3

I've come across this paper that benchmarks the efficiency of zk-SNARKs, zk-STARKs and Bulletproofs.

The table on page 8 states that the verification time for zk-SNARKs is linear in the size of the computation:

Efficiency and Security Comparison zk-SNARKs, zk-STARKs, Bulletproofs

Specifically they refer to Groth16 and Pinocchio in their evaluation of SNARKs.

I thought at least Groth16 has constant verification time and it also doesn't make any sense to me how the proof size can be constant (which they also state in the table) and the verification time is not.

EDIT: If anyone knows a different study that benchmarks zk-snarks or any of the other protocols, I would appreciate the recommendation :)

Niko Wolf
  • 111
  • 4

0 Answers0