Public statement
What we want to prove: for example, that a state transition follows a system’s rules.
Interactive laboratory · ES / EN
A bilingual lab exploring the cave, random challenges, cheating probability and hash commitments.
P = (1/2)n. Assumes independent, unpredictable and equally likely challenges.
Commit to a message with a random nonce, publish the hash and reveal the message to verify it. Commit–reveal reveals the message at the end: it is not a zero-knowledge proof.
Learning by doing
Choose an answer and review the explanation. You can try again.
These exercises assess understanding of the analogy; they do not certify a cryptographic proof.
ZKP · DeFi · zk-rollups
What we want to prove: for example, that a state transition follows a system’s rules.
The data used to construct the proof, which may remain hidden depending on the protocol and published data.
The verifier checks the proof and statement. In a zk-rollup, a validity proof does not by itself imply privacy: the published data matters.
The cave provides an intuition. Real applications require formal systems, cryptographic assumptions and security proofs.
Continue to unit 05 · ES ↗Study guide
Completeness: someone who knows the secret can answer correctly. Soundness: someone who does not know it has a limited probability of convincing the verifier. Zero knowledge: the verifier learns that the prover knows the secret, without learning the secret itself. The cave is a teaching analogy; a real ZKP requires a formal construction and proof of these properties.
If the verifier observes the initial path, they can learn whether the prover crossed the door. The full view shows internal information only to teach the mechanics; it does not represent the information available to the verifier.
Random bits are generated with Web Crypto. Each challenge has two equally likely outcomes. The formula (1/2)^n refers to passing all rounds of an independent experiment; it is not the success rate of one round and does not guarantee absolute security.
A random 128-bit nonce makes it harder to test dictionary messages against the public hash. The input is encoded as a list containing a domain identifier, the message and the nonce; SHA-256 uses the complete input. Verification recomputes the hash with the revealed message and the same nonce. This exercise runs locally and does not save the message.