# ZK-KZG for farming

**URL:** <https://forum.autonomys.xyz/t/zk-kzg-for-farming/1377>\
**Category:** Research\
**Created:** [April 12, 2023, 1:31pm UTC](https://forum.autonomys.xyz/t/zk-kzg-for-farming/1377 "2023-04-12T13:31:02Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![dariolina](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.autonomys.xyz/dariolina/32/743_2.png) [@dariolina](https://forum.autonomys.xyz/u/dariolina)\
**Post date:** [April 12, 2023, 1:31pm UTC](https://forum.autonomys.xyz/t/zk-kzg-for-farming/1377/1 "2023-04-12T13:31:02Z")

</div>

Unmasking all the chunks takes a long time (\> 1 sec) when proving a winning chunk. But we need it to recover the source record to compute the KZG witness. Can we leverage a ZK/hiding/homomorphic scheme to avoid unmasking?

- When plotting, we have source record polynomial r(x) of degree d with commitment C\_r
- We query the PoS table for quality strings to mask the chunks. They can be uniquely mapped to field elements and represented as polynomial q(x) of degree d with commitment C\_q
- If we mask with field addition instead of XOR, the masked chunks can then be represented as a polynomial p(x) = (r+q)(x) with commitment C = C\_r+C\_q

Can we prove a masked chunk as an evaluation (i, p(i)) without unmasking all the chunks and convince the verifier who knows the source commitment C\_r and q(i)? What else would the verifier need to know to be convinced?
