Interactive laboratory · ES / EN

Ali Baba and zero-knowledge proofs

A bilingual lab exploring the cave, random challenges, cheating probability and hash commitments.

The cave, step by step

SECRETABEntrance

0rounds
0passed
0failed

What does each round demonstrate?

  1. The prover enters one branch without being seen by the verifier.
  2. The verifier randomly asks for exit A or B.
  3. With the secret, the door can be crossed; without it, success depends on chance.
  4. The verifier observes whether the prover comes out through the requested branch.
3.125%probability of passing all without knowing the secret
100%0020

P = (1/2)n. Assumes independent, unpredictable and equally likely challenges.

Hash commitments: a different experiment

Commit to a message with a random nonce, publish the hash and reveal the message to verify it. Commit–reveal reveals the message at the end: it is not a zero-knowledge proof.

The hash will appear here.

Learning by doing

Three challenges to understand ZKP.

Choose an answer and review the explanation. You can try again.

1. Which information must stay hidden?

2. How many rounds make P < 0.1%?

3. Is commit–reveal a ZKP?

These exercises assess understanding of the analogy; they do not certify a cryptographic proof.

ZKP · DeFi · zk-rollups

From the cave to an application.

Public statement

What we want to prove: for example, that a state transition follows a system’s rules.

Private witness

The data used to construct the proof, which may remain hidden depending on the protocol and published data.

Verification

The verifier checks the proof and statement. In a zk-rollup, a validity proof does not by itself imply privacy: the published data matters.

The cave provides an intuition. Real applications require formal systems, cryptographic assumptions and security proofs.

Reference: Ethereum · zk-rollups ↗

Continue to unit 05 · ES ↗

Study guide

From intuition to the concept.

Completeness, soundness and zero knowledge

Completeness: someone who knows the secret can answer correctly. Soundness: someone who does not know it has a limited probability of convincing the verifier. Zero knowledge: the verifier learns that the prover knows the secret, without learning the secret itself. The cave is a teaching analogy; a real ZKP requires a formal construction and proof of these properties.

Why is the initial path hidden?

If the verifier observes the initial path, they can learn whether the prover crossed the door. The full view shows internal information only to teach the mechanics; it does not represent the information available to the verifier.

Randomness, repetition and model limitations

Random bits are generated with Web Crypto. Each challenge has two equally likely outcomes. The formula (1/2)^n refers to passing all rounds of an independent experiment; it is not the success rate of one round and does not guarantee absolute security.

What a nonce adds to a commitment

A random 128-bit nonce makes it harder to test dictionary messages against the public hash. The input is encoded as a list containing a domain identifier, the message and the nonce; SHA-256 uses the complete input. Verification recomputes the hash with the revealed message and the same nonce. This exercise runs locally and does not save the message.