Papers1 provider · 1 record
July 24, 2025· IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems
article

FPGA-Based Hardware Accelerator of zk-SNARK

Abstract

Zero-Knowledge Proof (ZKP) has gained widespread application across various domains, demonstrating remarkable success. Among ZKP algorithms, Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (zk-SNARK) is the most widely used. However, despite its advantages of small proof size and succinct verification, zk-SNARK proof generation faces significant challenges due to high computational demands, limiting its practical application. This paper addresses these challenges by accelerating two computationally intensive operations in zk-SNARK proof generation, Number Theory Transformation (NTT) and Multi-Scalar Multiplication (MSM), using FPGAs. In the implementation of NTT hardware accelerators for zk-SNARK applications, the traditional 4-step algorithm often encounters conflicts between off-chip bandwidth and on-chip memory. To resolve this issue, we propose an innovative approach that enhances accelerator performance by recursively applying the 4-step algorithm to create a more efficient 6-step algorithm. For MSM hardware acceleration on FPGAs, existing works are often constrained by limited on-chip memory, restricting the use of longer slice lengths, which are crucial for higher performance when using the commenly used Pippenger algorithm. To overcome this limitation, we introduce the Batch Method, optimizing off-chip memory consumption, enabling the accelerator to use longer slice lengths and achieve superior performance. Experimental results demonstrate that the proposed NTT design achieves 1.76× higher DSP efficiency than the SAM. Meanwhile, the proposed MSM design demonstrates 1.24× higher performance than the MSMAC with aligned frequency and number of PEs. When benchmarked against the GPU implementation GZKP, our MSM design exhibits 1.16× and 1.46× higher performance than GZKP for BLS12-381 and BN-254, respectively. However, the NTT design remains at a disadvantage due to the bandwidth limitation between our platform, Xilinx Alveo U250, and GZKP’s platforms, Nvidia GTX 1080 Ti and Nvidia Tesla V100.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.