The Zcash ArboretumThe Complete Arboretum PDF

Part VII FlyClient Guide: Merkle mountain ranges, the chain-history commitment, and the FlyClient sampling protocol

This volume of The Zcash Arboretum states the protocol by which a light client decides which of several claimed chains carries the most work while receiving a number of block headers logarithmic in the chain length. It constructs Merkle mountain ranges under the two bagging orders in use, with inclusion paths, prefix roots, position binding and aggregate binding; fixes the security model of the FlyClient paper of Bünz, Kiffer, Luu and Zamani; constructs the FlyClient protocol from the header chain commitment and the per-sample check through the optimal sampling distribution to the non-interactive protocol and its security theorem, with every hypothesis named; and states the chain-history commitment of ZIPs 221, 244 and 258, to which every Zcash block header after the Heartwood activation block commits. Each component of a Zcash FlyClient is classified as specified, designed but unspecified, or an open problem. The volume describes the protocol as specified for NU7, whose deployment ZIP, ZIP 259, has status Draft. It assumes the Math Guide, the Crypto Guide and the Consensus Guide, and cites the Ironwood Guide for network upgrades, ZIP statuses and transaction-level objects. It is non-normative: the Zcash Protocol Specification and the Zcash Improvement Proposals are authoritative.