There is a problem classical cryptography never fully solved: how do you prove that you know something without revealing what it is? This is not about hiding a value behind a hashed password, but about convincing another party of your knowledge while the value stays encrypted end to end. Zero-knowledge proofs (ZKP) are the mechanism that makes it possible, and today they underpin everything from passwordless authentication to Ethereum rollups.
What “zero knowledge” means
The term was coined by Shafi Goldwasser, Silvio Micali and Charles Rackoff in 1985. It defines a protocol between two actors: the prover (who claims to know a secret) and the verifier (who checks it). The “zero knowledge” property demands three conditions: completeness (if the prover tells the truth, it always convinces), soundness (if it lies, it cannot convince except with negligible probability) and zero knowledge (the verifier learns nothing about the secret, only gains the certainty that the prover knows it).
The intuition: Ali Baba’s cave
The best-known explanation was popularised by Jean-Jacques Quisquater. Imagine a circular cave with two entrances and a passage blocked by a magic door at the far end; only whoever knows the secret word can open it. Peggy enters through one entrance and Victor asks her to come out through the other. If Peggy knows the word, she always appears on the right side. If not, she has a 50 % chance of guessing correctly. But if they repeat the experiment n times, the probability that Victor is fooled drops to 2-n: Peggy can convince him of her knowledge without ever saying the word.
From interactive theory to Schnorr’s protocol
The cave example is an interactive protocol: the verifier issues a random challenge and the prover responds. A practical cornerstone is the Schnorr identification protocol, built on discrete logarithms. The prover knows a private key x (an integer) and publishes y = gx mod p, where g is a generator and p a large prime. To prove it knows x: it picks a random value r and sends t = gr; the verifier replies with a challenge c; the prover returns z = r + c·x; the verifier checks that gz = t · yc. An impostor who does not know x can only answer correctly by committing to the challenge in advance, which a well-designed protocol prevents.
The Fiat-Shamir transformation: no dialogue needed
A dialogue requires both parties to be connected. To publish a proof in a file, the interaction must go away. The Fiat-Shamir transformation replaces the verifier’s random challenge with the output of a hash function over the messages already emitted: c = Hash(t, context). Anyone reading the proof can then recreate the challenge and verify it in a non-interactive way, ideal for digital signatures and blockchains.
zk-SNARKs: proofs that fit in a transaction
The leap to zk-SNARKs (zero-knowledge Succinct Non-interactive ARguments of Knowledge) adds two properties: they are succinct (the proof occupies a fixed, small size) and instantly verifiable. Their architecture has three pieces. First, the computation is translated into an R1CS (system of Rank-1 Constraint Satisfaction), a set of linear equations representing the program’s circuit. Then a polynomial system called QAP (Quadratic Arithmetic Program) condenses those constraints into two polynomials that must coincide at certain points. Finally, a polynomial commitment (for instance, on elliptic curves or via the KZG commitment scheme) lets the prover demonstrate knowledge of those polynomials without revealing them. The verifier only evaluates a few pairing operations, independent of the size of the computation.
zk-STARKs: no trusted setup required
zk-STARKs (zero-knowledge Scalable Transparent ARguments of Knowledge) avoid a limitation of SNARKs: the trusted setup ceremony, in which parameters are generated that, if they fall into the wrong hands, would break security. STARKs rely on hash functions and finite-field extensions rather than elliptic curves, and offer larger proofs but full transparency (no setup) and resistance to quantum computers. Their flexibility makes them attractive on high-volume blockchains.
Where they stand today
ZKPs are no longer theory. You use them in passwordless sign-in when webAuthn and certain credential managers prove possession of a key without sending it. They appear in age verification that proves you are above a threshold without revealing your birth date, and in payments with privacy coins that hide the amount and the sender. Their most visible application is Ethereum layer-2 rollups: millions of transactions are processed off-chain, condensed into a single validity proof and published on the mainnet, which only has to verify one cryptographic operation instead of re-executing everything.
The cost of the magic
So much elegance has its price. Generating a proof demands a re-execution of the computation and considerable memory: SNARKs over large circuits can take minutes or even hours to compute, although they are later verified in milliseconds. The trusted setup and mathematical hardness assumptions (discrete-log hardness, bilinear pairings) are delicate points that the community audits relentlessly. Even so, more and more financial, identity and decentralised-storage systems choose to bet on proving less and, precisely for that reason, earning more trust.





