Digital pheromones: MPC for human connection & coordination by Vivek Bhupatiraju | Devcon SEA
Devcon·Tue, Oct 7, 2025, 12:00 AM
Speaker
Recent MPC research from Cursive and PSE enables a new concept called "digital pheromones": the ability to produce lightweight, privacy-preserving signals that people can use to coordinate safely and efficiently. The primary result we will cover is Trinity, a new 2PC scheme with nearly ideal UX/DevX, built on the trio of PLONK, Garbled Circuits, and KZG Witness Encryption. We will do a live demo with attendees and explore what a future filled with digital pheromones will enable! Speaker(s): Vivek Bhupatiraju Skill level: Intermediate Track: Applied Cryptography Keywords: MPC, Privacy, Use cases of cryptography Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/
Transcript
[Music] we have time to talk hello and hi uh I'm Vivic I'm gonna be talking about something that uh I've been working on with my team cursive called digital pheromones and the overall kind of affordance here is using NPC or multiparty computation uh for human connection and coordination so I want to start with kind of trying to Define this as as you know as we see it so far and for that I want to introduce first what is multi-party computation so this is essentially where multiple parties can come together they each have private data that they keep to themselves and they jointly compute the output of some sort of function such that only the output of the function is revealed and no like nothing intermediary or nothing about their like actual inp puts themselves um it's actually a fairly old technique a lot of the stuff that people are currently using is dates back to like the ' 8S 1986 and yeah has just uh gotten a lot faster and and and more performant in the past few decades I also want introduce like biological pheromones if that's unfamiliar for any folks um it's a chemical sub substance produced by an animal and it's generally used to basically um get individuals of the same species to coordinate or work together and some sort of way and there's a bunch of different option like bunch of different ways this happens like for for bees for example it's about like sort of setting off a signal and bringing a whole like swarm of bees to come together in one place a lot of animals like mark their territory using scents uh and there's also a lot of like sexual pheromones for different animals to Aid in their mating so digital pheromones kind of comes from combining these two different ideas and I think I would Define it in three principles at least at least right now as as we sort of played with it the first is that um this pheromone is a very lightweight and privacy preserving signal um it's it shouldn't be very heavy ideally it can just be transferred across like something like Bluetooth or some sort of like uh low energy Network and we we use it just to discover connection and perform coordination very similar to how this works biologically another requirement or kind of principle is that this stuff is fully programmable and verifiable um you can choose what conditions you want to reveal and also like because we have amazing Tech uh from from ZK land you can basically ensure that a lot of different stuff is actually verified so that people aren't putting out like sort of false pheromones and like essentially getting connection when they shouldn't be and I think a final requirement for this to really feel like almost like a a part of nature like as a as a biological fermon is is that this stuff happens in kind of a neutral peer-to-peer cryptographic protocol um we don't want this to be kind of within the ecosystem of a single app it should be something where you can use whatever front end and app you want but there's sort of like some sort of standard between them to be able to communicate and coordinate and ideally we don't need a server for coordination if a server can help in a way that's still privacy preserving but can sort of make ux better I think that's fine and broadly I think we think digital phones can help in two types of sort of like human connection uh discoverability and improving depth of connection so with discoverability a lot of our current stuff is based on like AI algorithms and advertising markets who basically like have all of your personal data from what you do on the app and their objectives are to keep you on the app for as long as possible and to maximize the amount of money you're spending with something like digital phones and the suite of cryptographic tools it's built on uh we get to a place where we can have full ownership over our own data using tools like signatures and zkps and use stuff like NPC to have these sort of like really safe programmable controllable interfaces to learn more about the people you're interacting with and in terms of depth of connection um I think right now in the in the current version of the web there's basically no verifiability on a lot of data you kind of just trust public profiles as they are and as a result like you know like there just isn't much depth and the other kind of twist of this is that often times these profiles are very sort of like public sanitized versions of who we are we're kind of playing to whatever game we think the algorithm will like or what other people will like with something like digital phermones it opens up a world where you can actually have all this stuff be verified and provable and because you are custody it privately you have control over how it's used uh ideally you can share more interesting and deeper personal information and thus facilitate better connection better matches all that sort of stuff and yeah using tools like NPC and this tool called a private seter section or PSI that'll introduce um you can do this in a very safe and um just sort of like efficient way cool so I want to just go through like a bunch of different like kind of use cases or general sort of like features that we think this sort of thing could enable some of which we've built out some of which we're still trying to figure out how we can make efficient uh just needs more like research and stuff so the first is idea of narrow casting so narrow casting is the opposite of a broadcast and the idea here is that you can basically choose a set of criteria uh that you want information to be reached or sorry choose set of criteria for people that you want this information to get to for example if you're throwing like a really exclusive party um you can basically find people that are in your city and find people that have certain other connections and certain other stuff and the cool thing about it is that this information is just like encrypted nonsense to people who don't match this uh but for people who do they can decrypt it and see this information and the idea here is that this can basically in enable more efficient and also like you know you can keep this sort of criteria private to yourself so basically like a a better interface to get information to people versus just like depending on an algorithm to do this for you another one is the idea of unbreakable consent so in in multiparty computation there's a general sort of like flaw or bug which is that in this computation someone can always drop out of the process and this can either like break the whole computation or potentially they can get the result of the computation and leave before other people do I think in the context of more like human facing stuff and especially for something like 2pc um this I think actually is a feature uh basically you need full consent across all the different parties for anything to be like verified or like revealed and so I think basically you can build a system in which consent is literally like mathematically baked in instead of you know just depending on the platform or other things to to do that for you another IDE is idea of super connectors so essentially idea here is that again like algorithms like stuff like Tinder and hinge are being used to basically sort of bring people together match them on different criteria and they're kind of this like Overlord that works with whatever incentives they want and we think this technology potentially could have the benefit of letting humans be those connectors for each other so you can sort of receive like privacy preserving like summaries of your friend's data in a way that's sort of like still private but you can still do computation over and then you can basically just be like hey you two should meet or you two like have a lot in common uh in a way that's like basically going through like a mutual friend instead of through an algorithm but still maintains privacy couple other quick ones um I think basically this generally allows for like more direct connection between two different parties uh in particular for businesses who are trying to you know do something like ads uh this can just happen this coordination can happen directly instead of like someone like Facebook custody all the data like providing the market and sort of you know taking a cut from that this other feature that we're hoping to build soon is basically something like I'm feeling serendipitous where you can just walk into a public space you can like put out a bunch of different sort of like privacy preserving signals of the sort of people you want to meet the sort of things you want to do and like I guess the upshot of this is that you can just sort of like privately manifest like the kinds of people the kinds of things that you want to do in the moment in a physical space and because it's all digital you can just send this over the internet as well through like encrypted channels finally like another one that's like a personal favorite of mine is like because this stuff is peer-to-peer very lightweight you can imagine just sort of like putting this out these signals out to your Community to your like neighbors and there's all sorts of like little like small coordination stuff you could do with your neighbors um that would be super useful that maybe it doesn't make sense to All Join the same social app and like you know put a bunch of information up but on some sort of more neutral protocol for example you could do things like oh like someone else is like looking for the same grocery or the same like other item like I'll just pick up some extras and then give it to them um if you need help with certain like house repairs or certain things like you can just query like hey like who nearby like you know how knows how to do this thing and generally like discover fun overlaps and intersections with the people who live close to you as a way to more easily connects cool so now this will progress into sort of the more technical part of this talk which is basically just what sorts of actual cryptographic tools are we using here to build this sort of thing um I'm going to go through some past stuff and then some upcoming stuff as well so the first one is something called private St intersection this is a really classic cryptographic technique um and the overall kind of like affordance here is that you can basically discover commonalities in a way that doesn't reveal anything else and you can apply this to anything from just like a ordered set to just like arbitrary data and so for example like people can just attest the different interests and then in a very very efficient cryptographic interaction discover only what they have in common and this can also basically expand from just two parties to be a group of parties uh for for coordination sort of things like for example calendly is sort of some like weak private like not cly I guess uh like lettuce meet and these sorts of things are kind of like a weak PSI where you like manually enter your stuff and you see everyone's availability so I think some nice things about PSI is that it is using privacy in an offensive way which is that basically you can put out a bunch of data about yourself and the only things that are going to be revealed are what you have in common with other people and just in general like I think the risk of sort of negative side effects for something like this are much lower because at the very worst case even if it is something like weird or personal it's like shared by the other person and this this contrast with tools like zero knowledge proofs where actually the goal is to share as minimally as possible you want to basically only reveal what you need to and then hide everything else I think PSI is also very conceptually easy to explain I think like out of all the different cryptography that I've worked on this is the one that like a general person lay person can pick up and understand the fastest but at the same time it's a very like rigid protocol it's like quite simple uh it's not very expressive and often in these sorts of like matching and Discovery things you want to do more complex operations so that takes us to a second tool that we've been working around with which is multiparty fhe or fully homomorphic encryption and I'd say the general sort of improvement here is that for especially consumer devices that are involved in this process there's a much like lower liveness and compute necessary than for a lot of other types of NPC so the general kind of flow of how this works is that I guess like a little bit of a primer in FHA you essentially can have like some sort of key that you can encrypt data to you can do operations on the encrypted data and then if when you decrypt this it's as if you did the same operations on like the like plain Text data and so in this case how we make that work in a multiparty setting is that there's three phases the first is that Alice and Bob or any sort of group of people come together and create a collective public key this is done in a way that none of them know the corresponding secret key so all of them can encrypt data to this public key and they know that no one else will be able to decrypt it within their party so once they've all sort of encrypted to the same key you can now do operations across it and so now you can take different people's data and you can do whatever operation it is uh like literally anything you could Define and get to some encrypted output and then finally because no one actually knows the secret key which you need to be able to decrypt this you need to do like a collective MPC to basically do this decryption and like in this case this is literally just building a PSI with um this multiparty FHA which is actually something that we've done in the past uh there's a really nice sort of like tool kit called ring learning with errors that essentially enables really efficient private set intersections on like an ordered set and so this is something that we've built out in the past uh works really nicely however there's still a bunch of rounds here in that the parties need to come together on every single computation to make this shared key at the beginning and come together at the end uh there's this new approach that was pioneered by Gus Labs uh which essentially can remove this sort of first step of the process everyone uploads just a public key and a server handles the process of essentially creating a shared uh like Collective key and then everyone can encrypt to that and then you still have the sort of collective decryption process at the end but you can skip this first step which is really really nice for a lot of applications so once thing we built on top of this was um at Frontiers uh conference in SF we basically built this sort of like private job matching setup where essentially as a job candidate you might want to have privacy over the fact that you're looking for a job and like what kind of salary you're looking for especially if you're currently employed somewhere you don't want to like mess up relationships but at the same time you should be able to find the best stuff that's out there and so what you can do is you can essentially encrypt your own job profile you can attach dkps for verification all that stuff and if other people also basically make postings that are private which maybe you want for like some sort of stealth role or generally just like don't have to put this data up publicly you can basically discover overlap in this both in terms of like the sorts of characteristics of the job and what the the candidate wants as well as like salary which is a more private thing of like the recruiter is willing to pay this much um and Below whereas the candidate is willing to work for like this much and above and you can just discover overlap in that without you know revealing those numbers too early on some really nice things about multiparty f is that the actual computation involved here can basically just be fully offloaded to a server and and so as a result of that devices only need to do uh generation of public keys and uploading that and then doing encryption of their data uh at least the ladder is a very cheap operation and the first one is a one-time thing the unfortunate thing is there's actually still quite a bit of back and forth rounds involved in this sort of thing where there is still this kind of final decryption step which can make for really weird both ux and devx and finally unfortunately with a lot of this stuff at least in its current state the data blow up here is immense where the public Keys you're using the different encrypted data uh grows in size a lot because essentially you're adding a bunch of like sort of noise to this data while still preserving its structure and as a result of that there's a really big blowup that can be in like tens to hundreds of megabytes uh which just doesn't really work on for most applications cool so I want to talk about um a new research result that's uh was built in house uh called Trinity which we think answers a lot of these different questions uh in particular it's it's a instance of a general form of of computation called non-interactive secure computation uh with an added bonus that it's verifiable at least the the the inputs uh their properties can be verifiable it's a combination of it's named this way because it's a combination of three different schemes the first is Garo circuits uh which is very classical technique uh casg witness encryption which actually came out this year uh really really beautiful paper uh very simple results but very powerful and finally uh good old plunk or any sort of like kzg based CK snark that's not grth 16 SC 16 is like weird so just a brief primer on each of these things gar circuits basically enable two different parties at least in the classical setting to compute some sort of function and there's this initial sort of like phase where one person sends over a garbling of the circuit which is basically like a uh a version of it that is sort of like hidden and like encrypted in a way and they sort of encrypt their own inputs into this but then the other person in this case Bob he needs to know his own encrypted inputs and so these two parties engage in what's called an oblivious transfer which basically Alice can send Bob's encrypted inputs without learning what Bob's actual inputs are and without Bob learning what the other encrypted inputs would be and this oblivious transfer technique unfortunately has a bunch of back and forth rounds so it gets us to about the same place in terms of rounds as like multiparty FHA the nice thing is this very recent result basically saves the day in that you can essentially I'm not going to go into the mathematical details but the high level is that you can essentially uh create a constant Siz commitment to all of your different data and post it once you can post it on the blockchain because it's so tiny and other people can essentially encrypt in puts to this commitment and so as a result this is all a bunch of like the math behind this you can basically make the oblivious transfer one round and so as a result you can just send it with the garbling and the upshot of this is that to do a 2pc with somebody else I just need to send them one message instead of having a bunch of like back and forth communication finally uh the really nice thing is this commitment is a kg commitment which means that you can use other really really powerful tools like plun to basically verify different properties of this and because so much amazing engineering work and theoretical work has gone into this this can be really really efficient and so you get basically both this sort of one round computation but then all the inputs you can basically have a proof that they satisfy different properties and yeah so as I mentioned basically there's just one round of data transfer and you have these like succinct very efficient validity proofs of all these inputs and actually Alice's inputs as well and so we think this can basically enable a really simple devx and ux for building consumer topc apps and hopefully like more parties in that as well with some more research um again you can use sort of other tripal data and maybe the overall way to describe this is that you can basically just send like this is actually very similar to like narrow casting it's like kind of almost the same concept of you basically send like one encrypted email and the other person is only going to be able to open it if they sort of match whatever criteria or whatever like function you set there and so there's stuff from like hiring dating uh like event promotion that we think could be used could be built on this sort of thing and be made a lot more like safe and effici one Counterpoint I like to make is that uh you might ask like why are you doing all this fancy cryptography like you can just use secure Hardware which will do it way easier and honestly that's pretty fair but I think at least in the context of this idea of digital pheromones I think secure Hardware is very not neutral and it's also very not peer-to-peer and that you have a like a server entity that is basically hosting this stuff for you and you need to trust them that they're doing the right thing and also like if they are cut out of the process or they censor you or they otherwise just like are not accessible you're basically just screwed and I think cryptography enables something that is much more peer-to-peer interoperable can be sort of like a neutral Network very very to like you know natural phermones cool so where can you actually try this stuff um so first off if you go downstairs uh we cursive has a really really nice Booth near the uh registration desk like right after it next to the badge Creation Station and you can try a couple of these different things so first off is private set intersection um you can basically uh you get these little NFC chips and you can create a profile around that and you can start tapping and meeting other people and building a little social graph and then if you import other types of data which includes like some connections to GitHub or your Devcon events or like different sort of like forms you can fill out you can basically do this private center section process and discover commonalities and we're hoping to add a few more data entries uh over the course of this week uh so this can be more interesting um another nice thing we just added recently is that basically uh as you do more and more PSI and as you learn more and more about different people they're sort of this little digital flower and the more and more you have in common the more you discover about each other this little guy gross and so you can end the event with basically this this Garden of connections Each of which is basically representing of yeah how much you sort of have learned about each other or otherwise shared um you were promised a live demo today I'm so sorry um it is so close to being done and later in the week this will actually just be uploaded into the uh app and so there'll be this sort of digital phones tab at the end of or like in one of the like parts of the app where you can essentially do this whole process you can send out queries you can receive them and you can also like you know with this idea of unbreakable consent no one is going to learn that you matched with it until you basically opt into it and so at the very least we're going to try to just run back this job matching stuff and ideally we can add some more fun stuff over the week uh a couple other the shout outs so this booth that I mentioned is actually model in the form of a museum exhibition called cryptographic connections it's both a bunch of art pieces and educational content about how cryptography can connect us both with present tools and also um with stuff from the past and again it's right right behind registration next to the badge station and in addition over the next few days we're going to be running this cryptographic classroom we have a bunch of like blackboards in the back of our booth and I'm hoping to basically both get to explain all this research in a lot more detail to anyone who's interested as well as just explain classic cryptography constructions um I really like teaching people about cryptography it helps me understand it better um right now it's this is going to be running from Thursday and Friday from 10:30 to 12:00 p.m. uh we'll maybe do more sessions if there's more interest uh just come by the booth and express that want other times and we can probably make it happen a quick shout out for cursive uh we're exploring all sorts of different research and design work around cryptography for human connection and this is just sort of one of those Explorations and come by our booth if you want to learn about past stuff we've built and finally a really big shout out to proac scaling Explorations which is a sub team of the ethereum foundation uh our team is Grant funded by them and we've been able to do a lot of really great research exploratory work uh both on our own and also with collaborating with other researchers in the ecosystem and if you want to learn more about cursive here are some links for you to take thank you for listening thank you Vivic we have some great questions rolling in uh let's take the first one what prevents Bad actors from interacting over the host search space to recover preference data that's a great question um I think ZK proofs are the main tool here so that basically like you can require on the most important stuff that you know the attributes that someone has is actually ZK proven and so as a result it's like much harder to basically like just kind of like fish for information the difficult thing here is that a lot of stuff is just self attested and so there's other sort of like outof band things like rate limiting or maybe ensuring that you only get queries from like a friend or like a friend of a friend to ensure that you aren't just getting like spammed and kind of like you know read in a way all right and is there any DK Library I can use to build on MPC fhe yes so um the main tool kit that we use to build out the hiring flow and a bunch of other experiments is called Phantom Zone this is a uh multiparty FH toolkit built by G Labs mostly J maaya uh and some other collaborators from within PSC um this is a really great toolkit um I think it's performance uh bandwidth all the sort of stuff is getting improved but uh it's very great terms NPC generally there's a lot of great tooling coming from private scaling Explorations um like a toolkit to basically write circuits in typescript called summon uh there's an like a a garble circuit Library called mpz which is used by the TLs notary team um both of these are going to be what Trinity is built on in the long term so that it's very easy to maintain and improve but um yeah those are my current wrecks perfect and how do you reason about incentives to report things honestly if interest matching with PSI reporting every possible interest yeah that's a great question um I think for a lot of stuff like there's sort of like a humanistic layer to this where like you don't really benefit from lying in a sense like you might as well just put what you are interested in and then you would actually just genuinely get matched with that obviously there is sort of this still attack where people can just like say they're interested in everything and then just be like wow we all we like the exact same things so you know it's it's difficult for a lot of the self-attested stuff um and potentially there's other ways of doing it where like you limit it to just like your top three interests or something um like on a on like a query level but uh yeah all right I think we have enough time to take two more questions uh what is the operational Bandits or footprint overhead multiplicator for MPC FHA MPC right so basically I'll talk about the interactive setting because I guess that's what this is asking um there's this initial NPC which requires I think like o of n squ uh different messag me being sent well actually yes I think that's correct it's oven squ messages being sent to set up this Collective public key if you want to do it in a peer-to-peer way um or it's like I think you can have a server be involved and then you can lower that to maybe something closer to oen but there's that initial NPC the FH itself there's actually no as far as I understand no huge performance increase the fact that you're doing over multiple parties because you're essentially just doing like single key FHA once you generate this Collective key and then there's also also this NPC at the end which I think is also squared messages so the more this expands the worse uh with non-interactive this is a lot better because the server can generate this Collective public Key by itself um and then you know can sort of handle that first phase awesome and how does the creation of collective public key works for more than two people trying to share phos right um I think so again is this if this is in the like interactive setting you basically just engage in a like multiparty computation between people where essentially like you need to generate some like auxiliary data between each other to generate a collective public key in a way that like neither of you actually get to learn the secret key uh there's some really efficient ways to do this for certain schemes um and then if it's more than two parties you basically just expand that uh with
Automatic transcript — names and jargon may be misspelled.