> For the complete documentation index, see [llms.txt](https://calnix.gitbook.io/zk-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://calnix.gitbook.io/zk-notes/0xparc-zk-learning-group/zk-learning-group-2-trusted-setup-workshop.md).

# \[ZK Learning Group 2] Trusted setup workshop

### Background: Secure Multi-Party Computation

<figure><img src="https://1983523492-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0nwEx8a60yETwfNYnenT%2Fuploads%2Frb4Qegrg23MRSaIowlA0%2Fimage.png?alt=media&amp;token=b8583d7c-67c0-4d29-9714-f5e94c165025" alt=""><figcaption></figcaption></figure>

* Multiple people have different parts of the inputs
* They do not want to reveal their component of input
* But must come together to jointly compute f(x,y,z)

### Trusted Setup

The setup is a process where the CRS (Common Reference String) is generated, or more publicly known as the pair of proving and verification keys. **These “keys” are used by the prover and verifer to generate and verify proofs for a specific problem** (or constraint system), respectively.

In this process, there are random elements which are sampled and must be kept secret — if the prover knows them, they will be able to create proofs which are verified successfully, without using an actual solution to the problem during the proving process. In other words, to forge proofs and break soundness. This randomness is also known as “toxic waste”.\
\
There are ways to avoid this worry and not put trust in a single entity. For public circuits, these usually involve a Multi-Party Computation — a process in which multiple players donate their own randomness, which they destroy afterwards. **The interesting fact is that it’s enough that one player is honest and destroys their randomness for the whole process to be secure.**

{% hint style="info" %}
everyone in MPC contributes a shard that gets put together to form the CRS.
{% endhint %}

<figure><img src="https://1983523492-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0nwEx8a60yETwfNYnenT%2Fuploads%2Fyn7SrA1GfUOUPW1NMRgC%2Fimage.png?alt=media&amp;token=24ce363e-f98f-4abb-8493-cfe0313838cb" alt=""><figcaption></figcaption></figure>

### Trusted setup can be split into 2 phases:

1. Phase 1: Circuit agnostic
2. Phase 2: Circuit dependent

#### Trusted setup Phase 1: Powers of Tau

* Since circuit agnostic, or "common work", we can simply crowdsource the data in an on-going fashion, making it publicly available for anyone to use.
* <https://github.com/weijiekoh/perpetualpowersoftau>
* Anyone can use the contributions of powers of tau as phase 1 input to their circuit trusted setup.

{% hint style="info" %}
We need participants to be acting honestly in both phase 1 and 2. If we didn't then there would be no need to have MPC in phase 2.&#x20;
{% endhint %}

{% hint style="success" %}
PLONK and STARK do not require phase 2. Just need to do the phase 1 universal setup.
{% endhint %}

### Example

<figure><img src="https://1983523492-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0nwEx8a60yETwfNYnenT%2Fuploads%2FOKVGolzsTzslgRFVA4fD%2Fimage.png?alt=media&amp;token=1129ef2a-b60d-4c52-85e2-bedb39cf96d8" alt=""><figcaption><p><a href="https://youtu.be/83Jar98QbP4?si=SvJoP360zUCTdh74&#x26;t=983">https://youtu.be/83Jar98QbP4?si=SvJoP360zUCTdh74&#x26;t=983</a></p></figcaption></figure>
