Preprint

ShadowPath phone tests show a wide gap in credential proof times

Preprint: ShadowPath moves credential-specific status lookup to the holder; Groth16 proving took 2.93 to 3.11 seconds on two tested phones, while PLONK took 39.12 to 55.29 seconds.

On an iPhone 17 Pro and a Galaxy S25, median proof-generation times were 3.11 and 2.93 seconds with Groth16, compared with 39.12 and 55.29 seconds with PLONK. The corresponding verification medians were 5.31 and 19.08 milliseconds for Groth16 and 8.08 and 17.05 milliseconds for PLONK.

ShadowPath moves credential-specific status lookup to the holder, who derives the result locally and sends a zero-knowledge proof binding that result to the credential in the same session. The paper examines the proving, verification and state-distribution costs of that design.

The phone test shows the gap

The paper uses one and 10 seconds as illustrative reference levels, not formal usability limits. Groth16 was above one second but below 10 seconds on both primary phones, while PLONK exceeded 10 seconds on both.

Across 10 physical devices and 200 Verkle proving trials, Groth16 stayed below 10 seconds on nine devices; the Galaxy A54 reached 10.46 seconds. No device stayed below one second, while PLONK exceeded 10 seconds on every device. Peak PLONK memory reached approximately 5.0 GB, and several runs reached serious or severe thermal states.

Two backend designs were tested

For the desktop comparison, the same field, Groth16 system, hardware and trial protocol were used for both backends. The test compared a 250-position address space, a depth-50 Poseidon sparse Merkle tree path and a five-level KZG Verkle path with branching factor 1,024. Each configuration retained 30 sequential trials, summarized by medians and interquartile ranges.

In selected functional validation, all five valid witnesses were accepted and all 13 negative cases were rejected. The deployed service completed 10 valid requests for each proof backend.

Under those matched Groth16 conditions, median proving time was 371.6 milliseconds for SMT and 2,109.5 milliseconds for Verkle. Median verification was 3.70 and 7.55 milliseconds, while proof sizes were 388 and 484 bytes, respectively. The reported Verkle-to-SMT ratios were 5.68 times for proving and 2.04 times for verification.

Within the evaluated ShadowPath-Verkle relation, median proving time was 2,109.5 milliseconds with Groth16 and 25,619.8 milliseconds with PLONK. The reported PLONK-to-Groth16 proving ratio was 12.14 times; verification medians were 7.55 and 9.60 milliseconds, and proof sizes were 484 and 1,352 bytes, respectively. The reported circuit-constraint counts were 74,649 for the status relation and 86,034 for the relation with credential authentication, a 15.3% difference.

At concurrency 32, a one-run endpoint test sent 300 requests to each backend. Groth16 recorded 346.8 requests per second, compared with 284.1 for PLONK; median request latency was 73.2 milliseconds compared with 99.54 milliseconds, and the 95th-percentile figures were 214.07 and 225.32 milliseconds, respectively.

The throughput comparison was a single snapshot because each backend was measured once at the tested concurrency. The desktop timings were host-specific and do not establish that the same ratios would hold on other hardware.

State transfer was part of the test

Complete Verkle summaries grew from 0.118 MB to 93.95 MB over the measured revocation range. In a controlled high-latency network profile, 30 raw transfers had a median time of 24.86 seconds, with an interquartile range of 10.08 seconds. Gzip produced a 38.09 MB payload and a 13.76-second median transfer time, with an interquartile range of 8.22 seconds.

At 50 revocations, a complete summary was 48,459 bytes, while each authenticated delta covering five updates was 1,385 bytes. Two such deltas totaled 2,770 bytes, and all 24 tested backend, population and update combinations reproduced the expected authenticated-state roots.

Network-free reconstruction took 427.18 seconds for Verkle and 23.44 seconds for SMT. Applying or verifying 100 updates took 6.77 seconds and 240.53 milliseconds, respectively.

The privacy statement is conditional

Under fresh pseudorandom session values, the paper states that verifier-visible status data should not reveal whether separate accepted presentations use the same credential. The stated guarantee excludes issuer-verifier collusion and state-synchronization metadata.

The evaluation used synthetic credentials and controlled infrastructure, with no human participants, real identities, personal data or live services. It was an engineering test of a prototype, not evidence of human usability or production performance.

The SMT artifact was a standalone in-memory Groth16 relation that excluded composition, IPFS/IPNS distribution and the mobile prototype. The SMT and Verkle columns were not equivalent deployments.

The document is an arXiv v1 preprint dated 20 August 2026 and displays NDSS Symposium 2027 information.

Paper data and sources

Original title: ShadowPath: Lookup-Private Credential Status Verification over Authenticated State
Authors: Patrick Herbke, Wolf Rieder, Christian René Sechting et al.
Journal/Repository: arXiv
Status: Preprint, not yet peer-reviewed
First online: 2026-08-20
DOI: Not available
Original paper · Full text

Versions and corrections

  1. Published after independent verification and editorial approval.