freecoding.school100% FREE · NO SIGNUP
Proof PeaksISSUE #3 of 38

pairing-based crypto · bilinear maps

ZeekaVSThe Collision
Zeeka saysA pairing maps two curve points into a third group while preserving multiplication in the exponents — the trick behind BLS signatures and KZG commitments.

A pairing is a bilinear map e(aP, bQ) = e(P, Q)^(ab). The point is that secrets sitting in the exponents can be multiplied and checked without ever being revealed — a verifier can confirm a relationship between hidden scalars. This is the engine under BLS signature aggregation, KZG polynomial commitments, and many SNARK verifiers.

Pairings only exist efficiently on special pairing-friendly curves like bn254 and bls12-381, and computing one is the expensive step in verification. Real pairings need extension fields and a Miller loop — too much for a sandbox — so the demo below models the bilinear identity on toy exponents. It is illustrative, not secure crypto, but it shows exactly the property pairings give you.

Power-ups you unlock

The Collision attacks — common mistakes

Boss battleUsing a toy exponent group, verify the bilinear identity e(g^(a+c), g^b) = e(g^a, g^b) · e(g^c, g^b).

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre id="o"></pre>
<script>
// ILLUSTRATIVE pairing (toy): real pairings need extension fields + a Miller loop.
// We model the bilinear IDENTITY on exponents to show the property correctly.
const P = 2003;                                    // toy target-group prime
const gt = 5;                                      // target generator
const pw = (a,e,m)=>{ let r=1; a%=m; while(e>0){ if(e&1) r=(r*a)%m; a=(a*a)%m; e>>=1; } return r; };
const pair = (a,b)=> pw(gt, a*b, P);               // e(g^a, g^b) := gt^(a·b)
const a=6, b=7, c=4;
document.getElementById('o').textContent = [
  'e(g^a, g^b) := gt^(a·b)   [illustrative — not a real pairing]',
  'e(g^6, g^7)    = ' + pair(6,7),
  'e(g,g)^(6·7)   = ' + pw(pair(1,1), 6*7, P) + '   ← same value',
  'bilinear: e(g^(6+4),g^7) == e(g^6,g^7)·e(g^4,g^7) ?',
  '  ' + ( pair(a+c,b) === (pair(a,b)*pair(c,b)) % P )
].join('\n');
</script></body></html>
▶ Open the interactive comic issue
‹ Elliptic Curves · Group Law · Secp256k1 Vs Bn254Bls Signatures · Aggregation · Validator Keys ›