New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Working Towards a Plural Public via Common Knowledge and Designated Verifier Proofs by Shrey Jain

DevconSat, Oct 7, 2023, 12:00 AM

Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. https://archive.devcon.org/archive/watch/6/working-towards-a-plural-public-via-common-knowledge-and-designated-verifier-proofs/ Often cited virtues of blockchains are immutability, transparency, decentralization, openness, and trustlessness. Many also think of their most natural applications as financial. Yet a critical affordance of such systems is often missed: the way they are uniquely suited to facilitate cooperation. Here I show how via CK and DVPs. Speaker(s): Shrey Jain Skill level: Intermediate Track: Governance & Coordination Keywords: Coordination,Non-Financial,Social Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon 6 was held in Bogotá, Colombia on Oct 11 - 14, 2022. Devcon is organized and presented by the Ethereum Foundation, with the support of our sponsors. To find out more, please visit https://ethereum.foundation/

Transcript

foreign [Music] months ago I was at a dinner with my parents at an Indian wedding and we were eating the food but there were no napkins on the dinner table not a big issue but if you've ever had Indian food you know that your hands get really messy and you need to have a napkin and as we were looking for a napkin asking the wedding venue staff we saw that the wedding party was getting really mad that there were no napkins in the venue and there was just a lot of emotion and anger being expressed at the time a week later I was with my dad at a coffee shop and we see this guy getting really mad at a barista and I said to my dad and I said napkin and because we had this shared experience of being at the wedding previously and we shared this context of what napkin meant not something that you traditionally label napkin with but something that we shared this context with I knew that he understood what napkin meant and I had this feeling that I could actually encrypt the word napkin in the physical world and only have the people who could understand it be the ones who were there for that experience and shared the context and I could actually draw this boundary around who would understand it and so I wanted you to get you all to think about some of these dictionaries that you may share with your friends your family or your co-workers that may consist of idioms symbols or these inside jokes that let you communicate incredibly efficiently with one another but not only do they let you communicate efficiently they actually have a boundary on who understands that dictionary and so if you've ever studied information Theory you may have heard of what's called The Source Code theorem and there's this concept called Hoffman Coatings and what Hoffman Coatings do is they let you take all the information that a computer needs to read and collapse it down into the minimum number of bits necessary for that computer to process the information well with these dictionaries that you build with your friends your family and your co-workers you can also communicate incredibly efficiently with anyone who's inside of this boundary and anyone outside requires much more context to interpret what you're saying but this doesn't just apply to inside jokes or idioms it applies to things much larger like let's look at the field of medicine as an example so of all the medical literature that exists in the world Colombia has said let's take all this literature and collapse it down into a set of texts that Colombian medical students will need to know and so long as they know this literature then they can communicate with one another and potentially among other assessments practice medicine in Colombia and so if I go up to a physician in Colombia and I say cardiac endoparditis I know what they know that cardiac endocarditis means something in the medical terminology and anyone outside of this field may require more context but does speaking this language or having this terminology allow you to be part of this group well no like if I read all this medical textbooks it doesn't make me a doctor nor does reading the Bible make me a Christian or reading legal textbooks make me a lawyer but what these texts are very powerful for is they let you communicate incredibly efficiently with people who are inside of these communities and so another problem that you may see is like let's put three scientists on a panel uh biologists an economist and a sociologist who are all aimed at talking about how to solve climate change and they each come onto this panel with each of their own dictionaries with each of their own peers and what ends up happening is you end up getting the most high level abstract communication possible and we don't we lose the richness that comes from each of these cultural communities and so what I've tried to do in this brief introduction is introduce some of the primers to the concepts that we'll be diving much deeper into into the rest of this talk like context collapse common knowledge and boundaries and this work is titled plural publics at Microsoft and his joint work with Glenn Weil York Rhodes and Divya Siddharth and I hope by the end of this talk we'll have a very tactical approach of how to build systems that can achieve common knowledge protect boundaries and also rebuild the context that we've lost in communication a lot of this work is influenced by some of the early thinkers like John Dewey and Walter Lipman who've taught a lot talked a lot about the plural publics as well as what it means to have informed decision making Dana Boyd from Microsoft research who's talked a lot about context collapse and I've had the pleasure of working with Joseph Halpern from Cornell who's done a lot of the early thinking on distributed systems and common knowledge and so when we talk about pluralism there's many different axes of pluralism there's one that felt most right to me it's about as a builder is how can we build systems that facilitate cooperation across social differences and so the way that I'm going to structure this talk is we're going to first focus on cooperation and then we're going to tie it back to social differences at the end and so at the beginning of this talk I said something like I know that they knew what napkin meant and so what was I trying to say there well there's this concept in Game Theory psychology and computer science called common knowledge and a fact is said to be common knowledge if everyone knows that this proposition is true everyone knows that everyone knows that this proposition is true and everyone knows that everyone knows everyone knows that everyone knows its proposition is true and when I first read this it didn't make much more sense to me as to what common knowledge was and so let's walk through a quick example so I want you to imagine we have two generals here a general on the left called General a and a general on the right called general b and their goal is to attack in the valley of this mountain in a coordinated way and the only way that they can communicate is through a messenger and this messenger has the possibility of getting lost in this Valley and so let's let's say General a says to General B let's attack at 6am do they attack no because General a doesn't know that general b got the message let's say General B acknowledges the message do they attack no because general b doesn't know that General a got the acknowledgment let's say that generally acknowledges the acknowledgment General a doesn't know that general b got the acknowledgment of the acknowledgment and so what I'm trying to Showcase here is that if a messenger can get lost we're unable to achieve systems that can attain what's called common knowledge but maybe we don't need common knowledge maybe we need something as close to common knowledge as possible and that's often referred to as what's called common key belief it's a as close to form of common knowledge that we can attain in systems where communication is not guaranteed and so let's let's now relate common knowledge back to these concepts of coordination and cooperation so coordination is when you have a set of Agents take action simultaneously cooperation is when these agents take action simultaneously but also understand the payoffs that come with these actions and so cooperation studied in economics and psychology has been broken down into two key subtypes altruistic cooperation and mutualistic cooperation so altruistic cooperation which is a fascinating topic to psychologists is when I incur a cost of myself to the benefit of others and why would we do this and so we've been studying these concepts of emotions that relate to reciprocation like trust empathy gratitude and we don't probabilistically measure these emotions we can categorize them I don't trust you with 20 accuracy I either trust you I don't or I really trust you I really don't trust you and humans are able to categorically depict the set of emotions in these categorical ways but mutualism what I think is what we often talk about in the web 3 ecosystem is when I take action you benefit but so do I and this problem is not as much of an emotional one related to trust or uh gratitude it's much more related to what's called an epistemological problem how well can I measure someone else's knowledge and in a lot of the psychology and research both empirically and theoretically we've seen that not only can humans categorize emotions but we can also categorize these levels of knowledge that people have so I in an example of this I know that I sent you a message I know that you I sent you a message and you got the message I know that I sent you the message you got the message and I know that you know that I sent you the message all the way up to these rich forms of what we talked about earlier being common knowledge and in these experiments it's in the physical world that people have run it's when people have common knowledge the most rich form of knowledge that the probability of taking action is much higher and everyone benefits much in a much richer way as well Okay so we've talked nothing about web3 so far we're going to get there I promise but what we've highlighted so far is that common knowledge is a critical component to cooperation let me walk through a brief historical explanation as to why we lack common knowledge today so we we talked earlier about the common P belief and why we lack it in the coordinated attack problem and I'm going to work through two key axes of communication right now one being knowledge and the second being privacy and so when we communicate in these physics in this physical world and I have a messenger privacy is not guaranteed I this messenger may go and leak the message they may not say the message in full and so privacy lacks and my common key belief as we saw earlier is weak we then move to forms of writing where at least I know whatever I write on the sheet of paper is going to get sent to that person but it still doesn't solve these problems of common key belief or leakage and after 50 years of the envelope being used for uh packaging gifts in Japanese culture we finally found ways to use it to package messages this improved privacy but still didn't improve the way we communicate for common knowledge I'm going to skip through forms of radio Telegraph and move to the ways we communicate today like SMTP for email SMS for texting or xmpp for WhatsApp or telegram we can achieve these forms of common p-belief but they actually quite hard to do in an interface level and they'll explain why in a second and as we've seen in a lot of these centralized settings we still lack the Privacy that we want to achieve as well and so my question now is where does a distributed Ledger play a role in all of this or a distributed Ledger being the key word here distributed Ledger does not imply blockchain and so where we've kind of come to in this setting and if you've been to a lot of the talks today clearly there's something going on with the relationship between zero knowledge proofs and blockchains it doesn't mean that they you need ZK to work with blockchains you can do it without but there's a rich ecosystem of innovation going on there where does communication play a role with distributed ledgers and Joseph Halpern who laid a lot of the work in distributed ledgers has said that if we can satisfy two Key properties of a distributed Ledger then we can achieve weak forms of common knowledge the first being what's called T consistency meaning a prefix of my ledger is a prefix of your Ledger and the second being what's called Delta weak growth which means that within a Time Delta I can add some information to each other's histories but let's make it much more clear like what exactly will distributed ledgers play a role in The Next Step of human communication well the first is that they actually are easier to build an interface on to achieve common pay belief and we'll show why that's the case in a second and the second is that we can actually provide a commitment to knowledge when we communicate so an example of this at Microsoft what we did is we switched the way we communicate from emails and Excel spreadsheets for our supply chain and started to use a blockchain because at every step of the inventory process we had common knowledge about the inventory who was where what was where and everyone knew that everyone knew that everyone knew we were able to save a lot of uh retroactive issues that we normally face and in fact this led to a savings of 50 million a year and one of our many Supply chains of our Azure stack what are other examples of where we could use this well we could use it for reporting for Social Action social movements or reporting on sexual assault cases whistleblowing whenever you need to have these coordinated attacks and it's really important to have common knowledge its protocols and distributed ledgers that do this in a really nice way with these two properties that I commented on earlier and the second part is that blockchains sorry today in communication we lack a commitment to knowledge communication is very accessible very free in a way that is good but also with cooperation purposes leads to extendious extraneous amount of communication to get something done what's really interesting about what's being explored in the web 3 ecosystem is how we can program these commitments and the way we communicate and so there's a protocol that was a while ago called ethereum whisper some of the core team there went and Built This research project called the VAC P2P Network where they reveal part of the vector on an elliptic curve from your public key to your private key as you start to send messages over a threshold limit to prevent spam and so there's an actual programmatic commitment that you make with every message you send we're starting to see Community currencies or tokens with regards to governance play a large role and how can we use these tokens to stake when we want to communicate with regards to cooperation purposes okay so what have we said so far clearly common knowledge is a requirement for cooperation if and if we want to cooperate we need to do so in a very rich way and we've walked through this historical example and now we can see why there's a case where we might want to explore with distributed ledgers to communicate for cooperation so now we got the cooperation box checked let's now figure out how can we do it across different sets of people but if we want to cooperate with another individual the first step is being able to recognize who are we cooperating with and in the web 3 ecosystem decentralized identity is its own Suite of problems so earlier this year we put out a paper that tried to exhaust a lot of the work being done on the decentralized identity Frontier and we looked at different Primitives and we look at what what needs to be done to identify an individual what becomes even harder is how we identify a set of individuals how do you put a boundary around a group of people and so let's talk a bit more about why we've lost boundaries today in the way that we communicate so in the past we had these very rich forms of tribal Dynamics whether it was literally we were part of tribes or was religion and we had a very clear sense of who was inside of a group and who was outside of a group and these strong tribal Bonds were quite good with respect to communication communicating quite efficiently and we understood each other's dictionaries quite well but these tribal Dynamics were quite oppressive to certain subgroups and so we started to find ways to liberate these individuals but some would argue we've gone so far so that these individuals now feel lonely alienated and are communicating on systems that try to rebuild these bonds like social media platforms that have done so in a way that lack context and so what is context here it's I'm communicating to this invisible audience that lacks the context to understand the dictionaries that I communicate with with my peers and the thing that we like in communication today is collective disclosure we talk a lot about I choose to disclose I disclose this I do that we don't have enough of we collectively can do things with strong guarantees so now let's talk about some tools that we can use today to go and do this so I want to introduce to people if you're not familiar with what's called designated verifier proofs there are a set of proofs that say instead of proving X let's prove Alice will prove the statement either X is true or I am Bob again it's one of those things that takes time to sit with so let's walk through an example to make this much more clear let's imagine we have two Dows the CIA Dao and the KGB dial and the goal of these dials is to prevent a double agent problem so meaning that I don't want my agents if I'm the CIA to be spying on myself for the KGB and the KGB wants the same things happening for them let's develop a scheme that makes us much less accessible to the agents so let's say I'm the CIA and an agent wants to go and turn on me and I am I'm unaware of this and they want to go to the work for the KGB so agent a goes to the KGB and says hey I'm part of the CIA and I want to work for you naturally what does the KGB need to know they need to validate this information it's very critical that they validate this information with high validity but we want to mitigate the CIA that this agent can go and do that so how do we do this so we're now going to walk through the designated verifier proof scheme we're not going to go through the technical details here but if you want to you can come up to I and someone who I'll introduce in a second in a minute but the way that this works is we have two two inputs the first is that the CIA now actually makes a claim agent a is part of the CIA and so they have this registry that exists of all the agents that are part of the CIA and so they can pass it through this circuit with and signing it with their private key that they're part of the CIA the key thing to recognize is that there's an or gate here and so this constraint can be satisfied by either the CIA actually making this claim or agent a private key can also make this message and so let's walk through why this is so important so again the CIA can make this claim or two the agent a can make this claim and we won't know which one it is but agent a knows that the CAA doesn't have their private key so if this if this circuit satisfies with the output of one then it must be the case that the CIA made this claim and they agent is not lying and so to a third party they don't know who made this claim whether agent a is lying or the CIA actually said this message so the only person who's persuaded by this information is actually agent a because they know the CIA doesn't have their private key and so what's the bigger part of all of this well you can't ever prevent someone from sharing information but you can prevent that information from being persuasive in its shared form so we can mitigate the belief that this has in its shared form and so um what we start to move towards is what's called Collective disclosure and so let's work it through a much more web 3 example of this now let's say that I'm a Dao and we have a secret that we want to keep within the Dow dowels today are quite leaky we lack systems to communicate and put boundaries around communication and so I tell a secret each of the members of the Dao I say hey we have a secret but we want to make make sure that the Integrity of this information is withheld with very strong guarantees within this Dao and so we issue a DVP to every member of the Dao with the secret and let's say for example here agency wants to go and communicate this to another dial but because we issued this through a DVP that third party won't be persuaded with high guarantees to that information but now let's say we want to collaborate with another group what we can do is we can have some internal proposal to say hey do we want to share this information with agent D if so let's issue a DVP again with our our wallet and they have agent DB part of that claim so now agent D is persuaded because they are part of the designated verifier scheme so I also want to credit here Enrico potatzi who's here and it works for polygon ID and we worked for through this and built some open source tools that allow people to go and build these schemes today as well and so what we've tried to highlight in this talk is that we have systems that can be built to achieve common p-belief but they're not as attainable as they are on distributed Ledger Technologies as we've started to see and we want to keep experimenting on that the way we've tried to rekindle these bonds between people to build and re refix context collapse has been quite weak and we need boundaries so that we can have these forms of intelligence and collaborative work across communities and so some experiments that our team wants to run with the communities is let's go and build a protocol where every claim for a DVP is with every claim within a dow is issued through a DVP so we can start to have some structure and maintain the Integrity of information within Dallas let's play with other commitment schemes with Community currencies or revealing vectors on an elliptic curve for how people commit to knowledge let's also build tools for anonymous reporting where if I want to come forward about a case I can do so in a way that first of all can leverage their knowledge technology but also attain common P beliefs so I know that other people are also going to come forward and they know that I will come forward but do so in a very protected way where we have a boundary around these claims and Via DVP and this can apply to things like social movements as well and so what I've tried to walk through in this talk is that there's something clearly quite powerful about blockchains but none of this had anything to do with staking Community currencies defy it was literally all about achieving knowledge and I think there's something really interesting about these cryptographic Primitives and something quite powerful but we've yet to understand how we can interweave these Primitives with the value that cultural communities can add to the community and so that's some of the work that we're trying to be building and working with the community to do that and so thank you foreign we have a few minutes for a q a are there any questions from the audience um how was what has been the process for connecting with communities yeah I think right now because it's so early the work it's been I think Enrico and I only release a lot of the DVP stuff in the past two weeks so it's been small Outreach to the communities that we're part of but part of being at Devcon was like reaching out to Dao's here and talking with them to see is there an interest in working with these DVP schemes and again I think part of even me speaking here today is to have the audience or people who watch the recording to come and work and find us to find ways that we can just be of value all of the work we're doing is an open source and so the goal is to just see how some of these ideas can facilitate some of the outcomes with the communities we're trying to work with and so we would also like guidance on how to work more with the community as well and are you focusing on dials then and crypto communities or also outside of crypto I it's really anyone who's like very motivated and as we can see with people here these web3 communities are very interested in experimenting with these tools so naturally it's a very nice vehicle to explore with a lot of these ideas and so the the Target right now has been webbed through communities yes and if there's oh I see another question and if anyone has any of the more technical questions I would love to work with everyone we're going to be in the ZK Community Hub on the main floor as well later in the afternoon so we can come and chat more about some of these DVP schemes as well there hi thank you for the presentation very interesting I just think when I hear your talk I was thinking how is that applied to ethereum conference so I think there's a context there's commitment for example when I go to buy the ticket for the for this conference uh is sold out within seconds later very fast but at the same time I have no idea how many ticket was been sold and so there's any uh anything from your talk that can help the ethereum foundation to to organize a better conference in the future yeah it's uh it's an interesting problem I think I'd want to think a bit more about it and if I do I'll relay it back to the community but I think in general anything that applies to a large group of people taking actions simultaneously so it feels as though you have teams or organizations that are all trying to get tickets how can we do so in a way that mutually benefits everyone I'd have to think more about it but I'll get back to the EF if I figure out a way that we can apply some of this to that problem hi I was just wondering if you could give a few more real world examples of this being obliged besides the KGB CIA down yeah I guess um I think like one example is like let's look at reporting internally in big tech companies in general for like sexual assault cases we want to make sure that when we come I want to make so for the common knowledge scenarios I want to make sure that if I come forward other people are also going to come forward because the risk is always on that first individual a much greater degree than any individual that follows so if we can coordinate in a coordinated attack way on a protocol that facilitates common knowledge the probability of each person taking action simultaneously will be higher but in the context of let's say what you're talking about with the KGB for dvps being a bit too strenuous even if I take any communication channel for any celebrity or any person who's high profile um let's say I'm the president of a country and I communicate with my peers I may not even be saying anything that's secret or relevant to National Defense or putting other people at risk but saying this information to an outside Community can be interpreted with the wrong context and so the only people I want to be persuaded by this information is by the boundaries that I draw on the people who have the context to interpret it appropriately and so I guess it's any communication Channel where people lack the context to interpret information and we want to mitigate persuasiveness to the third party hey how's it going what happens if somebody submits false or mistaken information so if you submit so again like the point here being is that if I am lying then I'm lying and then the third party is not persuaded by it I'm lying to myself basically but if the CIA let's say in this example lied there's no incentive for them to lie in this scheme if that lie unless there's like a broader set of incentives Beyond this like actual member registry or secret and so if I lie it doesn't do anything to the scheme because I'm just persuading myself in that scenario uh in the KGB example uh does the CIA then not uh reduce their ability to assert their authority to the general public then well the point being is like yeah in that scenario yes where we but we maintain the Integrity of secret information within the CIA with high integrity yeah yeah thank you with that I'd like to call on everyone to give our Applause for our speaker thank you everyone thank you [Applause]

Automatic transcript — names and jargon may be misspelled.