Research Notes: What Zero-Knowledge Proofs Enable on CKB

@Mulandi_Cecilia

I went through your groth16-ckb threat model, Molecule schema, and the zk-Lock M1 implementation. Your zk-Lock gives us a concrete creation-time proof-gated Lock profile, with the VK and public-input commitment fixed in the locked Cell’s args.

This materially helped sharpen the CellScript ZK proposal in Issue #22.In particular, your work suggests we should distinguish two integration profiles:

  1. a creation-time proof-gated Lock/verification slot, where vk_hash and the public-input commitment are fixed in args; and
  2. a dynamic CellScript transition verifier, where public inputs are derived from the exact old Cells, proposed outputs, action, Script identity, and replay context.

Also I think your Groth16/BN254 implementation is a nice concrete candidate for CellScript’s first experimental verifier profile.

If you are interested, I’d like to invite you to review the Phase 0 design when you are free (no rush though), which addresses things like:

  • proof-gate versus dynamic-transition semantics;
  • VK/verifier identity and CellDep resolution;
  • canonical proof/public-input codecs and WitnessArgs placement;
  • mandatory transition/replay bindings;
  • the adversarial and resource-evidence matrix?
5 Likes