# Mopro: Make Client-side Proving on Mobile Easy | Devcon SEA

- Channel: [Devcon](https://streameth.org/devcon)
- Date: 2025-10-09
- Duration: 15:59
- Topics: Science & Technology
- Watch: https://streameth.org/watch/yt-0ziKiYwhJHk
- YouTube: https://www.youtube.com/watch?v=0ziKiYwhJHk

## Description

Mopro is a toolkit for ZK app development on mobile. Mopro makes client-side proving on mobile simple. Mopro aims to connect different adapters with different platforms. In this talk, we will share:
- How to use Mopro to develop your own ZK mobile app.
- What is the current development progress, including the current supported proving systems, supported platforms, and mobile GPU exploration results. 
- Moreover, we will share the challenges that Mopro faces and our future roadmap.

Speaker(s): Ya-wen Jeng, Moven Tsai
Skill level: Intermediate
Track: Applied Cryptography
Keywords: ZKP, Cryptography, Mobile, android

Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon
Learn more about devcon: https://www.devcon.org/
Learn more about ethereum: https://ethereum.org/ 

Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more.

Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. 
Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024.
Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

## Transcript

So, my name is I'm Yaowen or Vivian and his movement. And we are going to talk about uh Mobpro to make uh mobile client-side proving easy. So, we found that there are more and more mobile users than uh compared to desktop users because because of the accessibility and portability of mobile. And then there are many powerful features in native mobile. For example, the performance is better than browser and the it can access to uh hardware devices like camera, GPS, my biometrics. And also the uh offline functionality and push notifications are also interesting features in native mobile. And last but not least, the mobile development lacks infrastructure for ZK applications. So, our goal of Mobpro is to improve the mobile developer experience. So, we provide FFI CLI and provide templates and documentations. And we want to improve the native mobile performance to generate like ZK proof and cryptography proofs. And also we want to build a mobile development ecosystem as complete as the web app ecosystem. So, we want to build packages for mobile developers and also build good communities for those who want to build mobile apps. Yeah. So, our road map is to adapt uh integrate as more as adapters as possible. For example, ZK and Halo 2 and folding system MPC FFG in the future. And we will generate bindings for different platforms, not only iOS and but also for website and gaming and also your desktops. Yeah, so you you can look look detail in this structure. We are now in the middleware of the Mopro in the middleware, but we we we need to coordinate the backend, the proving system, GPU acceleration and the front end is the like SDK for different protocols. Yeah, so how to use Mopro? We create provide a CLI for developers to easily use Mopro in it, Mopro build, Mopro create to create a iOS or Android templates. And then you can easily getting started with the the app. So the benchmark on mobile it can be speed up to like six times faster than Node.js on the Mac, but the disadvantage of mobile is that the memory is is a short is is really few. So we need to solve this problem. And this the benchmark of CPU and we will introduce the GPU research results. Okay. So we've been researching on GPU acceleration on client-side proving for a while. And what we found is that client-side proving is a completely different story from server-side GPU. So we want to highlight two things. The first is scalability. So if you look at the right-hand side table, you can see that although there are slight 9x 10x on computer power or memory capacity of server-side GPU, it seems not that much, but the point is it can be clustered thousand hundreds of thousands of GPU to do extremely fast computations. So on the other hand, the Uh, mobile GPU is just the one sits on your phone, so it's relatively limited. And the second thing we want to say is that the ecosystem support of the shading language, which is where we do programming on GPU, is uh, really different. So, uh, CUDA is one of the most mature GPU shading ecosystem right now. So, if you want to do development on CUDA, it's much more easier than metal, which is the one we do uh, GPU acceleration on your iPhone. Yeah. So, uh, we target MSM to accelerate because it's uh, encompass 70% of the proven time in uh, like processing. So, uh, the first thing is that we found that a current CPU implementation is much more faster than GPU one in the Z price 2023 winners. And the second thing is that uh, although the GPU is uh, much more slower uh, slower in this case, but when the instance size grows, uh, the uh, GPU has the potential to shine in larger instance size. Yeah. So, few takeaways is that we still have uh, so many things to under exploration. So, uh, better electrical library or making much more memory efficient for mobile. And we want to also want to leverage all of the computing resource on mobile device and make sure the GPU and CPU synchronize in the way that maximize the computation speed. Yeah, so our GPU is a totally different story and we want to explore more. Yeah, so here's the link to the MoPro resources and it includes a Google form that you can We want to collect feedback from uh, the uh, projects. So, what what you need for MoPro. And there's also a like GitHub link and Telegram link. And yeah, feel free to scan this QR code. Yeah, so Open car. Open car. Thank you, MoPro. and Yawan. Any questions? Oh, there's one over there. You guys want to give it a go? I don't think I can. Oh. Thank you. Hello. Oh. Okay. So, I saw your benchmarks. So, are the benchmarks comparing the SnarkJS on a browser or against Rapid Snarks on like mobile device? Like, what's your performance versus Rapid Snarks on mobile and Gnark on mobile? Yeah, so the SnarkJS on Mac is uh in with CLI. So, I use like MPX Snarks for proof proof to generate a the proof. And then the Mac is uh M1 M1 Pro Max. And uh my iPhone is the native app. So, it is uh iPhone 12. Yeah. Is the native app using SnarkJS or Rapid no, no, no. With with Mopro. So, it's the native bindings. Okay. Yeah, like the uh yeah, so we use Rust and then generate the bindings uh binaries for iOS. And then we uh calculate the proof with the binaries. So, uh do you need any specific DSL that you have to write your proofs or like Circoms or like you're going to integrate other DSLs as well? So, the uh actually we use the Circom uh results, the ZK and Wasm. And then you can use the these two key uh two two things in uh Mopro. And then it will generate the native bindings for you to generate the proofs, and then you can use it in the native app native app. And then the for example, the the iOS, and then you will create the also a FF I for Swift. So, I I can call like generate a second proof in Swift to generate this proof. Thank you. Any other questions? Oh, there's one over there. Uh oh, sounds nice. I just wonder about any like attempt or um challenge for building like AVX specified instructions because when it comes to like looking at um the vector databases and in in in other fields, they're trying to the facility that is it's calculation by implementing those uh the some transformer calculation you to embed it into the CPUs with using on AVX instructions. Are there any like attempt to doing a similar approaches when it comes to doing on electric curve acceleration for ZK stuff or kind of things? Uh Okay. So, can you say again? Uh okay. So, I just don't know about um there's some attempt to accelerate some um dot product calculation or like matrix calculation to using on when it comes to using on transformer architecture for accelerating each calculation using AVX instructions, which is to accelerate on the CPU compiler, which is compatible with X86 um architecture. So, some vector databases try to use those like AVX instructions to to to make sure to optimize those instructions. So, when you when I just try to looking at those approaches, I think it could be applied to accelerate on the calculation for electric car because we can just unloop those um uh uh duplicate calculations into on compiler level. Uh this is this my um kind of imagination, but have you ever tried those uh temporal kind of things? That's my question. Yeah, it's it's interesting but we haven't tried that like uh implementation that and we are Yeah, we can maybe you can create an an issue in our GitHub or we can contact contact each other and then know the more much more details about your uh suggestions. Yeah, thank you. Oh, we have two questions. Oh, maybe the front row first. Hi. Um here. Um is um is your research concerning also storage on mobile or it I see it has nothing to do with yeah, yeah, also also the the storage and memory also uh really feel in in mobile. Yeah. Okay. So, and and yes, uh with this, are you using like a different key generation for every time um every time I want to prove something or uh changes made? Because I think that um this um adds more to the phone storage, right? I heard from the folks of North that they have like a the different uh back end that only needs one one key to generate and store. Yeah, so that now we uh when we explore the second prover, and then there's a really large the key if your circuit is really big. So, yeah, it sometimes takes like several G uh gigabytes to store in the storage and it yeah, it's pretty pretty big. But yeah, like the Noir example, it has really smaller key and it's better for client-side proving. So, maybe in the future we can integrate more proving systems that is better for client-side proving. Yeah, thank you. Thank you for your suggestion. Also, on the GPU size, we're trying to use a much more efficient way to encode the elliptic curve points and scalars to make sure it is much more, you know, efficient for the storage in on the mobile device. Thank you. Okay, nice to meet you. I want to ask a question about the device device memory limit. Some more detail about your benchmark. As we know, the more larger your circuit or app was, then the more device memory yet may take on the GPU or your mobile memory. So, for example, you have shown that you can do Keccak or SHA hash on on your circuit to generate the proof, but I want to know for your device benchmark, 8 GB memory, how large you can do in SHA or Keccak? So, for SHA For example, For example, you you use SnarkJS and your Rust binding and do uh proof on your mobile. You use matter and the the app do uh SHA hash about uh 1 KB or 1 million bytes data as the prim image. Actually, for like SHA SHA or Keccak, it doesn't take like that much memory to generate proof in mobile. So, I would say like maybe less than 1 GB, but I forget the re- uh exact number. Okay. Yeah. Okay, I got it. Just uh want to want to know the limit. Uh but but yeah, like RSA is more more uh much more than uh like Keccak or SHA. Okay. or hash. Oh, there's one more question there. See, everybody's interested in mobile application. Um when you say mobile is not clusterable, like has to be stand alone, I'm just curious. Um have you like looked into So, like there was like Boeing or like there's like uh a I mean, I guess a few software or like a few frameworks that can actually uh facilitate cluster computing or even like building a uh I guess what they call like a cluster distribute cluster just uh with mobile devices. Uh have you considered like looking into those and um so that to just like get around the So, like memory limit or like storage limit of a single device. Thanks. Um yeah, I I I I think there would be a a way we want to explore, but we want to start much start from much more simple stuff, which is doing the proving on your own device. And then we uh do the the method you propose I uh leveraging uh many others like consumer device to do so. Yeah. But it it still cannot be compared to the the the server-side GPU when like like the one in data center is like hundreds of them inside. Uh it's really deep a really big difference. So, when you look at the benchmark of GPU acceleration, you might you know you you need to be mindful about like uh which device they use to benchmark. It's really different. Okay, thank you everyone. Let's
