ethereum/kzg-ceremony

Resources and documentation related to the ongoing Ethereum KZG Ceremony.

829

stars

106

commits

Jan 19, 2024

updated

README

Summary

The KZG Ceremony is a coordinated public ritual which will provide a cryptographic foundation for Ethereum scaling initiatives. From the specs repo:

The ceremony takes place between participants and the sequencer. Participants are the entities that contribute their secret randomness to the final output 𝜏 s. The role of the sequencer is to act as the common point of interaction for all participants as well as verifying participants' contribution as the ceremony progresses.

The ceremony is designed to have the following characteristics:

  • wide ecosystem participation
  • browser accessible
  • a meaningful narrative in a simple interface
  • easy to audit transcript

The best place to follow along is the KZG Ceremony channel in the Ethereum R&D Discord or the bridged telegram channel - DM one of the contributors to be added to either.

Resources

Audits

Client Implementations

There are a number of independent implementations interested Ceremony participants can try to run locally, will have a variety of different features. (no guarantees on the quality or completeness!)

CLI Interfaces

ImplementationBLS LibraryLanguageLicenseAuthorNotes
Chottoblst (jblst)JavaApache 2.0Stefan Bratanov (@StefanBratanov)
go-kzg-ceremony-clientgnark-cryptoGoMITIgnacio Hagopian (@jsign)Features: transcript verification, using additional external sources of entropy, eg. drand network, an arbitrary URL provided by the user. Note: double signing not supported due to lack of hash-to-curve in gnark.
eth-KZG-ceremony-altkilicGoGPL-3.0Arnaucube (@arnaucube)
Towers of PaublstGoMITDaniel Knopik (@dknopik), Marius van der Wijden (@MariusVanDerWijden)Linux only, no signatures.
cpp-kzg-ceremony-clientblstC++AGPL-3.0Patrice Vignola (@PatriceVignola)Features: BLS/ECDSA signing, transcript verification, Linux/Windows/MacOS support
czg-keremonynoble-curvesJavaScriptMITJoonKyo Kim (@rootwarp), HyungGi Kim (@kim201212)
kzg-ceremony-clientblstC#MITAlexey (@flcl42), CheeChyuan (@chee-chyuan), Michal (@mpzajac), Jorge (@jmederosalvarado), Prince (@prix0007)

Browser Interfaces

InterfaceBLS LibraryLicenseAuthorIPFSRepositoryNotes
ZKParty FrontendArkworksSeverallatest.kzgceremony.ethtrusted-setup-frontendReferences the latest version of the interface, which departs from the audited version in minor ways
ZKParty Frontend (Audit Commit)ArkworksSeveral[1] audit.kzgceremony.ethtrusted-setup-frontendThe exact interface which Sigma Prime audited in November 2022. May have minor bugs or differences from the latest version above. docker instructions
Doge KZGgnarkMITAndrew Davis (@Savid)[2]dogekzg🐶
  1. audit: QmevfvaP3nR5iMncWKa55B2f5mUgTAw9oDjFovD3XNrJTV
  2. doge: QmRs83zAU1hEnPHeeSKBUa58kLiWiwkjG3rJCmB8ViTcSU

BLS Libraries

LibraryLanguageLicenseAudit
blstC & assemblyApache 2.0Audit Report, [WIP] Formal Verification
ArkworksRustApache 2.0, MIT
gnark-cryptoGo & assemblyApache 2.0Audit Report
kilicGoApache 2.0
Herumi BLSC++ & assemblymodified BSDTechnical Assessment
ConstantineNimApache 2.0
py_eccPythonMIT
matterlabs/EIP1962RustApache 2.0
noble-curvesTypeScript/JSMIT

Special Contributions

April 1-16 2023 was the Special Contribution Period for the KZG Ceremony. This allowed participants to contribute in ways that may not have been possible in the Open Contribution period.

While the Ceremony only needs a single honest participant to provide a secure output, Special Contributions provide additional assurances beyond a standard entropy contribution:

  • computing over the entropy in an isolated environment (eg. on an airgapped machine, wiping and physically destroying hardware) means it's unlikely for a malicious entity to have extracted the entropy at any point
  • detailed documentation (explore links below) attached to real reputations are unlikely to all have been coopted or faked by a malicious coordinating entity. The records are available for future observers to explore.
  • different hardware and software limits correlated risk
  • differentiated entropy generation (eg. measuring an explosion) prevents the Ceremony output being compromised by some failure in the regular entropy generation (eg. the hosted interface)
  • contributions involving large groups of people are harder to fake than those with only one person

This post is a public record of the Special Contributions with information on methodology, where to find them in the transcript, and links to documenting media.

Media

TitleVenueParticipantsRelease Date
KZG Ceremony Duo Summons The Ethereum Road MapThe DefiantTegan Kline, Carl Beekhuizen, Trent Van EppsApril 2023
Episode 262: Ethereum’s KZG Ceremony with Trent & CarlZero KnowledgeAnna Rose, Kobi Gurkan, Carl Beekhuizen, Trent Van EppsFeb 2023
Ethereum's KZG CeremonyBanklessDavid Hoffman, Trent Van Epps, Carl BeekhuizenJan 2023
Peep an EIP - KZG CeremonyEthCatHerdersPooja Ranjan, Carl BeekhuizenJan 2023
Ethereum Foundation – EIP-4844 & KZG CeremonyEpicenterFriederike Ernst, Trent Van Epps, Carl BeekhuizenJan 2023
Building the KZG CeremonyPSE Learn and ShareNico Serrano, Geoff LamperdDec 2022
The KZG Ceremony - or How I Learnt to Stop Worrying and Love Trusted SetupsDevconCarl BeekhuizenOct 2022

Public Calls

Call #LinkDate
1Agenda/RecordingJune 9 2022
2Agenda/RecordingJune 23 2022
3Agenda/RecordingJuly 7 2022
4Agenda/RecordingJuly 21 2022
5Agenda/RecordingAug 4 2022
6Agenda/RecordingAug 18 2022
7Agenda/RecordingSept 1 2022
8Agenda/RecordingSept 15 2022
9Agenda/RecordingSept 29 2022

Contributors

tvanepps

70 commits

CarlBeek

28 commits

NicoSerranoP

2 commits

ethereum/kzg-ceremony

Resources and documentation related to the ongoing Ethereum KZG Ceremony.

829

stars

106

commits

Jan 19, 2024

updated

README

Summary

The KZG Ceremony is a coordinated public ritual which will provide a cryptographic foundation for Ethereum scaling initiatives. From the specs repo:

The ceremony takes place between participants and the sequencer. Participants are the entities that contribute their secret randomness to the final output 𝜏 s. The role of the sequencer is to act as the common point of interaction for all participants as well as verifying participants' contribution as the ceremony progresses.

The ceremony is designed to have the following characteristics:

  • wide ecosystem participation
  • browser accessible
  • a meaningful narrative in a simple interface
  • easy to audit transcript

The best place to follow along is the KZG Ceremony channel in the Ethereum R&D Discord or the bridged telegram channel - DM one of the contributors to be added to either.

Resources

Audits

Client Implementations

There are a number of independent implementations interested Ceremony participants can try to run locally, will have a variety of different features. (no guarantees on the quality or completeness!)

CLI Interfaces

ImplementationBLS LibraryLanguageLicenseAuthorNotes
Chottoblst (jblst)JavaApache 2.0Stefan Bratanov (@StefanBratanov)
go-kzg-ceremony-clientgnark-cryptoGoMITIgnacio Hagopian (@jsign)Features: transcript verification, using additional external sources of entropy, eg. drand network, an arbitrary URL provided by the user. Note: double signing not supported due to lack of hash-to-curve in gnark.
eth-KZG-ceremony-altkilicGoGPL-3.0Arnaucube (@arnaucube)
Towers of PaublstGoMITDaniel Knopik (@dknopik), Marius van der Wijden (@MariusVanDerWijden)Linux only, no signatures.
cpp-kzg-ceremony-clientblstC++AGPL-3.0Patrice Vignola (@PatriceVignola)Features: BLS/ECDSA signing, transcript verification, Linux/Windows/MacOS support
czg-keremonynoble-curvesJavaScriptMITJoonKyo Kim (@rootwarp), HyungGi Kim (@kim201212)
kzg-ceremony-clientblstC#MITAlexey (@flcl42), CheeChyuan (@chee-chyuan), Michal (@mpzajac), Jorge (@jmederosalvarado), Prince (@prix0007)

Browser Interfaces

InterfaceBLS LibraryLicenseAuthorIPFSRepositoryNotes
ZKParty FrontendArkworksSeverallatest.kzgceremony.ethtrusted-setup-frontendReferences the latest version of the interface, which departs from the audited version in minor ways
ZKParty Frontend (Audit Commit)ArkworksSeveral[1] audit.kzgceremony.ethtrusted-setup-frontendThe exact interface which Sigma Prime audited in November 2022. May have minor bugs or differences from the latest version above. docker instructions
Doge KZGgnarkMITAndrew Davis (@Savid)[2]dogekzg🐶
  1. audit: QmevfvaP3nR5iMncWKa55B2f5mUgTAw9oDjFovD3XNrJTV
  2. doge: QmRs83zAU1hEnPHeeSKBUa58kLiWiwkjG3rJCmB8ViTcSU

BLS Libraries

LibraryLanguageLicenseAudit
blstC & assemblyApache 2.0Audit Report, [WIP] Formal Verification
ArkworksRustApache 2.0, MIT
gnark-cryptoGo & assemblyApache 2.0Audit Report
kilicGoApache 2.0
Herumi BLSC++ & assemblymodified BSDTechnical Assessment
ConstantineNimApache 2.0
py_eccPythonMIT
matterlabs/EIP1962RustApache 2.0
noble-curvesTypeScript/JSMIT

Special Contributions

April 1-16 2023 was the Special Contribution Period for the KZG Ceremony. This allowed participants to contribute in ways that may not have been possible in the Open Contribution period.

While the Ceremony only needs a single honest participant to provide a secure output, Special Contributions provide additional assurances beyond a standard entropy contribution:

  • computing over the entropy in an isolated environment (eg. on an airgapped machine, wiping and physically destroying hardware) means it's unlikely for a malicious entity to have extracted the entropy at any point
  • detailed documentation (explore links below) attached to real reputations are unlikely to all have been coopted or faked by a malicious coordinating entity. The records are available for future observers to explore.
  • different hardware and software limits correlated risk
  • differentiated entropy generation (eg. measuring an explosion) prevents the Ceremony output being compromised by some failure in the regular entropy generation (eg. the hosted interface)
  • contributions involving large groups of people are harder to fake than those with only one person

This post is a public record of the Special Contributions with information on methodology, where to find them in the transcript, and links to documenting media.

Media

TitleVenueParticipantsRelease Date
KZG Ceremony Duo Summons The Ethereum Road MapThe DefiantTegan Kline, Carl Beekhuizen, Trent Van EppsApril 2023
Episode 262: Ethereum’s KZG Ceremony with Trent & CarlZero KnowledgeAnna Rose, Kobi Gurkan, Carl Beekhuizen, Trent Van EppsFeb 2023
Ethereum's KZG CeremonyBanklessDavid Hoffman, Trent Van Epps, Carl BeekhuizenJan 2023
Peep an EIP - KZG CeremonyEthCatHerdersPooja Ranjan, Carl BeekhuizenJan 2023
Ethereum Foundation – EIP-4844 & KZG CeremonyEpicenterFriederike Ernst, Trent Van Epps, Carl BeekhuizenJan 2023
Building the KZG CeremonyPSE Learn and ShareNico Serrano, Geoff LamperdDec 2022
The KZG Ceremony - or How I Learnt to Stop Worrying and Love Trusted SetupsDevconCarl BeekhuizenOct 2022

Public Calls

Call #LinkDate
1Agenda/RecordingJune 9 2022
2Agenda/RecordingJune 23 2022
3Agenda/RecordingJuly 7 2022
4Agenda/RecordingJuly 21 2022
5Agenda/RecordingAug 4 2022
6Agenda/RecordingAug 18 2022
7Agenda/RecordingSept 1 2022
8Agenda/RecordingSept 15 2022
9Agenda/RecordingSept 29 2022

Contributors

tvanepps

70 commits

CarlBeek

28 commits

NicoSerranoP

2 commits