Contents
- Introduction
-
I Math Guide: Mathematical foundations for Halo 2 and Zcash Orchard
- 1 Notation: sets, functions, and relations
- 2 The integers and modular arithmetic
- 3 Groups
- 4 Rings and fields
- 5 Polynomials over a field
- 6 Finite fields
- 7 Number theory for cryptography
- 8 Linear algebra over a field
- 9 Roots of unity and evaluation domains
- 10 Elliptic curves
- 11 Probability, asymptotics, and computation
-
II Crypto Guide: Cryptographic primitives from scratch
- 1 The provable-security model
- 2 Hardness assumptions
- 3 Hash functions and the random oracle model
- 4 Commitment schemes
- 5 Pseudorandom functions, block ciphers, and format-preserving
encryption
- 6 Symmetric encryption, AEAD, and key derivation
- 7 Key agreement
- 8 Digital signatures
- 9 Interactive proofs, zero knowledge, and SNARKs
- 10 Merkle trees and commitments to sets
-
III Halo 2 Guide: The Halo 2 proof system, from arithmetisation to recursion
- 1 Introduction
- 2 Arithmetisation: from a computation to committed polynomials
- 3 The inner-product polynomial commitment
- 4 The Halo 2 proof system
- 5 A rigorous treatment of knowledge soundness
- 6 The verifier’s decision and its implication chain
- 7 Recursive proof composition and accumulation schemes
-
IV Consensus Guide: Nakamoto consensus: the double-spend race, the arithmetic of confirmations, and the deployed most-work rule
- 1 Scope, sources, and the two double-spends
- 2 The block tree and the most-work rule
- 3 A probability toolkit
- 4 Playing catch-up
- 5 Waiting for confirmations
- 6 What the numbers say
- 7 The economics of the attack
- 8 NU7: 25-second blocks and bounded shielded work
- 9 Layer boundary
-
V Ironwood Guide: The Zcash Orchard protocol and its Ironwood pool
- 1 Introduction
- 2 Notation and primitive instances
- 3 Keys and addresses
- 4 Notes and note commitments
- 5 The note commitment tree
- 6 Nullifiers
- 7 Spend authorisation
- 8 Value commitments and the binding signature
- 9 The Action statement and its proof
- 10 Note encryption
- 11 Transactions and consensus rules
- 12 Security
-
VI Wallet Guide: The Zcash wallet layer: keys, transactions, and light-client synchronisation
- 1 Hierarchical key derivation (ZIP-32)
- 2 Diversified and unified addresses (ZIP-316)
- 3 Fees (ZIP-317)
- 4 Transaction construction
- 5 Partially created transactions (PCZT)
- 6 Broadcast, expiry, and the transaction lifecycle
- 7 Payment requests (ZIP-321)
- 8 Compact blocks (ZIP-307)
- 9 The light-client service
- 10 The scanning pipeline
- 11 Commitment-tree synchronisation
- 12 What the server learns
-
VII FlyClient Guide: Succinct chain verification: the sampling protocol, the deployed ZIP-221 commitment, and the unbuilt bridge
- 1 Scope, sources, and the deployment boundary
- 2 The problem: verifying a chain without downloading it
- 3 Merkle mountain ranges
- 4 The FlyClient protocol
- 5 ZIP-221: the deployed chain-history tree
- 6 NU5: the commitment becomes one of two
- 7 Deployed implementations
- 8 The deployment gap
-
VIII ZSA Guide: Zcash Shielded Assets: issuance, transfer, and the counterfeiting boundary
- 1 Scope, status, and sources
- 2 Asset identity
- 3 Issuance and finalization (ZIP-227)
- 4 Transfer and burn (ZIP-226)
- 5 Split notes and the counterfeiting boundary
- 6 Transaction integration and outlook
-
IX FROST Guide: Threshold RedPallas: FROST and its Zcash integration surfaces
- 1 Scope, sources, and deployment surfaces
- 2 FROST
- 3 Re-Randomized FROST for RedPallas
- 4 Deployment and open questions