Commitments in general
A commitment is the digital version of a sealed envelope. One party writes a value, seals it and hands over the envelope. Later they open it, and everyone can check that the value inside is the one that was sealed.
Dan Boneh and Victor Shoup’s textbook defines a commitment scheme as two algorithms. The first takes a message and outputs a commitment string, which is published, and an opening string, which the committer keeps. The second takes the message, the commitment and the opening and accepts or rejects. A secure scheme has two properties:
- Binding. Once the commitment is made, it can be opened to only one message. The committer cannot change their mind.
- Hiding. The commitment reveals no information about the message until it is opened.
Hash commitments and the nonce
One standard construction uses a hash function. To commit to a message, pick a random nonce, compute the hash of the message and the nonce together, and publish the hash. To open, reveal the message and the nonce, and anyone can recompute the hash and compare.
Each property depends on something different. Binding comes from collision resistance: opening the same commitment to two different messages would mean finding two inputs with the same hash. Hiding comes from the nonce, which Boneh and Shoup take at random from a space that is large relative to the hash output. Halevi and Micali showed in 1996 that practical string commitments can be built on collision-free hashing alone.
The nonce matters especially for locations. A location at a given precision has a limited set of possible values. Hash a location without a nonce and anyone can hash candidate places until one matches, which undoes the hiding. With a long secret nonce, the hash says nothing until the nonce is revealed.
Commit and reveal on a blockchain
A public blockchain is one place to publish a commitment: once a transaction is included, anyone can read it. The Solidity documentation’s blind auction shows the pattern. During bidding, each bidder sends only a hashed version of their bid, computed as keccak256 over the bid value, a flag and a secret. After bidding closes, bidders reveal their values and the contract checks that the hash matches. The documentation admits that a blind auction on a transparent computing platform might sound like a contradiction; the hash with a secret is what makes it work.
The same applies to locations. Anything committed to a public chain stays there, so a design has to decide what goes into the hash, what goes beside it in plain view, and what stays off the chain.
What goes into a location commitment
A location commitment can bind a few things together:
- The location, possibly coarsened first, for example as a geohash cell rather than exact coordinates.
- Who is claiming it, so the commitment cannot be reused for someone else.
- A secret nonce, so the commitment hides its contents.
- A time or ordering, which a blockchain transaction provides.
What a commitment does not do is check that the location is true. Binding only means the committer cannot change the claim afterwards. Evidence about whether the claim is plausible comes from elsewhere, such as a location witness who measures the claimant and signs what it saw, and who can then point to the commitment as the claim it was checking.
A documented example
Offline Protocol’s Proof of Location makes this split explicit. Its backend generates a random task ID and a secret per-commitment nonce, derives a precision-5 geohash (approximately a 5 km cell) from the claimed coordinates, computes keccak256(username, geoHash, nonce) and submits the task to an EigenLayer AVS contract on the Ethereum Sepolia testnet. EigenLayer’s README describes it as a restaking protocol that brings together restakers, operators and autonomous verifiable services (AVSs). The nonce is never published, so the commitment does not identify the username. The geohash and each task’s time, however, remain public on Sepolia, so the coarse location itself is not hidden. Operator witnesses then measure network round-trip time and sign individual attestations, which a consumer verifies against the intended task and commitment.
Limits to keep in mind
- A commitment is not evidence. It fixes a claim; it does not support it.
- Public context leaks. Whatever sits beside the commitment in plain view, such as a coarse cell or a timestamp, is readable by anyone, and what a location record can reveal adds up over many records.
- Losing the nonce loses the opening. If the committer deletes the nonce, nobody, including the committer, can open the commitment later.
- Chains are permanent. Obtain consent before committing anything about a person that cannot be removed.