Welcome to EA to E to E to E to E. All right, our next talk uh from Alexander is ZKPS in identity. Thank you very much. Yeah, thank you. Thank you.
Um yeah, thanks for having me. Um my name is Alex. I'm lead of cryptography at Ramo Protocol and distributed lab. And yeah, I wanted to go quickly through existing mechanism for creating your digital identity parts. Uh so yeah, the reality is nobody knows what the identity is.
Uh the best term is that's like a set of statements uh that describes some properties of particular object. Uh but everybody knows what exactly digital identity should provide. The first of all, it should be self- sovereign. It means that the user needs to control their own identity. So you're you shouldn't delegate this rights for your identity to some external provider.
The next one is a privacy. So uh privacy means you need to prove the statements about your identity but without revealing sensitive information. For example, I can prove that I'm adult but without reent exact age and without like reing other data included in my passport for example. The next one uh this like extension for the privacy uh you should be uh able generate all proofs locally. So without delegating the proven process to some trusted server it's like an ideal world.
The next one you shouldn't have like some trusted teacher uh sometimes it's not possible because a real world organized in the way when you have a lot of instances a lot of trusted authorities and each authority can create the statement about yourself. uh but ideally uh like you need to have a situation when you don't need to create the infrastructure and there's a problem in a lot of verifiable credential protocols uh because if you have some existing statements about your identity uh you need to have a way how you can digitize them and yeah we we will also cover that and the last one and probably the like the most difficult property is this uniqueness so sometimes it's not necessary but for some applications it's very crucial to have that and probably everything started with verifiable credentials uh such protocols like identado ID as a product uh verifiable credentials allow you to create a triangle with uh identity issues with users and verifiers uh so yeah first of all that's self- sovereign uh for example in Idensry protocol you're controlling the cryptographic key pairs And you can collect different statements and uh connect them to to this cryptographic pair and later prove the statements with a digital signature. So you're controlling your identity after the statements were issued by the trusted authority. The next one that's a private. So it 3 proposes like the way how you can malize all verifiable credentials and then prove that you're included into the set created by identity provider but without revealing your public key for example.
The next one is totally client side. So you can generate all proofs locally on your mobile device. The problem is you need to have this like trusted issues. Uh but that's not the biggest problem. The biggest problem is you need to create a new infrastructure for that.
So you need to integrate this like SDKs to like any existing authorities and push them to use identity protocol and it's very difficult reality. Uh and the last one yeah fortunately you can reach uniqueness with this approach. So if you have this trusted authority and it can detect unique users uh it can yeah create this source of uniqueness for them. Uh then um yeah we started probably two years ago as a verifiable credential aggregator for remote but later we investigated that you can bring some existing web two and web one web one uh artif uh credentials into web 3 for example digital passports uh that's like entity uh that has already issued lot of passports and you can fetch the data from the passport together with signatures and cover them with zero knowledge proofs. So you can snarkify the process of passport verification and you can fetch all data and create proofs that uh government uh confirm it.
You're like Ukrainian for example, you're 18 plus but without revealing your sensitive information. Uh but yeah, zero knowledge passports can be implemented in several ways. uh but the biggest problem is uniqueness here. So when you're creating zero knowledge proof stuff on your passport data, you cannot uh fetch the source of uniqueness in the way your government cannot trace that. So you can operate with password without uniqueness.
So just proving that you are Ukrainian. uh but if for example you need to reuse this infrastructure for the voting solution uh you need to have like one vote per one password uh and uh you can organize this like uniqueness generation with MPC protocols but in ideal case you shouldn't rely on some like MPC trusted authorities uh we solve with that in RAM in some way but it requires a public setup it means first of all you need to create the the registry with a lot of passers and additional key pairs and then you can extract the uniqueness from these key pairs. Uh we then launched uh voting solutions. Uh it's like not a voting solution but the solution for digital protests. We tried like to troll existing centralized regimes with that.
Uh so you can tap your passport and I don't know support some decision for example. uh and tested that uh firstly for Russian oppositioner then we launched the fork of the solution for Iran together with the mean money uh for Georgia. So yeah we tried to show an opportunity how you can organize the decentralized vault in like onchain but without like real and sensitive information. Uh and uh the question is how yeah a lot of people ask it ask us how you can prove that you're actual owner of the passport uh and yeah for sure you cannot create so this not deterministic process of proving your face uh and that's like closer to the KML and I can show you a quick demo how you can prove your face on your mobile device. So for example, I can scan my face something with the light.
Yeah. And I can extract the set of feature. Then I I I can extract the same set of features from my passport as well. Then I can create the next photo. Yeah, that's another features.
And then I'm proving the distance between the first set and the second one under particular threshold. That's a gross 16 proof. That's the difference. That's like 48. If that's under 60, so probably the same person before the camera.
And yeah, it doesn't resolve the problem like in general. Uh so you cannot use this approach for recovery your account but this additional layer of security if you're operating with passport data. Uh oop sorry uh yeah and this process allows you to create a verifiable probabilistic statements. So you can deterministically prove that some probabilistic algorithm like like the KML was executed correctly and we have built SDKs that allows you to implement following cases. The first one it's like the K leness.
Yeah, sometimes our models work like better than expected. So they uh define it like Jesus like is is life. But anyway, that's a probabilistic model. uh you can prove that you're a real person uh like without real and who who you are. Next one you can create a classifier and allows to prove like that the particular object or for example animal on the photo.
And the last one you can define you can convert a zero knowledge process when you're proven yeah where is your secret knowledge of particular object or the picture for example and you can pro create a pro proof of proximity so I can remember this specific object and for example attach that as a recovery option for your account. Uh so yeah and like a small announcement we will open source everything probably until the end of May. Uh what we are open sourcing this like a framework that allows you to create zk friendly models. So you can create the model train that like define weights and create a provable environment for different zkl parts. Uh and yeah, if you're interested, you can check uh our blog with construction how we um yeah, how we made that z friendly.
Um yeah, that's it. Thank you for your attention. Any questions for Alexander? Okay, good. if you if you if you want to have like a personal demo with the object.
So, I'm here. You can find me. Thank you again. Thank you.
Automatic transcript — names and jargon may be misspelled.