• Buy Crypto
  • Trade
  • Services
  • Travel
  • Banking
  • Business
  • Resources
Sign In
Register
Blog AlfaBit

What are ZK-Rollups

7 March 2024 г.

What are ZK-Rollups

The blockchain nets encounter a scalability dilemma, which is the inability to achieve three characteristics at once: security, decentralization, and large bandwidth. But second-level designs are promising solutions to improve blockchain scalability.


Second-level blockchains are becoming increasingly diverse: ZK roll-ups have become a distinct technology stack, along with optimistic rollups, Arbitrum, Validium, Plasma and Optimum solutions.


In this article, we’ll look at ZK roll-ups, which are second-level roll-ups that make use of a type of proof with zero disclosure («zero-knowledge proofs» or ZKPs).


What are ZK roll-ups?

ZK roll-ups are a second-level zoom decision that improves the speed of transaction processing. Transactions are processed outside of the main blockchain (off chain), but transaction data is written to the main blockchain (on chain). ZK roll-ups employ zero-knowledge proof-of-stake to ensure the validity of such operations by disclosing no private data.


As of the end of 2023, there are 11 actively operating ZK roll-ups that have a combined value of blockchain assets (TVL) of more than $1 billion. Some of the most popular solutions of this kind include zkSync, dYdX, and Starknet.


Core features of ZK roll-ups

The hallmarks of ZK roll-ups are evidence of validity and availability of data in the chain.


Validity proofs

Proofs of validity are checks performed by means of a zero-reveal proof. It is a verification cryptography proof that enables you to quickly validate the result of a calculation while not disclosing particular pieces of data about that calculation. There are different kinds of such proves, among them ZK-SNARK as well as ZK-STARK.


In-chain data availability

Although transactions are processed outside the basic chain of blocks, ZK roll-ups verify that certain sensitive data fragments are held on the basic unit or blockchain (the first-layer).


This storage model is the key to the consensus engine and renders ZK roll-ups storage packages universal. With this model, everyone can independently verify all transactions in the aggregate. The model is in fact one that is also even compliant with the Ethereum Virtual Machine (EVM), allowing it to be able to sustain a broad range of apps.


In what ways do ZK roll-ups provide increased blockchain scalability?

Unlike Plasma and Validium, storage packets (both ZK and optimistic) don’t fully implement second-level scaling. In particular, accumulation packets do not provide 100% off-network data store. Rather, they simply shift the status store and calculations outside the blockchain. Therefore, the rollup solution is limited by the data throughput of the underlying blockchain.


Even still, accumulation packets constitute a major advance over the base layer. For example, it takes 45 000 gas units (gwei) to endorse an ERC-20 token on Ethereum, whereas most rollups require less than 300 gwei for the same transaction.


In addition, rollup also compresses transaction details. Generally, Ethereum transfers require approximately 110 bytes, whereas using a roll-up allows for only 12 bytes. Compressing the caption offers the highest reduction in size. In ETH, the caption occupies about 68 bytes. Roll-up can group about a hundred operations together under one caption, decreasing the file size by up to 0,5 bytes.


Increased safety

The most important feature of ZK storage packages is the safety warranty, according to which the customer is always able to return the asset to first-layer. This is essential as other second-layer decisions don’t provide such a security assurance. In the case of Validium, for example, it’s possible to lose assets in the event of a failure of dataset accessibility.


ZK roll-ups don’t face any data availability issues, which means that attackers can’t cause significant impact. Furthermore, the affordability of data eliminates the need to match assets to owners. This is the biggest advantage of roll-ups compared to any other second-layer decision.


What is the way ZK roll-ups work?

ZK roll-ups operate via smart contracts within the first-layer of the blockchain. Smart contracts make a difference because they support records known as the condition value root.


Condition root

The condition root represents a Merkle tree consisting of packets of information about accounts, balances, and the rollup contract code. Users publish new packets (compressed transaction sets) with the oldest and newest condition roots. Then, the smart contract compares the oldest condition root against the currently posted root. When the two match, the current version switches to the newly published condition root.


Fund deposits and outputs

Of course, to enable deposits and withdrawals, roll-ups must allow «outside» input and output. A transaction that sends a packet containing «external» entry data also shifts holdings in a smart contract. Once an operation sends a packet containing «external» outputs, the contract initiates an output process. Accordingly, the underlying smart contract keeps status updates at the underlying and in the merge in sync.


Checking the post-state

How to test the correct post-state of the root? Previously, an attacker could provide any version of the root state. However, accumulation packets address this problem in two different ways: proof of validity and proof of fraud. Thus, we have two schemes: zero-disclosure and optimistic roll-ups.


ZK roll-ups rely on proofs of trustworthiness to ensure that there is no manipulation in the post-state of the root. For this reason, each new batch of transactions is accompanied by a ZK-SNARK (or ZK-STARK), a knowledge argument that confirms that the packet calculation actually yields the exact same output as the newly generated condition root. Most importantly: even the most complex computations can be quickly verified in the chain thanks to the very sophisticated mathematics behind the ZK proofs.


Let’s compare ZK roll-ups and optimistic roll-ups

Core analogy: both zero-knowledge roll-ups and optimistic roll-ups hold a portion of the on chain data.


Difference: zero-knowledge roll-ups utilize proof of authenticity, whereas optimistic roll-ups utilize proof of scam.


Validation-only data: with ZK-SNARK, zero-knowledge roll-ups remove the necessity of storing validation-only data on the blockchain, unlike optimistic roll-ups that need such data for checking for scams.


In zero-knowledge roll-ups, info that is important for verification only doesn’t need to be stored in the blockchain because the zero-knowledge proof is implicit in proving that all required verification data has been submitted. By contrast, scam proofs utilized in optimistic roll-ups verify operations ex post facto and require additional information. Thus, optimistic roll-ups hold all verification details on the blockchain, regardless of the status of the dispute.


Privacy preservation: ZK roll-ups keep more details of trades offline (off chain), making them a more effective privacy preservation tool. In a confidentiality-preserving output script, an optimistic roll-up consumes a maximum of 296 bytes/transaction in total, integrating different items — index root, zeroizer, beneficiary details and ZK-SNARK proof-of-stake. This results in a 77-fold increase in efficiency (compared to second-layer).


Both methods are based on a comparable number of transactions (~380,000). Furthermore, the cost of gas usage per operation in the blockchain is less for zero-knowledge roll-ups.


Gas cost per batch: compared to fraud evidence, ZK-SNARK verification for each batch is costly. ZK-SNARK technology tends to be much more complex. Consequently, optimistic packages are cheaper: 40,000 gas units compared to 500,000 units of gas.


Time to make output: optimistic roll-ups hold back output to allow enough time (e.g., 7 days) to resolve disputes. On the other hand, ZK roll-ups allow instant withdrawals.


Implementation and usage scenarios

Optimistic roll-ups are more common mainly because they are more suitable for generic EVM calculations. The overall amount of assets locked in optimistic roll-ups exceeds $10 bln, more than 10x the TVL in zero-knowledge roll-ups.


Zero-knowledge roll-ups are more suited for simple computation, sharing, and app-specific utilization. But recent advances in SNARK have also led to the emergence of general-purpose ZK roll-ups.


There are currently a bunch of active zero-knowledge roll-ups that have a combined blocked asset value of $1.3 bln. The majority of those projects exist in the beginning phases and are operator-driven.


Among the projects, the champions in terms of TPS strength include Starknet, dYdX and zkSync Era. All these networks have TVLs of over $100 million and process about 10 million transactions per month. Most rollups use zk-SNARK; outliers are dYdX and Starknet, both of which utilize ZK-STARK.


Summarize

Zero-knowledge roll-ups are a second-level zoom decision that leverages proofs of authenticity for off chain calculations and retains a modest volume of on chain transaction data.


The complexity of SNARK validation and the availability of on-chain data are the main challenges of ZK roll-ups transactions, which makes them least appealing for mainstream EVMs. This is the main driver why optimistic roll-ups are leading the market in terms of adoption. In addition, although only in the early stages of development, even the top zero-knowledge roll-up designs, Loopring, Starknet, and zkSync Era don’t operate autonomously.

Buy cryptocurrency at your desired price

With an AlfaBit account, you can not only exchange cryptocurrency but also trade it

Start trading
start traiding
prev

One AlfaBit account. Fiat and crypto — all in one!

next

CLARITY Act in 3 Minutes for Crypto Investors

Share

telegramvkinstagramfacebookx.comAsk AI about What are ZK-Rollups
Read AlfaBit News in Telegram
Traiding

Trade cryptocurrency with no commissions or hidden fees

Register an AlfaBit account now and perform trades and exchanges
commission-free for up to 6 months