ZKP: Validity rollups and beyond - Panel w/ Edi Sinovcic, Cathie So, Andrija Novakovic
ETH Belgrade Community·Sat, Oct 7, 2023, 12:00 AM
ZKP: Validity rollups and beyond (potential for Cloud 2.0) Participants: Edi Sinovcic (Shard Labs) Cathie So (Ethereum Foundation) Andrija Novakovic (Geometry) Moderator: Aleksandar Veljkovic (3327)
Transcript
foreign okay hello everyone Welcome to our panel on ZK Roll-Ups and the future of zkl Roll-Ups in context of potential Cloud 2.0 Solutions uh before we start with the questions for our guests we'll first introduce our guests actually they will introduce themselves so first Eddie Katie and Andrea okay thanks a lot so I'm an ex ethereum core Dev mostly working solidity but you know being in ZK space for like five years now researching it a bit and most recently kind of last three years been like working in Stark net ecosystem we have a strategic partnership we start with like combustion stuff from protocol to Dev tools to devs and so on so deep into the arabical I'm currently a Serial knowledge machine learning researcher at PSE privacy and scaling exploration team as a team at ethereum foundation so I've been doing a lot of kind of like infrastructure research like how do we actually speed up to do machine learning in CK so that you know we can actually make it like possible for the users uh yeah and I'm Andrea I'm cryptography researcher at geometry uh also focusing mainly on uh snarks and zero knowledge stuff so yeah happy to be here okay thank you so first let's start with the basics so Eddie can you explain us a bit uh what is DK roll up sure yeah like in general like maybe we can do distinction between optimistic and ZK Roll-Ups maybe validity once and so on so I assume most of the audience here knows about optimistic rollups you used it maybe if somebody wants did you use like optimistic ones okay we have you know decent amount it has in in air so you know with optimistic roll ups we have a roll up and we have fraud Pros that are posted kind of on layer one the issue with that usually is it takes a week or so maybe more or less depending on implementation but we have a you know a lot of delay in finalizing the solar one with ZK and this specifically validium Roll-Ups it takes much less time because the cryptography improving process is kind of different so let's say that we have already ones which are non-privacy oriented and then in the end we have a ZK ones which are actually with the Privacy embedded like Cal State like allele and some others so so yeah that's but the zika Roll Up is in its kind of core is you have a roll up and you have like this proving technology that kind of generates proofs and poses policies on layer 1 with a math that is a bit different than just the optimistic one but yeah that map is kind of yep so the ziki part is actually there to prove that each state change is correct between between I will say between blocks but in general between different states the transition is correct so Katie can you tell us maybe do you see any technical challenges regarding the zero knowledge zero knowledge proofs that are used for those roll ups right so um well in order to scale using CK row up the property that we're using is that the proof size when it's verified it's very small right that's why we could do it very quickly in L1 ethereum but the challenge is that then the proven time is quite long and significantly computationally extensive all right so actually I think one of the biggest challenge that CK rops have is first of all sequencing because it doesn't make sense for people to be repeating this computation since it's very expensive right so how do you actually delegate like different notes to do these proving so that you can then verify I think that's like one of the biggest technical challenge that we're facing with CK Rob yeah so from the implementation side we have those challenges do we have any challenges from the side of regular user that would like to run a node uh of this kind of roll up so Andrea can you tell us a bit of the challenges regarding the running the node so our the resources that are required yeah so in order to have like a huge scaling and to put a lot of transactions in in that transition function you need like a lot of ram um you also want to use some very well audited hash functions which are still uh not JK friendly hash functions so you have like the huge Now scalability problem and you will you as a prover you spend a lot of time actually making a proofs of something that is currently very cheap on normal computer so yeah like we also should have we also should see some shift in how we measure gas how we measure uh uh what is actually hard what is not when we switch to that system yeah so definitely we see the the value of those roll ups but we also see there are challenges for running the Roll-Ups and we also have technical challenges so another technical challenge may be using proofs that require trusted setup for example so where are we with this so yeah so trusted said and that people hear over and over again some of you might have heard of like the kcg uh setup ceremony that ethereum is running so basically there is a lot of different proving schemes that you can use for ZK and some of them require what we call a trusted setup which is like for a particular computation that you're doing you need a bunch of people to provide this like Randomness so that you guarantee that the proof is not tamper right so basically the idea is if you have some Randomness that people already know fully then people can essentially uh well tamper that proof if they know that entropy fully so the idea is well if we get a lot of people to do this trusted setup then um unless there's some malicious attacker that knows everyone's contribution otherwise it's not able uh to do so so there are so the more um I guess the more specific The Trusted setup is usually the trade-off is that the proving is cheaper the verifiers is also cheaper so growth 16 for example is like you have to have a trusted setup for every single computation that your different type of computation that you're doing but recently we also have like more Universal system like Planck where you just need a universal setup right so one setup that for example just similar to the kcg ceremony like that millions of people contribute to then we can reuse that over and over again for CK yeah but this is definitely a kind of trade-off like whether there's trusted setup or not there are other ways like see cash they use totally a setup that doesn't require trusted setup but then you have even longer preferred time so I guess that's um yeah the the other technical challenge we're facing yeah one of the interesting Roll-Ups is actually our ZK evm rollups so we're we're trying to emulate the the functioning of of ethereum virtual machine but using the ZK proof so how do we do that there are like different kind of approaches but yeah like so we have like maybe two just to go step back maybe on strike and Starks like you have a trusted setup in usually in snarks but there are also technological sargs which kind of removes that obviously there is some overhead due to that so it's not only that we need to use like you you know Universal setups but you know we also can use the Starks and so on they have their other disadvantages but yeah so maybe to go from there so what we have also on the market is EK VMS which is virtual machines and ZK EVMS which are kind of interior virtual machine why would we want to use like ethereal virtual machine well you know a lot of people already used that stack we have dabs developed and so on but the issue is that usually the hash functions and so on are not really ZK compatible or you know ZK friendly so we have to create some kind of conversion from you know the solidity code you have into the like EVMS like ZK VM that you have underneath I think scroll uses uh the bytecode compatible one or like the we have a guy from scroll here so maybe he can jump it but yeah we have we have like different kind of levels of compatibility with like uh in ZK VMS I know like ZK sync basically doesn't have phone compatibility so we have issue on that but scroll does and but I'm not sure what kind of is the biggest difference on on on those kind of things maybe Kathy you know there uh I'm not familiar with like the actual technicality but you're correct that scroll is uh at least currently 100 compatible um and then there was CK sync there's a little bit of difference but just riding on the bico thing um when discussing with scroll actually it's a very interesting problem is that like let's say there is an upgrade in evm like ethereum itself there's always a delay when you're gonna get a 100 compatible version in the ckevm right because like it doesn't directly translate so I think that's also and um would be a quite interesting issue that we're going to be facing in the near future when there's upgrade to ethereum yeah for sure like I'm personally proponent more on the ZK VMS than ckavms because DVM in its own core back at the time when it was built it was like really good system but you know we've seen some of the inefficiencies of it and so on so we have a trade-off if we want to Target let's say one billion users in the future do we use this Legacy system and build a top which have an overhead or do we go with like completely new stack with its own issues like Cairo like you know and new language completely new virtual machine and so on so these are some of the trade-offs we have to take into consideration but good side is we have multiple teams building this with different Traders so we'll see what survives and thrives in the future okay also one of the interesting things is that if you want to prove that the state change was correct you submit the proof to ethereum blockchain but for all the smart contracts you're mostly using a growth 60 improver because it's actually the cheapest but internally some ZK VMS use both Starks and snarks so we have multiple provers to to prove that the competition is correct and the proving was correct probably okay so we see that ZK Roll-Ups are getting more popular in general there are use cases for them and so on uh we also say when you say ZK roll up we say ZK between State changes but uh is there any ZK in the blocks themselves if you see if we talk about Roll-Ups as blockchains sub chains so uh is the data hidden inside blocks or is just transition different it just transition hidden so if yeah you can go in so like I know like the zika sync and both circuit just supposed to stay diff basically to to the like mainnet so what that what that means basically if we kind of do I don't know like we do 10 interactions on on a layer two on the roller basically for a specific thing only the difference between the first and the last basically state will be posted on layer one with I think scroll does it also does okay and you know like so most of the systems do just pause the difference or not if you know or no okay zkvm from polygon post is all the all the transitions of state if I'm not mistaken so we have it sorry scroll as well like all the transactions okay okay good to know I learned something new today so thanks so you know like the conclusion basically Ezekiel sync and starknet do just post like just the different difference in state and others basically post the other transactions and Transitions okay oh yeah so we have the ability still to see the data it's not zero knowledge hidden but we need to have a zero knowledge approach to confirm State changes okay exactly well zika Roll-Ups in general are one of the one of the leading scaling solutions for ethereum and the idea is to introduce decentralization to the wider audience if we can say it like that so the idea is to maybe switch from existing clouds to something more advanced or more let's say verifiable where do you see it or actually do you see the potential to reuse zero knowledge technology to something that can surpass current uh problems with cloud and become actually something that is now called Cloud 2.0 so yeah so I guess we have two sides there uh one side is what Getty mentioned about like zkml and just being able to verify all the models and some huge computation that you're getting from the cloud uh and different side you can also look at like computation delegation where actually um you can build your huge cloud like very powerful cloud from very small specialized chunks that are uh independent so instead of one Cloud having to run terabytes of ram machines to be scalable you can actually have many more many small players who run some specialized part of computation but I like designing a like specialized Hardware or or data centers or whatever just for a specific task and then a part of some huge computation can be delegated to them and that whole so to say graph of computation uh in this kind of PCD settings is fully verifiable so you don't need to trust any party in this holds um splitted Cloud so to say and you can very efficiently produce the same computation without actually having to care too much about scalability and having some machines running when they are not have what to run and like it can reduce the cost of of a fully centralized Cloud a lot without compromising the results or or anything like that interesting so Ezekiel will actually actually introduce verifiable computation to exactly exactly Network okay exactly so yeah Katie you are also involved in zkml so zero knowledge machine learning do you see any potential of uh using actually using a secret knowledge machine learning in the environment that could work as a cloud so I can submit a query like image and the network will be able to answer me to that query by you doing some computation domain of machine learning on the image so classification segmentation and so on right so um well regarding this Fair viable computation I guess the biggest challenge is of course if we can run it on the blockchain itself that would be great right and even when we talk about rollout when we talk about scaling we're scaling The Ledger right not the computation side so uh my personal take is that yeah so what definitely ckml is one thing or it really just any computational heavy applications it's actually best to take it off chain and have some form of ways to do verifiable computation so I think ckml is just a very small chunk of it right because machine learning ultimately is something that is probabilistic anyways so you don't have full 100 accuracy right so there's only so much you can do with machine learning but there is a lot of other things that um for example you know anything that is role-based algorithm base things that we might want to have a result to commit to a blockchain um you know so one of the example I give in earlier today's uh presentation was actually like Echo trading right we can easily have a verifiable algo trading if we are able to um you know achieve verifiable computation so I think the the power of like taking all these computation off chain but then at the same time being able to verify on this uh Ledger that we have a strong consensus Global consensus is a very powerful tool so do you see the possibility of utilizing ZK without blockchain in this constellation or you think that the blockchain is the basic Foundation that that needs to support such use case I think it will be kind of a network or a network off Network actually so computation would be a network of itself and then but we still need to rely on like The Ledger itself to have some kind of consensus so the way I think about it you know especially at Andrea use at the computer um uh analogy is that like you can think of maybe The Ledger or the block time itself could be the clock that we're clocking our computation right so how do you have a universal like let's think of it as if we have a bunch of decentralized computation how do you even Define time it's a very interesting question so I think like the idea of having a consensus is actually very important it's like the clocking of uh you know our computation so in general does it have to be a blockchain but there needs to have to be some kind of consensus that will synchronize the network to be able to operate like that so Eddie do you see any potential use cases for a system like that besides zero knowledge ml that we just mentioned some practical use cases for general population so like yeah one of the like things that kind of has been developing outside the fine FTS and so on this kind of game so usually like it's currently Primitives you have on-chain games and so on which are kind of we have a limited capacity of Ledger you know consensus is like expensive to to achieve and so on and potentially what you could have is you're playing some off-chain game that you know how it works and so on and you buy some item or whatever you can generate a proof settle it on chain basically do you have some item that you want to trade or whatever so it's kind of a hybrid potentially that you know you could still have a Marketplace on chain which is kind of trustless and so on Within game kind of inputs and stuff so that's one potential thing but obviously you know from cloud computing in general you can kind of prove any computation but you know more user-facing stuff that you will see also identity is kind of one of the biggest kind of questions like I just had a chat with the with the polygonate ID guys basically that's so many questions and not a lot of answers because in web 2 the identity for example it's not sold but theoretically if you have those fractions of identity we kind of combine them we could have an on-chain basically identity which is consist of multiple of those also like the idea is if that is also good because they are trusted kind of parties and so on but anyways we could have those kind of Hybrid models that kind of play hand in hand basically this cool so from the user perspective again I as a regular user may use a mobile phone with uh I wouldn't say the slower Hardware but compared to PC or any other server it's a it's a slow Hardware so does that mean that we can use a mobile phone and request some computation which is a lot heavier than the phone itself can fulfill submit it to the network and the network nodes will I say Network nodes in general I don't I don't have any idea of the architecture but I think about the nodes the nodes will perform the computation answer to me and I will be able to verify those results some way so do we see any any incentives maybe for operators of those nodes so any of us may use our own resources to to utilize the free resources on our computers to support some that kind of network so do you see any way to incentivize those people or whatever in general incentivize the people who run the clouds or incentivize yeah to run the nodes that will form the cloud the virtual Cloud because so I think that by just having the the ability to have some very specialized part of that whole Cloud will allow you like to lower your costs to have better approximation for scaling um to better utilize your resources and yeah you should have a lot of incentive to be a part of some like a bigger Cloud that as a user of a cloud or as a node Runner so it will support the system uh so I think both uh uh like but I think we should start from the perspective of node Runner which will be able to contribute to some huge scale system and without like needing to have full data centers around the world uh in order to to just be the part of that and as an end user whenever you have some important computation that you cannot easily verify that gets the value to you or your company I feel that you will be incentivized to just get approved that it was run correctly and yeah we should distinguish between the computation that you expect the proof for um maybe we can look at zkml stuff so if you have a I don't know Network would generate you the pictures and if you submit some requests you get a picture you yourself can like Vote or resolve is this good or not enough good for you without actually caring how that computation was done but if you have some NP problem like some optimization problem or like you have a service which optimizes your Logistics so to say and you put some parameters you get some results you cannot actually be sure how good that computation was and uh was it done on some lower model maybe it was just a guess from this club like whatever there is so many ways how they can make their life cheaper for just putting the wrong results on your site or not optimal results and this is the the part which you would like to have some kind of commitment from that cloud or that company on which you can verify that results you're getting are like at least what you're paying for yeah like I think we like let's let's go back basically let's forget about ZK so let's go back to ethereum so like we have an issue in sanitization of full nose light nodes and so on like that's kind of the biggest issue so I think this solution is kind of twofold we should incentivize also those kind of part of the infrastructure not just the validators not just the ones who are producing the block out also the one who are kind of you know watching this you know syncing the network and so on and the other basic part is making light notes lighter so you can run them on your mobile phone in a browser so you can verify things really easily so but obviously you know printing more tokens is not nothing not really a solution so you know also with the ZK kind of stuff it's hard because you still want have one prover or one sequencer at this point in in the development of the space so they are kind of trusted and so on you don't have this overhead which is a feature basically with possesses says that multiple kind of parties can verify this full State and generate the whole thing and so on because it will be too expensive as basically a real set so this is more than an open question than than the answer to be frank but yeah yeah I think like regarding incentive for running like a complete compute node I think there's a lot of incentive people are paying a lot for web 2 cloud services nowadays anyways uh definitely it will be more expensive in the web 3 version at least in the long in the short run uh I think maybe to me the probably the bigger bigger issue is whether there's incentive for the user to use this web 3 version of the cloud over a web 2 version all right so um you know there's very trusted cloud services in webtoon nowadays like why would they pay perhaps maybe 100 times more expensive for a web 3 version so it depends on like really how we how much we believe in but you know don't trust verify kind of point of view but yeah I see that maybe adoption could be a bigger issue here than you know asking people giving incentives to run like compute nodes we kind of have user experience current field blockchains is not really the best so so yeah yeah that's actually a good opening question for the for the next question so today we use let's say Gmail we use OneDrive or so on we use a lot of cloud services on our phones or any other device but how far are we from today from transforming the world where we use web tree cloud services on daily level so when I woke wake up in the morning I want to open the mail which is hosted in some decentralized environment I would like to store files in some decentralized file system I would like to stream videos from the centralized system and so on so today we rely a lot of on web on web 2 cloud services but what is the state of cloud services on web3 today so um okay I'm gonna start with uh just a little bit of I guess personal view is that like personally I don't believe that everything needs to be left three but as long as there's an option too right so you say uh Alex um email example actually nowadays we have the option to run our own email server at home right there are people who are doing that right so as long as there is the option the alternative to do that and I think it goes the same thing with all the other things that you're talking about and I believe there are a lot of other projects doing it in a decentralized way maybe not utilizing ZK but ZK could be a way that is more I guess trustable by the user without a lot of overhead of actually redoing the computation so like it is just a way to condense this trust other than like having the user to understand fully and you know do their own indexing look up all the data I see that like it could be a supplement to all these already decentralized streaming um uh what other decentralized services are there streaming p2b messaging etc etc but like CK just kind of add that verifiability in a more efficient way does that mean that in the future we'll still have clouds as today's webto cloud and Webster Cloud only for specialized Services where trust is important I mentioned those few use cases like file storage email and so on because there are solutions today that actually Focus their business models to the to that side so um what would be maybe the question for Eddie what are the the obstacles on our way to get to the web tree at least subset of cloud services on web tree so what are the problems for adoption system like that maybe demand for that because currently we're still playing kind of with League Legos and so on you know inventing your tokens you know like okay D5 was one of the biggest use cases because Finance is completely broken in web2 so you know we need this kind of system which is trustfulness you know so that's part of the story we had nft summer you know like different Federation and so on I believe in the future this kind of ownership potentially will be the next wave and so on but for the cloud compute and so One gaming could be one of the biggest things basically to drive this the main question I have there is what kind of stuff do we need to put on chain and what stuff you know we don't want to kind of trust to this big AAA companies and so on and also the time for that you know time to Market basically for one Triple A game is five years if they even start building it now in five years maybe we'll have demand for this so you know we're basically building for the future that may come so that definitely um needed but yeah maybe ml models maybe same AI is kind of a big term but yeah yeah and what you started asking about decentralizing some parts of the system so I think that before the whole verifiable computation um decentralization was a way to fight a party which has a lot of data and that is able to buy us the results in any way like by serving which data is serving to whom it's serving and kind of decentralizing any of those system was a way to fight that no party in the system can buy us the results for example you mentioned like uh streaming services or like social algorithms or whatever but now with verifiable computation it's also maybe we should just not decentralize that uh if we have like a public models that you can verify or just not models just like algorithms that are if you can verify that they're being run and you can check that they're like not biased or whatever you should have much more confidence in the in that service without necessarily decentralizing it and fighting with all incentives that you uh just get by by entering and putting more parties into some into some Network or system yeah there is always a level where we trust is it like software is it like Hardware is it like yes you know like it's it's always a trade-off okay do we want to build our own Hardware so we are like secure that this is not tampered weight or that it works actually as we want yeah do you see maybe any domain where the entrance of web3 cloud will be the quickest so where will be the first entry point for web3 systems in Commercial Way like it's like this kind of verifiable computation basically you'd mentioned like with you know now ai being a hype and so on it will probably mature into like there's a lot of open models and so on still we need to have a huge Lino clouds for this but we want this stuff to be as verifiable as possible although it's all probabilistic so the question is how are we going to verify it because you know we usually don't know what's under the hood so so yeah yeah no I think um I I truly has um I think the domain where fairness is important it's probably the most important for verifiable computation as well as you know Eddie just said like no one is always going to look under the hood even though we give the hood is openable in a way sorry like so like social media like Twitter open source there whatever algorithm who's going to really look into it right all users really care is whether this algorithm have been fairly applied to you and me and you know everyone else right and actually in that case like even though the CK seems like a such a mystery mystery thing I think it's actually the opposite in this case because it's very easily verifiable in terms of assuring that the same computation has been done to everyone's data right I don't need to understand the math I only need to see the proof that it's exactly the same computation done on everyone so I think like you know whenever fairness is very important um then that domain could probably adopt this verifiable computation uh the most uh yeah probably the soonest yeah now when we use our cloud services we submit data to some other centralized entity which follows certain rules of the country where they are where they're situated and if any data loss or any data breach appears they're reliable so do we see any problems here with the decentralized clouds where you submit data to the network and every node in the network can actually see the data the data is transparent but on the other side if some data breach happens who is responsible it's a difficult one yeah that's quite difficult question at this moment but um maybe you should still start with a entity that actually has the data and other entities are just like executing the parts of the computation before you go to this even harder part about decentralizing the storage and storage proofs and yeah so reducing the computation on the low level side where data is maybe indistinguishable for the from the inputs that are sent can actually solve the problem where every node participant has some chunk of computation which is anonymized and then Returns the results or maybe if the data is already it is okay for the data to be transparent so you submit data to the network that is public data then there is a there is a potential for the system but do you have any idea if bigger commercial companies will be glad to change their their corporate systems that are in the background of their companies to something that will technically make their data leave the company and move to some other entities like small companies or actually physical participants like us here how glad will they be ZK is not the solution for everything and I mean it is true like when it comes to data privacy um you know as Andrea is saying that when we talk about CK essentially the prover is the data owner and that's why there's also a lot of Technologies that's being developed like fully homomorphic encryption you know MPC so I think unfortunately um to be frank there might not be a lot of incentives for those who have two companies to disclose those data and then that would mean that we probably have to wait until like other tattoo to be um you know developed before that happens but like within I I guess at least within what we can do right now then there are still a lot of use cases that can make use of public data and verifiable communication it may be like similar experience we run back in 2017 also like this was like one of the companies basically around this it was a Consortium based chain like based on ethereum and so on why they do that is basically because part of the state is private and so on and only they have access to that so but to go step back basically to explain what the issue was so this was like the huge compound like Global one with multiple franchises in multiple countries each of those franchises behave like kind of a separate company so when you want to access from one side so one Island to to the other basically you need to request you know access somebody has to approve it and the issue with that is like the the basically computation and entities are separate somebody has to prove that then you have to order that and then what happens sometimes you somebody gives access to stuff that is sensitive they get sued and so on and the idea basically here was to create this kind of verifiable like you have a consensus atop so it's final blockchain is immutable database that nobody can tamper with and the idea like back then we didn't have ZK like in production but today like we could improve those kind of things a lot where okay you generate the proof that this was in your database someone that access it and so on you have approver as one of the entities anybody can verify that it's actually been done but on the other hand they don't see the whole data and everything because it's on their data availability you know committee or whatever so does that make sense that's kind of maybe but you know this is maybe what will kind of be the next iteration of experiments and so on a more Enterprise slash concerns Consortium basically chains so yeah we can conclude that there are still some obstacles and there are still problems with adoption but also there is a potential for such system in specific domains will actually add more value than web2 systems so adding a trust to some web to service currently run by some centralized entity with webtree we can add additional value which may surpass the costs of running such systems as I see we are a bit running out of time so thank you all for all all the nice sensors and all the all the potential answers for to the questions that are currently pretty difficult to answer but we have a clearer picture now and uh yep thank you all and we can switch to questions from the audience yep where is the mic um yeah in dark room this is kind of a ZK you know we have a microphone yeah sure we can repeat the question so feel free to ask sorry there's a question in front there's a question sorry sorry can you please just wait you know you're next yeah the rent there maybe repeating the questions oh yeah the question was do you use if you can imagine the use case where you can rent your Hardware to anyone else so to to the network in general or any other participant how do you see such a use case in this web pretty decentralizing clouds so I guess that's something we already mentioned but at like my take is that it should not be that decentralized because still I feel that some parties will have more incentive if they really specialize to very specific kind of computation um before you can have like the full Open Marketplace where you can submit something and yeah we like it I usually needs a specialized hardware for this kind of thing it's nothing behind in demand maybe for this kind of like things I don't know you have some gpus or a bit exactly better then you know you can get price for that but yeah with the the matter of better distribution distribution of resources right when it's two different visualize and two P2P then it might not be the most efficient way okay so there is a speed of light limit you know with propagation of information so that's also one of the limits there is a limit how much you can parallelize something until the communication becomes an overhead we had a question back I think to ask about the hash functions that are used currently and will be used in future starting from Poseidon we have Poseidon 2.0 by the way we as a company participate in research on Poseidon as well as reinforced concrete and there is also tip 5 and rescue Prime so there is a variety of of hash functions out there used in non-completely non-standardized way in particular because most of them like Paul say the hash are very parameterizable so my question would be from performance versus security perspective which one would be in your opinion of winning one if possible because that would be very important when it comes to standardization in future and possibility of putting all these proofs in Asic for systems uh okay I'm not sure if I heard the whole question so if I miss something please feel it um yeah so regarding hash functions I think all these ZK friendly hash functions are very new and for like some currently systems production that it is not that easy to just replace Shah kachak or Blake with with any new hash functions until certain period of time and auditing passes um so yeah I think it mainly depends on and at which stage your system is and what are you trying to achieve because what we were speaking about like evm and having the the network to be verified you really want to have um as fast as possible on the proverb side where which uh smaller proof size and uh and uh like non-linear verifier to say uh so yeah I think it's just like it really depends on the whole system and at which state it is it's like one of the things I would like add like to add is like okay there is new fancy like you know things but if you didn't test them in production we don't know if they have a security flow and with this kind of things you have it's a trade-off do you want something fancy new that's much better or do you want something as stable or something in between and so once exactly is currently maybe in in you know perfect spot quote-unquote but yeah yeah and for a very like specific use cases I think it's not very popular now maybe that's people not considering uh different kind of ZK proof systems which are not coming with this magical snark world world where you actually can do very efficient uh Shaw or cat tracking like NPC in the heads I think um where your verifier will also like not be succinct but will be extremely fast if you're not running evm or like on a just normal machine that is very far so yeah I think that's also something that should be considered uh if you're actually one if you still want to use like shower Gadget um then you don't want to go in this like VM kind of setting and the hash functions that are used for ZK were not invented to to be better in a security perspective From perspective security to be better than shot three but to be more efficient for circuit computations so they're that's why those arithmetic hashes are used instead of bit caches that like shot three so starting from that perspective we can see that arithmetic hashes may be the slower I mean will take some time to to achieve the security of shot three functions but for efficiency purposes they are good enough let's say and the time will show which uh which exact cache will be the winner like the best but it's not it's probably not Winner Takes all you know like they're like there is no one solution that you know like wins or absolutely so yeah yeah I just wanted to share a very quick use case that I actually use sha-256 in some of the ckml circuits and I get asked a lot like why actually everyone who read the code is like why are you using sha-256 I'm like well that's because there's also integration with other things right so in particular like if the data is hosted on ipfs actually they use shot 256 to generate their peace ID the CID well then you kind of have to integrate with that and it's not very efficient to have like two different set of hashes to verify to try to verify the same thing or something like that but for specific purposes where you have to achieve a certain level of security by some standards you are required to use verified functions like sha functions and so on that's where you don't you cannot ask the question which one should I use but the one that's on the list exactly yeah okay do we have any other question I think we have there so correct me if I'm wrong to generate this ZK proofs or ZK circuits you need quite a powerful Hardware and will that not be the same what happened to bitcoin that these Asics War started and they tried to generate data implemented new Hardwares created new Hardwares that were more efficient and it's it's now the main topic that there are very efficient but not efficient in the terms of energy consumption the it's consuming a lot of energy and ethereum is now proof of stake and it doesn't consume much energy but now the layers to this change in layer 2 will have the same effect that it will consume a lot of energy because of this ZK proofs and ZK circuits yeah maybe I can take this one like from the decentralization perspective I don't think it's the same problem because like with like Miners and someone you had a competition so the the bigger amount of hash you had in a system the more secure the system is here is nothing correctly like because of that and some of the designs I've seen on the centralization of SQL servers at Proverbs it would be on a range of 10 100 or whatever but it will be more or less capped and so on so you will have an overhead and move towards more special hybrids so one but probably it won't be uncapped or you know you won't won't have you know unlimited amounts of like you know miners that are doing this kind of stuff so I would say that on one hand this is kind of a proof of work we already have special or Hardware you know the better Hardware you have potentially faster the pros you'll generate and so on but on the other hand I don't think this on a consensus level will be on cap because you don't basically need this and also you have optimistic parallelization approving which kind of you give a chunk of the proving to each of the of the basically machines or the hardware so that way you don't have an overhead that you had with proof of work which everybody basically kind of generates you know approved for the whole day so so yeah okay seems like the time is up and thank you for all for listening thanks to all to our guests that thanks introduced us a bit further into Cloud technology on decentralized systems and that's about it [Applause]
Automatic transcript — names and jargon may be misspelled.