Knowledge-Soundness of Plonk abstract and batching theorems","evidence_url":"https://eprint.iacr.org/2024/994","id":"lineage-6ba1365678a5e190","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2010-KZG-PCS","relation_basis":"analysis","relation_type":"ANALYZES","review_status":"primary_source_checked","statement":"The PLONK knowledge-soundness work analyzes computational special soundness for KZG batch-opening protocols used by modern configurations.","successor":"PROOF-CONTRIB-2024-PLONK-KS"},{"change_dimensions":["security","assumption"],"evidence_locator":"On Knowledge-Soundness of Plonk abstract and PLONK theorems","evidence_url":"https://eprint.iacr.org/2024/994","id":"lineage-a0af993b99a41316","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2019-PLONK-PIOP","relation_basis":"analysis","relation_type":"ANALYZES","review_status":"primary_source_checked","statement":"The later work isolates interactive PLONK special soundness and the assumptions needed before a random-oracle compilation claim.","successor":"PROOF-CONTRIB-2024-PLONK-KS"},{"change_dimensions":["efficiency"],"evidence_locator":"Proving CPU Executions in Small Space abstract and Section 7","evidence_url":"https://eprint.iacr.org/2025/611","id":"lineage-afceaa8418752a21","map_relation":"lineage","predecessor":"PROOF-CONTRIB-2023-JOLT-LOOKUPVM","relation_basis":"technical_dependency","relation_type":"OPTIMIZES","review_status":"primary_source_checked","statement":"The small-space work retains the Jolt stack while changing the honest prover algorithm through streaming and recomputation instead of recursive sharding.","successor":"PROOF-CONTRIB-2025-JOLT-SPACE"}],"rubric_version":1,"schema_version":1,"selection_policy":"semantic_contract_anchors","subfield_views":[{"collection_id":"proof_polynomial_commitments","comparison_groups":[{"id":"concrete_pcs","label":"Polynomial commitment construction","reason":"KZG is currently the explicitly named concrete PCS component. The generic multilinear PCS interface, vector commitments, and proximity machinery do not supply interchangeable complete PCS construction rows.","record_ids":["PROOF-COMP-KZG"],"row_type":"technique"}],"comparison_note":"The contribution corpus covers more PCS results than the current normalized construction records. Additional exact PCS rows are needed for a broader construction comparison; proof-system consumers do not fill that gap.","focus_ids":["proof_succinct_verification","proof_setup_transparency","proof_post_quantum"],"problem_ids":["PROOF-OP-002"],"problem_note":"PROOF-OP-002 directly asks for a transparent post-quantum polynomial commitment with constant opening size and verification; this assignment follows its PCS target, not every proof system using a PCS."},{"collection_id":"proof_aggregation_incremental_verification","comparison_groups":[{"id":"composition_configurations","label":"Recursive and incremental configurations","reason":"These explicit configurations respectively wrap verification, fold relaxed R1CS, multi-fold CCS, or accumulate special-sound protocols. Preserve what is accumulated and the separate final verification or compression obligation.","record_ids":["PROOF-SYSTEM-HALO","PROOF-SYSTEM-NOVA","PROOF-SYSTEM-HYPERNOVA","PROOF-SYSTEM-PROTOSTAR"],"row_type":"construction"},{"id":"composition_interfaces","label":"Composition interfaces","reason":"The named mechanisms operate on different objects and are compared as interfaces, separately from their full configurations; folding is not automatically a succinct argument.","record_ids":["PROOF-COMP-RECURSIVE-WRAP","PROOF-COMP-RELAXED-FOLD","PROOF-COMP-MULTIFOLD","PROOF-COMP-SPECIAL-SOUND-ACCUMULATION"],"row_type":"technique"}],"comparison_note":"Aggregation, recursive wrapping, accumulation, and folding are not interchangeable algorithms. The existing configuration seed does not cover every aggregation result in the contribution list.","focus_ids":["proof_setup_transparency"],"problem_ids":["PROOF-OP-004"],"problem_note":"PROOF-OP-004 targets non-interactive accumulation without random oracles. Its accumulation target places it here; non-interactivity alone does not turn it into a NIZK problem."},{"collection_id":"proof_interactive_oracle_protocols","comparison_groups":[{"id":"protocol_interfaces","label":"Interactive and oracle protocol interfaces","reason":"These records describe independently named interactive or algebraic-oracle protocol interfaces. Their input relation, final evaluation obligation, and compiler assumptions differ; a shared row type does not make their costs directly comparable.","record_ids":["PROOF-COMP-SUMCHECK","PROOF-COMP-INNER-PRODUCT","PROOF-COMP-POLY-IOP"],"row_type":"technique"}],"comparison_note":"These are protocol components, not complete non-interactive proof systems. Compiled-system comparisons remain available in the short-proof and succinct-argument scope.","focus_ids":["proof_succinct_verification","proof_universal_expressiveness","proof_deployed_security","proof_post_quantum"],"problem_ids":["PROOF-OP-003"],"problem_note":"PROOF-OP-003 directly concerns state-preserving extraction for the specified IOP-based argument interface, so it also belongs to zero-knowledge and knowledge-extraction research and succinct arguments without being copied into new problem identities."},{"collection_id":"proof_zero_knowledge_security","comparison_groups":[],"comparison_note":"This subfield currently records definitions, simulation transforms, and independent security analyses. Exact comparable theorem rows are not yet normalized; original PLONK or Marlin configurations must not inherit guarantees proved for separately optimized variants.","focus_ids":["proof_deployed_security","proof_post_quantum"],"problem_ids":["PROOF-OP-003"],"problem_note":"PROOF-OP-003 explicitly asks for a stronger knowledge-extraction guarantee. PROOF-OP-001 asks for adaptive soundness, which does not by itself establish a knowledge-extraction or zero-knowledge target."},{"collection_id":"proof_nizk","comparison_groups":[{"id":"nizk_configurations","label":"Non-interactive zero-knowledge configurations","reason":"Each selected source configuration explicitly records non-interactivity and computational zero knowledge. Groth16's circuit-specific CRS and the KZG-backed compiled configurations retain their different setup and proof-model conditions; no stronger optimized-variant extraction claim is inherited.","record_ids":["PROOF-SYSTEM-GROTH16","PROOF-SYSTEM-MARLIN-KZG","PROOF-SYSTEM-PLONK-KZG"],"row_type":"construction"}],"comparison_note":"This is a selected configuration seed, not the full NIZK history or all NIZK-capable systems. BFM and FLS are separately recorded model and transformation contributions, not complete configuration rows.","focus_ids":["proof_deployed_security","proof_succinct_verification"],"problem_ids":[],"problem_note":"No existing problem card has yet been assigned directly to a NIZK target. Non-interactive accumulation and soundness-only SNARG targets do not establish zero knowledge by terminology alone; this is not a claim that NIZK has no open problems."},{"collection_id":"proof_succinct_arguments","comparison_groups":[{"id":"argument_configurations","label":"Short-proof and succinct-argument configurations","reason":"These exact argument configurations expose proof size, verification, proving, setup, and security contracts. Bulletproofs' short communication remains distinct from a succinct verifier; generic folding cores are not inserted as complete arguments.","record_ids":["PROOF-SYSTEM-GROTH16","PROOF-SYSTEM-BULLETPROOFS","PROOF-SYSTEM-STARK","PROOF-SYSTEM-MARLIN-KZG","PROOF-SYSTEM-PLONK-KZG","PROOF-SYSTEM-SPARTAN"],"row_type":"construction"}],"comparison_note":"Membership is not a universal performance ranking. Preserve circuit-specific or reusable setup, interaction compilation, verifier complexity, and configuration-dependent guarantees in every comparison.","focus_ids":["proof_succinct_verification","proof_setup_transparency","proof_universal_expressiveness","proof_deployed_security","proof_post_quantum"],"problem_ids":["PROOF-OP-001","PROOF-OP-003"],"problem_note":"PROOF-OP-001 targets adaptive all-NP succinct arguments under its stated assumptions; PROOF-OP-003 targets extraction for IOP-based succinct arguments. Their distinct soundness and knowledge obligations remain separate canonical problems."}],"threads":[{"color":"#667784","description":"Definitions and compilers that establish non-interactive and succinct proof contracts.","id":"proof_foundational_compilers","label":"Foundational proof compilers"},{"color":"#8b6340","description":"Pairing-based arguments with highly compressed proofs and verification.","id":"proof_pairing_qap","label":"Pairing and QAP succinctness"},{"color":"#73549a","description":"Polynomial protocols, commitment backends, and universal compilers.","id":"proof_polynomial_iop","label":"Polynomial IOP and commitments"},{"color":"#4f7b60","description":"Hash-authenticated coded oracles and Reed–Solomon proximity mechanisms.","id":"proof_transparent_oracle","label":"Transparent coded-oracle systems"},{"color":"#55758b","description":"Discrete-log inner-product arguments and commitment configurations reused in transparent recursion.","id":"proof_inner_product","label":"Inner-product commitments"},{"color":"#6f8050","description":"Transparent group- and lattice-based PCS constructions outside the coded-oracle genealogy.","id":"proof_transparent_pcs","label":"Transparent polynomial commitments"},{"color":"#2f718e","description":"Multilinear arithmetization and sum-check-based arguments.","id":"proof_sumcheck_multilinear","label":"Sum-check and multilinear proofs"},{"color":"#8e526e","description":"Mechanisms for aggregation, recursive composition, PCD, and IVC.","id":"proof_recursive_composition","label":"Recursion, accumulation, and folding"},{"color":"#2f7d77","description":"Lookup-centric proof architectures and virtual-machine realizations.","id":"proof_lookup_vm","label":"Lookup arguments and zkVMs"},{"color":"#a34e48","description":"Exact knowledge, simulation-extractability, and post-quantum analyses of optimized systems.","id":"proof_security_audit","label":"Security of concrete configurations"}]},"routes":[{"current_bottleneck":"The compiler assumes the central missing base object; known all-NP candidates either add non-falsifiable or proof-unprovability assumptions or weaken soundness.","evidence":"primary_source_checked","falsifiable_next_test":"For one candidate mild all-NP argument, write the exact extractor runtime and succinctness factor and check every hypothesis of Theorems 1–2 before attempting the recursive boost.","id":"PROOF-ROUTE-001","mechanism":"Instantiate the Cheng–Goyal mild-to-full compiler with a mildly succinct, adaptively knowledge-sound argument for all NP whose base security uses standard falsifiable assumptions and whose extractor satisfies the compiler's efficiency requirement.","status":"source_grounded_route","targets":["PROOF-OP-001"],"title":"Bootstrap a mild standard-assumption SNARK to full succinctness"},{"current_bottleneck":"Existing folding and proximity paths pay at least logarithmic transcript or verification cost, while known constant endpoints use non-post-quantum groups of unknown order.","evidence":"primary_source_checked","falsifiable_next_test":"Specify one proposed terminal compression and either prove degree-independent verifier work plus quantum binding, or exhibit the exact transcript/commitment term that still grows with log N.","id":"PROOF-ROUTE-002","mechanism":"Start from a quantum-audited hash- or lattice-based folding/proximity PCS and seek a degree-independent terminal check or recursion that preserves transparent setup and quantum extractability.","status":"source_grounded_route","targets":["PROOF-OP-002"],"title":"Compress transparent post-quantum polynomial openings past the logarithmic frontier"},{"current_bottleneck":"The present reduction extracts an IOP adversary and proves the stated knowledge notion, but it does not return the stronger environment-compatible state required for witness-extended or state-preserving extraction.","evidence":"primary_source_checked","falsifiable_next_test":"Formalize a one-round state-distance invariant for the IBCS opening measurement and prove or refute that the repair procedure preserves it under collapse-position binding.","id":"PROOF-ROUTE-003","mechanism":"Refine the multi-round quantum rewinding reduction so each extraction/repair step maintains an invariant relating the adversary's residual state to an accepting real transcript, then compose these bounds across IOP rounds.","status":"source_grounded_route","targets":["PROOF-OP-003"],"title":"Coherent rewinding with an explicit residual-state invariant"},{"current_bottleneck":"The non-interactive challenge must remain unpredictable and extractable across recursive accumulation without programming a random oracle or assuming knowledge of committed exponents.","evidence":"primary_source_checked","falsifiable_next_test":"Apply one candidate standard-model compiler to the two-instance accumulation game and either prove its adaptive knowledge-soundness reduction or produce a concrete circularity/dangling-extraction failure.","id":"PROOF-ROUTE-004","mechanism":"Isolate the exact challenge/commitment interface used by a special-sound folding or accumulation protocol and replace the Fiat–Shamir step with a standard-model non-interactive compiler under a named falsifiable assumption not already known to imply general SNARKs.","status":"source_grounded_route","targets":["PROOF-OP-004"],"title":"Standard-model compilation of a special-sound accumulation protocol"}],"stats":{"backboneClaims":18,"barriers":4,"benchmarkRuns":2,"claims":30,"comparableBenchmarkRuns":0,"components":22,"constructions":11,"countsByType":{"barrier":4,"benchmark_run":2,"construction":11,"implementation":5,"milestone":12,"open_problem":4,"paper":29,"result":30,"route":4,"technique":22},"entities":123,"implementations":5,"lineageRelationships":14,"milestones":12,"openProblems":4,"propertyAssertions":55,"relationships":221,"routes":4,"systems":11,"unresolvedReferences":0},"systems":[{"claim_ids":["PROOF-CONTRIB-2016-GROTH-3ELEMENT"],"complexity":{"memory":"not_reported","proof_size":"three_group_elements","prover":"linear_group_work_in_circuit_size","verifier":"constant_pairings_plus_public_input_work"},"configuration_note":"The structured group encoding is integral to this configuration; it is not represented as a modular PCS slot.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-GROTH16","name":"Groth16","paper_ids":["PROOF-PAPER-2016-GROTH"],"properties":{"interaction":"non_interactive","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"circuit_specific_structured_crs","soundness":"knowledge_soundness_in_stated_model"},"research_lenses":["pairing-succinct"],"stack":{"arithmetization":["PROOF-COMP-R1CS","PROOF-COMP-QAP"],"commitment_backend":[],"compiler":[],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-PAIRING-QAP"],"specialized_argument":[]},"stack_status":{"commitment_backend":"not_separate","compiler":"not_applicable","composition_mechanism":"not_applicable","specialized_argument":"not_applicable"},"status":"published","summary":"It is the compact pairing-based endpoint against which setup flexibility, transparency, and recursive friendliness are often contrasted.","system_family":"pairing_qap_snark","tasks":["succinct_argument_of_knowledge","zero_knowledge"],"title":"Groth16 · QAP / circuit-specific CRS","visibility":"backbone","year":2016},{"claim_ids":["PROOF-CONTRIB-2017-BULLETPROOFS-IPA"],"complexity":{"memory":"not_reported","proof_size":"logarithmic_in_witness_size","prover":"linear_in_witness_or_constraint_size","verifier":"linear_for_general_arithmetic_circuits"},"configuration_note":"General arithmetic-circuit row; aggregated range proofs are a related specialized task.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-BULLETPROOFS","name":"Bulletproofs","paper_ids":["PROOF-PAPER-2017-BULLETPROOFS"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"transparent_generators","soundness":"argument_of_knowledge_in_random_oracle_model"},"research_lenses":["transparent-hash","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-INNER-PRODUCT"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_separate","specialized_argument":"out_of_scope"},"status":"published","summary":"It shows that logarithmic proofs and no trusted setup do not imply a succinct verifier in every dimension.","system_family":"inner_product_argument","tasks":["zero_knowledge_argument","range_proof","aggregation"],"title":"Bulletproofs · general arithmetic-circuit configuration","visibility":"backbone","year":2017},{"claim_ids":["PROOF-CONTRIB-2018-STARK-SYSTEM"],"complexity":{"memory":"implementation_dependent","proof_size":"polylogarithmic_style_but_large_constants","prover":"quasilinear_style_for_supported_trace_encoding","verifier":"sublinear_polylogarithmic_style"},"configuration_note":"Representative 2018 coded-oracle architecture; FRI/IOP variants and later engineering are not merged into one benchmark row.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-STARK","name":"ZK-STARK","paper_ids":["PROOF-PAPER-2018-STARK"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"conditional_hash_model","privacy":"zero_knowledge_in_displayed_system","setup":"transparent","soundness":"computational_from_hash_and_iop_analysis"},"research_lenses":["transparent-hash"],"stack":{"arithmetization":["PROOF-COMP-AIR"],"commitment_backend":["PROOF-COMP-FRI"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","summary":"It makes transparency and hash-based assumptions visible as properties of a full AIR/IOP/backend stack.","system_family":"transparent_iop","tasks":["transparent_argument","zero_knowledge","scalable_verification"],"title":"ZK-STARK · AIR / coded-oracle configuration","visibility":"backbone","year":2018},{"claim_ids":["PROOF-CONTRIB-2019-HALO-RECURSION"],"complexity":{"memory":"implementation_dependent","proof_size":"does_not_grow_with_recursion_depth","prover":"configuration_dependent_recursive_work","verifier":"does_not_grow_with_recursion_depth"},"configuration_note":"Original recursive composition architecture using nested amortization and a cycle of non-pairing curves; this release does not normalize it to the later Halo2 PLONKish arithmetization.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-HALO","name":"Halo","paper_ids":["PROOF-PAPER-2019-HALO"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"conditional_on_full_configuration","setup":"transparent_generators","soundness":"argument_in_stated_random_oracle_model"},"research_lenses":["recursion-ivc","transparent-hash"],"stack":{"arithmetization":[],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-RECURSIVE-WRAP"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-INNER-PRODUCT"],"specialized_argument":[]},"stack_status":{"arithmetization":"not_normalized","specialized_argument":"out_of_scope"},"status":"published","summary":"Halo’s recursive wrapping is compared with folding only in the composition table, where the mechanism distinction is explicit.","system_family":"recursive_ipa_argument","tasks":["recursive_composition","proof_aggregation"],"title":"Halo · IPA / curve-cycle recursive configuration","visibility":"backbone","year":2019},{"claim_ids":["PROOF-CONTRIB-2019-MARLIN-AHP","PROOF-CONTRIB-2024-REALWORLD-SE"],"complexity":{"memory":"implementation_dependent","proof_size":"constant_number_of_commitments_and_openings","prover":"quasilinear_polynomial_work","verifier":"succinct_after_preprocessing"},"configuration_note":"Concrete representative instantiation of the AHP compiler with KZG.","evidence":"claim_audited","id":"PROOF-SYSTEM-MARLIN-KZG","name":"Marlin + KZG","paper_ids":["PROOF-PAPER-2019-MARLIN","PROOF-PAPER-2010-KZG"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"universal_updatable_structured_srs","soundness":"knowledge_soundness_and_claim_specific_extractability"},"research_lenses":["universal-polynomial","security-audit"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-KZG"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","summary":"Marlin makes the AHP-to-PCS compiler boundary explicit, which is central to the atlas stack view.","system_family":"universal_ahp_snark","tasks":["preprocessing_snark","zero_knowledge"],"title":"Marlin · AHP / KZG configuration","visibility":"backbone","year":2019},{"claim_ids":["PROOF-CONTRIB-2019-PLONK-PIOP","PROOF-CONTRIB-2024-REALWORLD-SE","PROOF-CONTRIB-2024-PLONK-KS"],"complexity":{"memory":"implementation_dependent","proof_size":"constant_number_of_group_and_field_elements","prover":"quasilinear_polynomial_work","verifier":"succinct_plus_public_input_work"},"configuration_note":"Fixes the original PLONKish protocol with KZG and Fiat–Shamir; other Halo2-style or alternative-PCS configurations require separate rows.","evidence":"claim_audited","id":"PROOF-SYSTEM-PLONK-KZG","name":"PLONK + KZG","paper_ids":["PROOF-PAPER-2019-PLONK","PROOF-PAPER-2010-KZG"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false","privacy":"computational_zero_knowledge","setup":"universal_updatable_structured_srs","soundness":"claim_and_variant_specific"},"research_lenses":["universal-polynomial","pairing-succinct","security-audit"],"stack":{"arithmetization":["PROOF-COMP-PLONKISH"],"commitment_backend":["PROOF-COMP-KZG"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","summary":"Security cards expose which batching and optimization choices are covered. The family name alone carries no automatic theorem.","system_family":"universal_polynomial_iop_snark","tasks":["succinct_argument_of_knowledge","zero_knowledge"],"title":"PLONK · original KZG-backed configuration","visibility":"backbone","year":2019},{"claim_ids":["PROOF-CONTRIB-2019-SPARTAN-R1CS"],"complexity":{"memory":"implementation_dependent","proof_size":"logarithmic_style_under_selected_commitment","prover":"linear_for_displayed_r1cs_path","verifier":"sublinear_after_public_preprocessing"},"configuration_note":"Representative transparent Spartan architecture; the multilinear PCS interface is explicit because concrete instantiations change proof and verifier costs.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-SPARTAN","name":"Spartan","paper_ids":["PROOF-PAPER-2019-SPARTAN"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_discrete_log_instantiation","privacy":"computational_zero_knowledge","setup":"transparent_with_public_preprocessing_for_sublinear_verification","soundness":"knowledge_soundness_in_stated_model"},"research_lenses":["multilinear-sumcheck","transparent-hash"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-MLPCS"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-SUMCHECK"],"specialized_argument":[]},"stack_status":{"composition_mechanism":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","summary":"It anchors the multilinear/sum-check path later reused in folding systems and lookup-oriented zkVMs.","system_family":"multilinear_sumcheck_snark","tasks":["transparent_zksnark","general_r1cs"],"title":"Spartan · transparent R1CS / sum-check configuration","visibility":"backbone","year":2019},{"claim_ids":["PROOF-CONTRIB-2021-NOVA-FOLDING"],"complexity":{"memory":"step_circuit_and_commitment_dependent","proof_size":"constant_size_running_ivc_state; a succinct final proof requires optional compression","prover":"per_step_linear_multiexponentiation_style","verifier":"constant_size_incremental_state_check_plus_separate_final_decider"},"configuration_note":"This row is the folding-based IVC core, not a claim that folding alone is a complete succinct proof system; optional SNARK compression and the final decider remain separate.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-NOVA","name":"Nova","paper_ids":["PROOF-PAPER-2021-NOVA"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_displayed_commitment","privacy":"zero_knowledge_in_paper_configuration","setup":"transparent_generators","soundness":"folding_soundness_plus_final_decider"},"research_lenses":["recursion-ivc","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-RELAXED-FOLD"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":[],"specialized_argument":[]},"stack_status":{"protocol_iop":"not_applicable","specialized_argument":"out_of_scope"},"status":"published","summary":"Nova changes the recursion problem from repeatedly proving verifier execution to folding the relation instances themselves.","system_family":"folding_based_ivc","tasks":["ivc"],"title":"Nova · relaxed-R1CS folding core","visibility":"backbone","year":2021},{"claim_ids":["PROOF-CONTRIB-2023-HYPERNOVA-MULTIFOLD"],"complexity":{"memory":"relation_and_commitment_dependent","proof_size":"constant_size_running_state_plus_optional_compression","prover":"one_primary_msm_style_per_fold_plus_sumcheck_work","verifier":"constant_size_incremental_state_plus_final_decider"},"configuration_note":"Displays CCS, multi-folding, and IVC/PCD capability as three different semantic layers.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-HYPERNOVA","name":"HyperNova","paper_ids":["PROOF-PAPER-2023-HYPERNOVA"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_displayed_commitment","privacy":"zero_knowledge_via_randomized_folding_in_updated_version","setup":"transparent_generators","soundness":"multifolding_soundness_plus_final_decider"},"research_lenses":["recursion-ivc","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-CCS"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-MULTIFOLD"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-SUMCHECK"],"specialized_argument":[]},"stack_status":{"specialized_argument":"out_of_scope"},"status":"published","summary":"It demonstrates how a more expressive relation layer and multi-instance composition should be represented without promoting either to a new top-level field.","system_family":"ccs_multifolding_ivc","tasks":["ivc","non_uniform_ivc","pcd"],"title":"HyperNova · CCS multi-folding configuration","visibility":"backbone","year":2023},{"claim_ids":["PROOF-CONTRIB-2023-JOLT-LOOKUPVM","PROOF-CONTRIB-2025-JOLT-SPACE"],"complexity":{"memory":"linear_baseline_with_source_backed_small_space_alternative","proof_size":"commitment_backend_dependent","prover":"dominated_by_execution_lookup_memory_and_commitment_work","verifier":"succinct_configuration_dependent"},"configuration_note":"Research architecture row; production implementations and PCS choices require versioned rows before benchmarking.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-JOLT","name":"Jolt","paper_ids":["PROOF-PAPER-2023-JOLT","PROOF-PAPER-2025-JOLT-SPACE"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"depends_on_selected_backend","privacy":"zero_knowledge_configuration_dependent","setup":"depends_on_selected_multilinear_commitment","soundness":"composition_of_spartan_lookup_and_memory_arguments"},"research_lenses":["lookups-zkvm","multilinear-sumcheck"],"stack":{"arithmetization":["PROOF-COMP-R1CS"],"commitment_backend":["PROOF-COMP-MLPCS"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":[],"computation_model":["PROOF-COMP-RISCV"],"protocol_iop":["PROOF-COMP-SUMCHECK"],"specialized_argument":["PROOF-COMP-LOOKUP","PROOF-COMP-MEMORY-CHECK"]},"stack_status":{"composition_mechanism":"optional_external"},"status":"published","summary":"Jolt makes visible why a zkVM is a system stack: ISA semantics, lookups, memory checking, R1CS/Spartan, and a PCS cannot be replaced by one “zkVM” category label.","system_family":"lookup_centric_zkvm","tasks":["zkvm","verifiable_cpu_execution"],"title":"Jolt · lookup-centric RISC-V zkVM stack","visibility":"backbone","year":2023},{"claim_ids":["PROOF-CONTRIB-2023-PROTOSTAR-GENERIC"],"complexity":{"memory":"not_reported","proof_size":"accumulator_state_plus_final_proof","prover":"per_step_cost_independent_of_lookup_table_size_in_stated_setting","verifier":"small_accumulation_verifier_plus_final_decider"},"configuration_note":"Concrete non-uniform IVC instantiation of the paper's generic special-sound accumulation compiler.","evidence":"primary_source_checked","id":"PROOF-SYSTEM-PROTOSTAR","name":"Protostar","paper_ids":["PROOF-PAPER-2023-PROTOSTAR"],"properties":{"interaction":"non_interactive_via_fiat_shamir","post_quantum":"false_for_displayed_commitment","privacy":"conditional_on_full_configuration","setup":"transparent_generators","soundness":"special_sound_accumulation_plus_final_decider"},"research_lenses":["recursion-ivc","lookups-zkvm"],"stack":{"arithmetization":["PROOF-COMP-PLONKISH"],"commitment_backend":["PROOF-COMP-IPA"],"compiler":["PROOF-COMP-FIAT-SHAMIR"],"composition_mechanism":["PROOF-COMP-SPECIAL-SOUND-ACCUMULATION"],"computation_model":["PROOF-COMP-CIRCUIT"],"protocol_iop":["PROOF-COMP-POLY-IOP"],"specialized_argument":["PROOF-COMP-LOOKUP"]},"stack_status":{},"status":"published","summary":"Generic accumulation and the Protostar PLONK/lookup instantiation are distinct objects linked by the source contribution.","system_family":"special_sound_accumulation_ivc","tasks":["non_uniform_ivc","vector_lookups"],"title":"Protostar · special-sound accumulation for PLONK","visibility":"backbone","year":2023}],"topic":{"firstQuestion":"Which atomic contributions changed the proof contract, capability, mechanism, security guarantee, or efficiency frontier, and how do their components combine in exact system configurations?","id":"proof-systems","stage":"representative_analytical_atlas","title":"Proof Systems","unknownSemantics":["true","false","conditional","unknown","not_reported","not_applicable"]},"unresolved":[],"sourceCommit":"v0.2.0","sourceBoundary":"Published literature snapshot"}