-
Notifications
You must be signed in to change notification settings - Fork 537
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Setting gamma to 1 (i.e., eliminating gamma from the verification key) #33
Comments
I'd be slightly hesitant to remove it altogether. You could argue the version with general gamma is potentially more secure as there are less elements the prover can generate in G1 when gamma is unknown, assuming he only has access to the original Groth16 CRS elements. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
It might be worth eliminating gamma from the verification key. I guess this isn't a huge deal, but my understanding from talking to @arielgabizon and Mary Maller is that it isn't actually necessary and you can just use the generator of G2.
This is useful from the point of view of proof composition because it makes the verification key smaller.
The text was updated successfully, but these errors were encountered: