Skip to content


Here are 16 public repositories matching this topic...

yelhousni commented Oct 28, 2021

A double-and-add scalar multiplication by N costs on average log(N) doublings and log(N/2) additions. For twisted Edwards curves (used in gnark for edDSA circuits), it costs 7 rank-1 constraints (Groth16) to describe an addition in affine coordinates and 6 for a doubling. These twisted Edwards curves can be converted to Montgomery form where it costs 4 R1C for an addition and **5

Improve this page

Add a description, image, and links to the r1cs topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the r1cs topic, visit your repo's landing page and select "manage topics."

Learn more