Reference
Glossary
Short definitions of the protocol, state-model and engine terms used throughout the StateSync-GKR documentation, each linked to the page that explains it.
Terms are listed alphabetically. Code names in parentheses are the Rust items that implement the term.
A#
Accumulator#
One of the running digests along a Merkle path: the leaf hash first, then the result of each compression up to the root. The witness carries all of them, and the circuit checks each transition independently. See Circuits and layers.
AssetId#
The key of a slot in the sparse Merkle tree, a wrapper around u64 (AssetId). While the depth is below 64 it must be less than 2^depth. See Sparse Merkle state.
B#
Batch#
A set of independent jobs that share one prepared circuit, each with its own witness, transcript and proof. A batch produces one proof per job, identical to the single-request proof; it is not proof aggregation. See Batching and parallelism.
C#
Challenge field#
The degree-four binomial extension of KoalaBear from which verifier challenges are drawn (ChallengeField). Its size, about 2^124 elements, keeps the per-round error of the interactive protocol small. See How GKR works.
Circuit identity#
The section of an encoded proof that names the circuit the proof is for: operation tag, depth, version axes, leaf bound, strategy and full circuit commitment (CircuitIdentity). Verifiers compare it with the identity computed from their own configuration. See Wire format.
Cube gate#
A Pow3 gate, which adds coeff * a^3 to its output wire and represents the Poseidon2 S-box. It is an operation of the circuit representation, not a processor instruction. See Circuits and layers.
D#
Dense reference#
DenseLayerOracle, a test-only prover oracle that materializes six tables over all input pairs of a layer. It anchors the equivalence tests and the internal memory comparison; production proving uses the sparse oracle. See How GKR works.
Derived wiring#
The production verifier's wiring oracle (DerivedRegularWiring). It evaluates data-parallel gate families in closed form, keeps every other gate on an exact sparse path, and is always rebuilt locally from the compiled circuit and its hints. See Circuits and layers.
Domain tag#
A fixed byte string absorbed first into a sponge so that the inputs of its different uses start with different prefixes: statesync-gkr/v0.1 for proof transcripts and ssgkr/circuit-commitment/v1 for circuit commitments. See Configuration.
F#
Fiat-Shamir#
The transform that replaces a verifier's random challenges with values derived from a hash of all earlier messages, which makes an interactive protocol non-interactive. Here the hash is a Poseidon2 duplex transcript. See How GKR works.
Full circuit commitment#
A Poseidon2 digest of a compiled circuit's configuration and of every gate and constant in it. Every proof transcript absorbs it, encoded proofs carry it, and verifiers take it from their own preparation. See Wire format.
G#
Gate kind#
One of the three weighted gates of the circuit representation (GateKind): Lin adds coeff * a, Mul adds coeff * a * b and Pow3 adds coeff * a^3. See How GKR works.
GKR#
The interactive proof protocol of Goldwasser, Kalai and Rothblum for layered arithmetic circuits. A claim about the outputs is reduced, one sumcheck per layer, to claims about the inputs. See How GKR works.
I#
Inner proof#
The GKR proof StateSync-GKR produces for one request (GkrProof), as opposed to an outer proof that wraps it. It is not zero-knowledge, and its verifier also needs the request's private witness. See Proof lifecycle.
inner-proof-v1#
The frozen canonical byte encoding of an inner proof together with its circuit identity and statement. See Wire format.
K#
KoalaBear#
The prime field with p = 2^31 - 2^24 + 1 = 2130706433 that holds circuit values, digests and public inputs (BaseField). See How GKR works.
L#
Layer strategy#
The rule that maps tree levels to GKR layers (LayerStrategy). Only strategy A, one data-parallel instance per tree level, compiles. See Configuration.
Layered circuit#
An arithmetic circuit divided into layers in which every wire depends only on wires of the next layer, the form GKR proves (LayeredCircuit). See How GKR works.
Leaf bound#
The maximum length of a leaf encoding in field elements, tag included (SmtParams::leaf_max_fields, 31 by default). It fixes the width of the leaf hash's pre-image. See Configuration.
Leaf pre-image#
The fixed-width layout of a leaf encoding that the leaf hash absorbs: the tag, the encoding length, the rest of the encoding verbatim, then zeros (leaf_fold). See Sparse Merkle state.
M#
Merkle path#
The sibling digests that connect a leaf to the root, ordered from the leaf level upward (MerklePath). A path for a tree of depth d holds exactly d siblings. See Sparse Merkle state.
MLE#
Multilinear extension: the unique polynomial of degree at most one in each variable that agrees with a table of 2^s values on every s-bit input. GKR evaluates layer values and wiring predicates as MLEs at random points. See How GKR works.
O#
Operation kind#
One of Membership, NonMembership and Update (SmtOpKind). Each kind has its own compiled circuit and the public operation tag 0, 1 or 2. See Sparse Merkle state.
P#
Poseidon2#
The hash permutation used for in-circuit hashing, the transcript and the circuit commitment: width 16 over KoalaBear with an x^3 S-box. See How GKR works.
Prepared material#
Reusable setup for one operation kind and configuration. In memory it is PreparedSync: the compiled circuit, derived wiring and full circuit commitment, built once. PreparedMaterialV1 is a canonical byte form of a circuit and its hints for one fixed profile (depth 24, strategy A, membership), from which the derived wiring is always rebuilt locally. See Proof lifecycle.
Public inputs#
The statement a proof is about: old_root, new_root, op_kind_tag, asset_id and value_digest, in that fixed order (PublicInputs). See Proof lifecycle.
R#
Receipt#
Evidence from an external verification network that it checked a submitted proof. A zkVerify testnet receipt is recorded for the fixed depth-24 membership example of the external wrap path; it is integration evidence, not a settlement or finality result. See Trust boundaries.
Residual claim#
What remains after a verifier's reduction steps: a point and the value a polynomial must take there. Sumcheck leaves a Subclaim; GKR verification leaves an InputClaim with two points on the input vector, which the party that knows the inputs must check. See How GKR works.
Residual output#
An output wire whose value is the difference between two quantities that must be equal. A compiled SMT circuit accepts exactly when every residual output is zero. See Circuits and layers.
Round polynomial#
The univariate polynomial a sumcheck prover sends in each round (RoundPoly). Each one here has degree at most 4 and is encoded as exactly five coefficients. See Wire format.
S#
Sparse layer reduction#
The production prover oracle (SparseLayerOracle). It answers each layer's sumcheck with Libra-style two-phase booking: tables over the first half of the variables, then tables over the second half, each with one entry per input wire. See How GKR works.
Sparse Merkle tree#
A Merkle tree over a fixed key space in which most slots are empty. StateSync-GKR proves membership, non-membership and single-leaf updates over one. See Sparse Merkle state.
Succinct wrapper#
An outer proof system that proves the wrap relation of an encoded inner proof and gives external verifiers a small proof. The published one is a RISC Zero native succinct proof for one fixed depth-24 membership example, not a service for arbitrary requests. See Trust boundaries.
Sumcheck#
An interactive protocol that checks a claimed sum of a polynomial over all boolean inputs, one variable per round, and ends in one evaluation at a random point. GKR runs one sumcheck per layer. See How GKR works.
T#
Table wiring#
The general wiring oracle (TableWiring), which evaluates predicate MLEs by iterating a circuit's sparse gate list. The derived oracle is checked against it, and verify_sync_op_reference uses it. See Circuits and layers.
Tombstone#
The leaf state of a deleted slot (LeafState::Tombstone). It differs from Empty, the never-used state, and both satisfy non-membership. See Sparse Merkle state.
Transcript#
The Poseidon2 duplex sponge that prover and verifier feed with the same observations, in the same order, to derive Fiat-Shamir challenges (Transcript). See Proof lifecycle.
V#
Value digest#
The public input naming the leaf an operation asserts: the hash of the occupied leaf, of the asserted empty or tombstone leaf, or of the new leaf of an update. See Proof lifecycle.
W#
Witness#
The private data of a request: the leaf and its sibling path (SmtWitness). The prover expands it into a value for every wire (CircuitWitness), and the verifier needs it to check the input claims. See Proof lifecycle.
Wrap relation#
The predicate an outer proof attests: the encoded inner proof decodes to this configuration's circuit identity, and the inner verifier accepts it for the request. wrap_relation returns the wrap statement exactly when the relation holds. See Proof lifecycle.
Wrap statement#
wrap-statement-v1, the six BN254 scalars an outer proof exposes: a header word, the circuit commitment, both roots, the key and the value digest. See Wire format.