# AnonKlub, Anonymous Proof of Ethereum Address Set Membership | Iskandar Andrews (January 2024)

- Channel: [Berlin Ethereum Meetup](https://streameth.org/berlin-ethereum-meetup)
- Date: 2024-10-07
- Duration: 15:49
- Watch: https://streameth.org/watch/yt-OLKgoSrdBew
- YouTube: https://www.youtube.com/watch?v=OLKgoSrdBew

## Description

Join us on Meetup to keep track of our events in Berlin: 
https://www.meetup.com/berlin-ethereum-meetup/

See you at the next one!

---

Apply to speak at our future meetups: https://forms.gle/5y9Y5ywZC7pSEqpV9
---

Twitter: @BerlinMeetup

## Transcript

so hey everyone thanks for being here tonight um I'm scand I work with the Privacy Skilling operations with Thea and uh today I want to talk about an Club Anonymous proof of ethereum address ownership within um with anous group so the goal is to enable anous group of membership of a unique set of ethereum addresses so um I'm assuming here uh like background um I'm assuming you've already encountered one of like these terms already ecdsa for example which is elliptic Cur digital signature algorithm and that's based on SB 256 q1 signature is required for three transactions and also you're familiar with z snars and knowing it's a way or it's a crypto primitive cryptographic Primitives to prove a statement without revealing the whole knowledge so if you have this already you would be fine the whole to uh um so why you're interested into uh ZK cdca why it's interesting or important right so I think one of the main or interesting examples would be airdrops uh like nowadays where usually the air drops are you have a list of addresses the people who can claim the air drops and they are um for you you can if you want to claim your airdrop you have to demonstrate your inclusion in a member in a miracle tree of addresses so that's break that breaks your anonity and using EA signatures could allow you to have some anonymity into this where um you just sent ZK proof of knowledge of a signature that corresponding to your ethereum address that uh proves that you're part of um a miracle tree of the air drops owners or claimers and uh the other the other applications would be un chat groups Anonymous voting Anonymous mixers Anonymous nfts so the all the all the main common thing between them all is um the uh the need for proving uh that you're part of a group and that that needs like a proof of uh membership and a membership of a group so in the context of ethereum that would require um that would require you to prove the ownership of an address within this list so that comes to you want to you want to prove that you have this address that belongs to this list and then you're going to use the ecdc signature but the problem here is um ECA signatures outputs are can cover back your public your public address so then what we can do is that we can put this in a snar so then we can um prove via having the signature that I am um that I have this public key that belongs to this list of addresses within the SAR and the outputs of the of the signature would be private inputs so the challenge is um so ECA is uh snar unfriendly and this is because um of the the bending curve uh easily say is the bending G so the snar friendly protocols um depending on uh like for example pm24 um which as you can suggest from the number it only supports the max maximum or like nowadays Zas not grouping systems have a maximum number of resistors of 254 bits but in the case of Zas Nike it needs a little bigger uh space so it needs a because depending on sigb and s q clipic curve cycle 256 K1 so if you have noticed already there are two two bits difference between both and this two bits could create or will create an overflow and what's called drwing field arithmatic and uh in order to resolve this um imagine you have a you on a tweet and old Twitter and you have like restricted some number of characters so you'll have to split your tweets in different uh tweets Etc so that requires it's annoying and requires much work the same in the ziki stuff so that will have like burden of adding more much more constraints all right so um the tools before or the work done before in this uh so for example from oire they have implemented the first implementation circuits of cir from ecca and as you have as you see here the time is the time taken is not good because what I've described already this one field as that um spocking the computation like or making it more complicated um so it takes 5 minutes to generate a proof from the server and and then the other project was uh efficient pcsa from Persona lab and they have um they had made a research to optimize the equations or the operations that you do um on the Sip 256 curve in order to get back the public key and their idea was is to extract some public stuff outside of the snark and make them pre-compiled equations so and that was pretty good like one minute um but the most the bit or the most efficient uh solution we had until the moment is having the same efficient or optimized equations but running them on Spartan back end uh snark system I will get back to snark in a moment to Spartan in a moment so um first here they Fork the circuit version to make it work with the b266 Curve and they um resolve it this right field arithmetic and uh the solution was or the the result was it taking around 60 seconds more or less depending of your machine on the proc without eing any servers the lastly um H from a and they have also library for supporting ecdc but uh we didn't I don't have benchmarking or time for that all right so talking about Spartan it's um implemented from Microsoft and uh it's a family of non-interacted Z know GRS and uh it uh for it supports C for uh R1 CS uh ability doesn't require thrust setup and we can work with any tic curve which what we need uh so the benchmarks for the part an e DCA as I mentioned before so it takes proving time around 40 uh 60 seconds and no GS 4 seconds which is which is good um all right so um I will show a live them now running generating a proof from uh pre created this thing or like a list of anonymous um Anonymous list all Nam fc20 and I should prove that I am having an address or controlling an address part of this list so um so I have already uh connected to my wallet and I'm going to go with to approve and then I have two uh two options so whether I should whether I go to onchain which has the a query server that supports dun apis and graft c apis um that allows you to uh allows you to to fit all the addresses that you need for your the Creator and Set uh all right but I would choose the on on a file which has already a file addresses that I've already um generated before so as you can see this is u a list of addresses oning ERT 20 with a specific range and I should I have an address um uh with this list already so our start first preparing approve request that will start by creating a miracle proof or a miracle tree structure and um including all the or the members within uh within the browser doesn't have any server and then I'll add just a message or any random message and we'll sign it so now it's like creating the tree and it's done and um like the notification here uh it was an old message before uh saying that we were using the server uh but now we don't use uh any server with the spart and ecdc and um yeah I can now submit the proof request so it takes around and iing in around 40 or 50 seconds and that that is the proof of having or yeah having the and belonging to this list and I can uh theud can take a look um I it's um it's a big number very big number okay so um all these console looks are like we're popping out from the Ros was in COD and I'll jump the next slide into how this is built or what's running behind the screen and what I can do now is using this full proof and uh verifying it from Spartan 2 so um I'll click proof or verify the proof and yeah not sure if you can see it really or not but this is what what I'm looking for the UI is not implemented yet to show it in a quter way uh but the verification result is true that I have um that my address is with this list so how this is BU um so first I I mentioned like there's this query server where you can just put any address of any nft or any rc20 and start setting the range and then it will fetch all the addresses on in that range and the main crates or the main the main uh components running in the in the browser is the mer Merle Tre rust tra which we had forkit um and and we had made it like buil it in a wasm code that you can that you can use it to run in the browser and and actually for this part specifically we have tried to use um the JavaScript implementation or the typescript impation for the miracle tree called the incremental Miracle tree from sore and there is results was the results were like really really different and bad so for the typescript implementation it took around one minute to insert 100 1,000 members each 1,000 members in a tree so the construction of three and the browser took around 30 32 minutes overall which was bad but the results with bottom code was significantly in very fast just in 4 seconds or something 32k of members and the three were created and yeah it's uh aome and um and other main component is the Spartan ecdc crate and it's the same like uh we had a fork adding some wasm needed functions and then um having the types strip wasm package and and this typ script uh was a package has what has web workers if any of you familiar with web workers so they work in a separate threads um yeah and and the whole uh the whole workers or the post workers are working directly in a browser without again needing any uh any browser so so what's next um is very interesting part of the of this scheme is like adding the ntif Fire part so having imagine like you want to plug the user to claim the air drop twice so you need a Notifier thing imagine it's like the nouns for transactions so um the N should have some properties um it should be deterministic it should be unique Etc uh but this is the what we're working on now and already there is a very promising um there's very very promising uh schema for uh project for supporting the 95 in in like as what we expect but still it's uh we just go PL but it's still it's uh in progress um it has uh already in progress ERC and um a PR for integrating this new nire schem inside wallets like mam mask um yeah I think that's the QR code for the GitHub so if if you're interested in the ntif fire specifically you can reach out and start um contributing and thank [Applause] you
