The envelope you cannot swap.
The first piece is a sealed envelope: whoever proves commits to a content before knowing which question will come. Later, when they open it, they cannot have changed anything.
On a computer, the envelope is a fingerprint of the text: a calculation (here, SHA-256) that turns any text into a 64-character number. Changing a single letter changes the whole fingerprint, and nobody knows how to find two texts with the same one. The technical name is commitment.
One detail is missing. If the content is short ("pink", "blue", "yellow"), anyone who sees the seal could try the three words and find out. So a salt is added to the content: random bytes kept by whoever proves, revealed only at opening time.
Seal and open
Why you learn nothing.
On the map, whoever checks picks a border at random, and whoever proves opens only those two envelopes. If she knows the coloring, the two colors always differ. If she is bluffing, there is at least one border with both colors equal, and every round there is a chance you pick exactly that one.
What do you see each round? Two different colors. But the colors are renamed every round, so "pink and blue" today says nothing about which region is pink. Anyone could have made up this conversation alone, drawing two different colors at random, without knowing any coloring. That is what "zero knowledge" means: what you receive could have been fabricated without the secret, so it does not carry the secret.
What convinces you is not the colors; it is that she never fails, round after round, on a question she had no way to predict.
The challenge nobody controls.
The conversation version has a practical problem: you have to be there, picking borders. And anyone watching later cannot tell whether you and the prover agreed on the questions in advance. The way out, from 1986, is to replace you with a calculation: each round's border is taken from the fingerprint of that round's own envelopes. The prover cannot pick envelopes that produce a convenient challenge, because changing one envelope scrambles the whole result.
That turns the proof into a file: every round, with the seals and the opened pairs. Anyone can redo the calculations and check it, at any time, without talking to whoever made it. The price is that a bluffer can now try at home as many times as they like before sending, so the chance of escaping must be absurdly small: with 1 bad border in 13, it takes 1,109 rounds to reach 1 chance in 2128, the security standard used in cryptography.
Generate and check a 1,109-round proof
This map proof takes about 314 KB. The age proof on the bench, made with a modern system, takes 164 bytes and is checked in 1.4 ms. Modern systems do the same job with more compact math; the logic of sealing, challenging and answering is still inside.
Any rule becomes a calculation.
Coloring maps looks like a game, but it is here for a reason: since 1986 we have known that any statement a computer can check can be translated into a map to color, and therefore proven without showing. In practice nobody goes through the map, which would be enormous. Today's systems write the rule directly as a sequence of small calculations and prove that all of them hold.
The age proof, for example, is a two-rule program. The issuing authority sealed the birth date when it issued the document; the seal is public. The phone proves it knows a date that matches that seal and that the date is at least 18 years before the current year.
# the age proof, written as a calculation public: year = 2026, document_seal secret: birth_year, salt rule 1: seal(birth_year, salt) equals document_seal rule 2: year − birth_year is at least 18 # becomes 2,184 small calculations; the proof says they all hold
On our bench, those two rules became 2,184 small calculations (constraints, in the technical name), proven in 26 ms. Proving you are on a list of one million names becomes 13,261; proving you know the text behind a SHA-256 fingerprint, 200,599.
What a proof must deliver.
Who knows, convinces
If the statement is true and the prover has the secret, the verifier accepts. On the map: whoever knows the coloring is never caught.
Who does not know, does not convince
If the statement is false, the verifier refuses, except by a stroke of luck that can be made as small as you like. On the map: 1 chance in 13 of being caught per round, adding up round after round.
The verifier learns nothing
Nothing beyond "the statement is true". Everything they saw could have been fabricated without the secret. On the map: pairs of different colors, at random.
To go further.
Where this page simplifies.
The salt must be secret and fresh
Reusing the salt across rounds, or drawing it badly, lets the seal be guessed. The specimen draws 16 new bytes per envelope, using the browser's own generator.
Do not build it yourself
This page is a demonstration. Real proofs have subtle details (how the challenge is computed, what goes into the fingerprint) where a small mistake destroys the guarantee. Use open, audited libraries.
The map proof is big
1,109 rounds and hundreds of KB for a small statement. It shows the mechanism; for real use, modern systems do the same in a few hundred bytes.
The made-up conversation has a condition
"Anyone could have fabricated the conversation" holds for a verifier who follows the protocol. Formal results also cover verifiers who try to peek; they are in the sources.
Does this apply to your case?
Tell us in two lines what you need to decide or measure. The first conversation is to see whether measurement solves your case, and if it does not, we say so.
- Goldwasser, Micali and Rackoff, "The knowledge complexity of interactive proof systems" (STOC 1985): the definition of zero knowledge.
- Goldreich, Micali and Wigderson, "Proofs that yield nothing but their validity" (FOCS 1986; Journal of the ACM, 1991): the three-color map proof, and that every statement a computer can check fits into it.
- Fiat and Shamir, "How to prove yourself: practical solutions to identification and signature problems" (CRYPTO 1986): replacing the verifier with a calculation, so the proof becomes a single message.
- SHA-256: NIST FIPS 180-4. In the specimen, through the browser's Web Crypto API; each seal is SHA-256 of "color|salt", with 16 bytes of salt. Each round's challenge in the single-message proof is the first 4 bytes of SHA-256(the round's seals | round number), modulo 13.
- Constraints and times for the age proof: our own bench (gnark v0.16.3, Groth16, BN254, Apple M2), on the bench page.