Files
circom-stark/README.md
2023-12-07 11:14:16 -06:00

626 B

circom-stark CircleCI

A binding to make R1CS proofs using rstark.

About

R1CS proofs are based on sets of constraints of the form A*B - C = 0 where A, B, and C are scalar sums. We can take such a system and reduce it to a single constraint using a random linear combination. This reduces to a STARK proof with trace length 1 and 1 constraint. The proof speed is limited by the total number of variables (aka signals) in the R1CS.