A happy family: ZK, TEE, and MPC! - Vanishree Rao
ETH Warsaw·Tue, Oct 7, 2025, 12:00 AM
ZKP, TEE, and MPC technologies are usually pitted against each other in our industry as different privacy solutions. This session explores their unique strengths and complementary roles in cryptographic solutions. Attendees will learn how to evaluate and combine these technologies to address complex security challenges effectively. 🧜🏻♀️ ETHWarsaw is a series of educational and entertaining events for an active community of blockchain builders, developers and enthusiasts with focus on Ethereum-related tech. Once a year, we organize a large conference and hackathon for the community in the center of the Polish capital with speakers from the best web3 projects and participants from all over the world. Follow ETHWarsaw on social media for the latest updates! X (Twitter): https://twitter.com/ETHWarsaw LinkedIn: https://www.linkedin.com/company/ethwarsaw Telegram chat: https://t.me/joinethwarsaw See you all at our events in Warsaw 🙌🏻
Transcript
hey everybody my name is vanishri um I am the founder of FMA FMA is a universal proof generation layer it is designed to generate proofs for any proof system in a cheap performant and reliable Manner and it functions as a marketplace where the supply supply side consists of any kinds of machines gpus fpd vpus Etc and uh as far as the demand site is concerned we can generate proofs in any instance where ZK is used that is what we are building and uh we are coming out of stealth in just a couple of weeks um and today I'm going to talk about not just ZK ZK is our main focus but we are not just going to talk about ZK but about ZK and two other very powerful crypto cryptographic tools multi party computation and uh trusted execution and M and the reason why we are talking about this is that as many of you may know um recently there has been a huge amount of debate uh trying to pit one against the other in search of the superior one and my goal here is to um say the following there is there is no one Superior tool but instead each one comes with its own purpose um and I have three main goals this is my first goal it is to to uh um let go of this misund understanding that there exists a superior one um and then the second one is to give some sort of a mental framework to decide which tool to use in which situation and then the third goal is to demonstrate that they are complimentary in nature by showing an application where they where all three of them can come together to achieve something that no single one of them could have achieved so effectively okay okay um so the agenda for today is that I'll first give you a framework the framework to think about okay you have an application you have so many of these cryptographic tools everybody's talking about them uh uh saying that one is better than the other what do you have to do uh how do you how do you how do you analyze the need of the application and the power of of tools in hand and how do you choose some tools versus others this is the mental framework right I'll try to give a mental framework and then we will apply this framework to these three Primitives right zero knowledge proves multi partic computation protocols and trusted execution environments and then finally we'll talk about data protected proving delegation this is something that we are working on here what what what is happening is that we are like I said we are bringing together all the three Primitives to achieve something that no single one of them could have achieved okay so first the framework I want to build up to the framework right let's start by noticing this fact this reality right in a kitchen think about a blender and a knife what's more useful uh knife is more useful when you want to chop vegetables while a blender is the APT one when you want to puree soups it's not that one is more Superior than the other uh more superior to the other this is exactly what is happening in cryptographic tools each one comes with its own purpose and um let's start with a cheat sheet of when to use which tool this is just a cheat sheet again we are building up to the framework so use zero knowledge proofs when you want when you use zero knowledge proofs if the situation is that one party needs to convince another party that some computation is done correctly and one of the two things hold you either want some part of the computation not to be known by the verifier that's the ZK part or you have this verifier who is very lightly resourced who cannot do the entirety of the computation it's right lightly resourced right um this is when you have to use zkp when do we use te um think of te uh the the the the aspect of te to keep in mind is um it's it's a a cheaper and a less secure version of zero knowledge proofs plus it has an added benefit that the person who is proving also does doesn't get to know what the secret is this is this is what the power of uh trusted execution environment is and then the and then when do we use multiparty computation protocols you want to use multiparty computation protocols when the power of uh the the the security level of trusted execution environment is not enough because you know the there are so many ways to break a te if your situation is in such a way that the the level of security that te gives is not enough or to begin with from the very get-go you the the the um inputs on which you want to compute the function is not just with one party it is with multiple parties then multiparty computation is the is the way to go okay so now the framework it's really helpful to think about about your situation as a as a puzzle right what let's say you have a an application where you are trying to figure out a c cryptographic solution um think of the situation as a piece of the puzzle and think of the tools as the other pieces of the puzzle and you're deciding which other pieces of the puzzles you need to put together to complete the puzzle right and this this isn't enough isn't enough this isn't the entirety of the framework the the core aspect of the framework is that it is is that there are three important questions very clear questions if you if you try to answer these questions it'll get you a long way in solving your problem um those three questions are what functionality are you trying to achieve what security do you desire what cost are you willing to pay right cost in terms of ux cost in terms of uh uh building it building the solutions Etc um I I'll get to I'll I'll add more flavor to each of this these as we go ahead but let's uh take the same argument from the other side let's start with zkp te and MPC and look at what functionalities do they allow what security do they provide what cost do you pay if you use any of them right let's start there um and then we will try to summarize everything that we said and try to have a a cohesive framework in mind the functionality that zero knowledge proves so even before I say that here is something that is very important to answer these questions right functional when you talk about functionality you shouldn't care about anybody acting maliciously the right answer to this question comes when you look at all the parties in your system as completely honest think of every party in your system to be completely honest and then see what is it that you want to achieve and that's the functionality right in the case of zero knowledge proofs there is a prer and there is a verifier assume that they are both honest with what is it that we want to achieve we want to achieve that the verifier gets the the pro convinces the verifier of the correctness of the computation even when the verifier is likly resourced this is the functionality there is no cryptography happening here yet when you describe functionality there is no cryptography happening it comes when you think about security right so what is this security that zero knowledge proofs provide you consider two situations situation one is when the prer is bad and malicious situation two is when the verifier is malicious when the prer is malicious what you don't want for this prer to be able to do is to convince the verifier of some wrong statements this is what we want right this is this is the security um this is the security that zero zero knowledge proofs need to provide this the the soundness property and when the verifier is dishonest you don't want the verifier to learn the secret information about the computation right this is the zero knowledge aspect about um about zero knowledge proofs and what is the cost the cost my belief is is that the cost you pay when you are using zero knowledge proofs now now with the presence of ZK VMS it's not so much in engineering but it is in in rigging up this network of provs maintaining them and and and incentivizing them this is exactly the problem we we are solving with FMA um and I believe that that is the heavy lift uh without FMA okay that's about zero knowledge proofs and how does the how does the piece of the puzzle of uh trusted execution environments look um so what is the functionality it allows for remember we said that think of tees as just a cheaper and a less secure version of zero knowledge proofs so it gives you very similar uh functionality properties somebody's running some computation and somebody's somebody's getting convinced that this computation is run correctly right this is basically it um and uh the security is that besides what was happening in besides what was happening in uh zero knowledge proof like I mentioned just a while ago there is this additional very interesting power of trusted execution environments that even the person who is doing the computation doesn't know what the secrets are so this is an interesting property that you can put to use in some applications cost sourcing tees maintaining them and incentivizing them ensuring that there is an optimal level of incentives for them this again just the way it is hard for uh zero knowledge proofs Pro improving here you have a similar cost multiparty computation protocols um multi-party computation protocols have a bad reputation that they are very expensive but you can actually in certain situations if if if you architect your system very nicely this these can be very powerfully useful and very efficient uh you need a systems solution there so um multi-party computation protocols as we know are you have not just one party doing the competition but multiple parties I have a secret you have a secret he has a secret uh we all talk to each other and find out something let's say who has uh who has the highest um we all hold a number in in our uh we all write a number in a piece of paper and uh then we figure out who wrote the highest number without any of us revealing any number to anybody right that's that's the really cool aspect of multiparty computation protocols functionality I give you a very high level example so let's formalize formalize it um multiple parties collaboratively compute a function of inputs that that exist with multiple parties right this is the functionality what is the security in this example that I gave you don't want any of us to know any information about the numbers that the others have except for the fact except for the fact that is revealed the the the highest value who has the highest value that's the only thing that is revealed nobody gets to know anything about anything else during the course of the computation during the course of the collaborative like in the protocol we talk to each other nothing is revealed from whatever we reveal to each other uh nothing else is revealed so that is the security you need uh you you get from multiparty computation protocols and the cost like I said at the very beginning they it's considered to be inefficient especially because um uh computation uh uh computation is not the uh is not the um hard part the communication is the hard part in multi-party competition protocols and um that typically is the case again um you can have system solution where this can get mitigated and and and and one shouldn't shy away from considering to use multiparty computation protocols okay so we looked at um the how to apply the framework for each of these tools and here is here is another important aspect about um the framework right and that is the following um how uh how do how do you think about the security and the cost aspect of your application it's not the same way as you think about the functionality aspect of your application it's more Dynamic right um functionality is very clear you're building an application it needs to achieve something that is not negotiable the level of security the amount of cost you're willing to pay that is probably it it's it's a more um flexible uh part of your puzzle um so so finding the pieces of your puzzle is it's it's not a very rigid process it's a very Dynamic process um and the graph here is to is to is to give another um cheat element to keep in mind that if you try to it it typically is the case that if you try to achieve more security if you try to ask for higher higher level of security you're likely to pay more it's very natural right it's you're likely to pay more in terms of ux or engineering cost Etc um and it is it is the the the dynamic nature of finding a solution to your problem is very clear here where do you where do you where do you want to place um where do you want to be on this curve right um of uh uh uh of of um the amount of cost you're willing to pay versus the amount of security you want right um so actually before before we go ahead um let's summarize I I talked in a very technical at a at a very technical manner but uh uh let's zoom out and try to see where this all comes together um back in the day um before crypto right there was there cryptography cryptography research had been very active it still is very active the the research is very active and and uh uh a typical a typical uh advice uh Crypt cryptographers give uh used to give to non- cryptographers is that uh don't do do your own crypto don't do your own cryptography we don't have time for that here in crypto we don't have time for that we have we are I think this is the way to go I I I I am guilty of subscribing to that kind of thinking back then but but that is not the way to go this is the way to go where where we build we break we build we break but but but very carefully though um uh because you you you you you uh Embrace technology at a pace where you cannot wait for all of us us to be trained cryptographers that is the that is the state we are living in and this is the way to be but um what is helpful when we're doing something like this is having Frameworks like these um and um it is good that we are Shining Light on uh very otherwise esoteric areas of cryptography um multiparty competition when I was working on Multi party competition 10 15 years ago I had I couldn't even have dreamt that something like that could see the day of flight but now um that isn't the case right so um want to go back uh I went to ahead yeah I wanted to stay there um so that is why I wanted a give a framework right we have been thinking about MPC we have been thinking about te we have been thinking about ZK uh pitting against each other trying to find what is the right tool to use in any given application and uh my thinking was to have to to to begin this consideration with a more formal framework in mind and I try to formalize that framework that was this part of the talk and now um um so the the rest of the talk is um the to mention something that we have been working on it is uh data data protected proving delegation um where all these three tools seemingly seemingly um competing tools coming together to uh to build something that um uh no one single one of them could have achieved um sorry I'm uh getting thirst here okay so this is a very cool concept right um it starts by uh it starts in a in a very real setting where you're trying to do ZK which is like like we said what is the cost you're you are paying for ZK it is improving right um and if you're having these phones generate proofs where for example um you're trying to prove something about your identity uh the proof needs to go out of your phone um worldcoin is an example when that happens um your architecture is not scalable with the increase in the size of the computation you want to prove or or decreas in the amount of resources your phone has uh it's not a future it's not a scalable architecture um instead what what if what do we have a way for for these phones to delegate these hard tasks to more resourced machines uh but there is a problem and what's the problem uh the computation consist of the computation is done on data that is sensitive right it has this personally identifiable data and that is why you the the whole premise of of uh doing computation on the phone is that it it it has sensitive data it has to lie with the with the users that is why you wanted to do it at the client side um but the but it's it's bad user experience U many of times you cannot even do it feasibly if you are using this old Nokia phones uh you cannot hope to generate proofs for sizable computation on these phones uh natural question how can you delegate proving while ensuring privacy or security of this data uh that is the main question right um the solution to that is is this protocol that we call uh data protected proving deleg ation um and this is what we are building and um here is the high level idea uh the the the Crux of it the the uh idea the core idea we are not the first people to think about it there is some amount of work but but we are productizing it by by having a system solution systems approach to it where MPC is not going to cost uh exorbitantly here is the idea uh you have your phone that has the sensitive information that is unable to generate proofs there are all these machines that are able to generate proofs there are multiple of them this machine secret shares this witness this uh this this sensitive data to all these machines secret shares uh in a way where uh no single share or even n minus one of the shares reveal anything about the data and then these gpus will talk to each talk to each other through MPC protocol and um there are these tees that are helper machines that are lying on the side to help you make the MPC as efficient as possible and then they generate the proof and send it back so you see there is you want to do ZK you're using MPC and you're using te was if you if you were to just do ZK and delegate Z delegate the proving it didn't solve this specific problem again because of the fact that it contains sensitive information so how do you solve is by putting all these thing all these three complimentary Technologies to together to achieve dppd um again Forma is building this um and that's all I wanted to say yeah uh uh so we are coming out of stealth soon um we are at fxyz uh please uh if if you're building in ZK come and write to us and uh um find me on Twitter DM or head over to firmar XYZ and uh there's a form there please uh fill it up and we'll get back to you thank you so much [Applause]
Automatic transcript — names and jargon may be misspelled.