#web-gpu #msm #bn254 #zero-knowledge

msm-webgpu

Multi-Scalar Multiplication (MSM) implementation for WebGPU

1 unstable release

0.1.0 May 19, 2025

#829 in Cryptography

Download history 98/week @ 2025-05-16 18/week @ 2025-05-23

116 downloads per month

MIT license

295KB
7K SLoC

Rust 5K SLoC // 0.0% comments WebGPU Shader Language 2K SLoC // 0.1% comments

ICME WebGPU MSM

An implementation of the cuZK paper in Rust for Multi-Scalar Multiplication (MSM) over the BN254 curve for WebGPU.

For an introduction to ZK proving using WebGPU, see this recent post by zkSecurity.

This work is built upon the existing ZPrize 2023 submission by Tal Derei and Koh Wei Jie. Their documentation will largely serve as a documentation for this implementation, too.

Further reads on the optimisations applied:

Test

For $2^{16}$ MSMs:

wasm-pack test --chrome --test test_webgpu_msm_cuzk_16

For $2^{17}$ MSMs:

wasm-pack test --chrome --test test_webgpu_msm_cuzk_17

For $2^{18}$ MSMs:

wasm-pack test --chrome --test test_webgpu_msm_cuzk_18

For $2^{19}$ MSMs:

wasm-pack test --chrome --test test_webgpu_msm_cuzk_19

For $2^{20}$ MSMs:

wasm-pack test --chrome --test test_webgpu_msm_cuzk_20

Future work

  • Implement cuzk on other curves.
  • Implement cuzk on other libraries other than halo2curves, such as arkworks.
  • Explore the trade-off between the running time and the extra storage space needed by parallel Pippenger algorithm on webGPU as the paper Elastic MSM suggests.

Dependencies

~17–48MB
~771K SLoC