The Zcash ArboretumCrypto Guide PDF

Crypto Guide
Cryptographic primitives from scratch

Abstract

This volume of The Zcash Arboretum assembles the cryptographic toolbox: the primitives from which a shielded protocol is built, each defined, constructed, and proved against a named enemy. It assumes the Math Guide, whose groups, finite fields, elliptic curves, probability, and model of computation are used throughout without re-derivation.

Every guarantee here is a claim about an adversary, and every security definition is a game: a challenger, an efficient adversary, and an advantage that must be negligible. A proof is a reduction that turns any winning adversary into a solver for a long-attacked computational problem, with the reduction’s loss accounted for down to a concrete bit-security budget. Under that discipline the volume denies, in turn: the cryptanalyst who would recover the exponent behind a public group element, and with it every key; the forger by coincidence, who would collide two documents into one digest or replay a digest outside its role; the peeker and the equivocator on either side of a sealed envelope, who would read a commitment early or open it to a different value; the oracle distinguisher, who would tell a short secret key from blind chance; the owner of the channel, who would read, splice, or counterfeit what passes over it; the woman in the middle, who would terminate both ends of a “secure” conversation at her own desk; the forger of signatures, who would exhibit an authorisation the signer never made; the cheating prover and the curious verifier, who would certify a falsehood or squeeze a transcript for the witness it hides; and the teller of lies about sets, who would prove membership in a collection that never recorded it. What survives their attentions— hash functions, commitments, pseudorandom functions, authenticated encryption, key agreement, signatures, zero-knowledge arguments, and Merkle trees—is the toolbox the deployed protocol spends.