StateSync-GKR: Machine-Checking the Trust Chain from Sparse-Merkle State Transitions to GKR Verification

📅 2026-10-04
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the missing chain of trust in state transition verification for GKR circuit applications by formally verifying sparse Merkle trees and the GKR protocol within Isabelle/HOL, thereby establishing a complete trust chain from the compiler to the proof layer. Methodologically, it achieves end-to-end verification by integrating a Rust executable prover, Creusot/Why3 contracts, and KoalaBear field extension techniques. The core contributions are threefold: first, it unifies compiler correctness and the GKR assembly model within a single proof assistant for the first time, explicitly delineating residual cryptographic obligations; second, it reduces semantic invalidity to explicit event bounds, exposing potential assumption vulnerabilities; and third, it ensures a reliable connection between the implementation code and the formal model.
📝 Abstract
GKR soundness bounds false output claims about arithmetic circuits, but an application also needs assurance that its circuit encodes the intended state transition. We machine-check this connection for sparse-Merkle membership, non-membership, and update in Isabelle/HOL. A compiler model relates circuit acceptance to transition validity in both directions. A reusable protocol model assembles layer reduction, wiring-predicate extensions, and imported sumcheck soundness into a bound on an explicit chain event. Their composition transfers semantic invalidity to that bound, with the witness fixed before the challenge experiment. Concrete interpretations and premise activations expose vacuous assumption sets that a clean build alone would miss. A further development constructs the exact degree-four KoalaBear extension, lifts the base-field circuit objects, and establishes the assembly bound with denominator $p^4$ under its stated challenge assumptions. An executable Rust prover accompanies the model. Creusot/Why3 contracts provide a partial implementation connection, and a conditional theorem relates successful verifier traces to the model event under an undischarged value-correspondence premise. Neither the transcript's online challenge distribution nor a multi-round Fiat--Shamir reduction is established. The contribution is the composition, within one proof assistant, of compiler correctness with a GKR assembly model, together with an explicit account of the remaining implementation and cryptographic obligations.
Problem

Research questions and friction points this paper is trying to address.

GKR verification
Sparse-Merkle tree
state transition
machine-checking
trust chain
Innovation

Methods, ideas, or system contributions that make the work stand out.

machine-checked verification
GKR protocol
sparse-Merkle tree
Isabelle/HOL
formal composition
🔎 Similar Papers
No similar papers found.
J
Jinwook Kim
Oraclizer Labs, Inc., Delaware, USA; Oraclizer Labs Korea, Seoul, Korea