# Computational cost for proof generation

**URL:** <https://forum.zcashcommunity.com/t/computational-cost-for-proof-generation/14200>\
**Category:** Community Collaborations\
**Created:** [February 9, 2017, 6:45pm UTC](https://forum.zcashcommunity.com/t/computational-cost-for-proof-generation/14200 "2017-02-09T18:45:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![zksnark](https://avatars.discourse-cdn.com/v4/letter/z/977dab/32.png) [@zksnark](https://forum.zcashcommunity.com/u/zksnark)\
**Post date:** [February 9, 2017, 6:45pm UTC](https://forum.zcashcommunity.com/t/computational-cost-for-proof-generation/14200/1 "2017-02-09T18:45:27Z")

</div>

I have been reading the zerocash paper and have a question more on the technical side: so the joinsplit/pour operation  
can take arbitrary number of input/outputs. I am wondering how does the time required to generate the zk-SNARKs grow with the number of inputs/outputs?

In the original paper, the benchmark was 2 minutes for 2 inputs and 2 outputs. So what about transactions  
with few hundred outputs? If it scales linearly, then it takes few hundred minutes to generate these proof, which is prohibitive. Any thoughts/clarifications would be helpful!

---

<div class="post-metadata">

**Author:** ![dlehenky](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/dlehenky/32/1751_2.png) [@dlehenky](https://forum.zcashcommunity.com/u/dlehenky)\
**Post date:** [February 11, 2017, 6:34am UTC](https://forum.zcashcommunity.com/t/computational-cost-for-proof-generation/14200/2 "2017-02-11T06:34:54Z")

</div>

I don’t have a specific answer (number), but I know flypool (very large ZEC pool) will not process miner payouts to z-addresses due to the performance issue. The pool owner stated that it was taking 15-20 minutes to send a z-addr join-split transaction. He didn’t mention a number of inputs/outputs, but I did take a quick look at the transaction on the blockchain, and it was upward of 200 outputs. Of course, I have no idea what hardware he was using, and clearly it could be a higher performance (server class) system compared to that used in the whitepaper benchmark.

It’s an issue that I’m surprised Zcash Co hasn’t put a higher priority on. In my opinion, it’s a very visible failing, given that flypool cannot, for practical reasons, use what is a fundamental feature of Zcash. If you cannot do z-addr join-split transactions with a reasonable number of inputs/outputs, then the Zcash network is not fully functional. I think that is, in part, the reason the price keeps slipping. Every point release that comes out, people are expecting this deficiency to be resolved, and nothing happens, nothing improves. So, this fundamental functionality remains broken, with no clear indication that Zcash Co. is in any hurry to make it right. Go figure.

If they would get it working/performing well, the pools would be a huge user of z-addr join-split transactions, which would help establish the credibility of zk-SNARK technology. As it is, shielded transactions, so far, have been a minor part of the overall network transaction volume. I think that is due to the user base not being fully confident that it works as advertised. Just my take on it.

Edit: I should add that a large percentage of miners would much rather have their payouts go to a z-addr.

---

<div class="post-metadata">

**Author:** ![dlehenky](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/dlehenky/32/1751_2.png) [@dlehenky](https://forum.zcashcommunity.com/u/dlehenky)\
**Post date:** [February 11, 2017, 3:53pm UTC](https://forum.zcashcommunity.com/t/computational-cost-for-proof-generation/14200/3 "2017-02-11T15:53:44Z")

</div>

Here’s a link to the latest flypool experience with z-addr join-split (it’s worse than I recalled):

> [@Zcash Pool- Zcash.flypool.org](https://forum.zcashcommunity.com/t/zcash-pool-zcash-flypool-org-anonymous-mining/3152/1369):
>
> Unfortunately payouts to z addresses will remain disabled for the time being. We have tested paying out directly to z address using the latest Zcash version 1.0.4 but the system is simply to slow for large scale payments required by the pool. Paying to just 10 timers took between 7 and 15 minutes which is not suitable for paying out thousands of miners in a timely fashion. We will continue to monitor the Zcash developments and evaluate the feasibility with every new Zcash version. Edit: All tes…

---

<div class="post-metadata">

**Author:** ![kunxian-xia](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/kunxian-xia/32/9214_2.png) [@kunxian-xia](https://forum.zcashcommunity.com/u/kunxian-xia)\
**Post date:** [January 28, 2019, 10:56am UTC](https://forum.zcashcommunity.com/t/computational-cost-for-proof-generation/14200/4 "2019-01-28T10:56:11Z")

</div>

I think the Sprout release of Zcash does not support arbitrary number of inputs/outputs. The maximum number of input notes is 2, so does the output notes. And you can get a benchmark result by running the following command script: `./zcash-cli zcbenchmark createjoinsplit 2`.
