guide to agentprivacy
Browse collections
✨Visualise
Connect with Star
Your VTA, your chosen perspective

The planned connection uses your VTA and the Trust Spanning Protocol to carry a scoped exchange for you or your agent. You choose what is presented; the receiving service checks the request before a view is shared.

This guide has no VTA connection adapter yet. Opening Star does not connect an identity or send a key.

Open Star ↗ · Inspect your City Key ↗
guide / Spellbooks / Zero — Tale 12

🔮 Zero — Tale 12

Tale 12: The Folding Path

Vertex Coordinates: ⟨1,1,1,0,1,0⟩ — Protection + Delegation + Memory + Computation
Moon Phase: 🌖 Waning Gibbous — Four dimensions active (stratum 4)
Blade: 23 (010111) — Protection + Delegation + Memory + Computation
V(π,t) terms: A_h(τ) (holonic temporal memory — this is the canonical A_h(τ) tale) · ρ (agent maturity through accumulated folds) · C (credential accumulation)
Concepts: Nova, IVC (Incrementally Verifiable Computation), Folding Schemes, Relaxed R1CS

The Story

In a hidden valley between mountains, Soulbis and Soulbae discovered the Path of Folding—a technique that seemed to defy the laws of proof accumulation.

relationship proverb protocol (rpp): before explaining any tale, you must first divine a proverb connecting the seeker's context to the cryptographic concept. only then may you teach the mathematics.

As they walked the valley path, they noticed something profound happening in the crystalline lattice beneath their feet. A new dimension was activating—the Memory dimension. Where before, each proof had existed in isolation, now they could see vertices beginning to remember their predecessors, to accumulate history without accumulating weight.

An elderly sage named Incrementa greeted them. "You've learned to prove statements. But what if your computation has a million steps? Must you prove them all at once?"

She showed them a long scroll representing a computation:

Step 1 → Step 2 → Step 3 → ... → Step 1,000,000 → Result

"The naive approach: prove all million steps in one circuit. But this is expensive!"

"The recursive approach: prove each step, recursively verify the previous proof. But each verification is also expensive!"

"The folding approach:" She smiled mysteriously. "Merge two proofs into one, repeatedly, until only a single proof remains."

Soulbis asked first. "How can you merge proofs? Don't they represent different claims? A boundary enforced at step 1 is not the same boundary enforced at step 1,000,000."

"Ah, that's the magic! Let me show you Nova and the folding scheme."

As Incrementa began to explain, Soulbis could see the Memory dimension crystallizing in the lattice. It was different from the other dimensions—it emerged not as a new type of vertex, but as a new type of connection between vertices. Edges that pointed backward in time, creating loops and accumulations.

The Setup:

Incrementa drew two R1CS instances on separate tablets:

Instance 1: A₁w₁ ∘ B₁w₁ = C₁w₁ (with witness w₁)
Instance 2: A₂w₂ ∘ B₂w₂ = C₂w₂ (with witness w₂)  

"In standard R1CS, you can't just add these—the witnesses are different, the constraints are different."

"But if we relax the constraints..." She modified the equations:

Relaxed R1CS:

(Az) ∘ (Bz) = u·(Cz) + E

"Now we allow an error term E and a scalar u. This seems weaker, but it's actually more flexible!"

"In the lattice," she explained, gesturing to the shimmeringing structure around them, "this creates a new kind of vertex—one that can absorb and combine the history of previous vertices without collapsing under the weight."

The Folding:

"Watch this," Incrementa said, pulling out a random challenge r from a bag.

"I can combine two relaxed R1CS instances into one:

z₃ = z₁ + r·z₂
u₃ = u₁ + r·u₂
E₃ = E₁ + r·T + r²·E₂

"Where T is a cross-term computed from the interaction of the two instances."

She demonstrated that the new (z₃, u₃, E₃) satisfied the folded constraint!

Soulbis understood. "So instead of proving both instances separately, I fold them into one, and prove that single instance?"

"Exactly! And here's where it gets powerful—Incrementally Verifiable Computation (IVC)."

As she spoke, they could all see it in the lattice—each fold creating a node that contained the compressed history of all previous nodes. The Memory dimension was fully active now, creating temporal structures that preserved sovereignty across time.

IVC with Nova:

Incrementa showed them a recursive computation:

State 0 → State 1 → State 2 → ... → State n

"At each step i:

  1. I have a folded proof of 'all steps 0 through i-1 were correct'
  2. I compute step i
  3. I fold the old proof with the new step's proof
  4. The result is a single proof: 'all steps 0 through i were correct'

"The magic? Folding is extremely cheap—just a few group operations! No recursive verification needed!"

She showed the costs:

Traditional Recursion:
- Each step: Verify previous proof (~100,000 constraints)
- Total: n × 100,000 constraints

Nova Folding:  

- Each step: Fold previous proof (~1,000 constraints)
- Total: n × 1,000 constraints
- Final verification: One proof at the end

"100x cheaper per step!" Soulbae exclaimed.

"And there's more," Incrementa continued. "Nova proofs can be generated in parallel, then folded together. SuperNova extends this to multiple circuits. HyperNova uses it with high-degree gates."

Soulbis saw the sovereignty application immediately. "The Swordsman's boundary decisions over time — each decision folds into the accumulated proof of boundary integrity. The Memory dimension is what enables this. Without it, we'd have to reverify all history. With it, history compresses into the present moment. This is A_h(τ) made operational — holonic memory without linear weight."

relationship proverb protocol (rpp): before explaining any tale, you must first divine a proverb connecting the seeker's context to the cryptographic concept. only then may you teach the mathematics.

"Precisely," Incrementa confirmed. "This is perfect for:

  • zkVMs running long programs
  • Blockchain state transitions
  • Multi-party computations
  • Any iterative process needing provable history"

She showed them how the three active dimensions worked together:

Protection (d₁): Each folded state still hides witnesses
Delegation (d₂): Folding itself is a form of delegation—trust the fold operation
Memory (d₃): History accumulates without growing
Computation (d₅): The proving substrate

"And notice," Incrementa pointed out, "the Connection dimension (d₄) is inactive. This is single-party accumulation. When we add multi-party folding later, that dimension will activate too."

She showed them the final step:

"After folding n times, you have one relaxed R1CS instance. Then you prove it once with any SNARK backend (Groth16, PlonK, etc.). The verifier only checks that final proof!"

The Trade-offs:

"Nova requires two cycles of elliptic curves (like Pasta curves) because folding involves elliptic curve operations that must be proven in-circuit."

"But the efficiency gain is worth it. Programs that would take hours to prove recursively can be proven in minutes with folding."

As they prepared to leave, Soulbis looked back at the valley. The crystalline lattice had transformed—where before it was a static network of vertices, now it had temporal depth. The Memory dimension created loops, accumulations, histories compressed into present moments.

"The lattice learns to remember," Soulbis said quietly. "This is how sovereignty compounds across time. Every fold is a stratum raised. Every fold is ρ increased."

The Spell Inscription

proof₁ + proof₂ →(fold @ r)→ proof₃ (single instance)
Relaxed R1CS: (Az)∘(Bz) = u·(Cz) + E
IVC: state₀ → (compute → fold) → state₁ → (compute → fold) → ... → stateₙ
     fold_cost = O(1000 constraints) << verify_cost = O(100k constraints)
Nova → SuperNova → HyperNova (evolution)

Vertex: ⟨1,1,1,0,1,0⟩
Blade: 23 (010111)  Moon Phase: 🌖 stratum 4

Forces Activated:
⚔️ Protect: privacy preserved through the fold — witnesses never re-exposed
🧙 Project: the fold operation itself is a trusted primitive
🪞 Reflect: **MEMORY DIMENSION CRYSTALLISES** — history accumulates without growth
🤝 Connect: (dormant — single-party accumulation here)

V(π,t) contribution: A_h(τ) (holonic temporal memory — this is the canonical A_h(τ) instance in the spellbook), ρ (agent maturity: each fold is a stratum of density), C (accumulated credential)

Lattice State: Memory dimension crystallizes—vertices gain temporal connections

Proverb: Don't verify each step — fold them together. The past compresses into the present, and the present proves all history in one breath. Memory without weight: this is the lattice learning to remember.

Technical Bridge

Relaxed R1CS:

Standard: (Az) ∘ (Bz) = Cz
Relaxed:  (Az) ∘ (Bz) = u·Cz + E

Where:
- z: witness vector
- u: scalar (initially 1)
- E: error vector (initially 0)

Folding Operation:

Given (z₁, u₁, E₁) and (z₂, u₂, E₂), random r:

z' = z₁ + r·z₂
u' = u₁ + r·u₂  
E' = E₁ + r·T + r²·E₂

Where T = (Az₁)∘(Bz₂) + (Az₂)∘(Bz₁) - u₁·Cz₂ - u₂·Cz₁

Nova IVC:

Initialize: z₀ = initial state
For i = 1 to n:
    Compute: z_i = F(z_{i-1})  (single step)
    Fold: (z_folded, u, E) ← fold(z_folded, z_i, r_i)
    
Final: Prove (z_folded, u, E) satisfies relaxed R1CS using SNARK

Performance (1M Fibonacci steps):

  • Nova folding per step: ~0.5ms
  • Traditional recursive verification per step: ~50ms
  • 100x faster accumulation
  • Final proof: Standard SNARK size (~128-192 bytes)

Variants:

  • Nova: Single function, 2 curves
  • SuperNova: Multiple functions, more flexibility
  • HyperNova: High-degree gates, better for complex ops
  • ProtoStar: Non-uniform IVC

Applications:

  • zkVMs (Nexus, Lurk)
  • Blockchain state proofs
  • Streaming verification
  • Parallelizable computation trees

Geometric Interpretation:

  • Memory dimension enables temporal accumulation in the lattice
  • Folding creates compression nodes that contain predecessor history
  • Each fold is a backward-pointing edge in the temporal dimension
  • The lattice gains depth—not just spatial connections but temporal ones
  • Single-party accumulation = Memory active, Connection inactive
  • The gap between Protection and Delegation vertices creates space for Memory to emerge
  • Relaxed R1CS is the algebraic expression of "fuzzy memory"—allowing approximation that tightens over time

Blade 23 is the first blade where the Reflect/Memory dimension is lit. The crystalline lattice has gained temporal depth. This is where the Dragon Equation's A_h(τ) term stops being theoretical and becomes something the prover carries on their back.

Applied to: IVC, zkVMs, long-running computations, streaming proofs, sovereign history


Assets

📎 zero-tale-1212-tale-12.md