# The Blind Man's Elephant: a product vision towards private identities by Andy | Devcon SEA

- Channel: [Devcon](https://streameth.org/devcon)
- Date: 2025-10-09
- Duration: 11:47
- Topics: Science & Technology
- Watch: https://streameth.org/watch/yt--BESF3MUM20
- YouTube: https://www.youtube.com/watch?v=-BESF3MUM20

## Description

A short talk introducing the concepts of key properties we want to achieve in private ZK identities. Sparkling concepts like SSI and DIDs and why blockchains are the best way to ensure that.

Finally it concludes with simple ZK and data-structure constructions and different alternatives that are seeking to provide this characteristics.

In short, this is a lightning overview of the space, it's desired features and different approaches to achieve them.

Speaker(s): Andy
Skill level: Intermediate
Track: Applied Cryptography
Keywords: Privacy, Identity, ZKP, Use Cases, selective, disclosure

Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon
Learn more about devcon: https://www.devcon.org/
Learn more about ethereum: https://ethereum.org/ 

Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more.

Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. 
Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024.
Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

## Transcript

[Music] [Music] so I know many people here uh work multiplying matrices and like doing a lot of polinomial day in day out uh but I think my talk is going to be a little higher level on like how programmable cryptography can solve one of the I would say most important use cases for our space and and in general like uh society which is like private identities and this product Vision it will be more like a high level overview about what characteristics do we want and some sort of approaches that we have been seeing in the space um yeah trying to solve these these issues so as we are in Thailand I thought it was great to start with uh an analogy of this blind man uh elephant illustration because this is the land of the white elephants um I think where people who are inside the identity space we kind of like see a lot of acronyms thr everywhere like Dad pod SSI um and those are these idea like self-sovereign identities verifiable credential decentralized identities those are useful and have nuances but at the end it has some core properties which I want to like explore in this talk I'll say these are the properties that we care um and probably we can grow the list even more and we can even make um security assumptions models to understand how like in which sense these properties we want to achieve want of flexibility we want to verifiability we want privacy we want decentralization self ownership transfers ship etc etc etc but I would say if I were to sum it up to like the core core properties that we really want to key achieve with this are um basically three actions that I think we should uh pursue and target with programmable cryptography in this identity space first uh and and the ones bolded are things that a user will typically do in order to leverage private identities one is the capacity to import all my identities and data into something a container um let's call it a wallet for now the other one is to generate proofs or generate an artifact that then I can take and then uh proof an identity an attribute something about myself so that I can execute an action so my proofs being useful elsewhere so if we were to summarize like all the complexity that we have in these three kind of like steps and actions it turns out that it's uh a bit easier to about like what type of like cryptography systems and targets do we want to achieve with programmable cryptography in uh identity so the first section is let's import all let's import all my identities my data uh and what does that mean it means that for all the documents and data that exists in the world in the digital space anything that is signed we should and want to Target it to bring it to private identities um cryptography use cases and that means means obvious things like your national ID card your passport there are great teams um in here targeting that but also driver licenses sign documents PDFs credit card transactions maybe we can like Leverage from WhatsApp telegram over reputation social graphs Spotify history there's all this signed data that I think we need to hijack and literally start adding into all of these containers that it can be called it can have very different names and we need to do that permissionless that means without asking the national government to allow us to do that we need to do that privately without them realizing that because maybe you want to use it for things that the government doesn't approve or the Spotify or whoever and we want to make that data verifiable that's why CK npcf and other programmable cryptography Technologies are so good and we need to achieve like a web two user experience in order for this to be useful and get adoption and that means technically that we have a lot of challenges that we need to support a lot of hashing mechanisms a lot of signature schemes a lot of dat structures uh standards uh that means that we need to invent new things like not only wrap things into CK but also like 2pc and NPC a proxies and have like wallet like experiences if we really want to achieve this property the other one is proof facts about them and if we want to have a great user experience then we need to generate proofs in useful ways doing selective disclosure in things like less than one second in targets where our user are going to be and that means browser in your laptop but also browser in your phone and also means native phone like apps um and that means mobile mo mobile side proving or client side proving is extremely important which not every programmable cryptography project is is is targeting and it needs to be very cheap or even free it needs to be very easy for me as a non-technical user to leverage my data and import it and generate facts about it whenever a website or a platform queries and I respond to that the other one yeah technically this mean Wason mobile proving small Ram uh memory uh Resort like low bandwidth environments uh that means leveraging techniques like proof aggregation recursion folding different verification layers things exploring things like Co Nars in order to do delegate proving exploring things like proof composition like I don't know client side proving with with one proving system like sparton then aggregating on a ckvm and then like proving unchain with gr 16 those are kind of like the solutions that we're seeing because we want to have cheap fast composable proofs of our data and lastly we want to basically do very useful actions with that and the most obvious candidates are voting forums chats um Etc but there are things that are popping up like yeah data syndicates or data marketplaces where a lot of people can just add up their data and then make um charge basically to do statistic analysis on that private anonymized data we can do reimbursements compliance stuff uh a lot of ux on web 3 like multi6 account recovery social recovery are needed like need identity so I think that's where our Solutions in this space are going to be extremely important humanitarian cases anti-il Etc so yeah basically we need to be able to do useful actions and one of the biggest I'll say challenges is like nullifiers and the Nar is like a strong problem I just listed um different approaches and levels of like nullif fire is where the government basically no nullifier that's the worst case and best case is like yeah not even the government trying to collude will be able to you know see that you sign up for a really controversial uh service so yeah for last things uh this needs to be secure post Quantum is like a must have now because like in five years you're doing voting and it gets like uh captured the data and then uh decrypted later it could be a problem for you it needs to be interoperable no Bender lock in it needs to be movable from wallet to wallet it needs to support key rotations live checks etc etc so these are some properties that we want to achieve and I think we all in this space are trying to actively work on so to finalize I think the three key messages that I want you to take is like first let's hijack everything let's take all the data of identity sources and da sources and try to Bing um to our use case onchain or offchain let's try to discover novel use cases like different interactions that we can unlock with this new data Providence um things and now let's build uh new Lego blocks to build a better future thanks thank you [Music] Andy there's a question there oh I did pretty well thank you good throw yeah um so question um great great to see the product perspective for once and I really like the three three stage components and um product deals with human nature right so human nature usually runs on incentives so if I give an example for the government the government gives you the right to drive a car so you have to get a driver license therefore you have to get an identity yes so it usually goes backwards right from 3 to one so I was wondering what are the cases that you've seen that the incentive is so big that you would then go and find an identity Source um because if you want to use this as a uh as an actual identity that people use they usually don't start with wow this is so private and has like encrypted proof and hashes and everything yeah so I was wondering what what do you see that uh that has kind of grass roots in in in reality when can it can really brings the masses back to the to the platform to platforms like this okay I think that's a great question what I understood is like what are places where we will search for identities or data where people are already there I would say like yeah I will start with where are people there like it's very hard for us to request to everyone to sign up to a system but it will be way better if we just say like yeah all people are interested in driving a car in these locations let's just use that as a like source of starting point to bring their identity on chain and to do actions on chain and to do like voting and etc etc um so yeah like I don't know like anything that that you sign up that has a digital signature I think it would be great to just hijack it and the more people use it the more common they are the more used to they are like face ID Touch ID all these secure enclaves I think they're great to to to start to do that just just to follow on that um like the way I approach it just uh just to say it in a couple words we we have a company called Grappa and um we use reputation basically so we're saying you want to prove your reputation going to say that you did something in life you want to have some kind of um attestation from somebody else that you are nor worthy in something that's usually a start for an identity that usually I want to prove this to the world I start with that that starts to be kind of the seed of my identity and then I cannot forgo that yeah right yeah no great use case all right so one question there okay I saw on your slide uh verifiable oblivia pseudo Ren functions yes uh what's the uh what where do you see it fitting in yes that's a technique that a couple of teams in the identity space are exploring I think is great they didn't get to all the technical details but basically a network like MPC of nodes and basically how it does is like it calculates the salt with this like in an MPC fashion that is deterministic but no any no node by themselves can calculate that salt for you so I think this solves two really important problems one is like using your private data and this Soul generation process which is deterministic you can recover your account or you can recover your identity even if you lose your phone or like your cash data the other one is that um yeah just like way way better user experience and oh the other one was that no government can calculate that unless yeah they tap into that these these process type uh like private data so and and we can make these like very Uh custom so like yeah you can choose like private data that only you know in your head plus like private data that I don't know it's very filed in a credential so yeah in short very strong por periers and uh yeah anti-is Discovery mechanisms any more questions for Andy okay thank you so much thank you [Applause]
