# ZKpassport: Private Unforgeable Identity | Devcon SEA

- Channel: [Devcon](https://streameth.org/devcon)
- Date: 2025-10-07
- Duration: 19:31
- Watch: https://streameth.org/watch/yt-W6C-duDEiOU
- YouTube: https://www.youtube.com/watch?v=W6C-duDEiOU

## Description

This talk presents ZKpassport, an identity verification solution integrating zero-knowledge proofs with ePassports to achieve privacy-preserving and unforgeable government-attested digital identities. We will delve into the technical architecture, implementation challenges, and practical applications. Attendees will gain insights into the development process, benefits, and potential uses of this technology in enhancing digital identity privacy and security.

Speaker(s): Michael Elliot, Théo Madzou
Skill level: Intermediate
Track: Applied Cryptography
Keywords: Privacy, Identity, Zero-Knowledge, noir

Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon
Learn more about devcon: https://www.devcon.org/
Learn more about ethereum: https://ethereum.org/ 

Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more.

Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. 
Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024.
Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

## Transcript

[Music] all right there we go now it's uh another Globe spinning very cool took me hours to make that so I wanted to make sure you guys saw it um yeah hey everyone really great to be here I'm excited to talk about what it is we're building I'm Michael Elliot from yeah and I'm d as introduced from FR obviously we just got introduce so need for that again um yeah we're looking forward to to going through uh what it is we're building and uh the tech involved and explaining you how we built it and also uh why we built it so I'm pretty sure everyone in this room is quite familiar uh with the fact that online identity verification sucks I think everyone here has had the experience of um taking a photograph of your passport and setting it off to some service for for kyc verification um you know you got to basically trust them to keep that data safe uh hint they won't there's been you know many many um hacks and data leaks uh throughout recent years that just demonstrates that it's you know very difficult for companies to keep that kind of data um secure and this inevitably leads to yeah theft and uh uh identity theft and fraud and another downside of this is that you can't bring it on chain so another more recent kind of um threat to this par this model is generative AI um this is becoming increasingly Advanced and uh easy to access so this is an example of a a fake ID generated by a service called only fakes so it's it's currently possible to pay like $15 and you can have a a really genuine authentic looking government issue document created so what you know a high school high school kid could do this find a profile photo of someone on like Twitter and then easily generate something that would fool the KY of of some services in fact the article that um this is from originally um they tried it out and they actually managed a kyc on a crypto exchange and I think it's just going to get easier and easier for this to be the case so this completely breaks the model of um taking a photograph of your documents and sending it in so what if instead of this what if instead um you could reveal only what you absolutely needed to reveal for a particular service so for example if you just needed to reveal uh your country and nothing more then that's all that you you you need to diss um and what if you could generate uh unforgeable onetime proofs so onetime in the sense that you can't replay these so once they us are consumed by the service um they can't use it again so unlike a photograph which could obviously be you know if it's stolen it could be reused um what if you could prove that you're a person person and and not an AI or a bot who holds a valid passport and reveal nothing else about yourself um and what if you could use this on Shane I think we'd all agree in this room that that would be pretty damn cool and so uh okay Mike that's great that sounds wonderful but like how do we actually get there great question Mike well let me let me explain so most people might not be aware of this although maybe you are now um given the booth and there's you know kind of more more awareness of this but everybody in this room um on your your passports your e passports that were issued by your government on the NFC chip there's your personal information and your issuing government has digitally signed over this information essentially attesting to its authenticity and creating like a tamper proof seal so we're able to verify the signatures um we leverage this existing INF structure um of essentially like a government signatures and root certificates um that are used by airports around the world every day for by by governments to protect their borders that's a kind of level of security we we take these signatures and we can verify them um in zero knowledge and then and then eventually we can M another circuit we can disclose that um selectively and this allows the creation of these private and unforgeable proofs of identity and so you can actually leverage this so we're going to show you the app later but as a developer you can easily integrate this can you just oh yeah [Music] sorry so we have built like a SDK which is going to be usable easily to easy to plug for any JavaScript or web developers whether it's in the context of web two or web web 3 whatever kind of web app so it's really friendly strongly type typescript SDK so itive to use to choose which kind of field you need from the passport what kind of information you want it's going to really unlock like a lot of interesting use case we thought about some uh but we really curious to see what people can build with it maybe they're going to come up with something we didn't think about so that's something very curious about and this is fully nonprofit public goods so it's like free to use there's no restriction there's no payment nothing you just plug it in and you're free to go no API key whats ever so here's an example of how it would look so as a first version of our SDK typescript so you specify your domain name the name the purpose of what you're trying to do with what the PE the visitors or users of your website and you will get the URL which encodes all the parameters you requested all the fields you paramed and then you can encode that into QR code and that the user scan it from the app and then you will get the information with with the proof in some of the Callback like on prooof generated that you requested uh the next step is that we're going to build like a react SDK so it's even easier to use we're going to take care of all the UI in ux flow so you don't have to take care of that so it's really one button and everything will be handled cool and um yeah so this section we're going to go go over uh kind of the differences between custodial versus self custodial and if it wasn't already obvious by the colors that I chose um one is good and one is bad and just to kind of maybe like reinforce that uh yeah this is the bad one and this is the good one okay so uh so for custodial identity verification as kind of like uh conceptually this is how it currently works so you're issuing government uh of your passport or other government documents they'll they'll provide it to you and then you'll be so also like digitally signing over it in example of a passport or a national ID card you'll then uh take a photograph of it and then you'll provide that to a kyc provider who will then maybe do a bunch of lookups in a private database and then eventually they'll just kind of let the service know um you know Yep this is Michael no this is not um and the issue with this model here is you have a like it's not not really end to end and so you lose the trust Providence uh along the route through this counterparty so it's kind of like it's wasted because the government's attesting to it originally and then that gets broken when you have this third party that has to re attest to it uh there's a Reliance on this this third party another downside is is it's all or nothing so you're taking you know a whole photograph of the passport um fraud is much easier with this approach because like I mentioned before generative AI you know that's coming it's going to get better uh it's also quite expensive so sometimes they need to fall back to manual verification which can can be costly for businesses which doesn't scale very well and I guess this is kind of like the you know the big issue with it really one of the ma major issues is you've got to rely on them to keep your data safe and they often don't which really sucks and so contrasting to that you've got self- custodial identity verification which is truly end to end and so in this model the government's you know digitally signing over your documents or attesting to these facts about you and providing it to you and then you can use uh you can use Z knowledge proofs here to uh verify the signatures in zero knowledge and then selectively reveal what it is you want to and provide that proof directly to the actual service end to end there's no other uh you know middleman that need to be involved in this even ask we just create the circuits um that to facilitate this but we aren't really the middleman and another great way to kind of think about this is who better to attest to the attest to your identity and your your personal information than the same entity that issued you your birth certificate so you know you change your name or you get married who do you go to right you go to your government and it's also another way to think about it it's kind of decentralized across the whole world in the sense that each government around the world they're attesting to these facts about their own citizens of their country and so onto some some interesting use cases here for Z passport there's really a myriad of different possibilities um but we'll just go over a few that kind of popped out to us is quite interesting and compelling uh private and compliant private tokens so we're currently building out uh a wallet called obsidian wallet on Aztec Network and we want to have privacy as the default and be able to have these stable coins like usdc on ramp and then be used completely privately so you can actually have um this peer to-peer you know private cash for for using it for just normal everyday transactions without worrying about privacy concerns and everyone seeing your full transaction history and so uh yeah in the future we hope to have this um integrated into obsidian wallet so we're going to have basically Zig passport as this kind of first class citizen F first class uh citizen for identity um as identity provider that will be able to automatically generate proofs uh whenever you know you're transferring us usdc around and so some maybe some examples here of the proofs would be generated so you'd have like uh compliance proofs which would prove maybe that you're not an ofac scn list you're not from a sanction country and then another option here could be maybe using this unique identifier that is the same for every passport um but also completely Anonymous you could track like transfers over time so you might impose like a super generous limit of maybe 100,000 usdc per month that's enough for 99.999% of people but that's going to severely limit uh like you know Bad actors from from laundering lots of of money through this and ultimately it's going to mean that you can off-ramp onto an exchange and not have to be worried about the exchange you know Banning your account um because you've used this this sort of this private and compliant token another use case could be proof of personhood so you can have increased Cil resistance so both in the context of web 2 and three is quite important you want to prevent spam and Bots for example you can have a social media platform that wants to really have one person and one account so you can do that much more easily with this solution or like simply the use case we use now day a capture you could replace that with a proof of P passport that would be much stronger another one is uh being able to prove you know your name is really what you say it is on social media so you can imagine like a very you know decentralized kind of way to do this with with a verified name badge You just prove your first and last name that was attested by some recognized government and then you could you could have that on social media as a a proof of name and another strong use case is proof of age there's some country that's start to impose age gating on some website such as adult content I know that because France is actually the country where I'm from is doing that they impose this legally speaking so but they want to do it privacy preserving way they still care about privacy which is nice to hear from the government so that's one use case as well um so here if you wanted to know which country actually support e passport electronic passport this is all the country in blue so that covers a PR big chunk of the world over 150 countries so this is an Open Standards set out by the IAL is an um institution of the United Nation so it's actually quite widely supported you will notice that India is not part of it it's like a big country that's not actually part of it for that country you would have solution like anadar which actually supports that kind of like alternative system uh but others like passport is pretty good there's some disparities in the signature algorithm though so they don't always use the same kind of signatures so we have to adapt to that it's not fully standardized but there's some flexibility to those standards but it's already quite good and another thing I want to point out is that National IDs especially in the EU also support that standards sometimes even resident permit so we can extend to that and the EU is also pushing generally for digital identity uh with the EU digital identity wallet and the general identity framework they're pushing with Eis and to give a bit of an overview here of the um the hierarchy of how this works it's very similar to pki with like the current the current web and SSL certificates you have this organization called iow and uh and iow they they are under the UN and uh they collect through diplomatic channels these root certificates from different countries and then these root certificates they then sign these intermediate certificates called DS or document signing certificates and those certificates they sign the actual e passport data itself so I'm going to go do a quick overview this is this our SEC work so essentially we get most of our data from what we call the data group one so it's like visible on the passport so the two bottom lines so it's like contain the name the date of birth and other information where you can derive a lot of information that generally people want and this is hashed into content with the rest of the data which itself is signed so this is what is interesting because that signed data is then we can verify it with the certificate mentioned by Michael the root trust chain go all the way up to the certificate that way we sure that that data has been issued in time by the state and from that we can derive proof of country proof of age while being sure that's coming from a verifiable source without riveting anything else about the information of the document um so cool great and uh so rather than just talk about it let's actually dive in and take a look at what ZK passport um looks like and how it works so this is ZK passport and the first step here is I'm going to tap my um government issue passport against the phone and it'll read the passport data in by NFC and then once that's done you'll see it come up here so that's me loaded into zikar passport and then the next step is just to connect it with the DAP so we can actually generate some identity proofs this is an integration that we did with Devcon and this allowed people who are from Southeast Asia to prove they from one of the countries from Southeast Asia um but nothing else about themselves and then they're able to get a discount voucher applied to their purchase of their Defcon ticket so to do that simply click on the continue button here this will generate a QR code which I'll then scan with my phone and then that will prompt that will prompt me to um which it'll prompt me to prove particular credentials that are being asked of me from this service in this case it's just my country um and that's completely up to the developer that's integrating this so I will hit uh accept this will generate the zero knowledge proof on my phone it'll then be sent via the secure end to end encrypted websocket where it's then verified um either on the back end or even um on a smart contract uh we uh we recently blessed by uh from with a visit from uh father vitalic at our booth just around the corner outside so please feel free to come by um we've got it for the rest of the day and um we have a workshop on tomorrow in classroom B at 12:00 p.m. so if you'd like to learn more about our SDK and uh and and how it works please come by and yeah you can chat with us sick and I guess lastly one one last QR code uh we have a demo available it works best on desktop it's the one we're using at the booth um so yeah there's a QR code if you want to try it out and you'll be able to load your passport in it supports both Android and iOS um yeah but if you have any issues with that please reach out to us and we can help you out all right round of applause give it up give it up okay cool so we have a couple of minutes left maybe time for two questions and uh let's just go with the top two so um I think you guys could just read that and answer it yeah yeah that's go for it um so regarding Noir as a DSL as a system so how did you land on Noir as the DSL for circuit does your system interact with a itself so first question um Noir so why did we choose that um we did choose it pretty early on when it was still quite unstable but now it's pretty stable so Noir I see it as a very um good language if you want to do Z cdsl cdsl that's mainten toward the future the Aztec team is pretty reliable they're a good team so you can rely on them and it's a universal language which means you can have like a single code base and switch your back end for a different one if you want a different proving scheme so you can still just improve uh with the whatever latest Improvement has been done in ZK while still maintaining the same Cod base so that I found this pretty powerful as for whether we interact with that St itself so zik passport is blockchain agnostic like the protocol itself is blockchain agnostic but as mentioned by Michael we're building this wallet called obsidian which yes that one's going to be interacted with Aztec specifically and going to integrate ZK passport for compliance and privacy mixed with identity at the wallet level on atic yeah there's no reason this can't be used on other chains like Alo or even like ethereum lay one um but it's more suitable as suppose on privacy chains where you can have these uh approv data um more private you more privately um how do you handle the ux problem of convincing users that their passport forther remains client side that's a great question I think this is going to be a challenge and it's going to come down to to Brand trust and basically building that up over time so we've got open source circuits and and open source codebase I think that's going to be that's going to help for sure uh and just being like critically neutral um you know people can trust this as a as as a brand that's going to respect privacy it's one of about core values so that's just going to take time I think and and you know demonstrating it through our actions okay make
