Skip to content

Home > Proof Systems > Groth16

Groth16

Description

Set a new benchmark for proof size and verification speed that remains the gold standard for many applications. Produces the smallest proofs (3 group elements, ~128–192 bytes) with very fast verification. Requires a circuit-specific trusted setup. Used in Zcash and many other production systems.

Technical Characteristics

Complexity: - Prover: O(n log n) - Verifier: O(1) — 3 pairing operations - Proof Size: ~192 bytes (3 elliptic curve points) - Setup: trusted (circuit-specific CRS)

Security: - Assumption: computational (q-PKE, AGM) - Post-quantum: no (pairing-based) - Basis: Bilinear pairings over BN254 or BLS12-381

Dependencies

Based on: QSP-GGPR13, Pinocchio Circuit representation: R1CS

Applications

Used by: gnark, Circom2, Docknetwork, Zcash

Resources