ARCHITECT_CRYPTOGRAPH_SOVEREIGN // DPH08: 400.100
ARC: [ONLINE]
VELLUM CASH
ENTER APP →
HOME/GITBOOK DOCS/04 // CRYPTOGRAPHY & CIRCUITS/Groth16 & BN254 Curve
FOLIO // 04.2[VERIFIED]
[ MATH // BN254 ]

Groth16 & BN254 Curve

Zero-knowledge proving mechanics, bilinear pairings, and constraint evaluation.

REVISION: MMXXVI.09.15MATHEMATICAL SOUNDNESS: FORMAL PROOFDEPTH 20 MERKLE COMMITMENT

§Why Groth16 zk-SNARKs?#

Vellum Cash selects the Groth16 (2016) zero-knowledge proof system for cross-chain settlement due to several critical engineering factors:

  • Minimal Proof Size: Exactly 3 group elements (A in G_1, B in G_2, C in G_1), amounting to only 128 bytes of calldata.
  • Lowest EVM Verification Cost: Requires only a single multi-scalar multiplication and pairing check on Ethereum, costing ~200,000 gas—far lower than Plonk, STARKs, or Halo2.
  • Sub-second Client Prover Times: Average proving time of 1.18 seconds on modern hardware using SnarkJS WebAssembly and WebGPU acceleration.

  • §The BN254 Pairing-Friendly Curve#

    The BN254 (also known as alt_bn128) elliptic curve is natively supported by Ethereum and EVM-compatible chains via precompiled contracts at addresses 0x06, 0x07, and 0x08.

    Curve Parameters:

  • Base Field: q = 21888242871839275222246405745257275088548364400416034343698204186575808495617
  • Scalar Field: r = 21888242871839275222246405745257275088696311157297823662689037894645226208583
  • Equation: y^2 = x^3 + 3 (mod q)
  • Pairing: Bilinear map e: G_1 × G_2 → G_T

  • §Bilinear Pairing Verification Equation#

    The on-chain verifier checks the validity of proof (A, B, C) against public inputs x by verifying:

    e(A, B) = e(α, β) · e( Σ_(i=0)^l x_i·γ_i , γ ) · e(C, δ)

    If and only if this equality holds in G_T, the proof is mathematically verified, guaranteeing that the prover possesses a valid witness without revealing any secret values.


    §Powers of Tau & Trusted Setup#

    The circuit parameters for Vellum Cash were generated through the universal Hermez Perpetual Powers of Tau ceremony, combined with circuit-specific Phase 2 contributions. The resultant proving keys (.zkey) are publicly hosted and verifiable against known BLAKE2b checksums.

    Was this sovereign documentation page helpful?Continuous formal verification & documentation feedback loop.