Zero-knowledge proofs · Groth16 on BN254 · written in Go
Prove the bill.
Hide the life.
A smart meter records your consumption every hour, and those 720 numbers a month show when you wake up, when you're away and when nobody's home. zkMeter lets the meter prove the bill is exactly right without sending a single reading. The supplier, in turn, proves its dynamic prices really came from the AI tariff model it committed to in advance.
What your hourly data gives away
This is what a supplier receives under normal smart-meter billing. Simple rules, no fancy AI, already reveal a lot:
September, hour by hour
Average week
darker = more consumptionInferred from the readings
Three parties, three proofs
Each box shows exactly what crosses the wire. The supplier never sees the readings; the customer never sees the model's weights.
1 · Committed AI tariff
Before the month starts, the supplier publishes a hash of its pricing model. Every hourly price must come from that exact model.
- model commitment
- -
- model accuracy
- -
- proof
- -
2 · Commit & prove the bill
The meter publishes a salted MiMC hash of its 720 readings, then proves that the bill computed from those readings and the published prices is exact.
- readings commitment
- -
- bill
- -
3 · Verify, without the data
Only the commitment, the amount and the proof arrive. Verification is a few pairing checks: milliseconds, on any machine.
Prove one fact, reveal nothing else
Capacity tariffs and grid connections care about the peak. The meter can prove "never above X kW" from the same commitment. A false claim can't be proven at all.
Attack lab
A proof system is only as good as its constraints. These are real attempts against the real circuits.
Negative reading
A dishonest meter swaps one reading for −20 kWh to shrink its bill. In a finite field, "−20000" is just a very large number.
Silent price change
The supplier raises a single hour by €0.005/kWh after committing. The tariff proof no longer matches.
Discounted claim
The customer forwards a valid proof but claims €1 less. Every public input is bound into the proof.
How it works
Commitments
MiMC hash of a secret random salt plus all readings. The salt matters: hourly readings have little entropy and could otherwise be brute-forced from the hash.
Range checks
Every reading is decomposed into 17 bits (0–131 kWh). "Less than" is proven by decomposing the difference: 17 constraints instead of ~1,800 for a generic comparison.
Verifiable AI tariff
The circuit evaluates the committed linear model in fixed point for all 720 hours. Caveat: a linear model's weights can be reconstructed from its public prices, so the guarantee here is integrity (same, unchanged model for everyone), not secrecy.
Trust assumptions
Groth16 needs a trusted setup; this demo runs a single-party setup. Production would use a multi-party ceremony or a transparent system (PLONK with a public SRS, STARKs).
Verify offline: download the bundle, then KEYS_DIR=keys zkmeter verify zkmeter-bill-proof.json