New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Confidential EVM: next-generation contracts - Harry Roberts | ETHDam 2024

CryptoCanalMon, Oct 7, 2024, 12:00 AM

Harry is a software engineer with a background in blockchain, currently spearheading the development of Oasis Sapphire and the Oasis Privacy Layer, security, privacy & distributed systems with the aim of making shared ecosystems easier to use, more interoperable, and open for the next generation of innovation. https://oasisprotocol.org/ https://twitter.com/OasisProtocol ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. In the dynamic space of ETHDam, privacy and security took center stage, featuring groundbreaking discussions on hacks, recovery, and the revolutionary work of figures like Pertsev. Privacy is dead in crypto, people that know, know. People who don’t know, should know. ETHDam is powered by CryptoCanal, an education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zürich. Keep up with us to see updates on future events: https://www.cryptocanal.org/ Follow CryptoCanal on X: https://twitter.com/CryptoCanal Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz We would like to thank our partners that made this event possible. 🌷 Battleship Partner 🛳Oasis Network https://oasisprotocol.org/ Jet Ski Partner 🛩⛷ NEAR https://near.org/ Canoe Partners 🛶WAKU https://waku.org/ 🛶Trail of Bits https://www.trailofbits.com/ 🛶Avalanche https://www.avax.network/ 🛶Privacy + Scaling Explorations https://pse.dev/en 🛶Threshold https://threshold.network/ Our Canoe Partner & Official Node Provider 🛶dRPC https://drpc.org/ Sponsor 🤝EF Ecosystem Support Program https://esp.ethereum.foundation/ Paddle Partners 🚣ChainSecurity https://chainsecurity.com/ 🚣Lido https://lido.fi/ 🚣Cyber Capital https://www.cyber.capital/ 🚣Diva https://www.divastaking.net/ 🚣Firn Protocol https://firn.cash/ 🚣Beefy https://beefy.com/ 🚣0xbow https://www.0xbow.io/ 🚣Obscura https://obscura.build/ 🚣Panther https://www.pantherprotocol.io/ 🚣Maven 11 https://www.maven11.com/ 🚣Zama https://www.zama.ai/ 🚣zkSync https://zksync.io/ 🚣Secret Network https://scrt.network/ ETHDam AfterParty Fren 🥳Bitvavo https://bitvavo.com/en Chapters: 00:00:00 - Introduction to Confidential Contracts and Confidential EVM 00:44:00 - Verifiable Infrastructure 00:01:40 - The Use of Secure Enclaves in Devices 00:02:00 - Trustable Execution 00:03:13 - The importance of cryptography and encryption 00:04:49 - Strategies for Security and Resilient Infrastructure 00:06:29 - Verifiability and Neutrality 00:08:05 - The Challenge of Data Recycling 00:09:36 - Privacy and Protection in Technology 00:11:10 - Transparent EVM and the Limitations of Confidential Smart Contracts 00:12:47 - The Self-regulating and Autonomous Nature of Composability 00:14:20 - Cryptographically verifiable chain of signatures 00:16:05 - Privacy Systems and Tradeoffs 00:17:43 - The Importance of Confidential Contracts in a ZK EVM 00:19:14 - Designing a Confidential EVM 00:20:47 - Challenges in Smart Contract Development 00:22:16 - Advantages of Confidential EVM 00:23:52 - Interacting with Web 2.0 systems 00:25:33 - Bounties and Hackathons

Transcript

[Music] yeah hi everyone I'm Harry I'm from Oasis and uh we're looking at uh sort of confidential contracts and confidential evm and uh what is like next Generation contracts which uh so I think that the first thing we have to think about is well what yeah what is confidential AVM why do we need this and then I'll look into so the current generation of smart contracts what is the current generation what are the technologies that they use and the sort of kinds of things that you can do with them and what can we do what do we want from the Next Generation that that solves a different set of problems uh so I do want to start with a bit of context uh to try to give some idea of the problems and overall the the big problem at the moment is because there's so much of the infrastructure that we we rely on uh depends on trust and it's not necessarily like a way process to reduce or remove the the trust it's a like a war of attrition uh and it takes effort and constant reevaluation uh because like trust is really simple uh and trustless is often really really difficult so it requires forethought to be trustless and like vigilance and Analysis and uh sometimes it is like a sort of two steps forward and and one step back uh as we you know we can rely on trust as we become complacent and slip back into the the path of least resistance and um as a whole though I do think it's heading in the right direction and uh like secure enclaves for example are a big part of that that move uh we have them in our phones uh in our payment cards um uh in know authenticator devices and there's probably billions of of devices right now that use them uh there might be more secure enclaves than there are people on the planet and if they're not then there will be fairly soon uh but right now I'm focusing on the the two steps back bed right so in an ideal world uh everyone does the needful everything works perfectly although reality it kind of sucks right so as a a baseline for having trustless systems we have disinterested parties uh we can generally trust them through like reputation or economic or game theoretic incentives or just plain old disinterest right so they've got nothing to gain or lose but that's always not there not always the best incentive uh you know to keep a reliable system running smoothly if they don't care about it um so yeah a lot of the time that doesn't really work uh so we have regulations that try to enforce this and uh it's very difficult to be a disinterested party if there's money or anything at stake so we need to to try and enforce this in meat space and that's all because we're trying to design these resilient systems that um really in an Ideal World we don't need regulations to be enforced in meat space we shouldn't necessarily need uh laws they should just uh you know in practice they should work and we want to enforce like this consistency and reliability through uh like real universal laws so thinking of mathematics cryptography uh like code silicon logic and uh at the root of it it all sort of boils down to uh either physics or like intractable logic problems and um we want to use these sort of intractable laws to create the systems and we have to encode them in the the rules of of that system in a way which is self-regulating it's self- enforcing and it's uh like self-evident that that it's correct um unfortunately there's a a Australian politician who said you know that the only laws that apply in Australia are the laws of Australia and I beg to differ because you didn't have to write a law to stop the people falling off the bottom of the planet and they also tried to do some silly things like in the US they they declared the cryptography is ammunition and uh they impose export controls and in some cases actively try to sabotage it uh and are they trying to do that to to prevent people from creating systems which they can't control I feel it's kind of sinister uh if they if I can think of like an intractable logic problem or a mathematics problem uh I should be able to demonstrate it that it does work that it is intractable that you know it's resilient and autonomous and this is why I think we do really need cryptography and encryption so signature schemes multiparty computation uh zero knowledge proofs and uh secure enclaves and all of these things working together so so we can protect us uh and protect our infrastructure uh regardless of whatever the people in power in a year four years 10 years are going to change their mind on and I I try to describe it as we need to sort of wedge the the door open so you can't ever close it and uh it's yeah this this takes uh this is the difficult route that we have to go down um so what are some strategies for security about how can we create this uh like trustable resilient infrastructure uh part of that like Independence and autonomy at every layer that when they're combined they strengthen and reinforce uh the other layers uh if we look at end to end encryption like many times it's not really end to end so if a great example is like ethereum IPC infrastructure uh we have this resilient blockchain of variable execution of smart contracts but you probably don't usually run your own ethereum node or even like run a local Fork of it uh so you take the path of least resistance and you use an RPC provider and you know your dap needs to query the smart contracts and use SSL to securely connect to the RPC provider and it does the query and Returns the result but there's something wrong with this which is H you're still blindly trusting the RPC provider with the unencrypted query uh and it returns a result which is not verifiably correct uh so again you're doing all of this work and then it's not end to and encrypted it's not verifiable it's not it relies on trust and you're not sure like are they keeping logs forever or if they say they don't keep blogs how do you really verify that the RPC provider May promise to be neutral uh and they might promise to not sensor your queries or they might promise to evaluate your contracts Faithfully against the the data you request and not modify your results and not log your requests and access patterns um but just like with the the politicians they they're only promises right now and uh there's no sort of real enforcement of this that that is independent of of whatever the whims of the the humans are involved so it can change at any moment and uh yeah so because it's not verifiable infrastructure you can't guarantee true neutrality you don't really have privacy um and it's not enforced in any meaningful way so you've basically just gone and circumvented everything that made it autonomous and independent and you might as well you know put all your stuff in a database in the cloud because it's going to be easier to use you know it's a lot of these l3s is just overly complicated you know why do it the real way or just use the cloud stop sort of uh doing I don't know this the stuff in the middle um they're kind of halfway Solutions you know uh they're making big compromises and uh this isn't really where I thought web 3 would be uh and maybe it should be somewhere else so the other problem is data so we're trying to think up some anal iies for like what is data like is it like nuclear waste or is it microplastics or Asbestos and unfortunately it's everywhere and we can't really recycle it like what is data recycling uh you know most kind of data we we really don't want it to be recycled in in any way at all uh because you know the the nature of it is that we uh we can't put it back in the box once it's out there uh but every cookie Banner you see on on the internet where you say yes or you just click the button that that's data Recycling and um it took 10 or 15 years for for SSL and https to become a standard and a handful of more years for Drive encryption to become the norm because you know if it gets stolen on a train you don't want them to access all your your data so now everyone's phones and your laptops are they're encrypted by default and you know just as we started to encrypt all the the servers and the devices we move everything to the cloud where where it's all sitting basically un encrypted so even though the the servers may be encrypted uh there's still you know hackers CIS admins the law for example uh can get access through the software that's running it we've got the software updates where uh you know sometimes we're not sure if it ever gets deleted and now we're putting all of this unencrypted data uh on the blockchain and like due to how it's structured by from the the get-go that's that's there forever and we can't delete it and when I think of blockchains now I think it's like the the elephant's foot in uh in the basement of the Chernobyl power plant where you know for every benefit it gives us it's it's also a little disaster that that we're not sure is really happening until it's too late and we've got all this data and it's out there forever so I think uh one of the things to think about today is how can we combine all of these different Technologies to have privacy and protection by default at at every level uh to have the sort of verifiable infrastructure uh and ideally to prevent the the unnecessary accumulation of data in public uh so it's like waste data right uh and all of the the blockchain history it's it's a byproduct of an inefficient process ultimately it would be nice to to have to choose specifically what's made public rather than having to try really really hard uh to keep certain things private uh so I'm going to try and get back on track and a little part of all of this is stuff that we at Oasis work on and I hope it fits into this this stuff that I've been talking about and it's essentially confidential smart contract so uh we have an evm compatible chain just because we solidity in evm just happens to be what everybody likes and it runs inside a secure enclave and we're experimenting with this like small but important difference to find uh s of new things which weren't possible without it and I I do like to look at like uh the early days of etherum where we're trying to go what can you do with smart contracts and I think it's what can you do with confidential smart contracts and uh there are some big problems that uh may or may not be solved with these in in the next you know handful of years but we we want to see what we want to find out so uh we need to make a big distinction so transparent evm uh which is ethereum polygon arbitrum optimism or whatnot and this is also applies to all sort of transparent chains uh with smart contracts not just evm so with a transparent evm the co data is not encrypted uh even if you encrypted the co data it's like the parameters for the contract uh a transparent contract can't keep that information private uh so its runtime state is visible to everybody and so is its storage uh so you know the execution is verifiable and it's deterministic but it can't by Design really operate programmatically on encrypted data without delving into some really interesting areas of you know math re encryption like snarks multiparty computation and you could have it like mediate encrypted Communications and you can have little bubbles of privacy but it's limited to S of subsets of of the functionality you don't have a full programmability uh and you know as a whole it's missing one critical thing which is a transparent evm it's not confidential or encrypted and in the real world that's really really really important so uh yeah I'm I'm surprised it's as popular as it is but it it's popular because we have modularity and composability and like the verifiable nature and Independence and uh sometimes it's really fast and uh in theory there's no barrier to entry so uh one of the the Beautiful Things is you don't have to allows a load of paperwork in compliance or set up a startup just to use it you know you don't have to ask for permission and generally it's self-regulating and autonomous and it's resilient which these are the properties that we we really want out of the system so realistically it has its own laws regardless of uh what the politicians that are saying this week or or month or whatever and that's in which jurisdiction you know so we we're really trying to create a system that's uh uh that that means that we can't change our minds and it it's going to carry on Independent of us so I'll go very very briefly over you know um uh some of the details if you are familiar with Intel sgx uh if you're an expert when it comes to this yeah I'm sort of fudging some of it for Simplicity but we we have a a smart contract that that it runs in the the secure enclave and we have endtoend encryption between the browser and the contract so you have the contract that's inside the secure enclave and we have a like a rotating call data key so only nodes which are in the the compute committee are allowed to have access to the the current call data uh encryption key uh and they have to prove that they're running a specific software stack with the most up-to-date version of our chain uh updated bios U Intel uh micr code for example and only through attestation process can they get access to the the current keys and uh that means that there is a cryptographically verifiable chain of signatures uh all the way down that says the software that I'm interacting with uh is part of this committee that has a key that I can encrypt stuff that only it can see and I can verify end to endend that it's only possible for this this Enclave to to have that key and uh with a basis the we're using a compartmentalized key manager so you can see it on the the right there uh and again that also runs inside the secure Enclave so importantly the confidential evm nodes they don't hold the master key they're given uh access to a limited subset of the keys based on what they need to compute on a a case-by casee basis and uh yeah so because execution happens in the secure Enclave with encrypted memory that means the the no creaters can't see uh the contract storage they can't see the runtime States uh they can't see the cool data that you send to the contract to invoke it um and if we look at like what is the the sort of State ofthe art in comparison to that at the moment and how does it differ from what we would like confidential evm to be and I think you have to make a distinction between like the single purpose system so uh versus General verifiable comp confidential compute and you can even go a little bit further and make a distinction between uh systems like ZK VMS or uh stuff that uses multiparty computation fully homomorphic encryption and uh something that we you know has the right set of tradeoffs like if we look at what is and what isn't feasible what is realistic now uh where are these tradeoffs you know so with the the single purpose privacy systems they're really limited you have like transactional privacy or encrypted Communications and storage that's like uh like Monera rail gun or signal and WhatsApp or even your your you know encrypted hard drives then you have things like alio or or Mina or or even ZK evm uh but there's an important difference with everything that's ZK based versus what I think confidential evm should be uh with all of the ZK based systems you can prove that you comput did something and you know the data involved in that computation it can be confidential uh you know in the example of like ZK evm confidentiality is not being taken advantage of nobody really cares that it's confidential because you have the succinct short verifiable computation proof that makes ZK evm you know something wor that's worth doing but uh if you take a like if you want to make a DEX or an order book or something that uses data with interaction between lots of different people at the same time that's really difficult to do with with ZK based systems because uh fundamentally you know a contract to do this efficiently would need to have its own private State you need to have something similar to the centralized exchange where they run the order book they can see all the orders but other people can't see each other's orders so you can't really do that with a ZK evm at least not easily so if if you have a confidential contract that can run the autom matching algorithm using all of this data then that that just it makes sense it does something that you can't do easily with with the other Tech and you know you can do it with a combination like multiart computation fully home oric encryption but that's really really slow and Incredibly tedious and uh if you've tried it you know try to convert some of these algorithms into circuits that you can prove with multiparity systems you compile to millions and millions of gates and uh it starts taking hours and hours to to get the proofs which slows everything down and really if we're looking at the tradeoff of using a secure Enclave with little to no overhead in comparison to to the other sort of State ofth art uh I think that that's hitting the The Sweet Spot for me and that's why I I work for a Oasis rather than on on ZK or NPC stuff because I I would be if these guys didn't exist uh so something that that's really really important for like uh smart contract chains is like composability so that's the contracts that are interacting with each other uh because you got like programmability and functions can be added later on by anybody so they can make it do stuff that it wasn't originally intended to do uh the contracts can be upgraded you can have even like modular plug-in based architectures and with like a confidential evm that's using trust execution you don't have to design all of this up front and really the the value comes from the composability and if you have a lot of unintuitive constraints that are pushed on you you have to Design Systems in a a very different way um so yeah it's we want something that's compatible with evbm uh we want something that has the minimum number of modifications that's necessary for your for your app so uh maybe a little wrapper plugin that adds encryption but you know to your adapt that you otherwise don't have to rewrite everything uh although you know we also want to be able to emit public information so we're defining a confidential evm the events should be public we should be able to it should be able to decide what is and what isn't private on a case-by casee basis um so the problem is that there are a few other complications that come with designing a confidential evm style system and uh one of the constraints we had is to prevent denial of service you can't really an anonymize the gas payer um so you see which accounts paying gas and the gas price and the destination address and how much gas was used in the transaction and of course like the events in which contracts emitted you know the events is also public and there are other a couple some subtle differences that can uh make smart contract development difficult so one of those that surprises people is you can't impersonate accounts uh so if you had a password manager you wouldn't want anybody like on ethereum you can simulate a transaction from anybody to any contract and see how it would inter you know how it would operate if you did that but if we you have a password manager you don't want somebody to be able to execute the password manager as you and say dumple my password so we have to come up with a a different way of authenticating users and uh one of those is like uh think of the the sign in with ethereum you know if we need a confidential evm we need a different way of authenticating people and that's that's very different from just connecting your wallet so there are a couple of places where everything's designed for transparent evm and we're only just discovering these problems that that have uh sort of significant ux impact so but one of the things we're doing is we're just setting the message sender to zero if it's a query that's not signed and that's kind of like a protective measure to prevent people from relying on information that uh could be impersonated or is not trusted I've got two minutes all so the second one is side channel so you've got the gas usage that can reveal which code path has been taken uh and this does make it does make it a bit brittle um and also the or order of events that are emitted is also another point where in comparison to transparent evm you have all of these problems that you didn't have to think of before and you know that's a problem that people don't usually think about so uh the other thing is uh confidential evm allows you to solve some problems in radically different ways so uh you can have a a a contract that generates a key pair and rather than having a relayer infrastructure you can have the contract sign a transaction for you and pay its own gas from an account that that manages it and if you look at all of the ethereum standards as they are now and you reimagine them from the confidential evm perspective uh you can get a rid of a lot of the the external infrastructure you can take completely different approaches to problems and also confidential standards none of our standards really have like confidentiality at the root of it so there is opportunity to reimagine what would the ethereum ecosystem be like if uh these contracts were encrypted and confidential and one of the things that comes with that is is uh there are some really really use useful building blocks that you just have to have accessible so one of those is uh uh a random number generator that the contract can generate key pair you know secret keys from and then well if you're generating secret keys and key pairs then why not have signing algorithms for all of the widely supported uh curves like you know uh the Bitcoin curve ed25519 and also the nist curves you know there is the the rest of of the world out there that's not using all this Bitcoin specific uh uh technology right and then encryption decryption to be able to have a contract that passes encrypted data through users back to itself or back to other contracts this is also a really useful primitive that you know without uh if you have to implement in solidity it just takes a lot of time so we have to provide this as standard and one of the big problems we're looking at is how do we interact with web 2 systems so if web 2 systems all using nist standards and you can have a contract that can act pretty much autonomously we need to be able to support uh for example the cryptog the cryptography that's used to verify Amazon Nitro Enclave attestations uh and with that kind of interaction with uh verifying attestations from other Cloud providers or from Hardware providers you can establish a root of trust in a confidential chain where it can then start controlling uh and orchestrating stuff in a way that you couldn't necessarily do before I'm running out of time so I think that the next question really is can we do confidential a AI we we do have a bounty for this and there is a big question of with endtoend encrypted AI are we making sacrifices now just because it's we need to get to Market to get GPT and we're releasing in all of this data into the public and it's being collected and it's going to be reused and and whatnot so we do have bounties and our hackathorn of course which we're sponsoring and there is an extra $2,000 Bounty if anybody wants to try and answer that question of how does confidential Ai and blockchain work together and of course we've got example apps so please I'll be upstairs if you're hacking come and talk and thank you that's that's me done for today w [Music]

Automatic transcript — names and jargon may be misspelled.