privacy-scaling-explorations / halo2curves

Other
174 stars 141 forks source link

Faster G2 subgroup check for BN curve #173

Closed kilic closed 1 month ago

kilic commented 2 months ago

Subgroup membership check in G2 is group order exponentiation. This PR makes it much more cheaper replacing with method ported from gnark-crypto