freecoding.school100% FREE · NO SIGNUP
Proof PeaksISSUE #9 of 38

pedersen commitments · homomorphic adds

ZeekaVSThe Collision
Zeeka saysPedersen commitments live in a group as C = g^v·h^r — perfectly hiding, and homomorphic: multiplying two commitments commits to the sum of their values.

A Pedersen commitment is C(v, r) = g^v · h^r, where v is the value, r is a random blinding factor, and g, h are group generators whose relative discrete log is unknown. The blinding makes it perfectly hiding; binding rests on nobody knowing the discrete log of h base g. Its killer feature is being homomorphic: C(v1,r1)·C(v2,r2) = C(v1+v2, r1+r2).

That lets you prove things about sums of hidden numbers — for example, that the inputs of a confidential transaction equal its outputs — without revealing any amount. Pedersen commitments are the backbone of confidential transactions and range proofs (Bulletproofs). The demo verifies the homomorphic identity in a toy order-11 group.

Power-ups you unlock

The Collision attacks — common mistakes

Boss battleOver a toy order-11 group, verify that C(4,7)·C(5,9) equals C(4+5, 7+9).

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre id="o"></pre>
<script>
// Pedersen commitment C(v,r) = g^v · h^r in a prime-order group (toy GF(23), q=11).
const p=23, q=11, g=2, h=3;                        // g,h both in the order-11 subgroup
const pw=(a,e,m)=>{ let r=1; a%=m; while(e>0){ if(e&1) r=(r*a)%m; a=(a*a)%m; e>>=1; } return r; };
const C=(v,r)=> (pw(g, ((v%q)+q)%q, p) * pw(h, ((r%q)+q)%q, p)) % p;
const v1=4,r1=7, v2=5,r2=9;
const lhs = (C(v1,r1) * C(v2,r2)) % p;             // C(v1,r1)·C(v2,r2)
const rhs = C(v1+v2, r1+r2);                       // C(v1+v2, r1+r2)
document.getElementById('o').textContent = [
  'C(4,7) = ' + C(v1,r1) + ',  C(5,9) = ' + C(v2,r2),
  'homomorphic: C(4,7)·C(5,9) mod p = ' + lhs,
  '            C(4+5, 7+9)         = ' + rhs,
  'equal? ' + (lhs === rhs) + '   → commitments add without opening them'
].join('\n');
</script></body></html>
▶ Open the interactive comic issue
‹ Commitment Schemes · Hiding · BindingKzg Commitments · Polynomial Openings ›