@crisp-e3/contracts
v0.23.0
Published
This directory contains the Solidity contracts for CRISP - Coercion-Resistant Impartial Selection Protocol.
Readme
Solidity Contracts
This directory contains the Solidity contracts for CRISP - Coercion-Resistant Impartial Selection Protocol.
Contracts are built and tested with Hardhat. Tests are defined in the test
directory.
Running Tests
To run contract tests from the CRISP example root (examples/CRISP/):
pnpm test:contractsAlternatively, you can run tests directly from this directory:
pnpm testDeployment
Local deploy is driven by ../../crisp.dev.env (see
../../docs/PROOF_AGGREGATION_AND_ZK.md):
pnpm dev:setup— applies profile, builds DKG circuits whenCRISP_SKIP_PROOF_AGGREGATION=falsepnpm dev:up→scripts/crisp_deploy.sh— setsENABLE_ZK_VERIFICATIONfrom the same file
CRISP-only deploy (Interfold already deployed)
pnpm deploy:contracts # production RISC0 verifier
pnpm deploy:contracts:full # also deploy Interfold stack (no ZK unless ENABLE_ZK_VERIFICATION=true)CRISP Program
This is the main logic of CRISP - an interfold program for secure voting.
It exposes three main functions:
validate- that is called when a new E3 instance is requested on Interfold (Interfold.request).verify- that is called when the ciphertext output is published on Interfold (Interfold.publishCiphertextOutput). This function ensures that the ciphertext output is valid. CRISP uses Risc0 as the compute provider for running the FHE program, thus the proof will be a Risc0 proof.publishInput- accepts the compact proof commitment for an input. A voter or relay calls it after the CRISP availability service has durably stored the ciphertext and signed the input ID with a 10-minute expiry. The function checks the stage, commitment cutoff, signed expiry, voter eligibility, service signature, and Noir proof over nine public inputs. It reserves the input's tree leaf and index immediately.finalizeInputlater verifies the VectorX receipt for the exact ciphertext hash without requiring the voter to remain online. The proof establishes that the ciphertext was encrypted correctly under the committee public key (examples/CRISP/packages/crisp-contracts/contracts/CRISPProgram.sol:493-554, paths from the repository root). The verifier is the one the round's census selects:CRISPVerifier.solfor a census posted as a Merkle root,CRISPOnchainVerifier.solfor one read from token balances on chain. Both files declare a contract namedHonkVerifier, which is why they are named by file. The Greco relations that proof checks are built bycrates/zk-helpers/src/circuits/threshold/user_data_encryption/and proved by the circuits undercircuits/bin/threshold/. See the Greco paper.
