# Polygon Miden: Extending Ethereum’s Feature Set | Dominik Schmid (April 2023)

- Channel: [Berlin Ethereum Meetup](https://streameth.org/berlin-ethereum-meetup)
- Date: 2023-10-07
- Duration: 35:33
- Watch: https://streameth.org/watch/yt-jMTMidok9sA
- YouTube: https://www.youtube.com/watch?v=jMTMidok9sA

## Description

Join us on Meetup to keep track of our events in Berlin: 
https://www.meetup.com/de-DE/berlin-ethereum-meetup

See you at the next one!

---

Apply to speak at our future meetups: https://forms.gle/bGXFc83MHAcnmMQM6

---

Twitter: @BerlinMeetup

## Transcript

I'm Dominic I'm working for a polygon Labs now we are called polygon labs and um I'm working for polygon Maiden so we have different products basically we try to do everything with zero knowledge now and putting on Maiden is a zero knowledge roll up that tries to extend ethereum's feature set whereas I'm sure you're more familiar with the zkevm or other zkevm Solutions and they are like straight scaling Solutions meaning that they offer the exact same feature set of ethereum just to more users and cheaper so our goal is to build a roll-up that extends ethereum's feature set and we think that enables a novel and useful applications that are currently not possible by some limitations of the evm so we thought about before all our moms would use ethereum still we think it should scale better it should be safer and more have more privacy but what we mean by that they should have the ability to handle High load over an extended time um it should have less human error and attack surface so if you lose your private key or my mom would lose it then uh there should be some way to recover it and um obviously there should be some sort of privacy at least at the level of uh PayPal but maybe more uh before my mom would start using it I guess and um so we try to add new features in that dimensions and basically one design a key design of our rollup is that users can create your knowledge proofs as distinct actors and this is super different to the evm and I will explain in a minute but basically the ability that for users to create zero knowledge proofs means that every transaction only gets executed once so the network only verifies whereas in a normal blockchain obviously we verify by re-executing or recomputation and we try to send only proofs in the network and that we think scale is better and um if the users can act distinct from each other like logically independent we can execute transactions concurrently which gives us um better scaling properties for example yeah or like we aim to have parallel transaction execution um at the safety uh Dimension We have basically a transaction model which I will explain in a second that helps us or allows us to recall transactions and that means if I send a transaction to an address that doesn't exist or I change my mind then I can get it back and obviously we have account obstruction uh which you probably know that gives you a social recovery social recovery key rotation rate limiting but in our model assets are also stored within the account so there is no Global ear C20 contract for example that stores who owns uh how many of these tokens but we so every asset in the account as a feature okay and for privacy so we use zero knowledge uh in the uh in the real sense of the of zero knowledge proof so not only for validity um uh reasons and uh so users can basically hide account data in our model and they can selectively reveal the state and uh one bonus is that there is no extra cost for privacy associated with that and um in addition to that we can also hide the transaction graph or the transaction data and first we will have web 2 privacy meaning that it is private from other users but eventually we will get to a fully private solution okay so that's a lot of promises how do we do it uh basically we uh because we don't follow the evm path we have created the maiden VM which I'll show you in a second uh we are not bound by the account model the ethereum uses so we basically uh mix together an account model and utxo model and zero knowledge proofs to achieve exactly the features that are just described so it's an actor-based model basically with concurrent of chain stage that's enough with the buzzwords but um let me explain who is familiar with the actor model yes it's like it's used with this databases and basically actors are little State machines with inboxes so when you think of a system and then you have these actors they're um every actor can change its state independently from each other and they can send messages to each other so they communicate by message passing and every little thing machine or actor has an inbox and receives a message and then it decides to change State then it can create other messages and Trigger State changes with other actors this is used in yeah distributed databases and this basically motivated our design for our Cinder and a key property is that messages can be produced and consumed asynchronously and this is how we try to get concurrency okay so the actor model and Maiden means we also have accounts in Biden like on ethereum and made in every account is a smart contract so it has a state and an interface some code and these actors these accounts basically they send notes to each other so the messages from the actor model now are just notes like banknotes and both can carry assets so an account has assets and the node has assets and you can send assets to each other with two transactions so that means the first transaction means that the accounting one would create a node and send it out and at some different point in time account 2 can consume the node and then the asset transfer is complete and this is uh like that means the transaction is actually quite different than on ethereum because a transaction always involves only one account it is defined as the state transition of a single account and it changes in state when it consumes nodes and or it produces nodes and that's how the transactions basically are Sting from each other and can be proven distinct from each other um so basically um like you can execute a transaction and consume several nodes in it um but um so you can consume the node by consuming the script reading the script of the node and in that case here for example the account receives something from node one and then it consumes no two in the same transaction receives another asset and then it can finalize it and because we have zero nodes roll up we can try to prove every transaction or every transaction at the end has been proven that means that um uh like a transaction to say transition and we use the Mind VM to create a stack proof for exactly that transaction and can prove the correctness of this state transition and because every transaction only in both One account we can do that in parallel and it's even so that users can do that themselves and that's how it scales so uh basically we have these two transaction modes a transaction needs to be prepared same as ethereum someone needs to define the structure of the transaction and which assets should be uh there it needs to be executed it needs to be proven in our case and then we have this final object the transaction proof and so the execution part and the proofing part can be done uh by the operator this would be the same as in any other zero numbers roll up out there like in the ZK ifm like there's a centralized prover or a small set of centralized proofers and you send them the transaction and they executed and prove it and on Maiden we also have this local transaction execution and this basically means that the user himself can execute this transaction apply a state transition prove it and send it to the network and the network or the operator only verifies that something correct happened um and now we combine this with um you have the ability to store your data with the operator um yeah like your full account data or you can only store a hash of your account data there and this is um how we get privacy so even with the hash you can verify a proof against it but you don't know what happened um in this state change and so we end up with actually Four uh modes of transaction so uh when you have a network execution so the operator executes the proofs and your online data then this is like uh on a normal zero nodes holder but if you have for example in the bottom right off-chain data so I store only the hash of my account with the operator and I locally execute uh and prove my own State transitions then I'm basically a layer three um on the mine roll up so basically every account is a zero knowledge roll up itself It's like because I can prove my state transition and then only that gets updated when the proof is being verified by the operator these proofs that can happen in parallel can be locally or network as I said and then the operator batches them together this is uh similar to other zero node rollups but at the end we need to roll stuff up or batch it together so we have recursive verification uh we have batch proofs and they get then a batch together into block Crews and the upper part must be done by the operator and um and this then actually like we add batch steps together into epochs again and then this gets updated to ethereum at the end um yeah and I want you to try it out so if you can I don't know if it's too far away but you can uh click on that and then um you should end up in the maiden playground so this is the mine VM in the browser and um it's it looks a bit weird but when you scroll down and you see a very small assembly program that adds one and two together at the bottom like at the top you have the button proof when you click on proof then you basically prove that the maiden VM executes this program then it adds one and two together and it should be in less than one second is it in less than one second yeah two seconds damn okay okay and when you uh now verify it should be a tenth of this uh time roughly yeah yeah right okay and this is like how it would work so obviously a transaction is a bit more complex as a program but uh like our goal is also that people can in theory or the mobile phone or on their laptop create these proof sent to the network and then the network only verifies let's say transition um like obviously there are uh you can choose uh execution or local execution and um it um like when a transaction touches public State that's a bit more complicated so when I just send some money to uh to Francie for example then it would only involve my account and my transaction and Fancy's account in her transaction um but imagine I would use a uni swap like a smart contract and I want to swap something and then this is somehow shared state so other users must know that something happened and actually what happened because the price changes and then um it is a bit more complex but I can show later that at least one of these transactions then uh needs to be an Network execution local execution obviously can be private whereas Network execution not so easily but at least you get privacy against other users and the hardware requirements are yeah high low obviously and a cool thing about Martin is the fees should be much lower when you prove it yourself right because this is resource intense and that means the more private mine will be used the cheaper it gets for the better it scales this is actually quite nice and a bit different to what we have seen from other uh roll up so far there where it gets more expensive when you add privacy to your turn yes that's a good question so we don't have a guest schedule or a gas model yet so um yeah but like it is yeah like I cannot really I like though the proof verification grows logarithmically and needs way less resources obviously uh but improved creation is quite resource intense but I do not know like I could not answer how much cheaper it would be yeah but maybe in two months hopefully speaking like 100 times like it's not clear yet on mine how we charge actually so like how gas looks like so I could not really tell um yeah all right um yeah so and our goal is to uh basically create this design space for novel applications and um so basically in a general rollout you have higher TPS than on ethereum and cheaper transactions that's the goal of scaling in a very short and we add client-side execution improving so our clients can create the proofs which is quite a nice feature and gives you that you can even run complex computations so you don't have a gas limit because the proof Size Doesn't really grow with the complexity of the program and uh you have these flexible transaction modes that I've shown you have off-chain data so basically I can create my own little layer 3 on Maiden for free and I have updatable transactions meaning that I can create a transaction and update it for free which is quite nice for example when you think of an audible exchange that you want to have on chain I can create an initial transaction and then I can keep updating it this is I can show you we also have recallable transactions so when I send something to the wrong address or to an address that doesn't exist then I can consume it myself after a certain time so let's think of an order book exchange for example this is one of these novel applications that you want to have on chain and uh for an audible exchange obviously you need to be super cheap because like this order book gets updated many times in a second or like in a certain time period And if you would pay every time to update this order book then uh it's just not feasible that's why we have these amms basically and on mine um I show you how it could be done a node in Maiden is this message as I said before that gets sent from one account to another and can carry Assets in this case the node has 100 each and the node does not only have an asset it only also has a script and this is the script that gets executed whoever consumes this node needs to execute the script and our scripts and programs are Written In Like A Merkle trees structure if you call it a must structure and basically I can start I can create this node with this worker tree and commit to a certain code and then I can say at the beginning whoever consumes this node gets the 100 eth from this node but he needs to create 1000 die like another note with 1000 die and send it to me okay and then people can say okay I don't take it that's too expensive and so after a certain period of time I can say Okay whoever consumes this node gets the 100 eth but needs to send me 500 Tai and hopefully like in this second thing is for free and almost in no time because I just need to reveal another part of this Market tree and this it does not need to be on chain and then if no one takes it I can just consume the node myself um yeah like other examples could be cool incomplete information games because I can hide basically moves and I can if you have a complex on-chain game logic you can build it on Maiden because it's not expensive anymore if you do client-side proving basically you don't pay cash when I create to prove myself and send it for verification to the network I can run fairly complex programs and they are super cheap and obviously you get the Privacy part so you could create a cool on chain game and server and wallets could be interesting as well so I could like obviously with a kind of extraction you have super powerful wallets but on Maiden you can hide parts of the wallet and reveal it to some people but to others not for example to I don't know compliance or Auditors and that means um you can um you can have like a a wallet that I know is hidden from competitors or when I'm a crypto founder crew then maybe it's good and I don't get hacked as much and not everyone sees that I have 10 000 ease in my wallet how do the private transactions work with respect to that availability because if you submit the hash you can of course make a proof but then have the other nodes actually know who sent what to who yes like the data availability question um in Maiden gets uh pushed to the user so if you want to use Biden privately then you can basically store the data encrypted on Google cloud or on any other program but if you lose it then the operator or the network would not know how to reconstruct that state if they only have the hash is if this is your question yeah kinda but more other people have more questions hi I just have a follow-up question on that so you said before that the user could choose when to send data is that is that correct so like for every transaction I would just choose what data I send um you can choose the transaction mode so you can choose to execute and prove the transaction yourself or you can just um send the transaction to the operator and the operator would execute and prove it and what would be the case well like why would I decide to actually send data it's like for example one second so imagine you have um like this setting like two accounts in a unit swap like smart contract right so um and then account one would wants to trade and account two wants to trade as well so they would execute the transaction they can do it locally and send a note to that smart contract but now the smart contract because Node 1 or Note 2 would change the state differently um needs to have a network transaction execution and proof by consuming both nodes at the same time and creating two nodes in the same transaction and this transaction three basically needs to be a network transaction because if not transacting to a node 2 could not be consumed anymore so if you have transactions with public shared state in that sense you always need to run a network transaction um I hope this answers your questions does that mean that all the Smart Control is very naive but does it mean that that all the smart contracts basically have to be like updated for this to just kind of like like or to decide whether it's a network transaction or not like so that the user is basically forced to share data uh no like on Biden every Everything is a smart contract basically and um but you would like when you code your smart contract for um like like decks or so then you would basically uh need to know this needs to be another transaction or not yeah but it can also be that you have your own prover and sequencer of that smart contract that is somehow public oh okay uh thanks my question is about ordering I understand when you're just sending assets between accounts then it's just local updates on the accounts to accept or to send that can be done in parallel but once you have notes that could be consumed by different nodes then ordering becomes important so you need some kind of a global consensus mechanism within this roll up um so that kind of makes makes it we're no longer parallel so how does this ordering work how do you decide what needs ordering and what kind of a consensus system or how does that happen in mind yes uh like if I unsaid your question correctly then exactly that in that example you need to order node one and node two right so one of those you need to execute first but because it's in one transaction basically the ordering happens in whoever executes this transaction so the transaction no I meant like suppose you have one of those Merkel tree diagrams you had before and there's a note out there and it could be consumed at two different accounts I could either you consume it you're back yourself to claim it back or somebody does accept your trade offer for the Thousand die and consumes the note and they can't both happen like this note can only be consumed once but we don't know which account will consume it so it's so we have to decide which one of the two happens so there needs to be a global ordering so or that yes so maybe I understand your question correctly now so basically there is a utxo database where you um basically when you create a node you add an entry and then there's a nullifier database that basically has an entry if the note is already consumed so if two accounts at the same time want to consume a node then it depends which like so you need consensus on the utxo database yes the global yeah that's what I mean exactly yeah okay okay now I get your question so I don't know yet at the beginning we have a centralized operator but there must be some sort of consensus mechanism exactly on the state database the suitcx or Notifier and account yes um I'm not sure if you if you have talked about this because slightly late but I will um have you this decided on what programming language is going to be used for creating smart contracts yes and the answer is I because we don't go with the zika evm solidity is quite hard right yeah because this is some new up codes there and um so at the moment we have our own assembler language modern assembly uh but we know that this will be uh quite hard for people to learn so we have a compiler team that basically at the moment we Implement Sway and move uh the smart contract language from Facebook um or like and these are easier with our model to implement and in the future hopefully we will have a solidity transpiler but I've just heard yesterday that never mind they tried to do that for stagnet um yeah and they seem to have now decided to keep Cairo 1.0 and not use this transplant but yeah we'll see at the moment it's my assembly that's in October when we have a public tested which should have or we aim to have a move compiler and so where you said as well yes okay that's why like a subset of rust or sway from fuel from qbm exactly um what's the is it late Frontier um what aggregation proof system do you guys use uh pardon me which aggregation the aggregation proof system like we the mindvm uses uh Stars yeah and we have uh like recursion in uh like that we built our own basically to verify within the Mind VM approve and create a proof for that so um does it ask you a question or kinda kinda but we're not using plunky right no no no it's uh Stark so uh yeah but like do you because like because what like plunky uses like a star key for the first transaction and then aggregation in Starkey too right yes so is that do you guys do something similar or we don't um I understand or a different team from uh from polygons I'm just wondering how how similar yes like we all use the same uh Prime field like the Goldilocks okay uh but we don't use uh strike yet at the very end like for the last proof uh we also think of using F flunk like sdkvm at the moment but we don't use Starkey yet so is it more similar to the Hermes back-end stuff with the East Arc I think okay is it the same no e Stark No like we use uh basically from uh yeah the Winterfell I don't know okay uh that was what bobbin created okay like a sterilized stack Rover and it's pure Stark so far yeah so whereas there's a KVM yeah they have a spark at the end yeah but we don't have an end yet so maybe okay in the future yeah and then we use deep fry and uh oh yeah I can send you some documentation after that but I'm not sure if I can answer the questions on the VM yeah yeah thank you hey thank you so much for the talk I learned a lot I was just wondering if you have any um like special new security concerns now that the like the playground has widened significantly if there are any new dangers lurking in the dark um you mean security when you use yeah I'm I'm a whitehead so I just wanted to know like where where am I supposed to look or um yeah it would be interesting uh and maybe that goes too deep but uh yeah in Biden like as I said we store assets within the account so um that could be interesting I like how the attack vectors would look there if you don't have a global uc20 contract that can be hacked or any other Global Contract um and yeah obviously like we are too early in the process to answer that question I would say so at the moment we have the VM running and um it's optimized and we are building the roller like the client in the node but uh would be interesting to talk to you in August or so um when there's more more than just a theoretical idea on how to build uh smart contract and how they interact cool yeah are you planning on like launching a buck monkey program maybe on yes immunify or something definitely yeah like like the like polygon did for the ZK VM we will do the same our roadmap basically is in October you should be able to use it in December we hopefully have cool new apps that we can have a showcase and in end of March next year so uh we hope to have mainnet and also mainnet is not 100 certain if we will be a standalone roll-up or somehow integrate with the ckevm or the other polygon products okay so yeah that's all I wanted to know thanks um so did I get you right that um at the end there should be a centralized entity or whatever how you call it which summarized these transactions did I get that right now um at the beginning exactly like at the beginning we need like we also have a roll up with training wheels like the others and at the beginning we need to have a centralized operator also for debugging purposes but Maiden actually as I extended here is quite suitable to be decentralized like we need to think of a consensus mechanism obviously but we have a nice way to mitigate State load um and basically if we have more operators running then not every operator needs to know the full state and that could help to really decentralize it but to your question at the beginning it will be a centralized operator run by polygon labs and hopefully one year from minute launch we hope we go to uh commodity centralized settings so which means so at the beginning you have one centralized Authority and it might be two then four what most times as well there's no maybe you have a thousand or whatever but at the end it's not going to be like everyone so not like decentralized so we're just like use like it is a decentralized idea which you gave you but at the end it's not decentralized but like there's a set of centralized authorities yeah so at the end it's it makes not like that much that depends I guess how you would Define and that's a super interesting discussion indeed how do you find decentralization so it could be still decentralized if everyone can verify proofs and when you have these Escape patches on layer one but you're right so not every player or actor in mind is equal um so yeah but at least our clients can create their own proofs which is a good step forward but yes you're right so um yeah and then but this is I think really decentralized uh zero nurse roll up um at least when we go from the Mind design I will take at least two years or so too much I was just thinking about this as it relates to um what it might mean for cross Shard compost ability if that makes sense as it relates to having operators kind of take care of straight across different um users or different applications in some sense uh what would the idea then be that I mean what would you kind of think about introducing another fee Market essentially for um you know like operators to kind of share State and settle transactions across um you know like state that is that has kind of Uncharted that like I could not like we don't have this design yet uh with the decentralized operators and we don't have fees yet so um yeah but it's like something I guess we definitely need but I cannot unfortunately answer the question right now okay thank you very much thank you foreign
