Grant Application - Research on a fully constant-time proving pipeline for open-source hardware wallet architectures, reusable for standard computers

Hey, folks!

Right now, as you may have observed, very few hardware wallets still maintain support for Zcash. Ledger recently started to add support for app-zcash ( GitHub - LedgerHQ/app-zcash · GitHub ), but as you will see in instances such as this, their PCZT parsers are still very constrained and circuit dependant, as you see they hardcoded the Orchard Action-1 spend circuit parsing in the firmware directly.

They are fundamentally geared towards providing support for so-called “cheap” signing operation such as for Transparent pools, and highly hesitate to parse circuits themselves, relying on pre-configured spend circuits that are very painful to upgrade if the network decides to add more features or types of transactions later. This is because if they just blindly signed a challenge scalar, they couldn’t ever verify it couldn’t be used by a malicious host, breaking the social contract of a wallet.

Even then, wallets such as Ledger further hesitate to just implement parsing of circuits because:

(a) it is expensive. Let’s face it, especially in Rust, recursion to be implemented in a small device with a 4 MB of SRAM is virtually infeasible.

(b) consequently, they have to rely on circuit-specific parsers and non-CT Rust algorithms, which exposes them to greater PR issues if a wallet were to be “hacked” later.

Hardware wallet manufacturers base their reputation on “nobody can steal anything”, and wallets such as Ledger especially pride themselves on having zero active zero-days at any given time. Doing complex calculations using code they cannot independently rewrite does not sit well with them.

Thus, this research grant proposal (Grant Application - Research on a fully CT proving pipeline for open-source hardware wallet architectures, reusable for standard computers · Issue #423 · ZcashCommunityGrants/zcashcommunitygrants · GitHub) aims to address that by hiring top-tier PhDs and researching mechanisms for hardware wallets to flexibly implement software in a way that it not brittle and much more secure, in languages more ambient to them (C and Rust), with minimal overhead.

We wish that via research conducted under this grant, more hardware wallet manufacturers become amicable to hosting Zcash on their platforms, and it may also enable Zcash to roll their own hardware wallets in the future.

We welcome questions!

3 Likes

Thank you for your proposal. After review by ZCG and a period for community input on the forum, the committee has decided not to fund this submission. We’re grateful for the effort you put into your application and hope you’ll remain an active part of the Zcash community. Meeting minutes.

1 Like