# Oasis Workshop | Matevz Jekovec | How to build on a confidential EVM | ETHDam 2024

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2024-10-07
- Duration: 36:37
- Watch: https://streameth.org/watch/yt-XqDUXEs3VVE
- YouTube: https://www.youtube.com/watch?v=XqDUXEs3VVE

## Description

ETHDam 2024 workshop on “How to build on a confidential EVM” with Matevz Jekovec, Software Engineer at Oasis Network. Matevz is a member of the DevEx team working on the documentation and other learning material for engineers, demo dApps, Oasis middleware for Go and TypeScript, and the Oasis CLI. If you find a non-working example, an outdated section in the docs or wondering if something is even possible to build on Oasis, he’s the right guy to poke. 
https://oasisprotocol.org/ https://twitter.com/OasisProtocol
ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. 

James Campbell - MC of ETHDam, Hackathon Organiser, and Web3 Developer.

ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. 

In the dynamic space of ETHDam, privacy and security took center stage, featuring groundbreaking discussions on hacks, recovery, and the revolutionary work of figures like Pertsev. Privacy is dead in crypto, people that know, know. People who don’t know, should know. 
ETHDam is powered by CryptoCanal, an education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zürich.
Keep up with us to see updates on future events: https://www.cryptocanal.org/ 
Follow CryptoCanal on X: https://twitter.com/CryptoCanal
Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity 
Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz

We would like to thank our partners that made this event possible. 🌷
Battleship Partner 
🛳Oasis Network https://oasisprotocol.org/

Jet Ski Partner
🛩⛷  NEAR https://near.org/

Canoe Partners
🛶WAKU https://waku.org/
🛶Trail of Bits https://www.trailofbits.com/
🛶Avalanche https://www.avax.network/
🛶Privacy + Scaling Explorations https://pse.dev/en
🛶Threshold https://threshold.network/

Our Canoe Partner & Official Node Provider
🛶dRPC https://drpc.org/

Sponsor
🤝EF Ecosystem Support Program https://esp.ethereum.foundation/

Paddle Partners
🚣ChainSecurity https://chainsecurity.com/
🚣Lido https://lido.fi/
🚣Cyber Capital https://www.cyber.capital/
🚣Diva https://www.divastaking.net/
🚣Firn Protocol https://firn.cash/
🚣Beefy https://beefy.com/
🚣0xbow https://www.0xbow.io/
🚣Obscura https://obscura.build/
🚣Panther https://www.pantherprotocol.io/
🚣Maven 11 https://www.maven11.com/
🚣Zama https://www.zama.ai/
🚣zkSync https://zksync.io/
🚣Secret Network https://scrt.network/

ETHDam AfterParty Fren
🥳Bitvavo https://bitvavo.com/en

Chapters:
00:00:00 - Sapphire and Solidity Hacking
00:04:05 - Zero Gas Fee Authentication
00:08:07 - Connecting to RPC endpoints and registering Sapphire
00:11:54 - Transferring Tokens from Paratime to Consensus Layer
00:15:41 - Running Sapphire Local Net
00:19:40 - Testing the Random Number Generator
00:23:50 - Combining the Address with a Random Seed
00:28:24 - Ethereum Transaction Generation and Signing
00:32:51 - Decoupling Web 3 tooling from the blockchain

## Transcript

[Music] uh now we have mates from Oasis thank you very much hey hey right so uh in the next 30 minutes I'm doing a crash course on Sapphire and um for those of you uh there's a recording of the session I had a week ago um there a one one hour course which ended up being 75 minutes long um and it's about it's it's it's a workshop on how to build deps on uh us Sapphire um but um I ran out out of time the last week uh for concrete Hands-On solidity hacking uh for conf confidential smart contracts so I thought of doing this in the next 30 minutes uh hackers oops sorry uh hackers got this uh so this is the ois cheat sheet basically and I would just go through through the the most relevant parts and then spend most of the time on the solidity uh code and just to you know um you know get your hands dirty on and see how how things work in practice best programming um practices put it this way okay so the first QR code here is the demo star project um and this is the project we suggest everyone to use um it's nothing particularly special so I already mentioned this a week ago uh basically it is come on um it's a monor repo uh written in typescript you have two components the backend one and the front end one and the smart contract is stored in the back end one the front end one is a view um based uh front end app and the back end one is the one uh that we're we'll be focusing today uh and I already checked it out here in my um home folder to my home folder and I we will use this ID uh to hack on it uh okay so um there were questions about uh whether I should use ethers or web3 or VM wagi whatever um so web3 is obsolete as you probably know so don't use that we prefer to use hardat and ethers combination uh wag me one already works out of the box wagm 2 we had a like huge 5,000 div PR ready to be merged in and uh it's not in yet so um we prefer to use you know typescript hardhead combination uh for the front end um use either wagi 1.0 or uh just an ordinary um ethers um connector okay um so this is the demo star project let's move on one um the next link here uh is a bunch of examples so this is the so-called playground um and that currently there are 13 projects uh there's again a bunch of projects on my to-do I'd like to add um but basically here just uh to briefly go go through for example if you click on let's say confidential voting um here there are these tags here and uh they show you which technology and what are the you know highlight features that you should uh be focusing on um so this one for example uses gasless uh this means that uh the user who votes concretely in This Confidential voting dep example uh they don't need to pay for any guas fees uh and we will also show uh see in the in in the examples at the end of this talk uh how this can be done you know in practice uh but the idea is that you don't um require uh that your users have an ethereum or whichever Network um e compatible wallet uh that they don't need funds to pay for the gas fee right so if you if you imagine there's an election government elections whatever and you have your voters wanting to to submit their U poll um they just uh you know go there and they um put in the ballet right uh in a box they don't need to have any uh tokens whatsoever to to pay for the fee so that's the ideal scenario and that's what this example is is about um right so here for example you you have um interesting things uh the authentication uh oan uh example um takes the um H basically the the mobile devices have this uh oend protocol integrated which you can use um to authenticate yourself uh to whichever service out there so this is just one maybe there's a team doing biometric stuff these are the examples uh they should look at um what else uh there are some uh examples which are strictly CLI so for example this one um they have this CLI tag so basically it's just a backend example um yeah um okay and some some more well uh for example uh o swag uh this was uh one of our favorites uh basically it us a onchain random number generator you um there's this Wheel of Fortune and then you uh get a reward uh for example the ois Hat on this screenshot um and let's see what do they use uh so it's a react based front end uh the ois swag is an nft thing so uh you can also then transfer it to your wallet random number generator and it was presented at consensus 2023 and this TC 2023 conferences so yeah and you can of course uh filter by a specific tag um search for it uh also the license um type of sources does it contain demo code is it part of the official documentation and so on okay um let's move on uh the test net foret so anyone uh deploying their dep on our test net we'll need the token and we are very um we are not conservative about that so you just go here you you pick your um layer so either the consensus layer or any of the popular chains below uh you will you will use Sapphire most of you so the confidential even in compatible chain and uh just type in the address let's go ahead and um I will this one I'm not a robot I hope so yeah capture and uh yeah cool and I should suppose that should work sooner or later oh is I yeah it's a SE test um okay so uh this is a testet facet I will not wait it it should work if it doesn't work ping me on on Discord um it does yeah awesome uh then the documentation um so the most important part for you is probably dep developments since you're a developer um so create D and Sapphire again uh the landing page for the sapphire uh chapter is the chain information um the chain ID so these are information needed if you want to um basically connect to it with your client backend front end whatever uh there are multiple um RPC endpoints since we are decentralized of course um and to register sappire to your metamask you don't need to enter that those information manually just click on the button for example here and uh if your network is not registered yet yet uh the manam mask popup uh popup will show and um add it to your config oh yeah tokens arrived um cool next uh the block Explorer and the wallet so um we have the official Oasis block Explorer uh it's at explorer. oasis. uh the main difference between our Explorer and the other explorers are that our Explorer is not only evm compatible but also covers uh consensus so this is still a work in progress but it will be there soon uh and also you will notice uh these icons here for transactions uh the gray icons mean that the transaction was not encrypted uh the green icon mean that that the transaction used the native um uh endtoend uh Oasis powered encryption um why am I talking this well because you can also have an unencrypted transaction an ordinary ethereum transaction with uh the call data as they are but inside the call data you can simply you know encrypt um the content with a shared key onchain for example and the transaction would be shown as an unencrypted transaction but actually if you try to look into the the transaction content you would see just some um binary blob basically um so yeah the this is the Explorer um you will notice typically you you just search for uh some um hash I don't have any any of those here or let's search for for this account okay and if you look up okay uh you may notice that there is an account on uh safire main net but there's one more result and it's also on testet so my account actually is on test net I think I used it once on the minut by the by accident yeah it's have half rows there you can yeah transfer it I have the private key here um so yeah uh the point being the same Explorer covers both test net and mayet okay so we just uh enter thing you're looking for here and both results will show up from the main net and and the test net um okay o this wallet um a very similar story uh so you can use metamask on ois Safar because Safar is evm compatible there's also another chain called Emerald uh this is an older chain which doesn't support um confidentiality and both are evm compatible that means that you can use metamask or any other ethereum compatible wallet uh to transfer tokens to um execute transactions um and stuff like that um but it doesn't support any confidentiality so the end to end encryption I I was talking about before you need to use a special JavaScript um on your website to enable to rep your metamask um wallet that it enables the endtoend encryption um also we are only talking about the evm compatible chains so what happens if you want to transfer if you want to move tokens from the par time back to consensus layer uh well you there are some special nonm transactions for that and that's why you need our wallet so if you're uh you know doing stuff like moving tokens on consensus ler for example to exchanges uh binance for example um C coin and some other exchanges only support receiving Rose tokens on consensus layer so no safire there and if you have roses on on on Sapphire you first need to withdraw them to consensus layer and then move them uh from there to the binance account uh so yeah this is the reason why there is a special uh wasis wallet and we have two versions of those uh one is at uh wallet.io that's a web wallet basically a website and you um insert your private key or ponic and then it's encrypted inside your browser State um another wallet is a uh wallet extension uh so it's I think I have it in it yeah it's on Chrome I I won't show I won't open it um right now but you can read more about uh here manage tokens ois wallet and you have the the web wallet and the browser extension and instructions to install it also Ledger is supported and so on and so forth so yeah uh but for all intents and purposes uh metam mask is probably the right tool for you uh maybe if you just for production on the main then you want to have some access to production roses and then you want to buy them probably on exchanges and move them uh to your account using this uh Oasis wallet um okay right um the Safar local net Docker uh so does anyone of you know the um hardhead node command okay some of you um so basically what the hardhead not command does is it runs uh mock uh blockchain locally on your computer so we have this um ethereum grpc interface uh and you can connect to it there are some pre-funded accounts called the the test pneumonic accounts um and you the hard head interface usually uh I can show it to you it prints the private keys and the addresses so the command to execute that is npx hardhead note um and this spins up uh the oops it already it's already running yeah okay let's try it again it basically spins up very quickly and prefunds what 20 20 accounts and then you can use those accounts locally you can even connect your metamask uh wallet to that instance and then when you hit the control c key um the chain uh is closed uh okay and now there's an issue right we have a bunch of um onchain Primitives for signing for random number generation uh encryption decryption and so on this is all done on chain and if you are trying to do this with this uh hardhead built-in uh mock uh you won't get anything mostly you know if you try to to call the random number generator you'll just have zeros all the time and for this reason we built a special uh Docker image which contains a complete um Oasis Network inside the docker image so we have the the validator node running the consensus layer and then you have one compute Noe uh running either Sapphire or Emerald we will be interested in in in in Sapphire uh and it prefunds some accounts uh either some random accounts or the test Min monic that are compatible with the npx hardhead node I'm I'm mentioning the this hardhead node command all the time because the tests are usually using those accounts and we use the same account so you can run your test for your dep uh using our safr local net Docker image for for that purpose um right and there's this command here uh on your cheat sheet so Docker run and then there are uh ports you need to open so um the HTP and websocket ports 8545 8546 um and I also use some debugging option let's remove those we don't need that and the is um yeah GitHub containers with protocol Sapphire local net and um you can pass it's written here either you you can do something like two and your um ethereum address and that account will be pref funded with I think 10,000 uh test tokens or something like like that um or you can just pass the test ponic parameter and it will pref fund the same um accounts that the ambex uh hardhead node command does so uh what are we going to do next um we will hack some uh solidity contracts and for this purpose we will spin up our uh Safar local net image so we can use this random number generation uh Primitives okay uh so this will just take a minute it takes a bit longer because our I mean we don't um mock anything here basically we we have a one second you know block time uh I think it's 10 minutes Epoch uh and so it it still needs to spin up the whole the whole network and elect all the Committees uh spin up the key manager and stuff like that yeah so this takes a minute or so uh but afterwards um it runs um it should run fine yeah so populating accounts okay uh cool uh so let's start on solidity what's my time okay perfect so 15 more minutes um so I checked out the demo star project uh and the first thing I'm going to do is I will import the uh Safar contracts so if you go to the cheat sheet this line import ois protocols F construct okay so this is the library we're going to use uh and the first task I'm going to show you is random number generator okay so let's uh what should we do okay let's let's um compute the my my favorite number so instead of calling message uh let's rename this to favorite number I suppose and it will return the uint for this purpose and okay so um let's just remove the seat for now and just ah return Safar do random bytes So Random bytes function will generate uh the X number of random bytes so 32 bytes in our case um and and I probably need to cast this to U 256 otherwise the compiler will complain um and let's also fix the tests so our test currently they call this set message we won't be using that anymore um also this can go out so the test will basically deploy our contract and it will run this favorite number um and let's let's print out the what it produces okay so we can see if the random number generator really works okay so um the safire local net image is now spun up and let's test our code if we do npm test will it compile okay so it complains that um oh you six does not need any bars okay and from bites memory to tooth so should probably do something like this so is Clumsy when it comes to casts but okay so cool the test ran and um our our contract returned zero so this smells if the random number generator is not running on our Sapphire but on some internal uh hard hat node right and this is exactly the reason so um if you want to run the tests on the uh Safar local net we're running you need to pass the dash dash Network Safar local net okay so this should produce something different now awesome yeah so this is the random number which was generated on chain and if we run it again it should be different right yeah um now just for uh as a as a side note the d-h network uh takes the predefined networks in your config file so the demo starter already has the following networks defined so the sappire is uh the mayet version sappire test net is the test net RPC URL here uh and then we have this safr local net which is basically if you spin up the docker image this is the address it will take the RPC address um okay so this is the number the random number generator now um what you usually what you usually do is the following um you don't generate the random number uh each time but you want to have for example you have uh some reward uh coupons you gave them out to to your users uh you probably got the blue roses uh at the venue right so I if you notice there's this test coupon um no it's not test it's a production coupon sorry and the QR code and basically how how the quiz is implemented is that it takes the coupon code it combines it with some random seed right and then it uh randomizes the the questions and answers for you okay and now the issue is the following you want to have uh so you want to have your answers and questions randomized but per user right so we have each coupon should have uh deterministically randomized uh question and and answers because otherwise I mean the the user could you know then select the answers submit it but then the the answers would be um uh reshuffled again and you couldn't you know match them anymore so you want to have a you know fixed randomized Vector per coupon okay so let's do this we want to combine the address for example the who who is assigning the transaction or doing the call we want to combine that address with some random seed okay uh so this random part will now go inside the um Constructor I suppose and it the seed will remain the same so Constructor um I don't know seed equals this and Seed will be our private uh variable so something like this so when we deploy the contract there will be the random seat generated and then that seed will remain there all the all the time the same and uh we will use it to derive uh then practical use cases for example the the order of uh questions and answers so in our case let's now uh combine the the message sender so the address with this seat so uh we do I think an example here right um basically we want to use the message and just copy and paste so this is how the determinism is is achieved we take the message sender we take the seed we combine the two well in solidity it's something uh like ABI do incode pack so we can just uh list arbitrary number number of um parameters and it will uh use the RP encoding and it will produce a long you know serialized version of those and um that's basically it uh and once we have this combined yes of course we want to Hash it so we don't reveal the the seed right to anyone and then once we hash it we just return something model 100 for example and okay let's try it out so this should now be more deterministic uh 90 okay and if you run it again oh it's different any ideas why okay so when you run the test the message box smart contract is redeployed each time so we you know computed the seat at the in Constructor so yeah if we do something like this so make then two two calls to the favorite number function using the same instance uh it should return the same the same right okay awesome 59 59 cool uh by the way the the N thing here is because it's a big number this is Javascript specifics don't uh don't bother um okay uh cool the next task um let's generate the signing keeper question um okay so four minutes including questions you have uh until 16 23 24 okay so let me just uh do another short example um so I want to generate the key pair on chain so something like this oops there's my solidity contract so this example is pretty cool so that's why I I want to I want to show it to you so um basically we will generate a signing keeper based on our seed uh and then we will use this keeper to create an ethereum transaction that can be you know broadcast gasless DX so yeah you already see from the name of the variable uh what's the point of everything uh so uh the sapphire Library also provides uh something called um eap1 155 signer that's basically um a shortcut to generate uh ethereum transaction on chain and sign it with the provided key uh the key is a 32 byte um secret part and uh 32 by public part and the address also needs to correspond the address is derived from the public key and the public key must match uh the the secrity key in order for uh signature to to work right okay so what do we do uh let's take the address um let's take one of this addresses uh suppose this account 070 will be the one who pays for the guess uh uh the secret key is this one and then the transaction content will be something like uh we need Ann and then find the guas price the guas limit so standard ethereum transaction and now what will the transaction do well we will call a method inside our smart contract which method let's say set message what parameter um my message okay and what else well yeah suppose this is fine uh maybe the test still needs some love I'm not sure if this works um okay yeah let's skip the key generation for now uh oh yeah this should be another solidity specifics and 29 line is which one oh non is 64 byte I didn't know that cool oh let's let's output the what's the output yeah so let's uh console log where did it go console log favorite number so now that we yeah we reimplemented the favorite number and it should output the ethereum transaction we can broadcast now the whole idea is that you generate transaction online using this uh public Key address and the secret key uh it can be stored you know suppose this is uh stored in a contract uh and no one can see it except for for example the owner of the contract and it can generate and sign transactions completely on chain so if you look at the transaction now uh and check if it's really an ethereum transaction we can go to the ethereum transaction decoder something like this and try to see what's inside and we can see it's a perfectly valid ethereum transaction there's the gas limit gas price nons destination address um data and uh data includes the uh function the transaction calls and the parameters so if you were there and just then use the client to submit that transaction it will work and that's the exactly same mechanism we used um in this uh e Dam quiz you got when you got your blue roses uh to receive your tokens so we have some other account paying the gas fee for you and you just need to type in the receiver um address for the tokens you don't need to have a metamask wallet connected to our dep or whatever okay so this is just a an idea for any any developers out there for for the hack owners who want to have who want to decouple you know the the current web 3 metamask is tool tooling away from from the actual um blockchain that's used behind the scenes as a backbone for example okay cool this is it for me thank good luck question oh yeah some yeah I had a I had a quick question uh in the Constructor on the random generation there was an empty string as one of the parameters um yeah what's that for uh this is the extra entrop extra entropy so suppose you want to initiate to initiate the random seat using some function some transaction not inside the Constructor but also want to provide some extra entropy if you don't trust the onchain enclave yeah thank you so you got to my question um so this was originally a question about is this possible or not because uh we want to use a third party tool which itself needs uh it has like a subset of JavaScript so itself needs to wrap the transaction that it makes to an evm so I was hoping that we could just make that straight to Sapphire um by putting the the RPC endpoint the sapphire in but maybe we can't because you're saying that you need some JavaScript to wrap the actual transactions to to Sapphire because it's not fully equivalent to the evm when you make that call but now I'm thinking you've just demonstrated wrapping a call to an actual EV evm in Sapphire does that mean that we could uh that we could we could use uh Sapphire to sign uh transaction to another evm so we could somehow call Sapphire via uh you know whatever simple endpoint and then uh use that to wrap a transaction to another evm okay so um if you want to have if you want to use Bridge uh we have this Oasis um privacy layer opl C which integrates the seller uh Bridge uh library and it already support sending messages back and forth a number of chains uh another thing safire is uh you can use ordinary non-encrypted standard uh evm transactions to safer and they will work fine but they won't be encrypted okay so it's up to you to use end to end encryption or not it's it's it's totally up to you so you can you can just as you said switch RPC and it it should work the contract should be deployed and it should work out of the box uh well not that much but yeah I mean the the the the whole Bounty idea is that you use the sapphire primitive the solidity Sapphire Primitives as much as you can you know to make something useful on chain amazing thank you so much unfortunately that's all we got time for on questions if you've got more questions for Oasis they have I'll be there and also on Discord Channel yeah they have the booth downstairs please go and interact with the sponsors that's why they're here they want to speak to you um they want to hear your questions um thank you so much for your time that was excellent thanks sh [Music]
