Home / Software y Cloud / Prove without revealing: how a zero-knowledge proof works

Prove without revealing: how a zero-knowledge proof works

A zero-knowledge proof is a cryptographic protocol with an almost paradoxical promise: proving to another party that a statement is true without revealing anything beyond the truth itself. This is not about hiding “a little” information, but about the verifier learning exactly zero new knowledge other than the fact that your claim is valid.

Such a proof is defined by three properties. Completeness: if the statement is true, an honest prover can always convince the verifier. Soundness: if the statement is false, no dishonest prover can forge a convincing proof except with negligible probability. Zero knowledge: everything the verifier observes during the proof can be simulated by the verifier himself without knowing the secret, so the interaction leaks not a single useful bit.

The thought experiment of the enchanted cave

The intuition comes from the classic Quisquater’s cave example, a circular passage with a sealed door inside that only opens by uttering a magic word. Peggy enters and randomly goes left or right; Victor, from outside, calls out which corridor she must exit from. If the magic word exists, Peggy can always leave through the requested path. If it does not, she only guesses right half the time. Repeating the round, the probability that an impostor gets lucky falls exponentially: after a few rounds, if Peggy always exits through the requested path, it is practically impossible that she does not know the word. Yet Victor never hears it. That is the “zero knowledge”: the proof convinces without transmitting the secret.

From abstraction to paper: Schnorr and Fiat-Shamir

The mathematics behind it is the discrete logarithm over a cyclic group. Suppose you know a secret s and publish the value S = g^s, where g is a generator of the group. Proving you know s without revealing it is done through what is known as the Schnorr protocol: you send a commitment to a random value (for example an r chosen on the fly), the verifier issues a random challenge e, and you reply with the mathematical relationship that combines both. The verifier checks the resulting equation. By the properties of the group, anyone who has seen s can generate that response, but the secret cannot be extracted from the response without solving the discrete logarithm, a problem considered intractable in well-chosen groups.

This protocol is interactive: prover and verifier exchange several messages. To turn it into something verifiable in a single pass, the Fiat-Shamir heuristic is applied: the random challenge is computed by the prover himself from the commitment using a cryptographic hash function instead of asking the verifier. This transforms the proof into a non-interactive one (a single self-contained message) and opens the door to signing, publishing, and storing it.

From classical protocols to zk-SNARKs

Classical protocols prove very small statements, such as “I know a secret”. To prove more complex claims, zk-SNARKs (zero-knowledge succinct non-interactive arguments of knowledge) rewrite the problem as an arithmetic circuit: a series of addition and multiplication operations over a finite field that represent the computation you want to validate. Proving that “you ran a program correctly” is equivalent to proving that there exists an assignment of values satisfying every equation of the circuit, which can be reduced to checking identities between polynomials.

The key to “succinctness” is that the final proof is tiny and verifies in an instant, whatever the underlying computation does. This is achieved with polynomial commitment schemes, such as KZG, based on bilinear pairings over pairing-friendly elliptic curves; the verifier performs only a few operations on the commitments, not over the whole circuit. Many schemes additionally require a “trusted setup ceremony”: a unique, reliable phase in which protocol parameters are generated and which, if ever destroyed or leaked, would put the soundness of the proof at risk.

zk-STARKs and the great technology race

Compared with SNARKs, zk-STARKs (scalable transparent arguments of knowledge) drop the trusted setup by using standard hash functions, at the cost of larger proofs (in the order of hundreds of kilobytes) and heavier prover computation. In exchange they are transparent, more resistant to quantum computers, and easy to make error-proof in code. Out of this family come zk-VMs (zero-knowledge virtual machines, such as RISC Zero or StarkWare’s zkVM), which run arbitrary code and produce a proof of its integrity. Proving usually costs two to three orders of magnitude more than simply executing the program; that is why research focuses on accelerating the prover step.

Why it matters beyond academia

The technology is already in production. On Ethereum, layer-2 rollups (such as ZK-Rollups) batch thousands of transactions, execute their computation off-chain, and publish a single zero-knowledge proof that the network verifies in seconds, multiplying throughput without sacrificing security. In financial privacy, the Zcash network uses zk-SNARKs to support “shielded” transactions in which amounts and addresses remain encrypted yet validity is cryptographically proven. Increasingly, zero-knowledge proofs underpin identity verification without exposing data (proving you are of legal age without revealing your date of birth), digital credentials, and pseudonymous reputation systems.

The takeaway is counterintuitive but powerful: sometimes the strongest way to assert something is to show nothing. Cryptography has learned to prove facts without handing over proof material, and that is one of the ideas reshaping how privacy, scale, and trust are verified in the digital world.