# Zk-rollups and a bit of zcash/zerocash history

**URL:** <https://forum.zcashcommunity.com/t/zk-rollups-and-a-bit-of-zcash-zerocash-history/37396>\
**Category:** General\
**Created:** [September 18, 2020, 2:03pm UTC](https://forum.zcashcommunity.com/t/zk-rollups-and-a-bit-of-zcash-zerocash-history/37396 "2020-09-18T14:03:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mistfpga](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/mistfpga/32/17700_2.png) [@mistfpga](https://forum.zcashcommunity.com/u/mistfpga)\
**Post date:** [September 18, 2020, 2:03pm UTC](https://forum.zcashcommunity.com/t/zk-rollups-and-a-bit-of-zcash-zerocash-history/37396/1 "2020-09-18T14:03:52Z")

</div>

Hi @Atam

Welcome to the forums and community 🙂

I have started a separate thread over here because I don’t really know what this means for the price, but I can help answer some of your other questions. Please feel free to ask more questions here or start a thread and I will do my best to answer you.

> [@Radical “to the moon” thread](https://forum.zcashcommunity.com/t/radical-to-the-moon-thread/32260/3474):
>
> When I read an article about zkRollup , zkSync , ZK- SNARK , always first thing that come to my mind is ECC and Zcash .

This makes me smile. Think zk think zcash. 😃 - you should, check the details at the end of the post for a whos who and the people involved.

[Medium article on zk-rollups](https://medium.com/ppio/zk-rollup-making-scalable-blockchains-possible-7308b695d929#:~:text=ZK%20Rollup%3A%20Making%20Scalable%20Blockchains%20Possible%201%20Principle.,...%206%20Current%20Application.%20...%207%20Summary.%20)

> [@](#):
>
> The essence of a ZK Rollup is to compress and store the user state on-chain in a Merkle tree, and transfer the state transition of the user states to the off-chain. At the same time, a zkSNARK proof is used to ensure the correctness of the off-chain state transition.

It says zkSNARK, then yep it is very likely either work done by the zcash community, whether a project recognises that is different, clones of clones of clones can forget what they have cloned. - It does not mean privacy though.

I am not sure if rollups are part of the zcash network, from what I read it would be more useful on networks that have smart contracts that want to do off chain work. it seems to be a bunch of t transactions wrapped into one big z transaction. I am not sure of the privacy implications, because im not really an Ethereum or smart contracts kind of person - but I dont think they are being used in a privacy context here. I could be wrong though.

I haven’t really looked into zk rollup, so others will probably have a more informed opinion. but they say they use zkSNARKS, so they very likely to be using zcash technology in some form, if not certainly the maths done buy the people i outline below.

Maybe someone else can answer more definitely as to what function they perform in regards to Eth. do they offer any form of privacy? or is it just for correctness.

[zcon1 eth zkrollup talk.](https://www.youtube.com/watch?v=QyM9qdFKsEA)

Ethereum and zcash are friends.

* * *

Here is a brief who’s who and what zk-snarks are.

Sorry if I am over simplifying things, I am trying to be thorough.

Hopefully this will show you how intertwined zk-snarks and zcash are. whilst they dont own the concept of zk or snarks, they are mathematical concepts, these are the people responsible for bringing them to crypto currencies.

the “ZK” used in ZK-SNARKS, and in cryptography in general references to the cryptographic concept of “Zero Knowledge Proofs”. Something the zcash team (and its predecessors) have successfully managed to integrate with blockchain technology

These have been around for quite a long time. - here is a reasonably good article on them.

- [Zero-knowledge proof - Wikipedia](https://en.wikipedia.org/wiki/Zero-knowledge_proof)

the “SNARK” is much more interesting for us and refers to “Succinct Non-interactive Argument of Knowledge”

Which are a form NIZK’s:

- [Non-interactive zero-knowledge proof - Wikipedia](https://en.wikipedia.org/wiki/Non-interactive_zero-knowledge_proof)

> [@Which have been a thing since about 1988](#):
>
> Non-interactive zero-knowledge proofs (NIZKs) are zero-knowledge proofs that require no interaction between the prover and verifier. Blum, Feldman, and Micali showed that a common reference string shared between the prover and the verifier is enough to achieve computational zero-knowledge without requiring interaction.  
> …  
> Non-interactive zero-knowledge proofs can also be obtained in the random oracle model using the Fiat–Shamir heuristic. The article[1] introduced the acronym zk-SNARK for zero-knowledge succinct non-interactive argument of knowledge that are the backbone of the Zcash protocol.

[1] - “Bitansky, Nir; Canetti, Ran; Chiesa, Alessandro”

SNARKs to the best of my knowledge were first implemented in crypto currencies in the zerocash protocol by “Eli Ben-Sasson, Alessandro Chiesa, Christina Garman, Matthew Green, Ian Miers, Eran Tromer, and Madars Virza”

I honestly dont know of Madars involvement with the ECC or zcash beyond zerocoin.

The others are zcash founding scientists. Ian Miers and Matthew Green are on the Zcash Foundation board of directors and Eran is a zcash foundation Alumni member. (You can find Ian and Eran posting on the forums, along with many ecc, zfnd and other key community members.)

> [@](#):
>
> For efficiency, however, Zerocash does not use “any” zero-knowledge proof, but leverages zero-knowledge Succinct Non-interactive ARguments of Knowledge (zk-SNARK) systems, which are zero-knowledge proofs that are particularly short and easy to verify.

Which gets its SNARKiness from work by

> [@](#):
>
> _Eli Ben-Sasson and Alessandro Chiesa and Eran Tromer and Madars Virza_
> 
> Abstract: We build a system that provides succinct non-interactive zero-knowledge proofs (zk-SNARKs) for program executions on a von Neumann RISC architecture. The system has two components: a cryptographic proof system for verifying satisfiability of arithmetic circuits, and a circuit generator to translate program executions to such circuits. Our design of both components improves in functionality and efficiency over prior work, as follows.

There are more people involved so sorry for not mentioning you (I know Aviel Rubin had involvement in zerocash but I cannot find reference to him for that or zcash. I am probably not looking hard enough.)

---

<div class="post-metadata">

**Author:** ![Atam](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Atam](https://forum.zcashcommunity.com/u/Atam)\
**Post date:** [September 23, 2020, 7:18am UTC](https://forum.zcashcommunity.com/t/zk-rollups-and-a-bit-of-zcash-zerocash-history/37396/2 "2020-09-23T07:18:41Z")

</div>

Thank you very very much for your detailed explanations. Your help is much appreciated and if i have some more questions, i will feel free to ask 🙂 .  
Thanks one more time!
