2026-06-16 02:38:18 +02:00

531 B

Partial proofs

If a large part of your witness is constant (or changing infrequently), you can precalculate a significant portion of the proof.

See this forum post for more details.

This is essentially free (the overhead is minimal, so already when doing 2 proofs with same shared part of the witness, it's worth do it).

A more advanced version, but one which also comes with a heavy trade-off, is developed in groth16/dynamic.