ParanO(1)d soundness under industry metrics
Committed production parameters evaluated under the metrics published by Plonky2, RISC Zero and ethSTARK, with conjectured scores separated from finite theorem-backed bounds.
Research archive
Papers, protocol notes, engineering studies and their results. Ordered by the date each research result was recorded.
Committed production parameters evaluated under the metrics published by Plonky2, RISC Zero and ethSTARK, with conjectured scores separated from finite theorem-backed bounds.
A three-column committed trace reduces an entire batch of Poseidon2b executions with two constraint sumchecks.
HistoryStep is the recursive proof of a block's state transition. B64 handles up to 64 user transaction pages and meets the preparation budget on the reference laptop; B255 extends the same relation to the 255-page block limit. Measurements found no useful operating range for a third class.
An early design accepted a block first and produced its recursive proof later in the background. The canonical chain could therefore move ahead of the HistoryStep-proven tip, forcing nodes to persist and recover a second queue. The production design accepts the block and its matching HistoryStep together: one atomic object, one canonical height and no deferred proof backlog.
HistoryStep binds every semantic header field under a nonce-free domain. PoW can vary the nonce without rebuilding the transition proof.
A joining node validates headers, verifies one recursive transition proof at a finalized boundary, installs exact live State and applies no more than eighteen recent blocks.
A monotone creation identifier inside the existing value lane invalidates stale slot openings without a second consensus root or reuse quarantine.
PCLMUL, VPCLMUL, AVX-512 and PMULL execute the same GF(2¹²⁸) arithmetic without changing witness layout or proof bytes.
A full-composition benchmark showed that independent verifier walks multiplied memory beyond 30 GB. One shared domain removed that factor.
A class with a 2^23-position constraint domain closes recursively: each proof verifies a predecessor with the same authenticated matrix and public layout.
Streaming compilation bounded 14–16 MiB of private authorization data with 4.7% overhead. The evaluated terminal proof did not meet the production latency budget.
Fusing two Merkle relations saved 5.94 KB but enlarged the combined multilinear trace and removed parallelism. Proving regressed from 2.68 to 4.50 seconds.
Public transaction arithmetic belongs to the block relation. The wallet proves one private fact—ownership—even when a spend contains 1,020 inputs.
An A/A′ adversarial test separates low-degree consistency from commitment provenance. A source root and shared queries close the edge.
Ladder FRI exposed proof-byte cost, FRI-Binius exposed source binding, and BaseFold exposed the cost of putting a verifier inside its successor.
No research matches this filter.