Zcash's Halo Breakthrough Is a Big Deal

gepubliceerd op by Coindesk | gepubliceerd op

That's especially in the sub-field of zero-knowledge proofs, which enable the verification of facts that are derived from a secret the verifier cannot access.

These advances matter because zero-knowledge proofs offer the tantalizing prospect of people transacting in confidence without accessing potentially compromising information about each other.

ECC had already been an engine of progress for cryptography by advancing the use of zk-SNARKS, another cryptocurrency-inspired addition to the zero-knowledge proof toolkit, with which zcash produces a provably auditable blockchain without revealing users' addresses.

The company's recent announcement of Halo, a "Trustless recursive" version of zero-knowledge proofs that provides a massively scalable solution to the field's unwieldy reliance on "Trusted setups," is arguably bigger.

Halo allows a user to both prove that no one involved in the initial establishment of a large-scale zero-knowledge proof system has created a secret backdoor with which to later amend the code and that that secure state has existed over the course of ongoing updates and changes to the system.

Halo gets around this problem by establishing an accumulated "Proof of proofs," such that the latest mathematical output contains within it a proof that all prior claims to the relevant secret knowledge have themselves been sufficiently proven through a similar process.

In a dramatic compression in computational requirements, all that's now needed to verify the veracity of the entire database's current state is a single mathematical proof.

Wilcox thinks Halo-like zero-knowledge proofs will pave the way.

Taking the prior example one step further, he said, "What if instead of me saying 'here is a proof that Equifax says I haven't had any defaults over the last 10 years,' I can say 'here is a proof from all the 100 people that have lent to me over the past 10 years and each of them attests to me not having defaulted?".

To be clear, Bowe's mathematical proof still needs to be subject to rigorous peer review.

x