Skip to content

🥷 Version 0.6.2: Add ZK-STARK section - #49

Open
DarkWindman wants to merge 9 commits into
BlockstreamResearch:mainfrom
DarkWindman:stark-section
Open

DarkWindman wants to merge 9 commits into
BlockstreamResearch:mainfrom
DarkWindman:stark-section

Conversation

@DarkWindman

@DarkWindman DarkWindman commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Objective

This PR adds ZK-STARKs to the book. Specifically, we include

  • Linear error-correction codes
  • Reed-Solomon codes
  • IOPP
  • FRI
  • AIR

Comment thread contents/3-zk-foundations/9-stark.tex Outdated

\begin{document}

In previous schemes, the verifier relied on algebraic structures: pairings in KZG, and group homomorphisms in Pedersen commitments. Here, we rely on nothing but hash functions. We need to verify that a committed function is a low-degree polynomial by examining only a few of its evaluations. Verifying this directly is impossible: the function could perfectly match a polynomial everywhere except at a single, unchecked point.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need to verify that a committed function is a low-degree polynomial by examining only a few of its evaluations

Why do we even care about this and how that is related to hash functions ?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I guess a reader would need some example which problem we try to solve (e.g. see or this more classical example with Fibonacci series).

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We discussed that with @DarkWindman and came to the same conclusion. The section will have more example and exercise blocks soon; the current version in non-finalized.

The Fibonacci example is nice and we will likely include it; the only problem is that this resource is too high-level, so we'll make sure to make it more rigor and suitable for our formalization.

Comment thread contents/3-zk-foundations/9-stark.tex Outdated
\end{equation*}
This representation admits non-determinism: the verification polynomials may have much lower degree than any polynomial that computes the next state. For instance, the transition $y = x^{-1}$ requires computing $x^{q-2}$, but it is verified by the degree-$2$ polynomial $xy - 1$.

\subsubsection{Trace interpolation}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again, we need an example. Perhaps show how the mentioned before Fibonacci evaluation is encoded in AIR

A non-zero polynomial $f \in \mathbb{F}[T]$ of degree $d$ has at most $d$ roots in $\mathbb{F}$.
\end{corollary}

Also, this might not be immediately obvious, but we can also divide polynomials in the same way as we divide integers. The result of division is not always a polynomial, so we also get a remainder.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

By the way this sentence sounds cringy 🥲

Comment thread contents/3-zk-foundations/9-stark.tex Outdated
Comment on lines +9 to +13
\subsection{Linear Codes}
%--------------------------------
\begin{intuition}
Suppose the sender wants to send a message $m$ over a noisy channel. The sender first uses an encoding function to map the $k$ message symbols into $n$ symbols, called a \emph{codeword}, and then sends it over the channel. The receiver gets a \emph{received word} of $n$ symbols and tries to decode it, recovering the original $k$ message symbols.
\end{intuition}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we need a more gentle introduction. For instance, historically, why do we even care about error-correction codes (ECC) and what they achieve. What constructions can be built using ECC. Why do they matter in ZK?

Comment thread contents/3-zk-foundations/9-stark.tex Outdated
\end{intuition}

\begin{definition}[Code]\label{def:code}
A \emph{code} of block length $n$ over an alphabet $\Sigma$ is a subset $C \subseteq \Sigma^n$, whose elements are called \emph{codewords}. We write $M := |C|$ for the number of codewords and $k := \log_{|\Sigma|} M$ for the number of message symbols. An \emph{encoding} for $C$ is an injective map $E : \Sigma^k \to \Sigma^n$ whose image is $C$.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again, everything is quite sudden. What is alphabet? Why do we need an encoding function? (answer: we want to extend the length of an input to add some additional redundant information such as parity bits, for example).

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Take a look at these lectures to get some intuition: https://www.canal-u.tv/chaines/inria/1-error-correcting-codes-and-cryptography

Comment thread contents/3-zk-foundations/9-stark.tex Outdated
\end{equation*}
\end{definition}

While comparing individual vectors is helpful, a code's effectiveness depends on the entire set. Specifically, we care about the distance between codewords, where the worst-case spacing between any two codewords is the defining metric.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"is the defining metric" sounds AI-ish :)

Comment thread contents/3-zk-foundations/9-stark.tex Outdated
and the \emph{relative minimum distance} of $C$ is $\mu(C) := \frac{1}{n} d_{\min}(C)$.
\end{definition}

The minimum distance is the foundation of error correction. If $d_{\min}(C) = d$, introducing fewer than $d$ errors will never result in another valid codeword. Furthermore, with fewer than $d/2$ errors, the corrupted string remains strictly closer to the original codeword than to any other. Essentially, a larger minimum distance forces codewords further apart, so the original codeword can be recovered as long as fewer than $d/2$ errors occur.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Some illustration would be nice

Comment thread contents/3-zk-foundations/9-stark.tex Outdated
\end{equation*}
from the codeword for $f(T)$.

Let $D$ be a subgroup of even order $n$ of the multiplicative group of the field, and let $\omega$ be a generator of this subgroup. Let $\{f(\omega^i)\}_{i=0}^{n-1}$ be the codeword for $f(T)$, corresponding to evaluation on $D$. Let $D^\star=\langle \omega^2\rangle$ be another domain of half the length, and let $\{f_E(\omega^{2i})\}_{i=0}^{n/2-1}$, $\{f_O(\omega^{2i})\}_{i=0}^{n/2-1}$ and $\{f^\star(\omega^{2i})\}_{i=0}^{n/2-1}$ be the codewords for $f_E(T)$, $f_O(T)$ and $f^\star(T)$, respectively, corresponding to evaluation on $D^\star$. As a result, we can rewrite the definition of $f^\star(T)$:

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just say that $D = \langle \omega \rangle$ where $\omega$ is a $2^t$-th root of unity :)
The reader already knows this machinery from the NTT section

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Additionally, I don't like notation $\{\cdot\}_{i=0}^{n-1}$. Write $i \in [n]$.

Comment thread contents/3-zk-foundations/9-stark.tex Outdated
\begin{definition}[FRI protocol]\label{def:fri}
Let $f_0 := f$ be given on $D_0 := D = \langle \omega \rangle$ of order $n$, with $\deg f < k = 2^r$.
\begin{itemize}
\item \textbf{Commit phase.} For $i = 0, 1, \ldots, r-1$:

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

$i \in [r]$

Comment thread contents/3-zk-foundations/9-stark.tex Outdated
\begin{itemize}
\item \textbf{Commit phase.} For $i = 0, 1, \ldots, r-1$:
\begin{algoen}
\item the prover sends the Merkle root of the codeword of $f_i$ on $D_i$;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is $D_i$? $\langle \omega^{2^i} \rangle$?

Comment thread contents/3-zk-foundations/9-stark.tex Outdated
transformation (\Cref{subsection:fiat-shamir}): each challenge $\beta_i$ and each starting point $x_0$
is derived by hashing the Merkle roots sent so far.
\end{remark}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As of now, I don't understand why I need to even verify $\delta$-proximity of some polynomial to some particular code. The section does not give any intuition or foreshadowing when this becomes useful.

Additionally, as I've written above, we need definitions of IOPP (e.g., because it is not clear what security notions FRI should satisfy in the first place).

Comment thread contents/3-zk-foundations/9-stark.tex Outdated
Comment on lines +371 to +373
\begin{definition}\label{def:aet}
Let $\mathbb{F}_q$ be the field of definition, and the computation describes the evolution of a state of $w$ registers for $\tau$ cycles. Then we define the \emph{algebraic execution trace (AET)} is the table of $\tau \times w$ field elements where every row describes the state of the system at the given point in time, and every column tracks the value of the given register.
\end{definition}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I am already lost here. I think since you are planning to rework this section, I will review it later

@ZamDimon ZamDimon added the new-lecture New feature or request label Oct 1, 2026
@ZamDimon ZamDimon changed the title Add ZK STARK section 🥷 Add ZK-STARK section Oct 1, 2026
@ZamDimon ZamDimon changed the title 🥷 Add ZK-STARK section 🥷 Version 0.6.2: Add ZK-STARK section Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new-lecture New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants