
How Shafi Goldwasser Co-Invented Zero-Knowledge Proofs
Source: YouTube · a16z crypto · published Aug 6, 2026 · 56:54
Zero-knowledge proofs—where a prover convinces a verifier of a claim while revealing nothing else—originated from the seemingly toy problem of playing mental poker over the phone, and have evolved into foundational technology powering modern blockchain scaling and privacy systems 0:00-0:04.
Key Takeaways:
• The concept emerged when Goldwasser and Micali tackled mental poker, realizing they needed interaction and randomness to prove cards were dealt properly without revealing hidden information 5:40-5:56
• Privacy was the original motivation for interactive proofs, not computational power—mathematicians initially rejected the concept because proofs were supposed to have zero error 10:13-10:21
• The sumcheck protocol, developed through multi-prover interactive proofs and culminating in IP=PSPACE, remains a core paradigm for building modern SNARKs 18:18-18:36
• Most systems called "ZK-SNARKs" today don't actually use zero knowledge—succinctness is often sufficient for blockchain scaling, though privacy applications like Zcash do require true ZK 25:26-26:04
• Goldwasser's recent work applies proof concepts to machine learning (training chatbots to produce verifiable proofs) and law (proving software usage without revealing proprietary code) 45:41-46:08
The journey from mental poker to SNARKs illustrates how playful, toy problems can unlock profound theoretical advances with real-world impact.
Sources:
- 0:00-0:04 Definition of zero knowledge
- 5:40-5:56 Mental poker leading to interactive proofs
- 10:13-10:21(https://www.youtube
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
The definition of zero knowledge is in some sense that at the end you will believe what I claim, but you will discover nothing else. In the beginning when we were trying to define these interactive proofs, we wanted to make sure that we talked about the prover as all powerful. And over the years the prover was assumed to actually not have much computational power. Part of the reason why you knew he couldn't cheat you is because he wasn't smart enough to do so because he was computationally limited. >> I've always kind of wondered why the notions of zero knowledge and interactive proofs kind of came together. >> The answer is privacy. The reason for introducing the interaction and the randomness was because this was the way to obtain privacy. [music] And only later, this was a paper by Gold…