.. DO NOT EDIT. .. THIS FILE WAS AUTOMATICALLY GENERATED BY SPHINX-GALLERY. .. TO MAKE CHANGES, EDIT THE SOURCE PYTHON FILE: .. "api/gallery/proofs/snarks/plot_04_powers_of_tau.py" .. LINE NUMBERS ARE GIVEN BELOW. .. only:: html .. note:: :class: sphx-glr-download-link-note :ref:`Go to the end ` to download the full example code or to run this example in your browser via JupyterLite. .. rst-class:: sphx-glr-example-title .. _sphx_glr_api_gallery_proofs_snarks_plot_04_powers_of_tau.py: Trusted-setup ceremonies: Zcash's parameters and the powers of tau (2016) ========================================================================= Pairing-based SNARKs need :math:`[\tau^i]G` for a :math:`\tau` that nobody knows: whoever knows it can prove false statements. In October 2016 six Zcash participants generated its parameters by multi-party computation, so that the secret stayed unknown unless *all* of them colluded. Later "powers of tau" ceremonies scaled this to thousands of participants. Each one multiplies the current string by a secret :math:`s` and destroys it: .. math:: [\tau^i]G \;\mapsto\; [(\tau s)^i]G, and publishes :math:`[s]G`, so that anyone can check with pairings that the update is honest and builds on the previous string. One honest participant is enough. .. GENERATED FROM PYTHON SOURCE LINES 22-26 .. code-block:: Python import matplotlib.pyplot as plt import blockchainkit as bk .. GENERATED FROM PYTHON SOURCE LINES 27-29 Five participants, each checked by everyone ------------------------------------------- .. GENERATED FROM PYTHON SOURCE LINES 29-43 .. code-block:: Python secrets = [1789, 31337, 271828, 141421, 577215] string = bk.proofs.start_ceremony(16) checks = [] for s in secrets: step = bk.proofs.contribute(string, s) checks.append(bk.proofs.verify_contribution(string, step)) string = step.srs tau = 1 for s in secrets: tau = tau * s % bk.proofs.FIELD_PRIME assert all(checks) and string == bk.proofs.trusted_setup(16, tau) print("every contribution verified; tau is the product of five secrets") .. rst-class:: sphx-glr-script-out .. code-block:: none every contribution verified; tau is the product of five secrets .. GENERATED FROM PYTHON SOURCE LINES 44-48 A participant who ignores the previous string is caught ------------------------------------------------------- Mallory publishes a fresh string from a tau she knows, discarding the others' contributions. .. GENERATED FROM PYTHON SOURCE LINES 48-53 .. code-block:: Python fresh = bk.proofs.contribute(bk.proofs.start_ceremony(16), 42) caught = not bk.proofs.verify_contribution(string, fresh) assert caught .. GENERATED FROM PYTHON SOURCE LINES 54-56 Why tau must be destroyed ------------------------- .. GENERATED FROM PYTHON SOURCE LINES 56-76 .. code-block:: Python f = [5, 0, 1] commitment = bk.proofs.kzg_commit(f, string) forged = bk.proofs.forge_opening(commitment, point=3, value=1_000_000, secret=tau, srs=string) assert bk.proofs.kzg_verify(commitment, forged, string) # f(3) is 14, yet "1,000,000" verifies. print("with tau, the commitment to 5 + x**2 opens to", forged.value, "at x = 3") fig, ax = plt.subplots(figsize=(7, 4)) names = [f"participant {i + 1}" for i in range(len(secrets))] + ["Mallory"] results = checks + [not caught] ax.barh(names, [1] * len(names), color=["#16a34a" if ok else "#dc2626" for ok in results]) for i, ok in enumerate(results): ax.text(0.5, i, "verified" if ok else "rejected", ha="center", va="center", color="white") ax.set_xticks([]) ax.invert_yaxis() ax.set_title("Pairing checks on each contribution") fig.tight_layout() plt.show() .. image-sg:: /api/gallery/proofs/snarks/images/sphx_glr_plot_04_powers_of_tau_001.png :alt: Pairing checks on each contribution :srcset: /api/gallery/proofs/snarks/images/sphx_glr_plot_04_powers_of_tau_001.png :class: sphx-glr-single-img .. rst-class:: sphx-glr-script-out .. code-block:: none with tau, the commitment to 5 + x**2 opens to 1000000 at x = 3 .. GENERATED FROM PYTHON SOURCE LINES 77-82 Exercise -------- The toy group has order about 2**31, so tau can be recovered from [tau]G by baby-step giant-step in about 2**16 steps. Write that search on the pairing curve and recover the ceremony's tau from ``string.powers[1]``. .. rst-class:: sphx-glr-timing **Total running time of the script:** (0 minutes 0.063 seconds) .. _sphx_glr_download_api_gallery_proofs_snarks_plot_04_powers_of_tau.py: .. only:: html .. container:: sphx-glr-footer sphx-glr-footer-example .. container:: lite-badge .. image:: images/jupyterlite_badge_logo.svg :target: ../../../../lite/lab/index.html?path=api/gallery/proofs/snarks/plot_04_powers_of_tau.ipynb :alt: Launch JupyterLite :width: 150 px .. container:: sphx-glr-download sphx-glr-download-jupyter :download:`Download Jupyter notebook: plot_04_powers_of_tau.ipynb ` .. container:: sphx-glr-download sphx-glr-download-python :download:`Download Python source code: plot_04_powers_of_tau.py ` .. container:: sphx-glr-download sphx-glr-download-zip :download:`Download zipped: plot_04_powers_of_tau.zip ` .. only:: html .. rst-class:: sphx-glr-signature `Gallery generated by Sphinx-Gallery `_