Ironwood Guide
The Zcash Orchard protocol and its Ironwood pool
Abstract
This volume of The Zcash Arboretum constructs the Orchard protocol for a shielded payment in its Ironwood pool: how the payment is constructed, delivered to its recipient and verified; why a valid payment cannot create value, consume a note twice or consume a note without the authority of its owner; and what its public data hide. Every public field of the payment is constructed, in dependency order, as a fixed function of private notes, keys and randomness; the relation that each Action of the payment proves is stated over those objects; and each security property is a theorem under named assumptions. The sealed Orchard pool enters only where a rule shared with the Ironwood pool, or a rule that distinguishes the two pools, is needed to state the Ironwood-pool payment correctly. The volume assumes the Math Guide and the Crypto Guide and cites the Halo 2 Guide for the proof system. It is non-normative: the Zcash Protocol Specification and the Zcash Improvement Proposals are authoritative.
Contents
- 1 Introduction
- 2 Notation and primitive instances
- 3 Keys and addresses
- 4 Notes and note commitments
- 5 The note commitment tree
- 6 Nullifiers
- 7 Spend authorisation
- 8 Value commitments and the binding signature
- 9 The Action statement and its proof
- 10 Note encryption
- 11 Transactions and consensus rules
- 12 Security