Glossary

The words of proving without showing.

Each term gets an everyday example before the definition. The technical names stay here, for whoever runs into them in a paper, a proposal or a vendor conversation.

Specimen · an age proof, piece by piece

Proving without showing

also: zero-knowledge proof · ZKP · ZK
In everyday life
Showing the doorman you are over 18 without handing over your ID: he is convinced and learns nothing else.
What it means here
A way to convince someone that a statement is true without revealing the data that makes it true. The checker walks away with certainty (the statement holds) and zero extra information about the secret.
Where it appears
The sectionHow it worksPractical uses

The prover

also: prover
In everyday life
The one who has the key to the cave's secret door and always comes out the side you ask for.
What it means here
The party that holds the secret and produces the proof: you, the app on your phone, a supplier's system. It does the heavier work (on our bench, 25 ms to 1.6 s).
Where it appears
The sectionHow it works

The checker

also: verifier
In everyday life
You, at the mouth of the cave, shouting "come out through B" without ever seeing the door.
What it means here
The party that needs convincing: the website, the bank, the auditor. It receives the proof and the statement, runs a quick calculation (1.4 to 3.3 ms on our bench) and answers accept or reject. It never sees the secret.
Where it appears
The sectionHow it works

The statement

also: statement · public input
In everyday life
The sentence the doorman needs to hear: "I am over 18". Not "I was born in 1990".
What it means here
What is being proven, stated publicly, briefly and exactly: "the document signed by this issuer says the holder is 18 or older in 2026". The checker sees the whole statement; only the secret stays hidden.
Where it appears
The sectionPractical uses

The secret

also: witness · private input
In everyday life
The date of birth that stays inside the phone while the proof goes out.
What it means here
The data that makes the statement true: the date of birth, the exact balance, which name on the list. It goes into the prover's calculation and never leaves where it is.
Where it appears
The sectionHow it works

Witness

also: witness
In everyday life
The technical name for the secret, and a misleading one: it is not a person, it is the data that "bears witness" to the statement.
What it means here
The set of secret values that satisfies the proof's rule. In papers and libraries, "witness" always means this: the date of birth, the salt, the path in the tree.
Where it appears
How it works

The sealed envelope

also: commitment
In everyday life
Writing the answer on a slip, sealing it in an envelope and handing it over before the question. Afterwards the slip cannot be swapped.
What it means here
A value that binds the prover to a choice without revealing it. It has two properties: hiding (the envelope does not let you see inside) and binding (it cannot be opened to show different contents). On our bench, the date of birth goes in sealed together with a salt.
Where it appears
How it works

The salt

also: salt · commitment randomness
In everyday life
A handful of confetti inside the envelope, so that two envelopes with the same answer do not look alike from outside.
What it means here
A random number sealed together with the secret. Without it, the checker could try the few possible birth dates and find which one produces the same seal.
Where it appears
How it worksBench

The data's fingerprint

also: cryptographic hash · SHA-256 · MiMC
In everyday life
A person's fingerprint: short, unique, and you cannot rebuild the person from it.
What it means here
A calculation that turns any data into a short number of fixed size. Changing a comma changes the whole result, and going back from the result to the data is infeasible. SHA-256 is the most used in the world; inside proofs others, like MiMC, are preferred because they are far cheaper to prove.
Where it appears
How it works

The challenge

also: challenge
In everyday life
"Come out through B!": the question you pick after she has already gone into the cave.
What it means here
A question chosen at random by the checker, after the envelope is sealed. Since the prover did not know which one would come, they can only answer all of them if they really have the secret.
Where it appears
How it works

The response

also: response
In everyday life
Coming out the requested side, showing only that and nothing of the door.
What it means here
What the prover sends back to the challenge: opening only one part of the envelope, the part that answers that question. Each correct answer halves (or far more) the chance of a bluff getting through.
Where it appears
How it works

The challenge nobody controls

also: Fiat-Shamir transform · non-interactive proof
In everyday life
Instead of asking someone to roll the die, taking the number from the envelope's own fingerprint: nobody picks it, and anyone can redo the calculation.
What it means here
A 1986 trick that removes the conversation from the proof. The challenge is computed from a cryptographic hash of the envelope, so the prover cannot choose it. The proof becomes a single message that anyone can check later, without talking to the prover.
Where it appears
How it works

The rule written as arithmetic

also: circuit · proven program
In everyday life
Turning "18 or older" into a form where every field is an addition or a multiplication.
What it means here
The program the proof guarantees was followed, rewritten as a list of simple calculations. The age rule becomes "birth year + 18 ≤ current year" and "the seal matches the document". If the rule is written wrong, the proof proves the wrong rule.
Where it appears
How it worksBench

Constraints

also: constraints · R1CS
In everyday life
The lines of the form: the more lines, the longer it takes to fill in.
What it means here
Each elementary calculation of the rule. It is how a proof's size is measured: the age proof has 2,184 constraints and takes 26 ms; the one for the text behind a SHA-256 has 200,599 and takes 1.6 s, with a 51 MB setup key.
Where it appears
Bench

The issuer

also: issuer · attesting authority
In everyday life
The registry office that stamped your certificate: the proof is only as good as the stamp.
What it means here
Whoever signs the source data: the identity agency, the bank, the list owner, the sensor itself. The proof guarantees the statement follows from what they signed; if they signed something wrong, the proof proves the mistake.
Where it appears
Practical usesThe section

The credential

also: verifiable credential · mdoc
In everyday life
The digital document on your phone, already stamped by the issuer, from which proofs are made.
What it means here
A set of data signed by the issuer and kept by the prover. It is the starting point: each proof says something about it without showing it. It is the format used by the digital wallets that already do age proofs.
Where it appears
Practical uses

The summarized list

also: Merkle tree · root
In everyday life
A knockout bracket: each pair becomes one name in the next round, until one champion is left. To prove you played, you only show the opponents along your path.
What it means here
A way to summarize a huge list into a single number (the root). Proving an item is on the list takes about 20 numbers for a million items. Inside a zero-knowledge proof, not even those 20 appear: only the root. On the bench, proving membership in a list of a million took 220 ms.
Where it appears
Practical usesBench

The setup ceremony

also: trusted setup · toxic waste · SRS
In everyday life
Making the mold for a key and then destroying it in public: if someone kept a copy of the mold, they can make fake keys.
What it means here
Some proof systems need, once, a setup with secret numbers that must then be erased. If they are not, whoever kept them can forge proofs that pass. That is why serious setups are run by many people, and one honest participant is enough. On our bench we used a test setup, not fit for production.
Where it appears
BenchThe section

Groth16

also: Groth16 (2016)
In everyday life
The thinnest envelope on the market, but with its own mold for each kind of letter.
What it means here
The most compact proof system in use: 164 to 196-byte proofs on our bench, checked in 1.4 to 3.3 ms. The price is a setup ceremony for each rule; change the rule, new ceremony.
Where it appears
Bench

PLONK

also: PLONK (2019) · universal setup
In everyday life
A mold that fits any letter up to a certain size: the ceremony is done only once.
What it means here
A proof system with a universal setup: one ceremony serves many rules. In exchange, on our bench the proofs were bigger (520 to 584 bytes) and slower to generate (91 ms to 40.6 s, against 26 ms to 1.6 s for Groth16).
Where it appears
Bench

Short proof

also: succinct proof · SNARK
In everyday life
A one-line note vouching for a whole book of calculations.
What it means here
A proof whose size and checking time barely grow with the size of the rule. On our bench, the SHA-256 rule is a hundred times bigger than the age rule, and the proof went from 164 to 196 bytes.
Where it appears
Bench

The BN254 curve

also: BN254 · alt_bn128 · pairing-friendly elliptic curve
In everyday life
The kind of paper the envelope is made of: strong today, but not proof against everything.
What it means here
The mathematical structure our proofs are built on, chosen because it is fast and widely used. It has about 100 bits of security by current estimates and, like every elliptic curve, would not withstand a large quantum computer; see the Post-quantum section.
Where it appears
Bench

Secrecy is not integrity

also: confidentiality vs integrity
In everyday life
A safe hides the money, but does not prove the amount inside is right.
What it means here
Hiding data (encrypting it) and proving something about it are different things. The encrypted computation in the FHE section hides; the zero-knowledge proof guarantees a rule was followed. Serious systems usually need both, like the encrypted ballot box, which uses a proof for each vote.
Where it appears
FHE: the encrypted ballot boxVerification

Batch proof

also: zk-rollup · validity rollup
In everyday life
An accountant who closes a thousand receipts of the day and hands the tax inspector one receipt proving every sum is right.
What it means here
The best-known use today, coming from cryptocurrency networks: bundling thousands of transactions off the main network and publishing only a short proof that all of them followed the rules. It serves as an example of scale, not as investment advice; the same idea applies to any batch of calculations someone needs to check without redoing.
Where it appears
Practical uses
Talk to us

Does this apply to your case?

Tell us in two lines what you need to decide or measure. The first conversation is to see whether measurement solves your case, and if it does not, we say so.

Talk on WhatsApp algorithms@stickybit.com.br Stickybit · Porto Alegre, Brazil, since 2004

← 0k-proof: proving without showing · stickybit.com.br

Sources