"Semi-dynamic" Groth16 proofs

This is loosely based on the Dynark paper:

  • "Dynark: Making Groth16 Dynamic" by Tianyu Zhang, Yupeng Ouyang and Yupeng Zhang

See also this write-up (mostly following the paper).

Here some details are different from the paper though, and our implementation is noticeably more efficient in practice.