Why
Any change in a circuit (logic, dependency update, parameters) changes its verification key, and a circuit or a key can turn out to be insecure. There is no mechanism today to invalidate the certificates produced with it: the trust in the circuit verification key is compile time only, and clients have no signal to reject a range of certificates.
What
Prepare a revocation mechanism for certificates in defined epoch ranges. The revocation list is published, signed by the genesis key, and must be verified by clients prior to verification.
How
Why
Any change in a circuit (logic, dependency update, parameters) changes its verification key, and a circuit or a key can turn out to be insecure. There is no mechanism today to invalidate the certificates produced with it: the trust in the circuit verification key is compile time only, and clients have no signal to reject a range of certificates.
What
Prepare a revocation mechanism for certificates in defined epoch ranges. The revocation list is published, signed by the genesis key, and must be verified by clients prior to verification.
How
testing-previewdev-preview(will be done upon deployment)pre-release-preview(will be done upon deployment)release-preprod(will be done upon deployment)release-mainnet