LibraryPrivacy2019Design paperCorpus record
Aurora: Transparent Succinct Arguments for R1CS
Aurora. Eli Ben-Sasson, Alessandro Chiesa, Michael Riabzev, Nicholas Spooner, Madars Virza and Nicholas P. Ward.
Aurora proves rank-one constraint systems with a transparent setup, using a FRI-style proximity test rather than a pairing.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
If a rollup says the setup is transparent, ask whether a new circuit needs new toxic waste. Aurora's answer is no.
The five-minute read
The defect
A succinct proof that needs a ceremony cannot be generated for a new program by a person who missed the ceremony.
The proposal
Aurora proves rank-one constraint systems with a transparent setup, using a FRI-style proximity test rather than a pairing.
Transparent means the setup is public randomness.
R1CS is the circuit language, not a chain.
The bound
Transparent does not mean trustless in the sense of no assumption. The hash and the code are the assumptions.
One action, walked through
- Write the computation as a constraint system.
- Prove proximity of a polynomial to a Reed-Solomon code.
- The verifier samples from public randomness and checks the transcript.
- What is the constraint language?
The argument, unpacked
What the paper is for
If a rollup says the setup is transparent, ask whether a new circuit needs new toxic waste. Aurora's answer is no.
What happened after
STARKs and later FRI systems are the production line. Aurora is a specific R1CS argument on that line.
What has to be true
- Transparent does not mean trustless in the sense of no assumption. The hash and the code are the assumptions.
- Proving time is the cost this family pays.
- It is not Groth16 and not PLONK.
What happened after the paper
STARKs and later FRI systems are the production line. Aurora is a specific R1CS argument on that line.
What to check before you use the idea
- Does a new program need a new setup?
- What is the constraint language?
- What does the verifier assume about the hash?
Terms
- Transparent setup
- Public randomness. No secret the prover must not know.
- R1CS
- A way to write a computation as rank-one constraints.
The problem the paper names
A succinct proof that needs a ceremony cannot be generated for a new program by a person who missed the ceremony.
What the design proposes
- Transparent means the setup is public randomness.
- R1CS is the circuit language, not a chain.
- Succinct is a communication claim, not a claim that proving is cheap.
How the mechanism is specified
- Write the computation as a constraint system.
- Prove proximity of a polynomial to a Reed-Solomon code.
- The verifier samples from public randomness and checks the transcript.
What this page does not treat as proven
- Transparent does not mean trustless in the sense of no assumption. The hash and the code are the assumptions.
- Proving time is the cost this family pays.
- It is not Groth16 and not PLONK.
Why a venture studio still reads it
If a rollup says the setup is transparent, ask whether a new circuit needs new toxic waste. Aurora's answer is no.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
