Stickybit.← 0k-proofPortuguêsExplainer · 0k-proof · 2026
Explainer · no formulas

How to prove without showing.

She knows how to color this map with three colors so that no two neighboring regions match. You want to be sure of that without learning the coloring. The solution uses sealed envelopes, a challenge you pick and an answer that opens only two envelopes at a time. The seals here are real: SHA-256 running in your browser.

Specimen · the three-color map, with sealed envelopes

0rounds
nocaught bluffing?
–chance a bluff would have survived so far
0regions whose color you learned

Each envelope holds the region's color together with 16 random bytes (the salt), and the seal is the SHA-256 fingerprint of the two. Every round the three colors are renamed and everything is sealed again, with fresh salt.

Step 1 · seal

The envelope you cannot swap.

The first piece is a sealed envelope: whoever proves commits to a content before knowing which question will come. Later, when they open it, they cannot have changed anything.

On a computer, the envelope is a fingerprint of the text: a calculation (here, SHA-256) that turns any text into a 64-character number. Changing a single letter changes the whole fingerprint, and nobody knows how to find two texts with the same one. The technical name is commitment.

One detail is missing. If the content is short ("pink", "blue", "yellow"), anyone who sees the seal could try the three words and find out. So a salt is added to the content: random bytes kept by whoever proves, revealed only at opening time.

Seal and open

the seal shows up here

Steps 2 and 3 · challenge and answer

Why you learn nothing.

On the map, whoever checks picks a border at random, and whoever proves opens only those two envelopes. If she knows the coloring, the two colors always differ. If she is bluffing, there is at least one border with both colors equal, and every round there is a chance you pick exactly that one.

What do you see each round? Two different colors. But the colors are renamed every round, so "pink and blue" today says nothing about which region is pink. Anyone could have made up this conversation alone, drawing two different colors at random, without knowing any coloring. That is what "zero knowledge" means: what you receive could have been fabricated without the secret, so it does not carry the secret.

What convinces you is not the colors; it is that she never fails, round after round, on a question she had no way to predict.

ONE ROUND proverrenames the colorsand seals everything 8 sealed envelopes verifierpicks a borderat random only these two open:seals match? colors differ? WHAT YOU TAKE FROM THE ROUND two different colors, at random. That is all.
The other six envelopes are never opened. Next round everything is renamed and sealed again, so piling up rounds does not reveal the coloring either.
From conversation to a single message

The challenge nobody controls.

The conversation version has a practical problem: you have to be there, picking borders. And anyone watching later cannot tell whether you and the prover agreed on the questions in advance. The way out, from 1986, is to replace you with a calculation: each round's border is taken from the fingerprint of that round's own envelopes. The prover cannot pick envelopes that produce a convenient challenge, because changing one envelope scrambles the whole result.

That turns the proof into a file: every round, with the seals and the opened pairs. Anyone can redo the calculations and check it, at any time, without talking to whoever made it. The price is that a bluffer can now try at home as many times as they like before sending, so the chance of escaping must be absurdly small: with 1 bad border in 13, it takes 1,109 rounds to reach 1 chance in 2128, the security standard used in cryptography.

Generate and check a 1,109-round proof

–proof size
–to generate, in your browser
–to check

This map proof takes about 314 KB. The age proof on the bench, made with a modern system, takes 164 bytes and is checked in 1.4 ms. Modern systems do the same job with more compact math; the logic of sealing, challenging and answering is still inside.

From the map to real life

Any rule becomes a calculation.

Coloring maps looks like a game, but it is here for a reason: since 1986 we have known that any statement a computer can check can be translated into a map to color, and therefore proven without showing. In practice nobody goes through the map, which would be enormous. Today's systems write the rule directly as a sequence of small calculations and prove that all of them hold.

The age proof, for example, is a two-rule program. The issuing authority sealed the birth date when it issued the document; the seal is public. The phone proves it knows a date that matches that seal and that the date is at least 18 years before the current year.

# the age proof, written as a calculation
public:  year = 2026, document_seal
secret:  birth_year, salt
rule 1:  seal(birth_year, salt) equals document_seal
rule 2:  year − birth_year is at least 18
# becomes 2,184 small calculations; the proof says they all hold

On our bench, those two rules became 2,184 small calculations (constraints, in the technical name), proven in 26 ms. Proving you are on a list of one million names becomes 13,261; proving you know the text behind a SHA-256 fingerprint, 200,599.

The three guarantees

What a proof must deliver.

Completeness

Who knows, convinces

If the statement is true and the prover has the secret, the verifier accepts. On the map: whoever knows the coloring is never caught.

Soundness

Who does not know, does not convince

If the statement is false, the verifier refuses, except by a stroke of luck that can be made as small as you like. On the map: 1 chance in 13 of being caught per round, adding up round after round.

Zero knowledge

The verifier learns nothing

Nothing beyond "the statement is true". Everything they saw could have been fabricated without the secret. On the map: pairs of different colors, at random.

The section

To go further.

Limits

Where this page simplifies.

The salt must be secret and fresh

Reusing the salt across rounds, or drawing it badly, lets the seal be guessed. The specimen draws 16 new bytes per envelope, using the browser's own generator.

Do not build it yourself

This page is a demonstration. Real proofs have subtle details (how the challenge is computed, what goes into the fingerprint) where a small mistake destroys the guarantee. Use open, audited libraries.

The map proof is big

1,109 rounds and hundreds of KB for a small statement. It shows the mechanism; for real use, modern systems do the same in a few hundred bytes.

The made-up conversation has a condition

"Anyone could have fabricated the conversation" holds for a verifier who follows the protocol. Formal results also cover verifiers who try to peek; they are in the sources.

Talk to us

Does this apply to your case?

Tell us in two lines what you need to decide or measure. The first conversation is to see whether measurement solves your case, and if it does not, we say so.

Talk on WhatsApp algorithms@stickybit.com.br Stickybit · Porto Alegre, Brazil, since 2004

← 0k-proof

Sources