gnark standard library
We provide the following functions in gnark/std:
- MiMC hash
- EdDSA signature verification
- Merkle proof verification
- zk-SNARK verifier
type mimcCircuit struct {
Data frontend.Variable
Hash frontend.Variable `gnark:",public"`
}
func (circuit *mimcCircuit) Define(api frontend.API) error {
hFunc, err := mimc.NewMiMC(api)
if err != nil {
return err
}
hFunc.Write(circuit.Data)
api.AssertIsEqual(circuit.Hash, hFunc.Sum())
return nil
}
type eddsaCircuit struct {
curveID tedwards.ID
PublicKey eddsa.PublicKey `gnark:",public"`
Signature eddsa.Signature `gnark:",public"`
Message frontend.Variable `gnark:",public"`
}
func (circuit *eddsaCircuit) Define(api frontend.API) error {
curve, err := twistededwards.NewEdCurve(api, circuit.curveID)
if err != nil {
return err
}
hFunc, err := mimc.NewMiMC(api)
if err != nil {
return err
}
return eddsa.Verify(curve, circuit.Signature, circuit.Message, circuit.PublicKey, &hFunc)
}
type merkleCircuit struct {
MerkleProof merkle.MerkleProof
Leaf frontend.Variable
}
func (circuit *merkleCircuit) Define(api frontend.API) error {
hFunc, err := mimc.NewMiMC(api)
if err != nil {
return err
}
// Path[0] is the leaf. The proof index is encoded in little-endian bit
// order in Path[1:].
circuit.MerkleProof.VerifyProof(api, &hFunc, circuit.Leaf)
return nil
}
Enables verifying a BLS12_377 Groth16 Proof inside a BW6_761 circuit
type verifierCircuit struct {
Proof recursion_groth16.Proof[sw_bls12377.G1Affine, sw_bls12377.G2Affine]
VerifyingKey recursion_groth16.VerifyingKey[sw_bls12377.G1Affine, sw_bls12377.G2Affine, sw_bls12377.GT]
InnerWitness recursion_groth16.Witness[sw_bls12377.ScalarField] `gnark:",public"`
}
func (circuit *verifierCircuit) Define(api frontend.API) error {
verifier, err := recursion_groth16.NewVerifier[
sw_bls12377.ScalarField,
sw_bls12377.G1Affine,
sw_bls12377.G2Affine,
sw_bls12377.GT,
](api)
if err != nil {
return err
}
return verifier.AssertProof(circuit.VerifyingKey, circuit.Proof, circuit.InnerWitness)
}
For a complete flow, see std/recursion/groth16/verifier_test.go. It shows how to compile the inner circuit, prove it natively, convert the proof, verifying key, and public witness with ValueOf*, and solve the outer circuit.