Skip to content



Folders and files

Last commit message
Last commit date

Latest commit



36 Commits

Repository files navigation

Verkle Tree

Rust implementation of Verkle tree verifiable by PlonK. The circuit implementation of Verkle tree verification is here.

Original Golang implementation is in crate-crypto/go-ipa and gballet/go-verkle.

This library uses alt-BabyJubjub BN128 instead Bandersnatch as the elliptic curve for commitments.

What this is, and is not

This is not an attempt to further speed up the creation or verification of Verkle tree proofs. The project is positioned as a groundwork for constructing Verkle tree proofs verifiable by PlonK and for making verification of Layer 2 transactions more efficient.


rustup override set nightly
cargo --version # >= 1.56.0


VerkleTreeWith32BytesKeyValue is the 32 bytes key-value storage with G1Affine-valued commitments. See also sample code about how to use this library.

use franklin_crypto::bellman::bn256::G1Affine;
use verkle_tree::bn256_verkle_tree::proof::VerkleProof;
use verkle_tree::bn256_verkle_tree::VerkleTreeWith32BytesKeyValue;

Create an empty Verkle tree

VerkleTreeWith32BytesKeyValue::new() returns a tree consisting of only one root node with no children.

let domain_size = 256;
let committer = IpaConfig::new(domain_size);
let mut tree = VerkleTreeWith32BytesKeyValue::new(committer);

Insert an entry in a Verkle tree

VerkleTreeWith32BytesKeyValue::insert() inserts (key, value) entry in given Verkle tree. This method updates the entry to the new value and returns the old value, even if the tree already has a value corresponding to the key.

let old_value: Option<[u8; 32]> = tree.insert(key, value);

Remove an entry from a Verkle tree

VerkleTreeWith32BytesKeyValue::remove() remove the entry corresponding to key in given Verkle tree. If the tree does not have a value corresponding to the key, this method does not change the tree state.

let old_value: Option<[u8; 32]> = tree.remove(&key);

Get the value from a Verkle tree

VerkleTreeWith32BytesKeyValue::get() fetch the value corresponding to key in given Verkle tree. The maximum time it takes to search entries depends on the depth of given Verkle tree.

let stored_value: Option<&[u8; 32]> = tree.get(&key);

Compute the commitment of a Verkle root

VerkleTreeWith32BytesKeyValue::compute_digest() computes the digest of given Verkle tree.

let digest: Fr = tree.compute_digest()?;

Compute the inclusion/exclusion proof of a Verkle tree (Verkle proof)

VerkleProof::create() returns the inclusion/exclusion proof and its auxiliary data. If keys includes one key, elements.zs[i] is a child index of the internal node corresponding the key prefix of length i, and elements.ys[i] is the value of that child. If keys includes two or more keys, compute elements.zs and elements.ys for each key, and concatenate them.

let (proof, elements) = VerkleProof::create(&mut tree, &keys)?;
let zs = elements.zs;
let ys = elements.ys;

Encode Verkle proof

under development

EncodedVerkleProof::encode() returns a Verkle proof in an serializable form. It omits duplications and elements that can be calculated from other elements.

let encoded_proof = EncodedVerkleProof::encode(&proof);

Decode Verkle proof

under development

EncodedVerkleProof::decode() returns a Verkle proof in an easy-to-calculate form. zs and ys can be restored from proof.

let (proof, zs, ys) = encoded_proof.decode()?;

Validate an inclusion/exclusion proof

VerkleProof::check() returns the validity of given inclusion/exclusion proof. The verification does not use elements.fs, which has information on all child nodes.

let domain_size = 256;
let committer = IpaConfig::new(domain_size);
let is_valid: bool = VerkleProof::check(&proof, &zs, &ys, &committer)?;



The transcript is the object storing all commitments which a prover should submits to a verifier and generating challenges (= pseudo-random variables) on behalf of the verifier. Generating challenges uses Poseidon hash function for low-cost PlonK proofs.

Elliptic Curve

We choose Alt-BN128 (a.k.a. BN254) curve in our implementation for use with Ethereum Solidity. We need this elliptic curve to do the inner product proof.

Verkle Tree

A tree data structure consists of the set called nodes. Each node consist of a value and a list of reference to other nodes called children. No reference is duplicated. There is only one node in a tree that is not referenced by any other node. This is called the root.

Verkle tree is a type of prefix tree, where each node correspond to a key prefix, i.e. the first few bytes of the key, and refers to nodes corresponding to a prefix that is one character longer than its own prefix. There are two types of nodes in the case of Verkle trees: internal and leaf. Each internal node has 256 children and a digest of its subtree. Each leaf node has no children and a digest of the suffix tree, which is a data structure storing multiple entries corresponding to a key prefix.

A similar data structure is Merkle tree, but the difference between these is in the way their commitments are computed.

If you would like to know more, please refer to Vitalik Buterin's post.

Encoded Verkle Proof


cargo test -- test_encode_verkle_proof --nocapture
cat test_cases/case1/proof.json
  "multi_proof": {
    "ipa": {
      "l": [
      "r": [
      "a": "0x1e7caca7461a0200b57594e57db4a4bc33526f80a2757a6f6d93bb2e54364059"
    "d": "0x406cbde73c39a688977004d833d80105f19c058698f4e69c8b7427af1858e1a4"
  "keys": [
  "values": [
  "extra_data_list": [
  "commitments": [

NOTE: This Verkle proof has 5 keys, but a capacity of about 32 keys (to be precise, it can contain 256 commitments before encoding). The size of multi_proof is constant within that capacity.


Rust implementation for Verkle tree.






No releases published


No packages published


  • Rust 100.0%